Version 0.4.0
Scanned August 13, 2026 at 12:00 AM UTC
Mode Demo scan (synthetic data)
Organization Demo (synthetic data)

Posture

Where you stand

Demo (synthetic data) — Security License Lens assessment

Version 0.4.0 Mode Demo scan (synthetic data) identity, endpoint priority packs

17% realized
6You own 1Fully workingof 6 prioritized 4Action required 1Incomplete 3Not licensed

25 licensed capabilities detected 6 evaluated capabilities

Realized investment

Realized security investment: 17% of 6 owned, evaluated security controls met the activation criteria.

Realized investment
Fully working capabilities17%
Owned, evaluated capabilities6
Operational distribution

Distribution of the 6 owned, evaluated capabilities: 4 action required, 1 incomplete, 1 operational, 3 not licensed.

Operational distribution
Action required4
Incomplete1
Operational1
Not licensed3
  • Action required 4
  • Incomplete 1
  • Operational 1
  • Not licensed 3

Of the security controls associated with the entitlements and assessment scope that could be evaluated, 17% met the defined activation criteria.

Of the security controls associated with the entitlements and assessment scope that could be evaluated, 17% met the defined activation criteria.

View prioritized actions

Priorities

What matters most

Ranked by security impact, evidence confidence, and estimated effort.

  1. 01
    Restrict user consent so only admins approve non-trivial permissions ~a few hours

    Why: Users can still approve app permissions themselves, which is a common path for consent phishing.

    Action: Restrict user consent so only admins approve non-trivial permissions.

    Checks: id-app-user-consent-restricted

  2. 02
    Disable SMS, Voice, and Email OTP authentication methods ~a few hours

    Why: SMS, voice, or email one-time codes are still allowed — these are the easiest multi-factor methods for attackers to abuse.

    Action: Disable SMS, Voice, and Email OTP authentication methods.

    Checks: id-auth-weak-methods-disabled

  3. 03
    Create two cloud-only, Global Administrator emergency accounts excluded from Conditional Access, declare them as break-glass principals in… ~a few hours

    Why: We could not confirm a dedicated emergency admin account. Without one, an outage or lockout can lock you out of your own tenant.

    Action: Create two cloud-only, Global Administrator emergency accounts excluded from Conditional Access, declare them as break-glass principals in your configured settings, and remove any other unexplained exclusions.

    Checks: id-break-glass-exclusion

Effort is a rough guide, not a quote.

Entitlements

What you're paying for

Licensed controls mapped to detected Microsoft entitlements, grouped by workload.

Owned SKUs (2)

SKU Service plans Licenses
Microsoft 365 E5 Microsoft Entra ID P2, Microsoft Entra ID Multifactor Authentication, Microsoft Defender for Cloud Apps, Microsoft 365 Advanced eDiscovery, Microsoft 365 Customer Lockbox, Microsoft Purview Information Protection P2, Microsoft Defender for Office 365 (Plan 2), Microsoft Defender for Endpoint P2 87 of 100
Microsoft Sentinel Microsoft Sentinel 1 of 1

Your security capabilities

Action requiredIncompleteOperationalNot licensedNot assessedVerification failed
Action required

Smarter sign-in rules

What it does Decide who can sign in, from where, on which devices, and whether they must prove it is really them (for example with multi-factor authentication).

Why it matters and what's covered

Why it matters Passwords alone are not enough. Good sign-in rules stop many everyday account takeovers before damage is done.

If left off Your licenses include advanced sign-in rules, but they may still be loose or incomplete.

Microsoft control Conditional Access
License Microsoft 365 E5
Service plan Microsoft Entra ID P2
Incomplete

Deep protection and visibility on PCs and devices

What it does See attacks on laptops and servers in more detail, find weak software, and respond before a single infected PC becomes a company-wide problem.

Why it matters and what's covered

Why it matters Devices are where people work. If they are not enrolled in advanced protection, you are flying partly blind.

If left off You may be paying for advanced device protection on seats that are not fully enrolled.

Microsoft control Microsoft Defender for Endpoint P2
License Microsoft 365 E5
Service plan Microsoft Defender for Endpoint P2
Incomplete

Watchdogs on your on-site directory (if you still have one)

What it does Spot attackers moving through traditional office servers and Active Directory, not only cloud sign-ins.

Why it matters and what's covered

Why it matters Many organizations still rely on on-site domain controllers. Cloud-only tools cannot see every attack path there.

If left off Identity threat sensors may be missing or unhealthy, so on-site directory attacks stay invisible.

Microsoft control Microsoft Defender for Identity
License Microsoft 365 E5
Service plan No matching service plan reported
Incomplete

Safe Attachments and Safe Links essentials

What it does Detonate risky attachments and rewrite dangerous links for licensed users even when the full P2 investigation pack is not present.

Why it matters and what's covered

Why it matters Many tenants own P1-level email protections that never leave default off states.

If left off Safe content policies may be missing, scoped to pilots, or left in evaluation mode.

Microsoft control Microsoft Defender for Office 365 P1
License Microsoft 365 E5
Service plan No matching service plan reported
Incomplete

Stronger email and file threat protection

What it does Open risky attachments and links in a safe way, catch advanced phishing, and investigate email threats faster when something slips through.

Why it matters and what's covered

Why it matters Most business breaches still start with email. Better email protection reduces ransomware and invoice fraud.

If left off Extra email protections in your license may still be off, in test mode, or only covering a few people.

Microsoft control Microsoft Defender for Office 365 P2
License Microsoft 365 E5
Service plan Microsoft Defender for Office 365 (Plan 2)
Operational

Cross-product incident correlation

What it does Connect identity, email, endpoint, and cloud signals into incidents that show the full attack story instead of isolated alerts.

Why it matters and what's covered

Why it matters Attackers hop products. Siloed alerts hide the path from phishing to privilege.

If left off XDR correlation may be licensed while automated investigation and response stay idle.

Microsoft control Microsoft Defender XDR
License Microsoft 365 E5
Service plan Microsoft Defender for Endpoint P2, Microsoft Defender for Office 365 (Plan 2)
Action required

Stronger control over admin accounts

What it does Give people powerful admin rights only when they need them, and get better tools to catch risky sign-ins on high-value accounts.

Why it matters and what's covered

Why it matters Admin accounts are the keys to your email, files, and business apps. If one is stolen, an attacker can look like a trusted employee.

If left off You are paying for stronger admin protections that are not fully turned on yet.

Microsoft control Microsoft Entra ID P2
License Microsoft 365 E5
Service plan Microsoft Entra ID P2
Incomplete

Business email and calendar in the cloud

What it does Host mailboxes in Microsoft 365 and apply tenant email security and sharing controls that protect everyday business communication.

Why it matters and what's covered

Why it matters Email remains a primary business channel and a primary attack path. Weak tenant defaults leave phishing and data exposure wide open.

If left off Mailboxes may be licensed while core protection and audit settings stay at weak defaults.

Microsoft control Exchange Online
License Microsoft 365 E5
Service plan No matching service plan reported
Operational

Baseline spam and malware filtering for email

What it does Filter obvious junk and malware before it reaches inboxes, as the foundation under optional Defender for Office 365 controls.

Why it matters and what's covered

Why it matters Without baseline filtering, every advanced email control sits on a weak floor.

If left off Core anti-spam or anti-malware policies may be off, overly permissive, or unmonitored.

Microsoft control Exchange Online Protection
License Microsoft 365 E5
Service plan No matching service plan reported
Action required

Alerts when a sign-in looks suspicious

What it does Automatically spot odd sign-in behavior (impossible travel, leaked passwords, unfamiliar locations) and require extra proof or block access.

Why it matters and what's covered

Why it matters Attackers often use valid passwords. Risk detection helps catch the session even when the password was correct.

If left off Suspicious-sign-in protection is included in your plan but may not be enforcing anything yet.

Microsoft control Microsoft Entra ID Protection
License Microsoft 365 E5
Service plan Microsoft Entra ID P2
Action required

Manage and protect company devices and apps

What it does Require healthy devices, push secure settings, and protect work data on phones and PCs people already use.

Why it matters and what's covered

Why it matters Unmanaged devices are a common path around strong cloud identity controls.

If left off Compliance or configuration profiles may be missing, unassigned, or never enforced.

Microsoft control Microsoft Intune
License Microsoft 365 E5
Service plan No matching service plan reported
Action required

The log store behind security analytics

What it does Land security and operational logs in a workspace that detections and investigations can query.

Why it matters and what's covered

Why it matters Sentinel without healthy log ingestion is an empty command center.

If left off Workspaces may exist while critical tables are missing, short-retained, or never connected.

Microsoft control Azure Log Analytics
License Microsoft Sentinel
Service plan No matching service plan reported
Action required

A central security command center in the cloud

What it does Bring security signals together in one place, detect patterns humans miss, and automate parts of incident response.

Why it matters and what's covered

Why it matters Without a place that correlates events, teams drown in alerts from many products and miss the story that ties them together.

If left off A security workspace may exist, but few detections or smart analytics are turned on.

Microsoft control Microsoft Sentinel
License Microsoft Sentinel
Service plan Microsoft Sentinel
Operational

Personal work files in the cloud

What it does Give people a private work drive while still enforcing sharing limits, device access, and retention expectations.

Why it matters and what's covered

Why it matters Personal work drives often hold the same sensitive files as shared libraries.

If left off OneDrive sharing or sync controls may lag behind the SharePoint tenant baseline.

Microsoft control OneDrive for Business
License Microsoft 365 E5
Service plan No matching service plan reported
Operational

Shared interactive business reports

What it does Publish and share interactive reports with colleagues under tenant-level export, sharing, and guest boundaries.

Why it matters and what's covered

Why it matters BI content often contains concentrated business truth; loose sharing leaks strategy.

If left off Tenant sharing or export settings may still allow broader distribution than intended.

Microsoft control Power BI Pro
License Microsoft 365 E5
Service plan No matching service plan reported
Operational

Low-code apps, flows, and environments

What it does Let teams build useful apps and automations inside governed environments with DLP and tenant isolation boundaries.

Why it matters and what's covered

Why it matters Ungoverned makers can connect business data to personal connectors overnight.

If left off Environment creation, connector policies, or tenant isolation may still be wide open.

Microsoft control Microsoft Power Platform
License Microsoft 365 E5
Service plan No matching service plan reported
Incomplete

A searchable record of important activity

What it does Reconstruct who did what across mail, files, and admin actions when something goes wrong.

Why it matters and what's covered

Why it matters Without audit history, investigations stall and compliance questions go unanswered.

If left off Audit logging may be off, truncated, or never queried after an incident.

Microsoft control Microsoft Purview Audit
License Microsoft 365 E5
Service plan Microsoft 365 Advanced eDiscovery
Incomplete

Oversight for risky business communications

What it does Detect harassment, threats, or sensitive-data sharing patterns in business conversations.

Why it matters and what's covered

Why it matters Toxic or noncompliant communication creates legal and cultural risk that identity tools miss.

If left off Communication compliance may be entitled but never scoped to the channels that matter.

Microsoft control Microsoft Purview Communication Compliance
License Microsoft 365 E5
Service plan No matching service plan reported
Action required

Guardrails so sensitive data is harder to leak

What it does Warn or block people when they try to share credit cards, health data, or other sensitive information in the wrong place.

Why it matters and what's covered

Why it matters Accidental oversharing is common. Guardrails protect customers and reduce regulatory and reputational harm.

If left off Data-protection rules may be missing or still in "test only" mode, so nothing is enforced yet.

Microsoft control Microsoft Purview Data Loss Prevention
License Microsoft 365 E5
Service plan Microsoft Purview Information Protection P2
Operational

Legal hold and investigation search

What it does Preserve and search relevant content when legal or investigative work demands it.

Why it matters and what's covered

Why it matters Missing holds destroy evidence and create legal and regulatory exposure.

If left off eDiscovery tools may be licensed while no one can run a defensible case workflow.

Microsoft control Microsoft Purview eDiscovery
License Microsoft 365 E5
Service plan Microsoft 365 Advanced eDiscovery, Microsoft 365 Customer Lockbox
Operational

Early warning for risky insider activity

What it does Spot patterns that suggest data theft, leak, or policy abuse by people who already have access.

Why it matters and what's covered

Why it matters Trusted access is powerful. Without signals, insider incidents surface only after damage.

If left off Insider risk policies may be unlicensed in practice or never moved past trial defaults.

Microsoft control Microsoft Purview Insider Risk Management
License Microsoft 365 E5
Service plan No matching service plan reported
Operational

Retention rules that keep or remove content on schedule

What it does Keep content for legal or regulatory periods and remove it when it is no longer needed, reducing both evidence risk and storage cost.

Why it matters and what's covered

Why it matters Retention protects evidence and reduces over-retention risk and storage cost.

If left off Retention policies may be absent, so content is either deleted too early or kept indefinitely without a defensible schedule.

Microsoft control Microsoft Purview Data Lifecycle Management
License Microsoft 365 E5
Service plan No matching service plan reported
Action required

Labels that classify and protect files and mail

What it does Mark sensitive content and apply encryption or access limits that travel with the file.

Why it matters and what's covered

Why it matters Classification without enforcement is a sticker; labels with protection change outcomes.

If left off Labels may exist but remain unpublished, unused, or never auto-applied.

Microsoft control Microsoft Purview Sensitivity Labels
License Microsoft 365 E5
Service plan Microsoft Purview Information Protection P2
Incomplete

Team sites and shared file libraries

What it does Host shared libraries with clear external sharing boundaries and default link permissions that match how the business actually works.

Why it matters and what's covered

Why it matters Over-broad sharing turns one mistaken link into a public data leak.

If left off Tenant sharing defaults may still allow anyone links or unmanaged access.

Microsoft control SharePoint Online
License Microsoft 365 E5
Service plan No matching service plan reported
Action required

Chat, meetings, and teamwork hub

What it does Keep collaboration fast while controlling guests, anonymous join, apps, and recording exposure.

Why it matters and what's covered

Why it matters Teams is where decisions and files move quickly — weak meeting or guest defaults become an easy side door.

If left off External access, lobby, or app policies may still favor convenience over control.

Microsoft control Microsoft Teams
License Microsoft 365 E5
Service plan No matching service plan reported

Findings

Findings

Every assessed control, most critical first. Expand a row for what we expected, what we observed, and what to do next. Select several values in a group to match any of them; different groups combine. Filter by compliance mappings (Mapped / Unmapped) to isolate controls with NIST or MITRE references.

Findings at a glance
Findings by status

Horizontal bars showing how many findings carry each status, out of 166 findings.

Findings by status
StatusFindings
Action required40
Incomplete17
Operational91
Not licensed6
Not assessed12
Findings by workload

Horizontal bars showing where findings concentrate across workloads, out of 166 findings.

Findings by workload
WorkloadFindings
Azure2
Collaboration24
Defender27
Endpoint13
Exchange12
Identity52
Power BI10
Power Platform8
Purview13
Sentinel5
Findings by severity

Horizontal bars showing how bad the findings are, out of 166 findings.

Findings by severity
SeverityFindings
Critical1
High100
Info1
Low2
Medium62
Showing 166 of 166
Action required

Require strong sign-in for powerful admin roles

Severity: Critical Workload: Identity Compliance: MITRE: T1078; NIST: IA-2, IA-5 id-ca-phishing-resistant-privileged
Admin accounts may still sign in with weaker multi-factor methods.
Action required

Require strong sign-in for powerful admin roles

Severity: Critical Effort: ~a few hours Scope: Administrator scope Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: IA-2, IA-5

Admin accounts may still sign in with weaker multi-factor methods.

Expected

Privileged directory roles sign in with phishing-resistant MFA via Conditional Access.

Observed

No enforced phishing-resistant MFA policy covers highly privileged roles.

Why it matters

Passwords alone are not enough. Good sign-in rules stop many everyday account takeovers before damage is done.

Value impact: High
Recommended action

Enforce phishing-resistant MFA for Global Administrator and other highly privileged roles.

Evidence
Technical evidence

Data sources: microsoft.graph

  • label: Phishing-resistant MFA for privileged roles
  • enforced_policies: None reported
  • report_only_policies: None reported
  • unjustified_exclusion_issues: None reported
  • break_glass_principal_count: 0

Limitations: None reported

Admin destination

Open the admin page

Action required

Review apps with broad permissions for everyone

Severity: High Workload: Identity Compliance: MITRE: T1098; NIST: AC-2, IA-5 id-app-risky-delegated-consent
Some apps have broad mail, files, or directory permissions for everyone.
Action required

Stop users from approving risky app permissions

Severity: High Workload: Identity Compliance: MITRE: T1098; NIST: AC-2, IA-5 id-app-user-consent-restricted
Users can still approve app permissions themselves, which is a common path for consent phishing.
Action required

Turn off SMS, voice, and email one-time codes

Severity: High Workload: Identity Compliance: MITRE: T1078; NIST: IA-2, IA-5 id-auth-weak-methods-disabled
SMS, voice, or email one-time codes are still allowed — these are the easiest multi-factor methods for attackers to abuse.
Action required

Turn off SMS, voice, and email one-time codes

Severity: High Effort: ~a few hours Scope: All users Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: IA-2, IA-5

SMS, voice, or email one-time codes are still allowed — these are the easiest multi-factor methods for attackers to abuse.

Expected

SMS, voice call, and email one-time codes are disabled.

Observed

Weak authentication methods remain enabled: sms.

Why it matters

Passwords alone are not enough. Good sign-in rules stop many everyday account takeovers before damage is done.

Value impact: High
Recommended action

Disable SMS, Voice, and Email OTP authentication methods.

Evidence
Technical evidence

Data sources: microsoft.graph

  • enabled_weak_methods: sms
  • configuration_count: 3

Limitations: None reported

Admin destination

Open the admin page

Action required

No documented emergency admin account, or exclusions without a reason

Severity: High Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, AC-6 id-break-glass-exclusion
We could not confirm a dedicated emergency admin account. Without one, an outage or lockout can lock you out of your own tenant.
Action required

No documented emergency admin account, or exclusions without a reason

Severity: High Effort: ~a few hours Scope: Administrator scope Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, AC-6

We could not confirm a dedicated emergency admin account. Without one, an outage or lockout can lock you out of your own tenant.

Expected

A documented break-glass account exists with justified sign-in rule exclusions.

Observed

No break-glass account was identified among the Global Administrators; no principal is declared as break-glass in this report's configuration.

Why it matters

Admin accounts are the keys to your email, files, and business apps. If one is stolen, an attacker can look like a trusted employee.

Value impact: High
Recommended action

Create two cloud-only, Global Administrator emergency accounts excluded from Conditional Access, declare them as break-glass principals in your configured settings, and remove any other unexplained exclusions.

Evidence
Technical evidence

Data sources: microsoft.graph

  • global_admin_principal_count: 2
  • declared_break_glass_principal_count: 0
  • identified_break_glass_accounts: None reported
  • enabled_ca_policy_count: 3
  • report_only_ca_policy_count: 0
  • unjustified_exclusion_issues: None reported
  • unjustified_exclusion_count: 0
  • global_admin_exclusion_issues: None reported

Limitations: The break-glass account could not be confidently identified from the scanned Global Administrator assignments and eligibilities — verify the emergency access account in the Entra portal before relying on this check

Admin destination

Open the admin page

Action required

Block device-code phishing sign-ins

Severity: High Workload: Identity Compliance: MITRE: T1078; NIST: IA-2, IA-5 id-ca-device-code-block
Device-code phishing can still complete a successful sign-in.
Action required

Block device-code phishing sign-ins

Severity: High Effort: ~a few hours Scope: All users Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: IA-2, IA-5

Device-code phishing can still complete a successful sign-in.

Expected

Device-code sign-ins are blocked by an enforced Conditional Access policy.

Observed

No enforced Conditional Access policy blocks device code flow.

Why it matters

Passwords alone are not enough. Good sign-in rules stop many everyday account takeovers before damage is done.

Value impact: High
Recommended action

Enforce a Conditional Access policy that blocks device code flow.

Evidence
Technical evidence

Data sources: microsoft.graph

  • label: Device code flow block
  • enforced_policies: None reported
  • report_only_policies: None reported
  • unjustified_exclusion_issues: None reported
  • break_glass_principal_count: 0

Limitations: None reported

Admin destination

Open the admin page

Action required

Block suspicious high-risk sign-ins

Severity: High Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, IA-2 id-ca-high-risk-signins
Suspicious high-risk sign-ins may still succeed.
Action required

Block suspicious high-risk sign-ins

Severity: High Effort: ~a few hours Scope: All users Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, IA-2

Suspicious high-risk sign-ins may still succeed.

Expected

Sign-ins marked high risk by Identity Protection are blocked.

Observed

No enforced Conditional Access policy blocks high-risk sign-ins.

Why it matters

Attackers often use valid passwords. Risk detection helps catch the session even when the password was correct.

Value impact: High
Recommended action

Enforce a Conditional Access policy that blocks high sign-in risk.

Evidence
Technical evidence

Data sources: microsoft.graph

  • label: High-risk sign-in block
  • enforced_policies: None reported
  • report_only_policies: None reported
  • unjustified_exclusion_issues: None reported
  • break_glass_principal_count: 0

Limitations: None reported

Admin destination

Open the admin page

Action required

Block accounts Microsoft marks as high risk

Severity: High Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, IA-2 id-ca-high-risk-users
Compromised accounts marked high risk may still sign in successfully.
Action required

Block accounts Microsoft marks as high risk

Severity: High Effort: ~a few hours Scope: All users Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, IA-2

Compromised accounts marked high risk may still sign in successfully.

Expected

Accounts marked high user risk by Identity Protection are blocked.

Observed

No enforced Conditional Access policy blocks high-risk users.

Why it matters

Attackers often use valid passwords. Risk detection helps catch the session even when the password was correct.

Value impact: High
Recommended action

Enforce a Conditional Access policy that blocks high user risk for all users.

Evidence
Technical evidence

Data sources: microsoft.graph

  • label: High-risk user block
  • enforced_policies: None reported
  • report_only_policies: None reported
  • unjustified_exclusion_issues: None reported
  • break_glass_principal_count: 0

Limitations: None reported

Admin destination

Open the admin page

Action required

Block outdated sign-in methods

Severity: High Workload: Identity Compliance: MITRE: T1078; NIST: IA-2, IA-5 id-ca-legacy-auth-block
Outdated sign-in methods may still work without multi-factor checks.
Action required

Block outdated sign-in methods

Severity: High Effort: ~a few hours Scope: All users Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: IA-2, IA-5

Outdated sign-in methods may still work without multi-factor checks.

Expected

Legacy authentication clients are blocked tenant-wide.

Observed

No enforced Conditional Access policy blocks legacy authentication.

Why it matters

Passwords alone are not enough. Good sign-in rules stop many everyday account takeovers before damage is done.

Value impact: High
Recommended action

Create a Conditional Access policy that blocks legacy authentication for all users, with documented emergency-access exclusions only.

Evidence
Technical evidence

Data sources: microsoft.graph

  • label: Legacy authentication block
  • enforced_policies: None reported
  • report_only_policies: None reported
  • unjustified_exclusion_issues: None reported
  • break_glass_principal_count: 0

Limitations: None reported

Admin destination

Open the admin page

Action required

Require strong phishing-resistant sign-in for everyone

Severity: High Workload: Identity Compliance: MITRE: T1078; NIST: IA-2, IA-5 id-ca-phishing-resistant-all
Users can still sign in with weaker multi-factor methods that phishing can defeat.
Action required

Require strong phishing-resistant sign-in for everyone

Severity: High Effort: ~days Scope: All users Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: IA-2, IA-5

Users can still sign in with weaker multi-factor methods that phishing can defeat.

Expected

Every user signs in with phishing-resistant MFA enforced by Conditional Access.

Observed

No enforced all-user phishing-resistant MFA policy was found.

Why it matters

Passwords alone are not enough. Good sign-in rules stop many everyday account takeovers before damage is done.

Value impact: High
Recommended action

Enforce phishing-resistant authentication strength for all users where feasible.

