Skip to content

Microsoft Entra ID Security Checks

All security checks Aether365 performs for Microsoft Entra ID.

IDTitleSeverityFramework
AE.1068Restrict non-admin users from creating tenants.MediumOther
AE.1069Restrict non-admin users from creating security groups.MediumOther
AE.1070Restrict device join to selected users/groups or none.MediumOther
AE.1077App registrations with privileged API permissions should have no ownersMediumOther
AE.1078App registrations with highly privileged directory roles should not have ownersMediumOther
AE.1079Privileged API permissions on service principals should not remain unusedMediumOther
AE.1080Credentials, tokens, or cookies from highly privileged users should not be exposed on vulnerable endpointsMediumOther
AE.1081Hybrid users should not be assigned Entra ID role assignmentsMediumOther
AE.1084Seamless Single SignOn should be disabled for all domains in EntraID Connect servers.MediumOther
AE.1085Pending approvals for Critical Asset Management should not be presentMediumOther
AE.1090Global administrator role should not be added as local administrator on the device during Microsoft Entra joinMediumOther
AE.1091Registering user should not be added as local administrator on the device during Microsoft Entra joinMediumOther
AE.1106Catalog resources must have valid roles (no stale / removed app roles or SPNs)MediumOther
AE.1107Access packages and catalogs should not reference deleted groupsMediumOther
AE.1108Access packages should not reference inactive or orphaned assignment policiesMediumOther
AE.1109Access package approval workflows must have valid approversMediumOther
AE.1110No catalog should contain resources without any associated access packagesMediumOther
AE.1111High privileged user should be linked to an identity.MediumOther
AE.1112Privileged user accounts should not remain enabled when the linked primary account is disabled.MediumOther
CISA.MS.AAD.1.1Legacy authentication SHALL be blocked.MediumCIS
CISA.MS.AAD.2.1Users detected as high risk SHALL be blocked.MediumCIS
CISA.MS.AAD.2.2A notification SHOULD be sent to the administrator when high-risk users are detected.MediumCIS
CISA.MS.AAD.2.3Sign-ins detected as high risk SHALL be blocked.MediumCIS
CISA.MS.AAD.3.1Phishing-resistant MFA SHALL be enforced for all users.MediumCIS
CISA.MS.AAD.3.2If phishing-resistant MFA has not been enforced, an alternative MFA method SHALL be enforced for all users.MediumCIS
CISA.MS.AAD.3.3If Microsoft Authenticator is enabled, it SHALL be configured to show login context information.MediumCIS
CISA.MS.AAD.3.4The Authentication Methods Manage Migration feature SHALL be set to Migration Complete.MediumCIS
CISA.MS.AAD.3.5The authentication methods SMS, Voice Call, and Email One-Time Passcode (OTP) SHALL be disabled.MediumCIS
CISA.MS.AAD.3.6Phishing-resistant MFA SHALL be required for highly privileged roles.MediumCIS
CISA.MS.AAD.3.7Managed devices SHOULD be required for authentication.MediumCIS
CISA.MS.AAD.3.8Managed Devices SHOULD be required to register MFA.MediumCIS
CISA.MS.AAD.4.1Security logs SHALL be sent to the agency's security operations center for monitoring.MediumCIS
CISA.MS.AAD.5.1Only administrators SHALL be allowed to register applications.MediumCIS
CISA.MS.AAD.5.2Only administrators SHALL be allowed to consent to applications.MediumCIS
CISA.MS.AAD.5.3An admin consent workflow SHALL be configured for applications.MediumCIS
CISA.MS.AAD.5.4Group owners SHALL NOT be allowed to consent to applications.MediumCIS
CISA.MS.AAD.6.1User passwords SHALL NOT expire.MediumCIS
CISA.MS.AAD.7.1A minimum of two users and a maximum of eight users SHALL be provisioned with the Global Administrator role.MediumCIS
CISA.MS.AAD.7.2Privileged users SHALL be provisioned with finer-grained roles instead of Global Administrator.MediumCIS
CISA.MS.AAD.7.3Privileged users SHALL be provisioned cloud-only accounts separate from an on-premises directory or other federated identity providers.MediumCIS
CISA.MS.AAD.7.4Permanent active role assignments SHALL NOT be allowed for highly privileged roles.MediumCIS
CISA.MS.AAD.7.5Provisioning users to highly privileged roles SHALL NOT occur outside of a PAM system.MediumCIS
CISA.MS.AAD.7.6Activation of the Global Administrator role SHALL require approval.MediumCIS
CISA.MS.AAD.7.7Eligible and Active highly privileged role assignments SHALL trigger an alert.MediumCIS
CISA.MS.AAD.7.8User activation of the Global Administrator role SHALL trigger an alert.MediumCIS
CISA.MS.AAD.7.9User activation of other highly privileged roles SHOULD trigger an alert.MediumCIS
CISA.MS.AAD.8.1Guest users SHOULD have limited or restricted access to Entra ID directory objects.MediumCIS
CISA.MS.AAD.8.2Only users with the Guest Inviter role SHOULD be able to invite guest users.MediumCIS
