EIDTNT-010: Custom Domain Configuration

Platform
Entra ID / M365
Category
Entra ID Tenant Configuration
Severity
Info
Zero Trust pillar
Governance (weight 1)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Custom domains registered in the tenant define the email address and sign-in suffixes used by the organization. Unverified or unauthorized domains may indicate misconfiguration or an attacker attempting to establish a presence in the tenant. Each custom domain should be verified through DNS records and periodically reviewed to ensure all domains are still owned by the organization and that DNS verification records remain intact.

Recommended value

All custom domains verified, actively managed, and with DNS verification records intact

Remediation

Review all custom domains registered in Entra ID > Custom domain names and verify that each domain is still owned by the organization and that DNS verification records are properly configured. Remove any domains that are no longer in use or that cannot be verified as organization-owned. Ensure that domain DNS registrations are protected with registrar locks and that domain expiration dates are monitored to prevent unintentional domain loss.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EIDTNT-010
ScenarioExpected verdict
cleanPASS
known-badWARN
no-dataNot Assessed

Framework mappings

NIST SP 800-53
CM-8