Evidence
Technical evidence

Data sources: microsoft.graph

  • label: Phishing-resistant MFA for all users
  • enforced_policies: None reported
  • report_only_policies: None reported
  • unjustified_exclusion_issues: None reported
  • break_glass_principal_count: 0

Limitations: None reported

Admin destination

Open the admin page

Action required

Keep privileged-role activation short, explained, and context-bound

Severity: High Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, AC-6 id-pim-activation-controls
Some activation guardrails are missing, so an attacker with a stolen admin account can hold powerful access longer and with less traceability.
Action required

Keep privileged-role activation short, explained, and context-bound

Severity: High Effort: ~a few hours Scope: Administrator scope Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, AC-6

Some activation guardrails are missing, so an attacker with a stolen admin account can hold powerful access longer and with less traceability.

Expected

Privileged-role activation requires justification, an authentication context, and a short time limit.

Observed

PIM activation guardrails are incomplete: activation duration is not capped at 8 hours or less; activation does not require an authentication context; activation does not require justification.

Why it matters

Admin accounts are the keys to your email, files, and business apps. If one is stolen, an attacker can look like a trusted employee.

Value impact: High
Recommended action

In PIM role settings for each privileged role, require justification on activation, attach an authentication context, and set the maximum activation duration to a short window (8 hours or less).

Evidence
Technical evidence

Data sources: microsoft.graph

  • policy_count: 1
  • activation_rule_count: 1
  • activation_maximum_durations: None reported
  • activation_duration_capped: False
  • auth_context_required: False
  • auth_context_claim_value: None reported
  • justification_required: False

Limitations: None reported

Admin destination

Open the admin page

Action required

Alert when Global Admin is turned on

Severity: High Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, AC-6 id-pim-ga-activation-alert
Global Admin can be activated without a clear alert path.
Action required

Alert when Global Admin is turned on

Severity: High Effort: ~a few hours Scope: Administrator scope Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, AC-6

Global Admin can be activated without a clear alert path.

Expected

Security is alerted the moment Global Administrator is activated.

Observed

No notification rule found for Global Administrator activation.

Why it matters

Admin accounts are the keys to your email, files, and business apps. If one is stolen, an attacker can look like a trusted employee.

Value impact: High
Recommended action

Enable notifications for Global Administrator activation.

Evidence
Technical evidence

Data sources: microsoft.graph

  • ga_notification_rules: 0

Limitations: None reported

Admin destination

Open the admin page

Action required

Require approval to turn on Global Admin

Severity: High Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, AC-6 id-pim-ga-activation-approval
Someone eligible for Global Admin can turn it on without a second approver.
Action required

Require approval to turn on Global Admin

Severity: High Effort: ~a few hours Scope: Administrator scope Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, AC-6

Someone eligible for Global Admin can turn it on without a second approver.

Expected

A second approver signs off on every Global Administrator activation.

Observed

Global Administrator activation does not require approval.

Why it matters

Admin accounts are the keys to your email, files, and business apps. If one is stolen, an attacker can look like a trusted employee.

Value impact: High
Recommended action

Require approval on Global Administrator PIM activation.

Evidence
Technical evidence

Data sources: microsoft.graph

  • ga_rule_count: 1
  • approval_required_rules: 0

Limitations: None reported

Admin destination

Open the admin page

Action required

Provision admin access only through just-in-time tools

Severity: High Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, AC-6 id-pim-no-outside-pam
Powerful admin access is granted permanently without a just-in-time system.
Action required

Provision admin access only through just-in-time tools

Severity: High Effort: ~days Scope: Administrator scope Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, AC-6

Powerful admin access is granted permanently without a just-in-time system.

Expected

Privileged roles are granted only through PIM eligibility.

Observed

Highly privileged roles are assigned permanently with no PIM eligibility schedules — provisioning appears outside a PAM workflow.

Why it matters

Admin accounts are the keys to your email, files, and business apps. If one is stolen, an attacker can look like a trusted employee.

Value impact: High
Recommended action

Stop direct permanent privileged assignments and route access through PIM.

Evidence
Technical evidence

Data sources: microsoft.graph

  • standing_highly_privileged_assignments: 2
  • eligible_schedules: 0

Limitations: None reported

Admin destination

Open the admin page

Action required

Remove always-on powerful admin assignments

Severity: High Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, AC-6 id-pim-no-permanent-privileged
Some powerful admin roles are permanently on instead of just-in-time.
Action required

Remove always-on powerful admin assignments

Severity: High Effort: ~days Scope: Administrator scope Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, AC-6

Some powerful admin roles are permanently on instead of just-in-time.

Expected

No permanent active assignments remain for highly privileged roles.

Observed

Found 2 permanent highly privileged role assignment(s).

Why it matters

Admin accounts are the keys to your email, files, and business apps. If one is stolen, an attacker can look like a trusted employee.

Value impact: High
Recommended action

Convert highly privileged standing assignments to PIM-eligible where possible.

Evidence
Technical evidence

Data sources: microsoft.graph

  • standing_highly_privileged_assignments: 2
  • eligible_schedules: 0

Limitations: None reported

Admin destination

Open the admin page

Action required

Admin accounts still have "always on" superpowers

Severity: High Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, AC-6 id-pim-unused
Admin superpowers appear permanently on. Time-limited admin access (included in your stronger identity plan) does not look like it is being used.
Action required

Admin accounts still have "always on" superpowers

Severity: High Effort: ~days Scope: Administrator scope Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, AC-6

Admin superpowers appear permanently on. Time-limited admin access (included in your stronger identity plan) does not look like it is being used.

Expected

Privileged access is operationalized through PIM activation with MFA.

Observed

Found 4 standing privileged role assignment(s) and 0 PIM eligible schedules — just-in-time admin access is not in use.

Why it matters

Admin accounts are the keys to your email, files, and business apps. If one is stolen, an attacker can look like a trusted employee.

Value impact: High
Recommended action

Ask IT to turn on time-limited admin access for your top admins first (Global Administrator and similar roles).

Evidence
Technical evidence

Data sources: microsoft.graph

  • privileged_permanent_assignments: 4
  • privileged_eligible_schedules: 0
  • privileged_permanent_principals: 4
  • privileged_eligible_principals: 0
  • global_admin_standing_assignments: 2
  • break_glass_standing_assignments: 0
  • standing_non_break_glass_assignments: 4
  • uncovered_standing_roles: Security Administrator, Global Administrator, Helpdesk Administrator
  • sample_standing_roles: Global Administrator, Helpdesk Administrator, Security Administrator

Limitations: None reported

Admin destination

Open the admin page

Action required

Move from Security Defaults to customizable sign-in rules

Severity: High Workload: Identity Compliance: MITRE: T1078; NIST: IA-2, IA-5 id-security-defaults-on
Security Defaults already includes baseline MFA protection and blocks outdated sign-in methods. Your plan also includes smarter sign-in rules you can customize, but that paid capability remains unused.
Action required

Move from Security Defaults to customizable sign-in rules

Severity: High Effort: ~a few hours Scope: All users Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: IA-2, IA-5

Security Defaults already includes baseline MFA protection and blocks outdated sign-in methods. Your plan also includes smarter sign-in rules you can customize, but that paid capability remains unused.

Expected

Conditional Access policies replace Security Defaults for MFA and legacy-authentication blocking.

Observed

Security defaults are enabled, providing baseline MFA protections and blocking legacy authentication. Licensed Conditional Access customization remains unused.

Why it matters

Passwords alone are not enough. Good sign-in rules stop many everyday account takeovers before damage is done.

Value impact: High
Recommended action

Create equivalent Conditional Access policies for MFA and legacy-authentication blocking in report-only mode. Validate coverage, exclusions, emergency access, and sign-in impact; then perform a controlled cutover from Security Defaults to the validated policies.

Evidence
Technical evidence

Data sources: microsoft.graph

  • security_defaults_enabled: True
  • baseline_protections_active: True
  • policy_id: 00000000-0000-0000-0000-000000000005
  • conditional_access_customization_unused: True

Limitations: None reported

Admin destination

Open the admin page

Action required

Turn on auto-labeling for sensitive content

Severity: High Workload: Purview Compliance: — pur-sensitivity-auto-labeling
Content must be labeled by hand. Configure auto-labeling so sensitive content is classified consistently.
Action required

Turn on auto-labeling for sensitive content

Severity: High Effort: ~a few hours Scope: All users Workload: Purview Confidence: High confidence Evaluation: Read directly Compliance:

Content must be labeled by hand. Configure auto-labeling so sensitive content is classified consistently.

Expected

Sensitive content is classified automatically through auto-labeling policies.

Observed

No auto-labeling policy is configured.

Why it matters

Classification without enforcement is a sticker; labels with protection change outcomes.

Value impact: High
Recommended action

Configure auto-labeling policies or default labels so new and existing content is classified automatically, then monitor the results.

Evidence
Technical evidence

Data sources: Microsoft Purview / Security & Compliance PowerShell (powershell.bridge)

  • adapter: purview_governance
  • label_policies: 1
  • auto_labeling: False
  • absent: False

Limitations: None reported

Admin destination

Open the admin page

Incomplete

Some paid device-management seats may not be enrolled

Severity: High Workload: Endpoint Compliance: MITRE: T1059; NIST: CM-6, SI-2 endpoint-enrollment-coverage
Without an authoritative eligible-device inventory we cannot confirm how much of the intended device population is actually managed.
Incomplete

Some paid device-management seats may not be enrolled

Severity: High Effort: ~days Scope: All devices Workload: Endpoint Confidence: Low confidence — verify in portal Evaluation: Read directly Compliance: MITRE: T1059; NIST: CM-6, SI-2

Without an authoritative eligible-device inventory we cannot confirm how much of the intended device population is actually managed.

Expected

Licensed devices are enrolled in Intune management.

Observed

Observed 2 Intune-managed device(s) vs ~100 purchased seats. Without an authoritative eligible device inventory this is a licensing-leverage signal, not confirmed enrollment coverage.

Why it matters

Unmanaged devices are a common path around strong cloud identity controls.

Value impact: High
Recommended action

Compare Intune licenses to enrolled devices and enroll the missing ones through the device management tools you already use.

Evidence
Technical evidence

Data sources: graph.deviceManagement, graph.subscribedSkus (proxy licensing signal)

  • managed_device_count: 2
  • licensed_units: 100
  • truncated: False
  • proxy: True

Limitations: Enrollment is compared against purchased license seats, not an authoritative device inventory; license counts do not necessarily equal the device population, so this is a licensing-leverage signal, not proven device coverage. Verify eligible devices in the Microsoft Intune admin center; Based on Microsoft Secure Score signals — confirm the real setting in the Microsoft 365 / security admin portal before treating this as definitive

Admin destination

Open the admin page

Incomplete

Powerful accounts may sign in without strong extra checks

Severity: High Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, AC-6 id-ca-priv-gaps
Some sign-in protections are present, but the full set is not enforced yet (multi-factor authentication and/or blocking outdated sign-in methods).
Incomplete

Powerful accounts may sign in without strong extra checks

Severity: High Effort: ~a few hours Scope: All users Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, AC-6

Some sign-in protections are present, but the full set is not enforced yet (multi-factor authentication and/or blocking outdated sign-in methods).

Expected

Privileged sign-ins require phishing-resistant MFA with legacy auth blocked.

Observed

Conditional Access is partially configured: missing enforced legacy authentication block.

Why it matters

Passwords alone are not enough. Good sign-in rules stop many everyday account takeovers before damage is done.

Value impact: High
Recommended action

Require multi-factor authentication for admins and block legacy email sign-in methods that skip modern security prompts.

Evidence
Technical evidence

Data sources: microsoft.graph

  • policy_count: 3
  • enabled_count: 3
  • report_only_count: 0
  • mfa_enforced_policies: Demo: MFA for all users, Demo: Require MFA for sign-in risk
  • mfa_report_only_policies: None reported
  • legacy_block_enforced: None reported
  • legacy_block_report_only: None reported
  • unjustified_exclusion_issues: None reported
  • privileged_principal_count: 4
  • global_admin_standing_count: 2
  • mfa_covers_privileged: True
  • mfa_report_only_covers_privileged: False
  • exposure_flags: None reported

Limitations: None reported

Admin destination

Open the admin page

Incomplete

Some PCs may not be enrolled in advanced device protection

Severity: High Workload: Endpoint Compliance: — mde-onboard-gap
Without an authoritative eligible-device inventory we cannot confirm how much of the intended device population is actually protected.
Incomplete

Some PCs may not be enrolled in advanced device protection

Severity: High Effort: ~days Scope: All devices Workload: Endpoint Confidence: Low confidence — verify in portal Evaluation: Read directly Compliance:

Without an authoritative eligible-device inventory we cannot confirm how much of the intended device population is actually protected.

Expected

Licensed devices are onboarded to Defender for Endpoint with healthy sensors.

Observed

Observed 40 onboarded Defender for Endpoint machine(s) vs ~100 purchased seats (40% of seats). This is a licensing-leverage signal and is not treated as device coverage; an eligible device inventory is required to confirm coverage.

Why it matters

Devices are where people work. If they are not enrolled in advanced protection, you are flying partly blind.

Value impact: High
Recommended action

Compare licensed seats to enrolled devices and enroll the missing ones (often through your device management tools).

Evidence
Technical evidence

Data sources: mde.api.machines, graph.subscribedSkus (proxy licensing signal)

  • onboarded_machines: 40
  • sample_size: 40
  • count_method: demo
  • truncated: False
  • licensed_units: 100
  • proxy: True
  • coverage_ratio: 0.4

Limitations: Coverage is reported against purchased license seats, not an authoritative device inventory; license counts do not necessarily equal the device population, so this is a licensing-leverage signal, not proven device coverage. Verify actual eligible devices in the Defender portal; Based on Microsoft Secure Score signals — confirm the real setting in the Microsoft 365 / security admin portal before treating this as definitive

Admin destination

Open the admin page

Incomplete

Some device-protection sensors may be inactive or unhealthy

Severity: High Workload: Endpoint Compliance: MITRE: T1059; NIST: SI-3, SI-4 mde-sensor-health
A few device-protection sensors look unhealthy and may be missing alerts.
Incomplete

Some device-protection sensors may be inactive or unhealthy

Severity: High Effort: ~days Scope: All devices Workload: Endpoint Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1059; NIST: SI-3, SI-4

A few device-protection sensors look unhealthy and may be missing alerts.

Expected

Every onboarded device reports an active, healthy Defender sensor.

Observed

8 of 40 sampled Defender for Endpoint sensor(s) are inactive or unhealthy.

Why it matters

Devices are where people work. If they are not enrolled in advanced protection, you are flying partly blind.

Value impact: High
Recommended action

Review inactive and unhealthy sensors and remediate them (reinstall, connectivity, or policy) so every licensed device reports health.

Evidence
Technical evidence

Data sources: mde.api.machines.health

  • machines_sampled: 40
  • health_status_counts: {"Active": 32, "ImpairedCommunication": 5, "NoSensorData": 3}
  • active_healthy: 32
  • impaired_communication: 5
  • no_sensor_data: 3
  • truncated: False
  • count_method: demo
  • unhealthy_total: 8
  • healthy_ratio: 0.8

Limitations: None reported

Admin destination

Open the admin page

Incomplete

Apply DLP across Exchange SharePoint OneDrive Teams

Severity: High Workload: Purview Compliance: — pur-dlp-locations-complete
DLP is not applied across Exchange, OneDrive, SharePoint, and Teams. Broaden policy locations.
Incomplete

Apply DLP across Exchange SharePoint OneDrive Teams

Severity: High Effort: ~a few hours Scope: All users Workload: Purview Confidence: Medium confidence Evaluation: Read directly Compliance:

DLP is not applied across Exchange, OneDrive, SharePoint, and Teams. Broaden policy locations.

Expected

DLP policies cover Exchange, SharePoint, OneDrive, Teams, and devices.

Observed

DLP policies cover only 1 workload location(s).

Why it matters

Accidental oversharing is common. Guardrails protect customers and reduce regulatory and reputational harm.

Value impact: High
Recommended action

Enable DLP for Exchange, OneDrive, SharePoint, Teams, and devices where licensed.

Evidence
Technical evidence

Data sources: Not reported

  • workloads: devices, exchange,sharepoint,onedrive
  • covered_workloads: devices

Limitations: None reported

Admin destination

Open the admin page

Incomplete

Your security command center may have few alarms turned on

Severity: High Workload: Sentinel Compliance: — sen-analytics-rule-coverage
Some detection alarms are on, but the configured rule baseline is still light for a paid security command center.
Incomplete

Your security command center may have few alarms turned on

Severity: High Effort: ~a few hours Scope: All users Workload: Sentinel Confidence: Medium confidence Evaluation: Read directly Compliance:

Some detection alarms are on, but the configured rule baseline is still light for a paid security command center.

Expected

Sentinel runs enabled scheduled rules covering identity, endpoint, and cloud sources.

Observed

Thin Sentinel analytics-rule deployment: 2 enabled scheduled/NRT rule(s), 2 tactic(s) (total rules=3).

Why it matters

Without a place that correlates events, teams drown in alerts from many products and miss the story that ties them together.

Value impact: High
Recommended action

Enable a starter set of detection rules for sign-ins, email, and devices, then expand coverage with your IT or security partner.

Evidence
Technical evidence

Data sources: azure.arm.securityInsights

  • total_rules: 3
  • enabled_rules: 2
  • enabled_scheduled_or_nrt: 2
  • tactics: InitialAccess, Persistence
  • tactic_count: 2
  • sample_enabled_rules: Demo Sign-in spike, Demo Rare process
  • workspace_resource_id: /subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/demo-rg/providers/Microsoft.OperationalInsights/workspaces/demo-sentinel

Limitations: None reported

Admin destination

Open the admin page

Incomplete

Feed your security command center with real signals

Severity: High Workload: Sentinel Compliance: — sen-data-connectors
A few data sources are connected, but the main identity and Microsoft 365 signals may still be missing.
Incomplete

Feed your security command center with real signals

Severity: High Effort: ~a few hours Scope: All users Workload: Sentinel Confidence: Medium confidence Evaluation: Read directly Compliance:

A few data sources are connected, but the main identity and Microsoft 365 signals may still be missing.

Expected

High-value data sources stream into the Sentinel workspace.

Observed

Thin Sentinel data connectors: 1 connector(s), only 0 high-value source(s).

Why it matters

Without a place that correlates events, teams drown in alerts from many products and miss the story that ties them together.

Value impact: High
Recommended action

Connect the main data sources (Entra ID, Microsoft 365, and Defender) to the security workspace, then confirm logs start arriving.

Evidence
Technical evidence

Data sources: azure.arm.securityInsights

  • total_connectors: 1
  • connected_connectors: 1
  • connector_kinds: AzureActivity
  • key_connectors_connected: None reported
  • workspace_resource_id: /subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/demo-rg/providers/Microsoft.OperationalInsights/workspaces/demo-sentinel

Limitations: None reported

Admin destination

Open the admin page

Not assessed

Add your mailbox to DMARC reports

Severity: High Workload: Exchange Compliance: — exo-dmarc-agency-contact
Add the contact to your configured settings so this DMARC field can be checked.
Not assessed

Add your mailbox to DMARC reports

Severity: High (potential impact — not yet assessed) Effort: ~a few hours Scope: All users Workload: Exchange Compliance:

Add the contact to your configured settings so this DMARC field can be checked.

Expected

DMARC records include the agency's internal report contact.

Why this was skipped

No agency contact configured in your settings, so this DMARC field was not checked.

Why it matters

Email remains a primary business channel and a primary attack path. Weak tenant defaults leave phishing and data exposure wide open.

Value impact: High
Recommended action

Add an internal mailbox to DMARC report recipients (rua/ruf addresses) using the contact from your configured settings.

Evidence
Technical evidence

Data sources: Not reported

  • configured: False
  • field: agency

Limitations: None reported

Admin destination

Open the admin page

Not assessed

Add the federal DMARC report mailbox when required

Severity: High Workload: Exchange Compliance: — exo-dmarc-federal-contact
Add the contact to your configured settings so this DMARC field can be checked.
Not assessed

Add the federal DMARC report mailbox when required

Severity: High (potential impact — not yet assessed) Effort: ~a few hours Scope: All users Workload: Exchange Compliance:

Add the contact to your configured settings so this DMARC field can be checked.

Expected

DMARC records include the required federal report contact.

Why this was skipped

No federal contact configured in your settings, so this DMARC field was not checked.

Why it matters

Email remains a primary business channel and a primary attack path. Weak tenant defaults leave phishing and data exposure wide open.

Value impact: High
Recommended action

When your configured settings include a federal contact, add it to every DMARC aggregate-report (rua) field.

Evidence
Technical evidence

Data sources: Not reported

  • configured: False
  • field: federal

Limitations: None reported

Admin destination

Open the admin page

Not assessed

Confirm identity logs reach your security team

Severity: High Workload: Identity Compliance: MITRE: T1078; NIST: AU-6, AU-12 id-logs-to-soc
Confirm Entra sign-in and audit logs reach your security monitoring platform.
Not assessed

Confirm identity logs reach your security team

Severity: High (potential impact — not yet assessed) Effort: ~days Scope: All users Workload: Identity Compliance: MITRE: T1078; NIST: AU-6, AU-12

Confirm Entra sign-in and audit logs reach your security monitoring platform.

Expected

Entra sign-in and audit logs flow to the SOC pipeline.

Why this was skipped

Centralized Entra sign-in/audit log shipping to a SOC is environment-specific and requires manual or SIEM-side verification.

Why it matters

Identity attacks hide in sign-in patterns; without logs flowing to your security team, the evidence never reaches the people who can act.

Value impact: High
Recommended action

Confirm Entra sign-in and audit logs are exported to your SOC or SIEM.

Evidence
Technical evidence

Data sources: microsoft.graph

  • manual: True
  • evaluation_mode: manual

Limitations: Manual verification required with your SOC / SIEM team

Admin destination

Open the admin page

Not assessed

Confirm suspicious-email alerts are enabled

Severity: High Workload: Defender Compliance: — mdo-alert-policies-enabled
Confirm required suspicious-email and connector alerts are enabled.
Not assessed

Confirm suspicious-email alerts are enabled

Severity: High (potential impact — not yet assessed) Effort: ~a few hours Scope: All users Workload: Defender Compliance:

Confirm required suspicious-email and connector alerts are enabled.

Expected

Required Defender alert policies are enabled for suspicious email activity.

Why this was skipped

Defender alert policies are portal-configured and not fully automated here.

Why it matters

Many tenants own P1-level email protections that never leave default off states.

Value impact: High
Recommended action

Enable the required suspicious email and connector alert policies in Defender.

Evidence
Technical evidence

Data sources: Not reported

  • manual: True
  • evaluation_mode: manual

Limitations: Manual verification required in Microsoft 365 Defender alert policies

Admin destination

Open the admin page

Not assessed

Confirm audit logs are retained long enough

Severity: High Workload: Defender Compliance: — mdo-audit-retention
Confirm audit logs stay searchable 3 months and retrievable 12 months.
Not assessed

Confirm audit logs are retained long enough

Severity: High (potential impact — not yet assessed) Effort: ~a few hours Scope: All users Workload: Defender Compliance:

Confirm audit logs stay searchable 3 months and retrievable 12 months.

Expected

Audit logs stay searchable for at least 3 months and retrievable for 12.

Why this was skipped

Unified audit retention depends on license tier and is not fully automated.

Why it matters

Without audit history, investigations stall and compliance questions go unanswered.

Value impact: High
Recommended action

Confirm at least 3 months searchable and 12 months retrievable audit retention.

Evidence
Technical evidence

Data sources: Not reported

  • manual: True
  • evaluation_mode: manual

Limitations: Manual verification required for audit log retention

Admin destination

Open the admin page

Not assessed

Protect key partner domains from look-alikes

Severity: High Workload: Defender Compliance: — mdo-impersonation-partner-domains
List your key partner domains in your configured settings to check their impersonation protection.
Not assessed

Protect key partner domains from look-alikes

Severity: High (potential impact — not yet assessed) Effort: ~a few hours Scope: All users Workload: Defender Compliance:

List your key partner domains in your configured settings to check their impersonation protection.

Expected

Impersonation protection covers profile-listed partner domains.

Why this was skipped

Partner-domain impersonation requires a configured list of partner domains.

