⚔ Campaign Report

Unified Security Posture Assessment — Generated 2026-07-11 15:20:21 UTC — 599 checks across 3 platforms (Google Workspace, Active Directory, Entra ID / M365)
Scan ID: sample-campaign — Duration: 5m 0s — Guerrilla v2.0.0
0
OVERRUN
Campaign Score (0–100). Weighted assessment of 599 checks across 3 platforms.
0 Passed 599 Failed 0 Warnings 0 Skipped
599
Total Checks
0
Passed
599
Failed
0
Warnings
0
Skipped
84
Critical
241
High
196
Medium
46
Low

Security Maturity

Overall maturity: Level 1 of 5 — Initial

The lowest unmet control anchors the rating (CMMI-style scale: 1 Initial to 5 Optimized), so a single critical exposure caps the score until it is resolved.

To reach Level 2, address:

CategoryLevelMaturity
AD ACL & DelegationLevel 1Initial
OAuth & API SecurityLevel 1Initial
Intune / Endpoint ManagementLevel 1Initial
Exchange Online SecurityLevel 1Initial
Entra ID Tenant ConfigurationLevel 1Initial
Entra ID Privileged Identity ManagementLevel 1Initial
Entra ID Federation & Hybrid IdentityLevel 1Initial
Entra ID Conditional AccessLevel 1Initial
Entra ID Authentication Methods & MFALevel 1Initial
Entra ID Application & Service Principal SecurityLevel 1Initial
Email SecurityLevel 1Initial
Tier-0 Hygiene & Hybrid Identity SurfaceLevel 1Initial
Authentication & Access ControlsLevel 1Initial
Attack PathsLevel 1Initial
Unified Audit & LoggingLevel 1Initial
AD Trust RelationshipsLevel 1Initial
AD Adversary Tradecraft IndicatorsLevel 1Initial
AD Certificate ServicesLevel 1Initial
AD Privileged Account SecurityLevel 1Initial
AD Password & Lockout PoliciesLevel 1Initial
AD Network & Relay PreconditionsLevel 1Initial
AD Logon Scripts & Network SharesLevel 1Initial
Admin & User ManagementLevel 1Initial
AD Kerberos SecurityLevel 1Initial
AD Group PolicyLevel 1Initial
AD Domain & Forest ConfigurationLevel 1Initial
SharePoint & OneDrive SecurityLevel 2Managed
Power Platform SecurityLevel 2Managed
Microsoft Teams SecurityLevel 2Managed
Logging, Alerting & MonitoringLevel 2Managed
AD Logging & EDR PostureLevel 2Managed
Drive Security & Data ProtectionLevel 2Managed
Device & Endpoint ManagementLevel 2Managed
AD Stale & Obsolete ObjectsLevel 2Managed
Collaboration & Communication SecurityLevel 2Managed
Azure IAM & Resource SecurityLevel 2Managed
EIDSCA BaselineLevel 2Managed
Defender for Office 365Level 2Managed

Indicators of Exposure

599 open exposure(s), ranked by severity and blast radius.

Critical: 84 High: 241 Medium: 196 Low: 46

+ 587 more exposure(s) in the detailed findings below.

Attack-Path Cartography

Visual map of escalation routes to Tier-0. ⚑ Red = non-privileged start, amber = already-privileged, ★ gold = Tier-0 objective. Follow the arrows left to right.

WriteDaclWriteDaclGenericAllMemberOfGenericAllMemberOfGenericWriteMemberOfSAMPLE\BackupOperators⚑ SAMPLE\BackupOperatorsAdminSDHolder★ AdminSDHolderSAMPLE\jsmith⚑ SAMPLE\jsmithServiceDesk-OperatorsServiceDesk-OperatorsTier1-Server-AdminsTier1-Server-AdminsDomain Admins★ Domain AdminsSAMPLE\HelpDesk⚑ SAMPLE\HelpDeskWorkstation-AdminsWorkstation-AdminsAccount OperatorsAccount OperatorsBackup-AdminsBackup-AdminsAdministrators★ Administrators

Attack Paths to Tier-0

4 escalation path(s) reaching Tier-0 — 3 from NON-privileged principals (shown first, highest risk). Each arrow is a control or membership edge an attacker can traverse.

Platform Summary

Google Workspace
OVERRUN — 140 checks
0
Pass: 0 Fail: 140 Warn: 0 Skip: 0
Entra ID / M365
OVERRUN — 248 checks
0
Pass: 0 Fail: 248 Warn: 0 Skip: 0
Active Directory
OVERRUN — 211 checks
0
Pass: 0 Fail: 211 Warn: 0 Skip: 0

Category Scores by Platform

Active Directory (15 categories)
AD Domain & Forest Configuration 0
Pass: 0 Fail: 20 Warn: 0
AD Network & Relay Preconditions 0
Pass: 0 Fail: 10 Warn: 0
AD Stale & Obsolete Objects 0
Pass: 0 Fail: 11 Warn: 0
Tier-0 Hygiene & Hybrid Identity Surface 0
Pass: 0 Fail: 7 Warn: 0
AD Password & Lockout Policies 0
Pass: 0 Fail: 22 Warn: 0
AD Privileged Account Security 0
Pass: 0 Fail: 30 Warn: 0
AD Adversary Tradecraft Indicators 0
Pass: 0 Fail: 10 Warn: 0
AD Logging & EDR Posture 0
Pass: 0 Fail: 7 Warn: 0
AD Logon Scripts & Network Shares 0
Pass: 0 Fail: 11 Warn: 0
AD ACL & Delegation 0
Pass: 0 Fail: 16 Warn: 0
AD Trust Relationships 0
Pass: 0 Fail: 11 Warn: 0
AD Group Policy 0
Pass: 0 Fail: 24 Warn: 0
AD Certificate Services 0
Pass: 0 Fail: 19 Warn: 0
AD Kerberos Security 0
Pass: 0 Fail: 11 Warn: 0
Attack Paths 0
Pass: 0 Fail: 2 Warn: 0
Entra ID / M365 (15 categories)
SharePoint & OneDrive Security 0
Pass: 0 Fail: 5 Warn: 0
Unified Audit & Logging 0
Pass: 0 Fail: 3 Warn: 0
Azure IAM & Resource Security 0
Pass: 0 Fail: 10 Warn: 0
Entra ID Conditional Access 0
Pass: 0 Fail: 18 Warn: 0
Entra ID Tenant Configuration 0
Pass: 0 Fail: 16 Warn: 0
Power Platform Security 0
Pass: 0 Fail: 3 Warn: 0
Defender for Office 365 0
Pass: 0 Fail: 3 Warn: 0
Entra ID Authentication Methods & MFA 0
Pass: 0 Fail: 18 Warn: 0
EIDSCA Baseline 0
Pass: 0 Fail: 44 Warn: 0
Entra ID Federation & Hybrid Identity 0
Pass: 0 Fail: 13 Warn: 0
Microsoft Teams Security 0
Pass: 0 Fail: 8 Warn: 0
Exchange Online Security 0
Pass: 0 Fail: 50 Warn: 0
Entra ID Privileged Identity Management 0
Pass: 0 Fail: 14 Warn: 0
Entra ID Application & Service Principal Security 0
Pass: 0 Fail: 20 Warn: 0
Intune / Endpoint Management 0
Pass: 0 Fail: 23 Warn: 0
Google Workspace (8 categories)
Admin & User Management 0
Pass: 0 Fail: 22 Warn: 0
Authentication & Access Controls 0
Pass: 0 Fail: 18 Warn: 0
Drive Security & Data Protection 0
Pass: 0 Fail: 17 Warn: 0
Device & Endpoint Management 0
Pass: 0 Fail: 11 Warn: 0
Email Security 0
Pass: 0 Fail: 31 Warn: 0
OAuth & API Security 0
Pass: 0 Fail: 10 Warn: 0
Logging, Alerting & Monitoring 0
Pass: 0 Fail: 6 Warn: 0
Collaboration & Communication Security 0
Pass: 0 Fail: 25 Warn: 0