CISA.MS.AAD.8.3Guest invites SHOULD only be allowed to specific external domains that have been authorized by the agency for legitimate business purposes.MediumCIS
EIDSCA.AF01Authentication Method - FIDO2 security key - StateMediumEIDSCA
EIDSCA.AF02Authentication Method - FIDO2 security key - Allow self-service set upMediumEIDSCA
EIDSCA.AF03Authentication Method - FIDO2 security key - Enforce attestationMediumEIDSCA
EIDSCA.AF04Authentication Method - FIDO2 security key - Enforce key restrictionsMediumEIDSCA
EIDSCA.AF05Authentication Method - FIDO2 security key - RestrictedMediumEIDSCA
EIDSCA.AF06Authentication Method - FIDO2 security key - Restrict specific keysMediumEIDSCA
EIDSCA.AG01Authentication Method - General Settings - Manage migrationMediumEIDSCA
EIDSCA.AG02Authentication Method - General Settings - Report suspicious activity - StateMediumEIDSCA
EIDSCA.AG03Authentication Method - General Settings - Report suspicious activity - Included users/groupsMediumEIDSCA
EIDSCA.AM01Authentication Method - Microsoft Authenticator - StateMediumEIDSCA
EIDSCA.AM02Authentication Method - Microsoft Authenticator - Allow use of Microsoft Authenticator OTPMediumEIDSCA
EIDSCA.AM03Authentication Method - Microsoft Authenticator - Require number matching for push notificationsMediumEIDSCA
EIDSCA.AM04Authentication Method - Microsoft Authenticator - Included users/groups of number matching for push notificationsMediumEIDSCA
EIDSCA.AM06Authentication Method - Microsoft Authenticator - Show application name in push and passwordless notificationsMediumEIDSCA
EIDSCA.AM07Authentication Method - Microsoft Authenticator - Included users/groups to show application name in push and passwordless notificationsMediumEIDSCA
EIDSCA.AM09Authentication Method - Microsoft Authenticator - Show geographic location in push and passwordless notificationsMediumEIDSCA
EIDSCA.AM10Authentication Method - Microsoft Authenticator - Included users/groups to show geographic location in push and passwordless notificationsMediumEIDSCA
EIDSCA.AP01Default Authorization Settings - Enabled Self service password reset for administratorsMediumEIDSCA
EIDSCA.AP04Default Authorization Settings - Guest invite restrictionsMediumEIDSCA
EIDSCA.AP05Default Authorization Settings - Sign-up for email based subscriptionMediumEIDSCA
EIDSCA.AP06Default Authorization Settings - User can join the tenant by email validationMediumEIDSCA
EIDSCA.AP07Default Authorization Settings - Guest user accessMediumEIDSCA
EIDSCA.AP08Default Authorization Settings - User consent policy assigned for applicationsMediumEIDSCA
EIDSCA.AP09Default Authorization Settings - Allow user consent on risk-based appsMediumEIDSCA
EIDSCA.AP10Default Authorization Settings - Default User Role Permissions - Allowed to create AppsMediumEIDSCA
EIDSCA.AP14Default Authorization Settings - Default User Role Permissions - Allowed to read other usersMediumEIDSCA
EIDSCA.AS04Authentication Method - SMS - Use for sign-inMediumEIDSCA
EIDSCA.AT01Authentication Method - Temporary Access Pass - StateMediumEIDSCA
EIDSCA.AT02Authentication Method - Temporary Access Pass - One-timeMediumEIDSCA
EIDSCA.AV01Authentication Method - Voice call - StateMediumEIDSCA
EIDSCA.CP01Default Settings - Consent Policy Settings - Group owner consent for apps accessing dataMediumEIDSCA
EIDSCA.CP03Default Settings - Consent Policy Settings - Block user consent for risky appsMediumEIDSCA
EIDSCA.CP04Default Settings - Consent Policy Settings - Users can request admin consent to apps they are unable to consent toMediumEIDSCA
EIDSCA.CR01Consent Framework - Admin Consent Request - Policy to enable or disable admin consent request featureMediumEIDSCA
EIDSCA.CR02Consent Framework - Admin Consent Request - Reviewers will receive email notifications for requestsMediumEIDSCA
EIDSCA.CR03Consent Framework - Admin Consent Request - Reviewers will receive email notifications when admin consent requests are about to expireMediumEIDSCA
EIDSCA.CR04Consent Framework - Admin Consent Request - Consent request duration (days)MediumEIDSCA
EIDSCA.PR01Default Settings - Password Rule Settings - Password Protection - ModeMediumEIDSCA
EIDSCA.PR02Default Settings - Password Rule Settings - Password Protection - Enable password protection on Windows Server Active DirectoryMediumEIDSCA
EIDSCA.PR03Default Settings - Password Rule Settings - Enforce custom listMediumEIDSCA
EIDSCA.PR05Default Settings - Password Rule Settings - Smart Lockout - Lockout duration in secondsMediumEIDSCA
EIDSCA.PR06Default Settings - Password Rule Settings - Smart Lockout - Lockout thresholdMediumEIDSCA
EIDSCA.ST08Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to become Group OwnerMediumEIDSCA
EIDSCA.ST09Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to have access to groups contentMediumEIDSCA
Vai šī lapa bija noderīga?