Why it matters

Most business breaches still start with email. Better email protection reduces ransomware and invoice fraud.

Value impact: High
Recommended action

Enable targeted domain protection for profile-listed partner domains.

Evidence
Technical evidence

Data sources: Not reported

  • partner_domains: None reported

Limitations: None reported

Admin destination

Open the admin page

Not assessed

Protect sensitive accounts from look-alike senders

Severity: High Workload: Defender Compliance: — mdo-impersonation-users-protected
List your high-value accounts (executives, admins) in your configured settings to check user impersonation protection.
Not assessed

Protect sensitive accounts from look-alike senders

Severity: High (potential impact — not yet assessed) Effort: ~a few hours Scope: All users Workload: Defender Compliance:

List your high-value accounts (executives, admins) in your configured settings to check user impersonation protection.

Expected

User impersonation protection covers profile-listed sensitive accounts.

Why this was skipped

Sensitive user impersonation requires a configured list of sensitive accounts.

Why it matters

Most business breaches still start with email. Better email protection reduces ransomware and invoice fraud.

Value impact: High
Recommended action

Enable user impersonation protection for profile-listed sensitive accounts.

Evidence
Technical evidence

Data sources: Not reported

  • sensitive_users: None reported

Limitations: None reported

Admin destination

Open the admin page

Not assessed

Make anyone links expire within 30 days

Severity: High Workload: Collaboration Compliance: — spo-anyone-link-expiration
Anyone links are disabled, so link expiration is not required.
Not assessed

Make anyone links view-only

Severity: High Workload: Collaboration Compliance: — spo-anyone-link-view
Anyone links are disabled, so link permissions are not required.
Operational

Device compliance rules may be missing or not assigned

Severity: High Workload: Endpoint Compliance: MITRE: T1059; NIST: CM-6, SI-2 endpoint-compliance-policy-assigned
Device compliance policies are defined and assigned.
Operational

Device compliance rules may be missing or not assigned

Severity: High Effort: ~a few hours Scope: All devices Workload: Endpoint Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1059; NIST: CM-6, SI-2

Device compliance policies are defined and assigned.

Expected

Compliance policies exist and are assigned to all managed platforms.

Observed

2 compliance policy(ies) assigned and covering managed platforms.

Why it matters

Unmanaged devices are a common path around strong cloud identity controls.

Value impact: High
Recommended action

Confirm compliance policies exist and are assigned to the right user or device groups, and that every managed device platform is covered.

Evidence
Technical evidence

Data sources: graph.deviceManagement

  • compliance_policy_count: 2
  • assigned_count: 2
  • uncovered_platforms: None reported

Limitations: None reported

Admin destination

Open the admin page

Operational

Devices may not be flowing into advanced protection

Severity: High Workload: Endpoint Compliance: MITRE: T1059; NIST: SI-3, SI-4 endpoint-mde-connector
Devices are flowing from Intune into Defender for Endpoint.
Operational

Devices may not be flowing into advanced protection

Severity: High Effort: ~a few hours Scope: All devices Workload: Endpoint Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1059; NIST: SI-3, SI-4

Devices are flowing from Intune into Defender for Endpoint.

Expected

The Intune to Defender for Endpoint connector is active with healthy devices.

Observed

Intune-MDE connector is active (2 device(s) onboarded).

Why it matters

Unmanaged devices are a common path around strong cloud identity controls.

Value impact: High
Recommended action

Enable the Intune to Defender for Endpoint connector and confirm devices appear onboarded.

Evidence
Technical evidence

Data sources: graph.deviceManagement

  • onboarded_device_count: 2
  • unknown_device_count: 0
  • unhealthy_device_count: 0

Limitations: None reported

Admin destination

Open the admin page

Operational

Core endpoint protections may be partially configured

Severity: High Workload: Endpoint Compliance: MITRE: T1059; NIST: CM-6, SI-3 endpoint-security-policy-coverage
Core endpoint protections are configured for managed devices.
Operational

Core endpoint protections may be partially configured

Severity: High Effort: ~a few hours Scope: All devices Workload: Endpoint Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1059; NIST: CM-6, SI-3

Core endpoint protections are configured for managed devices.

Expected

Antivirus, firewall, disk-encryption, and ASR policies cover managed devices.

Observed

Antivirus, firewall, disk-encryption, and ASR policies are all configured.

Why it matters

Unmanaged devices are a common path around strong cloud identity controls.

Value impact: High
Recommended action

Confirm endpoint-security policies exist for antivirus, firewall, disk encryption, and attack surface reduction, and that they are assigned.

Evidence
Technical evidence

Data sources: graph.deviceManagement

  • expected_families: antivirus, attack surface reduction, disk encryption, firewall
  • covered_families: antivirus, firewall, disk encryption, attack surface reduction
  • coverage_ratio: 1.0

Limitations: None reported

Admin destination

Open the admin page

Operational

Attack surface reduction rules may not be enforced on devices

Severity: High Workload: Endpoint Compliance: MITRE: T1059, T1204; NIST: SI-3, CM-6 ep-asr-rules
Attack surface reduction rules are configured and enforced.
Operational

Attack surface reduction rules may not be enforced on devices

Severity: High Effort: ~a few hours Scope: All devices Workload: Endpoint Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1059, T1204; NIST: SI-3, CM-6

Attack surface reduction rules are configured and enforced.

Expected

Attack surface reduction rules are configured and assigned to managed Windows devices.

Observed

1 ASR policy(ies) assigned with 3 rule(s) configured.

Why it matters

Devices are where people work. If they are not enrolled in advanced protection, you are flying partly blind.

Value impact: High
Recommended action

Confirm an ASR endpoint-security policy is assigned and that it actually carries attack surface reduction rules, then watch rule reports for hits.

Evidence
Technical evidence

Data sources: graph.deviceManagement

  • asr_policy_count: 1
  • assigned_count: 1
  • rules_total: 3

Limitations: None reported

Admin destination

Open the admin page

Operational

Device disks may not be encrypted

Severity: High Workload: Endpoint Compliance: MITRE: T1486, T1040; NIST: SC-28, CM-6 ep-bitlocker-policy
A drive-encryption policy is configured and assigned.
Operational

Device disks may not be encrypted

Severity: High Effort: ~a few hours Scope: All devices Workload: Endpoint Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1486, T1040; NIST: SC-28, CM-6

A drive-encryption policy is configured and assigned.

Expected

A BitLocker or disk-encryption policy is configured and assigned to managed Windows devices.

Observed

1 encryption configuration(s) assigned to devices.

Why it matters

Unmanaged devices are a common path around strong cloud identity controls.

Value impact: High
Recommended action

Confirm a BitLocker/disk-encryption configuration exists and is assigned to the devices that carry sensitive data.

Evidence
Technical evidence

Data sources: graph.deviceManagement

  • bitlocker_config_count: 1
  • assigned_count: 1

Limitations: None reported

Admin destination

Open the admin page

Operational

Devices may be out of compliance despite policies

Severity: High Workload: Endpoint Compliance: MITRE: T1059; NIST: CM-6, SI-2 ep-compliance-enforcement
Devices are actually compliant, so the compliance gate is enforced.
Operational

Devices may be out of compliance despite policies

Severity: High Effort: ~days Scope: All devices Workload: Endpoint Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1059; NIST: CM-6, SI-2

Devices are actually compliant, so the compliance gate is enforced.

Expected

Managed devices are actually compliant, with zero noncompliant devices reported.

Observed

90 device(s) are compliant with zero noncompliant devices.

Why it matters

Unmanaged devices are a common path around strong cloud identity controls.

Value impact: High
Recommended action

Review noncompliant or unknown devices in the compliance dashboard and remediate them, or tighten the policy so unhealthy devices are caught.

Evidence
Technical evidence

Data sources: graph.deviceManagement

  • compliance_policy_count: 2
  • managed_devices_total: 90
  • compliant_devices: 90
  • noncompliant_devices: 0
  • unknown_devices: 0
  • error_devices: 0
  • conflict_devices: 0
  • in_grace_period_devices: 0

Limitations: None reported

Admin destination

Open the admin page

Operational

Work data on phones may be unprotected

Severity: High Workload: Endpoint Compliance: MITRE: T1040, T1486; NIST: SC-28, AC-3 ep-mam-app-protection
App protection policies are configured and assigned.
Operational

Work data on phones may be unprotected

Severity: High Effort: ~a few hours Scope: All devices Workload: Endpoint Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1040, T1486; NIST: SC-28, AC-3

App protection policies are configured and assigned.

Expected

App protection policies exist and are assigned to protect managed app data.

Observed

2 app-protection policy(ies) assigned or org-wide.

Why it matters

Unmanaged devices are a common path around strong cloud identity controls.

Value impact: High
Recommended action

Confirm app protection policies exist and are assigned to the intended users or groups for every mobile platform in use.

Evidence
Technical evidence

Data sources: graph.deviceManagement

  • app_protection_policy_count: 2
  • assigned_count: 2
  • org_wide_count: 0

Limitations: None reported

Admin destination

Open the admin page

Operational

Tamper protection may be off on some devices

Severity: High Workload: Endpoint Compliance: MITRE: T1562; NIST: SI-3, SI-7 ep-tamper-protection
Defender tamper protection is configured and enforced.
Operational

Tamper protection may be off on some devices

Severity: High Effort: ~half a day Scope: All devices Workload: Endpoint Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1562; NIST: SI-3, SI-7

Defender tamper protection is configured and enforced.

Expected

Tamper protection is configured, assigned, and enabled on managed Windows devices.

Observed

Tamper protection is assigned and enabled on sampled devices.

Why it matters

Devices are where people work. If they are not enrolled in advanced protection, you are flying partly blind.

Value impact: High
Recommended action

Assign the Defender antivirus/tamper-protection configuration and confirm sampled Windows devices report tamper protection enabled.

Evidence
Technical evidence

Data sources: graph.deviceManagement

  • defender_atp_config_count: 1
  • assigned_count: 1
  • sampled_devices: 2
  • tamper_enabled_devices: 2
  • tamper_disabled_devices: 0
  • tamper_unknown_devices: 0

Limitations: None reported

Admin destination

Open the admin page

Operational

Turn on DKIM signing for every domain

Severity: High Workload: Exchange Compliance: — exo-dkim-enabled
Your domains sign outgoing mail with DKIM.
Operational

Turn on DKIM signing for every domain

Severity: High Effort: ~a few hours Scope: All users Workload: Exchange Confidence: High confidence Evaluation: Read directly Compliance:

Your domains sign outgoing mail with DKIM.

Expected

Every accepted domain publishes DKIM signing.

Observed

DKIM signing is enabled for all returned domains.

Why it matters

Email remains a primary business channel and a primary attack path. Weak tenant defaults leave phishing and data exposure wide open.

Value impact: High
Recommended action

Enable DKIM signing for each accepted domain in Defender.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • dkim_configs: 1
  • disabled_domains: None reported

Limitations: None reported

Admin destination

Open the admin page

Operational

Publish a DMARC record for every domain

Severity: High Workload: Exchange Compliance: — exo-dmarc-published
Your domains publish DMARC records.
Operational

Publish a DMARC record for every domain

Severity: High Effort: ~a few hours Scope: All users Workload: Exchange Confidence: High confidence Evaluation: Read directly Compliance:

Your domains publish DMARC records.

Expected

Every domain publishes a DMARC record at _dmarc.

Observed

Every assessed domain publishes a DMARC record.

Why it matters

Email remains a primary business channel and a primary attack path. Weak tenant defaults leave phishing and data exposure wide open.

Value impact: High
Recommended action

Publish a DMARC TXT record at _dmarc for each second-level domain.

Evidence
Technical evidence

Data sources: DNS TXT resolution (system resolver)

  • domains_checked: contoso.com
  • dmarc_missing: None reported

Limitations: None reported

Admin destination

Open the admin page

Operational

Set DMARC policy to reject

Severity: High Workload: Exchange Compliance: — exo-dmarc-reject
Your domains reject mail that fails authentication.
Operational

Set DMARC policy to reject

Severity: High Effort: ~a few hours Scope: All users Workload: Exchange Confidence: High confidence Evaluation: Read directly Compliance:

Your domains reject mail that fails authentication.

Expected

Every domain's DMARC policy is set to reject.

Observed

Every assessed domain publishes DMARC with a reject policy.

Why it matters

Email remains a primary business channel and a primary attack path. Weak tenant defaults leave phishing and data exposure wide open.

Value impact: High
Recommended action

Set p=reject on every domain DMARC record.

Evidence
Technical evidence

Data sources: DNS TXT resolution (system resolver)

  • domains_checked: contoso.com
  • dmarc_not_reject: None reported

Limitations: None reported

Admin destination

Open the admin page

Operational

Flag mail that comes from outside

Severity: High Workload: Exchange Compliance: — exo-external-sender-warnings
Users see a clear flag when mail comes from outside your organization.
Operational

Flag mail that comes from outside

Severity: High Effort: ~a few hours Scope: All users Workload: Exchange Confidence: High confidence Evaluation: Read directly Compliance:

Users see a clear flag when mail comes from outside your organization.

Expected

External mail carries a clear sender warning for users.

Observed

External sender warnings are enabled (mail tips and/or transport rule).

Why it matters

Email remains a primary business channel and a primary attack path. Weak tenant defaults leave phishing and data exposure wide open.

Value impact: High
Recommended action

Enable external sender mail tips or an [External] transport rule.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • mail_tips_external_tips: True
  • external_sender_rule: True

Limitations: None reported

Admin destination

Open the admin page

Operational

Stop automatic email forwarding to outside domains

Severity: High Workload: Exchange Compliance: — exo-forwarding-external-disabled
External mail forwarding is locked down.
Operational

Stop automatic email forwarding to outside domains

Severity: High Effort: ~a few hours Scope: All users Workload: Exchange Confidence: High confidence Evaluation: Read directly Compliance:

External mail forwarding is locked down.

Expected

Automatic forwarding to external domains is blocked except approved partners.

Observed

Automatic forwarding to external domains is disabled.

Why it matters

Email remains a primary business channel and a primary attack path. Weak tenant defaults leave phishing and data exposure wide open.

Value impact: High
Recommended action

Disable automatic forwarding on remote domains except approved partners.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • forwarding_domains: None reported
  • allowed_forwarding_domains: None reported
  • unapproved_forwarding: None reported

Limitations: None reported

Admin destination

Open the admin page

Operational

Keep mailbox auditing turned on

Severity: High Workload: Exchange Compliance: — exo-mailbox-audit-enabled
Mailbox access is being recorded for later investigation.
Operational

Keep mailbox auditing turned on

Severity: High Effort: ~a few hours Scope: All users Workload: Exchange Confidence: High confidence Evaluation: Read directly Compliance:

Mailbox access is being recorded for later investigation.

Expected

Mailbox auditing is enabled organization-wide.

Observed

Mailbox auditing is enabled for the organization.

Why it matters

Email remains a primary business channel and a primary attack path. Weak tenant defaults leave phishing and data exposure wide open.

Value impact: High
Recommended action

Ensure organization mailbox auditing is enabled (AuditDisabled false).

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • audit_disabled: False

Limitations: None reported

Admin destination

Open the admin page

Operational

Limit calendar sharing to approved domains

Severity: High Workload: Exchange Compliance: — exo-sharing-calendar-not-all-domains
Calendar sharing is limited to approved domains.
Operational

Limit calendar sharing to approved domains

Severity: High Effort: ~a few hours Scope: All users Workload: Exchange Confidence: High confidence Evaluation: Read directly Compliance:

Calendar sharing is limited to approved domains.

Expected

Calendar sharing policies exclude the all-domains scope.

Observed

Calendar sharing is not shared with all domains.

Why it matters

Email remains a primary business channel and a primary attack path. Weak tenant defaults leave phishing and data exposure wide open.

Value impact: High
Recommended action

Remove sharing-with-all-domains from calendar sharing policies.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • shares_with_all_domains: False
  • kind: Calendar

Limitations: Calendar free/busy vs full-detail sharing granularity is not distinguished

Admin destination

Open the admin page

Operational

Limit contact sharing to approved domains

Severity: High Workload: Exchange Compliance: — exo-sharing-contact-not-all-domains
Contact folder sharing is limited to approved domains.
Operational

Limit contact sharing to approved domains

Severity: High Effort: ~a few hours Scope: All users Workload: Exchange Confidence: High confidence Evaluation: Read directly Compliance:

Contact folder sharing is limited to approved domains.

Expected

Contact sharing policies exclude the all-domains scope.

Observed

Contact folder sharing is not shared with all domains.

Why it matters

Email remains a primary business channel and a primary attack path. Weak tenant defaults leave phishing and data exposure wide open.

Value impact: High
Recommended action

Remove sharing-with-all-domains from contact sharing policies.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • shares_with_all_domains: False
  • kind: Contact folder

Limitations: None reported

Admin destination

Open the admin page

Operational

Turn off SMTP AUTH for the organization

Severity: High Workload: Exchange Compliance: — exo-smtp-auth-disabled
Legacy basic-auth email submission is turned off.
Operational

Turn off SMTP AUTH for the organization

Severity: High Effort: ~a few hours Scope: All users Workload: Exchange Confidence: High confidence Evaluation: Read directly Compliance:

Legacy basic-auth email submission is turned off.

Expected

The organization keeps SMTP AUTH disabled for every Exchange Online mailbox.

Observed

SMTP AUTH is disabled at the organization level.

Why it matters

Email remains a primary business channel and a primary attack path. Weak tenant defaults leave phishing and data exposure wide open.

Value impact: High
Recommended action

Disable SMTP AUTH at the organization level unless a legacy app truly needs it.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • smtp_client_authentication_disabled: True

Limitations: None reported

Admin destination

Open the admin page

Operational

Publish a strict SPF record for every domain

Severity: High Workload: Exchange Compliance: — exo-spf-published
Your domains publish strict SPF records.
Operational

Publish a strict SPF record for every domain

Severity: High Effort: ~a few hours Scope: All users Workload: Exchange Confidence: High confidence Evaluation: Read directly Compliance:

Your domains publish strict SPF records.

Expected

Every domain publishes an SPF record that fails unapproved senders.

Observed

Every assessed domain publishes an SPF record that fails unapproved senders.

Why it matters

Email remains a primary business channel and a primary attack path. Weak tenant defaults leave phishing and data exposure wide open.

Value impact: High
Recommended action

Publish SPF TXT records that end in -all or ~all for each custom domain.

Evidence
Technical evidence

Data sources: DNS TXT resolution (system resolver)

  • domains_checked: contoso.com
  • spf_missing: None reported

Limitations: None reported

Admin destination

Open the admin page

Operational

Require multi-factor authentication for everyone

Severity: High Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, IA-2 id-ca-mfa-all-users
Everyone must use multi-factor authentication when signing in.
Operational

Require multi-factor authentication for everyone

Severity: High Effort: ~a few hours Scope: All users Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, IA-2

Everyone must use multi-factor authentication when signing in.

Expected

Every user signs in with MFA enforced by Conditional Access.

Observed

Enforced Conditional Access requires MFA for all users.

Why it matters

Passwords alone are not enough. Good sign-in rules stop many everyday account takeovers before damage is done.

Value impact: High
Recommended action

Enforce a Conditional Access policy requiring multi-factor authentication for all users.

Evidence
Technical evidence

Data sources: microsoft.graph

  • label: MFA for all users
  • enforced_policies: Demo: MFA for all users, Demo: Require MFA for sign-in risk
  • report_only_policies: None reported
  • unjustified_exclusion_issues: None reported
  • break_glass_principal_count: 0

Limitations: None reported

Admin destination

Open the admin page

Operational

Keep Global Admin count between two and eight

Severity: High Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, AC-6 id-ga-count-bounds
You have enough Global Admins for break-glass coverage without too many.
Operational

Keep Global Admin count between two and eight

Severity: High Effort: ~a few hours Scope: Administrator scope Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, AC-6

You have enough Global Admins for break-glass coverage without too many.

Expected

Between two and eight Global Administrator principals exist in the tenant.

Observed

Global Administrator principal count is within bounds (2).

Why it matters

Admin accounts are the keys to your email, files, and business apps. If one is stolen, an attacker can look like a trusted employee.

Value impact: High
Recommended action

Reduce or increase Global Administrator principals to land between 2 and 8.

Evidence
Technical evidence

Data sources: microsoft.graph

  • global_admin_principal_count: 2
  • global_admin_assignment_count: 2
  • min_recommended: 2
  • max_recommended: 8

Limitations: None reported

Admin destination

Open the admin page

Operational

Risk-based sign-in protection

Severity: High Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, IA-2 id-idprotect-off
Suspicious sign-ins and risky accounts appear to trigger automatic extra checks or blocks.
Operational

Risk-based sign-in protection

Severity: High Effort: ~a few hours Scope: All users Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, IA-2

Suspicious sign-ins and risky accounts appear to trigger automatic extra checks or blocks.

Expected

Identity Protection user-risk and sign-in-risk policies are enforced.

Observed

Enforced Conditional Access policies address both sign-in risk and user risk (Identity Protection outcomes).

Why it matters

Attackers often use valid passwords. Risk detection helps catch the session even when the password was correct.

Value impact: High
Recommended action

Turn on risk-based sign-in protection in stages — start by requiring extra verification when Microsoft marks a sign-in as risky.

Evidence
Technical evidence

Data sources: microsoft.graph

  • risk_policy_count: 2
  • sign_in_risk_enforced: Demo: Require MFA for sign-in risk
  • user_risk_enforced: Demo: Require password change for user risk
  • sign_in_risk_report_only: None reported
  • user_risk_report_only: None reported

Limitations: None reported

Admin destination

Open the admin page

Operational

Keep powerful admin accounts cloud-only

Severity: High Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, AC-6 id-priv-cloud-only
Powerful admin accounts look separate from on-premises directories.
Operational

Keep powerful admin accounts cloud-only

Severity: High Effort: ~days Scope: Administrator scope Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, AC-6

Powerful admin accounts look separate from on-premises directories.

Expected

Privileged accounts are cloud-only and separate from on-premises directories.

Observed

Privileged principals appear cloud-only (not on-premises synced).

Why it matters

Admin accounts are the keys to your email, files, and business apps. If one is stolen, an attacker can look like a trusted employee.

Value impact: High
Recommended action

Use separate cloud-only accounts for highly privileged roles.

Evidence
Technical evidence

Data sources: microsoft.graph

  • privileged_principals_checked: 4
  • cloud_only: 4
  • hybrid_or_synced: 0
  • unknown: 0
  • hybrid_sample: None reported

Limitations: None reported

Admin destination

Open the admin page

Operational

Remove broad anti-spam allow lists

Severity: High Workload: Defender Compliance: — mdo-anti-spam-no-allowed-domains
No broad anti-spam allow lists are configured.
Operational

Remove broad anti-spam allow lists

Severity: High Effort: ~a few hours Scope: All users Workload: Defender Confidence: High confidence Evaluation: Read directly Compliance:

No broad anti-spam allow lists are configured.

Expected

Anti-spam policies keep allowed sender and domain lists empty.

Observed

Anti-spam policies do not include allowed senders or domains.

Why it matters

Without baseline filtering, every advanced email control sits on a weak floor.

Value impact: High
Recommended action

Clear AllowedSenders and AllowedSenderDomains from anti-spam policies.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • allowed_entries: None reported

Limitations: None reported

Admin destination

Open the admin page

Operational

Clear the connection filter IP allow list

Severity: High Workload: Defender Compliance: — mdo-connection-filter-no-ip-allow
No IP allow list bypasses email filtering.
Operational

Clear the connection filter IP allow list

Severity: High Effort: ~a few hours Scope: All users Workload: Defender Confidence: High confidence Evaluation: Read directly Compliance:

No IP allow list bypasses email filtering.

Expected

Connection filter policies keep the IP allow list empty.

Observed

Connection filter IP allow list is empty.

Why it matters

Without baseline filtering, every advanced email control sits on a weak floor.

Value impact: High
Recommended action

Remove entries from the connection filter IP allow list.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • ip_allow_list: None reported

Limitations: None reported

Admin destination

Open the admin page

Operational

Turn off the connection filter safe list

Severity: High Workload: Defender Compliance: — mdo-connection-filter-no-safe-list
Safe-list bypass is turned off.
Operational

Turn off the connection filter safe list

Severity: High Effort: ~a few hours Scope: All users Workload: Defender Confidence: High confidence Evaluation: Read directly Compliance:

Safe-list bypass is turned off.