All Findings

Platform:
Status:
Severity:
Showing all findings
PlatformCheck IDCheck NameCategory SeverityStatusCurrent Value
Unknown ADACL-001 Critical Object ACL Audit AD ACL & Delegation Critical FAIL Disabled
Description
Access control lists on critical AD objects (Domain Root, AdminSDHolder, Schema, Configuration, Domain Controllers OU) must be audited for unauthorized or excessive permissions. Misconfigured ACLs on these objects can allow attackers to escalate privileges, modify directory services, or take full control of the domain
Current Value
Disabled
Recommended Value
Only default and explicitly authorized ACEs on critical AD objects; no unexpected principals with modify or full-control access
Remediation Steps
Review ACLs on critical objects using Get-Acl or dsacls.exe. Remove non-default ACEs that grant write, modify, or full-control permissions to unauthorized principals. Use AdminSDHolder to enforce consistent ACLs on protected groups. Document all intentional delegations.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 AC-6(5) AU-6
MITRE ATT&CK: T1222.001 T1003.006
Anssi: vuln_permissions_adminsdholder
Unknown ADACL-002 GenericAll Permissions on Critical Objects AD ACL & Delegation Critical FAIL Not configured (critical risk)
Description
GenericAll grants full control over an AD object including the ability to modify attributes, reset passwords, change group membership, and modify the DACL. Non-default principals with GenericAll on critical objects such as domain admins, domain controllers, or the domain root represent a direct path to domain compromise
Current Value
Not configured (critical risk)
Recommended Value
No non-default principals with GenericAll on critical AD objects
Remediation Steps
Enumerate ACLs on critical objects using PowerShell or BloodHound. Remove GenericAll ACEs for any principal that does not require full control. Replace with least-privilege delegated permissions where operational needs exist. Monitor for ACL changes using Directory Service Changes auditing (Event ID 5136).
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 AC-6(1) AC-3
MITRE ATT&CK: T1222.001 T1098
Anssi: vuln_permissions_genericall
Unknown ADACL-004 WriteDACL Permissions on Critical Objects AD ACL & Delegation Critical FAIL Not configured (critical risk)
Description
WriteDACL permission allows a principal to modify the discretionary access control list of an object, effectively granting the ability to assign any permission including GenericAll to themselves or others. This is a critical privilege escalation vector as it enables an attacker to grant themselves full control without directly having it
Current Value
Not configured (critical risk)
Recommended Value
No non-default principals with WriteDACL on critical AD objects
Remediation Steps
Enumerate WriteDACL permissions on all critical objects including the domain root, AdminSDHolder, GPO objects, and privileged group objects. Remove WriteDACL for non-default principals. Enable auditing of ACL changes (Event ID 5136) to detect unauthorized DACL modifications. Review changes regularly.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 AC-6(1) AC-3 AU-12
MITRE ATT&CK: T1222.001 T1098
Anssi: vuln_permissions_writedacl
Unknown ADACL-005 WriteOwner Permissions on Critical Objects AD ACL & Delegation Critical FAIL Not configured (critical risk)
Description
WriteOwner permission allows changing the owner of an AD object. The owner of an object implicitly has the ability to modify the DACL, making WriteOwner functionally equivalent to WriteDACL from an attack perspective. An attacker can take ownership and then grant themselves any desired permissions
Current Value
Not configured (critical risk)
Recommended Value
No non-default principals with WriteOwner on critical AD objects
Remediation Steps
Audit WriteOwner permissions on critical objects. Remove WriteOwner ACEs for non-default principals. Verify that object owners are appropriate privileged accounts. Enable ownership change auditing and monitor Event ID 4662 for WriteOwner operations.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 AC-6(1) AC-3
MITRE ATT&CK: T1222.001 T1098
Anssi: vuln_permissions_writeowner
Unknown ADACL-007 Excessive Delegation to Broad Groups AD ACL & Delegation Critical FAIL Unconstrained
Description
Delegation of sensitive permissions to broad groups such as Authenticated Users, Domain Users, or Everyone creates a wide attack surface where any compromised account can abuse the delegated rights. This is a common misconfiguration that dramatically reduces the effort required for privilege escalation
Current Value
Unconstrained
Recommended Value
No sensitive permissions delegated to Authenticated Users, Domain Users, Everyone, or other broad groups
Remediation Steps
Audit all ACLs for ACEs granted to well-known broad groups (S-1-5-11 Authenticated Users, Domain Users, Everyone, Domain Computers). Replace broad-group delegations with specific security groups containing only the required principals. Apply delegations at the narrowest OU scope possible.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 AC-6(1) AC-3(7)
MITRE ATT&CK: T1222.001 T1069.002
Anssi: vuln_delegation_broad_groups
Unknown ADACL-010 Extended Rights Audit AD ACL & Delegation Critical FAIL Disabled
Description
Extended rights in Active Directory include powerful operations such as DS-Replication-Get-Changes (DCSync), User-Force-Change-Password, and DS-Replication-Get-Changes-All. Unauthorized grants of these rights can lead to full domain compromise through credential theft or direct account takeover
Current Value
Disabled
Recommended Value
Extended rights limited to default and explicitly authorized principals; DCSync rights only on domain controllers
Remediation Steps
Enumerate all extended rights ACEs on the domain root and critical objects. Verify that DS-Replication-Get-Changes and DS-Replication-Get-Changes-All are only granted to domain controllers and authorized replication accounts. Remove any non-default extended rights grants. Monitor Event ID 4662 for extended rights usage.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 AC-6(5) AU-12
MITRE ATT&CK: T1003.006 T1098
Anssi: vuln_dcsync_rights
Unknown ADACL-015 Shadow Admins Detection AD ACL & Delegation Critical FAIL Excessive permissions found
Description
Shadow Admins are accounts that have indirect paths to Domain Admin-equivalent access through ACL chains but are not members of any privileged groups. These accounts bypass AdminSDHolder protection and traditional privileged access monitoring. For example, an account with WriteDACL on the Domain Admins group can grant itself membership without being flagged by group membership monitoring
Current Value
Excessive permissions found
Recommended Value
No shadow admin paths identified; all admin-equivalent access is through explicit privileged group membership
Remediation Steps
Use BloodHound or similar tools to identify ACL-based attack paths to Domain Admin-equivalent access. Remove unnecessary ACEs that create indirect privilege escalation paths. Ensure all administrative access is granted through protected group membership. Implement regular attack path analysis as part of security operations.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 AC-6(5) AC-2(7)
MITRE ATT&CK: T1222.001 T1098 T1069.002
Anssi: vuln_shadow_admins
Unknown ADACL-016 Attack Path Enumeration AD ACL & Delegation Critical FAIL Not configured (critical risk)
Description
Active Directory attack paths are chains of permissions, group memberships, and trust relationships that can be traversed to escalate from a low-privileged account to domain administrator. Comprehensive attack path enumeration identifies risks that individual ACL checks may miss, such as multi-hop escalation chains through intermediate objects
Current Value
Not configured (critical risk)
Recommended Value
No viable attack paths from unprivileged users to Tier 0 assets; all identified paths remediated or documented as accepted risk
Remediation Steps
Perform attack path analysis using tools such as BloodHound. Focus on shortest paths from Domain Users or Authenticated Users to Domain Admins, Enterprise Admins, and Domain Controllers. Break identified attack chains by removing the weakest link in each path. Prioritize paths that can be exploited without any special tools or elevated access.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 RA-5 CA-8
MITRE ATT&CK: T1222.001 T1069.002 T1098
Anssi: vuln_attack_paths
Unknown ADCS-002 ESC1 - Enrollee Supplies Subject Alternative Name AD Certificate Services Critical FAIL Vulnerable configuration
Description
ESC1 occurs when a certificate template allows the enrollee to specify a Subject Alternative Name (SAN) in the certificate request, has Client Authentication or any EKU that permits authentication, and allows enrollment by low-privileged users. An attacker can request a certificate with a SAN for any domain user including Domain Admins, then use the certificate to authenticate as that user
Current Value
Vulnerable configuration
Recommended Value
No certificate templates with CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT that allow low-privileged enrollment and have authentication EKUs
Remediation Steps
Identify templates where msPKI-Certificate-Name-Flag includes CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT (0x1), the template has Client Authentication or Smart Card Logon EKU, and enrollment is permitted for non-admin users. Remove the CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag, restrict enrollment permissions to privileged groups, or remove the authentication EKU. If SAN specification is operationally required, implement CA Manager approval.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 IA-5(2) CM-6
MITRE ATT&CK: T1649 T1556
Anssi: vuln_adcs_esc1
Unknown ADCS-003 ESC2 - Any Purpose Extended Key Usage AD Certificate Services Critical FAIL Vulnerable configuration
Description
ESC2 occurs when a certificate template specifies the Any Purpose EKU (OID 2.5.29.37.0) or no EKU at all (SubCA template equivalent). Certificates with Any Purpose EKU can be used for any purpose including client authentication, server authentication, and code signing. Combined with enrollee-controlled SANs or low enrollment requirements, this enables domain compromise
Current Value
Vulnerable configuration
Recommended Value
No certificate templates with Any Purpose EKU or empty EKU that allow low-privileged enrollment
Remediation Steps
Identify templates where pKIExtendedKeyUsage contains the Any Purpose OID (2.5.29.37.0) or is empty, and enrollment is permitted for non-admin users. Replace the Any Purpose EKU with specific required EKUs (e.g., Client Authentication only). If a SubCA template, restrict enrollment to Enterprise Admins only. Implement CA Manager approval for any remaining templates with broad EKUs.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 IA-5(2) CM-6
MITRE ATT&CK: T1649 T1556
Anssi: vuln_adcs_esc2
Unknown ADCS-006 ESC4 - Vulnerable Certificate Template ACLs AD Certificate Services Critical FAIL Vulnerable configuration
Description
ESC4 occurs when low-privileged users have write permissions on certificate template objects in AD, allowing them to modify template attributes to create an ESC1, ESC2, or ESC3 condition. An attacker with write access can add CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT, change the EKU, modify enrollment permissions, or alter other security-relevant attributes to enable certificate-based privilege escalation
Current Value
Vulnerable configuration
Recommended Value
No write permissions on certificate template objects for non-administrative principals
Remediation Steps
Enumerate ACLs on all certificate template objects in CN=Certificate Templates,CN=Public Key Services,CN=Services,CN=Configuration. Remove WriteDACL, WriteOwner, WriteProperty, and GenericAll/GenericWrite ACEs for non-administrative principals. Only Enterprise Admins and designated PKI administrators should have write access to template objects. Monitor for ACL changes on certificate template objects.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 AC-3 IA-5(2)
MITRE ATT&CK: T1649 T1222.001
Anssi: vuln_adcs_esc4
Unknown ADCS-007 ESC4 - Vulnerable Certificate Template Ownership AD Certificate Services Critical FAIL Vulnerable configuration
Description
If a certificate template object is owned by a non-administrative principal, that principal can modify the template's DACL to grant themselves write access and then modify the template to create exploitable conditions. Template ownership should be restricted to Enterprise Admins or the domain's PKI administration group
Current Value
Vulnerable configuration
Recommended Value
All certificate template objects owned by Enterprise Admins or designated PKI administrators
Remediation Steps
Check the Owner field on every certificate template object in CN=Certificate Templates,CN=Public Key Services,CN=Services,CN=Configuration. Transfer ownership of any incorrectly owned templates to Enterprise Admins using Set-Acl or the Security tab in adsiedit.msc. Investigate how non-admin accounts became owners to prevent recurrence.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 AC-3
MITRE ATT&CK: T1649 T1222.001
Anssi: vuln_adcs_esc4
Unknown ADCS-009 ESC6 - EDITF_ATTRIBUTESUBJECTALTNAME2 Flag AD Certificate Services Critical FAIL Vulnerable configuration
Description
When the EDITF_ATTRIBUTESUBJECTALTNAME2 flag is enabled on a CA, any certificate request can include a user-defined Subject Alternative Name regardless of the template configuration. This effectively makes every template on the CA vulnerable to ESC1-style attacks where an attacker specifies a SAN for a privileged user
Current Value
Vulnerable configuration
Recommended Value
EDITF_ATTRIBUTESUBJECTALTNAME2 flag disabled on all CA servers
Remediation Steps
Check the CA configuration using certutil -getreg policy\EditFlags on each CA server. If the EDITF_ATTRIBUTESUBJECTALTNAME2 flag (0x00040000) is set, remove it using certutil -setreg policy\EditFlags -EDITF_ATTRIBUTESUBJECTALTNAME2. Restart the CertSvc service after the change. Review all recently issued certificates for unexpected SANs that may indicate prior exploitation.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6 IA-5(2) AC-6
MITRE ATT&CK: T1649 T1556
Anssi: vuln_adcs_esc6
Unknown ADCS-010 ESC7 - Vulnerable CA ACLs AD Certificate Services Critical FAIL Vulnerable configuration
Description
ESC7 occurs when a non-admin principal has ManageCA or ManageCertificates permissions on the CA. ManageCA allows modifying CA configuration including enabling EDITF_ATTRIBUTESUBJECTALTNAME2 (creating an ESC6 condition). ManageCertificates allows approving pending certificate requests, bypassing CA Manager approval requirements on sensitive templates
Current Value
Vulnerable configuration
Recommended Value
ManageCA and ManageCertificates permissions restricted to designated CA administrators only
Remediation Steps
Review CA security permissions using certsrv.msc > Properties > Security tab or certutil -getacl. Remove ManageCA permissions from non-administrative principals. Remove ManageCertificates from any principal that is not an authorized certificate manager. Document all principals with CA management permissions. Implement separation of duties between CA administrators and certificate managers.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 AC-6(1) AC-5
MITRE ATT&CK: T1649
Anssi: vuln_adcs_esc7
Unknown ADCS-011 ESC8 - NTLM Relay to AD CS HTTP Endpoints AD Certificate Services Critical FAIL Not required
Description
ESC8 exploits the AD CS web enrollment (certsrv) and Certificate Enrollment Service (CES) HTTP endpoints that accept NTLM authentication. An attacker can coerce authentication from a domain controller or privileged account and relay the NTLM authentication to the CA HTTP endpoint to request a certificate as the relayed identity, leading to domain compromise
Current Value
Not required
Recommended Value
No HTTP-based enrollment endpoints; if required, enforce HTTPS with Extended Protection for Authentication (EPA) enabled
Remediation Steps
Identify all CA web enrollment endpoints using Get-CertificateEnrollmentService and checking IIS bindings. Disable HTTP-based enrollment endpoints and require HTTPS. Enable Extended Protection for Authentication on IIS to prevent NTLM relay. Alternatively, disable the web enrollment role entirely and use only the DCOM-based enrollment interface. Disable NTLM authentication on CA servers where possible.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-8 SC-23 IA-5(2)
MITRE ATT&CK: T1649 T1557 T1187
Anssi: vuln_adcs_esc8
Unknown ADDOM-005 Obsolete OS on Domain Controllers AD Domain & Forest Configuration Critical FAIL Not configured (critical risk)
Description
Domain controllers running end-of-life operating systems (Windows Server 2012 R2 or earlier) do not receive security updates and are vulnerable to known exploits. These represent critical infrastructure risk as compromising a DC gives full domain control
Current Value
Not configured (critical risk)
Recommended Value
All domain controllers running Windows Server 2019 or later with current patches
Remediation Steps
Plan migration of DCs running obsolete OS versions. Build new DCs on Windows Server 2022, transfer FSMO roles if needed, replicate, then demote and decommission old DCs. Prioritize this remediation as legacy DCs are actively targeted
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-2 CM-6 SA-22
MITRE ATT&CK: T1210 T1078.002
CIS Benchmark: 18.3.1
Anssi: R8
CisAd: 1.2.2
Unknown ADDOM-013 LDAP Signing Requirements AD Domain & Forest Configuration Critical FAIL Not required
Description
LDAP signing must be required on all domain controllers to prevent adversary-in-the-middle attacks on LDAP traffic. Without signing, attackers can intercept and modify LDAP queries and responses, potentially escalating privileges or exfiltrating data
Current Value
Not required
Recommended Value
LDAP server signing requirement set to 'Require signing' on all DCs
Remediation Steps
Configure via Group Policy: Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options > 'Domain controller: LDAP server signing requirements' = 'Require signing'. Apply to the Domain Controllers OU
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-8 SC-8(1) SC-23
MITRE ATT&CK: T1557
CIS Benchmark: 2.3.5.1
Anssi: R25
NsaAsd: LDAP-1
CisAd: 2.1.1
Unknown ADDOM-015 SMB Signing Requirements AD Domain & Forest Configuration Critical FAIL Not required
Description
SMB signing must be required on all domain controllers to prevent adversary-in-the-middle and relay attacks on SMB traffic. SMB relay attacks can be used to gain SYSTEM-level access on domain controllers, leading to full domain compromise
Current Value
Not required
Recommended Value
SMB signing required on all domain controllers and member servers
Remediation Steps
Configure via Group Policy: Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options > 'Microsoft network server: Digitally sign communications (always)' = Enabled. Apply to Domain Controllers OU and all server OUs
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-8 SC-8(1)
MITRE ATT&CK: T1557 T1021.002
CIS Benchmark: 2.3.8.1 2.3.8.2
Anssi: R26
NsaAsd: SMB-1
CisAd: 2.2.1
Unknown ADDOM-016 NTLMv1 Usage Detection AD Domain & Forest Configuration Critical FAIL Not required
Description
NTLMv1 is a severely weakened authentication protocol that can be cracked in seconds with modern hardware. Any NTLMv1 usage in the environment must be identified and eliminated as it exposes credentials to trivial offline attacks
Current Value
Not required
Recommended Value
Zero NTLMv1 authentication events detected; LAN Manager authentication level set to refuse NTLMv1
Remediation Steps
Enable NTLM auditing via Group Policy: Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options > 'Network security: Restrict NTLM' settings. Review event logs for NTLMv1 usage and remediate applications, then set 'Network security: LAN Manager authentication level' to 'Send NTLMv2 response only. Refuse LM & NTLM'
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(2) SC-8
MITRE ATT&CK: T1557 T1003
CIS Benchmark: 2.3.8.4
Anssi: R27
NsaAsd: NTLM-1
CisAd: 2.3.1
Unknown ADGPO-012 cPassword/GPP Password Detection AD Group Policy Critical FAIL Not configured (critical risk)
Description
Group Policy Preferences stored passwords (cPassword) are encrypted with a publicly known AES key published by Microsoft (MS14-025). Any domain user can read the XML files in SYSVOL containing these passwords and trivially decrypt them. This is one of the most common and easily exploitable Active Directory vulnerabilities
Current Value
Not configured (critical risk)
Recommended Value
No cPassword values present in any GPP XML files in SYSVOL
Remediation Steps
Search all SYSVOL GPO folders for XML files containing cpassword attributes in Groups.xml, Services.xml, Scheduledtasks.xml, DataSources.xml, Printers.xml, and Drives.xml. Remove all GPP items that contain stored passwords. Use LAPS, gMSA, or other modern credential management solutions instead. Apply MS14-025 patch to prevent new cPassword creation.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1) SC-28
MITRE ATT&CK: T1552.006 T1552.001
Anssi: vuln_gpp_passwords
Unknown ADKERB-002 Kerberoastable with Weak Encryption AD Kerberos Security Critical FAIL Disabled
Description
SPN-bearing user accounts configured to use RC4 or DES encryption are significantly easier to crack via Kerberoasting than those using AES. RC4 (ARCFOUR-HMAC-MD5) tickets can be cracked orders of magnitude faster than AES tickets on modern GPU hardware. Accounts explicitly configured with weak encryption types or lacking AES keys represent the highest-priority Kerberoasting targets
Current Value
Disabled
Recommended Value
All SPN-bearing accounts support AES256 encryption. No accounts restricted to RC4 or DES encryption types. msDS-SupportedEncryptionTypes includes AES flags on all service accounts
Remediation Steps
Query SPN-bearing user accounts and check their msDS-SupportedEncryptionTypes attribute. Accounts with value 0 (not set) default to RC4. Accounts with only RC4 (0x4) or DES (0x1, 0x2, 0x3) flags are vulnerable. Rotate passwords on all affected accounts after enabling AES support in the domain to generate AES keys. Set msDS-SupportedEncryptionTypes to include AES128 (0x8) and AES256 (0x10) flags
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1) SC-12
MITRE ATT&CK: T1558.003
Anssi: R36 R37
CisAd: 7.1.2
Unknown ADKERB-004 Unconstrained Delegation - Computers AD Kerberos Security Critical FAIL Unconstrained
Description
Computer accounts with unconstrained delegation (TrustedForDelegation) cache the TGT of any user who authenticates to them. If an attacker compromises such a machine, they can extract cached TGTs and impersonate any user including Domain Admins. Combined with the SpoolSample or PrinterBug coercion attack, an attacker can force a domain controller to authenticate and capture its TGT, leading to full domain compromise
Current Value
Unconstrained
Recommended Value
No computer accounts with unconstrained delegation except domain controllers (which inherently require it). All other delegation migrated to constrained or resource-based constrained delegation
Remediation Steps
Identify computers with unconstrained delegation using Get-ADComputer -Filter {TrustedForDelegation -eq $true} -Properties TrustedForDelegation. Exclude domain controllers from findings. For remaining computers, migrate to constrained delegation by identifying the specific services they need to delegate to, then configure msDS-AllowedToDelegateTo. Add sensitive accounts to the Protected Users group to prevent their TGTs from being cached. Mark high-value accounts as 'Account is sensitive and cannot be delegated'
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6
MITRE ATT&CK: T1558.001
Anssi: R35
CisAd: 7.3.1
Unknown ADKERB-005 Unconstrained Delegation - Users AD Kerberos Security Critical FAIL Unconstrained
Description
User accounts with unconstrained delegation are even more dangerous than computer accounts with the same setting, as user accounts are more easily compromised through credential theft, phishing, or password attacks. Any service running under a user account with unconstrained delegation can impersonate any user who authenticates to it, providing a direct path to domain compromise
Current Value
Unconstrained
Recommended Value
No user accounts with unconstrained delegation. All user account delegation migrated to constrained or resource-based constrained delegation
Remediation Steps
Identify users with unconstrained delegation using Get-ADUser -Filter {TrustedForDelegation -eq $true} -Properties TrustedForDelegation. This is almost never a legitimate configuration for user accounts. Remove the unconstrained delegation flag and configure constrained delegation to specific services if delegation is required. Rotate the account password immediately as the account may have been targeted
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6
MITRE ATT&CK: T1558.001
Anssi: R35
CisAd: 7.3.2
Unknown ADMIN-001 Super Admin Account Inventory Admin & User Management Critical FAIL Excessive permissions found
Description
All super admin accounts should be inventoried and reviewed. Super admins have unrestricted access to all organizational settings and data
Current Value
Excessive permissions found
Recommended Value
All super admin accounts documented and justified with clear business need
Remediation Steps
Admin Console > Directory > Users > Filter by admin role > Review all super admin accounts and remove unnecessary assignments
Compliance Mappings
NIST SP 800-53: AC-2(7) AC-6(1)
MITRE ATT&CK: T1078.004 T1087.004
CIS Benchmark: 4.1
Unknown ADNET-001 LDAP Signing Required on Domain Controllers AD Network & Relay Preconditions Critical FAIL Not required
Description
When domain controllers do not require LDAP signing, an attacker who can intercept or coerce LDAP traffic (for example via PetitPotam or any NTLM authentication trigger) can relay NTLM authentication to a DC's LDAP service and read or write directory data as the coerced principal. Enforcing LDAP signing closes the most common relay sink on a domain controller.
Current Value
Not required
Recommended Value
Default Domain Controllers Policy sets 'Domain controller: LDAP server signing requirements' to 'Require signing' (LDAPServerIntegrity = 2)
Remediation Steps
Edit the Default Domain Controllers Policy: Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options > 'Domain controller: LDAP server signing requirements' = 'Require signing'. Verify with: reg query HKLM\System\CurrentControlSet\Services\NTDS\Parameters /v LDAPServerIntegrity (should be 2). Microsoft has been hardening this default since 2020 (ADV190023) and will enforce it by default in future Windows Server releases.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-8 SC-23
MITRE ATT&CK: T1557.001
CisAd: 6.1.1
Unknown ADNET-003 SMB Server Signing Required (Domain Policy) AD Network & Relay Preconditions Critical FAIL Not required
Description
Without SMB signing required on the server side, an attacker who can position themselves in the network path or coerce SMB authentication can relay NTLM to SMB and execute file actions as the coerced principal. This is the classic relay sink for tools like ntlmrelayx; enforcing server-side signing closes it.
Current Value
Not required
Recommended Value
Default Domain Policy enables 'Microsoft network server: Digitally sign communications (always)' (RequireSecuritySignature on LanManServer = 1)
Remediation Steps
Edit the Default Domain Policy: Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options > 'Microsoft network server: Digitally sign communications (always)' = Enabled. Registry: HKLM\System\CurrentControlSet\Services\LanmanServer\Parameters\RequireSecuritySignature = 1. Windows 11 24H2 / Server 2025 enable this by default; older OS versions need explicit policy.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-8 SC-23
MITRE ATT&CK: T1557.001
CisAd: 6.2.1
Unknown ADNET-009 Print Spooler Service on Domain Controllers AD Network & Relay Preconditions Critical FAIL Not configured (critical risk)
Description
The Print Spooler service on a domain controller is the RPC endpoint exploited by the PrinterBug coercion technique (and a long list of follow-ons including the original CVE-2021-1675 PrintNightmare). When combined with any NTLM relay sink (ADCS Web, LDAP without signing, SMB without signing), it gives an unauthenticated attacker a primitive to coerce the DC machine account into authenticating to a target of their choice. Spooler is rarely needed on a DC.
Current Value
Not configured (critical risk)
Recommended Value
Print Spooler service is Disabled (start type 4) in the Default Domain Controllers Policy
Remediation Steps
Edit the Default Domain Controllers Policy: Computer Configuration > Policies > Windows Settings > Security Settings > System Services > Print Spooler > 'Define this policy setting' = Disabled. This propagates to every DC at the next gpupdate. Verify on each DC: Get-Service Spooler should show Status=Stopped, StartType=Disabled. If a DC also runs print services (it shouldn't), find another host for that role first.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-7
MITRE ATT&CK: T1210 T1557.001
CisAd: 6.4.1
Unknown ADPATH-001 Escalation Paths to Tier-0 Attack Paths Critical FAIL Not configured (critical risk)
Description
Models non-default control over Tier-0 objects (the domain root, AdminSDHolder, the Domain Controllers OU, and the GPO / Configuration / Schema containers) as privilege-escalation PATHS and reports the concrete takeover technique each one enables. Any non-default principal holding GenericAll / WriteDacl / WriteOwner / replication rights over one of these objects is a one-hop path to Domain Admin equivalence. It also flags non-default groups nested inside a Tier-0 group as escalation pivots — controlling such a group, or being added to it, confers the Tier-0 group's privileges. Full domain-wide transitive control-chain computation (low-priv user through a chain of GenericWrite/AddMember edges to Domain Admins) requires full-domain ACL collection, which is a separate roadmap item.
Affected Entities
Affected items (1):
  • SAMPLE\BackupOperators --[WriteDacl]--> AdminSDHolder => reaches all protected groups via SDProp
Current Value
Not configured (critical risk)
Recommended Value
No non-default principals have control over Tier-0 objects.
Remediation Steps
For each reported path, remove the attacker-controllable ACE from the target object's DACL (Active Directory Users and Computers > Advanced Security, or Set-Acl), or remove the principal from whatever group grants it. Only Tier-0 administrators should hold GenericAll/WriteDacl/WriteOwner or replication rights on the domain root, AdminSDHolder, the Domain Controllers OU, and the Policies/Configuration/Schema containers.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-5 AC-6
MITRE ATT&CK: T1098 T1222.001 T1484.001
Unknown ADPATH-002 Transitive Escalation Chains to Tier-0 Attack Paths Critical FAIL Not configured (critical risk)
Description
Computes MULTI-HOP privilege-escalation chains to Tier-0 by transitively following control (GenericAll / WriteDacl / WriteOwner / AddMember) and group-membership edges — for example HelpDesk --[WriteDacl]--> CORP-Admins --[MemberOf]--> Domain Admins. Complements ADPATH-001 (single-hop) by chaining edges of arbitrary length and reporting the shortest path per principal. Chain DEPTH is bounded by ACL-collection coverage: with the current six-critical-object collection most chains are one hop, so this check is typically clean today; the full-domain ACL collector (roadmap, live-gated) populates control edges over arbitrary objects and unlocks deep low-privilege-to-Domain-Admin chains. The engine itself chains arbitrary depth (BFS shortest-path, cycle-safe).
Affected Entities
Affected items (3):
  • SAMPLE\jsmith --[WriteDacl]--> ServiceDesk-Operators ==> ServiceDesk-Operators --[GenericAll]--> Tier1-Server-Admins ==> Tier1-Server-Admins --[MemberOf]--> Domain Admins => reaches domain admins (Tier-0 group)
  • SAMPLE\HelpDesk --[GenericAll]--> Workstation-Admins ==> Workstation-Admins --[MemberOf]--> Domain Admins => reaches domain admins (Tier-0 group)
  • Account Operators --[GenericWrite]--> Backup-Admins ==> Backup-Admins --[MemberOf]--> Administrators => reaches administrators (Tier-0 group)
Current Value
Not configured (critical risk)
Recommended Value
No transitive control chain leads a non-privileged principal to Tier-0.
Remediation Steps
For each chain, break the weakest link: remove the attacker-controllable ACE at the first hop (the non-privileged principal's control over the next object in the chain), or remove the nested group from the Tier-0 group. Re-run to confirm the chain is severed.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-5 AC-6
MITRE ATT&CK: T1098 T1222.001 T1484.001
Unknown ADPRIV-001 Domain Admins Enumeration AD Privileged Account Security Critical FAIL Excessive permissions found
Description
The Domain Admins group provides full administrative control over all domain-joined systems. Membership should be strictly limited and every member must have a documented business justification. Excessive membership dramatically increases the attack surface for credential theft and lateral movement
Current Value
Excessive permissions found
Recommended Value
Minimal membership (ideally 2-3 accounts maximum) with documented justification for each member. No day-to-day user accounts
Remediation Steps
Enumerate Domain Admins membership including nested groups using Get-ADGroupMember -Identity 'Domain Admins' -Recursive. Review each member for business need. Remove unnecessary members and migrate to delegated administration models. Ensure no regular user accounts are members
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6(1) AC-6(5) AC-2(7)
MITRE ATT&CK: T1078.002 T1069.002
CIS Benchmark: 9.2.1
Anssi: R2
CisAd: 4.1.1
Unknown ADPRIV-002 Enterprise Admins Enumeration AD Privileged Account Security Critical FAIL Excessive permissions found
Description
The Enterprise Admins group has forest-wide administrative privileges across all domains. This group should be empty during normal operations and only populated temporarily for forest-level changes. A compromised Enterprise Admin account leads to total forest compromise
Current Value
Excessive permissions found
Recommended Value
Empty during normal operations. Members added temporarily only for forest-level changes with documented approval
Remediation Steps
Enumerate Enterprise Admins membership using Get-ADGroupMember -Identity 'Enterprise Admins' -Recursive. Remove all permanent members. Implement a just-in-time access process for forest-level operations that temporarily adds and removes members with full audit logging
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6(1) AC-6(5) AC-2(2)
MITRE ATT&CK: T1078.002 T1069.002
CIS Benchmark: 9.2.2
Anssi: R2
CisAd: 4.1.2
Unknown ADPRIV-010 Privileged Users Password Never Expires AD Privileged Account Security Critical FAIL Never
Description
Privileged accounts with the 'Password Never Expires' flag set are exempt from password rotation policies. If such an account is compromised, the attacker retains persistent access indefinitely as the password will never be forced to change
Current Value
Never
Recommended Value
No privileged accounts with Password Never Expires flag set. All privileged accounts subject to password rotation policy of 60 days or less
Remediation Steps
Identify privileged accounts with PasswordNeverExpires using Get-ADUser -Filter {PasswordNeverExpires -eq $true -and AdminCount -eq 1}. Clear the flag and ensure these accounts are covered by an appropriate password policy. Implement FGPP for privileged accounts with a 60-day maximum password age
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1) AC-2
MITRE ATT&CK: T1078.002
CIS Benchmark: 1.1.4
Anssi: R36
CisAd: 4.3.1
Unknown ADPRIV-011 Privileged Users Password Not Required AD Privileged Account Security Critical FAIL Excessive permissions found
Description
The PASSWD_NOTREQD flag allows an account to have a blank password, completely bypassing password policy. On privileged accounts, this is catastrophic as it allows unauthenticated access to highly privileged resources
Current Value
Excessive permissions found
Recommended Value
No privileged accounts with PASSWD_NOTREQD flag set
Remediation Steps
Identify accounts using Get-ADUser -Filter {PasswordNotRequired -eq $true -and AdminCount -eq 1}. Clear the PASSWD_NOTREQD flag immediately and set a strong password on all identified accounts. Investigate how this flag was set as it may indicate compromise
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1) AC-2
MITRE ATT&CK: T1078.002
Anssi: R36
CisAd: 4.3.2
Unknown ADPRIV-012 Privileged Users No Kerberos Pre-Auth AD Privileged Account Security Critical FAIL Excessive permissions found
Description
Accounts with Kerberos pre-authentication disabled are vulnerable to AS-REP Roasting, where an attacker can request encrypted material offline without any authentication and crack it to recover the account password. On privileged accounts, this provides a direct path to domain compromise
Current Value
Excessive permissions found
Recommended Value
No privileged accounts with 'Do not require Kerberos preauthentication' flag set
Remediation Steps
Identify accounts using Get-ADUser -Filter {DoesNotRequirePreAuth -eq $true -and AdminCount -eq 1}. Enable Kerberos pre-authentication immediately on all privileged accounts. Rotate passwords on affected accounts as they may have already been compromised via AS-REP Roasting
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(2) AC-2
MITRE ATT&CK: T1558.004
Anssi: R36
CisAd: 4.3.3
Unknown ADPRIV-013 Privileged Users Reversible Encryption AD Privileged Account Security Critical FAIL Disabled
Description
Accounts with 'Store password using reversible encryption' enabled store passwords in a format that can be decrypted to plaintext. This is equivalent to storing passwords in cleartext and allows any attacker with access to the AD database to retrieve the actual password
Current Value
Disabled
Recommended Value
No accounts with reversible encryption enabled, especially not privileged accounts
Remediation Steps
Identify accounts using Get-ADUser -Filter {AllowReversiblePasswordEncryption -eq $true -and AdminCount -eq 1}. Clear the flag and force an immediate password change on all affected accounts. Review password policies to ensure they do not require reversible encryption
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1) SC-28
MITRE ATT&CK: T1003.006 T1078.002
CIS Benchmark: 1.1.1
Anssi: R36
CisAd: 4.3.4
Unknown ADPRIV-016 Privileged Accounts Weak Passwords AD Privileged Account Security Critical FAIL Excessive permissions found
Description
Privileged accounts with weak or commonly used passwords are trivially compromised through password spraying, dictionary attacks, or credential stuffing. A weak password on a Domain Admin account can lead to complete domain compromise within minutes
Current Value
Excessive permissions found
Recommended Value
All privileged account passwords meet a minimum of 25 characters and are not found in common password dictionaries
Remediation Steps
Test privileged account password strength by comparing NT hashes against known weak password lists (using tools like DSInternals). Force immediate password changes on any accounts with weak passwords. Implement FGPP requiring 25+ character passwords for privileged accounts
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1110.001 T1110.003 T1078.002
Anssi: R37
CisAd: 4.5.1
Unknown ADPRIV-020 AdminSDHolder Protected Object Audit AD Privileged Account Security Critical FAIL Disabled
Description
AdminSDHolder is a security mechanism that overwrites ACLs on protected objects (privileged users and groups) every 60 minutes via SDProp. Modifications to the AdminSDHolder ACL propagate to all protected objects, making it a high-value target for persistence. Unauthorized ACEs on AdminSDHolder grant backdoor access to all privileged accounts
Current Value
Disabled
Recommended Value
AdminSDHolder ACL contains only default entries with no unauthorized or unexpected ACEs
Remediation Steps
Review the AdminSDHolder ACL at CN=AdminSDHolder,CN=System,DC=domain using Get-ACL or ADSIEdit. Compare against the documented baseline. Remove any non-default ACEs immediately. Monitor for modifications to AdminSDHolder as part of ongoing security monitoring
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 AC-3 AU-6
MITRE ATT&CK: T1222.001 T1078.002
Anssi: R6
CisAd: 4.7.1
Unknown ADPRIV-022 krbtgt Password Age AD Privileged Account Security Critical FAIL Never expires
Description
The krbtgt account password is used to encrypt and sign all Kerberos tickets in the domain. If compromised, an attacker can create Golden Tickets granting unrestricted access to any resource for any duration. The krbtgt password should be rotated at least every 180 days and immediately after any suspected compromise
Current Value
Never expires
Recommended Value
krbtgt password changed within the last 180 days. Rotated twice (to invalidate all existing tickets) after any suspected compromise
Remediation Steps
Check krbtgt password age using Get-ADUser krbtgt -Properties PasswordLastSet. Reset the password twice (with sufficient time between resets for replication to complete) to invalidate all existing tickets. Use the krbtgt reset script from Microsoft to safely perform the rotation. Schedule regular rotation every 180 days
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1) SC-12
MITRE ATT&CK: T1558.001 T1550.003
CIS Benchmark: 18.3.1
Anssi: R39
CisAd: 4.8.1
Unknown ADPRIV-023 krbtgt Account Exposure Assessment AD Privileged Account Security Critical FAIL Not configured (critical risk)
Description
The krbtgt account configuration should be assessed for exposure indicators including supported encryption types, delegation settings, and SPNs. Any misconfiguration increases the risk of Golden Ticket and other Kerberos-based attacks
Current Value
Not configured (critical risk)
Recommended Value
krbtgt account configured with AES256 encryption only, no delegation, and no additional SPNs beyond the default kadmin/changepw
Remediation Steps
Review the krbtgt account properties including msDS-SupportedEncryptionTypes, delegation settings, and SPNs. Ensure AES256 is the primary encryption type. Verify no delegation flags are set. Check for unexpected SPNs that could indicate compromise or misconfiguration
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-12 SC-13
MITRE ATT&CK: T1558.001 T1550.003
Anssi: R39
CisAd: 4.8.2
Unknown ADPRIV-028 Users with DCSync Rights AD Privileged Account Security Critical FAIL Not configured (critical risk)
Description
DCSync allows replication of password data from Active Directory, including all user hashes. Accounts with 'Replicating Directory Changes All' and 'Replicating Directory Changes' rights can extract every password hash in the domain without touching a DC. Only domain controller computer accounts and the default admin account should have these rights
Current Value
Not configured (critical risk)
Recommended Value
Only domain controller computer accounts and default administrator account have replication rights. No additional users or groups granted DCSync permissions
Remediation Steps
Audit the domain root ACL for 'Replicating Directory Changes' and 'Replicating Directory Changes All' using (Get-ACL 'AD:\DC=domain,DC=com').Access | Where-Object {$_.ObjectType -match '1131f6a[a-d]'}. Remove any unauthorized entries immediately. Investigate whether unauthorized accounts have already performed DCSync
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6(1) AC-3
MITRE ATT&CK: T1003.006
CIS Benchmark: 18.3.1
Anssi: R41
CisAd: 4.11.1
Unknown ADPWD-010 Users with Blank Passwords AD Password & Lockout Policies Critical FAIL Not configured (critical risk)
Description
Accounts with the PASSWD_NOTREQD flag can have blank passwords, completely bypassing all password policies. This flag is sometimes set inadvertently during account creation scripts. Any account with a blank password can be accessed by anyone who knows the username
Current Value
Not configured (critical risk)
Recommended Value
No enabled accounts with blank passwords or PASSWD_NOTREQD flag
Remediation Steps
Identify accounts using Get-ADUser -Filter {PasswordNotRequired -eq $true -and Enabled -eq $true}. Clear the PASSWD_NOTREQD flag and set a strong password on all identified accounts immediately. Review account creation scripts and processes to prevent this flag from being set in the future
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1) IA-2
MITRE ATT&CK: T1078.002 T1078
Anssi: R36
CisAd: 5.5.1
Unknown ADSCRIPT-004 Hardcoded Credentials in Scripts AD Logon Scripts & Network Shares Critical FAIL Not configured (critical risk)
Description
Logon scripts frequently contain hardcoded credentials including passwords for network drive mappings, service accounts, database connections, and API keys. These credentials are readable by all authenticated users through the NETLOGON share and represent a trivial credential harvesting opportunity for attackers
Current Value
Not configured (critical risk)
Recommended Value
No hardcoded credentials, passwords, or API keys in any NETLOGON or SYSVOL scripts
Remediation Steps
Scan all scripts in NETLOGON and SYSVOL for patterns indicating credentials: password, passwd, pwd, credential, secret, apikey, token, connectionstring, and similar keywords. Replace hardcoded credentials with secure alternatives such as Windows Credential Manager, gMSA accounts, or encrypted configuration files with restricted access. Rotate any credentials found in scripts immediately.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1) SC-28 IA-5(7)
MITRE ATT&CK: T1552.001 T1059
Anssi: vuln_cleartext_password
Unknown ADSCRIPT-006 Plaintext Passwords in Scripts AD Logon Scripts & Network Shares Critical FAIL Not configured (critical risk)
Description
Scripts that contain plaintext passwords in net use commands, database connection strings, or variable assignments expose credentials to every authenticated domain user who can read the NETLOGON share. This includes passwords for service accounts, database accounts, and network resources that may provide lateral movement paths
Current Value
Not configured (critical risk)
Recommended Value
No plaintext passwords in any script files; all authentication uses integrated security or secure credential storage
Remediation Steps
Search all script files for patterns such as 'net use * /user:', password assignments in PowerShell or batch, connection strings with Password= or Pwd=, and WScript.Network.MapNetworkDrive calls with credentials. Replace all plaintext credential usage with Windows integrated authentication, Credential Manager, or gMSA accounts. Rotate all exposed passwords immediately.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1) SC-28 IA-5(7)
MITRE ATT&CK: T1552.001 T1059
Anssi: vuln_cleartext_password
Unknown ADSCRIPT-007 World-Writable Script Permissions AD Logon Scripts & Network Shares Critical FAIL Not configured (critical risk)
Description
Individual script files in NETLOGON or SYSVOL that grant write or modify permissions to non-administrative users can be modified by any attacker with domain credentials. Even if the share-level permissions are correct, overly permissive file-level NTFS permissions on individual scripts create a code execution opportunity
Current Value
Not configured (critical risk)
Recommended Value
All script files in NETLOGON and SYSVOL writable only by Domain Admins and SYSTEM; no write access for Domain Users or Authenticated Users
Remediation Steps
Enumerate NTFS permissions on every file in the NETLOGON share and SYSVOL scripts folders. Identify files where Domain Users, Authenticated Users, Everyone, or other broad groups have Write, Modify, or Full Control permissions. Reset permissions using icacls to grant Read and Execute to Authenticated Users and Full Control to Domain Admins and SYSTEM only.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-3 AC-6 CM-5
MITRE ATT&CK: T1222.001 T1059
Anssi: vuln_writable_scripts
Unknown ADTIER-001 Azure AD Connect Sync Account (MSOL_) Audit Tier-0 Hygiene & Hybrid Identity Surface Critical FAIL Disabled
Description
When Azure AD Connect installs in Express mode it creates a domain account named MSOL_<random-hex> and grants it Replicating Directory Changes + Replicating Directory Changes All on the domain naming context — i.e. DCSync rights. The account is effectively Tier-0 but it lives in the default Users container by default, has a 10-year password expiry, and rarely shows up in privileged-group enumeration tools because it gets its power via direct ACL rather than group membership. Compromise of this account is functionally a domain takeover.
Current Value
Disabled
Recommended Value
All MSOL_ accounts are inventoried, password rotated within the last 180 days, placed in a Tier-0 OU with restricted logon rights, and the AAD Connect server itself is hardened as a Tier-0 system.
Remediation Steps
Locate the MSOL_ account: Get-ADUser -Filter {sAMAccountName -like 'MSOL_*'}. Confirm it has DCSync rights: dsacls 'DC=domain,DC=com' | findstr MSOL_. Move it to a Tier-0 admin OU. Rotate the password using the AAD Connect tooling (do NOT reset via standard tooling — use Add-ADSyncADDSConnectorAccount in the ADSync PowerShell module on the AAD Connect server). Apply a logon-restriction GPO so the account can only log on locally to the AAD Connect server itself. Treat the AAD Connect host as Tier-0 — restrict who can RDP/admin it.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 IA-5
MITRE ATT&CK: T1003.006 T1078.004
CisAd: 8.1.1
Unknown ADTIER-002 Backup Software Service Accounts in Privileged Groups Tier-0 Hygiene & Hybrid Identity Surface Critical FAIL Excessive permissions found
Description
Backup software (Veeam, Commvault, Rubrik, Cohesity, NAKIVO, Backup Exec, Vembu, Acronis) typically asks for a service account with very high permissions. Documentation often suggests Domain Admin for ease of setup, and many admins comply. Once an attacker compromises the backup server (a frequent ransomware initial-access vector), they inherit Domain Admin via the service account. This is the #1 ransomware escalation path in 2023-2025 incident response data.
Current Value
Excessive permissions found
Recommended Value
No backup-software service accounts are members of Domain Admins, Enterprise Admins, Schema Admins, or Backup Operators. Use vendor-documented least-privilege accounts and isolated backup credentials.
Remediation Steps
Identify the backup product in use and follow its least-privilege guide (Veeam: backup-server local admin only + AD account with object read; Rubrik: dedicated service principal in cloud-only role; etc.). Remove the backup account from Domain Admins. Migrate to a gMSA where supported. Place the backup server in a Tier-1 OU with restricted logon rights. If full DA is genuinely required for a specific workload, document it and isolate that part of backup to its own account separate from the main one.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6
MITRE ATT&CK: T1078.002
CisAd: 8.2.1
Unknown ADTIER-004 Configuration Management Service Accounts in Privileged Groups Tier-0 Hygiene & Hybrid Identity Surface Critical FAIL Excessive permissions found
Description
Configuration-management platforms (SCCM/MECM, Intune Connector, Jamf, KACE, Lansweeper, ManageEngine, Ivanti, BigFix) push software to every endpoint by definition — they are already a privileged lateral-movement platform. SCCM in particular has well-known abuse primitives (Network Access Account exposure, NTLM coercion to site server, client push). A config-mgmt service account in Domain Admins gives an attacker who lands on any managed endpoint the keys to the domain.
Current Value
Excessive permissions found
Recommended Value
Config-management service accounts are scoped to their documented minimum rights and never in Domain Admins / Enterprise Admins. SCCM Network Access Account is a non-privileged dedicated identity.
Remediation Steps
Identify the config-mgmt product and review service account rights. For SCCM: ensure the Network Access Account is non-privileged (NOT a Domain Admin); ensure the site server's machine account is not a Domain Admin; review hierarchy service accounts for least privilege. Move site servers and management points to a Tier-0 OU with restricted logons.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6
MITRE ATT&CK: T1072 T1078.002
CisAd: 8.2.3
Unknown ADTRADE-001 Group Policy Preferences cpassword Leftovers in SYSVOL AD Adversary Tradecraft Indicators Critical FAIL Misconfigured
Description
From 2008 to May 2014, Group Policy Preferences let admins push scheduled tasks, local user passwords, mapped drives, and services using a 'cpassword' field — encrypted with an AES-256 key Microsoft publicly documented. The fix in MS14-025 disabled the cpassword field in NEW preferences but left existing ones in SYSVOL untouched. Every red-team engagement still finds these. Any authenticated domain user can read SYSVOL, grab the cpassword, and decrypt it offline. If you find anything here, treat every credential exposed as compromised and rotate it.
Current Value
Misconfigured
Recommended Value
Zero cpassword attributes anywhere under \\domain\SYSVOL\domain\Policies\**\*.xml.
Remediation Steps
Scan SYSVOL: Get-ChildItem -Path \\<domain>\SYSVOL\<domain>\Policies -Recurse -Include *.xml | Select-String 'cpassword'. For each match: (1) rotate the password of the account whose credential is exposed (the username is in the same XML), (2) audit logs for use of that credential since the preference was created, (3) delete the GPP preference once the new credential is in place. Microsoft's KB2962486 has the cleanup guidance.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5 AC-6
MITRE ATT&CK: T1552.006
CisAd: 10.1.1
Unknown ADTRADE-006 Shadow Credentials (msDS-KeyCredentialLink) on Privileged Principals AD Adversary Tradecraft Indicators Critical FAIL Excessive permissions found
Description
The msDS-KeyCredentialLink attribute holds public keys used for Windows Hello for Business / passwordless PKINIT logon. An attacker with write access to this attribute on a target can add their OWN key pair (Whisker / pyWhisker) and then request a Kerberos TGT as that account using the matching private key — a stealthy persistence and impersonation technique known as 'shadow credentials'. Any unexpected key credential on a Tier-0 object (a domain admin, a domain controller, or any adminCount=1 account) should be treated as a potential backdoor until proven to be a legitimate WHfB enrollment.
Current Value
Excessive permissions found
Recommended Value
No unrecognised msDS-KeyCredentialLink values on privileged/Tier-0 principals; every key maps to a known WHfB/passwordless enrollment.
Remediation Steps
For each flagged principal, inspect the key credentials (Get-ADObject -Properties msDS-KeyCredentialLink, or the DSInternals Get-ADKeyCredential cmdlet) and correlate each device key with a legitimate Windows Hello for Business enrollment. Remove any entry you cannot attribute to a sanctioned enrollment. Restrict who can write msDS-KeyCredentialLink (audit Key Admins / Enterprise Key Admins and OU/object DACLs granting that write). Reset the affected accounts if compromise is suspected.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5 AC-6 AU-6
MITRE ATT&CK: T1556 T1098
Anssi: vuln1_permissions_keycredentiallink
CisAd: 6.2.1
Unknown ADTRADE-007 BadSuccessor dMSA Migration Escalation Surface AD Adversary Tradecraft Indicators Critical FAIL Not configured (critical risk)
Description
Windows Server 2025 introduced delegated Managed Service Accounts (dMSA, object class msDS-DelegatedManagedServiceAccount) with a migration feature: a dMSA can be marked as superseding an existing account, after which it inherits that account's privileges and Kerberos keys. The 2024-disclosed 'BadSuccessor' technique abuses this: a principal that can merely CREATE a dMSA in an OU (CreateChild on the dMSA class, or broad write/GenericAll over the OU) can create one, point it at a privileged account, and inherit its keys — escalating to that account without ever holding rights over it directly. This check inventories OUs where a non-Tier-0 principal holds that capability.
Current Value
Not configured (critical risk)
Recommended Value
No non-Tier-0 principal can create or write a delegated MSA (msDS-DelegatedManagedServiceAccount) in any OU.
Remediation Steps
On each flagged OU, remove CreateChild (for the msDS-DelegatedManagedServiceAccount class), GenericAll, WriteDacl, and WriteOwner from non-administrative principals. Audit delegated OU permissions broadly — the same ACEs that enable BadSuccessor also enable other object-creation abuses. Until patched/mitigated, monitor creation of msDS-DelegatedManagedServiceAccount objects (4662/5137 events). This check SKIPs on forests whose schema predates Server 2025.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 AC-3
MITRE ATT&CK: T1098 T1078.002
Anssi: vuln1_delegation_dmsa
CisAd: 6.3.1
Unknown ADTRUST-004 SID Filtering Status AD Trust Relationships Critical FAIL Not configured (critical risk)
Description
SID filtering removes SIDs from foreign domains in authentication tokens, preventing SID history injection attacks. Without SID filtering, an attacker who compromises a trusted domain can craft tickets containing privileged SIDs (such as Enterprise Admins) from your domain, achieving full compromise
Current Value
Not configured (critical risk)
Recommended Value
SID filtering (quarantine) enabled on all external and forest trusts
Remediation Steps
Verify SID filtering status using 'netdom trust /domain:trusted.domain /Quarantine'. Enable SID filtering with 'netdom trust /domain:trusted.domain /Quarantine:Yes'. Note: SID filtering is enabled by default on external trusts but must be verified on forest trusts where it may have been deliberately disabled
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-4 AC-6
MITRE ATT&CK: T1134.005
CIS Benchmark: 18.3.1
Anssi: R32
CisAd: 3.2.1
Unknown ADTRUST-005 SID History Abuse Detection AD Trust Relationships Critical FAIL Not configured (critical risk)
Description
SID history is intended for domain migrations but can be abused to inject privileged SIDs into user tokens across trust boundaries. Attackers who compromise a trusted domain can add Enterprise Admin or Domain Admin SIDs to the SID history of any account they control
Current Value
Not configured (critical risk)
Recommended Value
No accounts with SID history values referencing privileged groups. SID history cleaned up after all migrations complete
Remediation Steps
Search for accounts with SID history using Get-ADUser -Filter {SIDHistory -like '*'} -Properties SIDHistory. Identify any SID history entries that reference privileged groups (Domain Admins, Enterprise Admins, etc.). Clean up SID history after migration using Remove-ADUser with the SIDHistory parameter. Enable SID filtering on trusts
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 AC-6(1)
MITRE ATT&CK: T1134.005
Anssi: R32
CisAd: 3.2.2
Unknown AUTH-001 2SV Enforcement Authentication & Access Controls Critical FAIL Not configured (critical risk)
Description
Two-step verification (2SV/MFA) should be enforced for all users to prevent account takeover via stolen credentials
Affected Entities
Active users without 2SV enforced (4):
  • jsmith@sample.org
  • akumar@sample.org
  • mchen@sample.org
  • rlopez@sample.org
Current Value
Not configured (critical risk)
Recommended Value
Enforced for all organizational units
Remediation Steps
Admin Console > Security > Authentication > 2-step verification > Set Enforcement to 'On'
Compliance Mappings
NIST SP 800-53: IA-2(1) IA-2(2)
MITRE ATT&CK: T1078.004
CIS Benchmark: 1.1
Unknown AUTH-012 Super Admin 2SV Enrollment Authentication & Access Controls Critical FAIL Excessive permissions found
Description
All super admin accounts must have 2SV enrolled. Super admins have unrestricted access to all settings and data
Affected Entities
Super admins without 2SV enrolled (5):
  • jsmith@sample.org
  • akumar@sample.org
  • mchen@sample.org
  • rlopez@sample.org
  • tokafor@sample.org
Current Value
Excessive permissions found
Recommended Value
100% of super admins enrolled in 2SV
Remediation Steps
Admin Console > Reporting > User Reports > Security > Filter by admin status > Ensure all super admins have 2SV enrolled
Compliance Mappings
NIST SP 800-53: IA-2(1) IA-2(11)
MITRE ATT&CK: T1078.004
CIS Benchmark: 1.12
Unknown EIDAPP-002 App Registrations with High-Risk API Permissions Entra ID Application & Service Principal Security Critical FAIL Unreviewed permissions
Description
Application registrations with high-risk API permissions such as Mail.ReadWrite, Files.ReadWrite.All, RoleManagement.ReadWrite.Directory, or Application.ReadWrite.All can be exploited to read sensitive data, modify directory objects, or escalate privileges tenant-wide. Attackers who compromise an application with these permissions gain broad access equivalent to or exceeding that of a Global Administrator. All high-risk permissions must be reviewed and justified with compensating controls.
Current Value
Unreviewed permissions
Recommended Value
No application registrations with high-risk API permissions unless documented with business justification and compensating controls
Remediation Steps
Review all application registrations in Entra ID > Applications > App registrations and examine the API permissions tab for each. Identify applications with high-privilege permissions such as Directory.ReadWrite.All, Mail.ReadWrite, or RoleManagement.ReadWrite.Directory. Remove unnecessary permissions and replace broad scopes with the most restrictive permissions that still meet application requirements.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 AC-6(1)
MITRE ATT&CK: T1098.002
CisM365: 5.3.1
Unknown EIDAPP-004 First-Party Microsoft Service Principals with Added Credentials Entra ID Application & Service Principal Security Critical FAIL Not configured (critical risk)
Description
Attackers add credentials to Microsoft first-party service principals to establish persistent backdoor access that blends in with legitimate Microsoft services. Because first-party service principals are trusted by default and often hold extensive permissions, added credentials on these objects provide stealthy, high-privilege persistence that is rarely audited. Any credential additions to first-party Microsoft service principals should be treated as a critical indicator of compromise.
Current Value
Not configured (critical risk)
Recommended Value
No credentials (secrets or certificates) added to any first-party Microsoft service principals
Remediation Steps
Enumerate all service principals where the appOwnerOrganizationId matches the Microsoft tenant ID (f8cdef31-a31e-4b4a-93e4-5f571e91255a) and check for added key credentials or password credentials. Remove any credentials found on first-party Microsoft service principals immediately as these are almost certainly unauthorized. Investigate the audit logs to determine who added the credentials and when, treating this as a potential security incident.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5
MITRE ATT&CK: T1098.001
Unknown EIDAPP-005 Service Principals with High Privileges and Added Credentials Entra ID Application & Service Principal Security Critical FAIL Excessive permissions found
Description
Service principals that combine high-privilege API permissions or directory role assignments with added client credentials represent the highest-risk application objects in the tenant. An attacker who obtains these credentials can authenticate non-interactively with elevated permissions, bypassing MFA and Conditional Access controls entirely. This combination of privilege and credential access is a primary persistence and lateral movement technique in cloud-based attacks.
Current Value
Excessive permissions found
Recommended Value
No service principals with both high-privilege permissions and added credentials unless documented with mandatory compensating controls
Remediation Steps
Cross-reference service principals that hold high-privilege API permissions or directory role assignments against those with added key or password credentials. For each match, validate the business necessity and either remove excessive permissions or migrate to managed identity authentication that eliminates the need for stored credentials. Implement certificate-based authentication with short-lived certificates where managed identities are not feasible.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 IA-5
MITRE ATT&CK: T1098.001
Unknown EIDAPP-014 Application Impersonation Role Holders Entra ID Application & Service Principal Security Critical FAIL Permanent assignments found
Description
The ApplicationImpersonation role in Exchange Online grants the ability to impersonate any mailbox in the organization, allowing full read and write access to all email without the mailbox owner's knowledge. This role is frequently abused in business email compromise and data exfiltration attacks because a single compromised account with this role can access the entire organization's email. Assignments should be extremely limited, time-bound, and continuously monitored.
Current Value
Permanent assignments found
Recommended Value
No permanent ApplicationImpersonation role assignments. Any required assignments must be scoped to specific mailboxes and time-limited
Remediation Steps
Review Exchange Online role assignments to identify all principals holding the ApplicationImpersonation role using Get-ManagementRoleAssignment in Exchange Online PowerShell. Remove all unnecessary assignments immediately and replace broad impersonation grants with scoped assignments restricted to specific mailboxes where required. Implement monitoring alerts for any new ApplicationImpersonation role assignments and conduct monthly reviews of existing assignments.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6(5)
MITRE ATT&CK: T1098.002
Unknown EIDAUTH-002 MFA Registration Status for All Users Entra ID Authentication Methods & MFA Critical FAIL Not enforced
Description
All users should be registered for multi-factor authentication to prevent account compromise through stolen or guessed credentials. Accounts without MFA registration are the primary target for credential-based attacks including password spraying and phishing. Unregistered users represent critical gaps in your identity security posture.
Current Value
Not enforced
Recommended Value
100% of active users registered for MFA
Remediation Steps
Review MFA registration status via Entra ID > Protection > Authentication methods > User registration details. Enforce MFA registration through Conditional Access policies requiring MFA for all users. Set a registration deadline and communicate requirements to unregistered users.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-2(1) IA-2(2)
MITRE ATT&CK: T1078 T1110
CisM365: 5.2.2.1
Unknown EIDAUTH-005 Users with No MFA Methods Registered Entra ID Authentication Methods & MFA Critical FAIL Not enforced
Description
Users without any registered MFA methods cannot satisfy MFA challenges and represent critical security gaps. These accounts are fully exposed to credential-based attacks including password spraying, phishing, and brute-force attacks. Immediate remediation is required to ensure all active accounts have at least one MFA method enrolled.
Current Value
Not enforced
Recommended Value
Zero active users without at least one MFA method registered
Remediation Steps
Query user registration details via Entra ID > Protection > Authentication methods > User registration details to identify users with no methods. Enforce MFA registration through a Conditional Access policy targeting unregistered users. Use Temporary Access Pass to assist users who need to bootstrap their MFA registration.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-2(1) IA-2(2)
MITRE ATT&CK: T1078 T1110
CisM365: 5.2.2.1
Unknown EIDAUTH-007 FIDO2 Key ROCA Vulnerability Check Entra ID Authentication Methods & MFA Critical FAIL Vulnerable configuration
Description
The ROCA (Return of Coppersmith's Attack) vulnerability (CVE-2017-15361) affects RSA key generation in Infineon TPM firmware used in certain FIDO2 security keys, allowing private key recovery from public keys. Affected keys produce weak RSA key pairs that can be factored, completely undermining the security of the authentication credential. Keys with vulnerable firmware must be identified and replaced immediately.
Current Value
Vulnerable configuration
Recommended Value
No FIDO2 keys with ROCA-vulnerable Infineon TPM firmware in use
Remediation Steps
Identify FIDO2 keys using Infineon TPMs by checking the AAGUID values against known vulnerable models. Test registered keys using ROCA detection tools to confirm vulnerability status. Replace all affected keys with patched firmware versions or alternative hardware and revoke the old key registrations in Entra ID.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-2(6) RA-5
MITRE ATT&CK: T1556
Unknown EIDCA-006 Break-Glass Account CA Exclusion Validation Entra ID Conditional Access Critical FAIL Vulnerable configuration
Description
Emergency access (break-glass) accounts must be excluded from Conditional Access policies to ensure access during outages or misconfigurations, but these exclusions must be tightly controlled. Failure to properly configure break-glass exclusions can result in complete lockout during critical incidents or create unmonitored backdoor accounts.
Current Value
Vulnerable configuration
Recommended Value
Exactly two break-glass accounts excluded from all CA policies with monitoring, alerts, and regular validation
Remediation Steps
Verify that dedicated break-glass accounts exist, are excluded from all Conditional Access policies, and are not used for daily operations. Configure Azure Monitor alerts to trigger on any sign-in activity from break-glass accounts. Test break-glass account access quarterly and store credentials securely in a physical safe or hardware security module.
Compliance Mappings
NIST SP 800-53: AC-2(2)
MITRE ATT&CK: T1078.004
CisM365: 1.1.4
Unknown EIDCA-007 MFA Enforcement via Conditional Access Entra ID Conditional Access Critical FAIL Not enforced
Description
Multi-factor authentication should be required for all users through Conditional Access policies to prevent credential-based attacks. Without MFA enforcement, compromised passwords alone grant full access to organizational resources, making this the single most impactful control against account takeover.
Current Value
Not enforced
Recommended Value
MFA required for 100% of users across all cloud applications via Conditional Access
Remediation Steps
Create a Conditional Access policy targeting all users and all cloud applications with a grant control requiring multifactor authentication. Verify the policy covers all user types including guests and external collaborators. Monitor the sign-in logs to confirm MFA is being prompted and review the CA insights workbook for coverage gaps.
Compliance Mappings
NIST SP 800-53: IA-2(1) IA-2(2)
MITRE ATT&CK: T1078 T1110
CisM365: 5.2.2.1
Unknown EIDCA-008 Legacy Authentication Blocking via CA Entra ID Conditional Access Critical FAIL Not configured (critical risk)
Description
Legacy authentication protocols such as IMAP, POP3, SMTP, and ActiveSync do not support modern authentication or MFA, making them a primary attack vector for password spray and brute-force attacks. Blocking legacy authentication through Conditional Access is essential to prevent these protocols from bypassing MFA controls.
Current Value
Not configured (critical risk)
Recommended Value
All legacy authentication protocols blocked via Conditional Access for all users
Remediation Steps
Create a Conditional Access policy targeting all users and all cloud applications with the client apps condition set to Exchange ActiveSync clients and other clients, then set the grant control to block access. Verify the policy is in enabled state and monitor sign-in logs for any remaining legacy authentication attempts. Coordinate with application owners to migrate any remaining legacy protocol dependencies to modern authentication.
Compliance Mappings
NIST SP 800-53: IA-2 AC-17(2)
MITRE ATT&CK: T1078 T1110.001
CisM365: 5.2.2.3
Unknown EIDFED-003 Federation Signing Certificate Issuer/Subject Mismatch Entra ID Federation & Hybrid Identity Critical FAIL Not required
Description
A mismatch between the issuer and subject fields of a federation signing certificate is a strong indicator of a potential Golden SAML attack, where an attacker has replaced the legitimate signing certificate with one they control. In a Golden SAML attack, the attacker generates a self-signed certificate with arbitrary issuer/subject values and configures it as the federation trust signing certificate, enabling them to forge SAML tokens for any user. Any issuer/subject mismatch that does not align with the expected certificate authority chain requires immediate investigation.
Current Value
Not required
Recommended Value
Federation signing certificate issuer and subject fields match expected organizational PKI chain with no unexpected self-signed certificates
Remediation Steps
Extract the signing certificate from each federated domain trust and compare the issuer and subject fields against your expected organizational PKI hierarchy. Investigate any certificates where the issuer does not match your known certificate authority or where the subject contains unexpected values. If a mismatch is detected, treat this as a potential security incident, rotate the federation signing certificate immediately, and review audit logs for unauthorized federation configuration changes.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(2)
MITRE ATT&CK: T1556.006
Unknown EIDPIM-004 Privileged Role Assignments to Guest Users Entra ID Privileged Identity Management Critical FAIL Unrestricted
Description
Guest or external users with privileged Entra ID role assignments present a significant supply chain and third-party risk. These accounts originate from external organizations and are not subject to the same security controls, password policies, or monitoring as internal accounts. A compromised guest account with administrative privileges can lead to full tenant compromise while being difficult to detect through normal internal security monitoring
Current Value
Unrestricted
Recommended Value
No guest or external users assigned to any privileged Entra ID roles
Remediation Steps
Review all privileged role assignments and identify any members with a userType of Guest. Remove privileged role assignments from all guest accounts immediately. If external administrative access is required, provision dedicated cloud-only accounts within the tenant under full organizational control instead of using guest invitations