Expected

Connection filter policies disable the safe list.

Observed

Connection filter safe list is disabled.

Why it matters

Without baseline filtering, every advanced email control sits on a weak floor.

Value impact: High
Recommended action

Disable EnableSafeList on connection filter policies.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • enable_safe_list: False

Limitations: None reported

Admin destination

Open the admin page

Operational

Protect your own domains from look-alikes

Severity: High Workload: Defender Compliance: — mdo-impersonation-domains-owned
Look-alike domains are caught before they fool your users.
Operational

Protect your own domains from look-alikes

Severity: High Effort: ~a few hours Scope: All users Workload: Defender Confidence: High confidence Evaluation: Read directly Compliance:

Look-alike domains are caught before they fool your users.

Expected

Impersonation protection covers every owned organization domain.

Observed

Domain impersonation protection is enabled for owned domains.

Why it matters

Most business breaches still start with email. Better email protection reduces ransomware and invoice fraud.

Value impact: High
Recommended action

Enable organization domain impersonation protection.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • surface: impersonation
  • property: EnableOrganizationDomainsProtection
  • value: True

Limitations: None reported

Admin destination

Open the admin page

Operational

Block risky click-to-run attachments

Severity: High Workload: Defender Compliance: — mdo-malware-file-filter
Risky file types like .exe are filtered from email.
Operational

Block risky click-to-run attachments

Severity: High Effort: ~a few hours Scope: All users Workload: Defender Confidence: High confidence Evaluation: Read directly Compliance:

Risky file types like .exe are filtered from email.

Expected

The common attachments filter blocks executable attachment types.

Observed

Click-to-run attachment filtering (common attachments filter) is enabled.

Why it matters

Many tenants own P1-level email protections that never leave default off states.

Value impact: High
Recommended action

Enable the common attachments filter including .exe, .cmd, and .vbe.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • surface: anti_malware
  • property: EnableFileFilter
  • value: True

Limitations: None reported

Admin destination

Open the admin page

Operational

Turn on zero-hour auto purge for malware

Severity: High Workload: Defender Compliance: — mdo-malware-zap
Delivered malware is automatically pulled back when detected.
Operational

Turn on zero-hour auto purge for malware

Severity: High Effort: ~a few hours Scope: All users Workload: Defender Confidence: High confidence Evaluation: Read directly Compliance:

Delivered malware is automatically pulled back when detected.

Expected

Zero-hour auto purge removes delivered malware from inboxes.

Observed

Zero-hour auto purge (ZAP) is enabled for malware.

Why it matters

Many tenants own P1-level email protections that never leave default off states.

Value impact: High
Recommended action

Enable ZAP on anti-malware policies.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • surface: anti_malware
  • property: ZapEnabled
  • value: True

Limitations: None reported

Admin destination

Open the admin page

Operational

Block automatic mail forwarding to outside addresses

Severity: High Workload: Defender Compliance: — mdo-outbound-spam-forwarding-block
Automatic mail forwarding to outside addresses is blocked.
Operational

Block automatic mail forwarding to outside addresses

Severity: High Effort: ~a few hours Scope: All users Workload: Defender Confidence: High confidence Evaluation: Read directly Compliance:

Automatic mail forwarding to outside addresses is blocked.

Expected

Outbound automatic forwarding is blocked tenant-wide by the outbound spam filter policy.

Observed

Outbound automatic forwarding is blocked tenant-wide.

Why it matters

Without baseline filtering, every advanced email control sits on a weak floor.

Value impact: High
Recommended action

Turn off automatic forwarding in the outbound spam filter policy.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • surface: outbound_spam
  • policies: 1
  • forwarding_enabled: None reported

Limitations: None reported

Admin destination

Open the admin page

Operational

Turn on Safe Links and Safe Attachments for everyone

Severity: High Workload: Defender Compliance: — mdo-p2-policies-default
Safe Links and Safe Attachments look enabled from a direct policy read.
Operational

Turn on Safe Links and Safe Attachments for everyone

Severity: High Effort: ~a few hours Scope: All users Workload: Defender Confidence: High confidence Evaluation: Read directly Compliance:

Safe Links and Safe Attachments look enabled from a direct policy read.

Expected

Safe Attachments and Safe Links run in block mode for all recipients.

Observed

Direct Exchange read: Safe Links (2 enabled), Safe Attachments (1 enabled), preset rules (1 enabled); 1 custom Safe Links policy(ies) also present.

Why it matters

Most business breaches still start with email. Better email protection reduces ransomware and invoice fraud.

Value impact: High
Recommended action

Turn on Preset security policies (Standard) for all users in the Defender portal — Safe Links and Safe Attachments included.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (exo_threat_policies)

  • source: powershell.exchange.exo_threat_policies
  • proxy: False
  • email_proxy_enabled: False
  • exchange_direct: True
  • safe_links_count: 2
  • safe_links_enabled: 2
  • safe_attachments_count: 1
  • safe_attachments_enabled: 1
  • preset_enabled: 1
  • custom_safe_links: 1
  • policies: {"preset_security": [{"assignments": [], "enabled": true, "identity": "Standard Preset Security Policy", "kind": "preset_standard", "name": "Standard Preset Security Policy", "properties": {"Priority": 0, "State": "Enabled"}}], "safe_attachments": [{"assignments": ["All"], "enabled": true, "identity": "Standard Preset Security Policy", "kind": "preset_standard", "name": "Standard Preset Security Policy", "properties": {"Action": "Block", "Enable": true}}], "safe_links": [{"assignments": ["All"], "enabled": true, "identity": "Standard Preset Security Policy", "kind": "preset_standard", "name": "Standard Preset Security Policy", "properties": {"AllowClickThrough": false, "DeliverMessageAfterScan": true, "EnableSafeLinksForEmail": true, "EnableSafeLinksForOffice": true, "EnableSafeLinksForTeams": true, "ScanUrls": true, "TrackClicks": true}}, {"assignments": ["finance@contoso.com"], "enabled": true, "identity": "Custom Safe Links", "kind": "custom", "name": "Custom Safe Links", "properties": {"AllowClickThrough": false, "EnableSafeLinksForEmail": true}}]}
  • note: Direct Exchange Online PowerShell read of Safe Links, Safe Attachments, and preset security policies (supersedes Secure Score proxy).

Limitations: None reported

Admin destination

Open the admin page

Operational

Block malware found by Safe Attachments

Severity: High Workload: Defender Compliance: — mdo-safe-attachments-block
Suspicious attachments are blocked or removed before reaching users.
Operational

Block malware found by Safe Attachments

Severity: High Effort: ~a few hours Scope: All users Workload: Defender Confidence: High confidence Evaluation: Read directly Compliance:

Suspicious attachments are blocked or removed before reaching users.

Expected

Safe Attachments blocks detected malware before delivery.

Observed

Safe Attachments is set to block or replace detected malware.

Why it matters

Most business breaches still start with email. Better email protection reduces ransomware and invoice fraud.

Value impact: High
Recommended action

Set Safe Attachments unknown malware response to Block or Dynamic Delivery.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • surface: safe_attachments
  • property: Action
  • value: True

Limitations: None reported

Admin destination

Open the admin page

Operational

Scan files in SharePoint OneDrive and Teams

Severity: High Workload: Defender Compliance: — mdo-safe-attachments-spo-teams
Files in SharePoint, OneDrive, and Teams are scanned for malware.
Operational

Scan files in SharePoint OneDrive and Teams

Severity: High Effort: ~a few hours Scope: All users Workload: Defender Confidence: High confidence Evaluation: Read directly Compliance:

Files in SharePoint, OneDrive, and Teams are scanned for malware.

Expected

Safe Attachments scans files in SharePoint, OneDrive, and Teams.

Observed

Safe Attachments covers SharePoint, OneDrive, and Teams.

Why it matters

Most business breaches still start with email. Better email protection reduces ransomware and invoice fraud.

Value impact: High
Recommended action

Enable Defender for Office 365 for SharePoint, OneDrive, and Teams.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • enable_atp_for_spo_teams_odb: True

Limitations: None reported

Admin destination

Open the admin page

Operational

Screen links in email Teams and Office apps

Severity: High Workload: Defender Compliance: — mdo-safe-links-block-list
Links in email, Teams, and Office apps are screened.
Operational

Block click-through on rewrapped links

Severity: High Workload: Defender Compliance: — mdo-safe-links-click-through
Users cannot click through to the original URL.
Operational

Track clicks on rewritten links

Severity: High Workload: Defender Compliance: — mdo-safe-links-click-tracking
You can see who clicked risky links after the fact.
Operational

Scan download links in real time

Severity: High Workload: Defender Compliance: — mdo-safe-links-real-time-scan
Links pointing to files are scanned before delivery.
Operational

Show safety tips for unusual senders

Severity: High Workload: Defender Compliance: — mdo-safety-tips-enabled
Users see warnings for unusual and look-alike senders.
Operational

Show safety tips for unusual senders

Severity: High Effort: ~a few hours Scope: All users Workload: Defender Confidence: High confidence Evaluation: Read directly Compliance:

Users see warnings for unusual and look-alike senders.

Expected

Anti-phish safety tips warn users about unusual senders.

Observed

All anti-phish safety tips are enabled.

Why it matters

Most business breaches still start with email. Better email protection reduces ransomware and invoice fraud.

Value impact: High
Recommended action

Enable all anti-phish safety tips and indicators.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • surface: anti_phish
  • enabled_safety_tips: EnableFirstContactSafetyTips, EnableSimilarUsersSafetyTips, EnableSimilarDomainsSafetyTips, EnableUnusualCharactersSafetyTips

Limitations: None reported

Admin destination

Open the admin page

Operational

Keep spam and phishing out of inboxes

Severity: High Workload: Defender Compliance: — mdo-spam-phish-not-inbox
Spam and phishing are kept out of user inboxes.
Operational

Keep spam and phishing out of inboxes

Severity: High Effort: ~a few hours Scope: All users Workload: Defender Confidence: High confidence Evaluation: Read directly Compliance:

Spam and phishing are kept out of user inboxes.

Expected

Spam and phishing messages land in quarantine, not the inbox.

Observed

Spam and phishing actions keep messages out of the inbox.

Why it matters

Without baseline filtering, every advanced email control sits on a weak floor.

Value impact: High
Recommended action

Set spam and phishing actions to quarantine or junk, not inbox delivery.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • weak_actions: None reported
  • policies: 1

Limitations: None reported

Admin destination

Open the admin page

Operational

Remove mail-flow rules that copy mail outside

Severity: High Workload: Defender Compliance: — mdo-transport-rule-external-forward
Mail-flow rules do not silently copy or redirect mail outside.
Operational

Remove mail-flow rules that copy mail outside

Severity: High Effort: ~a few hours Scope: All users Workload: Defender Confidence: High confidence Evaluation: Read directly Compliance:

Mail-flow rules do not silently copy or redirect mail outside.

Expected

No transport rule Bcc's or redirects mail to external domains.

Observed

No transport rule forwards or Bcc's mail to external domains.

Why it matters

Without baseline filtering, every advanced email control sits on a weak floor.

Value impact: High
Recommended action

Remove or rescope transport rules that redirect or blind-copy mail to external addresses.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • surface: transport_rules
  • rules: 1
  • accepted_domains: contoso.com
  • external_forward_rules: None reported
  • unresolved_rules: None reported

Limitations: None reported

Admin destination

Open the admin page

Operational

Turn on unified audit logging

Severity: High Workload: Defender Compliance: — mdo-unified-audit-enabled
User and admin activity is being recorded for investigation.
Operational

Turn on unified audit logging

Severity: High Effort: ~a few hours Scope: All users Workload: Defender Confidence: High confidence Evaluation: Read directly Compliance:

User and admin activity is being recorded for investigation.

Expected

Unified audit logging records user and admin activity.

Observed

Unified audit logging is enabled.

Why it matters

Without audit history, investigations stall and compliance questions go unanswered.

Value impact: High
Recommended action

Enable unified audit log ingestion.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • adapter: scc_compliance
  • unified_audit_ingestion: True

Limitations: None reported

Admin destination

Open the admin page

Operational

Turn off Power BI data export

Severity: High Workload: Power BI Compliance: — pbi-export-controls
Data export from Power BI is off.
Operational

Turn off Power BI data export

Severity: High Effort: ~minutes Scope: Tenant data Workload: Power_bi Confidence: High confidence Evaluation: Read directly Compliance:

Data export from Power BI is off.

Expected

Power BI data export is turned off for the organization.

Observed

Power BI data export is disabled.

Why it matters

BI content often contains concentrated business truth; loose sharing leaks strategy.

Value impact: High
Recommended action

Disable data export in the Power BI admin portal tenant settings.

Evidence
Technical evidence

Data sources: Power Platform / Power BI PowerShell (powershell.bridge)

  • surface: export_data
  • enabled: False

Limitations: None reported

Admin destination

Open the admin page

Operational

Turn off Power BI publish to web

Severity: High Workload: Power BI Compliance: — pbi-publish-to-web-disabled
Publish to web is off.
Operational

Turn off Power BI publish to web

Severity: High Effort: ~minutes Scope: Tenant data Workload: Power_bi Confidence: High confidence Evaluation: Read directly Compliance:

Publish to web is off.

Expected

Publish to web is disabled in Power BI tenant settings.

Observed

Power BI publish to web is disabled.

Why it matters

BI content often contains concentrated business truth; loose sharing leaks strategy.

Value impact: High
Recommended action

Disable publish to web in the Power BI admin portal.

Evidence
Technical evidence

Data sources: Power Platform / Power BI PowerShell (powershell.bridge)

  • surface: publish_to_web
  • enabled: False

Limitations: None reported

Admin destination

Open the admin page

Operational

Apply a DLP policy to every environment

Severity: High Workload: Power Platform Compliance: — pp-dlp-all-environments
Every environment has a DLP policy.
Operational

Apply a DLP policy to every environment

Severity: High Effort: ~a few hours Scope: Tenant data Workload: Power_platform Confidence: High confidence Evaluation: Read directly Compliance:

Every environment has a DLP policy.

Expected

Every environment, including the default, is covered by a DLP policy.

Observed

Every Power Platform environment is covered by a DLP policy.

Why it matters

Ungoverned makers can connect business data to personal connectors overnight.

Value impact: High
Recommended action

Assign a DLP policy that covers every environment, including the default environment.

Evidence
Technical evidence

Data sources: Power Platform / Power BI PowerShell (powershell.bridge)

  • environment_count: 3
  • dlp_policy_count: 2
  • covered_environments: env-default, env-prod-finance, env-sandbox-nodv
  • uncovered_environments: None reported

Limitations: None reported

Admin destination

Open the admin page

Operational

Apply DLP to every non-default environment

Severity: High Workload: Power Platform Compliance: — pp-dlp-nondefault-envs
Every non-default environment has a DLP policy.
Operational

Apply DLP to every non-default environment

Severity: High Effort: ~a few hours Scope: Tenant data Workload: Power_platform Confidence: High confidence Evaluation: Read directly Compliance:

Every non-default environment has a DLP policy.

Expected

A DLP policy protects each non-default Power Platform environment.

Observed

Every non-default environment is covered by a DLP policy.

Why it matters

Ungoverned makers can connect business data to personal connectors overnight.

Value impact: High
Recommended action

Assign a DLP policy to every non-default environment.

Evidence
Technical evidence

Data sources: Power Platform / Power BI PowerShell (powershell.bridge)

  • non_default_environment_count: 2
  • dlp_policy_count: 2
  • uncovered_nondefault_environments: None reported

Limitations: None reported

Admin destination

Open the admin page

Operational

Restrict environment creation to admins

Severity: High Workload: Power Platform Compliance: — pp-env-creation-admin-only
Environment creation is admin-only.
Operational

Restrict environment creation to admins

Severity: High Effort: ~minutes Scope: All users Workload: Power_platform Confidence: High confidence Evaluation: Read directly Compliance:

Environment creation is admin-only.

Expected

Only admins can create Power Platform environments.

Observed

Environment creation is restricted to admins.

Why it matters

Ungoverned makers can connect business data to personal connectors overnight.

Value impact: High
Recommended action

Turn off environment creation by non-admin users in the Power Platform admin center.

Evidence
Technical evidence

Data sources: Power Platform / Power BI PowerShell (powershell.bridge)

  • surface: environment_creation
  • property: disableEnvironmentCreationByNonAdminUsers
  • value: True

Limitations: None reported

Admin destination

Open the admin page

Operational

Restrict Power Pages creation to admins

Severity: High Workload: Power Platform Compliance: — pp-pages-creation-admin-only
Power Pages creation is admin-only.
Operational

Restrict Power Pages creation to admins

Severity: High Effort: ~minutes Scope: Tenant data Workload: Power_platform Confidence: High confidence Evaluation: Read directly Compliance:

Power Pages creation is admin-only.

Expected

Only admins can create Power Pages sites.

Observed

Power Pages creation is restricted to admins.

Why it matters

Ungoverned makers can connect business data to personal connectors overnight.

Value impact: High
Recommended action

Turn off Power Pages creation by non-admin users in the Power Platform admin center.

Evidence
Technical evidence

Data sources: Power Platform / Power BI PowerShell (powershell.bridge)

  • surface: power_pages
  • property: disablePortalsCreationByNonAdminUsers
  • value: True

Limitations: None reported

Admin destination

Open the admin page

Operational

Configure an explicit tenant isolation allowlist

Severity: High Workload: Power Platform Compliance: — pp-tenant-isolation-allowlist
Cross-tenant connections are limited to an explicit allowlist.
Operational

Configure an explicit tenant isolation allowlist

Severity: High Effort: ~a few hours Scope: Tenant data Workload: Power_platform Confidence: High confidence Evaluation: Read directly Compliance:

Cross-tenant connections are limited to an explicit allowlist.

Expected

Tenant isolation uses an explicit cross-tenant allowlist.

Observed

Tenant isolation allowlist contains 1 tenant(s).

Why it matters

Ungoverned makers can connect business data to personal connectors overnight.

Value impact: High
Recommended action

Enable tenant isolation and define its inbound and outbound allowlist.

Evidence
Technical evidence

Data sources: Power Platform / Power BI PowerShell (powershell.bridge)

  • surface: tenant_isolation
  • isolation_enabled: True
  • allowed_tenants: 11111111-1111-1111-1111-111111111111

Limitations: None reported

Admin destination

Open the admin page

Operational

Turn on Power Platform tenant isolation

Severity: High Workload: Power Platform Compliance: — pp-tenant-isolation-enabled
Tenant isolation is enabled.
Operational

Turn on Power Platform tenant isolation

Severity: High Effort: ~a few hours Scope: Tenant data Workload: Power_platform Confidence: High confidence Evaluation: Read directly Compliance:

Tenant isolation is enabled.

Expected

Tenant isolation blocks cross-tenant connections with an explicit allowlist.

Observed

Power Platform tenant isolation is enabled.

Why it matters

Ungoverned makers can connect business data to personal connectors overnight.

Value impact: High
Recommended action

Enable tenant isolation in the Power Platform admin center and review allowlist exceptions.

Evidence
Technical evidence

Data sources: Power Platform / Power BI PowerShell (powershell.bridge)

  • surface: tenant_isolation
  • isolation_enabled: True

Limitations: None reported

Admin destination

Open the admin page

Operational

Require sensitivity labels on new content

Severity: High Workload: Purview Compliance: — pur-default-and-mandatory-labels
New content gets a default sensitivity label, and people must label before saving or sending.
Operational

Require sensitivity labels on new content

Severity: High Effort: ~a few hours Scope: All users Workload: Purview Confidence: High confidence Evaluation: Read directly Compliance:

New content gets a default sensitivity label, and people must label before saving or sending.

Expected

A default sensitivity label and mandatory labeling are configured.

Observed

A published label policy sets a default sensitivity label and requires users to apply a label.

Why it matters

Classification without enforcement is a sticker; labels with protection change outcomes.

Value impact: High
Recommended action

In your label policy, set a default label and require users to apply a label.

Evidence
Technical evidence

Data sources: Microsoft Purview / Security & Compliance PowerShell (powershell.bridge)

  • adapter: purview_governance
  • label_policies: 1
  • default_label: True
  • mandatory_labeling: True
  • absent: False

Limitations: None reported

Admin destination

Open the admin page

Operational

Block sharing of sensitive information with DLP

Severity: High Workload: Purview Compliance: — pur-dlp-enforcement-block
DLP blocks sensitive data from being shared with everyone.
Operational

Block sharing of sensitive information with DLP

Severity: High Effort: ~a few hours Scope: All users Workload: Purview Confidence: High confidence Evaluation: Read directly Compliance:

DLP blocks sensitive data from being shared with everyone.

Expected

DLP rule actions block sharing of sensitive information.

Observed

1 DLP rule(s) block sharing sensitive information.

Why it matters

Accidental oversharing is common. Guardrails protect customers and reduce regulatory and reputational harm.

Value impact: High
Recommended action

Set DLP rule actions to block access for sensitive information.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • dlp_rules: 1
  • blocking_rules: 1

Limitations: None reported

Admin destination

Open the admin page

Operational

Notify users when they handle sensitive data

Severity: High Workload: Purview Compliance: — pur-dlp-notifications
Users get educated when they handle sensitive data.
Operational

Notify users when they handle sensitive data

Severity: High Effort: ~a few hours Scope: All users Workload: Purview Confidence: High confidence Evaluation: Read directly Compliance:

Users get educated when they handle sensitive data.

Expected

DLP user notifications explain blocked actions to users.

Observed

1 DLP rule(s) notify users about sensitive data.

Why it matters

Accidental oversharing is common. Guardrails protect customers and reduce regulatory and reputational harm.

Value impact: High
Recommended action

Enable user notifications on DLP rules.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • dlp_rules: 1
  • notifying_rules: 1

Limitations: None reported

Admin destination

Open the admin page

Operational

Create an enforced DLP policy for sensitive data

Severity: High Workload: Purview Compliance: — pur-dlp-policy-present
At least one DLP policy is actively protecting sensitive data.
Operational

Create an enforced DLP policy for sensitive data

Severity: High Effort: ~a few hours Scope: All users Workload: Purview Confidence: High confidence Evaluation: Read directly Compliance:

At least one DLP policy is actively protecting sensitive data.

Expected

An enforced DLP policy protects agency-defined sensitive information.

Observed

2 DLP polic(y/ies) are enforced.

Why it matters

Accidental oversharing is common. Guardrails protect customers and reduce regulatory and reputational harm.

Value impact: High
Recommended action

Create and enforce a DLP policy covering agency-defined sensitive information.

Evidence
Technical evidence

Data sources: scc_compliance

  • dlp_policy_count: 2
  • enforced_dlp_policies: 2

Limitations: Sensitive-information-type coverage (SSN/ITIN/credit card) is not enumerated; verify rule content in the Purview portal

Admin destination

Open the admin page

Operational

Protect data on endpoint devices

Severity: High Workload: Purview Compliance: — pur-endpoint-dlp
Endpoint devices are covered by DLP.
Operational

Protect data on endpoint devices

Severity: High Effort: ~a few hours Scope: All devices Workload: Purview Confidence: High confidence Evaluation: Read directly Compliance:

Endpoint devices are covered by DLP.

Expected

An enforced DLP policy covers endpoint devices.

Observed

1 DLP policy(ies) cover endpoint devices.

Why it matters

Accidental oversharing is common. Guardrails protect customers and reduce regulatory and reputational harm.

Value impact: High
Recommended action

Add a DLP policy that includes the Devices workload.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • dlp_policy_count: 2
  • endpoint_dlp_policies: Protect endpoints

Limitations: None reported

Admin destination

Open the admin page

Operational

Confirm insider risk management is set up

Severity: High Workload: Purview Compliance: — pur-insider-risk-readiness
Insider risk policies are live. Confirm analytics is enabled and policy scope matches your riskiest groups.
Operational

Confirm insider risk management is set up

Severity: High Effort: ~days Scope: All users Workload: Purview Confidence: High confidence Evaluation: Read directly Compliance:

Insider risk policies are live. Confirm analytics is enabled and policy scope matches your riskiest groups.

Expected

At least one insider risk policy is live; analytics is enabled.

Observed

1 Insider Risk Management policy(ies) found.

Why it matters

Trusted access is powerful. Without signals, insider incidents surface only after damage.

Value impact: High
Recommended action

Confirm an insider risk policy is created, scoped to the right users, and analytics is enabled in the Purview portal.

Evidence
Technical evidence

Data sources: graph.beta.security.insiderRiskManagement.policies

  • policy_count: 1
  • policy_names: Contoso data leak by departing users
  • source: graph.beta.security.insiderRiskManagement.policies
  • direct: True
  • proxy: False

Limitations: Analytics state is not exposed by this API; confirm it in the portal

Admin destination

Open the admin page

Operational

Apply retention policies to email and files

Severity: High Workload: Purview Compliance: — pur-retention-policy-coverage
Content retention rules are in place. Confirm durations match your legal or regulatory requirements.
Operational

Apply retention policies to email and files

Severity: High Effort: ~a few hours Scope: Tenant data Workload: Purview Confidence: High confidence Evaluation: Read directly Compliance:

Content retention rules are in place. Confirm durations match your legal or regulatory requirements.

Expected

Retention policies govern content across mail and file workloads.

Observed

1 retention polic(y/ies) with 1 rule(s) are configured.

Why it matters

Retention protects evidence and reduces over-retention risk and storage cost.

Value impact: High
Recommended action

Create retention policies with retention rules for Exchange, SharePoint, OneDrive, and Teams, then confirm the durations match your requirements.

Evidence
Technical evidence

Data sources: Microsoft Purview / Security & Compliance PowerShell (powershell.bridge)

  • adapter: purview_governance
  • retention_policies: 1
  • retention_rules: 1
  • absent: False

Limitations: None reported

Admin destination

Open the admin page

Operational

Publish sensitivity labels

Severity: High Workload: Purview Compliance: — pur-sensitivity-labels-published
Sensitivity labels are available for people to apply to content.
Operational

Publish sensitivity labels

Severity: High Effort: ~a few hours Scope: All users Workload: Purview Confidence: High confidence Evaluation: Read directly Compliance:

Sensitivity labels are available for people to apply to content.

Expected

Sensitivity labels are published to users through an enabled label policy.

Observed

2 sensitivity label(s) are defined and published to users.

Why it matters

Classification without enforcement is a sticker; labels with protection change outcomes.

Value impact: High
Recommended action

Create a label policy that publishes your sensitivity labels to the people who handle sensitive content, then confirm the labels appear in Office apps.

Evidence
Technical evidence

Data sources: Microsoft Purview / Security & Compliance PowerShell (powershell.bridge)

  • adapter: purview_governance
  • sensitivity_labels: 2
  • published_label_policies: 1
  • published: True
  • absent: False
  • unpublished: False

Limitations: None reported

Admin destination

Open the admin page

Operational

Limit external sharing to approved partner domains

Severity: High Workload: Collaboration Compliance: — spo-domain-restrictions
External sharing is limited to approved partner domains.
Operational

Limit external sharing to approved partner domains

Severity: High Effort: ~a few hours Scope: Tenant data Workload: Collaboration Confidence: High confidence Evaluation: Read directly Compliance:

External sharing is limited to approved partner domains.

Expected

External sharing is limited to organization-approved partner domains.

Observed

External sharing is limited to an approved domain allowlist.

Why it matters

Over-broad sharing turns one mistaken link into a public data leak.

Value impact: High
Recommended action

Turn on domain allowlisting and add only your approved partner domains.

Evidence
Technical evidence

Data sources: Microsoft Teams / SharePoint Online PowerShell (powershell.bridge)

  • sharing_capability: existingexternalusersharingonly
  • domain_restriction_mode: allowlist
  • allowed_domains: contoso.com, partner.gov

Limitations: None reported

Admin destination

Open the admin page

Operational

Restrict OneDrive sharing to existing guests

Severity: High Workload: Collaboration Compliance: — spo-onedrive-sharing-limited
OneDrive external sharing is restricted.
Operational

Restrict OneDrive sharing to existing guests

Severity: High Effort: ~a few hours Scope: Tenant data Workload: Collaboration Confidence: High confidence Evaluation: Read directly Compliance:

OneDrive external sharing is restricted.

Expected

OneDrive sharing is limited to existing guests or internal users only.

Observed

OneDrive sharing is limited to existing guests or internal users.

Why it matters

Personal work drives often hold the same sensitive files as shared libraries.

Value impact: High
Recommended action

Set OneDrive sharing to existing guests or internal-only.

Evidence
Technical evidence

Data sources: Microsoft Teams / SharePoint Online PowerShell (powershell.bridge)

  • sharing_capability: existingexternalusersharingonly

Limitations: None reported

Admin destination

Open the admin page

Operational

Restrict SharePoint sharing to existing guests

Severity: High Workload: Collaboration Compliance: — spo-sharing-capability-limited
SharePoint external sharing is restricted.
Operational

Restrict SharePoint sharing to existing guests

Severity: High Effort: ~a few hours Scope: Tenant data Workload: Collaboration Confidence: High confidence Evaluation: Read directly Compliance:

SharePoint external sharing is restricted.

Expected

SharePoint sharing is limited to existing guests or internal users only.

Observed

SharePoint sharing is limited to existing guests or internal users.

Why it matters

Over-broad sharing turns one mistaken link into a public data leak.

Value impact: High
Recommended action

Set SharePoint sharing to existing guests or internal-only.

Evidence
Technical evidence

Data sources: Microsoft Teams / SharePoint Online PowerShell (powershell.bridge)

  • sharing_capability: existingexternalusersharingonly

Limitations: None reported

Admin destination

Open the admin page

Operational

Block unmanaged devices from SharePoint and OneDrive

Severity: High Workload: Collaboration Compliance: — spo-unmanaged-device-access
Unmanaged devices cannot reach SharePoint or OneDrive files.
Operational

Block unmanaged devices from SharePoint and OneDrive

Severity: High Effort: ~a few hours Scope: Tenant data Workload: Collaboration Confidence: High confidence Evaluation: Read directly Compliance:

Unmanaged devices cannot reach SharePoint or OneDrive files.

Expected

Unmanaged devices cannot open SharePoint or OneDrive content.

Observed

Unmanaged devices are blocked from SharePoint and OneDrive content.

Why it matters

Over-broad sharing turns one mistaken link into a public data leak.

Value impact: High
Recommended action

Block access for unmanaged devices on the SharePoint access control page.

Evidence
Technical evidence

Data sources: Microsoft Teams / SharePoint Online PowerShell (powershell.bridge)

  • unmanaged_device_policy: blockaccess

Limitations: None reported

Admin destination

Open the admin page

Operational

Block anonymous users from starting meetings

Severity: High Workload: Collaboration Compliance: — teams-anonymous-start-disabled
Anonymous attendees cannot start meetings on their own.
Operational

Block anonymous users from starting meetings

Severity: High Effort: ~a few hours Scope: All users Workload: Collaboration Confidence: High confidence Evaluation: Read directly Compliance:

Anonymous attendees cannot start meetings on their own.

Expected

Meeting policies block anonymous users from starting any meeting.

Observed

Anonymous users cannot start meetings.

Why it matters

Teams is where decisions and files move quickly — weak meeting or guest defaults become an easy side door.

Value impact: High
Recommended action

Turn off 'Anonymous users and dial-in callers can start a meeting'.

Evidence
Technical evidence

Data sources: Microsoft Teams / SharePoint Online PowerShell (powershell.bridge)

  • policies: {"ExecRecording": {"AllowAnonymousUsersToStartMeeting": false, "AllowCloudRecording": true, "AllowExternalParticipantGiveRequestControl": false, "AllowPSTNUsersToBypassLobby": false, "AutoAdmittedUsers": "EveryoneInCompany"}, "Global": {"AllowAnonymousUsersToStartMeeting": false, "AllowCloudRecording": false, "AllowExternalParticipantGiveRequestControl": false, "AllowPSTNUsersToBypassLobby": false, "AutoAdmittedUsers": "EveryoneInCompany"}}

Limitations: None reported

Admin destination

Open the admin page

Operational

Allow external access only for specific domains

Severity: High Workload: Collaboration Compliance: — teams-external-access-per-domain
External access is limited to specific partner domains.
Operational

Allow external access only for specific domains

Severity: High Effort: ~a few hours Scope: All users Workload: Collaboration Confidence: High confidence Evaluation: Read directly Compliance:

External access is limited to specific partner domains.

Expected

Teams external access is limited to approved domains only.

Observed

Teams external access is limited to specific approved domains.

Why it matters

Teams is where decisions and files move quickly — weak meeting or guest defaults become an easy side door.

Value impact: High
Recommended action

Allow only specific external domains, not all.

Evidence
Technical evidence

Data sources: Microsoft Teams / SharePoint Online PowerShell (powershell.bridge)

  • allow_federated_users: True
  • allowed_domains: partner.gov

Limitations: None reported

Admin destination

Open the admin page

Operational

Restrict who can join teams as a guest

Severity: High Workload: Collaboration Compliance: — teams-guest-access-restricted
External guests cannot be added to teams.
Operational

Restrict who can join teams as a guest

Severity: High Effort: ~a few hours Scope: All users Workload: Collaboration Confidence: High confidence Evaluation: Read directly Compliance:

External guests cannot be added to teams.

Expected

Teams guest access is disabled or limited to approved domains.

Observed

Teams guest access is disabled tenant-wide.

Why it matters

Teams is where decisions and files move quickly — weak meeting or guest defaults become an easy side door.

Value impact: High
Recommended action

Turn off guest access in Teams, or limit guest invitations to approved domains.

Evidence
Technical evidence

Data sources: Microsoft Teams / SharePoint Online PowerShell (powershell.bridge)

  • allow_guest_user: False
  • allow_guest_calling: False
  • allow_guest_chat: False

Limitations: None reported

Admin destination

Open the admin page

Operational

Block unmanaged users from contacting you first

Severity: High Workload: Collaboration Compliance: — teams-unmanaged-inbound-blocked
Unmanaged accounts cannot reach your team first.
Operational

Block unmanaged users from contacting you first

Severity: High Effort: ~a few hours Scope: All users Workload: Collaboration Confidence: High confidence Evaluation: Read directly Compliance:

Unmanaged accounts cannot reach your team first.

Expected

Unmanaged Teams accounts cannot initiate contact with internal users.

Observed

Unmanaged users cannot initiate contact with internal users.

Why it matters

Teams is where decisions and files move quickly — weak meeting or guest defaults become an easy side door.

Value impact: High
Recommended action

Block inbound contact from unmanaged Teams accounts.

Evidence
Technical evidence

Data sources: Microsoft Teams / SharePoint Online PowerShell (powershell.bridge)

  • EnableTeamsConsumerInbound: False

Limitations: None reported

Admin destination

Open the admin page

Not licensed

Turn on Defender for Cloud protection for your subscription

Severity: High Workload: Azure Compliance: — az-defender-plan-enabled
This protection does not appear to be included in the licenses we detected, so there is nothing to configure for it yet.
Not licensed

Turn on Defender for Cloud protection for your subscription

Severity: High Effort: ~a few hours Scope: Tenant data Workload: Azure Confidence: High confidence Evaluation: Read directly Compliance:

This protection does not appear to be included in the licenses we detected, so there is nothing to configure for it yet.

Expected

The paid Defender for Cloud plan is enabled on the subscription with continuous export of findings.

Observed

Required capability not detected in tenant entitlements; check skipped.

Why it matters

Not reported

Value impact: High
Recommended action

If you expected this capability, confirm the correct Microsoft plan is assigned, or talk to your licensing partner.

Evidence
Technical evidence

Data sources: graph.subscribedSkus

Limitations: None reported

Admin destination

Open the admin page

Not licensed

Apps and service accounts are not protected by risk-based sign-in rules

Severity: High Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, IA-2 id-ca-workload-identity
This protection does not appear to be included in the licenses we detected, so there is nothing to configure for it yet.
Not licensed

Apps and service accounts are not protected by risk-based sign-in rules

Severity: High Effort: ~a few hours Scope: Tenant data Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, IA-2

This protection does not appear to be included in the licenses we detected, so there is nothing to configure for it yet.

Expected

Conditional Access policies evaluate service-principal risk for workload identities.

Observed

Required capability not detected in tenant entitlements; check skipped.

Why it matters

Not reported

Value impact: High
Recommended action

If you expected this capability, confirm the correct Microsoft plan is assigned, or talk to your licensing partner.

Evidence
Technical evidence

Data sources: graph.subscribedSkus

Limitations: None reported

Admin destination

Open the admin page

Not licensed

Confirm no app or automation account is compromised

Severity: High Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, IA-2 id-identity-protection-workload
This protection does not appear to be included in the licenses we detected, so there is nothing to configure for it yet.
Not licensed

Confirm no app or automation account is compromised

Severity: High Effort: ~a few hours Scope: Tenant data Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, IA-2

This protection does not appear to be included in the licenses we detected, so there is nothing to configure for it yet.

Expected

No service principals are currently flagged as risky or compromised.

Observed

Required capability not detected in tenant entitlements; check skipped.

Why it matters

Not reported

Value impact: High
Recommended action

If you expected this capability, confirm the correct Microsoft plan is assigned, or talk to your licensing partner.

Evidence
Technical evidence

Data sources: graph.subscribedSkus

Limitations: None reported

Admin destination

Open the admin page

Action required

Prove your admin-role reviews actually run and repeat

Severity: Medium Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, AC-6 id-access-reviews-scope
Periodic confirmation of powerful admin access does not look set up at all, so privilege can accumulate without review.
Action required

Prove your admin-role reviews actually run and repeat

Severity: Medium Effort: ~a few hours Scope: Administrator scope Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, AC-6

Periodic confirmation of powerful admin access does not look set up at all, so privilege can accumulate without review.

Expected

Access reviews for privileged roles recur on a schedule and have completed at least one round.

Observed

No access review definitions were found, so privileged roles are not covered by recurring, executed reviews.

Why it matters

Admin accounts are the keys to your email, files, and business apps. If one is stolen, an attacker can look like a trusted employee.

Value impact: Medium
Recommended action

Create or correct an access review that targets privileged directory roles, set a recurring cadence (monthly or quarterly), and complete the first review round with decisions applied.

Evidence
Technical evidence

Data sources: microsoft.graph

  • definition_count: 0
  • privileged_scoped_count: 0
  • privileged_recurring_count: 0
  • definitions_with_completed_rounds: None reported
  • instance_count_by_definition: None reported

Limitations: None reported

Admin destination

Open the admin page

Action required

Set up periodic access reviews for admins and guests

Severity: Medium Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, AC-6 id-access-reviews-unused
Your plan can periodically confirm who still needs powerful access and clean up old guest accounts. That process does not look set up yet.
Action required

Set up periodic access reviews for admins and guests

Severity: Medium Effort: ~a few hours Scope: Administrator scope Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, AC-6

Your plan can periodically confirm who still needs powerful access and clean up old guest accounts. That process does not look set up yet.

Expected

Periodic access reviews run for privileged roles and guest access.

Observed

No access review definitions were found. Access Reviews are included in the tenant's plan but have never been configured.

Why it matters

Admin accounts are the keys to your email, files, and business apps. If one is stolen, an attacker can look like a trusted employee.

Value impact: Medium
Recommended action

Create an Access Review for your Global Administrators and guest users (monthly or quarterly), then review the first round of results.

Evidence
Technical evidence

Data sources: microsoft.graph

  • definition_count: 0
  • definition_ids: None reported
  • privileged_scoped_count: 0
  • recurring_count: 0
  • privileged_recurring_count: 0

Limitations: None reported

Admin destination

Open the admin page

Action required

Block risky AI agents when the control is available

Severity: Medium Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, IA-2 id-ai-agents-risky-block
We did not find an automated block for risky AI agents. Confirm in Entra whether agent risk controls are available and enforced for your tenant.
Action required

Block risky AI agents when the control is available

Severity: Medium Effort: ~days Scope: All users Workload: Identity Confidence: Low confidence — verify in portal Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, IA-2

We did not find an automated block for risky AI agents. Confirm in Entra whether agent risk controls are available and enforced for your tenant.

Expected

Risky AI agents are blocked by Conditional Access or identity protection.

Observed

No Conditional Access policy clearly blocks risky AI agents.

Why it matters

Attackers often use valid passwords. Risk detection helps catch the session even when the password was correct.

Value impact: Medium
Recommended action

Review Entra AI agent risk controls and enforce blocks where licensed and supported.

Evidence
Technical evidence

Data sources: microsoft.graph

  • candidate_policies: None reported
  • manual_fallback: True

Limitations: AI agent risk controls vary by cloud and license; treat this as advisory

Admin destination

Open the admin page

Action required

Turn on admin approval requests for apps

Severity: Medium Workload: Identity Compliance: MITRE: T1098; NIST: AC-2, IA-5 id-app-admin-consent-workflow
There is no structured way for users to request admin approval for apps.
Action required

Rotate expiring app secrets and certificates

Severity: Medium Workload: Identity Compliance: MITRE: T1098; NIST: IA-5 id-app-expiring-credentials
Some app secrets or certificates are expired or about to expire.
Action required

Rotate expiring app secrets and certificates

Severity: Medium Effort: ~a few hours Scope: Administrator scope Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1098; NIST: IA-5

Some app secrets or certificates are expired or about to expire.

Expected

Application secrets and certificates rotate before expiry.

Observed

Found 0 credential(s) expiring within 30 days and 1 already expired.

Why it matters

Secrets and certificates that never expire keep working after a leak until someone finally notices.

Value impact: Medium
Recommended action

Rotate credentials expiring within 30 days and remove already-expired secrets.

Evidence
Technical evidence

Data sources: microsoft.graph

  • expiring_within_30_days: None reported
  • already_expired: {'app': 'Legacy Line-of-Business', 'end': '2024-01-01', 'days': '-955'}
  • expiring_count: 0
  • expired_count: 1

Limitations: None reported

Admin destination

Open the admin page

Action required

Block legacy app passwords

Severity: Medium Workload: Identity Compliance: MITRE: T1098; NIST: IA-5 id-app-password-addition-blocked
Users may still create app passwords that skip modern multi-factor checks.
Action required

Block legacy app passwords

Severity: Medium Effort: ~a few hours Scope: All users Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1098; NIST: IA-5

Users may still create app passwords that skip modern multi-factor checks.

Expected

App passwords that bypass MFA are blocked for all users.

Observed

No enforced policy blocking application password addition was found.

Why it matters

Legacy app passwords bypass multi-factor authentication, leaving an unprotected door into mail and files.

Value impact: Medium
Recommended action

Block creation of app passwords with Conditional Access or authentication method controls.

Evidence
Technical evidence

Data sources: microsoft.graph

  • enforced_policies: None reported

Limitations: None reported

Admin destination

Open the admin page

Action required

Stop regular users from creating apps

Severity: Medium Workload: Identity Compliance: MITRE: T1098; NIST: AC-2, AC-6 id-app-registration-admin-only
Anyone in the directory can create app registrations, which expands the attack surface for malicious apps.
Action required

Stop regular users from creating apps

Severity: Medium Effort: ~minutes Scope: All users Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1098; NIST: AC-2, AC-6

Anyone in the directory can create app registrations, which expands the attack surface for malicious apps.

Expected

Only administrators can register applications in the tenant.

Observed

Non-admin users can register applications.

Why it matters

When anyone can register apps, unvetted apps pile up holding permissions nobody tracks.

Value impact: Medium
Recommended action

Disable user application registration in Entra user settings.

Evidence
Technical evidence

Data sources: microsoft.graph

  • allowed_to_create_apps: True

Limitations: None reported

Admin destination

Open the admin page

Action required

Show app and location on Authenticator prompts

Severity: Medium Workload: Identity Compliance: MITRE: T1078; NIST: IA-2, IA-5 id-auth-authenticator-context
Authenticator prompts do not clearly show app and location context, which makes push phishing harder to spot.
Action required

Show app and location on Authenticator prompts

Severity: Medium Effort: ~minutes Scope: All users Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: IA-2, IA-5

Authenticator prompts do not clearly show app and location context, which makes push phishing harder to spot.

Expected

Authenticator prompts show the application name and sign-in location.

Observed

Microsoft Authenticator is enabled without full login context (app_name=False, location=False).

Why it matters

Passwords alone are not enough. Good sign-in rules stop many everyday account takeovers before damage is done.

Value impact: Medium
Recommended action

Enable application name and geographic location in Microsoft Authenticator notifications.

Evidence
Technical evidence

Data sources: microsoft.graph

  • authenticator_state: enabled
  • show_app_name: False
  • show_location: False
  • number_matching_enabled: None reported

Limitations: None reported

Admin destination

Open the admin page

Action required

Require company-managed devices for access

Severity: Medium Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, IA-2 id-ca-managed-devices
Users may access work apps from unmanaged personal devices.
Action required

Require company-managed devices for access

Severity: Medium Effort: ~days Scope: All users Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, IA-2

Users may access work apps from unmanaged personal devices.

Expected

Cloud app access requires a compliant or hybrid-joined managed device.

Observed

No enforced managed-device Conditional Access policy was found.

Why it matters

Passwords alone are not enough. Good sign-in rules stop many everyday account takeovers before damage is done.

Value impact: Medium
Recommended action

Enforce Conditional Access requiring compliant or hybrid-joined devices.

Evidence
Technical evidence

Data sources: microsoft.graph

  • label: Managed device required
  • enforced_policies: None reported
  • report_only_policies: None reported
  • unjustified_exclusion_issues: None reported
  • break_glass_principal_count: 0

Limitations: None reported

Admin destination

Open the admin page

Action required

Only allow multi-factor setup from managed devices

Severity: Medium Workload: Identity Compliance: MITRE: T1078; NIST: IA-2, IA-5 id-ca-mfa-registration-managed
Attackers with a stolen password may register their own multi-factor method.
Action required

Only allow multi-factor setup from managed devices

Severity: Medium Effort: ~a few hours Scope: All users Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: IA-2, IA-5

Attackers with a stolen password may register their own multi-factor method.

Expected

Security-information registration happens only from managed devices.

Observed

No enforced policy requires a managed device for MFA registration.

Why it matters

Passwords alone are not enough. Good sign-in rules stop many everyday account takeovers before damage is done.

Value impact: Medium
Recommended action

Require a managed device when users register security information.

Evidence
Technical evidence

Data sources: microsoft.graph

  • label: Managed device for MFA registration
  • enforced_policies: None reported
  • report_only_policies: None reported
  • unjustified_exclusion_issues: None reported
  • break_glass_principal_count: 0

Limitations: None reported

Admin destination

Open the admin page

Action required

Powerful accounts that nobody uses are still switched on

Severity: Medium Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, AC-6 id-dormant-privileged
Some powerful accounts are still switched on but have not been used recently. Unused admin accounts and workload identities are a favorite target for attackers.
Action required

Powerful accounts that nobody uses are still switched on

Severity: Medium Effort: ~days Scope: Administrator scope Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, AC-6

Some powerful accounts are still switched on but have not been used recently. Unused admin accounts and workload identities are a favorite target for attackers.

Expected

Dormant privileged accounts are disabled or moved to just-in-time access.

Observed

Found 2 enabled privileged principal(s) with no successful sign-in or workload activity in the last 90 days (2 user(s), 0 workload identities of 4 privileged principal(s)).

Why it matters

Admin accounts are the keys to your email, files, and business apps. If one is stolen, an attacker can look like a trusted employee.

Value impact: Medium
Recommended action

Review enabled admin accounts that have not signed in for a long time; disable or remove access you no longer need.