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6(5) IA-8
MITRE ATT&CK: T1078.004
CisM365: 1.1.2
Unknown EIDPIM-006 Privileged Users Without MFA Entra ID Privileged Identity Management Critical FAIL Not enforced
Description
Privileged accounts without multi-factor authentication registered are exposed to credential-based attacks including password spraying, phishing, and brute force. A compromised privileged account without MFA provides an attacker with immediate administrative access using only a stolen password. All accounts with privileged role assignments must have strong MFA methods registered and enforced through Conditional Access policies
Current Value
Not enforced
Recommended Value
100% of privileged users with MFA registered and enforced via Conditional Access
Remediation Steps
Review MFA registration status for all privileged users via Entra ID > Users > Per-user MFA or the Authentication Methods activity report. Ensure a Conditional Access policy requires MFA for all directory role assignments. Contact any privileged users lacking MFA registration and enforce registration within a defined deadline
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-2(1) IA-2(2)
MITRE ATT&CK: T1078 T1110
CisM365: 5.2.2.1
Unknown EIDPIM-012 Emergency Access Account Validation Entra ID Privileged Identity Management Critical FAIL Not configured (critical risk)
Description
Emergency access (break-glass) accounts are critical safeguards that ensure administrative access to the tenant when normal authentication mechanisms fail, such as during MFA outages, Conditional Access misconfigurations, or identity provider failures. At least 2 break-glass accounts should exist, be cloud-only, excluded from all Conditional Access policies, and protected with strong authentication such as FIDO2 keys stored securely. Without properly configured break-glass accounts, an organization risks permanent lockout from its own tenant
Current Value
Not configured (critical risk)
Recommended Value
At least 2 emergency access accounts that are cloud-only, permanently assigned Global Administrator, excluded from all Conditional Access policies, with FIDO2 or long complex passwords stored securely
Remediation Steps
Create at least 2 dedicated emergency access accounts that are cloud-only (not synced), assign permanent Global Administrator role, exclude from all Conditional Access policies, and configure with FIDO2 security keys or very long complex passwords stored in a physical safe. Configure monitoring alerts for any sign-in activity on these accounts and test the break-glass procedure quarterly
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-2(2) CP-2
MITRE ATT&CK: T1078.004
CisM365: 1.1.4
Unknown EIDTNT-007 Security Defaults Enabled/Disabled Status Entra ID Tenant Configuration Critical FAIL Disabled
Description
Security defaults provide a baseline set of identity security mechanisms including MFA registration requirements, MFA challenges for administrators, and blocking legacy authentication. Organizations using Conditional Access policies should have security defaults disabled to avoid conflicts, but tenants without Conditional Access that also have security defaults disabled have no baseline protection against common identity attacks. This check verifies that either security defaults or equivalent Conditional Access policies are actively protecting the tenant.
Current Value
Disabled
Recommended Value
Security defaults enabled for tenants without Conditional Access. For tenants with Conditional Access, security defaults disabled with equivalent or stronger CA policies in place
Remediation Steps
Check whether security defaults are enabled in Entra ID > Properties > Manage security defaults. If security defaults are disabled, verify that Conditional Access policies provide equivalent or stronger protection including MFA for all users, legacy authentication blocking, and MFA for administrative actions. If neither security defaults nor equivalent Conditional Access policies are in place, enable security defaults immediately as a baseline protection measure.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-2 AC-2
MITRE ATT&CK: T1078
CisM365: 1.1.1
Unknown EMAIL-001 SPF Record Validation Email Security Critical FAIL Not configured
Description
Sender Policy Framework (SPF) records must exist and be valid for all domains. SPF prevents email spoofing by specifying which mail servers are authorized to send email on behalf of a domain
Current Value
Not configured
Recommended Value
Valid v=spf1 record published for all domains with -all or ~all qualifier
Remediation Steps
Admin Console > Apps > Google Workspace > Gmail > Authenticate email > Publish SPF record: v=spf1 include:_spf.google.com ~all for each domain
Compliance Mappings
NIST SP 800-53: SI-8 SC-7
MITRE ATT&CK: T1566.001 T1566.002
CIS Benchmark: 2.1
Unknown EMAIL-002 DKIM Signing Enabled Email Security Critical FAIL Disabled
Description
DomainKeys Identified Mail (DKIM) signing must be enabled and valid for all domains. DKIM provides cryptographic proof that email content has not been tampered with in transit
Current Value
Disabled
Recommended Value
DKIM signing enabled with valid key published for all domains
Remediation Steps
Admin Console > Apps > Google Workspace > Gmail > Authenticate email > Generate DKIM key and publish DNS record for each domain
Compliance Mappings
NIST SP 800-53: SI-8 SC-8
MITRE ATT&CK: T1566.001 T1566.002
CIS Benchmark: 2.2
Unknown EMAIL-003 DMARC Policy Audit Email Security Critical FAIL Disabled
Description
Domain-based Message Authentication, Reporting and Conformance (DMARC) policy must be set to reject or quarantine for all domains. A DMARC policy of none provides no protection against spoofing
Current Value
Disabled
Recommended Value
DMARC policy set to reject or quarantine for all domains
Remediation Steps
Publish DMARC TXT record at _dmarc.<domain> with p=reject or p=quarantine. Start with p=none for monitoring, then escalate to quarantine and finally reject
Compliance Mappings
NIST SP 800-53: SI-8 SC-7
MITRE ATT&CK: T1566.001 T1566.002 T1036.005
CIS Benchmark: 2.3
Unknown EMAIL-017 Spoofing and Authentication Protection Email Security Critical FAIL Not configured (critical risk)
Description
Spoofing and authentication protections guard against domain spoofing, employee name spoofing, and unauthenticated email from domains that appear similar to the organization
Current Value
Not configured (critical risk)
Recommended Value
All spoofing and authentication protections enabled with quarantine action
Remediation Steps
Admin Console > Apps > Google Workspace > Gmail > Safety > Spoofing and authentication > Enable all protections: domain spoofing, employee name spoofing, inbound email spoofing, and unauthenticated email
Compliance Mappings
NIST SP 800-53: SI-8 IA-9
MITRE ATT&CK: T1566.001 T1566.002 T1036.005
CIS Benchmark: 2.17
Unknown INTUNE-008 Windows Defender/Antivirus policy audit Intune / Endpoint Management Critical FAIL Disabled
Description
Windows Defender Antivirus is the primary endpoint protection agent on Windows devices and must be properly configured to provide real-time protection, cloud-delivered protection, and sample submission. Disabled or weakened antivirus settings leave devices vulnerable to malware infections that can lead to data theft, ransomware, and lateral movement. Attackers frequently attempt to tamper with or disable antivirus as a first step in an attack chain.
Current Value
Disabled
Recommended Value
Real-time protection enabled, cloud-delivered protection enabled, automatic sample submission enabled, tamper protection enabled
Remediation Steps
Deploy an Intune antivirus policy that enforces real-time protection, cloud-delivered protection, automatic sample submission, and tamper protection on all managed Windows devices. Verify that PUA (Potentially Unwanted Application) protection is enabled and that scheduled scans are configured for at least weekly full scans. Monitor the Defender antivirus agent status across the fleet and investigate any devices reporting disabled protection or outdated definitions.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-3
MITRE ATT&CK: T1562.001
Unknown INTUNE-010 Endpoint Detection and Response configuration Intune / Endpoint Management Critical FAIL Not enrolled
Description
Endpoint Detection and Response (EDR) capabilities provided by Microsoft Defender for Endpoint enable advanced threat detection, investigation, and automated response on managed devices. Without EDR onboarding and proper sensor configuration, security teams lack visibility into sophisticated attacks that bypass traditional antivirus. EDR is critical for detecting fileless malware, living-off-the-land techniques, and advanced persistent threats.
Current Value
Not enrolled
Recommended Value
All managed devices onboarded to Defender for Endpoint with EDR in block mode; sample sharing and cloud protection enabled
Remediation Steps
Verify that all managed Windows devices are onboarded to Microsoft Defender for Endpoint through the Intune EDR policy and that the sensor health status shows as active. Enable EDR in block mode to provide additional blocking capabilities even when a third-party antivirus is the primary engine. Review the device inventory in the Defender portal to identify devices with sensor health issues and remediate connectivity or configuration problems preventing successful onboarding.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-4
MITRE ATT&CK: T1562.001
Unknown INTUNE-018 PowerShell script deployment audit Intune / Endpoint Management Critical FAIL Disabled
Description
Intune allows administrators to deploy PowerShell scripts to managed Windows devices, which execute with SYSTEM-level privileges by default. Malicious or poorly written scripts deployed through this channel can compromise device security, exfiltrate data, or install unauthorized software across the entire fleet. Every deployed script must be reviewed for security implications and tracked for authorized deployment.
Current Value
Disabled
Recommended Value
All deployed scripts reviewed and approved through change management; scripts run in user context where possible; script content documented
Remediation Steps
Audit all PowerShell scripts currently deployed through Intune and review their content for security risks such as hardcoded credentials, unrestricted remote downloads, or excessive permission changes. Ensure that scripts run in the user context rather than SYSTEM context wherever possible and that script execution is limited to the minimum required device scope. Implement a change management process for script deployment that includes peer review of script content and formal approval before production deployment.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6
MITRE ATT&CK: T1059.001
Unknown INTUNE-023 Multi-admin approval for destructive device actions Intune / Endpoint Management Critical FAIL Excessive permissions found
Description
Microsoft Intune supports multi-admin approval policies that require a second administrator to approve high-impact operations such as bulk device wipe, bulk device retire, and script deployments before they execute. Without multi-admin approval, a single compromised admin account can trigger mass device wipes across the entire organization. This check verifies that operation approval policies are configured to protect against destructive actions performed by a compromised or rogue admin account.
Current Value
Excessive permissions found
Recommended Value
Multi-admin approval enabled for destructive operations including bulk device wipe, bulk device retire, and script deployment actions
Remediation Steps
Navigate to Microsoft Intune admin center > Tenant administration > Multi-admin approval. Create an approval policy that requires a second admin to approve destructive operations. At minimum, enable approval for: Bulk device actions (Wipe, Retire, Delete), Apps deployment to large groups, and Script deployments. Assign an approval group containing trusted senior administrators who will review and approve these requests. Consider implementing an expedited approval process for emergency scenarios.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-3 AC-6 CM-5
MITRE ATT&CK: T1485 T1561
CIS Benchmark: 16.7
Unknown M365AUDIT-001 Unified Audit Log enabled Unified Audit & Logging Critical FAIL Disabled
Description
The Microsoft 365 Unified Audit Log records user and administrator activities across Exchange Online, SharePoint Online, OneDrive, Azure AD, Microsoft Teams, and other services, providing the foundational data source for security investigations. If unified auditing is disabled, the organization loses visibility into critical activities such as mailbox access, file sharing, permission changes, and administrative operations. Disabling the audit log is a known adversary technique used to cover tracks after compromising a tenant.
Current Value
Disabled
Recommended Value
Unified Audit Log enabled organization-wide with no per-user or per-mailbox overrides disabling auditing
Remediation Steps
Verify that unified audit logging is enabled by running Get-AdminAuditLogConfig and confirming that UnifiedAuditLogIngestionEnabled is set to True. If auditing is disabled, enable it immediately and investigate the audit history to determine when and by whom it was disabled, as this may indicate a security compromise. Set up a monitoring alert to detect any future attempts to disable the unified audit log and restrict the permissions required to modify audit log settings to a minimal set of trusted administrators.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-2 AU-3
MITRE ATT&CK: T1562.008
CisM365: 3.1.1
Unknown M365EXO-006 DKIM/DMARC/SPF validation Exchange Online Security Critical FAIL Not configured
Description
DKIM, DMARC, and SPF are email authentication protocols that verify sender identity and prevent domain spoofing. Without all three protocols properly configured, attackers can send emails that appear to originate from your organization's domain, enabling highly convincing phishing campaigns against employees, customers, and partners. Complete email authentication is a fundamental defense against business email compromise and domain impersonation.
Current Value
Not configured
Recommended Value
SPF record with -all (hard fail); DKIM signing enabled for all domains; DMARC policy set to reject or quarantine with aggregate reporting enabled
Remediation Steps
Verify that each organizational domain has a valid SPF record ending with -all (hard fail) that includes all authorized sending sources. Enable DKIM signing in Exchange Online for all custom domains and publish the DKIM CNAME records in DNS. Publish a DMARC record for each domain starting with a policy of none for monitoring, then progressively move to quarantine and finally reject once legitimate sending sources are confirmed, with aggregate reports configured for ongoing visibility.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-8
MITRE ATT&CK: T1566.001
CisM365: 2.1.9
Unknown M365EXO-007 Auto-forwarding policy Exchange Online Security Critical FAIL Allowed to external
Description
Automatic email forwarding to external addresses is a common data exfiltration technique used by attackers after compromising a mailbox. An attacker can set up auto-forwarding rules to silently copy all incoming email to an external address, maintaining persistent access to sensitive communications even after their access is revoked. Organizations should block external auto-forwarding by default and audit any existing forwarding rules.
Current Value
Allowed to external
Recommended Value
External auto-forwarding blocked via anti-spam outbound policy; existing forwarding rules audited and approved
Remediation Steps
Configure the outbound spam filter policy to set automatic forwarding to 'Automatic - System-controlled' or 'Off' to block external auto-forwarding at the transport level. Audit all existing mailbox forwarding rules and SMTP forwarding configurations to identify any unauthorized external forwarding that may indicate compromise. Remove any unapproved forwarding rules and implement monitoring alerts to detect new forwarding rule creation using the unified audit log.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-4
MITRE ATT&CK: T1114.003
CisM365: 2.1.6
Unknown M365EXO-015 SPF policy published for each domain (MS.EXO.2.2) Exchange Online Security Critical FAIL Non-compliant
Description
SCuBA MS.EXO.2.2 requires that an SPF policy be published for each domain, designating only approved addresses as senders and failing all others. SPF is published as a DNS TXT record rather than an Exchange Online setting. A missing SPF record, or one ending in +all or ?all, allows adversaries to spoof the FROM field of mail appearing to originate from the organization, enabling convincing phishing.
Current Value
Non-compliant
Recommended Value
A single SPF TXT record per domain that lists all approved senders and ends with -all (hard fail)
Remediation Steps
Publish a single SPF TXT record for each accepted domain that enumerates all approved sending sources and ends with -all to hard-fail unauthorized senders. Remove any duplicate SPF records, which violate RFC 7208 and cause validation to fail. Avoid +all and ?all, which neutralize SPF enforcement, and validate the record with a DNS lookup after publishing.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-8
MITRE ATT&CK: T1566.001
Unknown M365EXO-017 DMARC policy published for each domain (MS.EXO.4.1) Exchange Online Security Critical FAIL Non-compliant
Description
SCuBA MS.EXO.4.1 requires that a DMARC policy be published for every second-level domain. DMARC is a DNS TXT record at _dmarc.<domain> that tells receivers how to handle mail failing SPF and DKIM and where to send reports. Without a DMARC record, receivers handle authentication failures inconsistently, allowing spoofed mail to reach inboxes.
Current Value
Non-compliant
Recommended Value
A DMARC TXT record published at _dmarc for every second-level domain
Remediation Steps
Publish a DMARC TXT record at _dmarc.<domain> for every second-level domain; a record at the second-level domain protects its subdomains. Begin with p=none to gather aggregate reports without affecting delivery, validate that legitimate sources align under SPF or DKIM, then progress the enforcement level. Confirm the record resolves correctly using a DNS lookup.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-8
MITRE ATT&CK: T1566.001
Unknown OAUTH-003 OAuth Scope Analysis OAuth & API Security Critical FAIL Unreviewed permissions
Description
OAuth applications with high-risk scopes (Gmail, Drive, Admin) pose significant data exfiltration risk and must be reviewed and restricted
Current Value
Unreviewed permissions
Recommended Value
No unauthorized apps with high-risk scopes (gmail, drive, admin)
Remediation Steps
Admin Console > Security > API controls > App access control > Review apps with sensitive scopes > Revoke or restrict as needed
Compliance Mappings
NIST SP 800-53: AC-6 AC-3
MITRE ATT&CK: T1528 T1114.002 T1530
CIS Benchmark: 3.3
Unknown OAUTH-008 Domain-Wide Delegation Grants Audit OAuth & API Security Critical FAIL Disabled
Description
Domain-wide delegation allows service accounts to impersonate any user and access their data. Unauthorized or overly permissive grants represent a critical security risk
Current Value
Disabled
Recommended Value
Minimal domain-wide delegation grants with scoped permissions; all grants reviewed and approved
Remediation Steps
Admin Console > Security > API controls > Domain-wide delegation > Review all grants, remove unnecessary ones, and restrict scopes to minimum required
Compliance Mappings
NIST SP 800-53: AC-6(1) AC-2(7)
MITRE ATT&CK: T1098.003 T1134.001
CIS Benchmark: 3.8
Unknown ADACL-003 GenericWrite Permissions on Critical Objects AD ACL & Delegation High FAIL Disabled
Description
GenericWrite allows modification of most attributes on an object, enabling attacks such as targeted Kerberoasting (writing an SPN), Resource-Based Constrained Delegation (writing msDS-AllowedToActOnBehalfOfOtherIdentity), or Shadow Credentials (writing msDS-KeyCredentialLink). Non-default principals with GenericWrite on critical objects should be investigated
Current Value
Disabled
Recommended Value
No non-default principals with GenericWrite on critical AD objects
Remediation Steps
Audit ACLs on user, computer, and group objects for GenericWrite permissions. Remove unnecessary GenericWrite ACEs and replace with specific attribute-level write permissions. Pay special attention to write access on msDS-AllowedToActOnBehalfOfOtherIdentity, servicePrincipalName, and msDS-KeyCredentialLink attributes.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 AC-6(1) AC-3
MITRE ATT&CK: T1222.001 T1098
Anssi: vuln_permissions_genericwrite
Unknown ADACL-006 ForceChangePassword Rights AD ACL & Delegation High FAIL Disabled
Description
The Extended Right User-Force-Change-Password (also known as Reset Password) allows a principal to reset another user's password without knowing the current password. When granted to non-privileged accounts or broad groups, this creates a direct account takeover path that bypasses normal authentication requirements
Current Value
Disabled
Recommended Value
ForceChangePassword limited to authorized helpdesk and admin groups only; not granted to non-privileged accounts
Remediation Steps
Enumerate all principals with User-Force-Change-Password extended right on user objects. Verify each delegation is intentional and scoped appropriately. Remove rights from any principal that does not have a documented operational need. Use OU-scoped delegation rather than domain-wide grants.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 IA-5(1)
MITRE ATT&CK: T1098 T1078.002
Anssi: vuln_permissions_resetpassword
Unknown ADACL-009 Machine Account Quota AD ACL & Delegation High FAIL Disabled
Description
The ms-DS-MachineAccountQuota attribute on the domain root determines how many computer accounts any authenticated user can create. The default value of 10 allows any domain user to join computers to the domain, creating machine accounts that can be abused for resource-based constrained delegation attacks, relay attacks, and other privilege escalation techniques
Current Value
Disabled
Recommended Value
ms-DS-MachineAccountQuota set to 0
Remediation Steps
Set ms-DS-MachineAccountQuota to 0 on the domain root using Set-ADDomain -Identity (Get-ADDomain) -Replace @{'ms-DS-MachineAccountQuota'=0}. Delegate computer account creation to specific admin groups or use a prestaging workflow. Review existing computer accounts created by non-admin users.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6 AC-6
MITRE ATT&CK: T1098 T1136.002
Anssi: vuln_machineaccountquota
Unknown ADACL-011 Ownership of Critical Objects AD ACL & Delegation High FAIL Disabled
Description
The owner of an AD object has implicit permission to modify the object's DACL regardless of the explicit ACL entries. If critical objects such as the domain root, AdminSDHolder, privileged groups, or GPOs are owned by non-privileged or unexpected accounts, those accounts have a hidden path to full control
Current Value
Disabled
Recommended Value
Critical objects owned by Domain Admins, Enterprise Admins, or SYSTEM only
Remediation Steps
Enumerate ownership of all critical objects including the domain root, AdminSDHolder, Schema container, Configuration container, privileged group objects, and GPO objects. Transfer ownership of any incorrectly owned objects to Domain Admins using Set-Acl or the Security tab in ADUC. Enable auditing for ownership changes.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 AC-3
MITRE ATT&CK: T1222.001
Anssi: vuln_object_ownership
Unknown ADACL-012 Non-Default Domain Root Permissions AD ACL & Delegation High FAIL Disabled
Description
The domain root object is the top of the AD hierarchy and permissions set here can inherit throughout the entire directory. Non-default ACEs on the domain root that grant write, modify, or extended rights to unexpected principals represent a significant risk as they can affect every object in the domain
Current Value
Disabled
Recommended Value
Only default Microsoft ACEs on the domain root; all custom ACEs documented and justified
Remediation Steps
Compare current domain root ACL against the default ACL for your domain functional level. Document any non-default ACEs and validate their operational necessity. Remove ACEs that are no longer required or that grant excessive permissions. Pay special attention to ACEs that apply to 'This object and all descendant objects'.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 AC-3 CM-6
MITRE ATT&CK: T1222.001 T1003.006
Unknown ADACL-013 GPO Link Permissions AD ACL & Delegation High FAIL Misconfigured
Description
The ability to link Group Policy Objects to sites, domains, or OUs controls which policies apply to which objects. Unauthorized GPO link permissions allow an attacker to apply malicious GPOs to targeted OUs, potentially deploying malware, modifying security settings, or creating scheduled tasks on affected computers
Current Value
Misconfigured
Recommended Value
GPO link permissions restricted to authorized Group Policy administrators only
Remediation Steps
Audit gPLink and gPOptions write permissions on all OUs, the domain root, and site objects. Remove GPO link permissions from non-administrative principals. Use Group Policy Modeling to verify the impact of current GPO links. Implement change control for GPO linking operations.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 CM-5
MITRE ATT&CK: T1484.001
Anssi: vuln_gpo_link_permissions
Unknown ADACL-014 GPO Edit Permissions AD ACL & Delegation High FAIL Misconfigured
Description
Permissions to edit Group Policy Objects allow modification of domain-wide security settings, software deployment, logon scripts, and scheduled tasks. Unauthorized GPO edit access is a high-value target for attackers as it enables widespread code execution and configuration changes across the environment
Current Value
Misconfigured
Recommended Value
GPO edit permissions restricted to Group Policy Creator Owners and authorized administrators only
Remediation Steps
Review the security filtering and delegation tabs on each GPO. Verify that only authorized principals have Edit settings, Delete, or Modify security permissions. Remove GPO edit permissions from non-administrative groups. Use the Group Policy Management Console to audit GPO permissions systematically.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 CM-5 CM-6
MITRE ATT&CK: T1484.001
Anssi: vuln_gpo_edit_permissions
Unknown ADCS-004 ESC3 - Enrollment Agent Template Abuse Condition 1 AD Certificate Services High FAIL Vulnerable configuration
Description
ESC3 Condition 1 identifies certificate templates that have the Certificate Request Agent EKU (OID 1.3.6.1.4.1.311.20.2.1) and allow enrollment by low-privileged users. An Enrollment Agent certificate allows its holder to enroll in other templates on behalf of any user, potentially including templates with authentication EKUs that normally require CA Manager approval
Current Value
Vulnerable configuration
Recommended Value
Certificate Request Agent templates restricted to authorized enrollment agents only; not enrollable by low-privileged users
Remediation Steps
Identify templates with the Certificate Request Agent EKU that allow enrollment by non-administrative users. Restrict enrollment permissions on these templates to a dedicated Enrollment Agent security group. Configure Enrollment Agent restrictions on the CA to limit which templates and users enrollment agents can enroll for. Monitor Certificate Request Agent certificate issuance.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 IA-5(2) CM-6
MITRE ATT&CK: T1649
Anssi: vuln_adcs_esc3
Unknown ADCS-005 ESC3 - Enrollment Agent Template Abuse Condition 2 AD Certificate Services High FAIL Vulnerable configuration
Description
ESC3 Condition 2 identifies certificate templates that accept enrollment on behalf of other users (require an enrollment agent signature) and have an authentication EKU. When combined with ESC3 Condition 1, an attacker who obtains an Enrollment Agent certificate can enroll for authentication certificates on behalf of any user, including Domain Admins
Current Value
Vulnerable configuration
Recommended Value
Templates requiring enrollment agent signatures restricted to specific target users via enrollment agent restrictions on the CA
Remediation Steps
Identify templates that require an authorized signature with the Certificate Request Agent application policy and have Client Authentication or Smart Card Logon EKU. Configure Enrollment Agent restrictions on the CA to limit which templates these enrollment agents can enroll for and which users they can enroll on behalf of. This is configured in the CA properties under Enrollment Agents restrictions.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 IA-5(2) CM-6
MITRE ATT&CK: T1649
Anssi: vuln_adcs_esc3
Unknown ADCS-008 ESC5 - Vulnerable PKI Object ACLs AD Certificate Services High FAIL Vulnerable configuration
Description
ESC5 covers write permissions on other PKI-related AD objects beyond certificate templates, including the CA server's AD object, the NTAuthCertificates object, the Enrollment Services container, and the Certificate Templates container. Write access to these objects can allow an attacker to add rogue CAs, modify enrollment settings, or publish malicious templates
Current Value
Vulnerable configuration
Recommended Value
No write permissions on PKI container objects for non-administrative principals; write access limited to Enterprise Admins
Remediation Steps
Audit ACLs on all objects under CN=Public Key Services,CN=Services,CN=Configuration including the Enrollment Services container, AIA container, NTAuthCertificates object, and Certificate Templates container. Remove write permissions for non-administrative principals. Ensure the CA computer object in AD does not have write permissions for broad groups. Monitor these objects for unauthorized changes.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 AC-3 IA-5(2)
MITRE ATT&CK: T1649 T1222.001
Anssi: vuln_adcs_esc5
Unknown ADCS-012 ESC9 - No Security Extension AD Certificate Services High FAIL Vulnerable configuration
Description
ESC9 exploits the absence of the szOID_NTDS_CA_SECURITY_EXT security extension in issued certificates. Without this extension and when StrongCertificateBindingEnforcement is not set to 2, an attacker who can modify a user's UPN attribute (via GenericWrite on the user object) can request a certificate, change the UPN back, and use the certificate to authenticate as the modified identity
Current Value
Vulnerable configuration
Recommended Value
StrongCertificateBindingEnforcement set to 2 on all domain controllers; CT_FLAG_NO_SECURITY_EXTENSION not set on authentication templates
Remediation Steps
Check for templates with CT_FLAG_NO_SECURITY_EXTENSION (0x80000) in msPKI-Enrollment-Flag. Remove this flag from all authentication-capable templates. Set the registry value StrongCertificateBindingEnforcement to 2 under HKLM\SYSTEM\CurrentControlSet\Services\Kdc on all domain controllers to enforce strong certificate mapping. Test certificate-based authentication after enabling enforcement.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(2) CM-6 AC-6
MITRE ATT&CK: T1649 T1098
Anssi: vuln_adcs_esc9
Unknown ADCS-013 ESC11 - RPC Relay Without Encryption AD Certificate Services High FAIL Disabled
Description
ESC11 targets the AD CS RPC enrollment interface (ICertPassage) when the CA does not enforce encryption on the RPC connection. Similar to ESC8 for HTTP, an attacker can relay NTLM authentication to the unencrypted RPC endpoint to request certificates as the relayed identity. This affects the default DCOM-based enrollment interface
Current Value
Disabled
Recommended Value
IF_ENFORCEENCRYPTICERTREQUEST flag enabled on all CA servers to require RPC encryption
Remediation Steps
Check CA interface flags using certutil -getreg CA\InterfaceFlags. Enable the IF_ENFORCEENCRYPTICERTREQUEST flag using certutil -setreg CA\InterfaceFlags +IF_ENFORCEENCRYPTICERTREQUEST. Restart the CertSvc service. Verify that certificate enrollment still functions correctly from domain-joined clients after enabling encryption enforcement.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-8 SC-8(1) IA-5(2)
MITRE ATT&CK: T1649 T1557
Anssi: vuln_adcs_esc11
Unknown ADCS-014 ESC13 - Issuance Policy OID Group Link AD Certificate Services High FAIL Vulnerable configuration
Description
ESC13 exploits the linkage between certificate issuance policy OIDs and AD security groups through the msDS-OIDToGroupLink attribute. When a certificate template has an issuance policy that maps to a security group, anyone who enrolls in that template effectively gains membership in the linked group for the duration of certificate-based authentication
Current Value
Vulnerable configuration
Recommended Value
No issuance policy OIDs linked to privileged security groups; msDS-OIDToGroupLink only on non-sensitive groups
Remediation Steps
Query all OID objects in CN=OID,CN=Public Key Services,CN=Services,CN=Configuration for the msDS-OIDToGroupLink attribute. Identify any OIDs linked to privileged groups (Domain Admins, Enterprise Admins, etc.). Remove the msDS-OIDToGroupLink attribute from OIDs linked to sensitive groups. If the linkage is operationally required, restrict enrollment on templates using the issuance policy to authorized principals only.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 IA-5(2) CM-6
MITRE ATT&CK: T1649 T1098
Anssi: vuln_adcs_esc13
Unknown ADCS-016 ESC16 - UPN SAN Misconfiguration AD Certificate Services High FAIL Vulnerable configuration
Description
ESC16 exploits a misconfiguration where StrongCertificateBindingEnforcement is set to 1 (compatibility mode) and certificate templates with CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT or CT_FLAG_SUBJECT_ALT_REQUIRE_UPN allow the enrollee to set the UPN in the SAN. The weak binding allows certificates to be mapped to users based on UPN alone without the OID security extension, enabling impersonation
Current Value
Vulnerable configuration
Recommended Value
StrongCertificateBindingEnforcement set to 2; no templates allowing enrollee-specified UPN SAN with low-privileged enrollment
Remediation Steps
Set StrongCertificateBindingEnforcement to 2 on all domain controllers under HKLM\SYSTEM\CurrentControlSet\Services\Kdc. Review all templates that allow enrollee-specified subjects or require UPN in the SAN. Restrict enrollment on these templates to authorized principals. Test certificate-based authentication after enforcing strong binding to identify any incompatibilities before full rollout.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(2) CM-6 AC-6
MITRE ATT&CK: T1649 T1556
Unknown ADCS-017 EKEUwu - Extended Key Usage Abuse AD Certificate Services High FAIL Disabled
Description
The EKEUwu attack targets certificate templates where the Extended Key Usage field can be influenced by the enrollee through the certificate request. This occurs with certain template configurations where the EKU is not strictly enforced by the template, allowing an attacker to add authentication EKUs to certificates that were not intended for authentication purposes
Current Value
Disabled
Recommended Value
All certificate templates strictly enforce EKU from the template definition; no enrollee-controllable EKUs
Remediation Steps
Review all certificate templates for EKU enforcement. Ensure templates are Schema v2 or later where EKU enforcement is more robust. Remove unnecessary templates that do not strictly define and enforce EKUs. Test certificate requests to verify that the issued certificate EKU matches the template definition. Implement CA issuance policy modules that validate EKU in requests.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(2) CM-6
MITRE ATT&CK: T1649
Unknown ADCS-018 CA Auditing Configuration AD Certificate Services High FAIL Disabled
Description
AD CS Certificate Authority auditing controls which certificate-related events are logged including certificate requests, issuance, revocation, and CA configuration changes. Without adequate CA auditing, exploitation of certificate-based attack vectors (ESC1-ESC16) cannot be detected or investigated, and unauthorized certificate issuance goes unnoticed
Current Value
Disabled
Recommended Value
All CA audit categories enabled: Start/Stop, Backup/Restore, Certificate Issued, Certificate Revoked, Certificate Request, CA Security, CA Configuration Change
Remediation Steps
Configure CA auditing using certsrv.msc > CA Properties > Auditing tab. Enable all audit categories: Back up and restore the CA database, Change CA configuration, Change CA security settings, Issue and manage certificate requests, Revoke certificates and publish CRLs, Store and retrieve archived keys, Start and stop AD CS. Verify that the Windows Security event log has sufficient size and retention settings.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-2 AU-3 AU-12
MITRE ATT&CK: T1649 T1562.002
Unknown ADDOM-001 Forest Functional Level AD Domain & Forest Configuration High FAIL Disabled
Description
The Active Directory forest functional level should be at Windows Server 2016 or higher to enable modern security features such as Privileged Access Management and improved Kerberos protections. Running older functional levels exposes the environment to attacks that leverage legacy protocol weaknesses
Current Value
Disabled
Recommended Value
Windows Server 2016 or higher
Remediation Steps
Raise the forest functional level via Active Directory Domains and Trusts > Right-click the forest root > Raise Forest Functional Level. Ensure all domain controllers run a supported OS version before raising
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6 SI-2
MITRE ATT&CK: T1078.002
CIS Benchmark: 18.3.1
Anssi: R1
CisAd: 1.1.1
Unknown ADDOM-002 Domain Functional Level AD Domain & Forest Configuration High FAIL Disabled
Description
The Active Directory domain functional level should be at Windows Server 2016 or higher. Lower functional levels prevent the use of critical security features including Protected Users group functionality, authentication policies, and modern Kerberos armoring
Current Value
Disabled
Recommended Value
Windows Server 2016 or higher
Remediation Steps
Raise the domain functional level via Active Directory Domains and Trusts > Right-click the domain > Raise Domain Functional Level. Verify all DCs in the domain are running a compatible OS version first
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6 SI-2
MITRE ATT&CK: T1078.002
CIS Benchmark: 18.3.1
Anssi: R1
CisAd: 1.1.2
Unknown ADDOM-004 Domain Controller Inventory AD Domain & Forest Configuration High FAIL Disabled
Description
All domain controllers should be inventoried with their OS version, patch level, and location. Untracked domain controllers represent a significant security risk as they may miss patches or be compromised without detection
Current Value
Disabled
Recommended Value
All domain controllers documented with current OS version, site membership, and patch status
Remediation Steps
Query all DC computer objects from the Domain Controllers OU. Verify each DC is accounted for, running a supported OS, and receiving regular patches. Remove or demote any unauthorized DCs immediately
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-8 CM-8(1)
MITRE ATT&CK: T1018 T1078.002
CIS Benchmark: 1.1
Anssi: R8
CisAd: 1.2.1
Unknown ADDOM-007 AD Replication Health AD Domain & Forest Configuration High FAIL Disabled
Description
Active Directory replication failures can lead to inconsistent security policy application, stale credentials remaining valid, and split-brain scenarios. Persistent replication failures may also indicate a compromised or rogue DC
Current Value
Disabled
Recommended Value
All domain controllers replicating successfully with no errors in the last 24 hours
Remediation Steps
Run 'repadmin /replsummary' and 'repadmin /showrepl' to identify failures. Investigate and resolve DNS issues, network connectivity problems, or USN rollback conditions. Monitor replication status as part of routine operations
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-36 CP-10
MITRE ATT&CK: T1207
CIS Benchmark: 18.3.1
CisAd: 1.3.1
Unknown ADDOM-012 DNS Zone Security AD Domain & Forest Configuration High FAIL Disabled
Description
AD-integrated DNS zones should use secure dynamic updates only. Allowing nonsecure updates enables attackers to poison DNS records, redirect authentication traffic, and perform adversary-in-the-middle attacks against domain-joined systems
Current Value
Disabled
Recommended Value
Secure dynamic updates only on all AD-integrated DNS zones
Remediation Steps
Open DNS Manager > Right-click each AD-integrated zone > Properties > General tab > Change Dynamic Updates to 'Secure only'. Review all forward and reverse lookup zones. Verify DNSSEC signing if applicable
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-20 SC-21
MITRE ATT&CK: T1557 T1584.002
CIS Benchmark: 18.5.4
Anssi: R29
CisAd: 1.6.1
Unknown ADDOM-014 LDAP Channel Binding AD Domain & Forest Configuration High FAIL Not required
Description
LDAP channel binding tokens prevent relay attacks by cryptographically binding the LDAP session to the TLS channel. Without channel binding, attackers can relay LDAP authentication to gain unauthorized access
Current Value
Not required
Recommended Value
LDAP channel binding set to 'Always' on all domain controllers
Remediation Steps
Set the registry value LdapEnforceChannelBinding to 2 (Always) at HKLM\System\CurrentControlSet\Services\NTDS\Parameters on all DCs. Test with value 1 (When Supported) first to identify incompatible clients
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-8 SC-8(1) SC-23
MITRE ATT&CK: T1557
CIS Benchmark: 18.3.5
Anssi: R25
NsaAsd: LDAP-2
CisAd: 2.1.2
Unknown ADDOM-017 NTLMv2 Enforcement AD Domain & Forest Configuration High FAIL Not required
Description
The LAN Manager authentication level should be configured to send only NTLMv2 responses and refuse LM and NTLMv1. While NTLMv2 is still less secure than Kerberos, it is significantly stronger than NTLMv1 and should be the minimum NTLM standard
Current Value
Not required
Recommended Value
LAN Manager authentication level set to 'Send NTLMv2 response only. Refuse LM & NTLM' (level 5)
Remediation Steps
Configure via Group Policy: Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options > 'Network security: LAN Manager authentication level' = 'Send NTLMv2 response only. Refuse LM & NTLM'. Test thoroughly before enforcement
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(2) SC-8
MITRE ATT&CK: T1557 T1003
CIS Benchmark: 2.3.8.4
Anssi: R27
NsaAsd: NTLM-2
CisAd: 2.3.2
Unknown ADDOM-018 Null Session Enumeration AD Domain & Forest Configuration High FAIL Disabled
Description
Anonymous (null session) access to Active Directory allows unauthenticated attackers to enumerate users, groups, shares, and domain information. This reconnaissance data is used to plan credential attacks and lateral movement
Current Value
Disabled
Recommended Value
Null session enumeration disabled; RestrictAnonymous and RestrictAnonymousSAM set to prevent anonymous access
Remediation Steps
Configure via Group Policy: Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options > Set 'Network access: Restrict anonymous access to Named Pipes and Shares' = Enabled, 'Network access: Do not allow anonymous enumeration of SAM accounts' = Enabled, 'Network access: Do not allow anonymous enumeration of SAM accounts and shares' = Enabled
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-3 AC-14
MITRE ATT&CK: T1087.002 T1069.002
CIS Benchmark: 2.3.10.5 2.3.10.6
Anssi: R30
CisAd: 2.4.1
Unknown ADDOM-019 Print Spooler on Domain Controllers AD Domain & Forest Configuration High FAIL Disabled
Description
The Print Spooler service on domain controllers enables the PrintNightmare (CVE-2021-34527) and SpoolSample/PrinterBug attacks. An attacker can coerce a DC to authenticate to an attacker-controlled server, enabling credential relay and unconstrained delegation abuse
Current Value
Disabled
Recommended Value
Print Spooler service disabled on all domain controllers
Remediation Steps
Disable the Print Spooler service on all domain controllers via Group Policy: Computer Configuration > Policies > Windows Settings > Security Settings > System Services > Print Spooler > Startup Mode = Disabled. Apply to the Domain Controllers OU. Verify no print functionality depends on DCs
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-7 CM-7(1)
MITRE ATT&CK: T1187 T1210
CIS Benchmark: 5.2
Anssi: R9
CisAd: 1.2.3
Unknown ADGPO-007 GPO Permission Inconsistencies AD Group Policy High FAIL Misconfigured
Description
Each GPO has both AD permissions (on the GPC object) and NTFS permissions (on the SYSVOL GPT folder). Inconsistencies between these permission sets can prevent GPO application, allow unauthorized modification, or create security gaps where SYSVOL content is more permissive than the AD object
Current Value
Misconfigured
Recommended Value
Consistent permissions between AD GPC objects and SYSVOL GPT folders for all GPOs; Authenticated Users have Read access
Remediation Steps
Compare the security descriptor on each GPC object in AD with the NTFS ACL on the corresponding GPT folder in SYSVOL. Ensure that both grant Read access to Authenticated Users (required for GPO application). Resolve any inconsistencies by aligning SYSVOL permissions with the AD object. Run dcdiag /test:sysvolcheck to identify issues.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-3 CM-6
MITRE ATT&CK: T1484.001 T1222.001
Unknown ADGPO-011 GPO Settings Security Analysis AD Group Policy High FAIL Misconfigured
Description
GPO settings can weaken the security posture if they disable protections, relax authentication requirements, or configure insecure defaults. This check analyzes key security-relevant settings across all GPOs including password policies, account lockout, user rights assignments, security options, and audit policies
Current Value
Misconfigured
Recommended Value
All GPO settings align with organizational security baseline; no GPOs that weaken default security configurations
Remediation Steps
Export all GPO reports and analyze security-relevant settings including password policies, account lockout, user rights assignments, restricted groups, security options, and Windows Firewall rules. Compare settings against CIS benchmarks or organizational baselines. Remediate GPOs that configure weaker-than-baseline settings.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6 CM-6(1) AC-3
MITRE ATT&CK: T1484.001 T1484
Unknown ADGPO-013 Scripts in GPOs Analysis AD Group Policy High FAIL Misconfigured
Description
GPO startup, shutdown, logon, and logoff scripts execute with the privileges of the system or user and are stored in the accessible SYSVOL share. Malicious scripts placed in GPOs can achieve widespread code execution across the domain. Scripts should be reviewed for security issues including hardcoded credentials, unsafe commands, and references to non-secure locations
Current Value
Misconfigured
Recommended Value
All GPO scripts reviewed, signed where possible, and free of hardcoded credentials or unsafe operations
Remediation Steps
Enumerate all scripts configured in GPOs (Startup, Shutdown, Logon, Logoff) from the Scripts section of GPO reports. Review script content for hardcoded credentials, LOLBins usage, external resource references, and unsafe operations. Implement script signing where supported. Ensure script file permissions restrict modification to authorized administrators only.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6 SI-7 CM-5
MITRE ATT&CK: T1059 T1484.001
Unknown ADGPO-015 Scheduled Tasks in GPOs AD Group Policy High FAIL Misconfigured
Description
Group Policy Preferences can create scheduled tasks that run with specified credentials or as SYSTEM on targeted computers. Malicious scheduled tasks deployed via GPO provide persistent code execution across the environment. This is a common post-exploitation technique for maintaining domain-wide persistence
Current Value
Misconfigured
Recommended Value
All GPO-deployed scheduled tasks documented, using least-privilege accounts, and performing authorized operations only
Remediation Steps
Review all Scheduled Task items in GPO Preferences across all GPOs. Verify each task runs a legitimate and authorized command with the minimum required privileges. Remove any tasks that store credentials (use gMSA or SYSTEM context instead). Ensure task executables are stored in protected locations. Document the business purpose for each GPO-deployed scheduled task.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6 CM-5 AC-6
MITRE ATT&CK: T1053.005 T1484.001
Unknown ADGPO-017 Restricted Groups Analysis AD Group Policy High FAIL Disabled
Description
Restricted Groups GPO settings enforce group membership on target systems, commonly used to manage local Administrators group membership. Misconfigured Restricted Groups can inadvertently grant local admin access to unauthorized users or fail to remove unauthorized members from privileged local groups
Current Value
Disabled
Recommended Value
Restricted Groups configured to enforce least-privilege local admin membership; only authorized groups in local Administrators
Remediation Steps
Review Restricted Groups settings in all GPOs. Verify that the local Administrators group is managed to include only authorized admin groups. Ensure that Restricted Groups do not add Domain Users or other broad groups to privileged local groups. Consider using Group Policy Preferences for more granular control (Add/Remove members without replacing the entire membership).
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 AC-6(1) CM-6
MITRE ATT&CK: T1484.001 T1098
Unknown ADGPO-018 Audit Policy Configuration via GPO AD Group Policy High FAIL Disabled
Description
Windows audit policies configured through Group Policy determine which security events are logged on domain-joined systems. Insufficient audit configuration creates blind spots that allow attackers to operate undetected. Key audit categories include logon events, account management, directory service access, and object access
Current Value
Disabled
Recommended Value
Advanced Audit Policy configured via GPO with success and failure auditing for all critical categories aligned with organizational detection requirements
Remediation Steps
Configure Advanced Audit Policy Configuration (not legacy Audit Policy) via GPO. Enable at minimum: Account Logon (Success/Failure), Account Management (Success/Failure), Directory Service Access (Success/Failure), Logon/Logoff (Success/Failure), Object Access (Success/Failure for sensitive resources), Policy Change (Success), Privilege Use (Success/Failure), and System (Success/Failure). Deploy to all domain-joined systems.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-2 AU-3 AU-12
MITRE ATT&CK: T1484.001 T1562.002
Unknown ADGPO-021 PowerShell Logging Configuration AD Group Policy High FAIL Disabled
Description
PowerShell Module Logging, Script Block Logging, and Transcription provide critical visibility into PowerShell-based attacks which are used in the majority of modern Active Directory compromises. Without these logging capabilities, defenders cannot detect or investigate PowerShell-based reconnaissance, credential theft, or lateral movement
Current Value
Disabled
Recommended Value
Module Logging, Script Block Logging, and Transcription enabled via GPO on all systems
Remediation Steps
Configure GPO settings under Computer Configuration > Administrative Templates > Windows Components > Windows PowerShell. Enable Module Logging with '*' to log all modules. Enable Script Block Logging with 'Log script block invocation start/stop events'. Enable PowerShell Transcription with a secure output directory. Deploy to all domain-joined systems and verify log collection.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-2 AU-3 AU-12 SI-4
MITRE ATT&CK: T1059.001 T1562.002
Unknown ADGPO-023 LAPS GPO Configuration AD Group Policy High FAIL Misconfigured
Description
Local Administrator Password Solution (LAPS) provides automated rotation of local administrator passwords on domain-joined systems, preventing lateral movement via shared local admin credentials. LAPS must be deployed via GPO to be effective, and its configuration settings determine password complexity, rotation frequency, and which account is managed
Current Value
Misconfigured
Recommended Value
LAPS enabled via GPO on all domain-joined systems with 24-character passwords and 30-day maximum age
Remediation Steps
Install the LAPS CSE on all managed systems via GPO software installation or SCCM. Configure LAPS GPO settings: Enable local admin password management, set password complexity to large letters + small letters + numbers + specials, set password length to 24 or more characters, and set password age to 30 days or less. Verify LAPS is functioning by checking ms-Mcs-AdmPwdExpirationTime attributes.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 IA-5(1) CM-6
MITRE ATT&CK: T1078.003 T1021
Anssi: vuln_no_laps
Unknown ADKERB-001 Kerberoastable Accounts AD Kerberos Security High FAIL Disabled
Description
User accounts with Service Principal Names (SPNs) are vulnerable to Kerberoasting, where any authenticated domain user can request a service ticket encrypted with the account's password hash and attempt offline cracking. This attack requires no special privileges and is difficult to detect. Each SPN-bearing user account represents a potential credential exposure vector
Current Value
Disabled
Recommended Value
Minimal user accounts with SPNs. All Kerberoastable accounts identified, documented with business justification, and protected with 25+ character passwords or migrated to gMSA
Remediation Steps
Enumerate Kerberoastable accounts using Get-ADUser -Filter {ServicePrincipalName -ne '$null'} -Properties ServicePrincipalName. For each account: (1) evaluate if the SPN is still needed, (2) remove unnecessary SPNs, (3) migrate to Group Managed Service Accounts where possible, (4) for remaining accounts ensure passwords are 25+ characters and rotated regularly. Monitor for Kerberos TGS requests targeting sensitive accounts via Event ID 4769
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1558.003
Anssi: R36
CisAd: 7.1.1
Unknown ADKERB-003 AS-REP Roastable Accounts AD Kerberos Security High FAIL Disabled
Description
Accounts with the DONT_REQUIRE_PREAUTH flag set allow any user to request an AS-REP containing encrypted material that can be cracked offline without any prior authentication. Unlike Kerberoasting, AS-REP Roasting does not even require a valid domain account in some configurations, making it an attractive initial access technique for attackers with only network access to a domain controller
Current Value
Disabled
Recommended Value
No accounts with 'Do not require Kerberos preauthentication' flag set. Zero AS-REP Roastable accounts
Remediation Steps
Identify accounts using Get-ADUser -Filter {DoesNotRequirePreAuth -eq $true -and Enabled -eq $true}. Enable Kerberos pre-authentication on all accounts. There is rarely a legitimate reason to disable pre-authentication in modern environments. Rotate passwords on all previously vulnerable accounts as they may have already been targeted. Monitor for Event ID 4768 with pre-authentication type 0
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1558.004
Anssi: R36
CisAd: 7.2.1
Unknown ADKERB-006 Constrained Delegation Analysis AD Kerberos Security High FAIL Unconstrained
Description
Constrained delegation limits which services an account can delegate to via the msDS-AllowedToDelegateTo attribute, but misconfiguration can still enable privilege escalation. Delegation to LDAP, CIFS, or HOST services on domain controllers can be abused to perform DCSync attacks, access DC file shares, or execute commands as the delegated user. Each constrained delegation entry should be reviewed for security impact
Current Value
Unconstrained
Recommended Value
All constrained delegation entries documented with business justification. No delegation to sensitive services (LDAP, CIFS, HOST, WSMAN) on domain controllers
Remediation Steps
Enumerate constrained delegation using Get-ADObject -Filter {msDS-AllowedToDelegateTo -ne '$null'} -Properties msDS-AllowedToDelegateTo. Review each delegation target. Flag any delegation to DC services (especially LDAP, CIFS, HOST, HTTP, WSMAN) as high risk. Remove unnecessary delegation entries and document legitimate ones with business justification. Consider migrating to resource-based constrained delegation for improved security
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6
MITRE ATT&CK: T1550.003
CisAd: 7.3.3
Unknown ADKERB-007 Resource-Based Constrained Delegation AD Kerberos Security High FAIL Unconstrained
Description
Resource-based constrained delegation (RBCD) allows the target resource to control which accounts can delegate to it via the msDS-AllowedToActOnBehalfOfOtherIdentity attribute. While more secure by design than traditional constrained delegation, RBCD can be abused if an attacker gains write access to a computer object to configure unauthorized delegation paths. This is a common post-exploitation technique
Current Value
Unconstrained
Recommended Value
All RBCD configurations documented and audited. No unauthorized entries in msDS-AllowedToActOnBehalfOfOtherIdentity. Write access to computer objects restricted to authorized administrators only
Remediation Steps
Enumerate RBCD configurations using Get-ADComputer -Filter {msDS-AllowedToActOnBehalfOfOtherIdentity -ne '$null'} -Properties msDS-AllowedToActOnBehalfOfOtherIdentity. Review each entry for business justification. Audit who has write access to computer objects in AD to identify potential RBCD abuse paths. Remove unauthorized RBCD entries. Implement monitoring for changes to the msDS-AllowedToActOnBehalfOfOtherIdentity attribute
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6
MITRE ATT&CK: T1550.003
CisAd: 7.3.4
Unknown ADKERB-008 Protocol Transition Abuse Paths AD Kerberos Security High FAIL Disabled
Description
Accounts configured for constrained delegation with protocol transition (TrustedToAuthForDelegation / T2A4D flag) can obtain service tickets on behalf of any user without that user actually authenticating via Kerberos. This S4U2Self capability allows the account to impersonate any user to the services it is allowed to delegate to, making it a powerful privilege escalation vector when combined with delegation to sensitive services
Current Value
Disabled
Recommended Value
Protocol transition (TrustedToAuthForDelegation) disabled on all accounts unless explicitly required and documented. No protocol transition accounts that can delegate to domain controller services
Remediation Steps
Identify accounts with protocol transition using Get-ADObject -Filter {TrustedToAuthForDelegation -eq $true} -Properties TrustedToAuthForDelegation,msDS-AllowedToDelegateTo. For each account, evaluate whether protocol transition is truly required (only needed when the initial authentication does not use Kerberos). Disable protocol transition where not needed. For remaining accounts, strictly limit the delegation targets and ensure no DC services are in scope
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6
MITRE ATT&CK: T1550.003
CisAd: 7.3.5
Unknown ADKERB-009 Kerberos Encryption Types AD Kerberos Security High FAIL Disabled
Description
Kerberos encryption types determine the strength of ticket encryption. DES and RC4 (ARCFOUR-HMAC-MD5) are cryptographically weak and should be disabled in favor of AES128 and AES256. RC4 in particular is targeted by Kerberoasting attacks as it is significantly faster to crack than AES-encrypted tickets. Enforcing AES-only encryption substantially increases the difficulty of offline credential attacks
Current Value
Disabled
Recommended Value
AES256_HMAC_SHA1 and AES128_HMAC_SHA1 as the only supported encryption types. DES and RC4 disabled via Group Policy and domain functional level
Remediation Steps
Configure via Group Policy: Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options > 'Network security: Configure encryption types allowed for Kerberos' = AES128_HMAC_SHA1, AES256_HMAC_SHA1, Future encryption types. Audit accounts with msDS-SupportedEncryptionTypes to identify those restricted to RC4. Ensure all service accounts have AES keys generated by rotating passwords after AES support is enabled at the domain level
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-12 SC-13
MITRE ATT&CK: T1558
Anssi: R37
CisAd: 7.4.1
Unknown ADLOG-001 Advanced Audit Policy Configured AD Logging & EDR Posture High FAIL Disabled
Description
Legacy nine-category audit policy is too coarse for modern investigations — it can tell you SOMETHING failed under 'Audit account logon events' but not whether it was a Kerberos preauth failure, a service ticket request, or an explicit credential pass-through. Windows has supported Advanced Audit Policy (60+ subcategories) since Vista, but it has to be opted into. Presence of audit.csv in the Default Domain Controllers Policy SYSVOL folder is the on-the-wire indicator that the domain has migrated.
Current Value
Disabled
Recommended Value
Default Domain Controllers Policy ships an audit.csv (Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > <subcategories>).
Remediation Steps
Open the Default Domain Controllers Policy in GPMC. Navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies. Enable at minimum: Account Logon > Kerberos Service Ticket Operations (Success+Failure), Logon/Logoff > Logon (Success+Failure) + Special Logon (Success), Account Management > all (Success), Object Access > File Share + Detailed File Share (Success+Failure if monitoring lateral movement), Detailed Tracking > Process Creation (Success). Also enable 'Audit: Force audit policy subcategory settings' in Security Options so it takes precedence over the legacy nine-category settings.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-2 AU-3 AU-12
MITRE ATT&CK: T1562.002
CisAd: 9.1.1
Unknown ADLOG-002 PowerShell Script Block Logging Enabled AD Logging & EDR Posture High FAIL Disabled
Description
Event 4104 (PowerShell Script Block Logging) is the single most useful Windows event for investigating modern intrusions — it captures the actual PowerShell code being executed after deobfuscation, including code passed via -EncodedCommand. Without it, an investigator looking at PS-based ransomware deployment is blind. The setting is delivered by administrative template into HKLM\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging\EnableScriptBlockLogging.
Current Value
Disabled
Recommended Value
Group Policy 'Turn on PowerShell Script Block Logging' is Enabled at the domain or DC OU level. Registry: EnableScriptBlockLogging = 1.
Remediation Steps
Computer Configuration > Policies > Administrative Templates > Windows Components > Windows PowerShell > 'Turn on PowerShell Script Block Logging' = Enabled. Verify after gpupdate: Get-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging'. Make sure event log capacity for 'Microsoft-Windows-PowerShell/Operational' is sized for the volume (default 15 MB will rotate in hours under load).
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-2 SI-4
MITRE ATT&CK: T1059.001 T1562.002
CisAd: 9.2.1
Unknown ADLOG-004 Process Creation Auditing with Command Line AD Logging & EDR Posture High FAIL Disabled
Description
Event 4688 (process creation) is the foundational lateral-movement signal — it tells you what process was launched and by whom. The default 4688 event does NOT include the command line, which makes it nearly useless for investigations involving PowerShell, wmic, mshta, or other living-off-the-land binaries. The 'Include command line in process creation events' policy fills in that gap.
Current Value
Disabled
Recommended Value
Group Policy 'Include command line in process creation events' is Enabled, AND Advanced Audit Policy subcategory 'Audit Process Creation' is set to Success.
Remediation Steps
Two settings, both required: (1) Computer Configuration > Policies > Administrative Templates > System > Audit Process Creation > 'Include command line in process creation events' = Enabled. (2) Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Detailed Tracking > Audit Process Creation = Success. Without (1), 4688 events arrive without a NewProcessName argument string. Without (2), they don't arrive at all.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-2 AU-3
MITRE ATT&CK: T1059 T1218
CisAd: 9.1.2
Unknown ADLOG-005 Microsoft Defender Tamper Protection Policy AD Logging & EDR Posture High FAIL Non-compliant
Description
If your EDR can be turned off from the endpoint without an admin action, every attacker turns it off as step one of their playbook. Defender Tamper Protection (and the equivalent in any modern EDR) blocks local disablement. This check looks for the GPO settings that govern Defender real-time protection — full Tamper Protection state is set in the cloud (Intune/MDE portal), but the GPO-side hardening is verifiable from SYSVOL.
Current Value
Non-compliant
Recommended Value
Defender real-time protection cannot be disabled by the local user; exclusions are tightly governed (or empty); SmartScreen Enhanced is on. Tamper Protection itself is set via Microsoft Defender for Endpoint cloud portal — verify out-of-band.
Remediation Steps
In the MDE portal: Settings > Endpoints > Advanced features > Tamper Protection = On (apply to all devices). In GPO: Computer Configuration > Policies > Administrative Templates > Windows Components > Microsoft Defender Antivirus > 'Turn off Microsoft Defender Antivirus' = Disabled (yes, double-negative — this means 'do NOT allow turning Defender off'). Also: > Real-Time Protection > 'Turn off real-time protection' = Disabled. Review the Exclusions subkey carefully — every entry there is a hole an attacker will find.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-3 SI-4
MITRE ATT&CK: T1562.001
CisAd: 9.3.1
Unknown ADLOG-006 Windows Event Forwarding (WEF) Subscription Manager AD Logging & EDR Posture High FAIL Allowed to external
Description
Logs that only exist on the host that generated them are exactly as useful as that host's local disk after the attacker wipes it. Windows Event Forwarding ships logs off-box to a collector at the time of write. Without a SubscriptionManager GPO pointing every endpoint at the collector, WEF doesn't happen.
Current Value
Allowed to external
Recommended Value
Group Policy 'Configure target Subscription Manager' is set on workstations and servers to point at the WEF collector.
Remediation Steps
Computer Configuration > Policies > Administrative Templates > Windows Components > Event Forwarding > 'Configure target Subscription Manager' = Enabled. Value: Server=http://wec-server.domain.tld:5985/wsman/SubscriptionManager/WEC,Refresh=60. Configure subscriptions on the collector with xpath queries for the events you care about (4624, 4625, 4688, 4768, 4769, 4104, 1102, etc.). If you don't have a WEF collector, this is the project to start; it's almost always cheaper than a full SIEM agent rollout for the same telemetry.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-4 AU-6
MITRE ATT&CK: T1070.001
CisAd: 9.4.1
Unknown ADMIN-002 Admin Role Assignments Audit Admin & User Management High FAIL Disabled
Description
Administrative role assignments should follow the principle of least privilege. Custom roles should be used instead of broad built-in roles
Current Value
Disabled
Recommended Value
All admin role assignments reviewed with least-privilege custom roles used where possible
Remediation Steps
Admin Console > Account > Admin roles > Review each role assignment > Replace broad roles with scoped custom roles
Compliance Mappings
NIST SP 800-53: AC-6(1) AC-2(7)
MITRE ATT&CK: T1078.004 T1098.003
CIS Benchmark: 4.2
Unknown ADMIN-004 Inactive/Suspended Admin Accounts Admin & User Management High FAIL Excessive permissions found
Description
Suspended or inactive users should not retain admin role assignments. These accounts may be targeted for reactivation attacks
Current Value
Excessive permissions found
Recommended Value
No suspended or inactive users with admin role assignments
Remediation Steps
Admin Console > Directory > Users > Filter suspended users > Remove admin roles from any suspended accounts
Compliance Mappings
NIST SP 800-53: AC-2(3) AC-2(4)
MITRE ATT&CK: T1078.004 T1098
CIS Benchmark: 4.4
Unknown ADMIN-010 Groups Settings and External Membership Admin & User Management High FAIL Anyone (no restrictions)
Description
Google Groups that allow external members can expose internal communications and data to unauthorized parties
Current Value
Anyone (no restrictions)
Recommended Value
External group membership disabled or restricted to specific groups with documented justification
Remediation Steps
Admin Console > Apps > Google Workspace > Groups for Business > Sharing settings > Restrict external membership
Compliance Mappings
NIST SP 800-53: AC-3 AC-4
MITRE ATT&CK: T1530 T1213.003
CIS Benchmark: 4.10
Unknown ADMIN-013 Super Admin Count Admin & User Management High FAIL Excessive permissions found
Description
The number of super admin accounts should be between 2 and 4. Too few creates a single point of failure; too many increases the attack surface
Current Value
Excessive permissions found
Recommended Value
2-4 super admin accounts
Remediation Steps
Admin Console > Directory > Users > Filter by super admin role > Adjust count to 2-4 by removing unnecessary super admins or adding a backup
Compliance Mappings
NIST SP 800-53: AC-6(1) AC-2(7)
MITRE ATT&CK: T1078.004
CIS Benchmark: 4.13
Unknown ADMIN-020 Access to unconfigured third-party apps blocked (GWS.COMMONCONTROLS.10.4) Admin & User Management High FAIL Unreviewed permissions
Description
SCuBA GWS.COMMONCONTROLS.10.4 requires that users SHALL NOT be allowed to access unconfigured third-party apps, because an app that has not been explicitly reviewed can request broad OAuth scopes and become a data-exfiltration or account-takeover path. This check reads the api_controls.unconfigured_third_party_apps Cloud Identity policy and flags any organizational unit whose access level is not BLOCK_ALL_SCOPES (the value that blocks all access to unconfigured apps).
Current Value
Unreviewed permissions
Recommended Value
Access level for unconfigured third-party apps set to BLOCK_ALL_SCOPES in all organizational units.
Remediation Steps
In the Google Admin console, under Security > API controls > App access control, set unconfigured third-party apps to 'Blocked', so users cannot grant any access to apps that have not been explicitly configured and reviewed.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-3 AC-6
Unknown ADNET-002 LDAP Channel Binding Enforced on Domain Controllers AD Network & Relay Preconditions High FAIL Not required
Description
LDAP channel binding ties an LDAPS authentication to the underlying TLS channel. Without it, an attacker who has intercepted a TLS-protected LDAP session can still relay NTLM authentication to LDAPS. Together with LDAP signing, channel binding eliminates LDAP as a relay target.
Current Value
Not required
Recommended Value
Default Domain Controllers Policy sets 'Domain controller: LDAP server channel binding token requirements' to 'Always' (LdapEnforceChannelBinding = 2)
Remediation Steps
Edit the Default Domain Controllers Policy: Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options > 'Domain controller: LDAP server channel binding token requirements' = 'Always'. Registry: HKLM\System\CurrentControlSet\Services\NTDS\Parameters\LdapEnforceChannelBinding = 2. Originally introduced for CVE-2017-8563.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-8 SC-23
MITRE ATT&CK: T1557.001
CisAd: 6.1.2
Unknown ADNET-004 SMB Client Signing Required (Domain Policy) AD Network & Relay Preconditions High FAIL Not required
Description
Client-side SMB signing is the half of the contract that prevents a workstation from being lured into authenticating to a malicious SMB server (responder-style). Without it, any user on the network who is tricked into resolving a hostile name (LLMNR poisoning, WPAD, etc.) coughs up an NTLM hash that an attacker can crack or relay.
Current Value
Not required
Recommended Value
Default Domain Policy enables 'Microsoft network client: Digitally sign communications (always)' (RequireSecuritySignature on LanmanWorkstation = 1)
Remediation Steps
Edit the Default Domain Policy: Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options > 'Microsoft network client: Digitally sign communications (always)' = Enabled. Registry: HKLM\System\CurrentControlSet\Services\LanmanWorkstation\Parameters\RequireSecuritySignature = 1.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-8 SC-23
MITRE ATT&CK: T1557.001
CisAd: 6.2.2
Unknown ADNET-005 LLMNR Disabled by Domain Policy AD Network & Relay Preconditions High FAIL Non-compliant
Description
Link-Local Multicast Name Resolution is a broadcast-based fallback that any host on the local segment can answer. Responder.py and similar tools impersonate the answer, harvest NTLMv2 challenge-responses, and either crack them offline or relay them. Disabling LLMNR domain-wide is the single most impactful workstation hardening you can do for an internal pentest posture.
Current Value
Non-compliant
Recommended Value
Default Domain Policy enables 'Turn off multicast name resolution' (DnsClient policy EnableMulticast = 0)
Remediation Steps
Edit the Default Domain Policy: Computer Configuration > Policies > Administrative Templates > Network > DNS Client > 'Turn off multicast name resolution' = Enabled. Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient\EnableMulticast = 0.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-8
MITRE ATT&CK: T1557.001
CisAd: 6.3.1
Unknown ADNET-007 IPv6 mitm6 Mitigation Posture AD Network & Relay Preconditions High FAIL Disabled
Description
mitm6 is the IPv6 equivalent of Responder: a malicious DHCPv6 server hands out a link-local DNS server, then poisons WPAD lookups to harvest credentials. Enterprises that haven't deployed IPv6 typically also haven't disabled it, leaving link-local IPv6 enabled with no defensive posture. Mitigation is either to deploy IPv6 properly with RA Guard / DHCPv6 Guard at the switch, or to disable IPv6 components via DisabledComponents = 0xFF.
Current Value
Disabled
Recommended Value
Either IPv6 is disabled domain-wide via DisabledComponents = 0xFF, OR the network has RA Guard + DHCPv6 Guard deployed at the access layer (out-of-band, not detectable from AD)
Remediation Steps
If you don't use IPv6: push HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\DisabledComponents = 0xFF (hex) via GPO Registry to all workstations and servers. If you do use IPv6: ensure your access switches enforce DHCPv6 Guard / RA Guard so rogue DHCPv6 advertisements are dropped at the port. Microsoft has explicitly stated that disabling IPv6 entirely is not recommended for Windows but is acceptable for environments where IPv6 is unused.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-7 SC-8