Evidence
Technical evidence

Data sources: microsoft.graph

  • privileged_principal_count: 4
  • active_privileged_users: 2
  • dormant_privileged_users: 2
  • active_workload_identities: 0
  • dormant_workload_identities: 0
  • unverifiable_workload_identities: 0
  • non_user_privileged_principals: 0
  • disabled_or_unresolved: 0
  • lookback_days: 90
  • signin_sample_truncated: False
  • dormant_sample: {'id': 'user-admin-2', 'userPrincipalName': 'a***@contoso.com'}, {'id': 'user-help-dormant', 'userPrincipalName': 'o***@contoso.com'}
  • dormant_workload_sample: None reported

Limitations: None reported

Admin destination

Open the admin page

Action required

Limit what guests can see in your directory

Severity: Medium Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, AC-3 id-guest-directory-access-limited
Guest accounts can see directory information similar to full members.
Action required

Limit what guests can see in your directory

Severity: Medium Effort: ~a few hours Scope: All users Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, AC-3

Guest accounts can see directory information similar to full members.

Expected

Guests hold limited directory access as Guest or Restricted Guest users.

Observed

Guest users have the same directory permissions as members.

Why it matters

Guests browsing your directory can collect names, groups, and contacts — the raw material for targeted phishing.

Value impact: Medium
Recommended action

Set guest user access to limited or restricted in Entra external collaboration settings.

Evidence
Technical evidence

Data sources: microsoft.graph

  • guest_user_role_id: a0b1b346-4d3e-4e8b-98f8-753987be4970

Limitations: None reported

Admin destination

Open the admin page

Action required

Stop everyone from inviting external guests

Severity: Medium Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, AC-3 id-guest-inviter-restricted
Many users can invite external guests without a special role.
Action required

Stop everyone from inviting external guests

Severity: Medium Effort: ~a few hours Scope: All users Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, AC-3

Many users can invite external guests without a special role.

Expected

Only Guest Inviter role members and admins can invite guests.

Observed

Guest invitations are broadly allowed (allowInvitesFrom=everyone).

Why it matters

If any user can invite guests, one careless invite can give an outsider access to internal teams and files.

Value impact: Medium
Recommended action

Allow only admins and Guest Inviter role holders to invite guests.

Evidence
Technical evidence

Data sources: microsoft.graph

  • allow_invites_from: everyone

Limitations: None reported

Admin destination

Open the admin page

Action required

Alert when powerful roles are assigned

Severity: Medium Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, AC-6 id-pim-privileged-assignment-alert
Powerful role assignments may happen without an alert.
Action required

Alert when powerful roles are assigned

Severity: Medium Effort: ~a few hours Scope: Administrator scope Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, AC-6

Powerful role assignments may happen without an alert.

Expected

Highly privileged role assignments trigger alerts.

Observed

No PIM notification rules were found for privileged role assignments.

Why it matters

Admin accounts are the keys to your email, files, and business apps. If one is stolen, an attacker can look like a trusted employee.

Value impact: Medium
Recommended action

Enable PIM notifications for privileged role assignment events.

Evidence
Technical evidence

Data sources: microsoft.graph

  • notification_rule_count: 0

Limitations: None reported

Admin destination

Open the admin page

Action required

Guardrails against accidental data leaks may not be active

Severity: Medium Workload: Purview Compliance: — pur-dlp-not-enforced
You appear to pay for data-leak protection that is not meaningfully enforced yet. Confirm in the Purview portal.
Action required

Guardrails against accidental data leaks may not be active

Severity: Medium Effort: ~a few hours Scope: Tenant data Workload: Purview Confidence: Low confidence — verify in portal Evaluation: Approximated — verify in portal Compliance:

You appear to pay for data-leak protection that is not meaningfully enforced yet. Confirm in the Purview portal.

Expected

DLP policies are enforced in production across mail, files, and endpoints.

Observed

Secure Score suggests DLP is largely unused (2 controls, ~10% completion).

Why it matters

Accidental oversharing is common. Guardrails protect customers and reduce regulatory and reputational harm.

Value impact: High
Recommended action

Start with a simple policy for email and cloud files that detects obvious sensitive data, then move from "test" to "enforce" after a short tuning period.

Evidence
Technical evidence

Data sources: secureScore.controlScores (proxy)

  • dlp_secure_score: {"controls": [{"controlName": "DLP_Policies_Enabled", "description": "Data loss prevention policies", "maxScore": 1.0, "score": 0.1}, {"controlName": "Endpoint_DLP", "description": "Endpoint DLP", "maxScore": 1.0, "score": 0.1}], "matched_count": 2, "max_sum": 2.0, "ratio": 0.1, "score_sum": 0.2, "source": "secureScore.controlScores", "weak_control_count": 2}
  • dlp_graph: None reported
  • dlp_graph_error: demo: direct Graph DLP read unavailable
  • proxy: True
  • source: secureScore.controlScores (proxy)
  • note: Uses Microsoft Secure Score DLP/information-protection controls as a proxy when direct Purview policy APIs are unavailable to the app.

Limitations: Secure Score proxy — verify DLP enforce mode in Purview portal; Based on Microsoft Secure Score signals — confirm the real setting in the Microsoft 365 / security admin portal before treating this as definitive

Admin destination

Open the admin page

Action required

Automate part of the incident response

Severity: Medium Workload: Sentinel Compliance: — sen-automation-rules
Your security workspace reacts to nothing automatically — every alert waits for a person.
Action required

Automate part of the incident response

Severity: Medium Effort: ~a few hours Scope: All users Workload: Sentinel Confidence: Medium confidence Evaluation: Read directly Compliance:

Your security workspace reacts to nothing automatically — every alert waits for a person.

Expected

Automation rules trigger playbooks for high-value alerts.

Observed

No Sentinel automation rules or playbooks were found.

Why it matters

Without a place that correlates events, teams drown in alerts from many products and miss the story that ties them together.

Value impact: Medium
Recommended action

Add automation rules that trigger playbooks for common alerts, so response starts without waiting for a person.

Evidence
Technical evidence

Data sources: azure.arm.securityInsights

  • total_automation_rules: 0
  • enabled_automation_rules: 0
  • playbook_automation_rules: 0
  • workspace_resource_id: /subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/demo-rg/providers/Microsoft.OperationalInsights/workspaces/demo-sentinel

Limitations: None reported

Admin destination

Open the admin page

Action required

Keep security logs long enough to investigate

Severity: Medium Workload: Sentinel Compliance: — sen-log-analytics-retention
Security logs may be erased before investigations can complete.
Action required

Keep security logs long enough to investigate

Severity: Medium Effort: ~half a day Scope: Tenant data Workload: Sentinel Confidence: Medium confidence Evaluation: Read directly Compliance:

Security logs may be erased before investigations can complete.

Expected

Sentinel workspace retention covers at least 90 days for investigations.

Observed

Log Analytics retention is only 30 day(s).

Why it matters

Without a place that correlates events, teams drown in alerts from many products and miss the story that ties them together.

Value impact: Medium
Recommended action

Raise the workspace data retention to at least 90 days (and consider archive tiers for long-term storage).

Evidence
Technical evidence

Data sources: azure.arm.securityInsights

  • retention_in_days: 30
  • sku: PerGB2018
  • workspace_resource_id: /subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/demo-rg/providers/Microsoft.OperationalInsights/workspaces/demo-sentinel

Limitations: None reported

Admin destination

Open the admin page

Action required

Behavior-based detection may still be switched off

Severity: Medium Workload: Sentinel Compliance: — sen-ueba-not-enabled
Behavior analytics that learn normal patterns for people and devices still looks switched off.
Action required

Behavior-based detection may still be switched off

Severity: Medium Effort: ~a few hours Scope: All users Workload: Sentinel Confidence: Medium confidence Evaluation: Read directly Compliance:

Behavior analytics that learn normal patterns for people and devices still looks switched off.

Expected

UEBA entity behavior analytics is enabled on the Sentinel workspace.

Observed

Sentinel UEBA / entity analytics does not appear enabled.

Why it matters

Without a place that correlates events, teams drown in alerts from many products and miss the story that ties them together.

Value impact: Medium
Recommended action

Ask your security admin to turn on behavior analytics (UEBA) in the security workspace and connect the main data sources it needs.

Evidence
Technical evidence

Data sources: azure.arm.securityInsights

  • ueba_enabled: False
  • entity_analytics_enabled: False
  • ueba_setting_enabled: None reported
  • setting_names: None reported
  • raw_entity_present: False
  • raw_ueba_present: False
  • workspace_resource_id: /subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/demo-rg/providers/Microsoft.OperationalInsights/workspaces/demo-sentinel

Limitations: None reported

Admin destination

Open the admin page

Action required

Stop live events from always recording

Severity: Medium Workload: Collaboration Compliance: — teams-broadcast-not-always-record
Live events always record. Let organizers choose or disable recording.
Action required

Stop live events from always recording

Severity: Medium Effort: ~a few hours Scope: All users Workload: Collaboration Confidence: High confidence Evaluation: Read directly Compliance:

Live events always record. Let organizers choose or disable recording.

Expected

Live events are recorded only when the organizer chooses.

Observed

Live events are set to always record (AlwaysRecordEvents).

Why it matters

Teams is where decisions and files move quickly — weak meeting or guest defaults become an easy side door.

Value impact: Medium
Recommended action

Set 'Record an event' to organizer can record or never record.

Evidence
Technical evidence

Data sources: Microsoft Teams / SharePoint Online PowerShell (powershell.bridge)

  • policies: {"AlwaysRecordEvents": {"BroadcastRecordingMode": "AlwaysEnabled"}, "Global": {"BroadcastRecordingMode": "UserOverride"}}
  • weak_policies: AlwaysRecordEvents

Limitations: None reported

Admin destination

Open the admin page

Action required

Restrict Microsoft apps to approved ones

Severity: Medium Workload: Collaboration Compliance: — teams-microsoft-apps-governed
Some users can install any Microsoft app. Restrict to approved apps.
Action required

Restrict Microsoft apps to approved ones

Severity: Medium Effort: ~a few hours Scope: All users Workload: Collaboration Confidence: Medium confidence Evaluation: Read directly Compliance:

Some users can install any Microsoft app. Restrict to approved apps.

Expected

Microsoft app installation is limited to agency-approved apps.

Observed

Microsoft apps are open to all for some users (PowerUsers).

Why it matters

Teams is where decisions and files move quickly — weak meeting or guest defaults become an easy side door.

Value impact: Medium
Recommended action

Block all Microsoft apps or allow only approved ones.

Evidence
Technical evidence

Data sources: Microsoft Teams / SharePoint Online PowerShell (powershell.bridge)

  • catalog_types: {"Global": "blockedapplist", "PowerUsers": "allowedapplist"}
  • v2_readable: False
  • required_surface_incomplete: True
  • required_surface: app_settings_v2
  • weak_policies: PowerUsers

Limitations: Org-wide app settings (v2) were not readable; only legacy permission policies were evaluated

Admin destination

Open the admin page

Action required

Disable meeting recording by default

Severity: Medium Workload: Collaboration Compliance: — teams-recording-disabled
Recording is on for some users. Disable it unless explicitly required.
Action required

Disable meeting recording by default

Severity: Medium Effort: ~a few hours Scope: All users Workload: Collaboration Confidence: High confidence Evaluation: Read directly Compliance:

Recording is on for some users. Disable it unless explicitly required.

Expected

Meeting recording is off by default in meeting policies.

Observed

Meeting recording is enabled (ExecRecording).

Why it matters

Teams is where decisions and files move quickly — weak meeting or guest defaults become an easy side door.

Value impact: Medium
Recommended action

Turn off 'Meeting recording' unless a specific group needs it.

Evidence
Technical evidence

Data sources: Microsoft Teams / SharePoint Online PowerShell (powershell.bridge)

  • policies: {"ExecRecording": {"AllowAnonymousUsersToStartMeeting": false, "AllowCloudRecording": true, "AllowExternalParticipantGiveRequestControl": false, "AllowPSTNUsersToBypassLobby": false, "AutoAdmittedUsers": "EveryoneInCompany"}, "Global": {"AllowAnonymousUsersToStartMeeting": false, "AllowCloudRecording": false, "AllowExternalParticipantGiveRequestControl": false, "AllowPSTNUsersToBypassLobby": false, "AutoAdmittedUsers": "EveryoneInCompany"}}
  • weak_policies: ExecRecording

Limitations: None reported

Admin destination

Open the admin page

Incomplete

Clean up abandoned apps

Severity: Medium Workload: Identity Compliance: MITRE: T1098; NIST: AC-2, IA-5 id-app-ownerless-or-stale
Some apps have no owner or look abandoned, which makes secret and permission cleanup harder.
Incomplete

Clean up abandoned apps

Severity: Medium Effort: ~days Scope: Administrator scope Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1098; NIST: AC-2, IA-5

Some apps have no owner or look abandoned, which makes secret and permission cleanup harder.

Expected

Every application has an owner and current credentials.

Observed

Found 0 ownerless and 1 stale application(s).

Why it matters

Abandoned apps still hold permissions and are never reviewed, so they become quiet backdoors into business data.

Value impact: Medium
Recommended action

Assign owners to critical apps and remove abandoned registrations.

Evidence
Technical evidence

Data sources: microsoft.graph

  • app_count: 1
  • ownerless_count: 0
  • stale_count: 1
  • ownerless_sample: None reported
  • stale_sample: Legacy Line-of-Business

Limitations: None reported

Admin destination

Open the admin page

Incomplete

Finish consolidating sign-in method settings

Severity: Medium Workload: Identity Compliance: MITRE: T1078; NIST: IA-2, IA-5 id-auth-methods-migration
Your organization started consolidating sign-in methods but has not finished.
Incomplete

Finish consolidating sign-in method settings

Severity: Medium Effort: ~a few hours Scope: All users Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: IA-2, IA-5

Your organization started consolidating sign-in methods but has not finished.

Expected

Authentication methods policy migration is complete for MFA and SSPR.

Observed

Authentication methods migration is still in progress (migrationinprogress).

Why it matters

Passwords alone are not enough. Good sign-in rules stop many everyday account takeovers before damage is done.

Value impact: Medium
Recommended action

Complete authentication methods migration to Migration Complete.

Evidence
Technical evidence

Data sources: microsoft.graph

  • policy_migration_state: migrationinprogress

Limitations: None reported

Admin destination

Open the admin page

Incomplete

Tighten default access from unknown external tenants

Severity: Medium Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, AC-3 id-cross-tenant-defaults
External tenants can collaborate by default — tighten this unless partner allowlists are intentional.
Incomplete

Tighten default access from unknown external tenants

Severity: Medium Effort: ~a few hours Scope: All users Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, AC-3

External tenants can collaborate by default — tighten this unless partner allowlists are intentional.

Expected

Cross-tenant defaults block unknown external tenants until reviewed.

Observed

Default cross-tenant B2B inbound collaboration is allowed.

Why it matters

Passwords alone are not enough. Good sign-in rules stop many everyday account takeovers before damage is done.

Value impact: Medium
Recommended action

Review and tighten default cross-tenant access settings.

Evidence
Technical evidence

Data sources: microsoft.graph

  • inbound_access_type: allowed

Limitations: None reported

Admin destination

Open the admin page

Incomplete

Do not take other tenants' word for multi-factor auth

Severity: Medium Workload: Identity Compliance: MITRE: T1078; NIST: IA-2, IA-5 id-cross-tenant-mfa-trust
We could not confirm whether your tenant accepts other tenants' multi-factor authentication claims by default.
Incomplete

Do not take other tenants' word for multi-factor auth

Severity: Medium Effort: ~a few hours Scope: All users Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: IA-2, IA-5

We could not confirm whether your tenant accepts other tenants' multi-factor authentication claims by default.

Expected

Multi-factor authentication claims from external tenants are not trusted by default.

Observed

Cross-tenant inbound MFA trust setting was not conclusive; verify it in Entra External Identities.

Why it matters

Passwords alone are not enough. Good sign-in rules stop many everyday account takeovers before damage is done.

Value impact: Medium
Recommended action

In Entra external collaboration cross-tenant access default settings, disable 'Trust multi-factor authentication from Microsoft Entra tenants' for inbound access, and re-enable it only for specific trusted partners.

Evidence
Technical evidence

Data sources: microsoft.graph

  • inbound_mfa_trust_default: None reported
  • outbound_mfa_trust_default: None reported
  • partner_count: 0
  • partner_inbound_mfa_trust_count: 0
  • partner_outbound_mfa_trust_count: 0

Limitations: None reported

Admin destination

Open the admin page

Incomplete

Use narrower admin roles instead of Global Admin

Severity: Medium Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, AC-6 id-ga-finer-roles
Some finer-grained admin roles exist, but Global Admin may still be overused.
Incomplete

Use narrower admin roles instead of Global Admin

Severity: Medium Effort: ~days Scope: Administrator scope Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, AC-6

Some finer-grained admin roles exist, but Global Admin may still be overused.

Expected

Privileged users hold fine-grained roles instead of standing Global Admin.

Observed

Mixed privileged model: 2 Global Admin principal(s), 0 other highly privileged assignment(s).

Why it matters

Admin accounts are the keys to your email, files, and business apps. If one is stolen, an attacker can look like a trusted employee.

Value impact: Medium
Recommended action

Move routine admin duties to finer-grained directory roles and keep Global Admin rare.

Evidence
Technical evidence

Data sources: microsoft.graph

  • global_admin_principals: 2
  • other_highly_privileged_assignments: 0

Limitations: None reported

Admin destination

Open the admin page

Incomplete

Make approvals require typing the on-screen number

Severity: Medium Workload: Identity Compliance: MITRE: T1078; NIST: IA-2, IA-5 id-number-matching
We could not read the number-matching requirement, so please confirm it in the Entra authentication methods settings.
Incomplete

Make approvals require typing the on-screen number

Severity: Medium Effort: ~minutes Scope: All users Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: IA-2, IA-5

We could not read the number-matching requirement, so please confirm it in the Entra authentication methods settings.

Expected

Microsoft Authenticator requires users to type the number shown on screen when approving sign-ins.

Observed

Microsoft Authenticator number matching setting was not available, so enforcement could not be verified.

Why it matters

Passwords alone are not enough. Good sign-in rules stop many everyday account takeovers before damage is done.

Value impact: Medium
Recommended action

In Authentication methods settings, set Microsoft Authenticator number matching to Enabled and confirm the policy applies to all users.

Evidence
Technical evidence

Data sources: microsoft.graph

  • authenticator_state: enabled
  • number_matching_state: None reported
  • number_matching_explicit: False

Limitations: None reported

Admin destination

Open the admin page

Incomplete

Alert when other powerful admin roles activate

Severity: Medium Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, AC-6 id-pim-other-activation-alert
Confirm alerts fire when other admin roles are activated.
Incomplete

Alert when other powerful admin roles activate

Severity: Medium Effort: ~a few hours Scope: Administrator scope Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, AC-6

Confirm alerts fire when other admin roles are activated.

Expected

Alerts fire when other highly privileged roles activate.

Observed

PIM activation alerts for non-GA privileged roles were not confirmed.

Why it matters

Admin accounts are the keys to your email, files, and business apps. If one is stolen, an attacker can look like a trusted employee.

Value impact: Medium
Recommended action

Enable PIM activation notifications for other highly privileged roles.

Evidence
Technical evidence

Data sources: microsoft.graph

  • notification_rule_count: 0

Limitations: None reported

Admin destination

Open the admin page

Incomplete

On-site directory servers may lack attack sensors

Severity: Medium Workload: Defender Compliance: — mdi-sensors-missing
We could not confirm whether on-site directory attack sensors are installed. If you still run office domain controllers, ask IT to verify.
Incomplete

On-site directory servers may lack attack sensors

Severity: Medium Effort: ~days Scope: All users Workload: Defender Confidence: Low confidence — verify in portal Evaluation: Approximated — verify in portal Compliance:

We could not confirm whether on-site directory attack sensors are installed. If you still run office domain controllers, ask IT to verify.

Expected

Defender for Identity sensors are healthy on every domain controller.

Observed

No Defender for Identity–related Secure Score controls were found. Cannot confirm sensor deployment from this signal alone.

Why it matters

Many organizations still rely on on-site domain controllers. Cloud-only tools cannot see every attack path there.

Value impact: High
Recommended action

Confirm whether you still use on-site directory servers; if yes, install and health-check the identity sensors on each one.

Evidence
Technical evidence

Data sources: secureScore.controlScores (proxy)

  • source: secureScore.controlScores
  • proxy: True
  • matched_controls: 0
  • score_ratio: None reported
  • controls: None reported
  • note: Defender for Identity sensor health is approximated from Secure Score controls when the MDI API is not configured.

Limitations: Secure Score proxy — verify MDI sensors in the Defender portal; Based on Microsoft Secure Score signals — confirm the real setting in the Microsoft 365 / security admin portal before treating this as definitive

Admin destination

Open the admin page

Incomplete

Restrict custom apps to approved ones

Severity: Medium Workload: Collaboration Compliance: — teams-custom-apps-governed
Custom apps are governed by policy Org-wide app settings could not be confirmed automatically.
Incomplete

Restrict custom apps to approved ones

Severity: Medium Effort: ~a few hours Scope: All users Workload: Collaboration Confidence: Medium confidence Evaluation: Read directly Compliance:

Custom apps are governed by policy Org-wide app settings could not be confirmed automatically.

Expected

Custom app installation is limited to agency-approved apps.

Observed

Custom app installation is not open to all (partial: org-wide app settings v2 were not readable).

Why it matters

Teams is where decisions and files move quickly — weak meeting or guest defaults become an easy side door.

Value impact: Medium
Recommended action

Block all custom apps or allow only approved ones.

Evidence
Technical evidence

Data sources: Microsoft Teams / SharePoint Online PowerShell (powershell.bridge)

  • catalog_types: {"Global": "blockedapplist", "PowerUsers": "blockedapplist"}
  • v2_readable: False
  • required_surface_incomplete: True
  • required_surface: app_settings_v2

Limitations: Org-wide app settings (v2) were not readable; only legacy permission policies were evaluated

Admin destination

Open the admin page

Incomplete

Restrict third-party apps to approved ones

Severity: Medium Workload: Collaboration Compliance: — teams-third-party-apps-governed
Third-party apps are governed by policy Org-wide app settings could not be confirmed automatically.
Incomplete

Restrict third-party apps to approved ones

Severity: Medium Effort: ~a few hours Scope: All users Workload: Collaboration Confidence: Medium confidence Evaluation: Read directly Compliance:

Third-party apps are governed by policy Org-wide app settings could not be confirmed automatically.

Expected

Third-party app installation is limited to agency-approved apps.

Observed

Third-party app installation is not open to all (partial: org-wide app settings v2 were not readable).

Why it matters

Teams is where decisions and files move quickly — weak meeting or guest defaults become an easy side door.

Value impact: Medium
Recommended action

Block all third-party apps or allow only approved ones.

Evidence
Technical evidence

Data sources: Microsoft Teams / SharePoint Online PowerShell (powershell.bridge)

  • catalog_types: {"Global": "blockedapplist", "PowerUsers": "blockedapplist"}
  • v2_readable: False
  • required_surface_incomplete: True
  • required_surface: app_settings_v2

Limitations: Org-wide app settings (v2) were not readable; only legacy permission policies were evaluated

Admin destination

Open the admin page

Not assessed

Limit guest invites to approved partner domains

Severity: Medium Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, AC-3 id-guest-invite-domains
We cannot judge guest invite domains until your organization lists approved partner domains in your configured settings.
Not assessed

Limit guest invites to approved partner domains

Severity: Medium (potential impact — not yet assessed) Effort: ~days Scope: All users Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, AC-3

We cannot judge guest invite domains until your organization lists approved partner domains in your configured settings.

Expected

Guest invites are limited to organization-approved external domains.

Why this was skipped

Guest invite domain allowlisting requires approved partner domains in your configured settings.

Why it matters

Open invites let untrusted external identities walk into your tenant; approving specific partner domains keeps that door narrow.

Value impact: Medium
Recommended action

List approved partner domains in your configured settings and mirror them in Entra B2B allowlists.

Evidence
Technical evidence

Data sources: microsoft.graph

  • approved_guest_domains: None reported
  • cross_tenant_default_present: True
  • manual: True

Limitations: None reported

Admin destination

Open the admin page

Not assessed

Confirm high-risk account alerts reach security

Severity: Medium Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, IA-2 id-idprotect-notify-high-risk
Ask IT to confirm Identity Protection emails high-risk user alerts to a monitored security mailbox.
Not assessed

Confirm high-risk account alerts reach security

Severity: Medium (potential impact — not yet assessed) Effort: ~minutes Scope: Administrator scope Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, IA-2

Ask IT to confirm Identity Protection emails high-risk user alerts to a monitored security mailbox.