MITRE ATT&CK: T1557.001 T1557.003
CisAd: 6.3.3
Unknown ADNET-010 WebClient Service Default State on Workstations AD Network & Relay Preconditions High FAIL Disabled
Description
The WebClient service (WebDAV redirector) lets an attacker coerce HTTP authentication from a workstation by referencing a UNC path that begins with a hostname containing an '@' (e.g. \\attacker@80\share). This is the workstation analog of PetitPotam and is the relay source most commonly used to attack ADCS Web Enrollment (ESC8). WebClient is started on demand but should be set to Disabled domain-wide for non-mobile workstations.
Current Value
Disabled
Recommended Value
Default Domain Policy disables the WebClient service (start type 4) for all member workstations and servers that do not require WebDAV
Remediation Steps
Edit the Default Domain Policy: Computer Configuration > Policies > Windows Settings > Security Settings > System Services > WebClient > 'Define this policy setting' = Disabled. If a subset of hosts (e.g. SharePoint clients) actually need WebDAV, scope an opposing GPO to just those OUs. Monitor for sudden re-enablement.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-7
MITRE ATT&CK: T1187 T1557.001
CisAd: 6.4.2
Unknown ADPRIV-003 Schema Admins Enumeration AD Privileged Account Security High FAIL Excessive permissions found
Description
The Schema Admins group can modify the AD schema, which is irreversible and affects the entire forest. This group should be empty during normal operations as schema changes are rare and high-impact
Current Value
Excessive permissions found
Recommended Value
Empty during normal operations. Members added temporarily only for schema modifications with change management approval
Remediation Steps
Enumerate Schema Admins membership using Get-ADGroupMember -Identity 'Schema Admins'. Remove all permanent members. Add members only when schema changes are required through a formal change management process
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6(1) AC-6(5)
MITRE ATT&CK: T1078.002 T1069.002
CIS Benchmark: 9.2.3
Anssi: R2
CisAd: 4.1.3
Unknown ADPRIV-004 Account Operators Enumeration AD Privileged Account Security High FAIL Disabled
Description
Account Operators can create and modify most user and group accounts in the domain, including creating accounts in privileged OUs. This group is frequently overlooked but provides significant privilege escalation potential
Current Value
Disabled
Recommended Value
Empty. Use delegated OU-level permissions instead of Account Operators group membership
Remediation Steps
Enumerate Account Operators membership using Get-ADGroupMember -Identity 'Account Operators'. Remove all members and replace with OU-scoped delegation using Active Directory Delegation of Control wizard. Document all delegated permissions
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6(1) AC-6(5)
MITRE ATT&CK: T1078.002 T1098
CIS Benchmark: 9.2.4
Anssi: R3
CisAd: 4.1.4
Unknown ADPRIV-005 Server Operators Enumeration AD Privileged Account Security High FAIL Disabled
Description
Server Operators can log on to domain controllers, manage services, and modify shared resources. This group can be abused to escalate privileges on DCs by manipulating services to run arbitrary code as SYSTEM
Current Value
Disabled
Recommended Value
Empty. Use dedicated service management accounts with specific delegation instead
Remediation Steps
Enumerate Server Operators membership using Get-ADGroupMember -Identity 'Server Operators'. Remove all members and implement targeted delegation for any required server management tasks. Audit DC logon rights separately
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6(1) AC-6(5)
MITRE ATT&CK: T1078.002 T1543.003
Anssi: R3
CisAd: 4.1.5
Unknown ADPRIV-006 Backup Operators Enumeration AD Privileged Account Security High FAIL Disabled
Description
Backup Operators can back up and restore files on domain controllers, including the AD database (ntds.dit). This allows extraction of all password hashes in the domain, making Backup Operators membership equivalent to Domain Admin access for a skilled attacker
Current Value
Disabled
Recommended Value
Empty or restricted to dedicated backup service accounts only. No user accounts
Remediation Steps
Enumerate Backup Operators membership using Get-ADGroupMember -Identity 'Backup Operators'. Remove all user accounts. If backup service accounts require membership, ensure they are dedicated, have strong passwords, and are monitored. Consider agent-based backup solutions that do not require Backup Operators membership
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6(1) AC-6(5)
MITRE ATT&CK: T1003.003 T1078.002
Anssi: R3
CisAd: 4.1.6
Unknown ADPRIV-008 DnsAdmins Group Membership AD Privileged Account Security High FAIL Excessive permissions found
Description
Members of the DnsAdmins group can configure the DNS service on domain controllers to load an arbitrary DLL, which executes as SYSTEM. This well-known privilege escalation path can lead to full domain compromise from a seemingly low-privilege group membership
Current Value
Excessive permissions found
Recommended Value
Empty or restricted to dedicated DNS administration accounts only. Membership treated as Tier 0 privileged
Remediation Steps
Enumerate DnsAdmins membership using Get-ADGroupMember -Identity 'DnsAdmins'. Remove unnecessary members. Treat DnsAdmins as a Tier 0 privileged group in your tiering model. Monitor for changes to DNS server configuration and ServerLevelPluginDll registry value
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6(1) AC-6(5)
MITRE ATT&CK: T1543.003 T1078.002
Anssi: R3
CisAd: 4.1.8
Unknown ADPRIV-009 Nested Group Membership Analysis AD Privileged Account Security High FAIL Disabled
Description
Nested group memberships can obscure effective privileges by hiding privileged access behind chains of group nesting. Users may have Domain Admin equivalent access through deeply nested groups that are not visible through simple group enumeration
Current Value
Disabled
Recommended Value
All nested group paths to privileged groups documented. Maximum nesting depth of 2 levels. No circular nesting
Remediation Steps
Recursively enumerate all privileged group memberships using Get-ADGroupMember -Recursive. Map all nesting paths and identify users who gain privileges through indirect membership. Flatten unnecessary nesting and document all remaining nested paths with business justification
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6(1) AC-2
MITRE ATT&CK: T1069.002 T1078.002
Anssi: R4
CisAd: 4.2.1
Unknown ADPRIV-014 Privileged Users DES-Only Kerberos AD Privileged Account Security High FAIL Excessive permissions found
Description
Accounts configured to use DES-only Kerberos encryption are using a cryptographically broken algorithm. DES keys can be brute-forced rapidly, allowing attackers to forge or decrypt Kerberos tickets for the affected accounts
Current Value
Excessive permissions found
Recommended Value
No accounts with 'Use Kerberos DES encryption types for this account' flag set
Remediation Steps
Identify accounts using Get-ADUser -Filter {UseDESKeyOnly -eq $true -and AdminCount -eq 1}. Clear the DES-only flag and ensure accounts support AES256 encryption. Rotate passwords on affected accounts to generate new AES-based Kerberos keys
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-12 SC-13
MITRE ATT&CK: T1558 T1078.002
Anssi: R36
CisAd: 4.3.5
Unknown ADPRIV-015 Privileged Accounts No MFA Indicator AD Privileged Account Security High FAIL Not enforced
Description
Privileged accounts should be protected by multi-factor authentication for all interactive and remote logons. Without MFA, a stolen password alone is sufficient to gain full domain administrative access
Current Value
Not enforced
Recommended Value
All privileged accounts required to use MFA via smart card, Windows Hello for Business, or FIDO2. 'Smart card is required for interactive logon' flag set where applicable
Remediation Steps
Review privileged accounts for smart card logon requirement using Get-ADUser -Filter {SmartcardLogonRequired -eq $false -and AdminCount -eq 1}. Deploy smart card or Windows Hello for Business authentication for all privileged accounts. Enable 'Smart card is required for interactive logon' flag on Tier 0 accounts
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-2(1) IA-2(2)
MITRE ATT&CK: T1078.002
CIS Benchmark: 1.1.6
Anssi: R5
CisAd: 4.4.1
Unknown ADPRIV-017 Privileged Accounts Old Passwords AD Privileged Account Security High FAIL Excessive permissions found
Description
Privileged accounts with passwords that have not been changed in over 90 days have an extended exposure window. If credentials were compromised, the attacker retains access for the entire period the password remains unchanged
Current Value
Excessive permissions found
Recommended Value
All privileged account passwords changed within the last 60 days
Remediation Steps
Identify privileged accounts with old passwords using Get-ADUser -Filter {AdminCount -eq 1} -Properties PasswordLastSet | Where-Object {$_.PasswordLastSet -lt (Get-Date).AddDays(-90)}. Force password rotation on all identified accounts. Implement FGPP with 60-day maximum password age for privileged accounts
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1078.002
Anssi: R37
CisAd: 4.5.2
Unknown ADPRIV-019 Disabled Accounts in Privileged Groups AD Privileged Account Security High FAIL Excessive permissions found
Description
Disabled accounts remaining in privileged groups create risk because re-enabling the account (intentionally or through compromise) immediately grants full privileged access. Disabled accounts should be removed from all privileged groups
Current Value
Excessive permissions found
Recommended Value
No disabled accounts in any privileged groups
Remediation Steps
Identify disabled accounts in privileged groups using Get-ADGroupMember 'Domain Admins' -Recursive | Get-ADUser | Where-Object {$_.Enabled -eq $false}. Repeat for all privileged groups. Remove disabled accounts from all privileged group memberships immediately
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-2(3) AC-2
MITRE ATT&CK: T1078.002 T1098
Anssi: R38
CisAd: 4.6.2
Unknown ADPRIV-024 Service Accounts in Privileged Groups AD Privileged Account Security High FAIL Excessive permissions found
Description
Service accounts in privileged groups present elevated risk because they typically have passwords that do not expire, are shared among administrators, may be stored in scripts or configuration files, and run on multiple servers where credentials can be harvested
Current Value
Excessive permissions found
Recommended Value
No service accounts in privileged groups. Service accounts should use delegated permissions scoped to minimum required access
Remediation Steps
Identify service accounts in privileged groups by reviewing all members and checking for accounts used as service logon identities. Remove service accounts from privileged groups and grant only the specific permissions needed via delegation. Migrate to Group Managed Service Accounts (gMSA) where possible
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6(1) AC-6(5)
MITRE ATT&CK: T1078.002 T1078
Anssi: R40
CisAd: 4.9.1
Unknown ADPRIV-025 Computer Accounts in Privileged Groups AD Privileged Account Security High FAIL Excessive permissions found
Description
Computer accounts in privileged groups grant any process running as SYSTEM on those computers the privileges of the group. An attacker who compromises such a machine gains Domain Admin equivalent access, significantly expanding the lateral movement attack surface
Current Value
Excessive permissions found
Recommended Value
No computer accounts in any privileged groups
Remediation Steps
Enumerate privileged group members and identify any computer accounts using Get-ADGroupMember 'Domain Admins' | Where-Object {$_.objectClass -eq 'computer'}. Repeat for all privileged groups. Remove computer accounts immediately and investigate why they were added
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6(1) AC-2
MITRE ATT&CK: T1078.002
CisAd: 4.6.3
Unknown ADPRIV-026 Privileged Users Local Logon on DCs AD Privileged Account Security High FAIL Disabled
Description
Only designated Tier 0 administrative accounts should be permitted to log on locally to domain controllers. Allowing non-Tier 0 accounts to log on to DCs exposes privileged credentials to credential harvesting attacks on less-secured workstations
Current Value
Disabled
Recommended Value
Only Domain Admins and designated Tier 0 accounts allowed local logon on DCs. 'Allow log on locally' restricted via GPO on Domain Controllers OU
Remediation Steps
Configure via Group Policy applied to Domain Controllers OU: Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > User Rights Assignment > 'Allow log on locally' = Administrators, Domain Admins only. Remove all other entries and test thoroughly
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6(1) AC-3
MITRE ATT&CK: T1078.002 T1003
CIS Benchmark: 2.2.7
Anssi: R7
CisAd: 4.10.1
Unknown ADPRIV-027 Privileged Users RDP on DCs AD Privileged Account Security High FAIL Excessive permissions found
Description
Remote Desktop access to domain controllers should be strictly limited to designated Tier 0 administrators. RDP sessions cache credentials that can be harvested, and excessive RDP access increases the attack surface for credential theft and lateral movement to DCs
Current Value
Excessive permissions found
Recommended Value
Only designated Tier 0 administrative accounts allowed RDP access to DCs. 'Allow log on through Remote Desktop Services' restricted via GPO
Remediation Steps
Configure via Group Policy applied to Domain Controllers OU: Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > User Rights Assignment > 'Allow log on through Remote Desktop Services' = Administrators only. Consider using Remote Credential Guard or Restricted Admin mode for RDP sessions
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6(1) AC-3 AC-17
MITRE ATT&CK: T1078.002 T1021.001
CIS Benchmark: 2.2.26
Anssi: R7
CisAd: 4.10.2
Unknown ADPRIV-029 Protected Users Group Audit AD Privileged Account Security High FAIL Disabled
Description
The Protected Users security group provides hardened authentication protections including disabling NTLM authentication, enforcing AES Kerberos encryption, preventing credential caching, and setting short TGT lifetimes. All Tier 0 privileged accounts should be members
Current Value
Disabled
Recommended Value
All Tier 0 privileged user accounts are members of the Protected Users group
Remediation Steps
Add all Tier 0 accounts to the Protected Users group using Add-ADGroupMember -Identity 'Protected Users' -Members <account>. Test each account first as Protected Users disables NTLM and credential delegation which may break legacy applications. Note: service accounts and computer accounts should NOT be added
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 IA-5(2)
MITRE ATT&CK: T1003 T1550.003 T1078.002
CIS Benchmark: 18.3.1
Anssi: R5
CisAd: 4.12.1
Unknown ADPRIV-030 Privileged Users Not in Protected Users AD Privileged Account Security High FAIL Excessive permissions found
Description
Privileged accounts that are not members of the Protected Users group lack hardened authentication protections and remain vulnerable to credential theft techniques including NTLM relay, credential caching, and long-lived Kerberos tickets. Every eligible privileged account should be protected
Current Value
Excessive permissions found
Recommended Value
All eligible privileged user accounts enrolled in Protected Users group. Exceptions documented with compensating controls
Remediation Steps
Compare privileged group members against Protected Users membership. For each privileged account not in Protected Users, evaluate compatibility (NTLM dependencies, delegation requirements) and add to the group. Document any exceptions with specific technical reasons and compensating controls
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 IA-5(2)
MITRE ATT&CK: T1003 T1557 T1078.002
Anssi: R5
CisAd: 4.12.2
Unknown ADPWD-001 Default Domain Password Policy AD Password & Lockout Policies High FAIL Non-compliant
Description
The Default Domain Policy defines the baseline password and lockout settings for all domain users. This policy should enforce strong password requirements as it applies to every account not covered by a more specific fine-grained password policy
Current Value
Non-compliant
Recommended Value
Minimum length 14 characters, complexity enabled, maximum age 365 days, minimum age 1 day, history 24 passwords
Remediation Steps
Review the Default Domain Policy using Get-ADDefaultDomainPasswordPolicy. Configure via Group Policy Management: Default Domain Policy > Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy. Set values per organizational security requirements
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1110.001 T1110.003
CIS Benchmark: 1.1.1 1.1.2 1.1.3 1.1.4 1.1.5
Anssi: R34
CisAd: 5.1.1
Unknown ADPWD-004 Minimum Password Length AD Password & Lockout Policies High FAIL 4 characters
Description
Passwords below 14 characters are vulnerable to offline brute-force cracking with modern GPU hardware. NIST SP 800-63B recommends supporting passwords up to 64 characters and setting a minimum that balances security with usability. For AD environments, 14 characters is the minimum recommended baseline
Current Value
4 characters
Recommended Value
Minimum 14 characters for standard users, 25 characters for privileged accounts
Remediation Steps
Configure minimum password length in the Default Domain Policy or appropriate FGPP: Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy > Minimum password length = 14. Create a stricter FGPP for privileged accounts requiring 25+ characters
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1110.001 T1110.003
CIS Benchmark: 1.1.4
Anssi: R34
CisAd: 5.2.1
Unknown ADPWD-005 Password Complexity Requirement AD Password & Lockout Policies High FAIL Not required
Description
Windows password complexity requires at least three of four character categories (uppercase, lowercase, digits, special characters) and that the password does not contain the user's account name. While NIST no longer mandates complexity, disabling it in AD without compensating controls (such as banned word lists) significantly weakens passwords
Current Value
Not required
Recommended Value
Complexity enabled. Ideally supplemented with Azure AD Password Protection or custom banned word lists for defense against common patterns
Remediation Steps
Verify complexity is enabled in the Default Domain Policy: Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy > 'Password must meet complexity requirements' = Enabled. Consider deploying Azure AD Password Protection for additional banned password enforcement
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1110.001 T1110.003
CIS Benchmark: 1.1.5
Anssi: R34
CisAd: 5.2.2
Unknown ADPWD-006 Account Lockout Policy AD Password & Lockout Policies High FAIL No lockout configured
Description
Account lockout policies protect against online brute-force and password spraying attacks by locking accounts after a threshold of failed attempts. Without lockout, attackers can attempt unlimited password guesses against any account. However, overly aggressive lockout creates denial-of-service risk
Current Value
No lockout configured
Recommended Value
Account lockout threshold: 5-10 attempts. Lockout duration: 15-30 minutes. Reset counter after: 15-30 minutes
Remediation Steps
Configure account lockout in Default Domain Policy: Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Account Lockout Policy. Set threshold to 5-10 attempts, duration to 15-30 minutes, and observation window to 15-30 minutes. Monitor for lockout events that may indicate attacks
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-7
MITRE ATT&CK: T1110.001 T1110.003
CIS Benchmark: 1.2.1 1.2.2 1.2.3
Anssi: R35
CisAd: 5.3.1
Unknown ADPWD-009 Users with Password Never Expires AD Password & Lockout Policies High FAIL Never
Description
Accounts with the 'Password Never Expires' flag bypass the maximum password age policy. While this may be acceptable for managed service accounts (gMSAs handle rotation automatically), user accounts with this flag retain compromised passwords indefinitely
Current Value
Never
Recommended Value
No user accounts with Password Never Expires. Only Group Managed Service Accounts may have automatic rotation exemptions
Remediation Steps
Identify accounts using Get-ADUser -Filter {PasswordNeverExpires -eq $true -and Enabled -eq $true} -Properties PasswordNeverExpires. Review each account for business justification. Clear the flag on user accounts and migrate service accounts to gMSA where possible. Document any approved exceptions with compensating controls
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1078.002
CIS Benchmark: 1.1.4
Anssi: R36
CisAd: 5.4.1
Unknown ADPWD-011 Duplicate Password Hashes AD Password & Lockout Policies High FAIL Disabled
Description
Multiple accounts sharing the same password hash indicate password reuse, commonly used passwords, or accounts with default passwords. Password reuse amplifies the impact of any single credential compromise, allowing lateral movement across multiple accounts
Current Value
Disabled
Recommended Value
No clusters of accounts sharing identical password hashes. Each account should have a unique password
Remediation Steps
Extract and compare NT hashes using DCSync-capable tools (DSInternals) with appropriate authorization. Identify clusters of accounts sharing hashes. Force password changes on all accounts in duplicate clusters. Implement password filters to prevent common passwords and consider deploying Azure AD Password Protection
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1110.002 T1078.002
CisAd: 5.5.2
Unknown ADPWD-012 Passwords in HaveIBeenPwned Database AD Password & Lockout Policies High FAIL Disabled
Description
Passwords that appear in known breach databases are actively used in credential stuffing attacks. Comparing AD password hashes against the HaveIBeenPwned database identifies accounts using compromised passwords that are likely to be targeted
Current Value
Disabled
Recommended Value
No active accounts using passwords found in the HaveIBeenPwned database
Remediation Steps
Compare NT hashes against the HaveIBeenPwned Passwords database (downloadable hash list) using tools like DSInternals Test-PasswordQuality. Force immediate password changes on all accounts with matching hashes. Deploy Azure AD Password Protection or custom password filters to block known breached passwords going forward
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1110.002 T1078.002
CisAd: 5.5.3
Unknown ADPWD-014 Default/Common Passwords AD Password & Lockout Policies High FAIL Disabled
Description
Accounts using default, common, or trivially guessable passwords (such as Password1, Welcome1, or the account name) are the first targets in password spraying attacks. These passwords are included in every attacker wordlist and are often tested first
Current Value
Disabled
Recommended Value
No accounts using passwords from the top 1000 most common password lists or matching default password patterns
Remediation Steps
Test password hashes against common password lists (such as SecLists) using DSInternals Test-PasswordQuality. Force immediate password changes on all accounts with common passwords. Implement Azure AD Password Protection which includes a global banned password list updated by Microsoft
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1110.001 T1110.003 T1078.002
Anssi: R34
CisAd: 5.5.5
Unknown ADPWD-016 LAPS Deployment Status AD Password & Lockout Policies High FAIL Disabled
Description
Local Administrator Password Solution (LAPS) provides unique, randomly generated local administrator passwords for each computer, stored securely in AD. Without LAPS, local admin passwords are typically identical across all machines, enabling trivial lateral movement after capturing one hash
Current Value
Disabled
Recommended Value
LAPS deployed to 100% of domain-joined Windows computers. No computers with missing or expired LAPS passwords
Remediation Steps
Deploy the LAPS client (CSE) to all domain-joined computers via GPO, SCCM, or Intune. Configure LAPS GPO settings for password complexity, length (at least 20 characters), and age (30 days). Verify deployment by checking the ms-Mcs-AdmPwd or msLAPS-Password attribute on computer objects. Investigate any computers without LAPS passwords
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1) AC-6
MITRE ATT&CK: T1078.003 T1003
CIS Benchmark: 18.2.1
Anssi: R42
NsaAsd: LAPS-1
CisAd: 5.7.1
Unknown ADPWD-021 Account Lockout Threshold AD Password & Lockout Policies High FAIL No lockout configured
Description
The account lockout threshold defines the number of failed logon attempts before an account is locked. A threshold that is too high (or zero, meaning no lockout) allows extensive password spraying, while a threshold that is too low enables easy denial of service
Current Value
No lockout configured
Recommended Value
Lockout threshold between 5-10 failed attempts
Remediation Steps
Configure in Default Domain Policy: Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Account Lockout Policy > 'Account lockout threshold' = 5-10 attempts. A value of 0 disables lockout entirely and should be avoided. Balance between security and usability based on organizational needs
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-7
MITRE ATT&CK: T1110.001 T1110.003
CIS Benchmark: 1.2.1
Anssi: R35
CisAd: 5.3.2
Unknown ADSCRIPT-001 NETLOGON Share Permissions AD Logon Scripts & Network Shares High FAIL Disabled
Description
The NETLOGON share hosts logon scripts that execute on every domain-joined system during user logon. Overly permissive NTFS or share permissions on NETLOGON allow any authenticated user to modify scripts, enabling widespread code execution. Only Domain Admins and authorized administrators should have write access
Current Value
Disabled
Recommended Value
NETLOGON share: Authenticated Users Read only; write access limited to Domain Admins and authorized GPO administrators
Remediation Steps
Review NTFS permissions on the NETLOGON folder (typically %SystemRoot%\SYSVOL\sysvol\<domain>\Scripts) on each domain controller. Remove write, modify, or full control permissions for non-administrative groups. Verify share permissions match NTFS permissions. Ensure permissions are consistent across all domain controllers via DFSR replication.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-3 AC-6 CM-5
MITRE ATT&CK: T1059 T1222.001
Anssi: vuln_netlogon_permissions
Unknown ADSCRIPT-002 SYSVOL Share Permissions AD Logon Scripts & Network Shares High FAIL Anyone (no restrictions)
Description
The SYSVOL share contains Group Policy templates, scripts, and configuration files that are applied to all domain-joined systems. Incorrect SYSVOL permissions can allow unauthorized users to modify Group Policy settings, deploy malicious scripts, or tamper with security configurations affecting the entire domain
Current Value
Anyone (no restrictions)
Recommended Value
SYSVOL share: Authenticated Users Read only; write access limited to Domain Admins and SYSTEM
Remediation Steps
Audit NTFS permissions on the SYSVOL folder tree on each domain controller. The root SYSVOL folder should grant Authenticated Users Read and Execute. GPO subfolders should match the permissions defined on the corresponding GPC object in AD. Run dcdiag /test:sysvolcheck to identify permission issues. Reset permissions using icacls if necessary.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-3 AC-6 CM-5
MITRE ATT&CK: T1484.001 T1222.001
Anssi: vuln_sysvol_permissions
Unknown ADSCRIPT-005 LOLBins Usage in Scripts AD Logon Scripts & Network Shares High FAIL Disabled
Description
Living Off The Land Binaries (LOLBins) are legitimate Windows executables that can be abused for malicious purposes. Their presence in logon scripts may indicate an attacker has injected malicious commands that blend in with normal operations. Common LOLBins include certutil, bitsadmin, mshta, regsvr32, rundll32, and wscript used for downloading or executing payloads
Current Value
Disabled
Recommended Value
No LOLBins usage in logon scripts unless documented and operationally justified
Remediation Steps
Scan all scripts for references to known LOLBins including certutil, bitsadmin, mshta, regsvr32, rundll32, wscript, cscript, msiexec, installutil, regasm, regsvcs, msconfig, and control. Review each occurrence to determine if the usage is legitimate. Replace LOLBins with safer alternatives where possible. Document any operationally required LOLBins usage.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6 SI-3 SI-7
MITRE ATT&CK: T1059 T1218
Unknown ADSCRIPT-008 External Resource References AD Logon Scripts & Network Shares High FAIL Anyone (no restrictions)
Description
Logon scripts that reference external resources such as internet URLs, non-domain UNC paths, or cloud storage locations introduce supply chain risk. If the external resource is compromised, all systems executing the script will download and execute malicious content. External references also create data exfiltration opportunities
Current Value
Anyone (no restrictions)
Recommended Value
No references to external URLs, internet resources, or non-domain UNC paths in logon scripts
Remediation Steps
Scan all scripts for HTTP/HTTPS URLs, FTP references, non-domain UNC paths, and cloud storage URLs (OneDrive, SharePoint Online, Azure Blob, AWS S3). Replace external references with locally hosted copies on internal file shares. If external resources are required, implement integrity verification (hash checks) before execution. Document all approved external resource dependencies.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-7 SI-7 CM-5
MITRE ATT&CK: T1059 T1105
Unknown ADSCRIPT-010 UNC Paths to Non-DC Locations AD Logon Scripts & Network Shares High FAIL Disabled
Description
Logon scripts that reference UNC paths pointing to non-domain-controller file shares create dependency on additional systems and expand the attack surface. If the referenced file server is compromised, an attacker can modify the shared resources to deliver malicious payloads through the trusted logon script mechanism. UNC paths can also be exploited for NTLM relay attacks
Current Value
Disabled
Recommended Value
All script UNC paths reference SYSVOL or NETLOGON on domain controllers; no references to non-DC file shares for script content
Remediation Steps
Scan all scripts for UNC paths (\\server\share patterns). Identify paths that do not point to the domain SYSVOL or NETLOGON shares. Migrate referenced resources to the NETLOGON share where appropriate. For legitimate file share references, ensure the target servers are Tier 0 or Tier 1 assets with appropriate hardening. Document all approved non-DC UNC path dependencies.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-7 AC-3 CM-5
MITRE ATT&CK: T1187 T1557 T1059
Unknown ADSTALE-005 Obsolete OS Computers AD Stale & Obsolete Objects High FAIL Disabled
Description
Domain-joined computers running obsolete operating systems (Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008) that are no longer receiving any security updates represent high-risk assets. These systems contain known unpatched vulnerabilities that are actively exploited by attackers and cannot support modern security controls such as Credential Guard or LAPS
Current Value
Disabled
Recommended Value
No computers running Windows XP, Server 2003, Vista, or Server 2008 joined to the domain
Remediation Steps
Query computer accounts by operatingSystem attribute to identify obsolete OS versions. Verify that identified systems are still active using lastLogonTimestamp and ping tests. Create a migration plan to upgrade or replace obsolete systems. For systems that cannot be immediately upgraded, implement network isolation using VLANs and firewall rules. Disable computer accounts for confirmed decommissioned systems
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-2 CM-6
MITRE ATT&CK: T1210
Anssi: R03
CisAd: 9.3.1
Unknown ADSTALE-006 Unsupported OS Versions AD Stale & Obsolete Objects High FAIL Disabled
Description
Domain-joined computers running operating systems that are past their end-of-support date (Windows 7, Windows 8.1, Windows Server 2008 R2, Windows Server 2012/R2) no longer receive regular security patches. While Extended Security Updates may be available for some, these systems present elevated risk and should be identified, tracked, and prioritized for migration to supported platforms
Current Value
Disabled
Recommended Value
No computers running end-of-support operating systems unless covered by Extended Security Updates with a documented migration plan
Remediation Steps
Query computer accounts by operatingSystem attribute to identify end-of-support OS versions. Determine which systems are covered by Extended Security Updates (ESU). Create migration timelines for all unsupported systems. Implement compensating controls for systems that cannot be immediately upgraded: network segmentation, enhanced monitoring, restricted service access. Track progress against migration timelines
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-2
MITRE ATT&CK: T1210
Anssi: R03
CisAd: 9.3.2
Unknown ADTIER-003 Hypervisor / Virtualization Service Accounts in Privileged Groups Tier-0 Hygiene & Hybrid Identity Surface High FAIL Excessive permissions found
Description
vCenter / Hyper-V / SCVMM / Citrix / Nutanix integrations with AD often use a service account configured during setup. If that account is a Domain Admin, then compromise of the hypervisor management plane (or the host's SSO database) cascades to AD. The hypervisor is conceptually Tier-0 already; its AD identity should match.
Current Value
Excessive permissions found
Recommended Value
Hypervisor service accounts have only the rights documented by the vendor (typically read for inventory + specific OU writes if VM-AD integration is in use). Not in Domain Admins.
Remediation Steps
Review the AD service account for each hypervisor product. Apply vendor least-privilege guidance. For vCenter: use the documented SSO identity source pattern rather than mapping a Domain Admin. For Hyper-V/SCVMM: scope service-account rights to the OUs hosting VM computer accounts. Treat the hypervisor management host as Tier-0 in your administrative model.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6
MITRE ATT&CK: T1078.002
CisAd: 8.2.2
Unknown ADTIER-005 SQL / Database Service Accounts in Privileged Groups Tier-0 Hygiene & Hybrid Identity Surface High FAIL Excessive permissions found
Description
SQL Server / MySQL / PostgreSQL service accounts in Domain Admins are common in environments where the DBA team installed SQL with default 'Use existing AD account' guidance and picked an admin account out of convenience. Once the database server is reachable on the network, a SQL credential compromise or a SQL Server vulnerability gives the attacker Domain Admin directly.
Current Value
Excessive permissions found
Recommended Value
Database service accounts run as gMSAs or dedicated service identities with no privileged-group membership.
Remediation Steps
Migrate SQL service accounts to gMSA where supported. For accounts that must remain user-based, remove privileged group membership and grant only the local rights the database engine requires (Log on as a service, Bypass traverse checking, Adjust memory quotas for a process — see Microsoft docs for the specific rights).
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6
MITRE ATT&CK: T1078.002
CisAd: 8.2.4
Unknown ADTIER-006 Tier-0 Admin Accounts Outside a Dedicated Tier-0 OU Tier-0 Hygiene & Hybrid Identity Surface High FAIL Excessive permissions found
Description
If your Domain Admins live in the same OU as regular users, every GPO that targets users (logon scripts, browser policy, mapped drives, etc.) also applies to your Domain Admins — which means anyone who can edit those GPOs can run code as a Domain Admin at next logon. The Microsoft tiered model recommends a dedicated Tier-0 admin OU with restricted GPO authorship and restricted logon rights.
Current Value
Excessive permissions found
Recommended Value
All Domain Admins, Enterprise Admins, and Schema Admins members are in a dedicated Tier-0 OU (typically OU=Tier-0,OU=Admin) with restricted GPO authorship.
Remediation Steps
Create OU=Tier-0,OU=Admin if it doesn't exist. Move all members of Domain/Enterprise/Schema Admins into it. Restrict the GPO authorship on that OU (only Tier-0 admins themselves). Apply a dedicated logon-restriction GPO so Tier-0 accounts can only log on to Tier-0 hosts. Block inheritance on the OU.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-3 AC-6
MITRE ATT&CK: T1078
CisAd: 8.3.1
Unknown ADTIER-007 Service Accounts with Interactive Logon Rights via Privileged Group Tier-0 Hygiene & Hybrid Identity Surface High FAIL Disabled
Description
Service accounts that are members of Domain Admins (or any group granted 'Allow log on locally' via default privileged-group membership) can be used interactively. Attackers love this — capture a service account password (Kerberoasting, registry, scripts in SYSVOL), use it interactively on a workstation, dump LSASS, and pivot. Service accounts should not be able to log on interactively to anything but the host they serve.
Current Value
Disabled
Recommended Value
Service accounts (heuristic: sAMAccountName starts with svc/sa/service or has SPN + no interactive logon recently) are explicitly denied 'Allow log on locally' and 'Allow log on through Remote Desktop Services' via the Default Domain Controllers Policy and a dedicated Tier-1/Tier-2 logon-restriction GPO.
Remediation Steps
Identify service accounts (SPN-bearing, naming convention, or business inventory). Apply a Default Domain Policy GPO: Computer Configuration > Windows Settings > Security Settings > Local Policies > User Rights Assignment > 'Deny log on locally' = <service-accounts-group>. Add the same accounts to 'Deny log on through Remote Desktop Services'. Add them to Protected Users where supported (Server 2012 R2+).
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6
MITRE ATT&CK: T1078.002 T1003.001
CisAd: 8.3.2
Unknown ADTRADE-002 DCShadow Indicator (Rogue Configuration-Partition Servers) AD Adversary Tradecraft Indicators High FAIL Disabled
Description
DCShadow (Vincent LE TOUX / Benjamin Delpy, BlueHat IL 2018) registers an attacker-controlled host as a domain controller by writing nTDSDSA + server objects under CN=Sites,CN=Configuration. The fake DC is then used to inject malicious replication data (SID history, password hashes) without ever being a real DC. NOTE: on long-lived domains an unmatched server object is far more often LINGERING DC METADATA (a DC removed without 'ntdsutil metadata cleanup') than an actual DCShadow attack, so this is rated High rather than Critical — investigate the whenCreated timestamp to distinguish a recently created (suspicious) object from old stale metadata.
Current Value
Disabled
Recommended Value
All server objects under CN=Sites,CN=Configuration correspond to real, inventoried domain controllers. No recently created server objects that don't match a known DC.
Remediation Steps
Enumerate: Get-ADObject -Filter {objectClass -eq 'server'} -SearchBase "CN=Sites,$((Get-ADRootDSE).configurationNamingContext)" -Properties whenCreated, dNSHostName | Sort whenCreated. Cross-reference with your DC inventory (Get-ADDomainController -Filter *). Any server object not matching a real DC, especially recently created, demands immediate IR — DCShadow is a domain-takeover-grade primitive. Monitor for 5137 / 5141 events on schema container as a detection-time signal.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-4 AU-12
MITRE ATT&CK: T1207
CisAd: 10.2.1
Unknown ADTRADE-004 RODC Password Replication Policy Hygiene AD Adversary Tradecraft Indicators High FAIL Non-compliant
Description
Read-Only Domain Controllers cache passwords for the principals listed in their Password Replication Policy (PRP). If a Tier-0 account (Domain Admin, Enterprise Admin, krbtgt) is reachable by an RODC's PRP — directly or via group nesting — compromising the RODC compromises those accounts. The default 'Denied RODC Password Replication Group' should explicitly contain DA / EA / SA / Schema Admins / krbtgt; some environments customize the policy and accidentally remove those denials.
Current Value
Non-compliant
Recommended Value
All RODCs in the domain have a Password Replication Policy where Domain Admins, Enterprise Admins, Schema Admins, krbtgt, and Account Operators are members of the Deny side. No high-privileged accounts are members of the Allow side.
Remediation Steps
For each RODC: Get-ADDomainController -Filter {IsReadOnly -eq $true} | ForEach-Object { Get-ADDomainControllerPasswordReplicationPolicy -Identity $_ -Allowed; Get-ADDomainControllerPasswordReplicationPolicy -Identity $_ -Denied }. Verify the Denied list contains the 'Denied RODC Password Replication Group' built-in. If your environment has no RODCs this check is N/A — PASS. Microsoft's RODC planning guide has the canonical PRP template.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6
MITRE ATT&CK: T1003.001
CisAd: 10.4.1
Unknown ADTRADE-005 Entra Seamless SSO Computer Account (AZUREADSSOACC$) Key Rotation AD Adversary Tradecraft Indicators High FAIL Disabled
Description
When Entra (Azure AD) Seamless Single Sign-On is enabled for hybrid identity, AD creates a computer account named AZUREADSSOACC$. Its password is the shared Kerberos key Entra uses to validate SSO tickets. Microsoft documents that this key is NOT rotated automatically — administrators must roll it. If an attacker extracts the AZUREADSSOACC$ key (it is a normal NT hash readable via DCSync or from a DC), they can forge Kerberos Silver Tickets for the Azure AD service and authenticate as ANY synchronized hybrid user, with no further interaction, for as long as the key remains valid. A key that has not been rotated in over 90 days dramatically widens that window.
Current Value
Disabled
Recommended Value
AZUREADSSOACC$ Kerberos key rotated at least every 90 days (roll it twice per rotation to invalidate the previous key).
Remediation Steps
Rotate the Seamless SSO key on a machine with the Entra Connect / Azure AD module: Import-Module 'C:\Program Files\Microsoft Azure Active Directory Connect\AzureADSSO.psd1'; New-AzureADSSOAuthenticationContext; Update-AzureADSSOForest. Perform the rotation twice (the account stores current + previous key) and schedule it on a recurring basis. If Seamless SSO is no longer used, disable it and delete the AZUREADSSOACC$ object.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5 AC-6
MITRE ATT&CK: T1558.002 T1550.003
Anssi: vuln1_azureadssoacc_pwd_change
CisAd: 6.1.1
Unknown ADTRADE-008 Key Admins / Enterprise Key Admins Group Membership AD Adversary Tradecraft Indicators High FAIL Excessive permissions found
Description
The Key Admins (domain RID 526) and Enterprise Key Admins (RID 527) groups are granted the right to write the msDS-KeyCredentialLink attribute across the domain/forest. That makes any member a domain-wide shadow-credential primitive: a member can plant key credentials on any account and authenticate as it via PKINIT. These groups ship EMPTY and should stay empty unless a specific Windows Hello for Business key-provisioning workflow demonstrably requires them. Any member is an escalation path that must be justified.
Current Value
Excessive permissions found
Recommended Value
Key Admins and Enterprise Key Admins groups are empty (no standing members).
Remediation Steps
Review every member of Key Admins and Enterprise Key Admins. Remove any account that does not have a documented, ongoing need to provision Windows Hello for Business keys. If WHfB key provisioning requires delegated rights, scope them to a dedicated service account with the narrowest possible permissions rather than membership in these domain-wide groups. Treat unexpected members as a potential persistence mechanism.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 AC-2
MITRE ATT&CK: T1556 T1098
Anssi: vuln1_permissions_keycredentiallink
CisAd: 6.2.2
Unknown ADTRADE-009 Cert Publishers Group Membership AD Adversary Tradecraft Indicators High FAIL Vulnerable configuration
Description
Members of the Cert Publishers group (domain RID 517) are permitted to publish certificates to the NTAuth store and to user/computer objects. By default the group contains only the Enterprise CA computer account(s). A user or service account placed in this group gains the ability to influence which certificates are trusted for authentication, which is a stepping stone in several AD CS escalation paths (ESC-class attacks) and can enable certificate-based impersonation. Computer-account membership (the CA hosts themselves) is expected; any non-computer member is a finding.
Current Value
Vulnerable configuration
Recommended Value
Cert Publishers contains only the Enterprise CA computer account(s) — no user or service accounts.
Remediation Steps
Remove any user or service account from the Cert Publishers group; only Enterprise CA computer accounts belong there. Review NTAuth store contents (certutil -viewstore -enterprise NTAuth) for unexpected CA certificates. Harden AD CS broadly: audit certificate template enrollment permissions and the ESC1-ESC8 misconfiguration surface.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 IA-5
MITRE ATT&CK: T1649 T1556.004
Anssi: vuln1_adcs_cert_publishers
CisAd: 6.4.1
Unknown ADTRADE-010 group Managed Service Account (gMSA) Posture & Password Exposure AD Adversary Tradecraft Indicators High FAIL Disabled
Description
group Managed Service Accounts (gMSA) hold 240-bit passwords that AD generates and rotates automatically, eliminating Kerberoasting of weak service-account passwords and manual rotation toil. Two posture concerns: (1) whether gMSAs are used at all for service identities, and (2) who is authorised to retrieve the managed password, controlled by the msDS-GroupMSAMembership security descriptor (PrincipalsAllowedToRetrieveManagedPassword). If that descriptor grants a broad principal (Everyone, Authenticated Users, Domain Users) or a non-privileged principal, that principal can recover the cleartext gMSA password (e.g. GMSAPasswordReader) and fully impersonate the service.
Current Value
Disabled
Recommended Value
Service identities run as gMSAs; msDS-GroupMSAMembership is scoped to only the specific hosts that must run the service (no broad or non-privileged principals).
Remediation Steps
For each gMSA, set PrincipalsAllowedToRetrieveManagedPassword to the exact computer accounts (or a tightly-scoped group) that run the service: Set-ADServiceAccount -Identity <gmsa> -PrincipalsAllowedToRetrieveManagedPassword <hosts>. Remove Everyone / Authenticated Users / Domain Users from that list. Where service accounts still use static user-account passwords, migrate them to gMSAs to gain automatic rotation and Kerberoasting resistance.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5 AC-6
MITRE ATT&CK: T1552 T1558.003
Anssi: vuln2_gmsa_principalsallowedtoretrievemanagedpassword
CisAd: 6.5.1
Unknown ADTRUST-006 Selective Authentication Status AD Trust Relationships High FAIL Disabled
Description
Selective authentication restricts which users from a trusted domain can authenticate to resources in your domain by requiring explicit permissions on each resource. Without it, all authenticated users from the trusted domain can access any resource they have permissions to, expanding the attack surface significantly
Current Value
Disabled
Recommended Value
Selective authentication enabled on all forest trusts. Allowed-to-Authenticate permissions granted only on required resources
Remediation Steps
Enable selective authentication on forest trusts via Active Directory Domains and Trusts > Properties of the trust > Authentication tab > Select 'Selective authentication'. Then grant 'Allowed to Authenticate' permission on specific computer objects that external users need to access
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-3 AC-4 AC-6
MITRE ATT&CK: T1482 T1078.002
Anssi: R33
CisAd: 3.2.3
Unknown ADTRUST-010 Trust Key Age and Rotation AD Trust Relationships High FAIL SID filtering disabled
Description
Trust passwords (inter-realm keys) should be rotated regularly. Stale trust keys increase the window for credential-based attacks. By default, trust passwords rotate every 30 days, but this should be verified as failed rotations can go undetected
Current Value
SID filtering disabled
Recommended Value
Trust passwords rotated within the last 30 days. Automatic trust password rotation not disabled
Remediation Steps
Check the trust password last set date by examining the trustAuthOutgoing attribute or running 'netdom trust /domain:trusted.domain /verify'. If the trust password is stale, reset it using 'netdom trust /domain:trusted.domain /Reset'. Verify that no GPO or registry setting has disabled automatic trust password rotation
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1) SC-12
MITRE ATT&CK: T1482 T1550.003
CisAd: 3.2.4
Unknown AUTH-002 2SV Enrollment Rate Authentication & Access Controls High FAIL Disabled
Description
All active users should have 2SV enrolled. Low enrollment rates leave accounts vulnerable to credential-based attacks
Affected Entities
Active users not enrolled in 2SV (5):
  • jsmith@sample.org
  • akumar@sample.org
  • mchen@sample.org
  • rlopez@sample.org
  • tokafor@sample.org
Current Value
Disabled
Recommended Value
95% or higher enrollment among active users
Remediation Steps
Admin Console > Reporting > User Reports > Security > Review users without 2SV. Set enrollment deadline via Security > 2-Step Verification
Compliance Mappings
NIST SP 800-53: IA-2(1)
MITRE ATT&CK: T1078.004
CIS Benchmark: 1.2
Unknown AUTH-004 Password Minimum Length Authentication & Access Controls High FAIL 4 characters
Description
Password minimum length should be at least 12 characters to resist brute-force and dictionary attacks
Current Value
4 characters
Recommended Value
Minimum 12 characters
Remediation Steps
Admin Console > Security > Authentication > Password management > Set minimum length to 12 or higher
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1110.001 T1110.003
CIS Benchmark: 1.4
Unknown AUTH-008 Less Secure Apps Access Authentication & Access Controls High FAIL Unreviewed permissions
Description
Less secure apps (apps that don't support modern authentication) should be blocked to prevent credential exposure
Current Value
Unreviewed permissions
Recommended Value
Disabled for all users
Remediation Steps
Admin Console > Security > Authentication > Less secure apps > Set to 'Disable access to less secure apps'
Compliance Mappings
NIST SP 800-53: IA-5(2)
MITRE ATT&CK: T1078.004 T1110
CIS Benchmark: 1.8
Unknown AUTH-010 Recovery Options Configuration Authentication & Access Controls High FAIL Disabled
Description
User self-service recovery should be configured appropriately. Super admins should not have personal recovery options to prevent social engineering
Affected Entities
Super admins with personal recovery options (3):
  • jsmith@sample.org
  • akumar@sample.org
  • mchen@sample.org
Current Value
Disabled
Recommended Value
Super admins: no personal recovery. Regular users: recovery options allowed with admin override
Remediation Steps
Admin Console > Security > Authentication > Account recovery > Disable personal recovery for super admin OU
Compliance Mappings
NIST SP 800-53: IA-5(1) AC-2(4)
MITRE ATT&CK: T1078.004 T1098
CIS Benchmark: 1.10
Unknown AUTH-013 Stale Super Admin Accounts Authentication & Access Controls High FAIL Excessive permissions found
Description
Super admin accounts that have not logged in recently may be orphaned and at risk of compromise. All super admin accounts should be actively managed
Affected Entities
Stale super admin accounts (6):
  • jsmith@sample.org
  • akumar@sample.org
  • mchen@sample.org
  • rlopez@sample.org
  • tokafor@sample.org
  • dwilson@sample.org
Current Value
Excessive permissions found
Recommended Value
No super admin accounts inactive for more than 90 days
Remediation Steps
Admin Console > Directory > Users > Filter by admin role > Review and remove or suspend inactive super admin accounts
Compliance Mappings
NIST SP 800-53: AC-2(3) AC-2(4)
MITRE ATT&CK: T1078.004
CIS Benchmark: 1.13
Unknown AUTH-017 Super Admin Account Self-Recovery Authentication & Access Controls High FAIL Excessive permissions found
Description
Self-service account recovery for super admins is an account-takeover path via social engineering and should be turned off. Super admins should be recovered only by another administrator
Current Value
Excessive permissions found
Recommended Value
Super admin self-recovery disabled in all organizational units
Remediation Steps
Security > Authentication > Account recovery > Turn off 'Allow super admins to recover their account' for all organizational units
Compliance Mappings
NIST SP 800-53: IA-4 AC-6(5)
MITRE ATT&CK: T1078.004 T1098
CIS Benchmark: 1.15
Unknown AZIAM-001 Subscription-level role assignments audit Azure IAM & Resource Security High FAIL Disabled
Description
Subscription-level role assignments grant broad permissions across all resources within a subscription. Overly permissive or stale assignments at this scope can allow lateral movement and unauthorized access to sensitive workloads. Regular audits ensure that only authorized personnel retain subscription-wide privileges.
Current Value
Disabled
Recommended Value
Minimize subscription-level role assignments; prefer resource group or resource-level scoping
Remediation Steps
Review all subscription-level role assignments in Azure IAM and remove any that are stale, unnecessary, or overly broad. Reassign permissions at the resource group or individual resource level where possible. Implement a recurring quarterly access review using Azure AD Access Reviews for subscription-scoped roles.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-2 AC-6
CisAzure: 1.23
Unknown AZIAM-004 Azure Key Vault access policy audit Azure IAM & Resource Security High FAIL Disabled
Description
Azure Key Vault stores cryptographic keys, secrets, and certificates critical to application security and data protection. Overly permissive access policies can expose secrets to unauthorized users or service principals, leading to credential theft or data breaches. Both access policy and RBAC authorization models must be audited for least-privilege adherence.
Current Value
Disabled
Recommended Value
Use Azure RBAC for Key Vault access control; restrict Get/List/Set permissions to minimum required principals
Remediation Steps
Review all Key Vault access policies or RBAC assignments and remove any principals with unnecessary permissions such as Purge or full key management rights. Migrate from the legacy access policy model to Azure RBAC-based authorization for finer-grained control and auditability. Enable Key Vault logging to a Log Analytics workspace and set up alerts for suspicious access patterns.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 SC-12
CisAzure: 8.5
Unknown AZIAM-005 Storage account security settings Azure IAM & Resource Security High FAIL Disabled
Description
Azure Storage accounts often contain sensitive business data, backups, and application state that must be protected at rest and in transit. Misconfigured settings such as allowing public blob access, disabling HTTPS enforcement, or using legacy TLS versions create significant data exposure risks. Storage account security settings must be hardened to prevent unauthorized access and data leakage.
Current Value
Disabled
Recommended Value
Enforce HTTPS-only transfer, disable public blob access, require TLS 1.2 minimum, enable infrastructure encryption
Remediation Steps
Set the minimum TLS version to 1.2, enable HTTPS-only transfer, and disable public blob access on all storage accounts. Enable infrastructure encryption for double encryption at rest and configure private endpoints to restrict network access. Review shared access signatures and access keys, rotate keys on a regular schedule, and prefer Azure AD authentication over key-based access.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-8 SC-28
CisAzure: 3.1
Unknown AZIAM-006 Network Security Group rules audit Azure IAM & Resource Security High FAIL Disabled
Description
Network Security Groups control inbound and outbound traffic flow to Azure resources and are a primary network segmentation mechanism. Overly permissive NSG rules, such as allowing unrestricted inbound access from the internet on management ports, expose resources to brute-force attacks and exploitation. Regular audits of NSG rules are essential to maintain a secure network perimeter.
Current Value
Disabled
Recommended Value
Deny all inbound internet traffic by default; allow only required ports from specific source IP ranges
Remediation Steps
Review all NSG rules for overly permissive entries, particularly any rules allowing inbound traffic from 0.0.0.0/0 or Any on ports such as 22, 3389, 445, or 1433. Replace broad allow rules with specific source IP ranges or service tags and remove unused rules. Enable NSG flow logs and integrate with Azure Network Watcher for continuous monitoring of traffic patterns and anomaly detection.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-7
CisAzure: 6.1
Unknown COLLAB-004 Chat External Communication Collaboration & Communication Security High FAIL Anyone (no restrictions)
Description
External chat communication should be restricted to prevent data leakage through direct messages with external users
Current Value
Anyone (no restrictions)
Recommended Value
External chat restricted or disabled for most users
Remediation Steps
Admin Console > Apps > Google Workspace > Google Chat > Chat settings > External chat > Restrict external chat to specific OUs
Compliance Mappings
NIST SP 800-53: AC-4 SC-7
MITRE ATT&CK: T1567 T1048
CIS Benchmark: 5.4
Unknown COLLAB-008 Calendar External Sharing Collaboration & Communication Security High FAIL Anyone (no restrictions)
Description
Calendar sharing with external users should be limited to free/busy information to prevent exposure of meeting details and attendees
Current Value
Anyone (no restrictions)
Recommended Value
External calendar sharing limited to free/busy information only
Remediation Steps
Admin Console > Apps > Google Workspace > Calendar > Sharing settings > External sharing options > Set to 'Only free/busy information'
Compliance Mappings
NIST SP 800-53: AC-3 AC-22
MITRE ATT&CK: T1530 T1589
CIS Benchmark: 5.8
Unknown COLLAB-013 Chat external file sharing disabled (GWS.CHAT.2.1) Collaboration & Communication Security High FAIL Anyone (no restrictions)
Description
SCuBA GWS.CHAT.2.1 requires that external file sharing in Google Chat be disabled (set to no files). Allowing files to be shared with external users through Chat is a direct data-exfiltration path. This check reads chat.chat_file_sharing and fails any organizational unit where external file sharing is not set to NO_FILES.
Current Value
Anyone (no restrictions)
Recommended Value
External file sharing in Chat set to NO_FILES
Remediation Steps
In the Admin console under Apps > Google Workspace > Google Chat > External file sharing, set external file sharing to 'No files' so files cannot be shared to people outside the organization via Chat.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-4 SC-7
Unknown COLLAB-015 Meeting join restricted to the organization (GWS.MEET.2.1) Collaboration & Communication Security High FAIL Disabled
Description
SCuBA GWS.MEET.2.1 requires that access to meetings be restricted so only users in the organization (or trusted Workspace organizations) can join. Leaving meetings open to anyone lets external and unauthenticated parties into sessions that may involve students. This check reads meet.safety_access and fails any organizational unit where meetingsAllowedToJoin is broader than SAME_ORGANIZATION_ONLY / ANY_WORKSPACE_ORGANIZATION.
Current Value
Disabled
Recommended Value
meetingsAllowedToJoin set to SAME_ORGANIZATION_ONLY (or ANY_WORKSPACE_ORGANIZATION)
Remediation Steps
In Google Meet safety settings, restrict who can join meetings to users in your organization, so external/unauthenticated participants cannot join by default.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-3 AC-14 SC-7
Unknown DEVICE-001 MDM Policy Audit Device & Endpoint Management High FAIL Disabled
Description
Mobile devices accessing organizational data should be managed through MDM policies to enforce security controls
Current Value
Disabled
Recommended Value
All mobile devices under MDM management with enforced security policies
Remediation Steps
Admin Console > Devices > Mobile devices > Review device management status > Enable advanced MDM for unmanaged devices
Compliance Mappings
NIST SP 800-53: AC-19 CM-6
MITRE ATT&CK: T1458 T1078.004
CIS Benchmark: 6.1
Unknown DEVICE-002 Device Approval Requirements Device & Endpoint Management High FAIL Unreviewed permissions
Description
Mobile devices should require admin approval before accessing organizational data to prevent unauthorized device access
Current Value
Unreviewed permissions
Recommended Value
Device approval required before accessing organizational data
Remediation Steps
Admin Console > Devices > Mobile & endpoints > Settings > General > Require admin approval for device access
Compliance Mappings
NIST SP 800-53: AC-19(4) IA-3
MITRE ATT&CK: T1078.004
CIS Benchmark: 6.2
Unknown DEVICE-003 Screen Lock Enforcement Device & Endpoint Management High FAIL Disabled
Description
Screen lock should be enforced on all mobile devices to prevent unauthorized physical access to organizational data
Current Value
Disabled
Recommended Value
Screen lock enforced with minimum PIN/password requirements
Remediation Steps
Admin Console > Devices > Mobile & endpoints > Settings > Universal settings > Screen lock > Enforce screen lock with minimum complexity
Compliance Mappings
NIST SP 800-53: AC-11 AC-7
MITRE ATT&CK: T1458
CIS Benchmark: 6.3
Unknown DEVICE-004 Device Encryption Requirements Device & Endpoint Management High FAIL Disabled
Description
Device encryption should be required on all mobile devices to protect data at rest from physical theft or loss
Current Value
Disabled
Recommended Value
Encryption required on all managed devices
Remediation Steps
Admin Console > Devices > Mobile & endpoints > Settings > Universal settings > Encryption > Require device encryption
Compliance Mappings
NIST SP 800-53: SC-28 MP-5
MITRE ATT&CK: T1005
CIS Benchmark: 6.4
Unknown DEVICE-005 Compromised Device Blocking Device & Endpoint Management High FAIL Not enrolled
Description
Compromised devices should be automatically blocked from accessing organizational data to prevent data exposure
Current Value
Not enrolled
Recommended Value
Compromised device detection and blocking enabled
Remediation Steps
Admin Console > Devices > Mobile & endpoints > Settings > Universal settings > Compromised devices > Block compromised devices from accessing data
Compliance Mappings
NIST SP 800-53: SI-4 AC-19
MITRE ATT&CK: T1458
CIS Benchmark: 6.5
Unknown DEVICE-006 Jailbroken/Rooted Device Policy Device & Endpoint Management High FAIL Non-compliant
Description
Jailbroken (iOS) or rooted (Android) devices bypass OS-level security controls and should be blocked from accessing organizational data
Current Value
Non-compliant
Recommended Value
Jailbroken/rooted devices blocked from organizational data access
Remediation Steps
Admin Console > Devices > Mobile & endpoints > Settings > Universal settings > Compromised devices > Block jailbroken/rooted devices
Compliance Mappings
NIST SP 800-53: SI-7 AC-19
MITRE ATT&CK: T1398
CIS Benchmark: 6.6
Unknown DEVICE-008 Chrome Extension Whitelist/Blocklist Device & Endpoint Management High FAIL Disabled
Description
Chrome extensions should be managed through an allowlist or blocklist to prevent malicious extensions from accessing organizational data
Current Value
Disabled
Recommended Value
Extension installation restricted to admin-approved extensions via allowlist
Remediation Steps
Admin Console > Devices > Chrome > Apps & extensions > Configure extension allowlist and blocklist
Compliance Mappings
NIST SP 800-53: CM-7 CM-11
MITRE ATT&CK: T1176
CIS Benchmark: 6.8
Unknown DRIVE-001 External Sharing Defaults Drive Security & Data Protection High FAIL Anyone (no restrictions)
Description
Sharing outside the organization should be restricted or disabled by default to prevent accidental data exposure to external parties
Current Value
Anyone (no restrictions)
Recommended Value
External sharing restricted to allowlisted domains or disabled
Remediation Steps
Admin Console > Apps > Google Workspace > Drive and Docs > Sharing settings > Set sharing outside the organization to 'Off' or 'Allowlisted domains'
Compliance Mappings
NIST SP 800-53: AC-3 AC-4
MITRE ATT&CK: T1567 T1537
CIS Benchmark: 2.1
Unknown DRIVE-002 Link Sharing Default Settings Drive Security & Data Protection High FAIL Anyone (no restrictions)
Description
Default link sharing should be set to 'Restricted' (specific people) rather than broad access to prevent unintended data exposure
Current Value
Anyone (no restrictions)
Recommended Value
Default link sharing set to 'Restricted' (specific people only)
Remediation Steps
Admin Console > Apps > Google Workspace > Drive and Docs > Sharing settings > Set default link sharing to 'Restricted'
Compliance Mappings
NIST SP 800-53: AC-3 AC-6
MITRE ATT&CK: T1530
CIS Benchmark: 2.2
Unknown DRIVE-003 Anyone With the Link Sharing Audit Drive Security & Data Protection High FAIL Disabled
Description
Files shared with 'Anyone with the link' are accessible to anyone on the internet and represent a significant data exposure risk
Current Value
Disabled
Recommended Value
'Anyone with the link' sharing disabled or tightly controlled
Remediation Steps
Admin Console > Apps > Google Workspace > Drive and Docs > Sharing settings > Disable 'Anyone with the link' option or restrict to 'Domain users with the link'
Compliance Mappings
NIST SP 800-53: AC-3 AC-22
MITRE ATT&CK: T1530 T1213
CIS Benchmark: 2.3
Unknown DRIVE-006 Shared Drive External Sharing Drive Security & Data Protection High FAIL Anyone (no restrictions)
Description
External sharing on Shared Drives should be restricted to prevent sensitive organizational data from being shared outside the domain
Current Value
Anyone (no restrictions)
Recommended Value
External sharing on Shared Drives disabled or restricted to allowlisted domains
Remediation Steps
Admin Console > Apps > Google Workspace > Drive and Docs > Sharing settings > Shared drive sharing > Restrict external sharing
Compliance Mappings
NIST SP 800-53: AC-3 AC-4
MITRE ATT&CK: T1537 T1567
CIS Benchmark: 2.6
Unknown DRIVE-009 Third-Party App Drive Access Drive Security & Data Protection High FAIL Unreviewed permissions
Description
Third-party applications with access to Drive data should be reviewed and restricted to prevent unauthorized data exfiltration
Current Value
Unreviewed permissions
Recommended Value
Third-party app access to Drive data restricted and reviewed
Remediation Steps
Admin Console > Security > API controls > Third-party app access > Review and restrict apps with Drive access
Compliance Mappings
NIST SP 800-53: AC-3 AC-20
MITRE ATT&CK: T1530 T1567.002
CIS Benchmark: 2.9
Unknown DRIVE-014 Drive SDK API access disabled (GWS.DRIVEDOCS.4.1) Drive Security & Data Protection High FAIL Disabled
Description
SCuBA GWS.DRIVEDOCS.4.1: the Drive SDK lets third-party apps read and write Drive content via API, a direct data-exfiltration channel when broadly enabled. Reads drive_and_docs.drive_sdk; fails where enableDriveSdkApiAccess is on.
Current Value
Disabled
Recommended Value
Drive SDK API access disabled
Remediation Steps
In Admin console > Apps > Google Workspace > Drive and Docs > Features and Applications, disable Drive SDK unless specific reviewed integrations require it.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-4 AC-3 SC-7
Unknown EIDAPP-003 App Registrations with Added Credentials Entra ID Application & Service Principal Security High FAIL Unreviewed permissions
Description
Application registrations with client secrets or certificates added represent potential persistence mechanisms for attackers. A compromised secret or certificate allows an attacker to authenticate as the application and exercise all of its granted permissions without user interaction. Credentials should be inventoried, rotated on schedule, and removed when no longer needed to limit the window of exposure.
Current Value
Unreviewed permissions
Recommended Value
All application credentials inventoried with defined rotation schedules and no credentials older than 12 months
Remediation Steps
Review all application registrations and examine the Certificates & secrets blade for each. Document all active credentials including their expiration dates and creation timestamps. Remove expired or unused credentials immediately and establish a rotation policy requiring credentials to be renewed at least annually with automated alerts before expiration.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5
MITRE ATT&CK: T1098.001
Unknown EIDAPP-006 Excessive Microsoft Graph Permissions Entra ID Application & Service Principal Security High FAIL Disabled
Description
Applications granted broad Microsoft Graph application permissions such as Directory.ReadWrite.All, Sites.ReadWrite.All, or Mail.ReadWrite gain tenant-wide access to data and configuration without user context. Excessive Graph permissions violate the principle of least privilege and provide attackers who compromise the application with sweeping access to mailboxes, files, directory objects, and tenant settings. Permissions should be scoped to the minimum required for application functionality.
Current Value
Disabled
Recommended Value
All Microsoft Graph permissions scoped to the minimum required with application permissions replaced by delegated permissions where possible
Remediation Steps
Review Microsoft Graph permissions for all application registrations and identify any using broad .All scopes or application-level permissions where delegated permissions would suffice. Replace broad permissions with granular alternatives such as Mail.Read instead of Mail.ReadWrite.All or User.Read.All instead of Directory.Read.All. Use the Microsoft Graph permissions reference to identify the least-privilege permission for each API call the application makes.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6(1)
MITRE ATT&CK: T1098.002
Unknown EIDAPP-007 App Registrations with Azure IAM Role Assignments Entra ID Application & Service Principal Security High FAIL Not required
Description
Application registrations or their corresponding service principals with Azure resource-level IAM role assignments such as Contributor, Owner, or User Access Administrator can modify Azure infrastructure, deploy resources, or escalate privileges across subscriptions. These role assignments extend the application's blast radius beyond Entra ID into the Azure resource plane, enabling infrastructure compromise if application credentials are stolen.
Current Value
Not required
Recommended Value
No application registrations with Azure IAM role assignments above Reader unless documented with business justification and least-privilege scope
Remediation Steps
Review Azure IAM role assignments at the management group, subscription, and resource group levels to identify any assigned to application service principals. Remove Owner and User Access Administrator assignments and replace broad Contributor roles with custom roles scoped to specific resource types and actions. Limit IAM assignments to the narrowest scope possible, preferring resource-group level over subscription-level assignments.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6
CisAzure: 1.23
Unknown EIDAPP-011 Consent Grants Analysis Entra ID Application & Service Principal Security High FAIL Unreviewed permissions
Description
OAuth consent grants authorize applications to access organizational data on behalf of users (delegated) or as the application itself (application-level). Admin consent grants provide tenant-wide access for all users, while user consent grants are scoped to individual users. Malicious or excessive consent grants are a primary technique used in OAuth phishing attacks to gain persistent access to mailboxes, files, and directory data without requiring credentials.
Current Value
Unreviewed permissions
Recommended Value
All admin consent grants reviewed and justified. No user consent grants for high-risk permissions. Regular consent grant reviews established
Remediation Steps
Enumerate all OAuth2 permission grants in the tenant using Microsoft Graph and categorize them as admin consent or user consent. Review admin consent grants for overly broad permissions and revoke any that are no longer justified. Investigate user consent grants for suspicious applications, particularly those requesting Mail.Read, Files.ReadWrite, or other sensitive scopes, and revoke unauthorized grants.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6
MITRE ATT&CK: T1098.003
CisM365: 5.3.1
Unknown EIDAPP-012 User Consent Settings Policy Entra ID Application & Service Principal Security High FAIL Non-compliant
Description
The user consent settings policy controls whether users can grant applications access to organizational data without administrator approval. Permissive consent settings allow users to authorize applications independently, which attackers exploit through illicit consent grant phishing campaigns to gain persistent access. Restricting user consent to verified publishers or disabling it entirely forces all consent through an admin approval workflow.
Current Value
Non-compliant
Recommended Value
User consent disabled or restricted to apps from verified publishers with low-risk permissions only
Remediation Steps
Navigate to Entra ID > Enterprise applications > Consent and permissions > User consent settings. Set user consent to 'Do not allow user consent' or 'Allow user consent for apps from verified publishers, for selected permissions only' with only low-risk permissions selected. Enable the admin consent workflow to provide a structured process for users to request access to applications that require admin approval.
Compliance Mappings
NIST SP 800-53: AC-6
CisM365: 5.3.1
Unknown EIDAPP-015 OAuth2 Permission Grants Review Entra ID Application & Service Principal Security High FAIL Unreviewed permissions
Description
OAuth2 permission grants define the specific permissions that applications have been authorized to exercise, either as delegated permissions acting on behalf of a user or as application permissions acting independently. Accumulated permission grants across many applications can create a complex web of access that is difficult to audit and may include overly broad or unnecessary authorizations. Regular review ensures grants remain aligned with current business requirements.
Current Value
Unreviewed permissions
Recommended Value
All OAuth2 permission grants reviewed quarterly with stale or excessive grants revoked
Remediation Steps
Export all OAuth2 permission grants using Microsoft Graph and categorize them by permission type (delegated vs application), resource, and scope. Identify grants for applications that are no longer active or permissions that exceed what is required for current application functionality. Revoke unnecessary grants through the Entra admin center or Microsoft Graph API and establish a quarterly review cycle for all active grants.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6
MITRE ATT&CK: T1098.003
Unknown EIDAPP-019 Dangling Reply URLs Entra ID Application & Service Principal Security High FAIL Disabled
Description
Reply URLs pointing to expired, unowned, or unclaimed domains enable token theft by allowing attackers to register the abandoned domain and intercept OAuth authorization codes and tokens redirected by Entra ID. This vulnerability, known as a subdomain takeover or dangling DNS attack, gives attackers the ability to obtain valid access tokens for the application's permissions without any credential compromise. All reply URLs must be validated to ensure they resolve to organization-controlled infrastructure.
Current Value
Disabled
Recommended Value
All reply URLs resolve to active, organization-owned domains with no dangling or expired domain references
Remediation Steps
Extract all reply URLs from application registrations and resolve each domain to verify ownership and active DNS registration. Identify any reply URLs pointing to domains that are expired, available for registration, or not controlled by the organization. Remove or update dangling reply URLs immediately and implement a periodic review process to detect new dangling references as domains expire or infrastructure changes occur.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6
MITRE ATT&CK: T1566.002
Unknown EIDAUTH-004 Users with Only SMS/Voice MFA Methods Entra ID Authentication Methods & MFA High FAIL Not enforced
Description
Users relying solely on SMS or voice-based MFA are vulnerable to SIM swap attacks, where attackers social-engineer mobile carriers to transfer a victim's phone number, and SS7 signaling protocol attacks that intercept SMS messages in transit. These methods provide significantly weaker protection than app-based or hardware token authentication. Organizations should identify and migrate these users to phishing-resistant methods.
Current Value
Not enforced
Recommended Value
No users relying exclusively on SMS or voice as their only MFA method
Remediation Steps
Identify users with only SMS/voice MFA via Entra ID > Protection > Authentication methods > User registration details. Create a migration plan to move these users to Microsoft Authenticator or FIDO2 security keys. Consider disabling SMS/voice as allowed methods in the authentication methods policy after migration is complete.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-2(1)
MITRE ATT&CK: T1111 T1078
CisM365: 5.2.2.4
Unknown EIDAUTH-011 Self-Service Password Reset (SSPR) Configuration Entra ID Authentication Methods & MFA High FAIL Disabled
Description
SSPR allows users to reset their own passwords without helpdesk intervention, but must be properly configured to prevent account takeover. Misconfigured SSPR with weak verification methods or insufficient required methods enables attackers to reset passwords using compromised personal information. SSPR should require multiple strong verification methods and be enabled for all users.
Current Value
Disabled
Recommended Value
SSPR enabled for all users with a minimum of two authentication methods required for reset
Remediation Steps
Navigate to Entra ID > Protection > Password reset > Properties and enable SSPR for all users. Set the number of methods required to reset to 2. Under Authentication methods, ensure only strong methods such as mobile app notification, mobile app code, and email are allowed while disabling security questions.
Compliance Mappings
NIST SP 800-53: IA-5(1)
CisM365: 5.2.4
Unknown EIDAUTH-013 Password Protection (Banned Passwords) Configuration Entra ID Authentication Methods & MFA High FAIL Disabled
Description
Entra ID Password Protection prevents users from choosing commonly compromised passwords by checking against a global banned password list maintained by Microsoft. Without password protection enabled, users can select passwords that appear in known breach databases, making accounts vulnerable to password spraying and dictionary attacks. The feature should be enabled in enforced mode for both cloud and on-premises environments.
Current Value
Disabled
Recommended Value
Password protection enabled in Enforced mode with the global banned password list active
Remediation Steps
Navigate to Entra ID > Protection > Authentication methods > Password protection. Set the mode to Enforced and ensure the global banned password list is enabled. If using hybrid identity with on-premises Active Directory, deploy the Entra ID Password Protection proxy and DC agents to extend protection to on-premises password changes.
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1110.001 T1110.003
CisM365: 5.2.5
Unknown EIDAUTH-015 Legacy Authentication Protocol Usage Entra ID Authentication Methods & MFA High FAIL Disabled
Description
Legacy authentication protocols including POP3, IMAP4, SMTP AUTH, and Exchange ActiveSync Basic do not support modern authentication or MFA, allowing attackers to bypass MFA entirely using stolen credentials. These protocols transmit credentials in ways that are susceptible to interception and are the primary vector for password spray attacks against Microsoft 365 tenants. All legacy authentication should be blocked via Conditional Access policies.
Current Value
Disabled
Recommended Value
All legacy authentication protocols blocked via Conditional Access with no active usage detected in sign-in logs
Remediation Steps
Review legacy authentication usage in Entra ID > Monitoring > Sign-in logs > Filter by client app (legacy protocols). Create a Conditional Access policy to block legacy authentication for all users and all cloud apps. Monitor for blocked sign-in attempts and work with affected users to migrate to modern authentication clients.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-2 AC-17(2)
MITRE ATT&CK: T1078 T1110.001
CisM365: 5.2.2.3
Unknown EIDAUTH-016 ROPC (Resource Owner Password Credentials) Flow Enabled Entra ID Authentication Methods & MFA High FAIL Disabled
Description
The Resource Owner Password Credentials (ROPC) authentication flow sends username and password directly to the token endpoint, completely bypassing multi-factor authentication and Conditional Access policies. Applications using ROPC grant type expose credentials in a way that cannot be protected by modern security controls and represent a significant security gap. ROPC should be disabled for all applications unless there is an absolute technical requirement with compensating controls.
Current Value
Disabled
Recommended Value
ROPC flow disabled for all application registrations, no applications using password grant type
Remediation Steps
Review application registrations in Entra ID > Applications > App registrations for any apps configured to allow public client flows. Disable the 'Allow public client flows' setting for applications that do not require ROPC. Migrate applications using ROPC to supported interactive flows such as authorization code with PKCE or device code flow.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-2 IA-5
MITRE ATT&CK: T1078
Unknown EIDCA-002 CA Policy Coverage Gap Analysis Entra ID Conditional Access High FAIL Vulnerable configuration
Description
All users and applications should be covered by at least one Conditional Access policy. Gaps in coverage leave users or applications without security controls such as MFA, device compliance, or location restrictions, creating attack vectors for unauthorized access.
Current Value
Vulnerable configuration
Recommended Value
100% of active users and critical applications covered by at least one CA policy
Remediation Steps
Review all Conditional Access policies to identify users and applications that are not targeted by any policy. Create policies that cover uncovered users and applications with appropriate grant and session controls. Prioritize coverage for privileged accounts and business-critical applications.
Compliance Mappings
NIST SP 800-53: AC-2 AC-3
MITRE ATT&CK: T1078.004
CisM365: 5.2.2
Unknown EIDCA-004 CA Exclusion Group Analysis Entra ID Conditional Access High FAIL Vulnerable configuration
Description
Users and groups excluded from Conditional Access policies bypass critical security controls. Exclusions should be minimized, documented with business justification, and regularly reviewed to prevent privilege creep and unauthorized access.
Current Value
Vulnerable configuration
Recommended Value
All exclusions documented with business justification and reviewed quarterly
Remediation Steps
Audit all Conditional Access policies to identify excluded users and groups. Document the business justification for each exclusion and establish an owner responsible for periodic review. Remove any exclusions that no longer have a valid business need and implement compensating controls where exclusions are required.
Compliance Mappings
NIST SP 800-53: AC-6(1)
MITRE ATT&CK: T1078.004
Unknown EIDCA-005 Unprotected Groups in CA Exclusions Entra ID Conditional Access High FAIL Vulnerable configuration
Description
Groups used in Conditional Access exclusions that lack ownership, membership reviews, or access restrictions can be exploited by attackers to bypass security policies. An attacker who adds themselves to an unprotected exclusion group effectively bypasses all CA controls targeting that group.
Current Value
Vulnerable configuration
Recommended Value
All CA exclusion groups have assigned owners, restricted membership management, and regular access reviews enabled
Remediation Steps
Identify all groups referenced in CA policy exclusions and verify each group has an assigned owner, restricted join/leave settings, and an active access review schedule. Enable Privileged Access Group features or restrict group membership changes to authorized administrators only. Remove any unmanaged or orphaned groups from CA exclusions immediately.
Compliance Mappings
NIST SP 800-53: AC-6(1) AC-6(5)
MITRE ATT&CK: T1078.004
Unknown EIDCA-009 Device Compliance Requirement in CA Entra ID Conditional Access High FAIL Non-compliant
Description
Conditional Access policies should require device compliance to ensure only managed and healthy devices can access organizational resources. Without device compliance requirements, unmanaged or compromised devices can access sensitive data, increasing the risk of data exfiltration and malware propagation.
Current Value
Non-compliant
Recommended Value
Device compliance or Hybrid Azure AD join required for access to all cloud applications
Remediation Steps
Create or update Conditional Access policies to require device compliance or Hybrid Azure AD join as a grant control for all cloud applications. Ensure Intune device compliance policies are configured with appropriate security baselines before enforcing this requirement. Use report-only mode initially to assess impact, then transition to enforcement after confirming managed device coverage is sufficient.
Compliance Mappings
NIST SP 800-53: AC-17(2) CM-6
CisM365: 5.2.2.2
Unknown EIDCA-012 Sign-In Risk-Based CA Policies Entra ID Conditional Access High FAIL Not required
Description
Sign-in risk-based Conditional Access policies use Azure AD Identity Protection signals to detect anomalous sign-in behavior such as impossible travel, anonymous IP usage, and credential leak detection. Without risk-based policies, compromised credentials can be used from suspicious locations or patterns without triggering additional verification.
Current Value
Not required
Recommended Value
CA policies configured to require MFA or block access for medium and high sign-in risk levels
Remediation Steps
Create Conditional Access policies that target all users with the sign-in risk condition set to medium and high, requiring multifactor authentication as the grant control. Ensure Azure AD Identity Protection is enabled and properly licensed (requires Entra ID P2). Monitor the risky sign-ins report regularly and tune risk detection sensitivity based on organizational patterns.
Compliance Mappings
NIST SP 800-53: IA-2(13)
MITRE ATT&CK: T1078.004 T1110
CisM365: 5.2.2.7
Unknown EIDCA-013 User Risk-Based CA Policies Entra ID Conditional Access High FAIL Vulnerable configuration
Description
User risk-based Conditional Access policies respond to cumulative risk signals indicating a user account may be compromised, such as leaked credentials or anomalous activity patterns. Without user risk policies, accounts flagged as compromised by Identity Protection continue to operate normally without requiring password changes or additional verification.
Current Value
Vulnerable configuration
Recommended Value
CA policies configured to require password change for high user risk and MFA for medium user risk
Remediation Steps
Create Conditional Access policies targeting all users with user risk conditions set to medium and high, requiring a secure password change as the grant control for high risk and MFA for medium risk. Ensure self-service password reset (SSPR) is enabled and registered for all users to allow automated remediation. Review the risky users report regularly and investigate accounts that remain at elevated risk levels.
Compliance Mappings
NIST SP 800-53: IA-2(13)
MITRE ATT&CK: T1078.004
CisM365: 5.2.2.8
Unknown EIDFED-002 Federation Signing Certificate Validity Period Entra ID Federation & Hybrid Identity High FAIL Not required
Description
Federation signing certificates with excessively long validity periods provide an extended window for attackers who obtain the private key to forge SAML tokens and maintain persistent unauthorized access. Certificates with validity periods exceeding 3 years deviate from security best practices and may indicate a compromised or attacker-created certificate. Short-lived certificates limit the duration of potential abuse if the private key is compromised.
Current Value
Not required
Recommended Value
Federation signing certificates with validity periods no longer than 1 year with automated rotation procedures in place
Remediation Steps
Review the signing certificates for all federated domains and check their NotBefore and NotAfter dates to determine the validity period. Replace any certificates with validity periods exceeding 3 years with new certificates using shorter lifetimes aligned with organizational certificate policy. Implement automated certificate rotation procedures and configure monitoring alerts for certificates approaching expiration.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(2)
MITRE ATT&CK: T1556.006
Unknown EIDFED-004 Federation Trust Metadata Analysis Entra ID Federation & Hybrid Identity High FAIL SID filtering disabled
Description
Federation trust metadata defines the identity provider endpoints, supported protocols, and token signing configuration used for federated authentication. Manipulated metadata can redirect authentication flows to attacker-controlled endpoints or introduce rogue signing certificates, enabling token forgery and impersonation attacks. The metadata endpoint URL, passive and active endpoints, and signing algorithm configurations should be validated against known-good values.
Current Value
SID filtering disabled
Recommended Value
All federation trust metadata validated against known-good baseline with metadata refresh URLs pointing to organization-controlled endpoints
Remediation Steps
Review the federation configuration for each federated domain including the metadata exchange URI, passive sign-on endpoint, issuer URI, and signing certificate details. Compare current values against a documented baseline configuration to identify any unauthorized modifications. Ensure metadata refresh endpoints use HTTPS and point to organization-controlled infrastructure, and validate that signing algorithms use SHA-256 or stronger.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-8(4)
MITRE ATT&CK: T1556.006
Unknown EIDFED-005 Azure AD Connect Configuration Review Entra ID Federation & Hybrid Identity High FAIL Disabled
Description
Azure AD Connect synchronizes on-premises Active Directory objects to Entra ID and is a critical component of hybrid identity architecture. Misconfigured Azure AD Connect settings can expose sensitive attributes to the cloud, create unintended privilege escalation paths, or allow attackers with on-premises access to manipulate cloud identities. The connector account permissions, synchronization rules, and feature configuration should be reviewed against security best practices.
Current Value
Disabled
Recommended Value
Azure AD Connect configured with least-privilege connector accounts, hardened synchronization rules, and all security features enabled
Remediation Steps
Review the Azure AD Connect configuration including the connector account permissions, synchronization rules, and enabled features. Ensure the AD DS connector account uses the minimum required permissions and that the Entra ID connector account is a dedicated cloud-only service account. Verify that the Azure AD Connect server is treated as a Tier 0 asset with restricted administrative access and comprehensive monitoring.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6
MITRE ATT&CK: T1078.004
Unknown EIDFED-009 AD FS Server Configuration Assessment Entra ID Federation & Hybrid Identity High FAIL Disabled
Description
Active Directory Federation Services (AD FS) servers handle authentication for federated domains and process security-sensitive SAML tokens. Misconfigured AD FS settings such as weak token signing algorithms, disabled audit logging, overly permissive extranet access, or outdated claim rules can be exploited for token forgery, credential harvesting, or unauthorized access. The AD FS configuration should be regularly assessed against Microsoft security baselines and hardening guides.
Current Value
Disabled
Recommended Value
AD FS servers configured per Microsoft security baseline with SHA-256 signing, comprehensive audit logging, and current Windows Server patches
Remediation Steps
Review the AD FS server configuration including token signing algorithm (should be SHA-256), audit log settings (should capture success and failure events), extranet access policies, and claim rule complexity. Ensure AD FS servers are running the latest Windows Server patches and that the AD FS farm is configured with redundant servers. Validate that the AD FS service account follows least-privilege principles and that the token signing certificate private key is properly protected.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6 IA-8(4)
Unknown EIDFED-013 Entra Connect Sync-Client Version Currency Entra ID Federation & Hybrid Identity High FAIL Disabled
Description
Microsoft Entra Connect (formerly Azure AD Connect) is the sync client that replicates on-premises Active Directory identities into Entra ID and is a Tier-0 hybrid component: a compromise of the Connect server can lead to forged or manipulated cloud identities and tenant-wide impact. Microsoft periodically ships Entra Connect builds that contain undisclosed security fixes accompanied by expedited 'update immediately' guidance. A Connect server running a build below the minimum-safe baseline is an unpatched Tier-0 asset exposed to known but undisclosed vulnerabilities. Because the version is an attribute of the on-premises Connect server rather than a cloud directory property, version currency must be confirmed authoritatively on the Connect host; when it cannot be read it must be surfaced for manual verification rather than assumed compliant.
Current Value
Disabled
Recommended Value
Entra Connect updated to the latest available build (at or above the minimum-safe baseline), with auto-upgrade enabled where supported and the Connect server managed as a Tier-0 asset
Remediation Steps
Identify the installed Entra Connect build on the synchronization server using the registry key HKLM\SOFTWARE\Microsoft\Azure AD Connect or Get-ADSyncGlobalSettings, and compare it against the latest build published by Microsoft. Update Entra Connect to the latest release to apply security fixes, and enable automatic upgrade where the deployment supports it. Treat the Entra Connect server as a Tier-0 asset: restrict administrative access, apply current operating system patches, and enable comprehensive monitoring. Document a recurring process to track Microsoft Entra Connect release notes and apply security builds promptly.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-2 SI-2(2)
MITRE ATT&CK: T1195.002 T1078.004
Anssi: R36
Unknown EIDPIM-003 Permanent Privileged Role Assignments Entra ID Privileged Identity Management High FAIL Excessive permissions found
Description
Permanent (active) privileged role assignments provide standing administrative access without time limits or activation requirements. These permanent assignments should be converted to eligible (just-in-time) assignments via PIM, which require explicit activation with justification, approval, and time-bound access windows. Standing privileged access increases the risk and impact of credential compromise because the attacker gains immediate elevated access without any additional gates
Current Value
Excessive permissions found
Recommended Value
No permanent privileged role assignments except for break-glass accounts. All other privileged assignments should be PIM eligible
Remediation Steps
Navigate to Entra ID > Roles and administrators and identify all permanent role assignments. Convert each permanent assignment to an eligible assignment through PIM by removing the active assignment and creating a corresponding eligible assignment. Only break-glass accounts should retain permanent Global Administrator assignments
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-2(3) AC-6(1)
MITRE ATT&CK: T1078.004
CisM365: 1.1.3
Unknown EIDPIM-005 Privileged Role Assignments to Synced Accounts Entra ID Privileged Identity Management High FAIL Excessive permissions found
Description
Accounts synchronized from on-premises Active Directory via Entra Connect that hold privileged cloud roles create a dangerous hybrid attack path. If the on-premises environment is compromised, an attacker can manipulate synced account credentials or attributes to gain administrative access to the cloud tenant. Cloud-privileged roles should only be assigned to cloud-only accounts to maintain a security boundary between on-premises and cloud environments
Current Value
Excessive permissions found
Recommended Value
No synced (hybrid) accounts assigned to privileged Entra ID roles. All privileged accounts should be cloud-only
Remediation Steps
Identify all privileged role members whose onPremisesSyncEnabled property is true. Create dedicated cloud-only administrative accounts for each administrator and assign the required privileged roles to these new accounts. Remove privileged role assignments from all synced accounts to eliminate the on-premises to cloud escalation path
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6(5)
MITRE ATT&CK: T1078.004
Unknown EIDPIM-007 Privileged Users with Weak Authentication Methods Entra ID Privileged Identity Management High FAIL Excessive permissions found
Description
Privileged accounts relying on weak authentication methods such as SMS, voice call, or email OTP are vulnerable to SIM-swapping, call interception, and email compromise attacks. These legacy MFA methods do not provide the same level of assurance as phishing-resistant methods like FIDO2 security keys, Windows Hello for Business, or certificate-based authentication. Privileged accounts should be required to use phishing-resistant authentication methods exclusively
Current Value
Excessive permissions found
Recommended Value
All privileged users using phishing-resistant MFA methods (FIDO2, Windows Hello for Business, or certificate-based authentication). No SMS, voice, or email OTP
Remediation Steps
Review authentication methods registered for each privileged user via Entra ID > Authentication methods > Activity. Create a Conditional Access policy targeting privileged roles that requires authentication strength of phishing-resistant MFA. Provision FIDO2 security keys or configure Windows Hello for Business for all privileged users and remove weak methods
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-2(1)
MITRE ATT&CK: T1111 T1078
Unknown EIDPIM-008 Disabled Accounts in Privileged Roles Entra ID Privileged Identity Management High FAIL Excessive permissions found
Description
Disabled user accounts that retain privileged role assignments create a latent security risk. If the account is re-enabled through administrative action or compromise, it immediately regains full privileged access. Disabled accounts should be promptly removed from all privileged roles as part of the offboarding or account deprovisioning process to eliminate this reactivation risk
Current Value
Excessive permissions found
Recommended Value
No disabled accounts with active or eligible privileged role assignments
Remediation Steps
Enumerate all privileged role members and filter for accounts where accountEnabled is false. Remove all privileged role assignments from disabled accounts immediately. Implement an automated process or access review that detects and removes role assignments when accounts are disabled
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-2(3)
MITRE ATT&CK: T1078.004
Unknown EIDPIM-010 PIM Configuration Audit Entra ID Privileged Identity Management High FAIL Disabled
Description
Privileged Identity Management role settings control the activation workflow including whether approval is required, whether justification must be provided, maximum activation duration, and notification recipients. Misconfigured PIM settings can allow privileged roles to be activated without oversight, effectively negating the security benefits of just-in-time access. Each privileged role should require approval from a designated approver, mandate activation justification, and send notifications to security personnel
Current Value
Disabled
Recommended Value
All privileged roles configured with: approval required, justification required, maximum activation duration of 8 hours or less, and notifications enabled for role activation
Remediation Steps
Navigate to Entra ID > Roles and administrators > Settings and review each privileged role configuration. Enable approval requirement with designated approvers, require activation justification, set maximum activation duration to 8 hours or less, and configure notification recipients for activation events. Pay special attention to Global Administrator, Privileged Role Administrator, and Exchange Administrator roles
Compliance Mappings
NIST SP 800-53: AC-2(4) AC-6(1)
MITRE ATT&CK: T1078.004
CisM365: 1.1.3
Unknown EIDPIM-013 Separate Admin Account Enforcement Entra ID Privileged Identity Management High FAIL Excessive permissions found
Description
Administrative actions should be performed from dedicated administrative accounts rather than the same accounts used for daily activities such as email, web browsing, and collaboration. Using a single account for both administrative and daily tasks exposes privileged credentials to phishing, drive-by downloads, and other threats encountered during routine work. Separate admin accounts significantly reduce the likelihood of privileged credential compromise through normal user activity
Current Value
Excessive permissions found
Recommended Value
All administrators use dedicated admin accounts separate from their daily-use accounts. Admin accounts should not have mailboxes or productivity licenses assigned
Remediation Steps
Review all privileged role members and identify accounts that also have productivity licenses (Exchange Online, SharePoint, Teams) assigned, indicating dual-use. Create dedicated admin accounts following a naming convention such as adm-username for each administrator. Assign privileged roles to the dedicated admin accounts only and remove privileged roles from daily-use accounts
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-5 AC-6(2)
MITRE ATT&CK: T1078.004
CisM365: 1.1.1
Unknown EIDSCA-AM03 EIDSCA AM03: Authentication Method - Microsoft Authenticator - Require number matching for push notifications EIDSCA Baseline High FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AM03): evaluates 'featureSettings.numberMatchingRequiredState.state' on the MicrosoftAuthenticator authentication method against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq enabled
Remediation Steps
Configure the MicrosoftAuthenticator authentication method so 'featureSettings.numberMatchingRequiredState.state' is set to enabled. (Entra ID security-configuration baseline, control EIDSCA AM03.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AM04 EIDSCA AM04: Authentication Method - Microsoft Authenticator - Included users/groups of number matching for push notifications EIDSCA Baseline High FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AM04): evaluates 'featureSettings.numberMatchingRequiredState.includeTarget.id' on the MicrosoftAuthenticator authentication method against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq all_users
Remediation Steps
Configure the MicrosoftAuthenticator authentication method so 'featureSettings.numberMatchingRequiredState.includeTarget.id' is set to all_users. (Entra ID security-configuration baseline, control EIDSCA AM04.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AP01 EIDSCA AP01: Default Authorization Settings - Enabled Self service password reset for administrators EIDSCA Baseline High FAIL Disabled
Description
Entra ID security-configuration control (EIDSCA AP01): evaluates 'allowedToUseSSPR' on the Entra ID authorization policy against the recommended secure value.
Current Value
Disabled
Recommended Value
eq false
Remediation Steps
Configure the Entra ID authorization policy so 'allowedToUseSSPR' is set to false. (Entra ID security-configuration baseline, control EIDSCA AP01.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AP04 EIDSCA AP04: Default Authorization Settings - Guest invite restrictions EIDSCA Baseline High FAIL Unrestricted
Description
Entra ID security-configuration control (EIDSCA AP04): evaluates 'allowInvitesFrom' on the Entra ID authorization policy against the recommended secure value.
Current Value
Unrestricted
Recommended Value
in adminsAndGuestInviters, none
Remediation Steps
Configure the Entra ID authorization policy so 'allowInvitesFrom' is set to one of adminsAndGuestInviters, none. (Entra ID security-configuration baseline, control EIDSCA AP04.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AP07 EIDSCA AP07: Default Authorization Settings - Guest user access EIDSCA Baseline High FAIL Unrestricted
Description
Entra ID security-configuration control (EIDSCA AP07): evaluates 'guestUserRoleId' on the Entra ID authorization policy against the recommended secure value.
Current Value
Unrestricted
Recommended Value
eq 2af84b1e-32c8-42b7-82bc-daa82404023b
Remediation Steps
Configure the Entra ID authorization policy so 'guestUserRoleId' is set to 2af84b1e-32c8-42b7-82bc-daa82404023b. (Entra ID security-configuration baseline, control EIDSCA AP07.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AP08 EIDSCA AP08: Default Authorization Settings - User consent policy assigned for applications EIDSCA Baseline High FAIL Not required
Description
Entra ID security-configuration control (EIDSCA AP08): evaluates 'permissionGrantPolicyIdsAssignedToDefaultUserRole' on the Entra ID authorization policy against the recommended secure value.
Current Value
Not required
Recommended Value
clike-any ManagePermissionGrantsForSelf
Remediation Steps
Configure the Entra ID authorization policy so 'permissionGrantPolicyIdsAssignedToDefaultUserRole' is include ManagePermissionGrantsForSelf. (Entra ID security-configuration baseline, control EIDSCA AP08.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AP09 EIDSCA AP09: Default Authorization Settings - Allow user consent on risk-based apps EIDSCA Baseline High FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AP09): evaluates 'allowUserConsentForRiskyApps' on the Entra ID authorization policy against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq false
Remediation Steps
Configure the Entra ID authorization policy so 'allowUserConsentForRiskyApps' is set to false. (Entra ID security-configuration baseline, control EIDSCA AP09.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AS04 EIDSCA AS04: Authentication Method - SMS - Use for sign-in EIDSCA Baseline High FAIL Not required
Description
Entra ID security-configuration control (EIDSCA AS04): evaluates 'includeTargets.isUsableForSignIn' on the Sms authentication method against the recommended secure value.
Current Value
Not required
Recommended Value
eq false
Remediation Steps
Configure the Sms authentication method so 'includeTargets.isUsableForSignIn' is set to false. (Entra ID security-configuration baseline, control EIDSCA AS04.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-CP01 EIDSCA CP01: Default Settings - Consent Policy Settings - Group owner consent for apps accessing data EIDSCA Baseline High FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA CP01): evaluates the 'EnableGroupSpecificConsent' setting on the Entra ID directory (group) settings against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq False
Remediation Steps
Configure the Entra ID directory (group) settings so the 'EnableGroupSpecificConsent' setting is set to False. (Entra ID security-configuration baseline, control EIDSCA CP01.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-CP03 EIDSCA CP03: Default Settings - Consent Policy Settings - Block user consent for risky apps EIDSCA Baseline High FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA CP03): evaluates the 'BlockUserConsentForRiskyApps' setting on the Entra ID directory (group) settings against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq true
Remediation Steps
Configure the Entra ID directory (group) settings so the 'BlockUserConsentForRiskyApps' setting is set to true. (Entra ID security-configuration baseline, control EIDSCA CP03.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-PR03 EIDSCA PR03: Default Settings - Password Rule Settings - Enforce custom list EIDSCA Baseline High FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA PR03): evaluates the 'EnableBannedPasswordCheck' setting on the Entra ID directory (group) settings against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq True
Remediation Steps
Configure the Entra ID directory (group) settings so the 'EnableBannedPasswordCheck' setting is set to True. (Entra ID security-configuration baseline, control EIDSCA PR03.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-PR06 EIDSCA PR06: Default Settings - Password Rule Settings - Smart Lockout - Lockout threshold EIDSCA Baseline High FAIL No lockout configured
Description
Entra ID security-configuration control (EIDSCA PR06): evaluates the 'LockoutThreshold' setting on the Entra ID directory (group) settings against the recommended secure value.
Current Value
No lockout configured
Recommended Value
le 10
Remediation Steps
Configure the Entra ID directory (group) settings so the 'LockoutThreshold' setting is at most 10. (Entra ID security-configuration baseline, control EIDSCA PR06.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-ST09 EIDSCA ST09: Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to have access to groups content EIDSCA Baseline High FAIL Unrestricted
Description
Entra ID security-configuration control (EIDSCA ST09): evaluates the 'AllowGuestsToAccessGroups' setting on the Entra ID directory (group) settings against the recommended secure value.
Current Value
Unrestricted
Recommended Value
eq True
Remediation Steps
Configure the Entra ID directory (group) settings so the 'AllowGuestsToAccessGroups' setting is set to True. (Entra ID security-configuration baseline, control EIDSCA ST09.)
Remediation URL
Compliance Mappings
Unknown EIDTNT-002 User Settings Review Entra ID Tenant Configuration High FAIL Disabled
Description
Tenant-wide user settings control whether standard users can register applications, consent to applications accessing company data, create security groups, and read other users' directory information. Overly permissive user settings enable shadow IT, unauthorized application integrations, and group sprawl that expand the attack surface. These settings should be restricted to prevent standard users from performing actions that should require administrative oversight.
Current Value
Disabled
Recommended Value
Users cannot register applications, user consent restricted to verified publishers, group creation limited to authorized users
Remediation Steps
Navigate to Entra ID > User settings and review each setting. Disable 'Users can register applications' to prevent uncontrolled app registration sprawl. Restrict user consent settings to allow consent only for apps from verified publishers with low-risk permissions. Limit who can create Microsoft 365 groups and security groups to designated administrators or group owners.
Compliance Mappings
NIST SP 800-53: AC-6
CisM365: 1.3
Unknown EIDTNT-003 Guest User Access Restrictions Entra ID Tenant Configuration High FAIL Unrestricted
Description
Guest users are external identities invited to collaborate with the organization. By default, guest users may have overly broad visibility into the directory, including the ability to enumerate users, groups, and applications. Unrestricted guest access allows external parties to map the organization's identity structure, identify high-value targets, and gather intelligence for subsequent attacks. Guest permissions should be restricted to the minimum required for collaboration.
Current Value
Unrestricted
Recommended Value
Guest user access restricted to properties and memberships of their own directory objects only
Remediation Steps
Navigate to Entra ID > External Identities > External collaboration settings and review the guest user access restrictions. Set guest user access to the most restrictive option that limits guests to properties and memberships of their own directory objects. Verify that guests cannot enumerate the full user list, group memberships, or application registrations by testing with a guest account.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-14
MITRE ATT&CK: T1078.004
CisM365: 1.3.1
Unknown EIDTNT-005 External Collaboration Settings Entra ID Tenant Configuration High FAIL Anyone (no restrictions)
Description
External collaboration settings define the scope of domains from which guest users can be invited and which external organizations can collaborate with the tenant. Without domain restrictions, guests can be invited from any external organization, including competitors, sanctioned entities, or attacker-controlled tenants. Domain allowlists or blocklists should be configured to limit collaboration to approved partner organizations and prevent unauthorized external access.
Current Value
Anyone (no restrictions)
Recommended Value
External collaboration restricted to specific allowed domains with a deny list for known high-risk domains
Remediation Steps
Navigate to Entra ID > External Identities > External collaboration settings and configure collaboration restrictions. Implement either an allowlist of approved partner domains or a blocklist of known high-risk and competitor domains based on your organization's collaboration model. Review and update the domain list quarterly to reflect changes in partner relationships and ensure that collaboration restrictions align with data classification and information sharing policies.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-20
CisM365: 1.3.1
Unknown EIDTNT-006 Azure B2B Cross-Tenant Access Policies Entra ID Tenant Configuration High FAIL Disabled
Description
Cross-tenant access policies provide granular control over how users authenticate and access resources when collaborating with external Entra ID tenants. Default cross-tenant access settings may allow broad inbound and outbound access that does not align with organizational security requirements. Properly configured cross-tenant access policies enable trusted B2B collaboration while preventing unauthorized access from untrusted tenants and controlling which users can access external resources.
Current Value
Disabled
Recommended Value
Default cross-tenant access policy set to block with explicit allow rules for approved partner tenants only
Remediation Steps
Navigate to Entra ID > External Identities > Cross-tenant access settings and review the default inbound and outbound access settings. Configure the default policy to restrict both inbound and outbound access, then create organization-specific policies for approved partner tenants with appropriate access controls. Enable trust settings for partner tenants to accept their MFA claims and device compliance where appropriate, reducing authentication friction for trusted collaborations.
Compliance Mappings
NIST SP 800-53: AC-20
CisM365: 1.3.1
Unknown EIDTNT-011 Diagnostic Settings for Audit and Sign-In Logs Entra ID Tenant Configuration High FAIL Disabled
Description
Entra ID generates audit logs and sign-in logs that are critical for security monitoring, incident investigation, and compliance reporting. Without diagnostic settings configured to export these logs to a durable storage location such as a Log Analytics workspace, Azure Storage account, or SIEM, logs are retained for only a limited period within Entra ID and may be unavailable during incident investigation. Attackers actively target logging configuration to disable or evade detection.
Current Value
Disabled
Recommended Value
All Entra ID log categories (audit, sign-in, non-interactive sign-in, service principal sign-in, managed identity sign-in, provisioning) exported to a Log Analytics workspace or SIEM
Remediation Steps
Navigate to Entra ID > Monitoring > Diagnostic settings and create or verify a diagnostic setting that exports all log categories to a Log Analytics workspace, Azure Storage account, or Event Hub for SIEM ingestion. Ensure all available log categories are selected including audit logs, sign-in logs, non-interactive sign-in logs, service principal sign-in logs, managed identity sign-in logs, and provisioning logs. Verify that the destination storage has appropriate retention policies and access controls configured.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-2 AU-3 AU-6
MITRE ATT&CK: T1562.008
CisM365: 3.1
Unknown EIDTNT-012 Audit Log Retention Settings Entra ID Tenant Configuration High FAIL Disabled
Description
Audit log retention determines how long historical security events are available for investigation, compliance reporting, and forensic analysis. Insufficient retention periods may result in critical evidence being unavailable when investigating incidents that are discovered weeks or months after the initial compromise. Organizations should retain audit logs for at least 1 year to support incident response timelines and meet common regulatory requirements.
Current Value
Disabled
Recommended Value
Audit logs retained for a minimum of 1 year in an immutable storage location with at least 90 days immediately queryable
Remediation Steps
Review the retention settings on the Log Analytics workspace, Azure Storage account, or SIEM destination where Entra ID logs are exported. Configure retention for at least 365 days for all Entra ID log categories to support incident investigation and compliance requirements. Ensure that at least 90 days of logs are immediately queryable without restore operations, and implement immutable storage or write-once policies to prevent tampering with historical log data.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-11
CisM365: 3.1
Unknown EIDTNT-015 Privileged Partner Delegated Admin Access (GDAP) Entra ID Tenant Configuration High FAIL Excessive permissions found
Description
Granular Delegated Admin Privileges (GDAP) let a CSP or managed-services partner hold standing administrative roles in your tenant. This relationship is invisible in most day-to-day admin views, is rarely reviewed, and is a Kaseya-class propagation path: an attacker who compromises one partner inherits delegated administration in every downstream customer tenant at once. A partner relationship that carries a Tier-0 / high-impact directory role (Global Administrator, Privileged Role Administrator, Privileged/Authentication Administrator, Security Administrator, User/Password/Application/Cloud Application Administrator) is effectively an external set of keys to the kingdom. This check inventories active delegatedAdminRelationships and FAILS when any active relationship grants one of those privileged roles; it warns when non-privileged partner access exists so it can be confirmed and scoped, and passes only when there is no active partner delegated administration. Empty results are treated as 'no relationships' only when the collection succeeded — a failed call surfaces as Not Assessed, never as a clean pass.
Current Value
Excessive permissions found
Recommended Value
No active GDAP relationship grants a privileged directory role; partner access is least-privilege, time-bound, and reviewed
Remediation Steps
Review every active partner delegated admin (GDAP) relationship in Microsoft Entra admin center > Identity > External Identities > Cross-tenant access (Partner-led) and in the Microsoft 365 admin center > Settings > Partner relationships. For each relationship, remove Tier-0 / high-impact roles (Global Administrator, Privileged Role Administrator, Privileged Authentication Administrator, Security Administrator, User/Password/Application/Cloud Application Administrator) unless there is a documented, time-bound need. Replace standing privileged delegation with least-privilege roles, request just-in-time elevation through the partner's own PIM where possible, and terminate any relationship that is no longer required. Confirm the partner's own tenant enforces phishing-resistant MFA for the admins who exercise this access.
Compliance Mappings
NIST SP 800-53: AC-2 AC-3 AC-6 PS-7 SA-9
CisM365: 1.1.3
Unknown EMAIL-005 TLS Enforcement Email Security High FAIL Disabled
Description
Transport Layer Security (TLS) should be required for email transmission to prevent eavesdropping. Compliance TLS settings ensure encrypted connections with specified partner domains
Current Value
Disabled
Recommended Value
TLS required for all outbound and inbound connections
Remediation Steps
Admin Console > Apps > Google Workspace > Gmail > Compliance > Secure transport (TLS) compliance > Add rule requiring TLS for all domains or specific partner domains
Compliance Mappings
NIST SP 800-53: SC-8 SC-8(1) SC-23
MITRE ATT&CK: T1557 T1040
CIS Benchmark: 2.5
Unknown EMAIL-009 Auto-Forwarding Policy Email Security High FAIL Allowed to external
Description
Automatic email forwarding to external addresses should be disabled to prevent data exfiltration. Attackers frequently set up forwarding rules after compromising an account
Current Value
Allowed to external
Recommended Value
Auto-forwarding disabled for all organizational units
Remediation Steps
Admin Console > Apps > Google Workspace > Gmail > End User Access > Disable automatic forwarding for all OUs. Review existing forwarding rules via Gmail API
Compliance Mappings
NIST SP 800-53: AC-4 SC-7
MITRE ATT&CK: T1114.003 T1020
CIS Benchmark: 2.9
Unknown EMAIL-011 POP/IMAP Access Settings Email Security High FAIL Disabled
Description
POP and IMAP access should be disabled unless specifically required. These legacy protocols bypass modern security controls and can be used for credential-based attacks
Current Value
Disabled
Recommended Value
POP and IMAP disabled for all users
Remediation Steps
Admin Console > Apps > Google Workspace > Gmail > End User Access > Disable POP and IMAP access. Review individual user settings via Gmail API
Compliance Mappings
NIST SP 800-53: AC-17(2) CM-7
MITRE ATT&CK: T1078.004 T1110
CIS Benchmark: 2.11
Unknown EMAIL-012 Spam and Phishing Filter Settings Email Security High FAIL Disabled
Description
Enhanced spam and phishing filters should be enabled to provide maximum protection against social engineering attacks and malicious email campaigns
Current Value
Disabled
Recommended Value
Enhanced spam filtering and aggressive phishing detection enabled
Remediation Steps
Admin Console > Apps > Google Workspace > Gmail > Spam, phishing and malware > Enable 'Be more aggressive when filtering spam' and all phishing protection options
Compliance Mappings
NIST SP 800-53: SI-8 SI-3
MITRE ATT&CK: T1566.001 T1566.002
CIS Benchmark: 2.12
Unknown EMAIL-013 Enhanced Pre-Delivery Message Scanning Email Security High FAIL Disabled
Description
Enhanced pre-delivery message scanning uses advanced heuristics and sandboxing to detect malware and threats before messages are delivered to user inboxes
Current Value
Disabled
Recommended Value
Enhanced pre-delivery message scanning enabled
Remediation Steps
Admin Console > Apps > Google Workspace > Gmail > Spam, phishing and malware > Enable 'Enhanced pre-delivery message scanning' to identify suspicious content
Compliance Mappings
NIST SP 800-53: SI-3 SI-8
MITRE ATT&CK: T1566.001 T1204.001
CIS Benchmark: 2.13
Unknown EMAIL-015 Attachment Safety Settings Email Security High FAIL Disabled
Description
All attachment safety protections should be enabled to detect and block malicious file attachments including encrypted archives, anomalous file types, and scripts
Current Value
Disabled
Recommended Value
All attachment protection options enabled with quarantine action
Remediation Steps
Admin Console > Apps > Google Workspace > Gmail > Safety > Attachments > Enable all protections: encrypted attachments, scripts from untrusted senders, and anomalous attachment types
Compliance Mappings
NIST SP 800-53: SI-3 SI-8
MITRE ATT&CK: T1566.001 T1204.002
CIS Benchmark: 2.15
Unknown EMAIL-016 Links and External Images Protection Email Security High FAIL Anyone (no restrictions)
Description
Link protection should be enabled to scan URLs for phishing and malware. External image proxying prevents tracking pixels and IP disclosure
Current Value
Anyone (no restrictions)
Recommended Value
URL scanning, click-time warnings, and external image proxying enabled
Remediation Steps
Admin Console > Apps > Google Workspace > Gmail > Safety > Links and external images > Enable 'Identify links behind shortened URLs', 'Scan linked images', and 'Show warning prompt for click on links to untrusted domains'
Compliance Mappings
NIST SP 800-53: SI-3 SI-8
MITRE ATT&CK: T1566.002 T1204.001
CIS Benchmark: 2.16
Unknown EMAIL-022 Mail Forwarding Rule Enumeration Email Security High FAIL Allowed to external
Description
All user-level mail forwarding rules should be enumerated and reviewed. Attackers commonly set up forwarding rules to maintain persistent access to email after account compromise
Current Value
Allowed to external
Recommended Value
No unauthorized forwarding rules; all forwarding rules documented and approved
Remediation Steps
Enumerate forwarding rules via Gmail API for all users. Remove unauthorized forwarding addresses. Disable auto-forwarding at the OU level to prevent future abuse
Compliance Mappings
NIST SP 800-53: AC-4 SI-4 AU-6
MITRE ATT&CK: T1114.003 T1020
CIS Benchmark: 2.22
Unknown EMAIL-026 Gmail POP and IMAP access disabled (GWS.GMAIL.9.1) Email Security High FAIL Disabled
Description
SCuBA GWS.GMAIL.9.1: legacy POP and IMAP protocols bypass modern authentication and are a credential-stuffing / MFA-bypass vector. Reads gmail.imap_access and gmail.pop_access; fails where either is enabled.
Current Value
Disabled
Recommended Value
POP and IMAP access disabled
Remediation Steps
In Gmail settings > End User Access, disable POP and IMAP so mail clients must use modern authenticated protocols.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-2 AC-17 AC-14
Unknown GROUP-001 External access to Google Groups restricted (GWS.GROUPS.1.1) Collaboration & Communication Security High FAIL Anyone (no restrictions)
Description
SCuBA GWS.GROUPS.1.1 requires that Groups for Business sharing be limited so groups are not accessible to people outside the organization. When the group sharing collaboration capability is not set to domain-users-only, group content — which in a school can include student and staff data — becomes reachable by external parties. This check reads the groups_for_business.groups_sharing policy from the Cloud Identity Policy API and flags any organizational unit whose collaboration capability is not DOMAIN_USERS_ONLY.
Current Value
Anyone (no restrictions)
Recommended Value
Groups sharing collaboration capability set to DOMAIN_USERS_ONLY for all organizational units
Remediation Steps
In the Google Admin console under Apps > Google Workspace > Groups for Business > Sharing settings, set group access to be limited to users in the organization (not 'Anyone on the internet'), so external parties cannot access group content.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-3 AC-22 SC-7
Unknown INTUNE-002 Device compliance status overview Intune / Endpoint Management High FAIL Non-compliant
Description
The overall device compliance status indicates whether enrolled devices meet their assigned compliance policy requirements. A high percentage of non-compliant or not-evaluated devices signals enforcement gaps that could allow insecure devices to access corporate resources. Continuous monitoring of compliance status is essential for maintaining the security posture of the device fleet.
Current Value
Non-compliant
Recommended Value
95% or higher device compliance rate across all enrolled devices
Remediation Steps
Review the device compliance overview dashboard to identify the distribution of compliant, non-compliant, and not-evaluated devices. Investigate devices in a not-evaluated state to determine if they lack assigned policies or have sync issues preventing evaluation. Set up compliance status notifications and integrate with Conditional Access to block non-compliant devices from accessing corporate resources.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6
Unknown INTUNE-003 Non-compliant device enumeration Intune / Endpoint Management High FAIL Not enrolled
Description
Devices that fail compliance policy evaluation pose a direct risk to the organization by potentially lacking encryption, running outdated operating systems, or having disabled security features. Enumerating non-compliant devices and understanding the specific compliance failures enables targeted remediation. Without this visibility, insecure devices may continue accessing corporate data undetected.
Current Value
Not enrolled
Recommended Value
Zero non-compliant devices with access to corporate resources; all non-compliant devices should be blocked or in remediation
Remediation Steps
Generate a detailed report of non-compliant devices including the specific compliance settings that are failing for each device. Prioritize remediation of devices failing critical compliance checks such as encryption or antivirus requirements, and work with device owners to resolve issues. Configure actions for non-compliance in each compliance policy to mark devices as non-compliant after a grace period and integrate with Conditional Access to restrict resource access.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6
Unknown INTUNE-006 Windows Update for Business ring configuration Intune / Endpoint Management High FAIL Disabled
Description
Windows Update for Business rings control the cadence and deferral periods for quality and feature updates on managed Windows devices. Misconfigured update rings can result in devices running outdated builds with known vulnerabilities for extended periods. Properly staged update rings balance operational stability with timely security patching.
Current Value
Disabled
Recommended Value
Quality updates deferred no more than 7 days; feature updates deferred no more than 60 days; all rings assigned and actively delivering updates
Remediation Steps
Review all Windows Update for Business ring configurations and verify that quality update deferral periods do not exceed 7 days for security-critical rings. Ensure that at least a pilot and broad deployment ring exist with appropriate deferral staging. Monitor update compliance reports to identify devices that have not installed recent updates and investigate any update failures or stalled installations.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-2
Unknown INTUNE-007 BitLocker encryption policy audit Intune / Endpoint Management High FAIL Disabled
Description
BitLocker drive encryption protects data at rest on Windows devices, preventing unauthorized access to the hard drive contents if a device is lost or stolen. Without a properly configured BitLocker policy, devices may store corporate data unencrypted, exposing sensitive information. The policy must enforce encryption on OS and fixed data drives with secure key recovery options.
Current Value
Disabled
Recommended Value
BitLocker enabled on all OS and fixed data drives with XTS-AES 256-bit encryption and Azure AD key escrow
Remediation Steps
Create or update the Intune endpoint protection profile to require BitLocker encryption on operating system and fixed data drives using XTS-AES 256-bit encryption. Configure recovery key escrow to Azure AD to ensure key recovery is possible and set the policy to silently enable encryption without user interaction. Monitor the encryption status report to identify devices that have not completed encryption and remediate any failures.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-28
CisM365: 1.1.17
Unknown INTUNE-009 Attack Surface Reduction rules configuration Intune / Endpoint Management High FAIL Insecure rules found
Description
Attack Surface Reduction (ASR) rules in Microsoft Defender block common attack techniques such as obfuscated scripts, Office macro exploitation, and credential theft from LSASS. Without ASR rules configured and enforced, endpoints remain vulnerable to well-known attack patterns that commodity malware and adversaries routinely exploit. Properly configured ASR rules significantly reduce the attack surface of Windows endpoints.
Current Value
Insecure rules found
Recommended Value
All recommended ASR rules enabled in block mode; audit mode for newly deployed rules during testing
Remediation Steps
Review the current ASR rule configuration in Intune endpoint security and enable all Microsoft-recommended rules in at least audit mode. After a monitoring period to identify false positives, transition rules to block mode starting with high-impact rules such as blocking Office applications from creating child processes and blocking credential theft from LSASS. Configure ASR rule exclusions sparingly and only for documented business-critical applications, monitoring the ASR events report for ongoing effectiveness.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-7
MITRE ATT&CK: T1059
Unknown INTUNE-011 Application protection policies (MAM) Intune / Endpoint Management High FAIL Unreviewed permissions
Description
Application protection policies (Mobile Application Management) control how corporate data is handled within managed applications on both enrolled and unenrolled devices. Without these policies, users can copy corporate data to personal applications, share files through unmanaged channels, or back up corporate data to personal cloud storage. MAM policies are essential for preventing data leakage on mobile devices.
Current Value
Unreviewed permissions
Recommended Value
App protection policies applied to all managed apps on iOS and Android; cut/copy/paste restricted to managed apps; backup to unmanaged services blocked
Remediation Steps
Create application protection policies for both iOS and Android platforms targeting all Microsoft 365 and line-of-business applications that handle corporate data. Configure data protection settings to prevent cut/copy/paste to unmanaged applications, block backup to personal cloud services, and require app-level PIN or biometric authentication. Assign the policies to all users who access corporate data on mobile devices and monitor the app protection status report for non-compliant applications.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-19
Unknown INTUNE-015 Disk encryption status Intune / Endpoint Management High FAIL Disabled
Description
Full disk encryption ensures that data stored on device drives is protected if the physical device is lost, stolen, or decommissioned. Devices without encryption enabled expose corporate data including cached credentials, documents, and email to physical theft attacks. Monitoring encryption status across the fleet identifies devices that have failed encryption or have not yet been encrypted.
Current Value
Disabled
Recommended Value
100% of managed devices reporting encryption enabled on all drives
Remediation Steps
Review the Intune encryption report to identify all devices that are not reporting full disk encryption as enabled. Investigate encryption failures which may be caused by unsupported hardware, TPM issues, or policy conflicts and resolve the underlying causes. For devices that cannot support encryption, evaluate whether they should be allowed to access corporate resources and consider blocking them through Conditional Access policies.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-28
Unknown INTUNE-016 Firewall policy configuration Intune / Endpoint Management High FAIL Non-compliant
Description
The Windows Defender Firewall provides host-based network protection that blocks unauthorized inbound and outbound connections. Without a centrally managed firewall policy through Intune, individual devices may have inconsistent or disabled firewall settings, leaving them vulnerable to network-based attacks. Centralized firewall management ensures consistent protection across all managed endpoints regardless of network location.
Current Value
Non-compliant
Recommended Value
Windows Defender Firewall enabled for all profiles (Domain, Private, Public); block inbound connections by default; log dropped packets
Remediation Steps
Deploy an Intune endpoint security firewall policy that enables Windows Defender Firewall for Domain, Private, and Public network profiles with inbound connections blocked by default. Configure firewall rules for any required application exceptions and enable logging for dropped and successful connections. Monitor the firewall policy deployment status and investigate any devices reporting policy application errors or firewall disabled states.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-7
Unknown INTUNE-017 Security baselines compliance Intune / Endpoint Management High FAIL Non-compliant
Description
Microsoft security baselines in Intune provide pre-configured groups of Windows settings recommended by Microsoft security teams, covering areas such as credential protection, browser security, and attack surface reduction. Devices that deviate from the security baseline have weakened security postures and may be vulnerable to known attack vectors. Monitoring baseline compliance identifies configuration drift and helps maintain a consistent security posture.
Current Value
Non-compliant
Recommended Value
90% or higher compliance with assigned security baselines; all conflict and error states resolved
Remediation Steps
Deploy the latest Microsoft security baseline profile for Windows and Defender for Endpoint to all managed devices and monitor the per-setting compliance status. Investigate settings reporting conflict or error states, as these often indicate competing policies that need to be reconciled. Address non-compliant settings by evaluating whether the deviation is due to a legitimate business requirement that warrants a documented exception or a configuration issue that should be corrected.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6 SI-2
Unknown INTUNE-021 Remote actions audit (wipe, retire, lock) Intune / Endpoint Management High FAIL Disabled
Description
Intune remote actions such as wipe, retire, and remote lock are powerful device management capabilities that, if misused, can result in data loss or denial of service to legitimate users. Unauthorized or accidental remote wipes can destroy business-critical data on devices, while unaudited remote lock actions could indicate account compromise. All remote actions must be logged and reviewed for authorized use.
Current Value
Disabled
Recommended Value
All remote actions logged with operator identity; wipe actions require documented approval; audit logs reviewed weekly
Remediation Steps
Review the Intune audit logs for all remote action events including wipe, retire, remote lock, and passcode reset to identify any unauthorized or unusual activity. Implement an approval workflow for destructive remote actions such as full wipe that requires documented justification and secondary approval. Configure alert notifications for remote wipe actions to ensure security teams are immediately aware when devices are being wiped.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-6 MP-6
Unknown LOG-001 Audit Log Retention Settings Logging, Alerting & Monitoring High FAIL Disabled
Description
Audit logs should be retained for an adequate period to support incident investigation and compliance requirements. Default retention varies by Workspace edition
Current Value
Disabled
Recommended Value
Audit log retention of 12 months or longer; extended via BigQuery export for long-term retention
Remediation Steps
Admin Console > Reporting > Audit and investigation > Review log availability. Configure BigQuery export via Admin Console > Reporting > BigQuery export for long-term retention
Compliance Mappings
NIST SP 800-53: AU-11 AU-4
MITRE ATT&CK: T1070 T1562.008
CIS Benchmark: 7.1
Unknown LOG-002 Alert Center Rules Inventory Logging, Alerting & Monitoring High FAIL Insecure rules found
Description
Alert Center rules should be configured to detect and notify on security-relevant events including suspicious logins, data exfiltration, and policy violations
Current Value
Insecure rules found
Recommended Value
Alert rules configured for key security events (suspicious login, data exfiltration, privilege changes)
Remediation Steps
Admin Console > Security > Alert center > Review existing rules > Create rules for missing security event categories
Compliance Mappings
NIST SP 800-53: SI-4 IR-5
MITRE ATT&CK: T1562.008
CIS Benchmark: 7.2
Unknown M365AUDIT-002 Audit log retention policy Unified Audit & Logging High FAIL Disabled
Description
By default, Microsoft 365 audit log records are retained for 180 days (or 90 days for standard licenses), which may be insufficient for detecting long-running attacks or meeting regulatory compliance requirements. Advanced persistent threats may operate within an environment for months before detection, and without adequate log retention, the forensic evidence needed for investigation may have already been purged. Extending audit log retention ensures that historical activity data is available when needed.
Current Value
Disabled
Recommended Value
Audit log retention set to at least 365 days; priority activity types retained for longer periods; logs exported to external SIEM for long-term storage
Remediation Steps
Configure audit log retention policies in the Microsoft Purview compliance portal to retain all audit log records for at least 365 days, extending retention for high-priority record types such as MailItemsAccessed, FileAccessed, and UserLoggedIn. For organizations with Microsoft 365 E5 or equivalent licensing, configure 10-year retention policies for critical audit record types to support long-term forensic investigations. Implement log export to an external SIEM or log analytics platform such as Microsoft Sentinel for long-term storage and advanced correlation beyond the native retention period.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-11
CisM365: 3.1.2
Unknown M365DEF-001 Preset security policy audit Defender for Office 365 High FAIL Disabled
Description
Preset security policies in Microsoft Defender for Office 365 provide Microsoft-recommended configurations for anti-spam, anti-phishing, anti-malware, Safe Attachments, and Safe Links as a unified policy bundle. Organizations that do not leverage preset policies or equivalent custom configurations may have inconsistent protection levels across different threat protection features. Verifying that the Standard or Strict preset policy is applied ensures a comprehensive and consistently maintained baseline.
Current Value
Disabled
Recommended Value
Standard Protection preset policy applied to all users at minimum; Strict Protection applied to priority accounts and executives
Remediation Steps
Enable the Standard Protection preset security policy and assign it to all users to establish a Microsoft-recommended security baseline for email threat protection. Apply the Strict Protection preset policy to priority accounts, executives, and high-value targets who are most likely to be targeted by sophisticated attacks. If custom policies are preferred over presets, verify that each custom policy meets or exceeds the settings defined in the Standard or Strict preset configuration.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-3 SI-8
CisM365: 2.1.8
Unknown M365EXO-001 Anti-spam policy audit Exchange Online Security High FAIL Disabled
Description
Anti-spam policies in Exchange Online Protection filter inbound and outbound email to block unsolicited messages and spam-based phishing campaigns. Misconfigured or default anti-spam settings may not provide adequate protection, allowing malicious emails to reach user inboxes. Customized spam filter policies with appropriate thresholds and actions are essential for reducing the volume of threats delivered to end users.
Current Value
Disabled
Recommended Value
Custom anti-spam policy with high confidence spam quarantined; bulk email threshold set to 6 or lower; outbound spam alerts enabled
Remediation Steps
Review all anti-spam policies in Exchange Online and ensure that high confidence spam and high confidence phishing are set to quarantine rather than deliver to junk folder. Configure the bulk email threshold to 6 or lower to catch aggressive bulk senders and enable notifications for outbound spam detection. Apply the custom policy to all recipient domains and verify that no user-level overrides are weakening the organizational policy.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-8
CisM365: 2.1.1
Unknown M365EXO-002 Anti-phishing policy audit Exchange Online Security High FAIL Disabled
Description
Anti-phishing policies use mailbox intelligence and impersonation detection to identify emails that spoof trusted senders or domains. Without properly configured anti-phishing policies, attackers can impersonate executives, partners, or trusted domains to conduct business email compromise and credential harvesting attacks. Advanced anti-phishing settings including user and domain impersonation protection are critical for defending against targeted phishing campaigns.
Current Value
Disabled
Recommended Value
User impersonation protection enabled for executives and VIPs; domain impersonation protection enabled for all organizational domains; mailbox intelligence enabled
Remediation Steps
Configure anti-phishing policies with impersonation protection for high-value targets including executives, finance team members, and IT administrators. Enable domain impersonation protection for all organizational domains and key partner domains, setting the action to quarantine impersonated messages. Enable mailbox intelligence and spoof intelligence with appropriate safety tips to warn users about potentially impersonated senders.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-8
MITRE ATT&CK: T1566
CisM365: 2.1.2
Unknown M365EXO-003 Anti-malware policy audit Exchange Online Security High FAIL Disabled
Description
Anti-malware policies in Exchange Online scan email attachments for known malware, viruses, and malicious content before delivery. Default anti-malware settings may not block all dangerous file types, and certain attachment types commonly used in attacks such as executables and scripts may pass through without filtering. A comprehensive anti-malware policy with common attachment type filtering is essential to prevent malware delivery via email.
Current Value
Disabled
Recommended Value
Common attachment types filter enabled blocking executable and script file types; zero-hour auto purge enabled; admin notifications enabled for malware detection
Remediation Steps
Review the anti-malware policy and enable the common attachments filter to block dangerous file types including exe, vbs, js, ps1, bat, cmd, and other executable formats. Enable zero-hour auto purge (ZAP) to retroactively remove malware detected in already-delivered messages. Configure administrator notifications to alert the security team when malware is detected and verify that the policy is applied to all recipients in the organization.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-3
MITRE ATT&CK: T1204
CisM365: 2.1.3
Unknown M365EXO-004 Safe Attachments policy Exchange Online Security High FAIL Non-compliant
Description
Safe Attachments in Microsoft Defender for Office 365 detonates email attachments in a sandbox environment to detect zero-day malware and advanced threats that signature-based scanning cannot identify. Without Safe Attachments enabled, novel malware variants delivered as email attachments may bypass traditional anti-malware filters. This defense layer is critical for organizations targeted by sophisticated adversaries using custom or polymorphic malware.
Current Value
Non-compliant
Recommended Value
Safe Attachments enabled in Dynamic Delivery mode for all users; global settings enabled for SharePoint, OneDrive, and Teams
Remediation Steps
Create or update the Safe Attachments policy to use Dynamic Delivery mode, which delivers the email body immediately while attachments are scanned, minimizing user impact while maintaining protection. Enable Safe Attachments for SharePoint, OneDrive, and Teams in the global settings to extend file detonation protection beyond email. Assign the policy to all users and monitor the Threat Explorer for detections to validate policy effectiveness.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-3
CisM365: 2.1.4
Unknown M365EXO-005 Safe Links policy Exchange Online Security High FAIL Non-compliant
Description
Safe Links in Microsoft Defender for Office 365 provides time-of-click URL verification to protect users from malicious links in email messages and Office documents. Attackers commonly use deferred phishing techniques where a URL is benign at delivery time but is changed to point to a malicious site after the email passes initial scanning. Without Safe Links, users clicking on these weaponized URLs after delivery are unprotected.