Expected

High-risk user alerts reach a monitored security mailbox.

Why this was skipped

High-risk user admin notifications are portal-configured and not exposed as a complete Graph control for automated proof.

Why it matters

Attackers often use valid passwords. Risk detection helps catch the session even when the password was correct.

Value impact: Medium
Recommended action

In Identity Protection, send high-risk user alerts to a monitored security mailbox.

Evidence
Technical evidence

Data sources: microsoft.graph

  • manual: True
  • evaluation_mode: manual

Limitations: Manual verification required in Microsoft Entra ID Protection notifications

Admin destination

Open the admin page

Not assessed

Confirm communication compliance is set up

Severity: Medium Workload: Purview Compliance: — pur-communication-compliance-readiness
Confirm communication compliance policies cover the channels that matter.
Not assessed

Confirm communication compliance is set up

Severity: Medium (potential impact — not yet assessed) Effort: ~days Scope: All users Workload: Purview Compliance:

Confirm communication compliance policies cover the channels that matter.

Expected

Communication compliance policies cover key channels and route matches to reviewers.

Why this was skipped

Communication compliance policies are portal-configured and not automatically readable here.

Why it matters

Toxic or noncompliant communication creates legal and cultural risk that identity tools miss.

Value impact: High
Recommended action

Confirm communication compliance policies cover the channels that matter and route matches to the right reviewers in the Purview portal.

Evidence
Technical evidence

Data sources: Not reported

  • manual: True
  • evaluation_mode: manual

Limitations: Manual verification required in Microsoft Purview Communication Compliance

Admin destination

Open the admin page

Operational

Nothing may happen when a device falls out of compliance

Severity: Medium Workload: Endpoint Compliance: MITRE: T1059; NIST: CM-6, SI-2 endpoint-compliance-noncompliance-action
Falling out of compliance triggers an action.
Operational

Nothing may happen when a device falls out of compliance

Severity: Medium Effort: ~a few hours Scope: All devices Workload: Endpoint Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1059; NIST: CM-6, SI-2

Falling out of compliance triggers an action.

Expected

Every compliance policy has a scheduled action for noncompliant devices.

Observed

All 2 compliance policy(ies) configure a noncompliance action.

Why it matters

Unmanaged devices are a common path around strong cloud identity controls.

Value impact: High
Recommended action

Configure a noncompliance action (such as notify or block access) on each compliance policy.

Evidence
Technical evidence

Data sources: graph.deviceManagement

  • compliance_policy_count: 2
  • policies_with_action: 2

Limitations: None reported

Admin destination

Open the admin page

Operational

No security baseline may be applied to devices

Severity: Medium Workload: Endpoint Compliance: MITRE: T1059; NIST: CM-6, SI-2 endpoint-security-baseline
A security baseline is applied to managed devices.
Operational

No security baseline may be applied to devices

Severity: Medium Effort: ~a few hours Scope: All devices Workload: Endpoint Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1059; NIST: CM-6, SI-2

A security baseline is applied to managed devices.

Expected

Security baseline profiles are assigned to every managed platform.

Observed

1 endpoint-security baseline profile(s) configured.

Why it matters

Unmanaged devices are a common path around strong cloud identity controls.

Value impact: High
Recommended action

Deploy a Microsoft security baseline profile to your managed devices and monitor its adoption.

Evidence
Technical evidence

Data sources: graph.deviceManagement

  • configuration_policy_count: 5
  • baseline_policy_count: 1

Limitations: None reported

Admin destination

Open the admin page

Operational

Shorten long-lived app certificates

Severity: Medium Workload: Identity Compliance: MITRE: T1098; NIST: IA-5 id-app-certificate-lifetime
App certificates we could see stay within a reasonable lifetime.
Operational

Shorten long-lived app certificates

Severity: Medium Effort: ~days Scope: Administrator scope Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1098; NIST: IA-5

App certificates we could see stay within a reasonable lifetime.

Expected

Application certificates expire within 365 days of issuance.

Observed

No app certificates exceed 365 days.

Why it matters

A stolen app certificate stays valid until it expires; short lifetimes shrink that damage window from years to days.

Value impact: Medium
Recommended action

Keep application certificate lifetimes at 365 days or less and rotate on schedule.

Evidence
Technical evidence

Data sources: microsoft.graph

  • long_lived_certificate_count: 0
  • sample: None reported

Limitations: None reported

Admin destination

Open the admin page

Operational

Shorten long-lived app secrets

Severity: Medium Workload: Identity Compliance: MITRE: T1098; NIST: IA-5 id-app-password-lifetime
App secrets we could see stay within a reasonable lifetime.
Operational

Shorten long-lived app secrets

Severity: Medium Effort: ~days Scope: Administrator scope Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1098; NIST: IA-5

App secrets we could see stay within a reasonable lifetime.

Expected

Application password credentials expire within 180 days.

Observed

No app password credentials exceed 180 days.

Why it matters

Long-lived app secrets mean a leaked credential keeps working for months without being noticed.

Value impact: Medium
Recommended action

Rotate app secrets and keep password credential lifetime at 180 days or less.

Evidence
Technical evidence

Data sources: microsoft.graph

  • long_lived_password_count: 0
  • sample: None reported

Limitations: None reported

Admin destination

Open the admin page

Operational

Turn on mailbox intelligence for impersonation detection

Severity: Medium Workload: Defender Compliance: — mdo-mailbox-intelligence
Mailbox intelligence learns your senders so look-alike impersonation is caught.
Operational

Turn on mailbox intelligence for impersonation detection

Severity: Medium Effort: ~a few hours Scope: All users Workload: Defender Confidence: High confidence Evaluation: Read directly Compliance:

Mailbox intelligence learns your senders so look-alike impersonation is caught.

Expected

Mailbox intelligence is enabled on all anti-phish policies.

Observed

Mailbox intelligence is enabled across all 1 anti-phish policy(ies).

Why it matters

Most business breaches still start with email. Better email protection reduces ransomware and invoice fraud.

Value impact: Medium
Recommended action

Enable mailbox intelligence on every anti-phish policy.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • surface: anti_phish
  • policies: 1
  • mailbox_intelligence_enabled: 1
  • mailbox_intelligence_missing: None reported

Limitations: None reported

Admin destination

Open the admin page

Operational

Restrict quarantine release and keep mail longer

Severity: Medium Workload: Defender Compliance: — mdo-quarantine-policy
Users cannot release quarantined mail without admin review.
Operational

Restrict quarantine release and keep mail longer

Severity: Medium Effort: ~minutes Scope: All users Workload: Defender Confidence: High confidence Evaluation: Read directly Compliance:

Users cannot release quarantined mail without admin review.

Expected

End users have limited quarantine access and mail is kept long enough.

Observed

End-user quarantine permissions are limited and retention is adequate.

Why it matters

Without baseline filtering, every advanced email control sits on a weak floor.

Value impact: High
Recommended action

Restrict end-user quarantine permissions and increase the retention window.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • surface: quarantine
  • policies: 1
  • full_access_policies: None reported
  • retention_days: 30

Limitations: None reported

Admin destination

Open the admin page

Operational

Scan Office files from untrusted sources

Severity: Medium Workload: Defender Compliance: — mdo-safe-documents
Office documents are scanned before users open them.
Operational

Scan Office files from untrusted sources

Severity: Medium Effort: ~minutes Scope: All users Workload: Defender Confidence: High confidence Evaluation: Read directly Compliance:

Office documents are scanned before users open them.

Expected

Safe Documents protects users who open Office files from the internet.

Observed

Safe Documents scans Office files opened from untrusted sources.

Why it matters

Most business breaches still start with email. Better email protection reduces ransomware and invoice fraud.

Value impact: High
Recommended action

Turn on Safe Documents in Microsoft 365 Defender settings.

Evidence
Technical evidence

Data sources: Exchange Online PowerShell (powershell.bridge), Security & Compliance PowerShell (scc_compliance)

  • enable_safe_docs: True
  • allow_safe_docs_open: True

Limitations: None reported

Admin destination

Open the admin page

Operational

Turn off external Power BI invitations

Severity: Medium Workload: Power BI Compliance: — pbi-external-invite-disabled
External invitations are off.
Operational

Turn off external Power BI invitations

Severity: Medium Effort: ~minutes Scope: Tenant data Workload: Power_bi Confidence: High confidence Evaluation: Read directly Compliance:

External invitations are off.

Expected

External user invitations are disabled in Power BI tenant settings.

Observed

External invitations to Power BI content are disabled.

Why it matters

BI content often contains concentrated business truth; loose sharing leaks strategy.

Value impact: Medium
Recommended action

Disable external invitations in the Power BI admin portal.

Evidence
Technical evidence

Data sources: Power Platform / Power BI PowerShell (powershell.bridge)

  • surface: external_invite
  • enabled: False

Limitations: None reported

Admin destination

Open the admin page

Operational

Turn off Power BI guest access

Severity: Medium Workload: Power BI Compliance: — pbi-guest-access-disabled
Guest access is off.
Operational

Turn off Power BI guest access

Severity: Medium Effort: ~minutes Scope: Tenant data Workload: Power_bi Confidence: High confidence Evaluation: Read directly Compliance:

Guest access is off.

Expected

Guest access is disabled in Power BI tenant settings.

Observed

Power BI guest user access is disabled.

Why it matters

BI content often contains concentrated business truth; loose sharing leaks strategy.

Value impact: Medium
Recommended action

Disable guest user access in the Power BI admin portal.

Evidence
Technical evidence

Data sources: Power Platform / Power BI PowerShell (powershell.bridge)

  • surface: guest_access
  • enabled: False

Limitations: None reported

Admin destination

Open the admin page

Operational

Turn off Python and R visuals

Severity: Medium Workload: Power BI Compliance: — pbi-python-r-visuals-disabled
Python and R visuals are off.
Operational

Turn off Python and R visuals

Severity: Medium Effort: ~minutes Scope: Tenant data Workload: Power_bi Confidence: High confidence Evaluation: Read directly Compliance:

Python and R visuals are off.

Expected

Python and R visuals are disabled in Power BI tenant settings.

Observed

Python and R visuals are disabled.

Why it matters

BI content often contains concentrated business truth; loose sharing leaks strategy.

Value impact: Medium
Recommended action

Disable Python and R visuals in the Power BI admin portal.

Evidence
Technical evidence

Data sources: Power Platform / Power BI PowerShell (powershell.bridge)

  • surface: python_r_visuals
  • enabled: False

Limitations: None reported

Admin destination

Open the admin page

Operational

Block Power BI resource key authentication

Severity: Medium Workload: Power BI Compliance: — pbi-resource-key-auth-blocked
Resource key authentication is blocked.
Operational

Block Power BI resource key authentication

Severity: Medium Effort: ~minutes Scope: Tenant data Workload: Power_bi Confidence: High confidence Evaluation: Read directly Compliance:

Resource key authentication is blocked.

Expected

Resource key authentication is blocked in Power BI tenant settings.

Observed

Power BI resource key authentication is blocked.

Why it matters

BI content often contains concentrated business truth; loose sharing leaks strategy.

Value impact: Medium
Recommended action

Block resource key authentication in the Power BI admin portal.

Evidence
Technical evidence

Data sources: Power Platform / Power BI PowerShell (powershell.bridge)

  • surface: resource_key_auth
  • enabled: True

Limitations: None reported

Admin destination

Open the admin page

Operational

Turn on Power BI sensitivity labels

Severity: Medium Workload: Power BI Compliance: — pbi-sensitivity-labels-enabled
Sensitivity labels are applied to Power BI content.
Operational

Turn on Power BI sensitivity labels

Severity: Medium Effort: ~a few hours Scope: Tenant data Workload: Power_bi Confidence: High confidence Evaluation: Read directly Compliance:

Sensitivity labels are applied to Power BI content.

Expected

Sensitivity labels are enabled so Power BI content inherits classification.

Observed

Power BI sensitivity labels are enabled.

Why it matters

BI content often contains concentrated business truth; loose sharing leaks strategy.

Value impact: Medium
Recommended action

Enable sensitivity labels in the Power BI admin portal and publish label policies.

Evidence
Technical evidence

Data sources: Power Platform / Power BI PowerShell (powershell.bridge)

  • surface: sensitivity_labels
  • enabled: True

Limitations: None reported

Admin destination

Open the admin page

Operational

Restrict Power BI API access for service principals

Severity: Medium Workload: Power BI Compliance: — pbi-sp-api-restricted
Service principal API access is restricted to allowed groups.
Operational

Restrict Power BI API access for service principals

Severity: Medium Effort: ~a few hours Scope: Tenant data Workload: Power_bi Confidence: High confidence Evaluation: Read directly Compliance:

Service principal API access is restricted to allowed groups.

Expected

Service principal API access is disabled or limited to specific security groups.

Observed

Service principal API access is limited to specific security groups.

Why it matters

BI content often contains concentrated business truth; loose sharing leaks strategy.

Value impact: Medium
Recommended action

Restrict service principal API access to specific security groups or disable it.

Evidence
Technical evidence

Data sources: Power Platform / Power BI PowerShell (powershell.bridge)

  • surface: service_principal_api
  • enabled: True
  • security_groups: sg-pbi-sp

Limitations: None reported

Admin destination

Open the admin page

Operational

Turn off service principal profiles

Severity: Medium Workload: Power BI Compliance: — pbi-sp-profiles-disabled
Service principal profiles are off.
Operational

Turn off service principal profiles

Severity: Medium Effort: ~minutes Scope: Tenant data Workload: Power_bi Confidence: High confidence Evaluation: Read directly Compliance:

Service principal profiles are off.

Expected

Service principals cannot create Power BI profiles.

Observed

Service principal Power BI profile creation is disabled.

Why it matters

BI content often contains concentrated business truth; loose sharing leaks strategy.

Value impact: Medium
Recommended action

Disable service principal profile creation in the Power BI admin portal.

Evidence
Technical evidence

Data sources: Power Platform / Power BI PowerShell (powershell.bridge)

  • surface: service_principal_profiles
  • enabled: False

Limitations: None reported

Admin destination

Open the admin page

Operational

Block sharing apps with everyone

Severity: Medium Workload: Power Platform Compliance: — pp-share-with-everyone-disabled
Share-with-everyone is disabled.
Operational

Block sharing apps with everyone

Severity: Medium Effort: ~minutes Scope: Tenant data Workload: Power_platform Confidence: High confidence Evaluation: Read directly Compliance:

Share-with-everyone is disabled.

Expected

Power Apps sharing with everyone is disabled.

Observed

Sharing Power Apps with everyone is disabled.

Why it matters

Ungoverned makers can connect business data to personal connectors overnight.

Value impact: Medium
Recommended action

Disable share-with-everyone in the Power Platform admin center.

Evidence
Technical evidence

Data sources: Power Platform / Power BI PowerShell (powershell.bridge)

  • surface: share_with_everyone
  • property: disableShareWithEveryone
  • value: True

Limitations: None reported

Admin destination

Open the admin page

Operational

Restrict trial environment creation to admins

Severity: Medium Workload: Power Platform Compliance: — pp-trial-creation-admin-only
Trial environment creation is admin-only.
Operational

Restrict trial environment creation to admins

Severity: Medium Effort: ~minutes Scope: All users Workload: Power_platform Confidence: High confidence Evaluation: Read directly Compliance:

Trial environment creation is admin-only.

Expected

Only admins can create Power Platform trial environments.

Observed

Trial environment creation is restricted to admins.

Why it matters

Ungoverned makers can connect business data to personal connectors overnight.

Value impact: Medium
Recommended action

Turn off trial environment creation by non-admin users in the Power Platform admin center.

Evidence
Technical evidence

Data sources: Power Platform / Power BI PowerShell (powershell.bridge)

  • surface: environment_creation
  • property: disableTrialEnvironmentCreationByNonAdminUsers
  • value: True

Limitations: None reported

Admin destination

Open the admin page

Operational

Confirm eDiscovery is set up

Severity: Medium Workload: Purview Compliance: — pur-ediscovery-readiness
eDiscovery is configured and has been exercised. Keep case access and legal-hold reviews on a regular cadence.
Operational

Confirm eDiscovery is set up

Severity: Medium Effort: ~days Scope: All users Workload: Purview Confidence: High confidence Evaluation: Read directly Compliance:

eDiscovery is configured and has been exercised. Keep case access and legal-hold reviews on a regular cadence.

Expected

Premium eDiscovery cases exist and legal hold workflows are in use.

Observed

1 Premium eDiscovery case(s) found — case and hold workflows are in use.

Why it matters

Missing holds destroy evidence and create legal and regulatory exposure.

Value impact: High
Recommended action

Create a test Premium case with a legal hold, and confirm eDiscovery administrators are assigned in the Purview portal.

Evidence
Technical evidence

Data sources: graph.security.cases.ediscoveryCases

  • case_count: 1
  • case_names: Contoso investigation 2026-Q1
  • source: graph.security.cases.ediscoveryCases
  • direct: True
  • proxy: False

Limitations: None reported

Admin destination

Open the admin page

Operational

Default new links to specific people

Severity: Medium Workload: Collaboration Compliance: — spo-default-link-specific
New sharing links only reach the specific people you choose.
Operational

Default new links to view-only

Severity: Medium Workload: Collaboration Compliance: — spo-default-link-view
New sharing links are view-only by default.
Operational

Require verification-code reauthentication within 30 days

Severity: Medium Workload: Collaboration Compliance: — spo-verification-reauth
Verification-code access reauthenticates within a safe window.
Operational

Require verification-code reauthentication within 30 days

Severity: Medium Effort: ~a few hours Scope: All users Workload: Collaboration Confidence: High confidence Evaluation: Read directly Compliance:

Verification-code access reauthenticates within a safe window.

Expected

Verification-code users reauthenticate within 30 days or fewer.

Observed

Verification-code users must reauthenticate within 30 days.

Why it matters

Over-broad sharing turns one mistaken link into a public data leak.

Value impact: Medium
Recommended action

Require verification-code users to reauthenticate within 30 days.

Evidence
Technical evidence

Data sources: Microsoft Teams / SharePoint Online PowerShell (powershell.bridge)

  • email_attestation_required: True
  • email_attestation_reauth_days: 30
  • sharing_capability: existingexternalusersharingonly

Limitations: None reported

Admin destination

Open the admin page

Operational

Hold anonymous and dial-in callers in the lobby

Severity: Medium Workload: Collaboration Compliance: — teams-anonymous-lobby
Unmanaged attendees wait in the lobby.
Operational

Hold anonymous and dial-in callers in the lobby

Severity: Medium Effort: ~a few hours Scope: All users Workload: Collaboration Confidence: High confidence Evaluation: Read directly Compliance:

Unmanaged attendees wait in the lobby.

Expected

Anonymous and dial-in callers are held in the meeting lobby.

Observed

Anonymous users and dial-in callers are not auto-admitted.

Why it matters

Teams is where decisions and files move quickly — weak meeting or guest defaults become an easy side door.

Value impact: Medium
Recommended action

Keep 'Who can bypass the lobby' away from Everyone.

Evidence
Technical evidence

Data sources: Microsoft Teams / SharePoint Online PowerShell (powershell.bridge)

  • policies: {"ExecRecording": {"AllowAnonymousUsersToStartMeeting": false, "AllowCloudRecording": true, "AllowExternalParticipantGiveRequestControl": false, "AllowPSTNUsersToBypassLobby": false, "AutoAdmittedUsers": "EveryoneInCompany"}, "Global": {"AllowAnonymousUsersToStartMeeting": false, "AllowCloudRecording": false, "AllowExternalParticipantGiveRequestControl": false, "AllowPSTNUsersToBypassLobby": false, "AutoAdmittedUsers": "EveryoneInCompany"}}

Limitations: None reported

Admin destination

Open the admin page

Operational

Keep dial-in callers in the lobby

Severity: Medium Workload: Collaboration Compliance: — teams-dialin-lobby
Dial-in callers wait in the lobby.
Operational

Keep dial-in callers in the lobby

Severity: Medium Effort: ~a few hours Scope: All users Workload: Collaboration Confidence: High confidence Evaluation: Read directly Compliance:

Dial-in callers wait in the lobby.

Expected

Dial-in callers wait in the meeting lobby.

Observed

Dial-in callers cannot bypass the meeting lobby.

Why it matters

Teams is where decisions and files move quickly — weak meeting or guest defaults become an easy side door.

Value impact: Medium
Recommended action

Turn off 'People dialing in can bypass the lobby'.

Evidence
Technical evidence

Data sources: Microsoft Teams / SharePoint Online PowerShell (powershell.bridge)

  • policies: {"ExecRecording": {"AllowAnonymousUsersToStartMeeting": false, "AllowCloudRecording": true, "AllowExternalParticipantGiveRequestControl": false, "AllowPSTNUsersToBypassLobby": false, "AutoAdmittedUsers": "EveryoneInCompany"}, "Global": {"AllowAnonymousUsersToStartMeeting": false, "AllowCloudRecording": false, "AllowExternalParticipantGiveRequestControl": false, "AllowPSTNUsersToBypassLobby": false, "AutoAdmittedUsers": "EveryoneInCompany"}}

Limitations: None reported

Admin destination

Open the admin page

Operational

Disable channel email integration

Severity: Medium Workload: Collaboration Compliance: — teams-email-integration-disabled
Channels cannot receive external email.
Operational

Disable channel email integration

Severity: Medium Effort: ~a few hours Scope: All users Workload: Collaboration Confidence: High confidence Evaluation: Read directly Compliance:

Channels cannot receive external email.

Expected

Teams channel email integration is turned off.

Observed

Teams channel email integration is disabled.

Why it matters

Teams is where decisions and files move quickly — weak meeting or guest defaults become an easy side door.

Value impact: Medium
Recommended action

Turn off 'Users can send emails to a channel email address'.

Evidence
Technical evidence

Data sources: Microsoft Teams / SharePoint Online PowerShell (powershell.bridge)

  • allow_email_into_channel: False

Limitations: None reported

Admin destination

Open the admin page

Operational

Block external participants from taking control

Severity: Medium Workload: Collaboration Compliance: — teams-external-control-disabled
External attendees cannot take over shared screens.
Operational

Block external participants from taking control

Severity: Medium Effort: ~a few hours Scope: All users Workload: Collaboration Confidence: High confidence Evaluation: Read directly Compliance:

External attendees cannot take over shared screens.

Expected

Meeting policies deny external participants control over shared screens.

Observed

External participants cannot request control of shared content.

Why it matters

Teams is where decisions and files move quickly — weak meeting or guest defaults become an easy side door.

Value impact: Medium
Recommended action

Turn off 'External participants can give or request control'.

Evidence
Technical evidence

Data sources: Microsoft Teams / SharePoint Online PowerShell (powershell.bridge)

  • policies: {"ExecRecording": {"AllowAnonymousUsersToStartMeeting": false, "AllowCloudRecording": true, "AllowExternalParticipantGiveRequestControl": false, "AllowPSTNUsersToBypassLobby": false, "AutoAdmittedUsers": "EveryoneInCompany"}, "Global": {"AllowAnonymousUsersToStartMeeting": false, "AllowCloudRecording": false, "AllowExternalParticipantGiveRequestControl": false, "AllowPSTNUsersToBypassLobby": false, "AutoAdmittedUsers": "EveryoneInCompany"}}

Limitations: None reported

Admin destination

Open the admin page

Operational

Block internal users from contacting unmanaged accounts

Severity: Medium Workload: Collaboration Compliance: — teams-unmanaged-outbound-blocked
Your team cannot reach unmanaged accounts.
Operational

Block internal users from contacting unmanaged accounts

Severity: Medium Effort: ~a few hours Scope: All users Workload: Collaboration Confidence: High confidence Evaluation: Read directly Compliance:

Your team cannot reach unmanaged accounts.

Expected

Internal users cannot contact unmanaged Teams accounts.

Observed

Internal users cannot initiate contact with unmanaged users.