Current Value
Non-compliant
Recommended Value
Safe Links enabled for email and Office apps; URL rewriting enabled; do not allow click-through to malicious URLs; real-time scanning enabled
Remediation Steps
Configure a Safe Links policy that applies to all users with URL scanning enabled for email messages and Microsoft Office applications. Enable the setting to block users from clicking through to detected malicious URLs and turn on real-time URL scanning for suspicious links. Do not add broad URL exceptions to the do-not-rewrite list and review any existing exceptions to ensure they are still necessary and do not create security gaps.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-3
MITRE ATT&CK: T1566.002
CisM365: 2.1.5
Unknown M365EXO-009 Mailbox auditing enabled Exchange Online Security High FAIL Disabled
Description
Mailbox auditing records actions performed on mailbox contents by the mailbox owner, delegates, and administrators, providing critical forensic evidence during security investigations. Although mailbox auditing is enabled by default in Microsoft 365, organizations may have disabled it for specific mailboxes or may not have verified that the default audit actions are sufficient. Without mailbox auditing, unauthorized mailbox access and data exfiltration cannot be detected or investigated.
Current Value
Disabled
Recommended Value
Mailbox auditing enabled for all mailboxes; default audit actions include MailItemsAccessed, Send, and SoftDelete for all logon types
Remediation Steps
Verify that mailbox auditing is enabled organization-wide by checking that the AuditDisabled parameter is set to False on all mailboxes. Review the audited actions for each logon type (Owner, Delegate, Admin) and ensure that critical actions such as MailItemsAccessed, Send, SoftDelete, HardDelete, and UpdateFolderPermissions are being recorded. For mailboxes that have audit disabled, re-enable auditing and investigate why it was disabled to rule out malicious tampering.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-2 AU-3
CisM365: 3.1.1
Unknown M365EXO-011 OAuth/SMTP AUTH per-mailbox audit Exchange Online Security High FAIL Disabled
Description
Legacy authentication protocols such as SMTP AUTH allow mailbox authentication using only username and password, bypassing multi-factor authentication and Conditional Access controls. Attackers who obtain mailbox credentials through phishing or password spraying can use SMTP AUTH to access email without triggering MFA challenges. Disabling SMTP AUTH and legacy OAuth flows on mailboxes that do not require them closes a significant authentication bypass vector.
Current Value
Disabled
Recommended Value
SMTP AUTH disabled organization-wide with per-mailbox exceptions only for documented service accounts; legacy OAuth disabled
Remediation Steps
Disable SMTP AUTH at the organization level using Set-TransportConfig and then selectively enable it only for specific service account mailboxes that require it for application integration. Audit all mailboxes with SMTP AUTH enabled to verify there is a documented business justification and that the credentials are managed securely. Monitor sign-in logs for SMTP AUTH usage to detect potential credential abuse and plan migration of legacy applications to modern authentication methods.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-2
MITRE ATT&CK: T1078
CisM365: 1.1.16
Unknown M365EXO-012 Remote domains auto-forward setting Exchange Online Security High FAIL Allowed to external
Description
Remote domain settings in Exchange Online control message formatting and out-of-office delivery to external domains, including whether auto-forwarding is permitted per domain. The default remote domain (*) may be configured to allow auto-forwarding, which overrides the outbound spam policy and enables data exfiltration through mailbox forwarding rules. This setting must be audited independently from the outbound spam filter to ensure consistent external forwarding controls.
Current Value
Allowed to external
Recommended Value
Auto-forwarding disabled on the default remote domain (*) and all custom remote domains unless explicitly required
Remediation Steps
Review the default remote domain (*) configuration and set AutoForwardEnabled to False to prevent automatic forwarding to all external domains. Audit any custom remote domain entries and disable auto-forwarding unless there is a documented business requirement for a specific partner domain. Verify that the remote domain settings align with the outbound spam policy auto-forwarding configuration to ensure consistent enforcement across both control layers.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-4
MITRE ATT&CK: T1114.003
Unknown M365EXO-013 Automatic forwarding to external domains disabled (MS.EXO.1.1) Exchange Online Security High FAIL Anyone (no restrictions)
Description
SCuBA MS.EXO.1.1 requires that automatic forwarding to external domains be disabled. Remote domain configuration in Exchange Online governs whether mail can be auto-forwarded out of the tenant. When the default remote domain (*) permits auto-forwarding, a compromised mailbox can silently exfiltrate all inbound mail to an attacker-controlled external address, persisting access even after credentials are reset.
Current Value
Anyone (no restrictions)
Recommended Value
AutoForwardEnabled set to False on the default remote domain (*) and on every custom remote domain unless a specific partner integration is documented
Remediation Steps
In the Exchange admin center under Mail flow, open Remote domains and edit the Default (*) entry so that automatic forwarding is not allowed (AutoForwardEnabled = False). Repeat for every custom remote domain that does not have a documented business need for cross-tenant auto-forwarding. Confirm the outbound spam policy auto-forward setting is consistent so that both control layers enforce the same restriction.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-4
MITRE ATT&CK: T1114.003
Unknown M365EXO-016 DKIM enabled for all domains (MS.EXO.3.1) Exchange Online Security High FAIL Disabled
Description
SCuBA MS.EXO.3.1 recommends that DKIM be enabled for all domains. DKIM adds a cryptographic signature to the message header so recipients can verify message integrity and authenticity. Without DKIM, recipients have one fewer signal to detect spoofed mail and DMARC alignment cannot rely on DKIM, weakening overall email authentication.
Current Value
Disabled
Recommended Value
DKIM signing enabled for every custom domain with the corresponding selector CNAME records published in DNS
Remediation Steps
Enable DKIM signing in Exchange Online for every custom domain and publish the two selector CNAME records that the service generates in the domain's DNS. Verify that the signing configuration reports an Enabled state once the CNAME records propagate. Rotate keys periodically and confirm that newly added domains have DKIM enabled as part of domain onboarding.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-8
MITRE ATT&CK: T1566.001
Unknown M365EXO-018 DMARC enforcement set to p=reject (MS.EXO.4.2) Exchange Online Security High FAIL Not configured
Description
SCuBA MS.EXO.4.2 requires that the DMARC message rejection option be set to p=reject. Of the three policy values (none, quarantine, reject), reject provides the strongest protection by instructing receivers to drop unauthenticated mail outright. A policy of none or quarantine leaves a window for spoofed mail to reach or land near user inboxes.
Current Value
Not configured
Recommended Value
DMARC record for each domain contains p=reject
Remediation Steps
After confirming that all legitimate senders pass SPF or DKIM alignment under monitoring, update each domain's DMARC record to p=reject so receivers discard mail that fails authentication. Move through p=none and p=quarantine first to avoid disrupting legitimate mail. Continue monitoring aggregate reports after enforcing reject to catch any newly onboarded sender that is not yet aligned.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-8
MITRE ATT&CK: T1566.001
Unknown M365EXO-020 SMTP AUTH disabled organization-wide (MS.EXO.5.1) Exchange Online Security High FAIL Disabled
Description
SCuBA MS.EXO.5.1 requires that SMTP AUTH be disabled. SMTP AUTH is a legacy submission protocol that authenticates with username and password and cannot enforce multi-factor authentication. Leaving it enabled as the tenant default gives attackers a path to send mail using stolen credentials while bypassing MFA and Conditional Access.
Current Value
Disabled
Recommended Value
SMTP AUTH disabled as the organization default (SmtpClientAuthenticationDisabled = True), with per-mailbox exceptions only for documented service accounts
Remediation Steps
Disable SMTP AUTH as the global default by setting SmtpClientAuthenticationDisabled to True on the transport configuration. Where a specific service account genuinely requires SMTP AUTH, enable it only on that individual mailbox and document the justification. Monitor sign-in telemetry for SMTP AUTH usage and migrate legacy applications to modern authentication.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-2
MITRE ATT&CK: T1078 T1110
Unknown M365EXO-024 Data loss prevention solution in use (MS.EXO.8.1) Exchange Online Security High FAIL Disabled
Description
SCuBA MS.EXO.8.1 requires that a DLP solution be used, offering services comparable to the native Microsoft solution. DLP detects sensitive information in Exchange Online mail and prevents unauthorized disclosure. Without DLP, users may inadvertently or maliciously send sensitive data outside the organization with no automated detection or blocking.
Current Value
Disabled
Recommended Value
At least one active DLP policy scoped to the Exchange Online workload
Remediation Steps
Deploy a DLP solution that covers the Exchange Online mail workload and confirm at least one policy is enabled and applied. If using the native Microsoft DLP capability, create a policy in the compliance portal scoped to Exchange email. Validate that the policy is in enforce mode rather than test-only so disclosures are actually blocked.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-4 SC-7
MITRE ATT&CK: T1048
Unknown M365EXO-025 DLP protects PII and sensitive data types (MS.EXO.8.2) Exchange Online Security High FAIL Disabled
Description
SCuBA MS.EXO.8.2 requires that the DLP solution protect PII and sensitive information, restricting at minimum the sharing of credit card numbers, Taxpayer Identification Numbers, and Social Security numbers via email. A DLP solution that exists but does not detect these high-value identifiers fails to prevent the most damaging classes of inadvertent disclosure.
Current Value
Disabled
Recommended Value
DLP policy includes sensitive information types covering credit card numbers, TIN, and SSN with a restrict/block action for email
Remediation Steps
Configure the DLP policy that covers Exchange Online to detect the sensitive information types for credit card numbers, Taxpayer Identification Numbers, and Social Security numbers, plus any additional agency-defined PII. Set the rule action to block or restrict outbound mail containing these identifiers. Test with sample data to confirm detection and that user notifications and incident reports are generated.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-4 SC-7 MP-6
MITRE ATT&CK: T1048
Unknown M365EXO-026 Email filtered by attachment file type (MS.EXO.9.1) Exchange Online Security High FAIL Disabled
Description
SCuBA MS.EXO.9.1 requires that emails be filtered by attachment file type, comparable to the Common Attachment Filter. Many malware payloads arrive as click-to-run attachments. Filtering inbound mail by attachment type blocks dangerous file classes before they reach users, reducing the chance of accidental execution.
Current Value
Disabled
Recommended Value
A malware/anti-malware policy with the common attachment type filter enabled (EnableFileFilter = True)
Remediation Steps
Enable the common attachments filter on the anti-malware policy so inbound mail is filtered by attachment file type. Confirm the policy is applied to all recipients and not limited to a subset. Where a comparable third-party gateway provides this filtering, verify it is enabled and covers the same dangerous file classes.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-3
MITRE ATT&CK: T1204.002
CisM365: 2.1.11
Unknown M365EXO-028 Disallowed attachment file types set (MS.EXO.9.3) Exchange Online Security High FAIL Disabled
Description
SCuBA MS.EXO.9.3 requires that disallowed file types be determined and set, blocking at minimum click-to-run files such as .exe, .cmd, and .vbe. An attachment filter that is enabled but has an empty or insufficient block list provides no real protection. The organization must define and maintain the list of blocked extensions in line with its risk tolerance.
Current Value
Disabled
Recommended Value
Attachment filter block list populated with executable/click-to-run types including at least exe, cmd, vbe, vbs, js, ps1, bat
Remediation Steps
Populate the attachment filter block list with the file types the organization will not accept over email, ensuring click-to-run executables such as exe, cmd, vbe, vbs, js, ps1, and bat are included at minimum. Review the list against current threat trends and the organization's risk tolerance. Verify the list is non-empty and applied to all recipients.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-3
MITRE ATT&CK: T1204.002
Unknown M365EXO-029 Emails scanned for malware (MS.EXO.10.1) Exchange Online Security High FAIL Disabled
Description
SCuBA MS.EXO.10.1 requires that emails be scanned for malware. Email is a primary malware delivery channel; scanning inbound mail detects known malicious content before it reaches users. An organization with no active anti-malware policy leaves users directly exposed to malware-laden attachments.
Current Value
Disabled
Recommended Value
At least one active anti-malware policy applied to all recipients
Remediation Steps
Confirm at least one anti-malware policy is active and applied to all recipients so inbound mail is scanned for malware. If using a comparable third-party solution, verify it is enabled and covers all inbound mail. Periodically review detection telemetry to confirm scanning is functioning.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-3
MITRE ATT&CK: T1566.001
Unknown M365EXO-030 Malware emails quarantined or dropped (MS.EXO.10.2) Exchange Online Security High FAIL Disabled
Description
SCuBA MS.EXO.10.2 requires that emails identified as containing malware be quarantined or dropped. Detection alone is insufficient if the malicious message is still delivered. The anti-malware policy must take a removal action so users cannot interact with messages found to contain malware.
Current Value
Disabled
Recommended Value
Anti-malware policy action quarantines or drops messages identified as malware (no deliver-with-warning action)
Remediation Steps
Configure the anti-malware policy so messages identified as containing malware are quarantined or dropped rather than delivered. Verify no policy is set to deliver malware-positive messages with only a warning. Confirm administrator notifications are enabled so the security team is alerted on detections.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-3
MITRE ATT&CK: T1566.001
Unknown M365EXO-031 Post-delivery malware scanning enabled (MS.EXO.10.3) Exchange Online Security High FAIL Disabled
Description
SCuBA MS.EXO.10.3 requires that email scanning be capable of reviewing emails after delivery. Malware signatures update continuously, so a message benign at delivery may later be recognized as malicious. Zero-hour auto purge (ZAP) retroactively removes such messages from mailboxes, reducing the window of exposure.
Current Value
Disabled
Recommended Value
Zero-hour auto purge (ZAP) enabled on all anti-malware policies (ZapEnabled = True)
Remediation Steps
Enable zero-hour auto purge (ZAP) on every anti-malware policy so messages later identified as malware are removed from mailboxes after delivery. Confirm ZAP is enabled across all policies, not just the default. Where a comparable third-party solution is used, verify it provides equivalent post-delivery remediation.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-3
MITRE ATT&CK: T1566.001
Unknown M365EXO-032 Impersonation protection checks enabled (MS.EXO.11.1) Exchange Online Security High FAIL Disabled
Description
SCuBA MS.EXO.11.1 recommends that impersonation protection checks be used. Impersonation protection compares sender addresses against known users and domains to flag look-alike addresses (for example, exmple.com versus example.com). Without it, users must manually distinguish near-identical sender addresses, which is unreliable and increases phishing success.
Current Value
Disabled
Recommended Value
Anti-phish policy with user and/or domain impersonation protection enabled and applied to high-value targets
Remediation Steps
Enable user and domain impersonation protection in an anti-phish policy and apply it to high-value targets such as executives, finance, and IT, plus organizational and key partner domains. Set the action for impersonated messages to quarantine. Note that impersonation protection requires a Defender for Office 365 plan; if unavailable, evaluate a comparable third-party capability.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-8
MITRE ATT&CK: T1656 T1566
Unknown M365EXO-035 No IP allow list in connection filter (MS.EXO.12.1) Exchange Online Security High FAIL Disabled
Description
SCuBA MS.EXO.12.1 recommends that IP allow lists not be created. Addresses on the connection filter allow list bypass spam filtering, SPF, DKIM, DMARC, and FROM-address enforcement. Any entry on this list is a hole through which an attacker who can send from that address can deliver mail that skips all inbound security controls.
Current Value
Disabled
Recommended Value
Connection filter policy IPAllowList empty for all policies
Remediation Steps
Edit the connection filter policy and remove all entries from the allowed IP address list so no senders bypass spam filtering and authentication checks. If a sender must be allowed to avoid false positives, prefer a narrowly scoped allowed-sender entry over an IP allow list. Verify no custom connection filter policy reintroduces allow-list entries.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-7 SI-8
MITRE ATT&CK: T1566.001
CisM365: 2.1.12
Unknown M365EXO-037 Mailbox auditing enabled organization-wide (MS.EXO.13.1) Exchange Online Security High FAIL Disabled
Description
SCuBA MS.EXO.13.1 requires that mailbox auditing be enabled. Mailbox auditing records actions taken on mailbox contents by owners, delegates, and administrators, providing essential forensic evidence for investigating compromise. Although enabled by default, this control guards against inadvertent or malicious disabling at the organization level.
Current Value
Disabled
Recommended Value
Organization AuditDisabled = False so mailbox auditing is enabled tenant-wide
Remediation Steps
Verify that mailbox auditing is enabled organization-wide by confirming AuditDisabled is False on the organization configuration. If auditing is disabled, re-enable it and investigate why it was turned off to rule out tampering. Confirm the default audited actions cover MailItemsAccessed, Send, SoftDelete, and HardDelete across logon types.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-2 AU-3
MITRE ATT&CK: T1114
Unknown M365EXO-038 Inbound spam filter enabled (MS.EXO.14.1) Exchange Online Security High FAIL Disabled
Description
SCuBA MS.EXO.14.1 requires that a spam filter be enabled, comparable to the native spam filtering. Spam clutters mailboxes, reduces productivity, and often carries malicious links or attachments. An organization with no active inbound spam policy leaves users exposed to the full volume of unsolicited and potentially malicious mail.
Current Value
Disabled
Recommended Value
At least one active hosted content (anti-spam) filter policy applied to all recipients
Remediation Steps
Confirm at least one inbound anti-spam (hosted content filter) policy is active and applied to all recipients. If using a comparable third-party gateway, verify it is enabled for all inbound mail. Review spam action thresholds to ensure aggressive bulk and spam senders are filtered.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-8
MITRE ATT&CK: T1566
Unknown M365EXO-041 URL block-list comparison enabled (MS.EXO.15.1) Exchange Online Security High FAIL Disabled
Description
SCuBA MS.EXO.15.1 recommends that URL comparison with a block list be enabled. Time-of-click URL protection compares links against block lists and known-malicious site lists so users are stopped before reaching dangerous destinations. Without it, links that are weaponized after delivery remain clickable and unprotected.
Current Value
Disabled
Recommended Value
Safe Links (or comparable) policy enabled for email with URL scanning active (EnableSafeLinksForEmail = True)
Remediation Steps
Enable a Safe Links or comparable URL protection policy for email so links are scanned against block lists and known-malicious site lists at time of click. Apply the policy to all users and avoid broad do-not-rewrite URL exceptions. Safe Links requires a Defender for Office 365 plan; where unavailable, evaluate a comparable third-party link protection capability.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-3
MITRE ATT&CK: T1566.002
Unknown M365EXO-042 Direct download links scanned for malware (MS.EXO.15.2) Exchange Online Security High FAIL Disabled
Description
SCuBA MS.EXO.15.2 recommends that direct download links be scanned for malware. Links in mail may point directly to malware downloads. Real-time scanning of the destination file when a user clicks a direct download link blocks the download if malware is detected, preventing device infection.
Current Value
Disabled
Recommended Value
Safe Links (or comparable) policy with real-time URL/file scanning enabled (ScanUrls = True)
Remediation Steps
Enable real-time scanning of URLs and direct-download destinations in the Safe Links or comparable policy so files behind links are scanned for malware at click time. Apply the policy to all users. Verify the option to deliver only after scanning completes is configured where appropriate to maximize protection.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-3
MITRE ATT&CK: T1566.002
Unknown M365EXO-044 Required Exchange Online alerts enabled (MS.EXO.16.1) Exchange Online Security High FAIL Disabled
Description
SCuBA MS.EXO.16.1 requires that a minimum set of alerts be enabled, including suspicious email sending patterns, suspicious connector activity, suspicious email forwarding activity, messages delayed, tenant restricted from sending unprovisioned email, tenant restricted from sending email, and a potentially malicious URL click detected. These alerts give administrators real-time insight into likely security incidents.
Current Value
Disabled
Recommended Value
The seven required alert policies enabled: suspicious sending patterns, suspicious connector activity, suspicious forwarding, messages delayed, tenant restricted from sending unprovisioned email, tenant restricted from sending email, malicious URL click
Remediation Steps
Verify each of the seven required alert policies is enabled: suspicious email sending patterns, suspicious connector activity, suspicious email forwarding activity, messages have been delayed, tenant restricted from sending unprovisioned email, tenant restricted from sending email, and a potentially malicious URL click was detected. Enable any that are disabled. Where a comparable third-party alerting solution is used, confirm it covers equivalent conditions.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-4 IR-4 AU-6
MITRE ATT&CK: T1114.003
Unknown M365EXO-046 Purview Audit (Standard) logging enabled (MS.EXO.17.1) Exchange Online Security High FAIL Disabled
Description
SCuBA MS.EXO.17.1 requires that Microsoft Purview Audit (Standard) logging, the unified audit log, be enabled. The unified audit log captures user and admin activity across Microsoft 365 and is foundational for incident response and threat detection. If unified audit log ingestion is disabled, activity evidence is not collected and investigations are severely hampered.
Current Value
Disabled
Recommended Value
Unified audit log ingestion enabled (UnifiedAuditLogIngestionEnabled = True)
Remediation Steps
Verify that unified audit log ingestion is enabled (UnifiedAuditLogIngestionEnabled = True) so user and admin activity is captured in the Microsoft 365 audit log. If disabled, enable it via the audit log configuration. Confirm logging is active by querying for recent events after enabling.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-2 AU-3 AU-12
MITRE ATT&CK: T1562.008
Unknown M365EXO-050 DLP restricts sharing of SSN, ITIN, and credit-card numbers (MS.EXO.8.4) Exchange Online Security High FAIL Anyone (no restrictions)
Description
SCuBA MS.EXO.8.4 requires that the Data Loss Prevention solution, at a minimum, restrict sharing of credit card numbers, U.S. Individual Taxpayer Identification Numbers (ITIN), and U.S. Social Security Numbers (SSN) via email. This check inspects the DLP compliance rules collected from the tenant and confirms at least one enabled rule references each of those three sensitive information types. It reads DLP rules (not just policies); because Get-DlpComplianceRule cannot distinguish an unconfigured DLP solution from one that could not be read, an absent or empty rule set is reported as Not Assessed rather than a failure or a pass. A FAIL is only returned when rules are present but demonstrably do not cover one of the three required types.
Current Value
Anyone (no restrictions)
Recommended Value
At least one enabled DLP rule each for U.S. SSN, U.S. ITIN, and Credit Card Number sensitive information types, scoped to Exchange email
Remediation Steps
In the Microsoft Purview compliance portal under Data loss prevention > Policies, create or extend a policy scoped to the Exchange email location with rules that detect the Credit Card Number, U.S. Social Security Number (SSN), and U.S. Individual Taxpayer Identification Number (ITIN) sensitive information types, and set the action to block or restrict external sharing. Enable the policy (not test mode) so the rules are enforced.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-7 SI-4 AC-4
Unknown M365PP-001 Environment creation restrictions Power Platform Security High FAIL Disabled
Description
By default, all users in a Microsoft 365 tenant can create new Power Platform environments, which spin up associated Dataverse databases and can host Power Apps and Power Automate flows with access to organizational data. Unrestricted environment creation leads to shadow IT sprawl where ungoverned applications are built with data connections that bypass IT security controls. Restricting environment creation to administrators ensures proper governance and prevents uncontrolled data exposure.
Current Value
Disabled
Recommended Value
Environment creation restricted to Global Admins and Power Platform Admins only; all production environments managed through a formal provisioning process
Remediation Steps
Navigate to the Power Platform admin center and restrict environment creation to only Global Administrators and Power Platform Administrators by configuring the tenant-level setting. Implement a formal request and provisioning process for new environments that includes security review, data classification, and DLP policy assignment before environment creation. Audit existing environments to identify and decommission any ungoverned environments that were created before restrictions were put in place.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-7
CisM365: 9.1
Unknown M365PP-002 DLP policy configuration Power Platform Security High FAIL Non-compliant
Description
Data Loss Prevention policies for Power Platform control which connectors can be used together within Power Apps and Power Automate flows, preventing unauthorized data movement between business and non-business data sources. Without DLP policies, users can create flows that automatically transfer corporate data from SharePoint, Dynamics 365, or Azure SQL to personal email, social media, or third-party cloud storage. DLP connector classification is the primary mechanism for preventing data exfiltration through citizen-developed applications.
Current Value
Non-compliant
Recommended Value
Tenant-level DLP policy classifying business-critical connectors (SharePoint, Outlook, Dataverse) as Business and blocking their combination with non-business connectors; environment-level policies for specific use cases
Remediation Steps
Create a tenant-level DLP policy that classifies all connectors containing corporate data (such as SharePoint, Outlook, Dataverse, Azure SQL, and OneDrive) in the Business group and moves known non-business connectors to the Blocked group. Review the default connector classification to ensure that newly released connectors are automatically placed in the Non-Business group until reviewed and approved. Create environment-specific DLP policies for environments that require access to additional connectors beyond the tenant-level policy, ensuring they are at least as restrictive as the tenant policy.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-4
CisM365: 9.2
Unknown M365PP-003 Tenant isolation settings Power Platform Security High FAIL Disabled
Description
Power Platform tenant isolation controls whether connectors in your tenant can establish connections to other Azure AD tenants, and whether other tenants can connect to yours. Without tenant isolation, users can create flows and apps that connect to external organizations' data sources, and external organizations can build automations that access your tenant's resources. Enabling tenant isolation prevents unauthorized cross-tenant data flows that could result in data leakage or supply chain compromise.
Current Value
Disabled
Recommended Value
Tenant isolation enabled with inbound and outbound restrictions; allow-listed exceptions only for approved partner tenants
Remediation Steps
Enable Power Platform tenant isolation in the Power Platform admin center to restrict both inbound and outbound cross-tenant connections by default. Configure an allow list of specific trusted partner tenant IDs that require cross-tenant connectivity for legitimate business scenarios. Review the allow list quarterly to remove tenants that no longer require cross-tenant access and monitor the audit logs for any cross-tenant connection attempts that are being blocked by the isolation policy.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-20
CisM365: 9.3
Unknown M365SPO-001 External sharing settings SharePoint & OneDrive Security High FAIL Anyone (no restrictions)
Description
SharePoint Online external sharing settings control whether and how content can be shared with users outside the organization. Overly permissive sharing settings such as allowing anonymous sharing links can lead to uncontrolled data exposure and make it impossible to track who has accessed corporate content. Restricting external sharing to authenticated guests with verified identities is essential for maintaining data governance.
Current Value
Anyone (no restrictions)
Recommended Value
External sharing limited to existing guests or new and existing guests with authentication required; anonymous sharing links disabled
Remediation Steps
Navigate to the SharePoint admin center sharing settings and configure the organization-level sharing to 'New and existing guests' or 'Existing guests only' based on your collaboration requirements. Disable anonymous access links (Anyone links) to ensure all external access requires authentication and can be tracked. Review site-level sharing overrides to ensure no individual sites have more permissive sharing settings than the organizational default.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-21
CisM365: 7.2.1
Unknown M365SPO-005 DLP policy configuration SharePoint & OneDrive Security High FAIL Non-compliant
Description
Data Loss Prevention policies in SharePoint Online and OneDrive detect and protect sensitive information such as personally identifiable information, financial data, and health records from being shared inappropriately. Without DLP policies, users can inadvertently share documents containing sensitive data with external users or through unmonitored channels. DLP policies provide automated detection, user notification, and blocking of sensitive data exposure.
Current Value
Non-compliant
Recommended Value
DLP policies configured for all regulated data types with user notifications and sharing blocks for external sharing of sensitive content
Remediation Steps
Create DLP policies targeting SharePoint Online and OneDrive locations that detect sensitive information types relevant to your regulatory requirements such as PII, PCI, or HIPAA data. Configure policy rules to display user notifications with guidance on proper handling when sensitive content is detected, and block external sharing of documents containing high-sensitivity data. Enable incident reports to notify the compliance team of policy matches and review the DLP activity reports to tune policy accuracy and reduce false positives.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-4 SC-7
Unknown M365TEAMS-001 External access settings Microsoft Teams Security High FAIL Anyone (no restrictions)
Description
External access (federation) in Microsoft Teams controls whether users can communicate with people in other Microsoft 365 organizations or Skype users. Unrestricted external access allows any external organization to initiate chats and calls with your users, creating vectors for social engineering and phishing through the Teams client. Limiting federation to specific trusted domains reduces the attack surface while maintaining necessary business communication.
Current Value
Anyone (no restrictions)
Recommended Value
External access limited to specific allowed domains rather than open federation; Skype consumer access disabled
Remediation Steps
Configure Teams external access to use a domain allow list containing only trusted partner organization domains rather than allowing open federation with all external tenants. Disable communication with Skype consumer users unless there is a specific business requirement. Review and update the allowed domain list quarterly to remove organizations that no longer require federation access.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-20
CisM365: 8.1.1
Unknown M365TEAMS-002 Guest access settings Microsoft Teams Security High FAIL Unrestricted
Description
Guest access in Microsoft Teams allows external users to be added to teams and channels, granting them access to conversations, files, and shared resources. Overly permissive guest settings can allow external users to create channels, modify team settings, or access sensitive content that should be restricted to internal users. Guest capabilities must be configured to provide the minimum necessary access for external collaboration.
Current Value
Unrestricted
Recommended Value
Guest access enabled with restricted capabilities; guests cannot create or update channels, participate in private chats, or share files without approval
Remediation Steps
Review the Teams guest access settings and restrict guest capabilities to prevent guests from creating or deleting channels, adding or removing apps, and sharing screen in meetings. Disable guest access entirely if external collaboration is not required, or configure it with the most restrictive settings that still support business needs. Implement Azure AD access reviews for Teams guest accounts to regularly validate that guest access is still appropriate.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-14
CisM365: 8.1.2
Unknown M365TEAMS-004 Anonymous meeting join settings Microsoft Teams Security High FAIL Unrestricted
Description
Anonymous meeting join allows anyone with a meeting link to join Teams meetings without authentication, making it impossible to verify the identity of participants. This setting is frequently exploited in meeting bombing attacks where uninvited participants join to disrupt meetings or eavesdrop on confidential discussions. Disabling anonymous join or requiring all participants to authenticate significantly improves meeting security.
Current Value
Unrestricted
Recommended Value
Anonymous meeting join disabled; all meeting participants required to authenticate; lobby enabled for unauthenticated users
Remediation Steps
Disable anonymous meeting join in the Teams meeting policy to require all participants to sign in before joining meetings. If anonymous join must be allowed for specific use cases such as public webinars, create a separate meeting policy with anonymous join enabled and assign it only to the users who need it. Enable the lobby for all external and guest participants and configure meeting organizers to manually admit attendees from the lobby.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-14
CisM365: 8.5.2
Unknown OAUTH-001 OAuth App Whitelist/Blocklist OAuth & API Security High FAIL Unreviewed permissions
Description
OAuth app access should be governed by an allowlist or blocklist to prevent unauthorized applications from accessing organizational data
Current Value
Unreviewed permissions
Recommended Value
OAuth app allowlist configured with only approved applications
Remediation Steps
Admin Console > Security > API controls > App access control > Manage third-party app access > Configure trusted/blocked apps
Compliance Mappings
NIST SP 800-53: CM-7 AC-3
MITRE ATT&CK: T1550.001 T1528
CIS Benchmark: 3.1
Unknown OAUTH-002 Installed OAuth Apps Inventory OAuth & API Security High FAIL Unreviewed permissions
Description
All OAuth applications installed by users should be inventoried and reviewed to identify unauthorized or risky applications accessing organizational data
Current Value
Unreviewed permissions
Recommended Value
All installed OAuth apps reviewed and approved by security team
Remediation Steps
Admin Console > Security > API controls > App access control > Review installed apps and revoke access for unauthorized applications
Compliance Mappings
NIST SP 800-53: CM-8 CM-11
MITRE ATT&CK: T1528 T1550.001
CIS Benchmark: 3.2
Unknown OAUTH-004 OAuth App Risk Scoring OAuth & API Security High FAIL Unreviewed permissions
Description
OAuth applications should be risk-scored based on their granted scopes and publisher trust to prioritize security review
Current Value
Unreviewed permissions
Recommended Value
All high-risk apps reviewed and approved; no unreviewed apps with broad scopes
Remediation Steps
Admin Console > Security > API controls > App access control > Review apps sorted by scope breadth > Address high-risk applications
Compliance Mappings
NIST SP 800-53: RA-3 CM-11
MITRE ATT&CK: T1528
CIS Benchmark: 3.4
Unknown OAUTH-005 Unverified App Access Policy OAuth & API Security High FAIL Non-compliant
Description
Access to unverified third-party apps should be restricted to prevent users from granting permissions to potentially malicious applications
Current Value
Non-compliant
Recommended Value
Unverified app access blocked for all users
Remediation Steps
Admin Console > Security > API controls > App access control > Settings > Block unverified apps
Compliance Mappings
NIST SP 800-53: CM-7 SI-7
MITRE ATT&CK: T1528 T1204.003
CIS Benchmark: 3.5
Unknown OAUTH-009 Service Account Key Enumeration OAuth & API Security High FAIL Disabled
Description
Service account keys should be inventoried and rotated regularly. Leaked or stale keys provide persistent unauthorized access
Current Value
Disabled
Recommended Value
All service account keys inventoried, rotated within 90 days, and unused keys removed
Remediation Steps
Google Cloud Console > IAM & Admin > Service accounts > Review and rotate keys > Remove unused service account keys
Compliance Mappings
NIST SP 800-53: IA-5(1) AC-2(3)
MITRE ATT&CK: T1078.004 T1552.004
CIS Benchmark: 3.9
Unknown OAUTH-010 Connected Apps With Sensitive Scopes OAuth & API Security High FAIL Unreviewed permissions
Description
Applications with access to Drive, Gmail, or Calendar data should be inventoried and validated to prevent data exfiltration through connected apps
Current Value
Unreviewed permissions
Recommended Value
All apps with sensitive scopes (Drive, Gmail, Calendar) reviewed and approved
Remediation Steps
Admin Console > Security > API controls > App access control > Filter by scope (Drive, Gmail, Calendar) > Review and restrict unauthorized apps
Compliance Mappings
NIST SP 800-53: AC-3 AC-6
MITRE ATT&CK: T1530 T1114.002 T1528
CIS Benchmark: 3.10
Unknown ADACL-008 OU Delegation Analysis AD ACL & Delegation Medium FAIL Unconstrained
Description
Organizational Unit delegation is the recommended method for granting administrative permissions in Active Directory, but misconfigured OU delegations can create unintended access paths. This check analyzes all OU-level permission delegations to identify overly permissive grants, inherited permissions that bypass intended scoping, and delegations that may have become stale
Current Value
Unconstrained
Recommended Value
All OU delegations documented, scoped to specific object types, and using least-privilege permissions
Remediation Steps
Review all non-default ACEs on each OU using dsacls.exe or PowerShell. Verify that delegations use the InheritedObjectType to scope permissions to specific object classes. Remove delegations that are no longer required. Document all intentional delegations in an authorization matrix.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 AC-6(3) CM-5
MITRE ATT&CK: T1222.001
Unknown ADCS-015 ESC15 - Application Policies in Schema v1 Templates AD Certificate Services Medium FAIL Vulnerable configuration
Description
ESC15 (also known as EKUwu) exploits Schema Version 1 certificate templates where the Application Policies extension can be specified by the enrollee in the certificate request. Because Schema v1 templates do not enforce the Application Policies from the template, an attacker can add Client Authentication or any other EKU to the issued certificate, regardless of the template configuration
Current Value
Vulnerable configuration
Recommended Value
No Schema v1 templates published that allow low-privileged enrollment; migrate all required templates to Schema v2 or later
Remediation Steps
Identify all Schema v1 templates (msPKI-Template-Schema-Version = 1) that are published on Enterprise CAs. Migrate Schema v1 templates to Schema v2 or later by creating new templates based on the v1 template with explicit EKU enforcement. Restrict enrollment on any remaining v1 templates to administrative accounts only. Unpublish v1 templates that are no longer required.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6 IA-5(2)
MITRE ATT&CK: T1649
Unknown ADDOM-003 Schema Version Identification AD Domain & Forest Configuration Medium FAIL Default (insecure)
Description
The AD schema version should be documented and correspond to the latest supported version. An outdated schema may lack attributes required by modern security features and applications
Current Value
Default (insecure)
Recommended Value
Schema version corresponding to Windows Server 2022 (version 88) or later
Remediation Steps
Run adprep /forestprep and adprep /domainprep from the latest Windows Server installation media to update the schema. Verify the objectVersion attribute on CN=Schema,CN=Configuration,DC=domain
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6 CM-2
MITRE ATT&CK: T1078.002
CIS Benchmark: 18.3.1
CisAd: 1.1.3
Unknown ADDOM-008 Tombstone Lifetime Configuration AD Domain & Forest Configuration Medium FAIL Default (insecure)
Description
The tombstone lifetime defines how long deleted objects are retained before permanent removal and determines the maximum offline time for a DC before it must be rebuilt. A value too low can cause lingering objects; the default of 60 days should be increased to 180 days for modern environments
Current Value
Default (insecure)
Recommended Value
180 days
Remediation Steps
Modify the tombstoneLifetime attribute on CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=domain. Set to 180 using ADSIEdit or PowerShell. Ensure AD Recycle Bin is enabled before modifying
Remediation URL
Compliance Mappings
NIST SP 800-53: CP-9 CP-10
MITRE ATT&CK: T1485
CisAd: 1.4.1
Unknown ADDOM-009 AD Recycle Bin Status AD Domain & Forest Configuration Medium FAIL Default (insecure)
Description
The Active Directory Recycle Bin allows recovery of deleted objects with all attributes intact. Without it, restoring accidentally or maliciously deleted objects requires authoritative restore from backup, which causes significant downtime
Current Value
Default (insecure)
Recommended Value
Enabled
Remediation Steps
Enable AD Recycle Bin via Active Directory Administrative Center > right-click domain > Enable Recycle Bin, or run Enable-ADOptionalFeature 'Recycle Bin Feature' in PowerShell. Note: this action is irreversible
Remediation URL
Compliance Mappings
NIST SP 800-53: CP-9 CP-10
MITRE ATT&CK: T1485
CIS Benchmark: 18.3.1
CisAd: 1.4.2
Unknown ADDOM-010 Sites and Subnets Configuration AD Domain & Forest Configuration Medium FAIL Default (insecure)
Description
All IP subnets in use should be assigned to AD sites. Missing subnet-to-site mappings cause clients to authenticate against suboptimal DCs, potentially sending credentials across WAN links in cleartext and degrading security posture
Current Value
Default (insecure)
Recommended Value
All IP subnets mapped to appropriate AD sites with no orphaned subnets
Remediation Steps
Review AD Sites and Services > Subnets container. Cross-reference with network documentation to identify unmapped subnets. Create subnet objects for all production networks and associate them with the correct site
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-7 CM-6
MITRE ATT&CK: T1557
CisAd: 1.5.1
Unknown ADDOM-020 DSRM Password Configuration AD Domain & Forest Configuration Medium FAIL Default (insecure)
Description
The Directory Services Restore Mode (DSRM) password provides local administrator access to a domain controller when booted in recovery mode. An attacker with physical or remote access who knows the DSRM password can extract the entire AD database. The DSRM password should be unique per DC and rotated regularly
Current Value
Default (insecure)
Recommended Value
DSRM password unique per DC, rotated annually, and stored securely. DsrmAdminLogonBehavior set to 0 to prevent network DSRM logon
Remediation Steps
Reset DSRM passwords using 'ntdsutil > set dsrm password' on each DC. Set the registry value DsrmAdminLogonBehavior to 0 at HKLM\System\CurrentControlSet\Control\Lsa to prevent DSRM account from being used for network logon. Document and securely store passwords
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1) AC-6
MITRE ATT&CK: T1003 T1078.002
Anssi: R10
CisAd: 1.2.4
Unknown ADGPO-006 GPOs with Broken Links AD Group Policy Medium FAIL Misconfigured
Description
GPO links that reference non-existent GPOs or GPOs whose SYSVOL data is missing indicate replication issues, improper deletion, or corruption. Broken links can cause Group Policy processing errors and may mask the absence of intended security configurations
Current Value
Misconfigured
Recommended Value
No broken GPO links; all gPLink references resolve to valid GPOs with intact SYSVOL data
Remediation Steps
Parse gPLink attributes on all OUs, sites, and the domain root to extract referenced GPO GUIDs. Verify each GUID exists in the GPC (AD) and GPT (SYSVOL) containers. Remove broken links using Set-GPLink or by directly editing the gPLink attribute. Investigate the root cause of any missing GPO data.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-3 CM-6
MITRE ATT&CK: T1484.001
Unknown ADGPO-008 GPOs Not Applied Due to WMI Filters AD Group Policy Medium FAIL Misconfigured
Description
WMI filters can prevent GPOs from applying to target systems based on WQL queries. Overly broad or misconfigured WMI filters may inadvertently block security-critical GPOs from applying to systems that require them, creating gaps in the intended security configuration
Current Value
Misconfigured
Recommended Value
All security-critical GPOs apply to intended targets; WMI filters validated against actual environment conditions
Remediation Steps
Review WMI filters linked to security-critical GPOs using Get-GPO and examining WMI filter assignments. Test WMI filter queries against representative target systems to verify they evaluate correctly. Use Group Policy Results (gpresult) on sample systems to confirm GPOs are applying. Replace or fix WMI filters that are blocking intended application.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6 CM-3
MITRE ATT&CK: T1484.001
Unknown ADGPO-009 GPOs with No Apply Permission AD Group Policy Medium FAIL Misconfigured
Description
If the Apply Group Policy (Read + Apply) permission is not granted to the appropriate security principals, the GPO will not be processed by those systems even when linked to the correct OU. This commonly occurs when Authenticated Users is removed from the GPO security filtering without adding specific groups
Current Value
Misconfigured
Recommended Value
All GPOs have Apply Group Policy permission granted to appropriate security groups; no GPOs with no apply targets
Remediation Steps
Check each GPO for Apply Group Policy permissions using Get-GPPermission. Ensure that at least one security group with members has the Apply permission. For GPOs that should apply to specific groups only, verify the target groups contain the intended members. Add Authenticated Users with Read-only permission (without Apply) if security filtering is used.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6 AC-3
MITRE ATT&CK: T1484.001
Unknown ADGPO-010 SYSVOL/AD GPO Version Mismatch AD Group Policy Medium FAIL Misconfigured
Description
Each GPO maintains version numbers in both the AD GPC object (versionNumber attribute) and the SYSVOL GPT folder (gpt.ini). A mismatch between these versions indicates replication failure, SYSVOL corruption, or incomplete GPO updates. Version mismatches can cause clients to apply stale or incomplete policies
Current Value
Misconfigured
Recommended Value
All GPO versions match between AD GPC objects and SYSVOL GPT gpt.ini files across all domain controllers
Remediation Steps
Compare the versionNumber attribute in AD with the Version value in SYSVOL gpt.ini for each GPO across all domain controllers. Investigate and resolve any DFSR or FRS replication issues causing mismatches. Force replication using repadmin /syncall and DFSRDIAG. For persistent mismatches, use the authoritative restore process for SYSVOL.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-3 CM-6 SI-7
MITRE ATT&CK: T1484.001
Unknown ADGPO-014 MSI Packages in GPOs AD Group Policy Medium FAIL Misconfigured
Description
Software Installation GPO settings deploy MSI packages to targeted computers. Compromised or unauthorized MSI packages in GPOs can deploy malware across the domain. The source location of MSI packages and access controls on those locations must be verified
Current Value
Misconfigured
Recommended Value
All GPO-deployed MSI packages sourced from secure, access-controlled locations with verified integrity
Remediation Steps
Identify all software installation settings in GPOs. Verify that MSI source paths point to secured shares with appropriate NTFS and share permissions. Confirm that MSI packages are from trusted vendors and have not been tampered with. Consider using WDAC or AppLocker to restrict MSI installation to approved packages.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-5 CM-7(5) SI-7
MITRE ATT&CK: T1484.001 T1072
Unknown ADGPO-016 Registry Settings Security Review AD Group Policy Medium FAIL Default (insecure)
Description
GPOs can deploy registry settings that affect security configurations including disabling security features, weakening authentication protocols, or enabling insecure services. Registry-based settings in GPOs should be reviewed to ensure they do not weaken the security posture of targeted systems
Current Value
Default (insecure)
Recommended Value
No GPO registry settings that weaken security defaults; all registry modifications documented and justified
Remediation Steps
Export GPO registry settings from Administrative Templates and Registry Preferences. Review settings that affect security-relevant registry keys including HKLM\SYSTEM\CurrentControlSet\Control\Lsa, HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies, and authentication-related keys. Remove or correct settings that weaken security posture.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6 CM-6(1)
MITRE ATT&CK: T1484.001 T1112
Unknown ADGPO-019 Windows Firewall Configuration via GPO AD Group Policy Medium FAIL Misconfigured
Description
Windows Defender Firewall with Advanced Security settings deployed via GPO control network access on domain-joined systems. GPOs that disable the firewall, allow overly permissive inbound rules, or fail to configure the firewall leave systems vulnerable to lateral movement and network-based attacks
Current Value
Misconfigured
Recommended Value
Windows Firewall enabled for all profiles (Domain, Private, Public) with deny-by-default inbound rules configured via GPO
Remediation Steps
Review Windows Firewall GPO settings across all applicable GPOs. Ensure the firewall is enabled for Domain, Private, and Public profiles. Verify that inbound rules follow a deny-by-default approach with specific allow rules for required services only. Remove any GPO settings that disable the Windows Firewall. Test firewall rules in a staging OU before domain-wide deployment.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-7 SC-7(5) CM-6
MITRE ATT&CK: T1484.001 T1562.004
Unknown ADGPO-020 PowerShell Execution Policy via GPO AD Group Policy Medium FAIL Misconfigured
Description
PowerShell execution policy controls which scripts can run on a system. While execution policy is not a security boundary, setting it to Unrestricted or Bypass via GPO removes a layer of defense and makes it easier for attackers to execute malicious scripts without user prompts
Current Value
Misconfigured
Recommended Value
PowerShell execution policy set to AllSigned or RemoteSigned via GPO; not set to Unrestricted or Bypass
Remediation Steps
Review GPO settings under Computer Configuration > Administrative Templates > Windows Components > Windows PowerShell > Turn on Script Execution. Set the execution policy to AllSigned for high-security environments or RemoteSigned for standard environments. Implement code signing for authorized PowerShell scripts. Avoid setting Bypass or Unrestricted via GPO.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6 CM-7 SI-7
MITRE ATT&CK: T1059.001 T1484.001
Unknown ADGPO-022 AppLocker/WDAC Policy Assessment AD Group Policy Medium FAIL Non-compliant
Description
Application control policies such as AppLocker and Windows Defender Application Control restrict which executables, scripts, and DLLs can run on managed systems. Without application control, attackers can execute arbitrary tools and malware on compromised systems to facilitate lateral movement and persistence
Current Value
Non-compliant
Recommended Value
AppLocker or WDAC policy deployed via GPO in enforce mode on all workstations and servers with a documented baseline
Remediation Steps
Deploy AppLocker or WDAC policies via GPO starting in audit mode. Analyze audit logs to build a baseline of approved applications. Create allow-list rules based on publisher, path, or hash. Transition from audit to enforce mode after validating the baseline. Monitor for blocked execution events and update rules as needed.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-7(5) CM-7(2) SI-7
MITRE ATT&CK: T1059 T1204.002
Unknown ADKERB-010 Kerberos Ticket Lifetime AD Kerberos Security Medium FAIL Weak encryption (RC4)
Description
Kerberos ticket lifetimes control how long authentication tickets remain valid. Excessively long TGT or service ticket lifetimes extend the window during which stolen tickets can be used for pass-the-ticket attacks. The default TGT lifetime of 10 hours and maximum renewal of 7 days should be reviewed to balance security with operational requirements
Current Value
Weak encryption (RC4)
Recommended Value
TGT maximum lifetime: 4-10 hours. Service ticket maximum lifetime: 600 minutes. Maximum ticket renewal: 7 days. Maximum clock skew: 5 minutes
Remediation Steps
Configure Kerberos policy in Default Domain Policy: Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Kerberos Policy. Set maximum lifetime for service ticket (600 minutes), maximum lifetime for user ticket (10 hours or less), and maximum lifetime for user ticket renewal (7 days). For Tier 0 accounts, add them to the Protected Users group which automatically enforces a 4-hour TGT lifetime
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-12
CisAd: 7.5.1
Unknown ADLOG-003 PowerShell Module Logging Enabled AD Logging & EDR Posture Medium FAIL Disabled
Description
Event 4103 (PowerShell Module Logging) records the cmdlet/parameter invocations of any module configured for logging. Pair this with Script Block Logging and you have a high-confidence telemetry stack for any PS-based attack. The setting is delivered by administrative template into HKLM\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ModuleLogging.
Current Value
Disabled
Recommended Value
Group Policy 'Turn on Module Logging' is Enabled with at least the '*' module name list. Registry: EnableModuleLogging = 1.
Remediation Steps
Computer Configuration > Policies > Administrative Templates > Windows Components > Windows PowerShell > 'Turn on Module Logging' = Enabled. Add '*' to the Module Names list (logs all modules) or specifically Microsoft.PowerShell.* + the modules your environment uses for administration.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-2 SI-4
MITRE ATT&CK: T1059.001
CisAd: 9.2.2
Unknown ADLOG-007 Sysmon Deployment Indicator AD Logging & EDR Posture Medium FAIL Default (insecure)
Description
Sysmon (System Monitor, from Sysinternals) is the gold-standard endpoint telemetry source for the events Windows native logging doesn't cover well: file hash on process creation, network connections per process, DLL loads, registry monitoring, named pipes. It runs as a kernel-mode driver. There's no GPO-side detection of 'Sysmon is installed' from SYSVOL alone — the indicator is the presence of a Sysmon config GPO or a startup script that deploys it. This check WARNs and asks the auditor to verify out-of-band.
Current Value
Default (insecure)
Recommended Value
Sysmon is installed on workstations and servers via a deployment GPO or configuration-management push, with a configuration tuned to the environment (SwiftOnSecurity, Olaf Hartong, or vendor-provided baselines).
Remediation Steps
Deploy Sysmon (https://download.sysinternals.com/files/Sysmon.zip) via GPO startup script or your config-management platform. Use a community baseline as starting point (SwiftOnSecurity/sysmon-config or Olaf Hartong/sysmon-modular). Verify deployment via Get-CimInstance Win32_Service -Filter "Name='Sysmon64'" against a representative host set, or query the WEF collector for 'Microsoft-Windows-Sysmon/Operational' events.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-2 SI-4
MITRE ATT&CK: T1562.001
CisAd: 9.4.2
Unknown ADMIN-003 Delegated Admin Permissions Review Admin & User Management Medium FAIL Excessive permissions found
Description
Custom admin roles should be reviewed to ensure delegated permissions are appropriately scoped and do not grant excessive access
Current Value
Excessive permissions found
Recommended Value
Custom admin roles scoped to minimum necessary permissions
Remediation Steps
Admin Console > Account > Admin roles > Review each custom role > Verify permissions are scoped appropriately
Compliance Mappings
NIST SP 800-53: AC-6(1) AC-3
MITRE ATT&CK: T1098.003
CIS Benchmark: 4.3
Unknown ADMIN-005 User Account Inventory Admin & User Management Medium FAIL Default (insecure)
Description
User account inventory should be maintained with clear counts of active, suspended, and archived accounts for governance
Current Value
Default (insecure)
Recommended Value
Complete user inventory with all accounts in appropriate active/suspended/archived state
Remediation Steps
Admin Console > Directory > Users > Review user list > Suspend or archive accounts that are no longer needed
Compliance Mappings
NIST SP 800-53: AC-2 CM-8
MITRE ATT&CK: T1087.004
CIS Benchmark: 4.5
Unknown ADMIN-006 Stale User Accounts Admin & User Management Medium FAIL Multiple found
Description
User accounts with no login in 90 or more days may be orphaned and should be reviewed for suspension or deletion
Current Value
Multiple found
Recommended Value
No user accounts inactive for more than 90 days without documented justification
Remediation Steps
Admin Console > Directory > Users > Sort by last sign-in > Review and suspend accounts inactive for 90+ days
Compliance Mappings
NIST SP 800-53: AC-2(3)
MITRE ATT&CK: T1078.004
CIS Benchmark: 4.6
Unknown ADMIN-008 Directory Sharing Settings Admin & User Management Medium FAIL Anyone (no restrictions)
Description
Directory sharing controls who can view organizational contacts and profiles. External directory sharing should be limited
Current Value
Anyone (no restrictions)
Recommended Value
Directory sharing restricted to internal users only
Remediation Steps
Admin Console > Directory > Directory settings > Sharing settings > Restrict contact sharing to domain users
Compliance Mappings
NIST SP 800-53: AC-3 AC-22
MITRE ATT&CK: T1087.004 T1589
CIS Benchmark: 4.8
Unknown ADMIN-011 Group Creation Restrictions Admin & User Management Medium FAIL Default (insecure)
Description
Group creation should be restricted to prevent proliferation of unmanaged groups that may expose organizational data
Current Value
Default (insecure)
Recommended Value
Group creation restricted to admins or specific delegated roles
Remediation Steps
Admin Console > Apps > Google Workspace > Groups for Business > Sharing settings > Restrict who can create groups
Compliance Mappings
NIST SP 800-53: CM-7 AC-6
MITRE ATT&CK: T1136.003
CIS Benchmark: 4.11
Unknown ADMIN-012 Groups for Business Settings Admin & User Management Medium FAIL Default (insecure)
Description
Groups for Business settings control group features including external posting, member visibility, and content sharing
Current Value
Default (insecure)
Recommended Value
Groups for Business configured with restricted external access and posting
Remediation Steps
Admin Console > Apps > Google Workspace > Groups for Business > Sharing settings > Review all settings
Compliance Mappings
NIST SP 800-53: AC-3 AC-4
MITRE ATT&CK: T1530 T1213.003
CIS Benchmark: 4.12
Unknown ADMIN-014 Assured Controls - Access Approvals Enabled Admin & User Management Medium FAIL Disabled
Description
Access Approvals should be enabled so that Google support staff must request and obtain organizational approval before accessing covered data, reducing the risk of unauthorized provider access.
Current Value
Disabled
Recommended Value
Access Approvals enabled (Google staff require customer approval before accessing data)
Remediation Steps
Admin Console > Data > Compliance > Access Management / Access Approvals > Enable the requirement for Google support staff to request approval before accessing organizational data. Requires Assured Controls.
Compliance Mappings
NIST SP 800-53: AC-3 AC-6 AU-9
MITRE ATT&CK: T1199
Unknown ADMIN-015 Assured Controls - Support Access Restricted to U.S. Staff Admin & User Management Medium FAIL Default (insecure)
Description
Support access should be restricted to Google staff located in the United States to maintain data sovereignty and prevent covered data from being handled by non-U.S. personnel.
Current Value
Default (insecure)
Recommended Value
Support access audience restricted to U.S. Google staff
Remediation Steps
Admin Console > Data > Compliance > Access Management > Set the allowed support audience to U.S. Google staff only. Requires Assured Controls.
Compliance Mappings
NIST SP 800-53: AC-3 SA-9
MITRE ATT&CK: T1199
Unknown ADMIN-016 Assured Controls - Multi-Region Data Processing Disabled Admin & User Management Medium FAIL Default (insecure)
Description
Data processing across multiple regions should be disabled for all Google Workspace products so that covered data is processed only within its designated storage region, preserving data sovereignty.
Current Value
Default (insecure)
Recommended Value
Data processing limited to the storage region (multi-region processing disabled)
Remediation Steps
Admin Console > Data > Compliance > Data regions > Enable 'Limit data processing to the chosen storage region' across Calendar, Drive and Docs, Gmail, Chat, Meet, and Gemini. Requires Assured Controls / Data Regions.
Compliance Mappings
NIST SP 800-53: SC-7 AC-4
MITRE ATT&CK: T1530
Unknown ADMIN-017 Internal apps not auto-trusted (GWS.COMMONCONTROLS.10.3) Admin & User Management Medium FAIL SID filtering disabled
Description
SCuBA GWS.COMMONCONTROLS.10.3: automatically trusting internal (domain-owned) OAuth apps grants them access without review, an insider/lateral data-access path. Reads api_controls.internal_apps; warns where trustInternalApps is on.
Current Value
SID filtering disabled
Recommended Value
Internal apps are not automatically trusted
Remediation Steps
In Admin console > Security > API controls, disable automatic trust of internal apps so they undergo the same review as third-party apps.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-3 AC-6 CM-7
Unknown ADMIN-021 Additional Google services without individual control restricted (GWS.COMMONCONTROLS.16.1) Admin & User Management Medium FAIL Default (insecure)
Description
SCuBA GWS.COMMONCONTROLS.16.1 recommends that Google services which do not have their own individual admin control be turned OFF for everyone. Google models this with inverted semantics: the enterprise_service_restrictions service must be ENABLED for those additional services to be restricted (blocked). This check reads the enterprise_service_restrictions.service_status Cloud Identity policy and flags any organizational unit where serviceState is not ENABLED, meaning users can still reach unconfigured additional services.
Current Value
Default (insecure)
Recommended Value
enterprise_service_restrictions serviceState set to ENABLED (additional services restricted) in all organizational units.
Remediation Steps
In the Google Admin console, under Apps > Additional Google services, set the access setting for services without an individual control to OFF for everyone. This enables the enterprise service restriction so users cannot access those additional services.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-7 AC-6
Unknown ADMIN-022 Early Access applications disabled (GWS.COMMONCONTROLS.16.2) Admin & User Management Medium FAIL Unreviewed permissions
Description
SCuBA GWS.COMMONCONTROLS.16.2 recommends disabling user access to Early Access applications, which are pre-release features that have not completed Google's full review and may carry unassessed risk. This check reads the early_access_apps.service_status Cloud Identity policy and flags any organizational unit where serviceState is ENABLED.
Current Value
Unreviewed permissions
Recommended Value
early_access_apps serviceState not ENABLED (Early Access applications disabled) in all organizational units.
Remediation Steps
In the Google Admin console, under Apps > Additional Google services > Early Access Apps, turn the service OFF for everyone so users cannot enable pre-release Early Access applications.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-7 SA-22
Unknown ADNET-006 NetBIOS over TCP/IP Configuration Reviewed AD Network & Relay Preconditions Medium FAIL Default (insecure)
Description
NetBIOS-NS is the second leg of name-resolution poisoning attacks after LLMNR. Disabling it at the DHCP/interface level requires Reset Of network configuration that GPO can't fully express; however, the Tcpip\Parameters\Interfaces NetbiosOptions value can be set via DHCP scope option 1 or by direct registry. This check reports whether ANY domain-wide policy artifact addresses it, so the auditor knows whether to investigate at the DHCP or imaging layer.
Current Value
Default (insecure)
Recommended Value
Domain-wide method exists to disable NetBIOS over TCP/IP on workstations (DHCP option 1 = 0x2, group policy preference, or imaging baseline)
Remediation Steps
Disable NetBIOS over TCP/IP fleet-wide. Options: (1) Set DHCP scope option Microsoft Disable Netbios Option (option 1) to 0x2; (2) Group Policy Preferences > Windows Settings > Registry to push NetbiosOptions = 2 to each Tcpip_<Interface> key; (3) Bake it into the workstation imaging baseline. This setting is interface-specific and not directly addressable via standard GPO security settings.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-8
MITRE ATT&CK: T1557.001
CisAd: 6.3.2
Unknown ADNET-008 WPAD Auto-Discovery Disabled AD Network & Relay Preconditions Medium FAIL Default (insecure)
Description
Web Proxy Auto-Discovery resolves the name 'wpad' via DNS, NetBIOS, or LLMNR and trusts whatever proxy configuration comes back. An attacker can poison any of those resolutions and proxy the victim's web traffic. Even with LLMNR and NetBIOS disabled, the WinHttpAutoProxySvc can still attempt WPAD, so a defense-in-depth GPO that disables WPAD outright is recommended.
Current Value
Default (insecure)
Recommended Value
GPO disables WPAD via 'Turn off auto-proxy result caching' or by setting WinHttpAutoProxySvc start type to 4 (disabled), or DNS server has a wpad GlobalQueryBlockList entry
Remediation Steps
Three complementary controls: (1) Add 'wpad' to the DNS server's GlobalQueryBlockList: dnscmd /Config /GlobalQueryBlockList wpad isatap; (2) Disable the WinHttpAutoProxySvc via GPO Services policy; (3) GPO Internet Explorer / Edge: 'Disable changing Automatic Configuration settings' and ensure no PAC URL is auto-configured. (1) is the single most impactful fix.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-8
MITRE ATT&CK: T1557.001 T1557.003
CisAd: 6.3.4
Unknown ADPRIV-007 Print Operators Enumeration AD Privileged Account Security Medium FAIL Default (insecure)
Description
Print Operators can manage printers and load printer drivers on domain controllers. Malicious printer drivers can execute arbitrary code as SYSTEM on DCs, providing a path to full domain compromise
Current Value
Default (insecure)
Recommended Value
Empty. Manage printers using dedicated print servers, not domain controllers
Remediation Steps
Enumerate Print Operators membership using Get-ADGroupMember -Identity 'Print Operators'. Remove all members. Deploy print services on dedicated member servers rather than domain controllers. Restrict printer driver installation through Group Policy
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6(1) CM-7
MITRE ATT&CK: T1547.012 T1078.002
Anssi: R3
CisAd: 4.1.7
Unknown ADPRIV-018 Privileged Accounts Never Logged In AD Privileged Account Security Medium FAIL Disabled
Description
Privileged accounts that have never logged in may be provisioned accounts that were never claimed, test accounts, or migration artifacts. These unmanaged accounts in privileged groups represent a significant risk as they may have default or weak passwords
Current Value
Disabled
Recommended Value
No privileged accounts with null LastLogonTimestamp. All privileged accounts actively used by their assigned owners
Remediation Steps
Identify privileged accounts that have never logged in using Get-ADUser -Filter {AdminCount -eq 1} -Properties LastLogonTimestamp | Where-Object {$_.LastLogonTimestamp -eq $null}. Investigate each account to determine if it is needed. Disable or remove unnecessary accounts from privileged groups
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-2(3) AC-2
MITRE ATT&CK: T1078.002
CisAd: 4.6.1
Unknown ADPRIV-021 AdminCount Orphans AD Privileged Account Security Medium FAIL Excessive permissions found
Description
When objects are removed from protected groups, the AdminCount attribute remains set to 1 and inherited permissions remain blocked. These 'AdminCount orphans' have broken permission inheritance, which may prevent security policies from applying correctly and can mask privilege escalation
Current Value
Excessive permissions found
Recommended Value
No accounts with AdminCount=1 that are not members of any protected group
Remediation Steps
Identify orphaned accounts using Get-ADUser -Filter {AdminCount -eq 1} and cross-reference with current protected group membership. For orphans, clear the AdminCount attribute and re-enable inheritance on the object's ACL. Use PowerShell or ADSIEdit to fix inherited permissions
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 AC-3
MITRE ATT&CK: T1078.002
CisAd: 4.7.2
Unknown ADPWD-002 Fine-Grained Password Policy Enumeration AD Password & Lockout Policies Medium FAIL Non-compliant
Description
Fine-grained password policies (FGPPs) allow different password requirements for different groups of users. All FGPPs should be documented to understand the complete password policy landscape and ensure no groups are covered by weaker-than-intended policies
Current Value
Non-compliant
Recommended Value
All FGPPs documented with their precedence, target groups, and policy settings. At minimum, a strict FGPP for privileged accounts and a standard FGPP for regular users
Remediation Steps
Enumerate all FGPPs using Get-ADFineGrainedPasswordPolicy -Filter *. Document each policy's precedence value, target groups, and settings. Verify that privileged accounts are covered by a stricter policy than standard users. Create FGPPs if only the Default Domain Policy exists
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1) AC-2
MITRE ATT&CK: T1110.001
Anssi: R34
CisAd: 5.1.2
Unknown ADPWD-003 FGPP Application Analysis AD Password & Lockout Policies Medium FAIL Unreviewed permissions
Description
Fine-grained password policies must be applied to the correct groups to be effective. Misconfigured FGPP application can leave high-value accounts under weaker policies or create policy gaps where no FGPP applies and the Default Domain Policy is used instead
Current Value
Unreviewed permissions
Recommended Value
All privileged accounts covered by a strict FGPP. No policy gaps where high-value accounts fall back to a weaker default policy
Remediation Steps
For each FGPP, review the msDS-PSOAppliesTo attribute to see target groups. Cross-reference with privileged group membership to verify coverage. Use Get-ADUserResultantPasswordPolicy for specific accounts to determine the effective policy. Fix any gaps in FGPP application
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1) AC-2
MITRE ATT&CK: T1110.001 T1078.002
CisAd: 5.1.3
Unknown ADPWD-007 Password History Enforcement AD Password & Lockout Policies Medium FAIL 0 passwords remembered
Description
Password history prevents users from cycling through the same passwords. Without sufficient history depth, users can alternate between a small set of passwords, negating the security benefit of password rotation requirements
Current Value
0 passwords remembered
Recommended Value
Password history remembering at least 24 previous passwords
Remediation Steps
Configure in Default Domain Policy: Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy > 'Enforce password history' = 24 passwords remembered. Also ensure 'Minimum password age' is set to at least 1 day to prevent rapid cycling through the history
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1110.001
CIS Benchmark: 1.1.1
Anssi: R34
CisAd: 5.2.3
Unknown ADPWD-008 Maximum Password Age AD Password & Lockout Policies Medium FAIL Never expires
Description
Maximum password age forces periodic password rotation. While NIST SP 800-63B recommends against mandatory periodic changes unless compromise is suspected, many compliance frameworks still require it. The policy should balance compliance requirements with usability, avoiding excessively short rotation periods that lead to weak passwords
Current Value
Never expires
Recommended Value
Maximum password age between 90-365 days depending on compliance requirements. For privileged accounts, 60 days maximum
Remediation Steps
Configure in Default Domain Policy: Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy > 'Maximum password age' = 365 days (or per compliance requirement). Implement a stricter FGPP for privileged accounts with 60-day maximum
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1078.002
CIS Benchmark: 1.1.2
Anssi: R34
CisAd: 5.2.4
Unknown ADPWD-013 Custom Dictionary Password Check AD Password & Lockout Policies Medium FAIL Default (insecure)
Description
Passwords based on organization-specific terms (company name, product names, seasons, location names) are commonly used and easily guessed by targeted attackers. Custom dictionary checks identify passwords that meet complexity requirements but are still predictable
Current Value
Default (insecure)
Recommended Value
No accounts using passwords containing organization-specific terms, common patterns (Season+Year), or keyboard walks
Remediation Steps
Build a custom dictionary including company names, product names, location names, seasons, and common patterns. Test password hashes against this dictionary using DSInternals or similar tools. Force password changes on matching accounts. Deploy custom password filters or Azure AD Password Protection custom banned password list
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1110.001 T1110.003
CisAd: 5.5.4
Unknown ADPWD-015 Password Last Set Age Distribution AD Password & Lockout Policies Medium FAIL Never expires
Description
Analyzing the distribution of password ages across all accounts reveals policy enforcement effectiveness and identifies accounts with extremely old passwords. Accounts with passwords unchanged for years may have been missed by policy changes or have Password Never Expires set
Current Value
Never expires
Recommended Value
No enabled user accounts with passwords older than the maximum password age policy. Distribution should show regular rotation patterns
Remediation Steps
Generate a password age distribution report using Get-ADUser -Filter {Enabled -eq $true} -Properties PasswordLastSet | Group-Object {(New-TimeSpan $_.PasswordLastSet (Get-Date)).Days -replace '\d$','0'}. Investigate accounts with passwords older than the policy allows. Force password changes where needed and review Password Never Expires flags
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1078.002
CisAd: 5.6.1
Unknown ADPWD-017 LAPS Password Expiration AD Password & Lockout Policies Medium FAIL Never
Description
LAPS passwords should be rotated regularly to limit the window of exposure if a local admin password is compromised. Expired or stale LAPS passwords indicate that the LAPS client is not functioning correctly on those machines
Current Value
Never
Recommended Value
LAPS password expiration set to 30 days. No computers with expired LAPS passwords
Remediation Steps
Review LAPS password expiration dates on computer objects using Get-ADComputer -Filter * -Properties ms-Mcs-AdmPwdExpirationTime. Identify computers with expired passwords and investigate the LAPS CSE functionality on those machines. Configure GPO to set password age to 30 days maximum
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1078.003
Anssi: R42
CisAd: 5.7.2
Unknown ADPWD-019 Azure AD Password Protection AD Password & Lockout Policies Medium FAIL Default (insecure)
Description
Azure AD Password Protection extends banned password enforcement to on-premises AD by deploying proxy and DC agent components. It blocks passwords matching a global Microsoft-curated banned list and an optional custom banned list, preventing users from choosing passwords known to be weak
Current Value
Default (insecure)
Recommended Value
Azure AD Password Protection deployed in enforced mode with custom banned password list configured
Remediation Steps
Deploy the Azure AD Password Protection proxy service and DC agent on all domain controllers. Configure a custom banned password list in Azure AD including organization-specific terms. Set the mode to Enforced (not Audit). Monitor password change rejections through event logs and Azure AD reporting
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1110.001 T1110.003
CisAd: 5.5.6
Unknown ADPWD-022 Lockout Observation Window AD Password & Lockout Policies Medium FAIL No lockout configured
Description
The lockout observation window defines the time period during which failed logon attempts are counted toward the lockout threshold. If the observation window is too short, attackers can spread password spray attempts over time to avoid triggering lockout
Current Value
No lockout configured
Recommended Value
Observation window of 15-30 minutes, matching or exceeding the lockout duration
Remediation Steps
Configure in Default Domain Policy: Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Account Lockout Policy > 'Reset account lockout counter after' = 15-30 minutes. Ensure this value is equal to or greater than the lockout duration to prevent attackers from waiting out the counter between spray attempts
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-7
MITRE ATT&CK: T1110.001 T1110.003
CIS Benchmark: 1.2.3
Anssi: R35
CisAd: 5.3.3
Unknown ADSCRIPT-009 Malformed Scripts AD Logon Scripts & Network Shares Medium FAIL Default (insecure)
Description
Scripts with syntax errors, encoding issues, or corrupt content may fail silently during execution, resulting in incomplete security configuration or missing drive mappings. Malformed scripts can also indicate tampering where an attacker modified a script but introduced errors, or where encoding issues mask injected malicious content
Current Value
Default (insecure)
Recommended Value
All scripts pass syntax validation with no encoding anomalies or structural errors
Remediation Steps
Validate script syntax using appropriate tools: PowerShell scripts with Test-ScriptFileInfo or PSScriptAnalyzer, batch files with manual review for unclosed blocks and invalid commands, VBScript with WSH syntax checking. Check file encoding for unexpected byte sequences or mixed encoding. Review scripts with unusual encoding (UTF-16 with BOM in batch files, null bytes) for potential injection.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-3 SI-7
MITRE ATT&CK: T1059
Unknown ADSCRIPT-011 Script Content Analysis AD Logon Scripts & Network Shares Medium FAIL Default (insecure)
Description
Comprehensive content analysis of all logon scripts can reveal suspicious patterns beyond specific checks such as obfuscated code, base64-encoded commands, PowerShell download cradles, encoded executables, and anti-analysis techniques. These patterns are strong indicators of malicious script injection or backdoors planted by attackers
Current Value
Default (insecure)
Recommended Value
No obfuscated code, encoded payloads, download cradles, or anti-analysis techniques present in any logon scripts
Remediation Steps
Analyze all scripts for suspicious patterns including base64 encoding (Convert-FromBase64, certutil -decode), download cradles (Invoke-WebRequest, Net.WebClient, BitsTransfer), obfuscation techniques (string concatenation, char codes, variable substitution to hide commands), and anti-analysis techniques (sleep timers, environment checks). Investigate and replace any scripts containing suspicious patterns.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-3 SI-7 CM-3
MITRE ATT&CK: T1059 T1027 T1105
Unknown ADSTALE-001 Inactive User Accounts AD Stale & Obsolete Objects Medium FAIL Multiple found
Description
User accounts that have not been used for an extended period represent an unnecessary attack surface. Inactive accounts may still have valid credentials and group memberships, making them attractive targets for attackers who can compromise forgotten or shared credentials without triggering alerts tied to active users. Accounts inactive for more than 90 days should be reviewed and disabled
Current Value
Multiple found
Recommended Value
No enabled user accounts inactive for more than 90 days; inactive accounts disabled or removed
Remediation Steps
Query user accounts where lastLogonTimestamp is older than 90 days and the account is enabled using Search-ADAccount -AccountInactive -TimeSpan 90 -UsersOnly. Verify with account owners or managers before taking action. Disable inactive accounts first, then delete after a 30-day grace period if unclaimed. Remove disabled accounts from all security groups. Implement automated lifecycle management
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-2(3)
MITRE ATT&CK: T1078.002
CisAd: 9.1.1
Unknown ADSTALE-002 Inactive Computer Accounts AD Stale & Obsolete Objects Medium FAIL Multiple found
Description
Computer accounts that have not authenticated to the domain for an extended period indicate decommissioned, reimaged, or offline systems. These stale computer accounts retain their machine credentials and group memberships, and an attacker who recovers or resets the machine account password can authenticate as the computer, potentially accessing resources or performing Kerberos delegation attacks
Current Value
Multiple found
Recommended Value
No enabled computer accounts inactive for more than 90 days; inactive accounts disabled or removed
Remediation Steps
Query computer accounts where lastLogonTimestamp is older than 90 days using Search-ADAccount -AccountInactive -TimeSpan 90 -ComputersOnly. Cross-reference with asset management systems to verify decommissioning status. Disable stale computer accounts and move to a Disabled Computers OU. Delete after a 60-day grace period if the system does not reconnect. Remove from security groups upon disabling
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-2(3)
MITRE ATT&CK: T1078.002
CisAd: 9.1.2
Unknown ADSTALE-003 Disabled Accounts with Group Memberships AD Stale & Obsolete Objects Medium FAIL Default (insecure)
Description
Disabled user and computer accounts that retain membership in security groups continue to appear in group-based access control evaluations and can create confusion in access reviews. While disabled accounts cannot authenticate, their group memberships may be restored if the account is re-enabled, and the retained memberships inflate group sizes and complicate least-privilege analysis
Current Value
Default (insecure)
Recommended Value
All disabled accounts removed from all security groups except Domain Users
Remediation Steps
Identify disabled accounts with non-default group memberships using Get-ADUser -Filter {Enabled -eq $false} -Properties MemberOf. Remove all security group memberships (except the primary group) from disabled accounts. Implement an automated workflow that strips group memberships when accounts are disabled. Include group membership cleanup in the account deprovisioning process
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-2(3) AC-6
CisAd: 9.2.1
Unknown ADSTALE-004 Expired Passwords Not Disabled AD Stale & Obsolete Objects Medium FAIL Never
Description
Accounts with passwords that have exceeded the maximum password age but remain enabled may indicate accounts that are not being actively managed. These accounts could have been compromised with credentials obtained through historical breaches or credential dumps, and the long-unchanged passwords increase the window for offline brute-force attacks
Current Value
Never
Recommended Value
No accounts with passwords older than the maximum password age policy unless explicitly exempted as documented service accounts
Remediation Steps
Query accounts where PasswordLastSet is older than the maximum password age using Get-ADUser -Filter * -Properties PasswordLastSet,PasswordNeverExpires. Exclude accounts with PasswordNeverExpires that are documented service accounts. Force password reset at next logon for accounts with expired passwords. Disable accounts that are not claimed after notification. Review PasswordNeverExpires exemptions annually
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1078.002
CisAd: 9.2.2
Unknown ADSTALE-007 Orphaned Foreign Security Principals AD Stale & Obsolete Objects Medium FAIL Multiple found
Description
Foreign Security Principals (FSPs) are placeholder objects created in the ForeignSecurityPrincipals container when external domain users or groups are added to local domain groups via trusts. Orphaned FSPs reference SIDs from trusted domains that no longer exist or accounts that have been deleted, resulting in unresolvable SIDs in group memberships that clutter access control and complicate auditing
Current Value
Multiple found
Recommended Value
No orphaned Foreign Security Principals with unresolvable SIDs in the domain
Remediation Steps
Enumerate all objects in CN=ForeignSecurityPrincipals and attempt to resolve each SID to a name using the corresponding trust. Identify FSPs where the SID cannot be resolved (trust removed or account deleted). Remove orphaned FSPs from any group memberships. Delete the orphaned FSP objects. Review remaining FSPs to verify the trust relationship and referenced accounts are still valid
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-2
CisAd: 9.4.1
Unknown ADSTALE-008 Orphaned SID History AD Stale & Obsolete Objects Medium FAIL Multiple found
Description
SID History is used during domain migrations to preserve access to resources in the source domain. After migration is complete, SID History entries should be removed as they can be abused for privilege escalation. Orphaned SID History entries referencing non-existent domains or deleted accounts provide no legitimate benefit and increase the risk of SID injection attacks across trust boundaries
Current Value
Multiple found
Recommended Value
No SID History entries referencing non-existent domains. SID History cleaned after migration completion
Remediation Steps
Query all user and group accounts with SID History using Get-ADUser -Filter {SIDHistory -like '*'} -Properties SIDHistory. Cross-reference each SID History domain component against existing trusts to identify orphaned entries. Remove SID History entries for completed migrations using Remove-ADUser with the -Remove parameter or Netdom trust /CleanupSIDHistory. Monitor for new SID History additions using Event ID 4765
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-2
MITRE ATT&CK: T1134.005
CisAd: 9.4.2
Unknown ADSTALE-011 DNS Record Staleness AD Stale & Obsolete Objects Medium FAIL Multiple found
Description
Stale DNS records in Active Directory-integrated DNS zones point to IP addresses that are no longer assigned to the original hosts. Attackers can claim these abandoned IP addresses and intercept traffic intended for the original hosts, enabling man-in-the-middle attacks, credential harvesting, and service impersonation. DNS scavenging should be enabled to automatically clean up stale records
Current Value
Multiple found
Recommended Value
DNS scavenging enabled with appropriate no-refresh and refresh intervals; no stale DNS records older than 30 days
Remediation Steps
Enable DNS scavenging on the DNS server properties and on each AD-integrated DNS zone. Configure the no-refresh interval to 7 days and the refresh interval to 7 days. Set scavenging period on at least one DNS server. Manually review aged DNS records before the first scavenging run to identify critical static records that need to be excluded. Mark records that should not be scavenged as static
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-2
CisAd: 9.5.3
Unknown ADTRADE-003 Stale BitLocker Recovery Keys AD Adversary Tradecraft Indicators Medium FAIL Multiple found
Description
BitLocker recovery keys are stored in AD as msFVE-RecoveryInformation child objects of the computer that backed them up. When a computer is decommissioned but the AD object is left dangling, the recovery keys remain queryable by anyone with BitLocker recovery rights — typically a wider group than 'Tier-0'. Stale keys mean disposed drives are decryptable if recovered from a refurbisher or trash bin.
Current Value
Multiple found
Recommended Value
All msFVE-RecoveryInformation objects belong to computers active in the last 90 days. No keys orphaned to disabled or recently-modified-then-stale computer accounts.
Remediation Steps
Enumerate recovery information: Get-ADObject -Filter {objectClass -eq 'msFVE-RecoveryInformation'} -Properties whenCreated. For each, walk up to the parent computer object and check its lastLogonTimestamp / Enabled. For computers inactive >90 days: confirm the drive has been wiped or destroyed, then delete the AD computer object (which cascades the recovery info). For computers actively in use but with very old recovery keys: rotate via Backup-BitLockerKeyProtector. Verify that the BitLocker recovery group has tight membership.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6 MP-6
MITRE ATT&CK: T1552
CisAd: 10.3.1
Unknown ADTRUST-002 Trust Direction Analysis AD Trust Relationships Medium FAIL SID filtering disabled
Description
Inbound trusts allow external domain users to authenticate into your domain. Each inbound or bidirectional trust should be reviewed to ensure that the trusted domain maintains adequate security controls. A compromised trusted domain can be used to attack your environment
Current Value
SID filtering disabled
Recommended Value
All trust directions justified and documented. Bidirectional trusts converted to one-way where possible to reduce attack surface
Remediation Steps
Review each trust direction using Get-ADTrust -Filter *. For bidirectional trusts, evaluate whether both directions are required. Convert to one-way trusts where the business need only requires one direction. Document the justification for all inbound trust paths
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-20 AC-4
MITRE ATT&CK: T1482 T1078.002
CisAd: 3.1.2
Unknown ADTRUST-003 Trust Transitivity Analysis AD Trust Relationships Medium FAIL SID filtering disabled
Description
Transitive trusts extend authentication paths beyond direct trust partners, potentially creating unintended access paths through chains of trusted domains. Each transitive trust should be evaluated for the extended attack surface it creates
Current Value
SID filtering disabled
Recommended Value
All transitive trusts documented with full transitivity path analysis. External trusts preferred over forest trusts when transitivity is not required
Remediation Steps
Map all transitive trust paths to identify indirect authentication routes. For forest trusts, understand that all child domains are transitively trusted. Consider using external (non-transitive) trusts when only specific domain access is needed
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-20 AC-4
MITRE ATT&CK: T1482 T1078.002
CisAd: 3.1.3
Unknown ADTRUST-007 Azure AD Hybrid Trust Security AD Trust Relationships Medium FAIL SID filtering disabled
Description
Hybrid identity configurations connecting on-premises AD with Azure AD create additional attack paths. Azure AD Connect, pass-through authentication agents, and federation services can be targeted to pivot between cloud and on-premises environments
Current Value
SID filtering disabled
Recommended Value
Azure AD Connect running latest version on a hardened, dedicated server. PHS preferred over PTA/federation. Seamless SSO disabled if not required. Cloud-only break-glass accounts configured
Remediation Steps
Review Azure AD Connect configuration and ensure it runs on a Tier 0 hardened server. Evaluate switching from federation or PTA to Password Hash Sync (PHS) for reduced attack surface. If using Seamless SSO, ensure the AZUREADSSOACC computer account password is rotated. Verify cloud-only emergency access accounts exist
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-2 AC-20 SC-8
MITRE ATT&CK: T1078.004 T1649
CisAd: 3.3.1
Unknown ADTRUST-008 Foreign Domain Trust Enumeration AD Trust Relationships Medium FAIL SID filtering disabled
Description
Trusts with domains outside the organization extend the security boundary to entities with potentially different security standards. Foreign domain trusts should receive additional scrutiny as the trusting organization cannot control the security posture of the external domain
Current Value
SID filtering disabled
Recommended Value
All foreign domain trusts documented with external security assessment, contractual security requirements, and annual review
Remediation Steps
Identify trusts with domains outside the organization using Get-ADTrust -Filter *. For each external trust, verify that a security agreement is in place, SID filtering is enabled, selective authentication is configured, and the trust is reviewed annually
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-20 CA-3 SA-9
MITRE ATT&CK: T1482 T1078.002
CisAd: 3.1.4
Unknown ADTRUST-009 Orphaned Trust Detection AD Trust Relationships Medium FAIL Multiple found
Description
Orphaned trusts reference domains that no longer exist or are no longer reachable. These stale trust objects may retain credentials and create confusion during security audits. They should be removed to reduce unnecessary attack surface and maintain a clean trust topology
Current Value
Multiple found
Recommended Value
No orphaned or unresolvable trust relationships present
Remediation Steps
Enumerate all trusts and attempt to validate each by resolving the trusted domain name and testing the trust with 'netdom trust /verify'. Remove orphaned trusts where the partner domain no longer exists or is unreachable using 'netdom trust /Remove' or Active Directory Domains and Trusts
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6 AC-20
MITRE ATT&CK: T1482
CisAd: 3.4.1
Unknown AUTH-003 2SV Method Strength Authentication & Access Controls Medium FAIL Default (insecure)
Description
Security keys should be the primary 2SV method. SMS and voice-based 2SV are vulnerable to SIM-swapping and interception attacks
Current Value
Default (insecure)
Recommended Value
Security keys enforced as primary method
Remediation Steps
Admin Console > Security > Authentication > 2-step verification > Set allowed methods to 'Security key only'
Compliance Mappings
NIST SP 800-53: IA-2(1) IA-2(12)
MITRE ATT&CK: T1111 T1078.004
CIS Benchmark: 1.3
Unknown AUTH-005 Password Reuse Restriction Authentication & Access Controls Medium FAIL Default (insecure)
Description
Users should not be able to reuse recent passwords, preventing credential cycling attacks
Current Value
Default (insecure)
Recommended Value
Password reuse not allowed
Remediation Steps
Admin Console > Security > Authentication > Password management > Enable 'Enforce password policy at next sign-in' and restrict reuse
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1110.004
CIS Benchmark: 1.5
Unknown AUTH-006 Session Duration Authentication & Access Controls Medium FAIL Default (insecure)
Description
Web session duration should be limited to reduce the window for session hijacking and unauthorized access from shared devices
Current Value
Default (insecure)
Recommended Value
Session duration of 12 hours or less
Remediation Steps
Admin Console > Security > Google Session Control > Set web session duration
Compliance Mappings
NIST SP 800-53: AC-12 SC-23
MITRE ATT&CK: T1550.004
CIS Benchmark: 1.6
Unknown AUTH-007 SSO Configuration Authentication & Access Controls Medium FAIL Default (insecure)
Description
If SSO is configured, it should use secure protocols and trusted identity providers
Current Value
Default (insecure)
Recommended Value
SAML SSO properly configured with trusted IdP
Remediation Steps
Admin Console > Security > Authentication > SSO with third-party IdP > Verify configuration
Compliance Mappings
NIST SP 800-53: IA-2(6) IA-8
MITRE ATT&CK: T1078.004
CIS Benchmark: 1.7
Unknown AUTH-009 App Passwords Policy Authentication & Access Controls Medium FAIL Non-compliant
Description
App-specific passwords bypass 2SV and should be controlled. If allowed, they should require 2SV enrollment first
Current Value
Non-compliant
Recommended Value
App passwords restricted or disabled
Remediation Steps
Admin Console > Security > Authentication > 2-step verification > Review app password settings
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1078.004
CIS Benchmark: 1.9
Unknown AUTH-011 Login Challenge Settings Authentication & Access Controls Medium FAIL Disabled
Description
Login challenges should be enabled to provide additional verification when suspicious login attempts are detected
Current Value
Disabled
Recommended Value
Login challenges enabled with employee ID or other verification
Remediation Steps
Admin Console > Security > Authentication > Login challenges > Enable
Compliance Mappings
NIST SP 800-53: IA-2(13)
MITRE ATT&CK: T1078.004
CIS Benchmark: 1.11
Unknown AUTH-014 2SV Enrollment Allowed Authentication & Access Controls Medium FAIL Default (insecure)
Description
Users must be allowed to enroll in two-step verification. Disabling 2SV enrollment blocks MFA adoption and leaves accounts protected by passwords alone
Current Value
Default (insecure)
Recommended Value
2SV enrollment allowed in all organizational units
Remediation Steps
Security > Authentication > 2-step verification > Set 'Allow users to turn on 2-Step Verification' to On for all organizational units
Compliance Mappings
NIST SP 800-53: IA-2(1)
MITRE ATT&CK: T1078.004
CIS Benchmark: 1.2
Unknown AUTH-018 Account self-recovery disabled for users and non-super admins (GWS.COMMONCONTROLS.8.2) Authentication & Access Controls Medium FAIL Excessive permissions found
Description
SCuBA GWS.COMMONCONTROLS.8.2 requires that account self-recovery be disabled for users and non-super-admin accounts. Self-service recovery is an account-takeover vector: an attacker who controls a recovery channel can seize the account without the help desk. This check reads the security.user_account_recovery Cloud Identity policy and flags any organizational unit where self-recovery is enabled.
Current Value
Excessive permissions found
Recommended Value
Account self-recovery disabled (enableAccountRecovery = false) for users and non-super admins in all organizational units.
Remediation Steps
In the Google Admin console, under Security > Account recovery, disable self-recovery for users (and non-super admins), so account recovery is handled through an administrator or help-desk process rather than a user-controlled channel.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5 AC-2
Unknown AZIAM-002 Users with Azure IAM roles directly on resources Azure IAM & Resource Security Medium FAIL Permanent assignments found
Description
Direct role assignments to individual users on Azure resources bypass group-based access governance and make permission tracking difficult. This practice increases the risk of orphaned permissions when users change roles or leave the organization. Group-based assignments provide better auditability and lifecycle management.
Current Value
Permanent assignments found
Recommended Value
Assign roles to Azure AD groups rather than directly to individual users
Remediation Steps
Identify all direct user-to-resource role assignments using Azure Resource Graph or the IAM blade. Create appropriate Azure AD security groups for each access pattern and migrate individual assignments to group-based assignments. Remove the direct user assignments after confirming group membership grants equivalent access.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6(1)
CisAzure: 1.23
Unknown AZIAM-003 Resource group permission analysis Azure IAM & Resource Security Medium FAIL Default (insecure)
Description
Resource groups serve as logical containers for Azure resources and their IAM assignments cascade to all contained resources. Misconfigured resource group permissions can inadvertently grant access to sensitive resources such as databases, key vaults, or virtual machines. Analyzing these permissions ensures consistent enforcement of least-privilege principles.
Current Value
Default (insecure)
Recommended Value
Apply least-privilege role assignments at the resource group level with documented justification
Remediation Steps
Enumerate all role assignments at each resource group using Get-AzRoleAssignment and review for excessive permissions such as Owner or Contributor roles granted to broad groups. Downgrade overly permissive roles to more specific built-in roles like Reader or specific resource provider roles. Document the business justification for each resource group role assignment and schedule periodic reviews.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6
Unknown AZIAM-007 Azure Policy compliance status Azure IAM & Resource Security Medium FAIL Non-compliant
Description
Azure Policy enforces organizational standards and assesses compliance at scale across Azure resources. Non-compliant resources indicate configuration drift from security baselines, potentially exposing the environment to risks that governance controls are designed to prevent. Monitoring policy compliance ensures that deployed resources consistently meet security and regulatory requirements.
Current Value
Non-compliant
Recommended Value
All assigned policies should report 95% or higher compliance; non-compliant resources should have documented exceptions
Remediation Steps
Review the Azure Policy compliance dashboard to identify non-compliant resources and prioritize remediation based on policy severity. Use remediation tasks to automatically fix non-compliant resources where supported by the policy effect (DeployIfNotExists, Modify). For resources that cannot be made compliant, create documented policy exemptions with expiration dates and business justification.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6
CisAzure: 2.1
Unknown AZIAM-009 Custom RBAC role definitions Azure IAM & Resource Security Medium FAIL Permanent assignments found
Description
Custom Azure RBAC roles provide tailored permissions beyond what built-in roles offer, but they can inadvertently grant excessive or dangerous action combinations. Poorly scoped custom roles with wildcard permissions or overly broad assignable scopes create privilege escalation paths. Each custom role must be reviewed to ensure it follows least-privilege principles and does not combine sensitive operations.
Current Value
Permanent assignments found
Recommended Value
Minimize custom role definitions; avoid wildcard actions; restrict assignable scopes to specific management groups or subscriptions
Remediation Steps
List all custom RBAC role definitions and review their actions, notActions, dataActions, and assignable scopes for overly permissive configurations. Remove any wildcard permissions (*/*, Microsoft.*/*, etc.) and replace with specific action strings required for the role's function. Document the business justification for each custom role and evaluate whether a built-in role or combination of built-in roles could replace the custom definition.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6
CisAzure: 1.23
Unknown AZIAM-010 Resource locks configuration Azure IAM & Resource Security Medium FAIL Default (insecure)
Description
Azure resource locks prevent accidental deletion or modification of critical resources such as production databases, networking components, and key vaults. Without resource locks, users with sufficient permissions can inadvertently destroy infrastructure, causing service outages and potential data loss. Applying CanNotDelete or ReadOnly locks to critical resources provides an additional safety layer beyond RBAC.
Current Value
Default (insecure)
Recommended Value
Apply CanNotDelete locks on all production resource groups and critical individual resources
Remediation Steps
Identify all production and business-critical resource groups and resources that should be protected from accidental deletion or modification. Apply CanNotDelete locks at the resource group level for production environments and ReadOnly locks for immutable infrastructure components. Document the lock strategy and ensure that operational procedures include lock removal steps when intentional changes are required, with appropriate change management approval.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6
Unknown COLLAB-001 Meet Recording Settings Collaboration & Communication Security Medium FAIL Default (insecure)
Description
Meeting recording settings should be controlled to prevent unauthorized capture of sensitive discussions
Current Value
Default (insecure)
Recommended Value
Recording restricted to meeting organizers or disabled for sensitive OUs
Remediation Steps
Admin Console > Apps > Google Workspace > Google Meet > Meet video settings > Recording > Configure recording permissions
Compliance Mappings
NIST SP 800-53: AC-3 AU-14
MITRE ATT&CK: T1125
CIS Benchmark: 5.1
Unknown COLLAB-002 Meet External Participant Settings Collaboration & Communication Security Medium FAIL Anyone (no restrictions)
Description
External participant access to meetings should be controlled to prevent unauthorized attendance and information disclosure
Current Value
Anyone (no restrictions)
Recommended Value
External participants require approval or knocking to join
Remediation Steps
Admin Console > Apps > Google Workspace > Google Meet > Meet video settings > Participants > Require approval for external participants
Compliance Mappings
NIST SP 800-53: AC-3 AC-17
MITRE ATT&CK: T1040
CIS Benchmark: 5.2
Unknown COLLAB-003 Meet Anonymous Join Settings Collaboration & Communication Security Medium FAIL Unrestricted
Description
Anonymous users (without Google accounts) should not be able to join meetings without explicit host approval
Current Value
Unrestricted
Recommended Value
Anonymous join disabled or requires host approval
Remediation Steps
Admin Console > Apps > Google Workspace > Google Meet > Meet video settings > Participants > Disable anonymous join or require knocking
Compliance Mappings
NIST SP 800-53: AC-3 IA-2
MITRE ATT&CK: T1040
CIS Benchmark: 5.3
Unknown COLLAB-005 Chat History Settings Collaboration & Communication Security Medium FAIL Default (insecure)
Description
Chat history should be enabled and retained for compliance and audit purposes. Disabling history can hide malicious communications
Current Value
Default (insecure)
Recommended Value
Chat history enabled and retained according to retention policy
Remediation Steps
Admin Console > Apps > Google Workspace > Google Chat > Chat settings > History > Enable history and configure retention
Compliance Mappings
NIST SP 800-53: AU-11 AU-3
MITRE ATT&CK: T1070.008
CIS Benchmark: 5.5
Unknown COLLAB-006 Chat Spaces External Access Collaboration & Communication Security Medium FAIL Anyone (no restrictions)
Description
Chat spaces (rooms) that allow external members can expose internal communications and shared files to unauthorized parties
Current Value
Anyone (no restrictions)
Recommended Value
External access to Chat spaces restricted or disabled
Remediation Steps
Admin Console > Apps > Google Workspace > Google Chat > Chat settings > Spaces > Restrict external access to spaces
Compliance Mappings
NIST SP 800-53: AC-3 AC-4
MITRE ATT&CK: T1530 T1213
CIS Benchmark: 5.6
Unknown COLLAB-009 Calendar External Invitations Collaboration & Communication Security Medium FAIL Anyone (no restrictions)
Description
Users should be warned or restricted when sending calendar invitations to external recipients to prevent accidental information disclosure
Current Value
Anyone (no restrictions)
Recommended Value
External invitation warnings enabled
Remediation Steps
Admin Console > Apps > Google Workspace > Calendar > Sharing settings > Enable external invitation warnings
Compliance Mappings
NIST SP 800-53: AC-4 SI-11
MITRE ATT&CK: T1589
CIS Benchmark: 5.9
Unknown COLLAB-012 Meet Host Management Collaboration & Communication Security Medium FAIL Default (insecure)
Description
Host management should be enabled so meeting hosts retain moderation controls such as muting, removing, and locking to prevent meeting hijacking and disruption
Current Value
Default (insecure)
Recommended Value
Host management enabled
Remediation Steps
Apps > Google Workspace > Google Meet > Meet safety settings > Host management > Enable host management controls
Compliance Mappings
NIST SP 800-53: AC-3
MITRE ATT&CK: T1199
CIS Benchmark: 6.2
Unknown DEVICE-007 Chrome Browser Management Device & Endpoint Management Medium FAIL Default (insecure)
Description
Chrome browsers used to access organizational data should be enrolled in Chrome Browser Cloud Management for policy enforcement
Current Value
Default (insecure)
Recommended Value
Chrome browsers enrolled in Cloud Management with policies enforced
Remediation Steps
Admin Console > Devices > Chrome > Settings > Review and configure Chrome browser policies for managed browsers
Compliance Mappings
NIST SP 800-53: CM-6 CM-7
MITRE ATT&CK: T1189 T1185
CIS Benchmark: 6.7
Unknown DEVICE-009 Chrome OS Device Policies Device & Endpoint Management Medium FAIL Not enrolled
Description
Chrome OS devices should have appropriate policies enforced including auto-update, login restrictions, and security settings
Current Value
Not enrolled
Recommended Value
Chrome OS devices managed with enforced policies for updates, login, and security
Remediation Steps
Admin Console > Devices > Chrome > Settings > Device settings > Configure auto-update, login restrictions, and security policies
Compliance Mappings
NIST SP 800-53: CM-6 SI-2
MITRE ATT&CK: T1189
CIS Benchmark: 6.9
Unknown DEVICE-010 Endpoint Verification Settings Device & Endpoint Management Medium FAIL Not enrolled
Description
Endpoint verification provides device trust signals for context-aware access policies and should be enabled
Current Value
Not enrolled
Recommended Value
Endpoint verification enabled for context-aware access
Remediation Steps
Admin Console > Devices > Mobile & endpoints > Settings > General > Enable endpoint verification for context-aware access policies
Compliance Mappings
NIST SP 800-53: AC-19 IA-3
MITRE ATT&CK: T1078.004
CIS Benchmark: 6.10
Unknown DRIVE-004 Shared Drive Creation Restrictions Drive Security & Data Protection Medium FAIL Anyone (no restrictions)
Description
Shared Drive creation should be restricted to prevent uncontrolled proliferation and ensure proper governance of shared data repositories
Current Value
Anyone (no restrictions)
Recommended Value
Shared Drive creation restricted to specific groups or admins
Remediation Steps
Admin Console > Apps > Google Workspace > Drive and Docs > Sharing settings > Shared drive creation > Restrict who can create shared drives
Compliance Mappings
NIST SP 800-53: CM-7 AC-6
MITRE ATT&CK: T1530
CIS Benchmark: 2.4
Unknown DRIVE-005 Shared Drive Member Management Drive Security & Data Protection Medium FAIL Anyone (no restrictions)
Description
Shared Drive member management should be controlled to prevent unauthorized users from being added or permissions being escalated
Current Value
Anyone (no restrictions)
Recommended Value
Only managers can add members and change access levels
Remediation Steps
Admin Console > Apps > Google Workspace > Drive and Docs > Sharing settings > Shared drive settings > Configure member management permissions
Compliance Mappings
NIST SP 800-53: AC-3 AC-6(1)
MITRE ATT&CK: T1098
CIS Benchmark: 2.5
Unknown DRIVE-007 File Ownership Transfer Settings Drive Security & Data Protection Medium FAIL Default (insecure)
Description
File ownership transfer should be controlled to prevent unauthorized data migration and maintain proper data governance chains
Current Value
Default (insecure)
Recommended Value
File ownership transfer restricted to admins or controlled process
Remediation Steps
Admin Console > Apps > Google Workspace > Drive and Docs > Transfer ownership settings > Configure restrictions
Compliance Mappings
NIST SP 800-53: AC-3 MP-5
MITRE ATT&CK: T1537
CIS Benchmark: 2.7
Unknown DRIVE-008 Drive for Desktop Allowed/Blocked Drive Security & Data Protection Medium FAIL Default (insecure)
Description
Drive for Desktop syncs files locally and should be controlled to prevent data from being stored on unmanaged endpoints
Current Value
Default (insecure)
Recommended Value
Drive for Desktop restricted to managed devices or disabled
Remediation Steps
Admin Console > Apps > Google Workspace > Drive and Docs > Features and Applications > Drive for Desktop > Configure access
Compliance Mappings
NIST SP 800-53: SC-28 MP-7
MITRE ATT&CK: T1530 T1005
CIS Benchmark: 2.8
Unknown DRIVE-010 Drive DLP Rules Audit Drive Security & Data Protection Medium FAIL Disabled
Description
Data Loss Prevention rules should be configured to detect and prevent sharing of sensitive data through Google Drive
Current Value
Disabled
Recommended Value
DLP rules configured for sensitive data types (PII, financial, health data)
Remediation Steps
Admin Console > Security > Data protection > Manage rules > Create rules for sensitive data types in Drive
Compliance Mappings
NIST SP 800-53: SC-7 SI-4
MITRE ATT&CK: T1567 T1048
CIS Benchmark: 2.10
Unknown DRIVE-011 Target Audience Settings Drive Security & Data Protection Medium FAIL Default (insecure)
Description
Target audience settings control who can be suggested when sharing files and should be configured to limit accidental sharing
Current Value
Default (insecure)
Recommended Value
Target audiences configured to limit sharing suggestions appropriately
Remediation Steps
Admin Console > Directory > Target audiences > Review and configure target audience groups
Compliance Mappings
NIST SP 800-53: AC-3 AC-6
MITRE ATT&CK: T1530
CIS Benchmark: 2.11
Unknown DRIVE-013 Offline Access Settings Drive Security & Data Protection Medium FAIL Default (insecure)
Description
Offline access allows Drive files to be cached locally on devices and should be controlled to prevent data exposure on shared or unmanaged devices
Current Value
Default (insecure)
Recommended Value
Offline access disabled or restricted to managed devices
Remediation Steps
Admin Console > Apps > Google Workspace > Drive and Docs > Features and Applications > Offline > Disable or restrict offline access
Compliance Mappings
NIST SP 800-53: SC-28 AC-19
MITRE ATT&CK: T1005 T1530
CIS Benchmark: 2.13
Unknown DRIVE-016 Drive file security update enforced (GWS.DRIVEDOCS.3.1) Drive Security & Data Protection Medium FAIL Default (insecure)
Description
SCuBA GWS.DRIVEDOCS.3.1: the file security update tightens link-sharing on affected files; letting users remove it re-opens access. Reads drive_and_docs.file_security_update; warns where users are allowed to remove/manage the security update.
Current Value
Default (insecure)
Recommended Value
Security update applied and users cannot remove it
Remediation Steps
In Drive settings, apply the file security update and do not allow users to remove it from files they own.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-3 CM-6
Unknown DRIVE-017 Default file access set to private to owner (GWS.DRIVEDOCS.1.8) Drive Security & Data Protection Medium FAIL Default (insecure)
Description
SCuBA GWS.DRIVEDOCS.1.8 requires that 'Private to owner' be the default access level for newly created Drive items, so files are not shared more broadly than intended at creation time. This check reads the drive_and_docs.general_access_default Cloud Identity policy and flags any organizational unit where the default file access is not PRIVATE_TO_OWNER.
Current Value
Default (insecure)
Recommended Value
Default access level for new files set to PRIVATE_TO_OWNER (defaultFileAccess) in all organizational units.
Remediation Steps
In the Google Admin console, under Apps > Google Workspace > Drive and Docs > Sharing settings > General access default, set the default to 'Private to owner' so newly created files start private and are shared only by deliberate action.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-3 AC-6
Unknown EIDAPP-008 Credential Expiration Monitoring Entra ID Application & Service Principal Security Medium FAIL Never
Description
Application credentials (client secrets and certificates) that are approaching expiration or have already expired can cause service outages if not rotated in time, or create security risks if expiration policies are set too far in the future. Credentials with long validity periods extend the window during which a compromised credential can be exploited. Proactive monitoring and alerting on credential expiration ensures timely rotation and reduces security exposure.
Current Value
Never
Recommended Value
All application credentials have a maximum validity of 12 months with automated alerts at 30 and 60 days before expiration
Remediation Steps
Enumerate all application credentials and their expiration dates using the Microsoft Graph API. Identify credentials expiring within 30 days and those with validity periods exceeding 12 months. Establish an automated monitoring process that alerts application owners and security teams when credentials approach expiration, and enforce a maximum credential lifetime policy through governance procedures.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1)
Unknown EIDAPP-009 Stale Application Registrations Entra ID Application & Service Principal Security Medium FAIL Multiple found
Description
Application registrations with no recent sign-in activity may be abandoned, orphaned, or no longer needed, yet they retain all granted permissions and credentials. Stale applications expand the attack surface because they are unlikely to be monitored or maintained by their original owners, making them attractive targets for attackers seeking to leverage forgotten credentials or permissions. Regular cleanup of unused applications reduces the tenant's overall risk exposure.
Current Value
Multiple found
Recommended Value
No application registrations without sign-in activity in the last 90 days unless documented with a valid exception
Remediation Steps
Review application sign-in logs in Entra ID to identify applications with no authentication activity in the past 90 days. Contact the listed application owners to confirm whether the application is still required. Disable or delete stale application registrations after confirming they are no longer needed, and remove any associated credentials and permissions.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-2(3)
Unknown EIDAPP-010 Multi-Tenant Application Analysis Entra ID Application & Service Principal Security Medium FAIL Unreviewed permissions
Description
Multi-tenant application registrations are configured to accept sign-ins from any Entra ID tenant, allowing users from external organizations to authenticate. While necessary for SaaS and partner scenarios, multi-tenant configuration on internal applications creates an unnecessary risk by allowing external identities to obtain tokens. Each multi-tenant application should be validated to confirm the configuration is intentional and that appropriate authorization controls are in place.
Current Value
Unreviewed permissions
Recommended Value
No multi-tenant application registrations unless required by business need with documented justification and appropriate authorization controls
Remediation Steps
Review all application registrations and identify those with signInAudience set to AzureADMultipleOrgs or AzureADandPersonalMicrosoftAccount. For each multi-tenant application, validate that multi-tenant access is required and document the business justification. Convert applications that do not require multi-tenant access to single-tenant configuration and implement token validation to restrict which external tenants can access multi-tenant applications.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-20
CisM365: 5.3.2
Unknown EIDAPP-013 Admin Consent Workflow Configuration Entra ID Application & Service Principal Security Medium FAIL Excessive permissions found
Description
The admin consent workflow provides a structured process for users to request administrator approval before applications can access organizational data. Without an admin consent workflow, users whose consent is restricted have no formal mechanism to request application access, leading to shadow IT workarounds or helpdesk bottlenecks. A properly configured workflow ensures legitimate application requests are reviewed and approved by designated administrators.
Current Value
Excessive permissions found
Recommended Value
Admin consent workflow enabled with designated reviewers and defined SLA for review completion
Remediation Steps
Navigate to Entra ID > Enterprise applications > Consent and permissions > Admin consent settings. Enable the admin consent workflow and designate appropriate reviewers from your security or IT administration teams. Configure notification settings to alert reviewers of pending requests and establish a service level agreement for review turnaround to prevent workflow bottlenecks.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-6
CisM365: 5.3.1
Unknown EIDAPP-018 Change Tracking on App Registrations and Service Principals Entra ID Application & Service Principal Security Medium FAIL Unreviewed permissions
Description
Changes to application registrations and service principals such as new credential additions, permission modifications, or configuration changes should be tracked and reviewed. Attackers frequently modify existing applications to add backdoor credentials, escalate permissions, or change redirect URIs as part of persistence and privilege escalation techniques. Without change tracking, these modifications can go undetected indefinitely.
Current Value
Unreviewed permissions
Recommended Value
All changes to application registrations and service principals logged, monitored, and reviewed with alerts for high-risk modifications
Remediation Steps
Configure audit log monitoring to capture all changes to application registrations and service principals including credential additions, permission changes, and configuration modifications. Create alert rules in Microsoft Sentinel or Azure Monitor for high-risk changes such as new credentials added to existing applications, application permission grant changes, and reply URL modifications. Establish a review process for all application changes with designated security reviewers.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-3 SI-4
MITRE ATT&CK: T1098
Unknown EIDAPP-020 Group Owner Consent to Applications Blocked Entra ID Application & Service Principal Security Medium FAIL Unreviewed permissions
Description
When group-specific (group owner) consent is enabled, owners of Microsoft 365 groups and Teams can authorize applications to access data owned by their group without administrator review. Attackers exploit this through illicit consent grant phishing aimed at group and team owners to obtain persistent, scoped access to organizational data. SCuBA requires that group owners not be allowed to consent to applications, forcing all such consent through the admin approval workflow. In Entra ID this is governed by the EnableGroupSpecificConsent setting in the directory (group) settings; it must be false. Note that Microsoft has deprecated the admin-center toggle for this control, but the underlying directory setting remains the authoritative signal.
Current Value
Unreviewed permissions
Recommended Value
EnableGroupSpecificConsent set to false in the directory (group) settings — group owners cannot consent to applications
Remediation Steps
Ensure group owners cannot consent to applications, satisfying SCuBA MS.AAD.5.4. Set the directory (group) setting 'EnableGroupSpecificConsent' to false (Group.Unified settings template). Route all application consent for group-owned data through the admin consent workflow so that a reviewer approves access. Where the legacy admin-center toggle is no longer present, confirm the directory setting value directly via the group settings configuration.
Compliance Mappings
NIST SP 800-53: AC-6 AC-3
MITRE ATT&CK: T1528
CisM365: 5.1.6.1
Unknown EIDAUTH-008 Passwordless Authentication Readiness Entra ID Authentication Methods & MFA Medium FAIL Default (insecure)
Description
Passwordless authentication eliminates passwords as an attack vector, removing the risk of credential theft, phishing, and password spraying. Organizations should assess their readiness to deploy passwordless methods such as FIDO2, Windows Hello for Business, and Microsoft Authenticator phone sign-in. This check evaluates current method adoption and identifies gaps preventing passwordless deployment.
Current Value
Default (insecure)
Recommended Value
Organization has a passwordless deployment plan with at least 50% of users capable of passwordless sign-in
Remediation Steps
Review authentication method registrations to determine how many users have passwordless-capable methods enrolled. Enable FIDO2 and Microsoft Authenticator passwordless sign-in in the authentication methods policy. Create a phased rollout plan starting with privileged users and IT staff before expanding to the broader organization.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-2(6)
Unknown EIDAUTH-009 Windows Hello for Business Configuration Entra ID Authentication Methods & MFA Medium FAIL Default (insecure)
Description
Windows Hello for Business provides phishing-resistant, hardware-backed authentication using biometrics or PIN tied to the device TPM. Misconfigured WHfB deployments may fall back to weaker convenience PIN without proper TPM attestation, reducing security guarantees. The configuration should enforce TPM-backed keys and appropriate biometric policies.
Current Value
Default (insecure)
Recommended Value
Windows Hello for Business enabled with TPM requirement enforced and multi-factor unlock configured for sensitive roles
Remediation Steps
Navigate to Entra ID > Protection > Authentication methods > Windows Hello for Business. Enable the method and configure key restrictions to require TPM-backed keys. Deploy WHfB configuration profiles via Intune to enforce TPM attestation and PIN complexity requirements across managed devices.
Compliance Mappings
NIST SP 800-53: IA-2(6)
CisM365: 5.2.3
Unknown EIDAUTH-010 Temporary Access Pass (TAP) Policy Audit Entra ID Authentication Methods & MFA Medium FAIL Disabled
Description
Temporary Access Pass allows time-limited passcodes for onboarding users to passwordless credentials, but can serve as a backdoor if not properly restricted. TAPs that are configured with long lifetimes or reusable settings can be exploited by attackers who compromise the issuance process. The TAP policy should enforce short lifetimes, single-use restrictions, and limit issuance to authorized administrators.
Current Value
Disabled
Recommended Value
TAP enabled with maximum lifetime of 1 hour, single-use only, restricted to authorized onboarding administrators
Remediation Steps
Review the TAP policy in Entra ID > Protection > Authentication methods > Temporary Access Pass. Set the minimum and maximum lifetime to the shortest practical duration and enable one-time use. Restrict TAP issuance permissions to a limited set of administrators through role-based access controls.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1)
MITRE ATT&CK: T1078
Unknown EIDAUTH-012 SSPR Methods and Requirements Entra ID Authentication Methods & MFA Medium FAIL Default (insecure)
Description
The specific methods allowed for SSPR and the number required directly impact the security of the password reset process. Allowing weak methods such as security questions or requiring only a single method creates opportunities for attackers to reset passwords through social engineering or OSINT. Organizations should require at least two strong methods for all password resets.
Current Value
Default (insecure)
Recommended Value
Two or more strong authentication methods required for password reset, security questions disabled
Remediation Steps
Navigate to Entra ID > Protection > Password reset > Authentication methods. Set the number of methods required to 2 and remove security questions from the allowed methods list. Prioritize mobile app notification and mobile app code as the primary SSPR methods to ensure strong verification.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1)
CisM365: 5.2.4
Unknown EIDAUTH-014 Custom Banned Password List Status Entra ID Authentication Methods & MFA Medium FAIL Default (insecure)
Description
In addition to the global banned password list, organizations should maintain a custom banned password list containing company-specific terms, product names, locations, and other easily guessable variations. Without a custom list, users may choose passwords based on organizational context that attackers can easily guess through targeted attacks. The custom list supports up to 1000 entries and should be regularly updated.
Current Value
Default (insecure)
Recommended Value
Custom banned password list enabled with organization-specific terms including company name, products, locations, and common variations
Remediation Steps
Navigate to Entra ID > Protection > Authentication methods > Password protection. Enable the custom banned password list and add entries for your organization name, product names, office locations, and commonly used internal terms. Review and update the list quarterly to include new terms and patterns identified in password audits.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1)
CisM365: 5.2.5
Unknown EIDAUTH-017 Per-User MFA vs Conditional Access MFA Conflict Detection Entra ID Authentication Methods & MFA Medium FAIL Not enforced
Description
Legacy per-user MFA settings (enabled/enforced at the individual user level) can conflict with Conditional Access-based MFA policies, creating unpredictable authentication behavior. When both are active, users may experience duplicate MFA prompts, authentication failures, or inconsistent policy enforcement depending on which mechanism evaluates first. Organizations should migrate entirely to Conditional Access-based MFA and disable per-user MFA settings to ensure consistent policy application.
Current Value
Not enforced
Recommended Value
Per-user MFA disabled for all users with MFA enforced exclusively through Conditional Access policies
Remediation Steps
Check per-user MFA status via Entra ID > Users > Per-user MFA and identify users with per-user MFA enabled or enforced. Create equivalent Conditional Access policies that enforce MFA for all users before disabling per-user MFA. Disable per-user MFA by setting each user's status to Disabled after confirming Conditional Access MFA coverage is complete.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-2(1)
CisM365: 5.2.2.1
Unknown EIDAUTH-018 Microsoft Authenticator Login Context (Application Name and Location) Entra ID Authentication Methods & MFA Medium FAIL Disabled
Description
When the Microsoft Authenticator authentication method is enabled, displaying login context information (application name and geographic location) in push and passwordless notifications gives the user the situational awareness needed to recognize and reject MFA prompts they did not initiate. Without this context, users are far more likely to approve adversary-initiated push requests during MFA fatigue or real-time phishing attacks. This setting is controlled by the displayAppInformationRequiredState and displayLocationInformationRequiredState feature settings on the MicrosoftAuthenticator method configuration.
Current Value
Disabled
Recommended Value
If Microsoft Authenticator is enabled, displayAppInformationRequiredState is enabled (application name shown); displayLocationInformationRequiredState is also recommended
Remediation Steps
Navigate to Entra ID > Protection > Authentication methods > Policies > Microsoft Authenticator. Under the Configure tab, set 'Show application name in push and passwordless notifications' to Enabled for all users, and enable 'Show geographic location in push and passwordless notifications'. This satisfies SCuBA MS.AAD.3.3, which requires Microsoft Authenticator to be configured to show login context when it is enabled.
Compliance Mappings
NIST SP 800-53: IA-2(1) IA-2(2)
MITRE ATT&CK: T1621
CisM365: 5.2.3.2
Unknown EIDCA-003 CA Policies in Report-Only Mode Entra ID Conditional Access Medium FAIL Vulnerable configuration
Description
Conditional Access policies left in report-only mode do not enforce security controls and only log what would have happened. Policies that have completed testing should be switched to the enabled state to actively protect the environment.
Current Value
Vulnerable configuration
Recommended Value
No policies in report-only mode unless actively being tested with a defined transition timeline
Remediation Steps
Review all Conditional Access policies currently in report-only mode and evaluate their sign-in log impact data. For policies that have been validated and show acceptable impact, change the state from report-only to enabled. Establish a policy lifecycle process that defines maximum report-only durations before enforcement.
Compliance Mappings
CisM365: 5.2.1
Unknown EIDCA-010 Location-Based CA Policies Audit Entra ID Conditional Access Medium FAIL Disabled
Description
Location-based Conditional Access policies restrict access based on IP address ranges, countries, or named locations. Without location controls, attackers can authenticate from any geographic location, making it harder to detect and prevent unauthorized access from suspicious or high-risk regions.
Current Value
Disabled
Recommended Value
Location-based policies configured to block or require additional controls for access from untrusted locations
Remediation Steps
Review existing named locations and ensure trusted corporate IP ranges and countries are accurately defined. Create Conditional Access policies that require MFA or block access from untrusted locations, particularly for privileged accounts and sensitive applications. Regularly update named location definitions as corporate network infrastructure changes.
Compliance Mappings
NIST SP 800-53: AC-2(11) SC-7
Unknown EIDCA-011 Named Locations Configuration Review Entra ID Conditional Access Medium FAIL Default (insecure)
Description
Named locations define trusted and untrusted network boundaries used by Conditional Access policies. Misconfigured named locations can result in overly permissive access from untrusted networks or unnecessarily restricted access from legitimate corporate locations.
Current Value
Default (insecure)
Recommended Value
All named locations accurately reflect current corporate network boundaries with trusted locations marked appropriately
Remediation Steps
Navigate to the Named Locations blade in the Entra admin center and review all configured locations for accuracy. Verify that trusted corporate IP ranges are up to date and that country-based locations align with organizational presence. Remove any stale or unused named locations and ensure trusted location flags are only applied to verified corporate networks.
Compliance Mappings
NIST SP 800-53: AC-2(11)
Unknown EIDCA-014 Session Controls Audit Entra ID Conditional Access Medium FAIL Disabled
Description
Conditional Access session controls govern sign-in frequency and browser session persistence. Without proper session controls, users may remain authenticated indefinitely, increasing the window of opportunity for session hijacking and token theft attacks.
Current Value
Disabled
Recommended Value
Sign-in frequency set to no more than 24 hours for sensitive applications with persistent browser sessions disabled
Remediation Steps
Review Conditional Access policies for session control configurations including sign-in frequency and persistent browser session settings. Configure sign-in frequency to appropriate intervals based on application sensitivity, with shorter intervals for privileged access. Disable persistent browser sessions for sensitive applications to ensure tokens expire and require re-authentication.
Compliance Mappings
NIST SP 800-53: AC-12 SC-10
CisM365: 5.2.2.6
Unknown EIDCA-017 High-Risk User Notification to Administrators Entra ID Conditional Access Medium FAIL Excessive permissions found
Description
Identity Protection can email administrators when users are flagged as high-risk, enabling proactive investigation and containment of likely account compromise as it occurs. SCuBA recommends that such a notification be sent to administrators when high-risk users are detected. The Identity Protection 'Users at risk detected' notification recipient configuration is not exposed through a stable read-only Microsoft Graph endpoint, so an agentless assessment cannot positively confirm it; this check surfaces the requirement honestly and reports whether the supporting risk-detection telemetry is even available in the tenant rather than asserting compliance it cannot verify.
Current Value
Excessive permissions found
Recommended Value
Identity Protection configured to email administrators when high-risk users are detected
Remediation Steps
Configure the high-risk user notification, satisfying SCuBA MS.AAD.2.2. In Entra ID go to Protection > Identity Protection > Notifications and set 'Users at risk detected' alerts to email the appropriate security administrators or a monitored security operations distribution list. This control requires Entra ID P2 (Identity Protection). Because the notification recipient list is not readable agentlessly via Microsoft Graph, verify the setting manually in the portal.
Compliance Mappings
NIST SP 800-53: SI-4 IR-6 AU-6
MITRE ATT&CK: T1078.004
Unknown EIDCA-018 Managed Device Required for MFA Registration Entra ID Conditional Access Medium FAIL Not enforced
Description
Requiring an agency-managed (compliant or Hybrid Entra joined) device for the security-information registration action reduces the risk of an adversary using stolen credentials to enroll their own MFA method and establish persistence. SCuBA recommends that managed devices be required to register MFA. This is implemented as a Conditional Access policy targeting the 'Register security information' user action and requiring a compliant device or Hybrid Entra ID joined device as a grant control. This check inspects enabled Conditional Access policies for that configuration.
Current Value
Not enforced
Recommended Value
An enabled Conditional Access policy targets the security-information registration user action and requires a compliant or Hybrid Entra ID joined device
Remediation Steps
Create a Conditional Access policy to require a managed device for MFA registration, satisfying SCuBA MS.AAD.3.8. Target the user action 'Register security information', scope it to all users (excluding break-glass accounts), and set the grant control to require a compliant device or Hybrid Entra ID joined device. Pilot in report-only mode, ensure a bootstrap path exists for new devices (for example Temporary Access Pass), then enable enforcement.
Compliance Mappings
NIST SP 800-53: IA-2(1) IA-5 AC-19
MITRE ATT&CK: T1556.006
Unknown EIDFED-006 Azure AD Connect Sync Scope Audit Entra ID Federation & Hybrid Identity Medium FAIL Disabled
Description
The synchronization scope in Azure AD Connect determines which on-premises organizational units, groups, and attributes are replicated to Entra ID. An overly broad sync scope may replicate sensitive service accounts, administrative accounts, or security groups that should remain exclusively on-premises. Conversely, an improperly restricted scope may fail to sync accounts that require cloud access, causing authentication failures.
Current Value
Disabled
Recommended Value
Synchronization scope restricted to required organizational units and objects only, with sensitive service accounts and administrative objects excluded
Remediation Steps
Review the Azure AD Connect synchronization scope including OU filtering, group-based filtering, and attribute-level filtering rules. Verify that only OUs containing user accounts that require cloud access are included in the sync scope. Exclude sensitive on-premises service accounts, administrative accounts, and security groups that do not need cloud representation, and document the rationale for each included OU.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-2
Unknown EIDFED-007 Password Hash Sync Enabled Status Entra ID Federation & Hybrid Identity Medium FAIL Disabled
Description
Password Hash Synchronization (PHS) replicates a hash of on-premises password hashes to Entra ID, enabling cloud authentication as a backup when federation or pass-through authentication is unavailable. While PHS provides resilience and enables leaked credential detection through Entra ID Identity Protection, organizations must understand the security implications of storing password derivatives in the cloud. PHS should be evaluated against organizational security requirements and risk tolerance.
Current Value
Disabled
Recommended Value
PHS enabled as a backup authentication method with leaked credential detection active through Entra ID Identity Protection
Remediation Steps
Check the Azure AD Connect configuration to determine if Password Hash Synchronization is enabled. If PHS is disabled, evaluate enabling it as a backup authentication method and to support Entra ID Identity Protection leaked credential detection. If PHS is already enabled, verify that Entra ID Identity Protection is configured to leverage the password hashes for risk-based detection of compromised credentials.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5
Unknown EIDFED-008 Pass-Through Authentication Agent Status Entra ID Federation & Hybrid Identity Medium FAIL Default (insecure)
Description
Pass-Through Authentication (PTA) validates user passwords against on-premises Active Directory in real-time without storing password hashes in the cloud. PTA agents running on on-premises servers must be properly secured, monitored, and kept current, as a compromised PTA agent could be manipulated to accept any password or to intercept credentials during authentication. Agent health, version currency, and server security posture are critical to maintaining authentication integrity.
Current Value
Default (insecure)
Recommended Value
At least 2 PTA agents deployed on hardened servers with current agent versions and health monitoring enabled
Remediation Steps
Review the PTA agent status in Entra ID > Hybrid management > Azure AD Connect > Pass-through authentication. Verify that at least two agents are deployed for redundancy and that all agents show a healthy status with current software versions. Ensure PTA agent servers are treated as Tier 0 assets with restricted administrative access, up-to-date security patches, and comprehensive event log monitoring.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-2
MITRE ATT&CK: T1556
Unknown EIDFED-010 AD FS Extranet Lockout Settings Entra ID Federation & Hybrid Identity Medium FAIL No lockout configured
Description
AD FS extranet lockout protects against brute-force and password spray attacks targeting the AD FS endpoint exposed to the internet. Without proper extranet lockout configuration, attackers can attempt unlimited password guesses against any federated account through the AD FS proxy, potentially compromising accounts with weak or commonly used passwords. The smart lockout feature in AD FS provides protection while minimizing lockout impact on legitimate users.
Current Value
No lockout configured
Recommended Value
Extranet smart lockout enabled with appropriate threshold and observation window configured to prevent brute-force attacks
Remediation Steps
Review the AD FS extranet lockout configuration using Get-AdfsProperties in PowerShell on the AD FS server. Enable extranet smart lockout if not already active and configure an appropriate lockout threshold and observation window based on your organization's authentication patterns. Monitor the AD FS security logs for extranet lockout events and adjust thresholds if legitimate users are being locked out or if brute-force attempts are succeeding.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-7
Unknown EIDFED-011 Hybrid Join Configuration Entra ID Federation & Hybrid Identity Medium FAIL Default (insecure)
Description
Hybrid Azure AD join registers on-premises domain-joined devices with Entra ID, enabling Conditional Access policies that require device compliance or domain join status. Misconfigured hybrid join settings can result in devices failing to register, which prevents users from satisfying device-based Conditional Access requirements, or can allow unauthorized devices to register if the service connection point is not properly secured. The configuration should be validated end-to-end.
Current Value
Default (insecure)
Recommended Value
Hybrid Azure AD join configured and functional with service connection point properly secured and device registration verified for all target OUs
Remediation Steps
Verify the service connection point (SCP) configuration in Active Directory and ensure it points to the correct Entra ID tenant. Check that the hybrid join configuration in Azure AD Connect includes the correct domains and that required enterprise registration endpoints are accessible from client devices. Validate that devices are successfully registering by reviewing the device list in Entra ID and troubleshooting any devices that show a pending state.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-3
Unknown EIDPIM-009 Accounts Never Signed In with Active Privileged Role Entra ID Privileged Identity Management Medium FAIL Excessive permissions found
Description
Accounts that hold privileged role assignments but have never signed in may represent provisioned-but-unclaimed accounts, test accounts, or migration artifacts. These dormant privileged accounts are high-risk targets because they may have default or weak credentials and are unlikely to be monitored by their intended owners. An attacker who discovers and authenticates as one of these accounts gains immediate privileged access
Current Value
Excessive permissions found
Recommended Value
No privileged role assignments on accounts that have never signed in
Remediation Steps
Review all privileged role members and identify accounts with a null or empty lastSignInDateTime. Investigate each account to determine if it is still needed. Remove privileged role assignments from dormant accounts and disable any accounts that have no valid business purpose
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-2(3)