Why it matters

Teams is where decisions and files move quickly — weak meeting or guest defaults become an easy side door.

Value impact: Medium
Recommended action

Block outbound contact to unmanaged Teams accounts.

Evidence
Technical evidence

Data sources: Microsoft Teams / SharePoint Online PowerShell (powershell.bridge)

  • EnableTeamsConsumerAccess: False

Limitations: None reported

Admin destination

Open the admin page

Operational

Cross-product incident correlation may not be active

Severity: Medium Workload: Defender Compliance: MITRE: T1059; NIST: IR-4, AU-6 xdr-incident-readiness
Cross-product incidents are being correlated, so XDR is actively in use.
Operational

Cross-product incident correlation may not be active

Severity: Medium Effort: ~a few hours Scope: All users Workload: Defender Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1059; NIST: IR-4, AU-6

Cross-product incidents are being correlated, so XDR is actively in use.

Expected

Defender XDR correlates signals from identity, email, and endpoint into incidents.

Observed

Defender XDR correlation is operating (1 incident(s), 1 alert(s) observed).

Why it matters

Attackers hop products. Siloed alerts hide the path from phishing to privilege.

Value impact: High
Recommended action

Confirm XDR is enabled and that identity, email, and endpoint signals are connected in the Microsoft Defender portal.

Evidence
Technical evidence

Data sources: graph.security.incidents

  • incident_count: 1
  • alert_count: 1
  • capability_operating: True

Limitations: None reported

Admin destination

Open the admin page

Not licensed

Access to apps, groups, and Teams is not yet lifecycle-governed

Severity: Medium Workload: Identity Compliance: MITRE: T1078; NIST: AC-2, AC-6 id-entitlement-access-packages
This protection does not appear to be included in the licenses we detected, so there is nothing to configure for it yet.
Not licensed

Access to apps, groups, and Teams is not yet lifecycle-governed

Severity: Medium Effort: ~half a day Scope: Tenant data Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: AC-2, AC-6

This protection does not appear to be included in the licenses we detected, so there is nothing to configure for it yet.

Expected

Entitlement Management access packages are configured for governed access.

Observed

Required capability not detected in tenant entitlements; check skipped.

Why it matters

Not reported

Value impact: Medium
Recommended action

If you expected this capability, confirm the correct Microsoft plan is assigned, or talk to your licensing partner.

Evidence
Technical evidence

Data sources: graph.subscribedSkus

Limitations: None reported

Admin destination

Open the admin page

Not licensed

Premium capacity use and capacity admins are checked directly

Severity: Medium Workload: Power BI Compliance: — pbi-premium-capacity-governance
This protection does not appear to be included in the licenses we detected, so there is nothing to configure for it yet.
Not licensed

Premium capacity use and capacity admins are checked directly

Severity: Medium Effort: ~a few hours Scope: Tenant data Workload: Power_bi Confidence: High confidence Evaluation: Read directly Compliance:

This protection does not appear to be included in the licenses we detected, so there is nothing to configure for it yet.

Expected

Premium capacities are in use and capacity admins stay limited.

Observed

Required capability not detected in tenant entitlements; check skipped.

Why it matters

Not reported

Value impact: Medium
Recommended action

If you expected this capability, confirm the correct Microsoft plan is assigned, or talk to your licensing partner.

Evidence
Technical evidence

Data sources: graph.subscribedSkus

Limitations: None reported

Admin destination

Open the admin page

Action required

Stop calendar-based password expiration

Severity: Low Workload: Identity Compliance: MITRE: T1078; NIST: IA-5 id-password-never-expire
Passwords still expire on a schedule. Modern guidance is to ban periodic expiration and use strong multi-factor authentication instead.
Action required

Stop calendar-based password expiration

Severity: Low Effort: ~a few hours Scope: All users Workload: Identity Confidence: High confidence Evaluation: Read directly Compliance: MITRE: T1078; NIST: IA-5

Passwords still expire on a schedule. Modern guidance is to ban periodic expiration and use strong multi-factor authentication instead.

Expected

User passwords never expire on verified managed domains.

Observed

One or more verified domains still enforce password expiration: contoso.onmicrosoft.com (90d)

Why it matters

Forced password changes push people toward weak, predictable patterns; strong multi-factor authentication protects far better.

Value impact: Low
Recommended action

Set password validity to never expire on verified managed domains.

Evidence
Technical evidence

Data sources: microsoft.graph

  • never_expire_domains: None reported
  • expiring_domains: {'domain': 'contoso.onmicrosoft.com', 'days': 90}

Limitations: None reported

Admin destination

Open the admin page

Operational

Auto-admit internal users to meetings

Severity: Low Workload: Collaboration Compliance: — teams-internal-auto-admit
Your team joins meetings without lobby friction.
Operational

Auto-admit internal users to meetings

Severity: Low Effort: ~a few hours Scope: All users Workload: Collaboration Confidence: High confidence Evaluation: Read directly Compliance:

Your team joins meetings without lobby friction.

Expected

Internal users are admitted to meetings without waiting in the lobby.

Observed

Internal users are auto-admitted to meetings.

Why it matters

Teams is where decisions and files move quickly — weak meeting or guest defaults become an easy side door.

Value impact: Low
Recommended action

Set 'Who can bypass the lobby' to People in my org.

Evidence
Technical evidence

Data sources: Microsoft Teams / SharePoint Online PowerShell (powershell.bridge)

  • policies: {"ExecRecording": {"AllowAnonymousUsersToStartMeeting": false, "AllowCloudRecording": true, "AllowExternalParticipantGiveRequestControl": false, "AllowPSTNUsersToBypassLobby": false, "AutoAdmittedUsers": "EveryoneInCompany"}, "Global": {"AllowAnonymousUsersToStartMeeting": false, "AllowCloudRecording": false, "AllowExternalParticipantGiveRequestControl": false, "AllowPSTNUsersToBypassLobby": false, "AutoAdmittedUsers": "EveryoneInCompany"}}

Limitations: None reported

Admin destination

Open the admin page

Not licensed

Review Azure resource posture in Defender for Cloud

Severity: Info Workload: Azure Compliance: — az-cspm-out-of-scope
This protection does not appear to be included in the licenses we detected, so there is nothing to configure for it yet.
Not licensed

Review Azure resource posture in Defender for Cloud

Severity: Info Effort: ~days Scope: Tenant data Workload: Azure Confidence: High confidence Evaluation: Manual review Compliance:

This protection does not appear to be included in the licenses we detected, so there is nothing to configure for it yet.

Expected

Azure resource posture is continuously reviewed and remediated in Defender for Cloud.

Observed

Required capability not detected in tenant entitlements; check skipped.

Why it matters

Not reported

Value impact: Low
Recommended action

If you expected this capability, confirm the correct Microsoft plan is assigned, or talk to your licensing partner.

Evidence
Technical evidence

Data sources: graph.subscribedSkus

Limitations: None reported

Admin destination

Open the admin page

Technical details (product names, SKUs, check IDs)

Subscribed SKUs

Part number Status Units Service plans
SPE_E5 Enabled 87 / 100 AAD_PREMIUM_P2, MFA_PREMIUM, ADALLOM_S_O365, EQUIVIO_ANALYTICS, LOCKBOX_ENTERPRISE, MIP_S_CLP2, THREAT_INTELLIGENCE, DEFENDER_ENDPOINT_P2
MICROSOFT_SENTINEL Enabled 1 / 1 MICROSOFT_SENTINEL

Finding reference table

Status Check ID Technical title Workload Severity Confidence Evaluation mode
Action required id-ca-phishing-resistant-privileged Require strong sign-in for powerful admin roles identity critical High confidence direct
Action required id-app-risky-delegated-consent Review apps with broad permissions for everyone identity high High confidence direct
Action required id-app-user-consent-restricted Stop users from approving risky app permissions identity high High confidence direct
Action required id-auth-weak-methods-disabled Turn off SMS, voice, and email one-time codes identity high High confidence direct
Action required id-break-glass-exclusion No documented emergency admin account, or exclusions without a reason identity high High confidence direct
Action required id-ca-device-code-block Block device-code phishing sign-ins identity high High confidence direct
Action required id-ca-high-risk-signins Block suspicious high-risk sign-ins identity high High confidence direct
Action required id-ca-high-risk-users Block accounts Microsoft marks as high risk identity high High confidence direct
Action required id-ca-legacy-auth-block Block outdated sign-in methods identity high High confidence direct
Action required id-ca-phishing-resistant-all Require strong phishing-resistant sign-in for everyone identity high High confidence direct
Action required id-pim-activation-controls Keep privileged-role activation short, explained, and context-bound identity high High confidence direct
Action required id-pim-ga-activation-alert Alert when Global Admin is turned on identity high High confidence direct
Action required id-pim-ga-activation-approval Require approval to turn on Global Admin identity high High confidence direct
Action required id-pim-no-outside-pam Provision admin access only through just-in-time tools identity high High confidence direct
Action required id-pim-no-permanent-privileged Remove always-on powerful admin assignments identity high High confidence direct
Action required id-pim-unused Admin accounts still have "always on" superpowers identity high High confidence direct
Action required id-security-defaults-on Move from Security Defaults to customizable sign-in rules identity high High confidence direct
Action required pur-sensitivity-auto-labeling Turn on auto-labeling for sensitive content purview high High confidence direct
Action required id-access-reviews-scope Prove your admin-role reviews actually run and repeat identity medium High confidence direct
Action required id-access-reviews-unused Set up periodic access reviews for admins and guests identity medium High confidence direct
Action required id-ai-agents-risky-block Block risky AI agents when the control is available identity medium Low confidence — verify in portal direct
Action required id-app-admin-consent-workflow Turn on admin approval requests for apps identity medium High confidence direct
Action required id-app-expiring-credentials Rotate expiring app secrets and certificates identity medium High confidence direct
Action required id-app-password-addition-blocked Block legacy app passwords identity medium High confidence direct
Action required id-app-registration-admin-only Stop regular users from creating apps identity medium High confidence direct
Action required id-auth-authenticator-context Show app and location on Authenticator prompts identity medium High confidence direct
Action required id-ca-managed-devices Require company-managed devices for access identity medium High confidence direct
Action required id-ca-mfa-registration-managed Only allow multi-factor setup from managed devices identity medium High confidence direct
Action required id-dormant-privileged Powerful accounts that nobody uses are still switched on identity medium High confidence direct
Action required id-guest-directory-access-limited Limit what guests can see in your directory identity medium High confidence direct
Action required id-guest-inviter-restricted Stop everyone from inviting external guests identity medium High confidence direct
Action required id-pim-privileged-assignment-alert Alert when powerful roles are assigned identity medium High confidence direct
Action required pur-dlp-not-enforced Guardrails against accidental data leaks may not be active purview medium Low confidence — verify in portal proxy
Action required sen-automation-rules Automate part of the incident response sentinel medium Medium confidence direct
Action required sen-log-analytics-retention Keep security logs long enough to investigate sentinel medium Medium confidence direct
Action required sen-ueba-not-enabled Behavior-based detection may still be switched off sentinel medium Medium confidence direct
Action required teams-broadcast-not-always-record Stop live events from always recording collaboration medium High confidence direct
Action required teams-microsoft-apps-governed Restrict Microsoft apps to approved ones collaboration medium Medium confidence direct
Action required teams-recording-disabled Disable meeting recording by default collaboration medium High confidence direct
Action required id-password-never-expire Stop calendar-based password expiration identity low High confidence direct
Incomplete endpoint-enrollment-coverage Some paid device-management seats may not be enrolled endpoint high Low confidence — verify in portal direct
Incomplete id-ca-priv-gaps Powerful accounts may sign in without strong extra checks identity high High confidence direct
Incomplete mde-onboard-gap Some PCs may not be enrolled in advanced device protection endpoint high Low confidence — verify in portal direct
Incomplete mde-sensor-health Some device-protection sensors may be inactive or unhealthy endpoint high High confidence direct
Incomplete pur-dlp-locations-complete Apply DLP across Exchange SharePoint OneDrive Teams purview high Medium confidence direct
Incomplete sen-analytics-rule-coverage Your security command center may have few alarms turned on sentinel high Medium confidence direct
Incomplete sen-data-connectors Feed your security command center with real signals sentinel high Medium confidence direct
Incomplete id-app-ownerless-or-stale Clean up abandoned apps identity medium High confidence direct
Incomplete id-auth-methods-migration Finish consolidating sign-in method settings identity medium High confidence direct
Incomplete id-cross-tenant-defaults Tighten default access from unknown external tenants identity medium High confidence direct
Incomplete id-cross-tenant-mfa-trust Do not take other tenants' word for multi-factor auth identity medium High confidence direct
Incomplete id-ga-finer-roles Use narrower admin roles instead of Global Admin identity medium High confidence direct
Incomplete id-number-matching Make approvals require typing the on-screen number identity medium High confidence direct
Incomplete id-pim-other-activation-alert Alert when other powerful admin roles activate identity medium High confidence direct
Incomplete mdi-sensors-missing On-site directory servers may lack attack sensors defender medium Low confidence — verify in portal proxy
Incomplete teams-custom-apps-governed Restrict custom apps to approved ones collaboration medium Medium confidence direct
Incomplete teams-third-party-apps-governed Restrict third-party apps to approved ones collaboration medium Medium confidence direct
Not assessed exo-dmarc-agency-contact Add your mailbox to DMARC reports exchange high Low confidence — verify in portal direct
Not assessed exo-dmarc-federal-contact Add the federal DMARC report mailbox when required exchange high Low confidence — verify in portal direct
Not assessed id-logs-to-soc Confirm identity logs reach your security team identity high Low confidence — verify in portal manual
Not assessed mdo-alert-policies-enabled Confirm suspicious-email alerts are enabled defender high Low confidence — verify in portal manual
Not assessed mdo-audit-retention Confirm audit logs are retained long enough defender high Low confidence — verify in portal manual
Not assessed mdo-impersonation-partner-domains Protect key partner domains from look-alikes defender high Low confidence — verify in portal direct
Not assessed mdo-impersonation-users-protected Protect sensitive accounts from look-alike senders defender high Low confidence — verify in portal direct
Not assessed spo-anyone-link-expiration Make anyone links expire within 30 days collaboration high Low confidence — verify in portal direct
Not assessed spo-anyone-link-view Make anyone links view-only collaboration high Low confidence — verify in portal direct
Not assessed id-guest-invite-domains Limit guest invites to approved partner domains identity medium Low confidence — verify in portal manual
Not assessed id-idprotect-notify-high-risk Confirm high-risk account alerts reach security identity medium Low confidence — verify in portal manual
Not assessed pur-communication-compliance-readiness Confirm communication compliance is set up purview medium Low confidence — verify in portal manual
Operational endpoint-compliance-policy-assigned Device compliance rules may be missing or not assigned endpoint high High confidence direct
Operational endpoint-mde-connector Devices may not be flowing into advanced protection endpoint high High confidence direct
Operational endpoint-security-policy-coverage Core endpoint protections may be partially configured endpoint high High confidence direct
Operational ep-asr-rules Attack surface reduction rules may not be enforced on devices endpoint high High confidence direct
Operational ep-bitlocker-policy Device disks may not be encrypted endpoint high High confidence direct
Operational ep-compliance-enforcement Devices may be out of compliance despite policies endpoint high High confidence direct
Operational ep-mam-app-protection Work data on phones may be unprotected endpoint high High confidence direct
Operational ep-tamper-protection Tamper protection may be off on some devices endpoint high High confidence direct
Operational exo-dkim-enabled Turn on DKIM signing for every domain exchange high High confidence direct
Operational exo-dmarc-published Publish a DMARC record for every domain exchange high High confidence direct
Operational exo-dmarc-reject Set DMARC policy to reject exchange high High confidence direct
Operational exo-external-sender-warnings Flag mail that comes from outside exchange high High confidence direct
Operational exo-forwarding-external-disabled Stop automatic email forwarding to outside domains exchange high High confidence direct
Operational exo-mailbox-audit-enabled Keep mailbox auditing turned on exchange high High confidence direct
Operational exo-sharing-calendar-not-all-domains Limit calendar sharing to approved domains exchange high High confidence direct
Operational exo-sharing-contact-not-all-domains Limit contact sharing to approved domains exchange high High confidence direct
Operational exo-smtp-auth-disabled Turn off SMTP AUTH for the organization exchange high High confidence direct
Operational exo-spf-published Publish a strict SPF record for every domain exchange high High confidence direct
Operational id-ca-mfa-all-users Require multi-factor authentication for everyone identity high High confidence direct
Operational id-ga-count-bounds Keep Global Admin count between two and eight identity high High confidence direct
Operational id-idprotect-off Risk-based sign-in protection identity high High confidence direct
Operational id-priv-cloud-only Keep powerful admin accounts cloud-only identity high High confidence direct
Operational mdo-anti-spam-no-allowed-domains Remove broad anti-spam allow lists defender high High confidence direct
Operational mdo-connection-filter-no-ip-allow Clear the connection filter IP allow list defender high High confidence direct
Operational mdo-connection-filter-no-safe-list Turn off the connection filter safe list defender high High confidence direct
Operational mdo-impersonation-domains-owned Protect your own domains from look-alikes defender high High confidence direct
Operational mdo-malware-file-filter Block risky click-to-run attachments defender high High confidence direct
Operational mdo-malware-zap Turn on zero-hour auto purge for malware defender high High confidence direct
Operational mdo-outbound-spam-forwarding-block Block automatic mail forwarding to outside addresses defender high High confidence direct
Operational mdo-p2-policies-default Turn on Safe Links and Safe Attachments for everyone defender high High confidence direct
Operational mdo-safe-attachments-block Block malware found by Safe Attachments defender high High confidence direct
Operational mdo-safe-attachments-spo-teams Scan files in SharePoint OneDrive and Teams defender high High confidence direct
Operational mdo-safe-links-block-list Screen links in email Teams and Office apps defender high High confidence direct
Operational mdo-safe-links-click-through Block click-through on rewrapped links defender high High confidence direct
Operational mdo-safe-links-click-tracking Track clicks on rewritten links defender high High confidence direct
Operational mdo-safe-links-real-time-scan Scan download links in real time defender high High confidence direct
Operational mdo-safety-tips-enabled Show safety tips for unusual senders defender high High confidence direct
Operational mdo-spam-phish-not-inbox Keep spam and phishing out of inboxes defender high High confidence direct
Operational mdo-transport-rule-external-forward Remove mail-flow rules that copy mail outside defender high High confidence direct
Operational mdo-unified-audit-enabled Turn on unified audit logging defender high High confidence direct
Operational pbi-export-controls Turn off Power BI data export power_bi high High confidence direct
Operational pbi-publish-to-web-disabled Turn off Power BI publish to web power_bi high High confidence direct
Operational pp-dlp-all-environments Apply a DLP policy to every environment power_platform high High confidence direct
Operational pp-dlp-nondefault-envs Apply DLP to every non-default environment power_platform high High confidence direct
Operational pp-env-creation-admin-only Restrict environment creation to admins power_platform high High confidence direct
Operational pp-pages-creation-admin-only Restrict Power Pages creation to admins power_platform high High confidence direct
Operational pp-tenant-isolation-allowlist Configure an explicit tenant isolation allowlist power_platform high High confidence direct
Operational pp-tenant-isolation-enabled Turn on Power Platform tenant isolation power_platform high High confidence direct
Operational pur-default-and-mandatory-labels Require sensitivity labels on new content purview high High confidence direct
Operational pur-dlp-enforcement-block Block sharing of sensitive information with DLP purview high High confidence direct
Operational pur-dlp-notifications Notify users when they handle sensitive data purview high High confidence direct
Operational pur-dlp-policy-present Create an enforced DLP policy for sensitive data purview high High confidence direct
Operational pur-endpoint-dlp Protect data on endpoint devices purview high High confidence direct
Operational pur-insider-risk-readiness Confirm insider risk management is set up purview high High confidence direct
Operational pur-retention-policy-coverage Apply retention policies to email and files purview high High confidence direct
Operational pur-sensitivity-labels-published Publish sensitivity labels purview high High confidence direct
Operational spo-domain-restrictions Limit external sharing to approved partner domains collaboration high High confidence direct
Operational spo-onedrive-sharing-limited Restrict OneDrive sharing to existing guests collaboration high High confidence direct
Operational spo-sharing-capability-limited Restrict SharePoint sharing to existing guests collaboration high High confidence direct
Operational spo-unmanaged-device-access Block unmanaged devices from SharePoint and OneDrive collaboration high High confidence direct
Operational teams-anonymous-start-disabled Block anonymous users from starting meetings collaboration high High confidence direct
Operational teams-external-access-per-domain Allow external access only for specific domains collaboration high High confidence direct
Operational teams-guest-access-restricted Restrict who can join teams as a guest collaboration high High confidence direct
Operational teams-unmanaged-inbound-blocked Block unmanaged users from contacting you first collaboration high High confidence direct
Operational endpoint-compliance-noncompliance-action Nothing may happen when a device falls out of compliance endpoint medium High confidence direct
Operational endpoint-security-baseline No security baseline may be applied to devices endpoint medium High confidence direct
Operational id-app-certificate-lifetime Shorten long-lived app certificates identity medium High confidence direct
Operational id-app-password-lifetime Shorten long-lived app secrets identity medium High confidence direct
Operational mdo-mailbox-intelligence Turn on mailbox intelligence for impersonation detection defender medium High confidence direct
Operational mdo-quarantine-policy Restrict quarantine release and keep mail longer defender medium High confidence direct
Operational mdo-safe-documents Scan Office files from untrusted sources defender medium High confidence direct
Operational pbi-external-invite-disabled Turn off external Power BI invitations power_bi medium High confidence direct
Operational pbi-guest-access-disabled Turn off Power BI guest access power_bi medium High confidence direct
Operational pbi-python-r-visuals-disabled Turn off Python and R visuals power_bi medium High confidence direct
Operational pbi-resource-key-auth-blocked Block Power BI resource key authentication power_bi medium High confidence direct
Operational pbi-sensitivity-labels-enabled Turn on Power BI sensitivity labels power_bi medium High confidence direct
Operational pbi-sp-api-restricted Restrict Power BI API access for service principals power_bi medium High confidence direct
Operational pbi-sp-profiles-disabled Turn off service principal profiles power_bi medium High confidence direct
Operational pp-share-with-everyone-disabled Block sharing apps with everyone power_platform medium High confidence direct
Operational pp-trial-creation-admin-only Restrict trial environment creation to admins power_platform medium High confidence direct
Operational pur-ediscovery-readiness Confirm eDiscovery is set up purview medium High confidence direct
Operational spo-default-link-specific Default new links to specific people collaboration medium High confidence direct
Operational spo-default-link-view Default new links to view-only collaboration medium High confidence direct
Operational spo-verification-reauth Require verification-code reauthentication within 30 days collaboration medium High confidence direct
Operational teams-anonymous-lobby Hold anonymous and dial-in callers in the lobby collaboration medium High confidence direct
Operational teams-dialin-lobby Keep dial-in callers in the lobby collaboration medium High confidence direct
Operational teams-email-integration-disabled Disable channel email integration collaboration medium High confidence direct
Operational teams-external-control-disabled Block external participants from taking control collaboration medium High confidence direct
Operational teams-unmanaged-outbound-blocked Block internal users from contacting unmanaged accounts collaboration medium High confidence direct
Operational xdr-incident-readiness Cross-product incident correlation may not be active defender medium High confidence direct
Operational teams-internal-auto-admit Auto-admit internal users to meetings collaboration low High confidence direct
Not licensed az-defender-plan-enabled Turn on Defender for Cloud protection for your subscription azure high High confidence direct
Not licensed id-ca-workload-identity Apps and service accounts are not protected by risk-based sign-in rules identity high High confidence direct
Not licensed id-identity-protection-workload Confirm no app or automation account is compromised identity high High confidence direct
Not licensed id-entitlement-access-packages Access to apps, groups, and Teams is not yet lifecycle-governed identity medium High confidence direct
Not licensed pbi-premium-capacity-governance Premium capacity use and capacity admins are checked directly power_bi medium High confidence direct
Not licensed az-cspm-out-of-scope Review Azure resource posture in Defender for Cloud azure info High confidence manual