MITRE ATT&CK: T1078.004
Unknown EIDPIM-014 Privileged Role Assignment Notification Settings Entra ID Privileged Identity Management Medium FAIL Excessive permissions found
Description
Notifications should be configured to alert security personnel when privileged roles are activated or permanently assigned. Without proper notification settings, unauthorized privilege escalation or role activation can go undetected, allowing attackers or malicious insiders to operate with elevated permissions without triggering any alerts. Notification settings are a critical detective control that complements preventive PIM configurations
Current Value
Excessive permissions found
Recommended Value
Notifications enabled for all privileged role activations and new permanent assignments, sent to designated security operations contacts
Remediation Steps
Navigate to Entra ID > Roles and administrators > Settings for each privileged role. Under the Notification tab, ensure notifications are enabled for role activation, permanent assignment, and eligible assignment events. Configure notification recipients to include the security operations team distribution list. Verify notifications are being received by performing a test activation
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-5 SI-4
MITRE ATT&CK: T1078.004
Unknown EIDSCA-AF01 EIDSCA AF01: Authentication Method - FIDO2 security key - State EIDSCA Baseline Medium FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AF01): evaluates 'state' on the Fido2 authentication method against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq enabled
Remediation Steps
Configure the Fido2 authentication method so 'state' is set to enabled. (Entra ID security-configuration baseline, control EIDSCA AF01.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AF03 EIDSCA AF03: Authentication Method - FIDO2 security key - Enforce attestation EIDSCA Baseline Medium FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AF03): evaluates 'isAttestationEnforced' on the Fido2 authentication method against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq true
Remediation Steps
Configure the Fido2 authentication method so 'isAttestationEnforced' is set to true. (Entra ID security-configuration baseline, control EIDSCA AF03.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AF04 EIDSCA AF04: Authentication Method - FIDO2 security key - Enforce key restrictions EIDSCA Baseline Medium FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AF04): evaluates 'keyRestrictions.isEnforced' on the Fido2 authentication method against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq true
Remediation Steps
Configure the Fido2 authentication method so 'keyRestrictions.isEnforced' is set to true. (Entra ID security-configuration baseline, control EIDSCA AF04.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AG01 EIDSCA AG01: Authentication Method - General Settings - Manage migration EIDSCA Baseline Medium FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AG01): evaluates 'policyMigrationState' on the Entra ID authentication methods policy against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
in migrationComplete,
Remediation Steps
Configure the Entra ID authentication methods policy so 'policyMigrationState' is set to one of migrationComplete, . (Entra ID security-configuration baseline, control EIDSCA AG01.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AG02 EIDSCA AG02: Authentication Method - General Settings - Report suspicious activity - State EIDSCA Baseline Medium FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AG02): evaluates 'reportSuspiciousActivitySettings.state' on the Entra ID authentication methods policy against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq enabled
Remediation Steps
Configure the Entra ID authentication methods policy so 'reportSuspiciousActivitySettings.state' is set to enabled. (Entra ID security-configuration baseline, control EIDSCA AG02.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AG03 EIDSCA AG03: Authentication Method - General Settings - Report suspicious activity - Included users/groups EIDSCA Baseline Medium FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AG03): evaluates 'reportSuspiciousActivitySettings.includeTarget.id' on the Entra ID authentication methods policy against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq all_users
Remediation Steps
Configure the Entra ID authentication methods policy so 'reportSuspiciousActivitySettings.includeTarget.id' is set to all_users. (Entra ID security-configuration baseline, control EIDSCA AG03.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AM01 EIDSCA AM01: Authentication Method - Microsoft Authenticator - State EIDSCA Baseline Medium FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AM01): evaluates 'state' on the MicrosoftAuthenticator authentication method against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq enabled
Remediation Steps
Configure the MicrosoftAuthenticator authentication method so 'state' is set to enabled. (Entra ID security-configuration baseline, control EIDSCA AM01.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AM02 EIDSCA AM02: Authentication Method - Microsoft Authenticator - Allow use of Microsoft Authenticator OTP EIDSCA Baseline Medium FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AM02): evaluates 'isSoftwareOathEnabled' on the MicrosoftAuthenticator authentication method against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq false
Remediation Steps
Configure the MicrosoftAuthenticator authentication method so 'isSoftwareOathEnabled' is set to false. (Entra ID security-configuration baseline, control EIDSCA AM02.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AM06 EIDSCA AM06: Authentication Method - Microsoft Authenticator - Show application name in push and passwordless notifications EIDSCA Baseline Medium FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AM06): evaluates 'featureSettings.displayAppInformationRequiredState.state' on the MicrosoftAuthenticator authentication method against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq enabled
Remediation Steps
Configure the MicrosoftAuthenticator authentication method so 'featureSettings.displayAppInformationRequiredState.state' is set to enabled. (Entra ID security-configuration baseline, control EIDSCA AM06.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AM07 EIDSCA AM07: Authentication Method - Microsoft Authenticator - Included users/groups to show application name in push and passwordless notifications EIDSCA Baseline Medium FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AM07): evaluates 'featureSettings.displayAppInformationRequiredState.includeTarget.id' on the MicrosoftAuthenticator authentication method against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq all_users
Remediation Steps
Configure the MicrosoftAuthenticator authentication method so 'featureSettings.displayAppInformationRequiredState.includeTarget.id' is set to all_users. (Entra ID security-configuration baseline, control EIDSCA AM07.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AP05 EIDSCA AP05: Default Authorization Settings - Sign-up for email based subscription EIDSCA Baseline Medium FAIL Not required
Description
Entra ID security-configuration control (EIDSCA AP05): evaluates 'allowedToSignUpEmailBasedSubscriptions' on the Entra ID authorization policy against the recommended secure value.
Current Value
Not required
Recommended Value
eq false
Remediation Steps
Configure the Entra ID authorization policy so 'allowedToSignUpEmailBasedSubscriptions' is set to false. (Entra ID security-configuration baseline, control EIDSCA AP05.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AP06 EIDSCA AP06: Default Authorization Settings - User can join the tenant by email validation EIDSCA Baseline Medium FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AP06): evaluates 'allowEmailVerifiedUsersToJoinOrganization' on the Entra ID authorization policy against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq false
Remediation Steps
Configure the Entra ID authorization policy so 'allowEmailVerifiedUsersToJoinOrganization' is set to false. (Entra ID security-configuration baseline, control EIDSCA AP06.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AP10 EIDSCA AP10: Default Authorization Settings - Default User Role Permissions - Allowed to create Apps EIDSCA Baseline Medium FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AP10): evaluates 'defaultUserRolePermissions.allowedToCreateApps' on the Entra ID authorization policy against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq false
Remediation Steps
Configure the Entra ID authorization policy so 'defaultUserRolePermissions.allowedToCreateApps' is set to false. (Entra ID security-configuration baseline, control EIDSCA AP10.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AT02 EIDSCA AT02: Authentication Method - Temporary Access Pass - One-time EIDSCA Baseline Medium FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AT02): evaluates 'isUsableOnce' on the TemporaryAccessPass authentication method against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq true
Remediation Steps
Configure the TemporaryAccessPass authentication method so 'isUsableOnce' is set to true. (Entra ID security-configuration baseline, control EIDSCA AT02.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AV01 EIDSCA AV01: Authentication Method - Voice call - State EIDSCA Baseline Medium FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AV01): evaluates 'state' on the Voice authentication method against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq disabled
Remediation Steps
Configure the Voice authentication method so 'state' is set to disabled. (Entra ID security-configuration baseline, control EIDSCA AV01.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-CP04 EIDSCA CP04: Default Settings - Consent Policy Settings - Users can request admin consent to apps they are unable to consent to EIDSCA Baseline Medium FAIL Excessive permissions found
Description
Entra ID security-configuration control (EIDSCA CP04): evaluates the 'EnableAdminConsentRequests' setting on the Entra ID directory (group) settings against the recommended secure value.
Current Value
Excessive permissions found
Recommended Value
eq true
Remediation Steps
Configure the Entra ID directory (group) settings so the 'EnableAdminConsentRequests' setting is set to true. (Entra ID security-configuration baseline, control EIDSCA CP04.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-CR01 EIDSCA CR01: Consent Framework - Admin Consent Request - Policy to enable or disable admin consent request feature EIDSCA Baseline Medium FAIL Disabled
Description
Entra ID security-configuration control (EIDSCA CR01): evaluates 'isEnabled' on the Entra ID admin consent request policy against the recommended secure value.
Current Value
Disabled
Recommended Value
eq true
Remediation Steps
Configure the Entra ID admin consent request policy so 'isEnabled' is set to true. (Entra ID security-configuration baseline, control EIDSCA CR01.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-PR01 EIDSCA PR01: Default Settings - Password Rule Settings - Password Protection - Mode EIDSCA Baseline Medium FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA PR01): evaluates the 'BannedPasswordCheckOnPremisesMode' setting on the Entra ID directory (group) settings against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq Enforce
Remediation Steps
Configure the Entra ID directory (group) settings so the 'BannedPasswordCheckOnPremisesMode' setting is set to Enforce. (Entra ID security-configuration baseline, control EIDSCA PR01.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-PR02 EIDSCA PR02: Default Settings - Password Rule Settings - Password Protection - Enable password protection on Windows Server Active Directory EIDSCA Baseline Medium FAIL Disabled
Description
Entra ID security-configuration control (EIDSCA PR02): evaluates the 'EnableBannedPasswordCheckOnPremises' setting on the Entra ID directory (group) settings against the recommended secure value.
Current Value
Disabled
Recommended Value
eq True
Remediation Steps
Configure the Entra ID directory (group) settings so the 'EnableBannedPasswordCheckOnPremises' setting is set to True. (Entra ID security-configuration baseline, control EIDSCA PR02.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-PR05 EIDSCA PR05: Default Settings - Password Rule Settings - Smart Lockout - Lockout duration in seconds EIDSCA Baseline Medium FAIL No lockout configured
Description
Entra ID security-configuration control (EIDSCA PR05): evaluates the 'LockoutDurationInSeconds' setting on the Entra ID directory (group) settings against the recommended secure value.
Current Value
No lockout configured
Recommended Value
ge 60
Remediation Steps
Configure the Entra ID directory (group) settings so the 'LockoutDurationInSeconds' setting is at least 60. (Entra ID security-configuration baseline, control EIDSCA PR05.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-ST08 EIDSCA ST08: Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to become Group Owner EIDSCA Baseline Medium FAIL Unrestricted
Description
Entra ID security-configuration control (EIDSCA ST08): evaluates the 'AllowGuestsToBeGroupOwner' setting on the Entra ID directory (group) settings against the recommended secure value.
Current Value
Unrestricted
Recommended Value
eq false
Remediation Steps
Configure the Entra ID directory (group) settings so the 'AllowGuestsToBeGroupOwner' setting is set to false. (Entra ID security-configuration baseline, control EIDSCA ST08.)
Remediation URL
Compliance Mappings
Unknown EIDTNT-004 Guest Invitation Restrictions Entra ID Tenant Configuration Medium FAIL Unrestricted
Description
Guest invitation settings control who can invite external users to the tenant, ranging from allowing any user to invite guests to restricting invitations to administrators only. Permissive invitation settings allow standard users to invite external parties without oversight, potentially introducing unvetted external identities with access to organizational resources. Invitation restrictions should align with the organization's external collaboration governance requirements.
Current Value
Unrestricted
Recommended Value
Guest invitations restricted to users with specific admin roles or guest inviter role, with no self-service guest access enabled
Remediation Steps
Navigate to Entra ID > External Identities > External collaboration settings and review the guest invite settings. Restrict guest invitations to users assigned the Guest Inviter role or specific administrator roles rather than allowing all members to invite. Disable the option for guests to invite other guests to prevent uncontrolled invitation chains and establish an approval workflow for guest invitation requests.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-14
CisM365: 1.3.1
Unknown EIDTNT-013 Notification Settings Audit Entra ID Tenant Configuration Medium FAIL Disabled
Description
Entra ID notification settings control who receives alerts for critical security events such as users at risk, weekly digest reports, and administrative notifications. Misconfigured notification settings may result in security alerts being sent to inactive mailboxes, former employees, or not being sent at all. Proper notification routing ensures that security-relevant events reach the appropriate personnel for timely investigation and response.
Current Value
Disabled
Recommended Value
All security notifications routed to active, monitored mailboxes belonging to current security operations personnel
Remediation Steps
Review notification settings across Entra ID including Identity Protection notification recipients, password reset notification settings, and technical notification contacts. Verify that all notification recipients are current employees with actively monitored mailboxes and update any references to former employees or inactive distribution lists. Configure notifications to be sent to a security operations distribution list rather than individual users to ensure continuity when personnel changes occur.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-5
Unknown EIDTNT-016 Partner Delegated Admin Grant Hygiene (Long-Lived GDAP) Entra ID Tenant Configuration Medium FAIL Excessive permissions found
Description
A GDAP relationship's duration is its auto-extension window: when it lapses it renews itself for that period without any human review. A long auto-extend (beyond a year) is therefore a standing, self-renewing grant of partner administrative access — the opposite of just-in-time — and is exactly the kind of forgotten relationship that outlives the engagement that created it. This check inspects active delegatedAdminRelationships and warns when any relationship auto-extends beyond 365 days; a relationship whose duration cannot be determined is treated conservatively as long-lived rather than assumed fine. It passes only when all active relationships auto-extend within a year. This is a hygiene/governance signal that complements EIDTNT-015 (which grades the privilege the partner holds); here the concern is how long the grant persists unreviewed.
Current Value
Excessive permissions found
Recommended Value
All active GDAP relationships auto-extend within 365 days and are reviewed on each renewal
Remediation Steps
For each active partner delegated admin (GDAP) relationship, set the shortest auto-extension duration that fits the engagement (avoid multi-year standing grants), and schedule a review at each renewal. In the Microsoft 365 admin center under Settings > Partner relationships, confirm each relationship is still required and terminate stale ones. Prefer short, renewable delegations over long-lived auto-extending access so that partner administration is re-authorized deliberately rather than by default.
Compliance Mappings
NIST SP 800-53: AC-2 AC-2(3) PS-7 SA-9
CisM365: 1.1.3
Unknown EMAIL-004 MTA-STS Policy Email Security Medium FAIL Non-compliant
Description
Mail Transfer Agent Strict Transport Security (MTA-STS) prevents TLS downgrade attacks and man-in-the-middle interception of email in transit by requiring authenticated TLS connections
Current Value
Non-compliant
Recommended Value
MTA-STS TXT record published and policy hosted at https://mta-sts.<domain>/.well-known/mta-sts.txt
Remediation Steps
Publish _mta-sts.<domain> TXT record with v=STSv1; id=<unique_id> and host MTA-STS policy file at https://mta-sts.<domain>/.well-known/mta-sts.txt
Compliance Mappings
NIST SP 800-53: SC-8 SC-8(1)
MITRE ATT&CK: T1557 T1040
CIS Benchmark: 2.4
Unknown EMAIL-006 Email Allowlist/Blocklist Review Email Security Medium FAIL Default (insecure)
Description
Email allowlists and blocklists should be reviewed for overly permissive entries. Allowlisted senders bypass spam filtering and can be exploited if misconfigured
Current Value
Default (insecure)
Recommended Value
Minimal allowlist entries with no wildcard domains; blocklist actively maintained
Remediation Steps
Admin Console > Apps > Google Workspace > Gmail > Spam, phishing and malware > Review Email allowlists and Blocked senders lists for overly broad entries
Compliance Mappings
NIST SP 800-53: SI-8 SC-7(5)
MITRE ATT&CK: T1566.001
CIS Benchmark: 2.6
Unknown EMAIL-007 Inbound Gateway Configuration Email Security Medium FAIL Default (insecure)
Description
Inbound email gateways should be properly configured to preserve sender authentication results. Misconfigured gateways can strip SPF/DKIM/DMARC headers or bypass security filtering
Current Value
Default (insecure)
Recommended Value
Inbound gateways configured with correct IP ranges and header preservation
Remediation Steps
Admin Console > Apps > Google Workspace > Gmail > Spam, phishing and malware > Inbound gateway > Verify gateway IPs and that authentication headers are preserved
Compliance Mappings
NIST SP 800-53: SI-8 SC-7
MITRE ATT&CK: T1566.001 T1566.002
CIS Benchmark: 2.7
Unknown EMAIL-008 Email Routing Rules Audit Email Security Medium FAIL Disabled
Description
Email routing rules should be reviewed for suspicious or unauthorized configurations. Malicious routing rules can redirect email to attacker-controlled destinations
Current Value
Disabled
Recommended Value
All routing rules reviewed and documented with business justification
Remediation Steps
Admin Console > Apps > Google Workspace > Gmail > Routing > Review all routing rules, default routing, and recipient maps for unauthorized entries
Compliance Mappings
NIST SP 800-53: SI-4 AU-6
MITRE ATT&CK: T1114.003 T1020
CIS Benchmark: 2.8
Unknown EMAIL-010 Delegate Access Settings Email Security Medium FAIL Default (insecure)
Description
Mail delegation allows users to grant other users read and send access to their mailbox. Excessive delegation can lead to unauthorized access and impersonation
Current Value
Default (insecure)
Recommended Value
Mail delegation restricted and reviewed periodically; no unexpected delegates
Remediation Steps
Admin Console > Apps > Google Workspace > Gmail > End User Access > Review mail delegation settings. Check individual users for unauthorized delegates via Gmail API
Compliance Mappings
NIST SP 800-53: AC-3 AC-6(1)
MITRE ATT&CK: T1098.002 T1114.002
CIS Benchmark: 2.10
Unknown EMAIL-014 External Recipient Warning Email Security Medium FAIL Anyone (no restrictions)
Description
Users should be warned when sending email to recipients outside the organization to prevent accidental data disclosure and social engineering
Current Value
Anyone (no restrictions)
Recommended Value
External recipient warning enabled for all users
Remediation Steps
Admin Console > Apps > Google Workspace > Gmail > End User Access > Enable 'Warn users when they send messages outside the domain'
Compliance Mappings
NIST SP 800-53: AC-4 AT-2
MITRE ATT&CK: T1048 T1567
CIS Benchmark: 2.14
Unknown EMAIL-018 Compliance Rules Audit Email Security Medium FAIL Disabled
Description
Content compliance rules should be reviewed to ensure sensitive data is appropriately handled. Rules can enforce encryption, quarantine, or rejection based on content patterns
Current Value
Disabled
Recommended Value
Content compliance rules configured for sensitive data types with appropriate actions
Remediation Steps
Admin Console > Apps > Google Workspace > Gmail > Compliance > Content compliance > Review existing rules and create rules for sensitive content types (PII, financial data, health records)
Compliance Mappings
NIST SP 800-53: AC-4 SI-4 SC-7
MITRE ATT&CK: T1048 T1567
CIS Benchmark: 2.18
Unknown EMAIL-019 DLP Rules Configuration Email Security Medium FAIL Insecure rules found
Description
Data Loss Prevention (DLP) rules should be configured to detect and prevent sensitive data from leaving the organization via email. DLP provides automated content inspection and policy enforcement
Current Value
Insecure rules found
Recommended Value
DLP rules configured for key data types (credit cards, SSNs, health records) with block or warn action
Remediation Steps
Security > Data protection > Manage rules: create a Gmail DLP rule that detects sensitive content patterns (credit cards, SSNs, health records) and applies a block or warn action
Compliance Mappings
NIST SP 800-53: AC-4 SC-7 SI-4
MITRE ATT&CK: T1048 T1567 T1020
CIS Benchmark: 2.19
Unknown EMAIL-023 Per-user outbound gateways disabled (GWS.GMAIL.12.1) Email Security Medium FAIL Default (insecure)
Description
SCuBA GWS.GMAIL.12.1 requires that per-user outbound gateways be disabled. When enabled, users can route outbound mail through their own external SMTP servers, bypassing the organization's mail security controls and creating a data-exfiltration and spoofing path. This check reads the gmail.per_user_outbound_gateway policy from the Cloud Identity Policy API and flags any organizational unit where external SMTP routing is allowed. When the policy is not returned the result is Not Assessed.
Current Value
Default (insecure)
Recommended Value
Per-user outbound gateways (external SMTP) disabled for all organizational units
Remediation Steps
In the Google Admin console under Apps > Google Workspace > Gmail > Routing, ensure per-user outbound gateways are not permitted so users cannot route mail through external SMTP servers. Keep outbound routing centralized through approved gateways only.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-4 SC-7 SI-8
Unknown EMAIL-024 Gmail Security Sandbox enabled (GWS.GMAIL.16.1) Email Security Medium FAIL Disabled
Description
SCuBA GWS.GMAIL.16.1 recommends enabling the Gmail Security Sandbox, which detonates inbound attachments in a virtual environment to detect zero-day malware that signature scanning misses. This check reads the gmail.security_sandbox policy from the Cloud Identity Policy API and flags organizational units where the sandbox is disabled. The exact policy field is best-effort pending confirmation on a licensed tenant; when the policy is not returned the result is Not Assessed rather than a fabricated verdict.
Current Value
Disabled
Recommended Value
Security Sandbox enabled (virtual attachment detonation) for all organizational units
Remediation Steps
In the Google Admin console under Apps > Google Workspace > Gmail > Safety > Attachments, enable Security Sandbox so inbound attachments are detonated in a virtual environment before delivery. Note Security Sandbox requires the appropriate Google Workspace edition.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-3 SC-44
Unknown EMAIL-025 Gmail mail delegation disabled (GWS.GMAIL.1.1) Email Security Medium FAIL Unconstrained
Description
SCuBA GWS.GMAIL.1.1: mail delegation lets a user grant another account read/send access to their mailbox, a standing data-access path that outlives the delegation's purpose. Reads gmail.mail_delegation; warns where enableMailDelegation is on.
Current Value
Unconstrained
Recommended Value
Mail delegation disabled unless deliberately required
Remediation Steps
In Gmail settings > User settings, disable mail delegation unless a reviewed business need exists.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-3 AC-6
Unknown EMAIL-030 Automatic email forwarding disabled (GWS.GMAIL.11.1) Email Security Medium FAIL Allowed to external
Description
SCuBA GWS.GMAIL.11.1 recommends disabling automatic email forwarding, especially to external domains. Auto-forwarding is a common data-exfiltration channel and a persistence mechanism after account takeover, because it silently copies inbound mail to an attacker-controlled address. This check reads the gmail.auto_forwarding Cloud Identity policy and flags any organizational unit where automatic forwarding is enabled.
Current Value
Allowed to external
Recommended Value
Automatic email forwarding disabled (enableAutoForwarding = false) in all organizational units.
Remediation Steps
In the Google Admin console, under Apps > Google Workspace > Gmail > End User Access, disable 'Allow users to automatically forward incoming email to another address', prioritizing external destinations. Review existing forwarding rules for unexpected external recipients.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-4 SC-7
Unknown EMAIL-031 Enhanced pre-delivery message scanning enabled (GWS.GMAIL.15.1) Email Security Medium FAIL Disabled
Description
SCuBA GWS.GMAIL.15.1 requires enhanced pre-delivery message scanning, which improves detection of suspicious and phishing content before a message reaches the inbox. This check reads the gmail.enhanced_pre_delivery_message_scanning Cloud Identity policy and flags any organizational unit where improved suspicious-content detection is not enabled.
Current Value
Disabled
Recommended Value
Enhanced pre-delivery message scanning enabled (enableImprovedSuspiciousContentDetection = true) in all organizational units.
Remediation Steps
In the Google Admin console, under Apps > Google Workspace > Gmail > Spam, Phishing, and Malware, enable enhanced pre-delivery message scanning so Gmail performs additional analysis of suspicious content before delivery.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-3 SI-8
Unknown GROUP-002 Group owners cannot add external members (GWS.GROUPS.1.2) Collaboration & Communication Security Medium FAIL Anyone (no restrictions)
Description
SCuBA GWS.GROUPS.1.2 requires that group owners not be permitted to add members from outside the organization. External members gain access to everything shared with the group. This check flags organizational units where owners can allow external members (ownersCanAllowExternalMembers is enabled).
Current Value
Anyone (no restrictions)
Recommended Value
Group owners cannot allow external members (ownersCanAllowExternalMembers disabled)
Remediation Steps
In Groups for Business sharing settings, disable the option that lets group owners add members from outside the organization, so external membership requires administrative action.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-2 AC-3 SC-7
Unknown GROUP-003 Groups cannot receive mail from outside the org (GWS.GROUPS.1.3) Collaboration & Communication Security Medium FAIL Default (insecure)
Description
SCuBA GWS.GROUPS.1.3 requires that group owners not be permitted to allow incoming email from outside the organization. Allowing public inbound mail to groups is an inbound phishing and spam vector. This check flags organizational units where owners can allow incoming mail from the public (ownersCanAllowIncomingMailFromPublic is enabled).
Current Value
Default (insecure)
Recommended Value
Group owners cannot allow incoming mail from the public (ownersCanAllowIncomingMailFromPublic disabled)
Remediation Steps
In Groups for Business sharing settings, disable the option that lets group owners accept incoming email from outside the organization, restricting group mail to internal senders unless explicitly configured.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-7 SI-8
Unknown INTUNE-005 Configuration profile assignment analysis Intune / Endpoint Management Medium FAIL Not required
Description
Configuration profiles are only effective when properly assigned to the correct device or user groups. Profiles assigned to overly broad groups may cause conflicts or apply settings to inappropriate devices, while narrowly assigned profiles may leave devices unconfigured. Analyzing assignment coverage ensures that security configurations reach all intended endpoints without conflicts.
Current Value
Not required
Recommended Value
All security-critical profiles assigned to appropriate groups with no unassigned critical profiles and no conflicting assignments
Remediation Steps
Review the assignment status and target groups for each configuration profile, paying attention to profiles with errors or conflicts. Resolve any profile conflicts by adjusting assignments, merging similar profiles, or using filters to target specific device characteristics. Ensure security-critical profiles such as BitLocker, firewall, and antivirus settings are assigned to all applicable devices through comprehensive group membership.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6
Unknown INTUNE-012 Conditional launch settings Intune / Endpoint Management Medium FAIL Default (insecure)
Description
Conditional launch settings within application protection policies define the conditions under which a managed application can be launched, such as minimum OS version, maximum allowed threat level, or jailbreak/root detection. Without these settings, compromised or outdated devices can access corporate data through managed applications even when the device itself is insecure. These controls provide a critical last line of defense for data protection.
Current Value
Default (insecure)
Recommended Value
Block access on jailbroken/rooted devices; require minimum OS version; block access when device threat level is high
Remediation Steps
Review and update the conditional launch settings in each application protection policy to block app access on jailbroken or rooted devices. Configure minimum OS version requirements that align with vendor-supported versions and set maximum device threat level thresholds that integrate with your Mobile Threat Defense solution. Test the conditional launch settings with a pilot group before broad deployment to ensure that legitimate users are not inadvertently blocked.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-19
Unknown INTUNE-013 Device enrollment restrictions Intune / Endpoint Management Medium FAIL Not enrolled
Description
Device enrollment restrictions control which device types, platforms, and OS versions are allowed to enroll in Intune management. Without proper restrictions, users could enroll personal devices running unsupported or vulnerable operating system versions, expanding the attack surface. Enrollment restrictions also prevent unauthorized device types from gaining access to corporate resources through device management.
Current Value
Not enrolled
Recommended Value
Block personally owned devices or limit to specific platforms; enforce minimum OS version requirements; limit per-user device enrollment count
Remediation Steps
Review the device enrollment restrictions in Intune and configure platform-specific restrictions that align with your organization's supported device policy. Set minimum operating system version requirements for each platform and configure the maximum number of devices a single user can enroll to prevent abuse. If corporate-owned device enrollment is preferred, block personally owned device enrollment and direct users to use app protection policies for BYOD scenarios.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-3
Unknown INTUNE-019 Win32 app deployment security review Intune / Endpoint Management Medium FAIL Unreviewed permissions
Description
Win32 application deployments through Intune package and distribute traditional desktop applications to managed devices. Improperly vetted applications may contain vulnerabilities, bundled malware, or excessive system modifications that weaken device security. Reviewing the Win32 app deployment catalog ensures that only approved and secure applications are distributed to the managed device fleet.
Current Value
Unreviewed permissions
Recommended Value
All Win32 apps sourced from trusted vendors with documented approval; install commands reviewed for security implications
Remediation Steps
Review all Win32 applications deployed through Intune and verify that each application is sourced from a trusted vendor and has been approved through your software approval process. Examine the install and uninstall command lines for any suspicious parameters, script execution, or registry modifications that could weaken security. Implement an application review process that evaluates new Win32 app packages for security risks before deployment to production device groups.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-11
Unknown INTUNE-022 OneDrive sync restrictions Intune / Endpoint Management Medium FAIL Default (insecure)
Description
OneDrive sync client settings control how corporate files are synchronized between cloud storage and managed devices, and unrestricted sync can lead to corporate data being stored on unmanaged or non-compliant devices. Without domain restrictions on the sync client, users may sync corporate SharePoint and OneDrive content to personal devices outside of IT control. Proper sync restrictions prevent data leakage through unmanaged file synchronization.
Current Value
Default (insecure)
Recommended Value
OneDrive sync restricted to domain-joined or Intune-managed devices; Known Folder Move enabled for backup; Files On-Demand enabled
Remediation Steps
Configure the OneDrive sync client through Intune to restrict synchronization to devices that are Azure AD joined or Intune managed using the tenant allow list. Enable Known Folder Move to automatically redirect Desktop, Documents, and Pictures to OneDrive for data protection and enable Files On-Demand to minimize local data storage. Block sync of personal OneDrive accounts on corporate devices if permitted by organizational policy to prevent data commingling.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-19
Unknown LOG-003 Activity Rules Coverage Analysis Logging, Alerting & Monitoring Medium FAIL Insecure rules found
Description
Activity rules should provide adequate coverage across security domains including login, Drive, Admin, and email events
Current Value
Insecure rules found
Recommended Value
Activity rules covering login, Drive sharing, admin changes, email forwarding, and OAuth events
Remediation Steps
Admin Console > Security > Alert center > Rules > Review coverage across event categories > Add rules for uncovered security domains
Compliance Mappings
NIST SP 800-53: SI-4(5) AU-6
MITRE ATT&CK: T1562.008
CIS Benchmark: 7.3
Unknown LOG-004 Data Export Settings Logging, Alerting & Monitoring Medium FAIL Default (insecure)
Description
Google Takeout (data export) should be controlled to prevent users from bulk-exporting organizational data outside the domain
Current Value
Default (insecure)
Recommended Value
Google Takeout disabled or restricted for most users
Remediation Steps
Admin Console > Apps > Additional Google services > Google Takeout > Disable or restrict for applicable OUs
Compliance Mappings
NIST SP 800-53: AC-4 MP-5
MITRE ATT&CK: T1567 T1537
CIS Benchmark: 7.4
Unknown LOG-005 Admin Email Alerts Configuration Logging, Alerting & Monitoring Medium FAIL Excessive permissions found
Description
Email alerts should be configured for critical admin actions including super admin changes, security setting modifications, and bulk operations
Current Value
Excessive permissions found
Recommended Value
Email alerts enabled for critical admin actions and security events
Remediation Steps
Admin Console > Security > Alert center > Configure email notification recipients for critical alert types
Compliance Mappings
NIST SP 800-53: SI-4 AU-5
MITRE ATT&CK: T1562.008
CIS Benchmark: 7.5
Unknown M365AUDIT-003 Audit log search capability Unified Audit & Logging Medium FAIL Disabled
Description
The ability to effectively search and analyze audit log data is critical for security investigations, compliance audits, and incident response activities. Without verified search capability and trained personnel, audit log data that exists cannot be leveraged during time-sensitive security incidents. Organizations must ensure that audit log search tools are accessible, functional, and that response procedures include audit log analysis.
Current Value
Disabled
Recommended Value
Audit log search accessible to security team; search queries tested and documented for common investigation scenarios; SIEM integration operational
Remediation Steps
Verify that members of the security operations and incident response teams have the appropriate role assignments (Audit Logs or View-Only Audit Logs role) to search the unified audit log. Create and document standard search queries for common investigation scenarios such as mailbox compromise, unauthorized file access, and administrative privilege escalation. Test the audit log search functionality regularly and validate that SIEM integration is ingesting and indexing audit events correctly for automated detection and correlation.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-6
Unknown M365DEF-002 Alert policy inventory Defender for Office 365 Medium FAIL Non-compliant
Description
Alert policies in Microsoft 365 Defender generate notifications when specific security events or suspicious activities are detected, enabling timely incident response. Without a comprehensive set of alert policies, critical security events such as mass file deletions, impossible travel, or malware campaigns may go unnoticed for extended periods. Reviewing the alert policy inventory ensures that all important threat categories have corresponding detection and notification mechanisms.
Current Value
Non-compliant
Recommended Value
All default alert policies enabled; custom alert policies for organization-specific threats; alert recipients configured for the security team
Remediation Steps
Review all default and custom alert policies in the Microsoft 365 Defender portal and ensure that default security alert policies have not been disabled or modified to reduce their effectiveness. Configure alert notification recipients to include the security operations team and verify that email notifications are being delivered and monitored. Create custom alert policies for organization-specific threat scenarios such as unusual mail flow patterns, bulk permission changes, or access from blocked geographies.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-4 AU-5
Unknown M365DEF-003 Threat intelligence configuration Defender for Office 365 Medium FAIL Disabled
Description
Threat intelligence capabilities in Microsoft Defender for Office 365 provide visibility into the threat landscape targeting your organization, including campaign views, threat analytics, and threat tracker insights. Without utilizing threat intelligence features, security teams lack the context needed to understand whether their organization is being targeted by specific threat actors or attack campaigns. Proper threat intelligence configuration enables proactive defense and informed security decision-making.
Current Value
Disabled
Recommended Value
Threat Explorer and real-time detections actively monitored; threat trackers configured for priority threats; automated investigation and response enabled
Remediation Steps
Ensure that security analysts have access to Threat Explorer or real-time detections views and are trained to use them for investigating email-based threats and campaigns. Configure threat trackers to monitor for specific threat categories relevant to your industry and organization profile. Enable automated investigation and response (AIR) capabilities to automatically investigate and remediate detected threats, reducing the time between detection and response for common threat patterns.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-5
Unknown M365EXO-008 Transport rules inventory and analysis Exchange Online Security Medium FAIL Insecure rules found
Description
Exchange Online transport rules (mail flow rules) process email messages in transit and can modify headers, redirect messages, add disclaimers, or bypass security controls. Malicious or misconfigured transport rules can silently redirect email, strip security headers, or bypass spam filtering for specific senders. A comprehensive audit of all transport rules is necessary to identify rules that may weaken security or facilitate data exfiltration.
Current Value
Insecure rules found
Recommended Value
All transport rules documented with business justification; no rules bypassing spam filtering or security controls without explicit approval
Remediation Steps
Export and review all Exchange Online transport rules, paying particular attention to rules that bypass spam filtering, redirect email to external addresses, or modify message headers. Remove or disable any rules that lack a documented business justification or that were created by accounts that have since been compromised or deprovisioned. Implement a change management process for transport rule creation and modification, and set up audit log alerts for transport rule changes.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-4
Unknown M365EXO-010 External sender warnings Exchange Online Security Medium FAIL Anyone (no restrictions)
Description
External sender identification helps users recognize when an email originates from outside the organization, reducing the effectiveness of impersonation and social engineering attacks. Without visible external sender indicators, users may not distinguish between internal colleagues and external senders spoofing internal display names. Configuring external sender tags or mail tips provides a visual cue that prompts users to exercise additional caution.
Current Value
Anyone (no restrictions)
Recommended Value
External sender tag or mail tip enabled to visually identify emails from external senders
Remediation Steps
Enable the external sender identification feature in the Exchange Online anti-phishing policy to display a visual indicator on emails from external senders. Consider implementing a transport rule that prepends '[External]' to the subject line of inbound emails from outside the organization as an additional visual warning. Communicate the change to end users and provide guidance on how to identify and respond to suspicious external emails.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-8
CisM365: 2.1.7
Unknown M365EXO-014 Approved sending IP list maintained (MS.EXO.2.1) Exchange Online Security Medium FAIL Unreviewed permissions
Description
SCuBA MS.EXO.2.1 requires that a list of approved IP addresses for sending mail be maintained, which forms the basis of an accurate SPF record. The approved sender list is the authoritative input that determines which hosts may legitimately send mail for each domain. Without a maintained list, an SPF policy cannot be scoped correctly and either fails to block spoofers or blocks legitimate senders.
Current Value
Unreviewed permissions
Recommended Value
A documented, current list of all approved sending sources per domain (Exchange Online include plus any third-party senders), reflected in the published SPF record
Remediation Steps
Inventory every system that legitimately sends email on behalf of each accepted domain, including Exchange Online (spf.protection.outlook.com), marketing platforms, ticketing systems, and on-premises relays. Record this approved sender list as the source of truth and ensure the published SPF record references exactly those sources. Review the list whenever a new sending service is onboarded or retired so the SPF record stays accurate.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-8
MITRE ATT&CK: T1566.001
Unknown M365EXO-019 DMARC aggregate report contact configured (MS.EXO.4.3) Exchange Online Security Medium FAIL Not configured
Description
SCuBA MS.EXO.4.3 requires that the DMARC aggregate report contact (RUA) include reports@dmarc.cyber.dhs.gov for federal executive-branch agencies, and more generally that an aggregate report destination be configured. Aggregate reports give domain owners visibility into who is sending mail as their domain, which is essential for safely advancing to p=reject and detecting spoofing campaigns.
Current Value
Not configured
Recommended Value
DMARC record includes an rua= aggregate report destination; federal executive-branch agencies include reports@dmarc.cyber.dhs.gov
Remediation Steps
Add an rua= tag to each DMARC record pointing to a monitored mailbox or report-processing service so aggregate reports are collected and reviewed. Federal executive-branch departments and agencies must include reports@dmarc.cyber.dhs.gov in the RUA field per BOD 18-01. Ensure the receiving mailbox or service is actively monitored so spoofing trends are acted upon.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-8 AU-6
MITRE ATT&CK: T1566.001
Unknown M365EXO-021 Contact folder sharing not open to all domains (MS.EXO.6.1) Exchange Online Security Medium FAIL Anyone (no restrictions)
Description
SCuBA MS.EXO.6.1 requires that contact folders not be shared with all domains. Exchange Online sharing policies can relax the default restriction on outbound contact sharing. A policy that shares contacts with all domains (a '*' domain entry) exposes directory and contact data broadly, creating a data exfiltration avenue and aiding reconnaissance for social engineering.
Current Value
Anyone (no restrictions)
Recommended Value
No sharing policy rule grants contact sharing to the wildcard domain (*); sharing limited to specific approved domains only
Remediation Steps
Review every Exchange Online sharing policy and remove any rule that shares contact folders with the wildcard domain (*). Where external contact sharing is genuinely required, scope it to specific named partner domains rather than all domains. Validate that the default sharing policy does not silently re-enable all-domain contact sharing.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-4 AC-21
MITRE ATT&CK: T1087
Unknown M365EXO-022 Calendar detail sharing not open to all domains (MS.EXO.6.2) Exchange Online Security Medium FAIL Anyone (no restrictions)
Description
SCuBA MS.EXO.6.2 requires that calendar details not be shared with all domains. Sharing policies can permit external calendar detail sharing; a rule covering the wildcard domain (*) exposes meeting subjects, locations, and attendee information to any external party. This leaks organizational activity that supports targeted phishing and physical reconnaissance.
Current Value
Anyone (no restrictions)
Recommended Value
No sharing policy rule grants calendar detail sharing (CalendarSharing*) to the wildcard domain (*); sharing limited to specific approved domains, ideally free/busy only
Remediation Steps
Review every Exchange Online sharing policy and remove any rule that shares calendar details with the wildcard domain (*). If external calendar sharing is required, restrict it to specific named domains and prefer free/busy-only levels over full detail. Confirm the default sharing policy does not expose calendar details to all domains.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-4 AC-21
MITRE ATT&CK: T1087
Unknown M365EXO-023 External sender warning implemented (MS.EXO.7.1) Exchange Online Security Medium FAIL Anyone (no restrictions)
Description
SCuBA MS.EXO.7.1 requires that external sender warnings be implemented. Marking mail that originates outside the organization helps users recognize impersonation and social engineering attempts. This can be delivered via the native external sender tag (Set-ExternalInOutlook) or a mail flow rule that prepends an indicator such as [External] to the subject of inbound external mail.
Current Value
Anyone (no restrictions)
Recommended Value
Native external sender identification enabled (Get-ExternalInOutlook Enabled = True) or a mail flow rule that prepends an external marker to inbound external mail
Remediation Steps
Enable the native external sender identification feature so Outlook displays an External tag on mail from outside the organization. Alternatively, or in addition, create an enabled mail flow rule that prepends a marker such as [External] to the subject of mail received from outside the organization. Communicate the change to users so they understand what the indicator means.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-8
MITRE ATT&CK: T1566
Unknown M365EXO-027 Attachment filter assesses true file type (MS.EXO.9.2) Exchange Online Security Medium FAIL Default (insecure)
Description
SCuBA MS.EXO.9.2 recommends that the attachment filter attempt to determine the true file type and assess the file extension. Attackers rename files to disguise dangerous types (for example, renaming an executable to a .txt). True-type detection catches mismatches where the extension does not match the actual file content, closing a common evasion technique.
Current Value
Default (insecure)
Recommended Value
Attachment filtering configured to inspect true file type rather than relying on the file extension alone
Remediation Steps
Ensure the attachment filtering solution inspects the actual file content to determine the true type rather than trusting the file extension. In the native solution this is provided by the common attachment filter's type detection; verify it is enabled. For third-party gateways, confirm true-type or content-based inspection is configured so renamed dangerous files are still caught.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-3
MITRE ATT&CK: T1036.008
Unknown M365EXO-033 User safety tips/warnings displayed (MS.EXO.11.2) Exchange Online Security Medium FAIL Default (insecure)
Description
SCuBA MS.EXO.11.2 recommends that user warnings comparable to EOP safety tips be displayed. Safety tips surface automated signals (unusual characters in the FROM address, first-contact senders) directly in the client, prompting caution at the moment of risk. This offloads detection work from users and reduces successful phishing.
Current Value
Default (insecure)
Recommended Value
Anti-phish policy with first-contact safety tips and spoof/impersonation safety tips enabled
Remediation Steps
Enable the safety tip options in the anti-phish policy, including first-contact safety tips and spoof and impersonation safety tips, so users receive in-client warnings. Apply the policy to all users. Where a comparable third-party solution is used, confirm it presents equivalent recipient-facing warnings.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-8
MITRE ATT&CK: T1566
Unknown M365EXO-034 AI-based phishing detection in use (MS.EXO.11.3) Exchange Online Security Medium FAIL Default (insecure)
Description
SCuBA MS.EXO.11.3 recommends an AI-based phishing detection tool comparable to EOP Mailbox Intelligence. Mailbox intelligence builds a model of a user's normal correspondents to detect anomalous senders that rule-based filters miss. Without an AI-based layer, novel or highly targeted phishing is more likely to evade detection.
Current Value
Default (insecure)
Recommended Value
Anti-phish policy with mailbox intelligence enabled (EnableMailboxIntelligence = True) and protection action configured
Remediation Steps
Enable mailbox intelligence in the anti-phish policy and configure the mailbox intelligence protection action to handle detected impersonations. Apply the policy to all users. Mailbox intelligence requires a Defender for Office 365 plan; where unavailable, evaluate a comparable AI-based third-party phishing detection capability.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-8
MITRE ATT&CK: T1566
Unknown M365EXO-036 Connection filter safe list disabled (MS.EXO.12.2) Exchange Online Security Medium FAIL Default (insecure)
Description
SCuBA MS.EXO.12.2 recommends that safe lists not be enabled. The connection filter safe list is a dynamic, third-party-sourced list of 'known good' senders whose mail bypasses spam filtering and sender authentication. Because the list is externally curated, enabling it cedes a security bypass decision to a source the organization does not control.
Current Value
Default (insecure)
Recommended Value
Connection filter policy EnableSafeList set to False for all policies
Remediation Steps
Edit the connection filter policy and ensure the safe list option is turned off (EnableSafeList = False) so externally sourced 'known good' senders do not bypass spam and authentication checks. Verify the setting on the default and any custom connection filter policies. A connection filter IP block list may still be used to block known malicious senders.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-7 SI-8
MITRE ATT&CK: T1566.001
CisM365: 2.1.13
Unknown M365EXO-039 Spam routed to junk or quarantine (MS.EXO.14.2) Exchange Online Security Medium FAIL Default (insecure)
Description
SCuBA MS.EXO.14.2 requires that spam and high confidence spam be moved to either the junk email folder or quarantine. Delivering spam to the inbox defeats the purpose of filtering and increases exposure to malicious content. The anti-spam policy actions must route detected spam away from the inbox while preserving user review of false positives.
Current Value
Default (insecure)
Recommended Value
SpamAction and HighConfidenceSpamAction set to MoveToJmf (junk) or Quarantine; never set to deliver to inbox
Remediation Steps
Configure the anti-spam policy so the spam and high confidence spam actions move messages to the junk email folder or quarantine rather than delivering them to the inbox. Verify neither action is set to add a header and deliver. Confirm the policy applies to all recipients so spam routing is consistent.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-8
MITRE ATT&CK: T1566
Unknown M365EXO-040 No allowed domains in anti-spam policy (MS.EXO.14.3) Exchange Online Security Medium FAIL Non-compliant
Description
SCuBA MS.EXO.14.3 requires that allowed domains not be added to inbound anti-spam policies. Allowing an entire domain lets every sender at that domain bypass spam protections, and common domains can be spoofed to abuse the exception. Allowed individual senders are acceptable, but domain-wide allow entries create a broad bypass.
Current Value
Non-compliant
Recommended Value
AllowedSenderDomains empty on all anti-spam (hosted content filter) policies
Remediation Steps
Review every anti-spam policy and remove all entries from the allowed sender domains list. Where false positives must be addressed, add specific allowed senders rather than whole domains. Confirm no custom anti-spam policy reintroduces an allowed-domain entry, especially for common domains.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-8
MITRE ATT&CK: T1566
Unknown M365EXO-043 User click tracking enabled (MS.EXO.15.3) Exchange Online Security Medium FAIL Disabled
Description
SCuBA MS.EXO.15.3 recommends that user click tracking be enabled. Click tracking records when users click links in mail, providing after-the-fact visibility into whether a malicious link may have been visited. This is essential for scoping and responding to incidents involving phishing links.
Current Value
Disabled
Recommended Value
Safe Links (or comparable) policy with click tracking enabled (DoNotTrackUserClicks = False)
Remediation Steps
Ensure user click tracking is enabled in the Safe Links or comparable policy so that clicks on links in mail are recorded (the do-not-track option should be off). Apply the policy to all users. Confirm click telemetry is available in the relevant reporting surface for incident investigation.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-2 SI-4
MITRE ATT&CK: T1566.002
Unknown M365EXO-045 Alerts routed to monitored destination (MS.EXO.16.2) Exchange Online Security Medium FAIL Default (insecure)
Description
SCuBA MS.EXO.16.2 recommends that alerts be sent to a monitored address or incorporated into a SIEM. An alert that fires but is delivered nowhere monitored is not actionable, allowing suspicious events to go unaddressed and increasing incident impact. Each required alert policy should notify a monitored recipient or feed a SIEM.
Current Value
Default (insecure)
Recommended Value
Each enabled alert policy has notification recipients set to a monitored mailbox or is ingested by a SIEM
Remediation Steps
Configure each enabled alert policy with one or more notification recipients that point to a monitored mailbox or distribution list, or forward alerts into a SIEM. Confirm the destination is actively monitored so alerts are triaged promptly. Where a third-party alerting solution is used, verify its alerts reach the same monitored destination or SIEM.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-4 IR-4 AU-6
MITRE ATT&CK: T1114.003
Unknown M365EXO-047 Purview Audit (Premium) logging enabled (MS.EXO.17.2) Exchange Online Security Medium FAIL Disabled
Description
SCuBA MS.EXO.17.2 requires that Microsoft Purview Audit (Premium) logging be enabled. Premium auditing adds high-value event types (such as MailItemsAccessed) and longer default retention that Standard does not include, materially improving visibility during an investigation. Premium auditing requires E5/G5 or equivalent add-on licensing.
Current Value
Disabled
Recommended Value
Premium audit event types (e.g., MailItemsAccessed) and audit retention features enabled, subject to E5/G5 or add-on licensing
Remediation Steps
Enable Microsoft Purview Audit (Premium) features so additional event types such as MailItemsAccessed are captured. Confirm the tenant carries the required E5/G5 licensing or compliance add-on; where not licensed, this control cannot be met and should be tracked as not assessed rather than passed. Validate that high-value audit events are being recorded after enabling.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-2 AU-3 AU-12
MITRE ATT&CK: T1114
Unknown M365EXO-048 Audit log retention meets minimum (MS.EXO.17.3) Exchange Online Security Medium FAIL Disabled
Description
SCuBA MS.EXO.17.3 requires that audit logs be retained for at least the minimum duration dictated by OMB M-21-31 (Appendix C), which calls for at least twelve months in active storage. Default retention may be shorter than required, and logs unavailable when needed prevent investigation of older incidents. An explicit audit log retention policy enforces the required duration.
Current Value
Disabled
Recommended Value
An audit log retention policy retaining unified audit logs for at least 12 months in active storage (per OMB M-21-31 Appendix C)
Remediation Steps
Create an audit log retention policy that retains unified audit logs for at least twelve months in active storage as required by OMB M-21-31 Appendix C, with additional cold storage retention as applicable. Confirm the tenant licensing supports custom audit retention (E5/G5 or add-on); where not licensed, track this as not assessed rather than passed. Validate the policy scope covers the relevant Exchange and unified audit log record types.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-11
MITRE ATT&CK: T1070
Unknown M365EXO-049 Executable attachment types blocked (MS.EXO.9.5) Exchange Online Security Medium FAIL Default (insecure)
Description
SCuBA MS.EXO.9.5 requires that click-to-run executable file types (for example .exe, .cmd, and .vbe) be blocked at the mail gateway. Microsoft Defender for Office 365 enforces this through the Common Attachment Filter on the anti-malware policy, which rejects messages carrying the listed file types outright regardless of content scanning. Executable attachments are a primary malware-delivery vector; blocking the high-risk types by extension stops the most common payloads before any detonation is required. This check inspects every anti-malware policy and confirms the Common Attachment Filter is enabled and covers at minimum .exe, .cmd, and .vbe.
Current Value
Default (insecure)
Recommended Value
Common Attachment Filter enabled on all anti-malware policies, blocking at minimum .exe, .cmd, and .vbe
Remediation Steps
In the Microsoft Defender portal under Email & collaboration > Policies & rules > Threat policies > Anti-malware, enable the Common Attachment Filter on each policy and ensure the blocked file-type list includes the click-to-run executables (.exe, .cmd, .vbe and related types). Prefer the Standard or Strict preset security policies, which enable this by default. Confirm the policy applies to all recipients.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-3 SC-7
Unknown M365SPO-002 Guest access expiration SharePoint & OneDrive Security Medium FAIL Never
Description
Guest access to SharePoint and OneDrive content without an expiration policy leads to perpetual external access that is rarely reviewed or revoked. Former partners, vendors, and collaborators may retain access to sensitive corporate content long after the business relationship has ended. Configuring automatic guest access expiration ensures that external sharing is time-limited and requires periodic re-authorization.
Current Value
Never
Recommended Value
Guest access expiration set to 30-90 days; sharing links expire within 30 days
Remediation Steps
Configure the guest access expiration policy in the SharePoint admin center to automatically expire guest permissions after 30 to 90 days based on organizational data sensitivity requirements. Set sharing link expiration to a maximum of 30 days for external sharing links to prevent long-lived access tokens. Implement a recurring guest access review process to audit active external sharing and remove access that is no longer needed.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-2(3)
CisM365: 7.2.3
Unknown M365SPO-003 Default sharing link type SharePoint & OneDrive Security Medium FAIL Anyone (no restrictions)
Description
The default sharing link type determines the initial permission level when users create sharing links, and a permissive default increases the likelihood of accidental oversharing. If the default is set to 'Anyone' or 'Organization-wide,' users may inadvertently share sensitive documents with a broader audience than intended. Setting the default to 'Specific people' ensures users make a conscious choice about who receives access to shared content.
Current Value
Anyone (no restrictions)
Recommended Value
Default sharing link type set to 'Specific people' with 'View' permission level
Remediation Steps
Set the default sharing link type to 'Specific people' in the SharePoint admin center to require users to explicitly specify recipients when sharing. Configure the default link permission to 'View' rather than 'Edit' to enforce a least-privilege approach to shared content. Educate users on the differences between sharing link types and the importance of selecting the most restrictive link type appropriate for their sharing scenario.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-3
CisM365: 7.2.2
Unknown M365SPO-004 Site creation restrictions SharePoint & OneDrive Security Medium FAIL Default (insecure)
Description
Unrestricted site creation in SharePoint Online allows any user to create new sites, teams, and associated resources without governance oversight. Uncontrolled site proliferation leads to inconsistent security settings, ungoverned data repositories, and difficulty enforcing classification and retention policies. Restricting site creation to authorized personnel or requiring an approval workflow ensures proper governance from the point of creation.
Current Value
Default (insecure)
Recommended Value
Site creation restricted to authorized administrators or governed through an approval process; Microsoft 365 group creation restricted
Remediation Steps
Restrict self-service site creation in the SharePoint admin center by disabling the ability for users to create new sites directly. Implement a site provisioning request process that routes creation requests through an approval workflow ensuring appropriate classification, sharing settings, and ownership are established. If self-service creation must be allowed, configure default sensitivity labels and sharing policies that are automatically applied to newly created sites.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6
CisM365: 7.2.4
Unknown M365TEAMS-003 External meeting participant settings Microsoft Teams Security Medium FAIL Anyone (no restrictions)
Description
External meeting participant settings control what capabilities external users have when joining Teams meetings hosted by your organization. Allowing external participants to have presenter roles, bypass the lobby, or share screens without restriction can lead to meeting hijacking, unauthorized content sharing, and sensitive information exposure. Restricting external participant capabilities reduces the risk of meeting disruption and data leakage.
Current Value
Anyone (no restrictions)
Recommended Value
External participants default to attendee role; lobby bypass disabled for external users; screen sharing restricted to organizer and presenters only
Remediation Steps
Configure the global meeting policy to require external participants to wait in the lobby and default to the attendee role when admitted to meetings. Restrict screen sharing and content sharing to meeting organizers and designated presenters to prevent unauthorized content sharing by external attendees. Create specific meeting policies for different user groups if some departments require more permissive settings for regular external collaboration.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-20
CisM365: 8.5.1
Unknown M365TEAMS-005 Recording and transcription policies Microsoft Teams Security Medium FAIL Default (insecure)
Description
Teams meeting recording and transcription features capture audio, video, and text content of meetings that may contain sensitive business discussions, strategic planning, or confidential information. Unrestricted recording capabilities allow any meeting participant to record conversations without other participants' awareness or consent. Recording and transcription policies must balance business needs with data protection and privacy compliance requirements.
Current Value
Default (insecure)
Recommended Value
Cloud recording restricted to meeting organizers; automatic transcription requires consent; recordings stored in approved locations with appropriate retention
Remediation Steps
Configure the meeting policy to restrict cloud recording initiation to meeting organizers and co-organizers rather than all participants. Enable recording consent notifications so that all participants are aware when a recording begins, and configure automatic transcription settings to comply with privacy regulations in your jurisdiction. Review the storage location and retention policies for meeting recordings to ensure they are stored in a governed location with appropriate access controls and lifecycle management.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-2
CisM365: 8.5.5
Unknown M365TEAMS-006 Messaging policies (external communication) Microsoft Teams Security Medium FAIL Anyone (no restrictions)
Description
Teams messaging policies control user capabilities within chat and channel conversations, including the ability to communicate with external users through chat. Unrestricted messaging to external users enables data exfiltration through chat, file sharing, and link sharing without the visibility and controls applied to email communication. Messaging policies must be configured to prevent sensitive data leakage through the Teams chat channel.
Current Value
Anyone (no restrictions)
Recommended Value
External chat limited to specific domains; URL preview disabled for external conversations; file sharing restricted in external chats
Remediation Steps
Review the Teams messaging policies and restrict the ability to chat with external users to only those personnel who have a business need for cross-organization communication. Disable URL previews in conversations with external users to prevent accidental data exposure through link expansion. Consider implementing DLP policies for Teams chat to detect and block sharing of sensitive information types in external conversations.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-20
CisM365: 8.2.1
Unknown M365TEAMS-007 App permission policies Microsoft Teams Security Medium FAIL Unreviewed permissions
Description
Teams app permission policies control which third-party and custom applications can be installed and used within the Teams environment. Unrestricted app installation allows users to add third-party applications that may request excessive permissions, access corporate data, or introduce security vulnerabilities. App governance policies must balance user productivity with security by curating the available application catalog.
Current Value
Unreviewed permissions
Recommended Value
Third-party apps restricted to an approved list; custom app uploads restricted to authorized developers; app permission requests reviewed by administrators
Remediation Steps
Configure the Teams app permission policy to block all third-party apps by default and selectively allow only approved applications that have been vetted by the security team. Restrict custom app sideloading to authorized developers and require all custom apps to go through an approval process before publication. Review the list of currently installed third-party apps, remove any that are unapproved or no longer needed, and audit the permissions each app has been granted.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-7
CisM365: 8.6.1 8.4.1
Unknown M365TEAMS-008 File sharing settings in Teams Microsoft Teams Security Medium FAIL Anyone (no restrictions)
Description
File sharing within Microsoft Teams is backed by SharePoint Online and OneDrive, and the sharing settings determine how files shared in channels and chats can be accessed by internal and external users. Misconfigured file sharing settings can result in sensitive documents being accessible to guest users or through overly permissive sharing links generated from Teams. Aligning Teams file sharing settings with organizational data protection policies prevents unintended data exposure.
Current Value
Anyone (no restrictions)
Recommended Value
File sharing with external users restricted to authenticated guests; cloud storage providers limited to OneDrive and SharePoint; external file sharing disabled in private channels
Remediation Steps
Review the Teams file sharing configuration and ensure that files shared in channels and chats inherit the SharePoint Online sharing restrictions configured at the organizational level. Disable third-party cloud storage integration (Citrix Files, Dropbox, Box, Google Drive, Egnyte) in Teams to prevent data from being uploaded to unmanaged storage services. Configure sensitivity labels for Teams and associated SharePoint sites to enforce file protection policies that persist when documents are shared or downloaded.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-21
Unknown OAUTH-006 API Access Control OAuth & API Security Medium FAIL Default (insecure)
Description
API access should be controlled with appropriate scoping and restrictions to prevent unauthorized programmatic access to organizational data
Current Value
Default (insecure)
Recommended Value
API access restricted to approved applications and scopes
Remediation Steps
Admin Console > Security > API controls > Manage Google Services > Restrict API access to trusted apps only
Compliance Mappings
NIST SP 800-53: AC-3 AC-17
MITRE ATT&CK: T1106
CIS Benchmark: 3.6
Unknown OAUTH-007 Marketplace App Installation Restrictions OAuth & API Security Medium FAIL Unreviewed permissions
Description
Google Workspace Marketplace app installation should be restricted to prevent users from installing unauthorized applications
Current Value
Unreviewed permissions
Recommended Value
Marketplace app installation restricted to admin-approved apps or allowlisted apps only
Remediation Steps
Admin Console > Apps > Google Workspace Marketplace apps > Settings > Restrict marketplace app installation
Compliance Mappings
NIST SP 800-53: CM-11 CM-7
MITRE ATT&CK: T1195.002 T1204.003
CIS Benchmark: 3.7
Unknown ADDOM-011 Site Link Configuration AD Domain & Forest Configuration Low FAIL Not configured
Description
AD site links should be configured with appropriate cost, replication interval, and schedule to ensure timely replication while respecting network constraints. Misconfigured site links can delay security policy propagation
Current Value
Not configured
Recommended Value
Site links configured with appropriate costs and replication intervals of 15-60 minutes depending on link capacity
Remediation Steps
Review AD Sites and Services > Inter-Site Transports > IP. Verify each site link has appropriate cost values, replication interval (default 180 minutes is often too long), and schedule. Adjust based on network topology
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-36 CM-6
MITRE ATT&CK: T1557
CisAd: 1.5.2
Unknown ADGPO-002 Empty GPOs AD Group Policy Low FAIL Misconfigured
Description
GPOs that contain no configured settings (both Computer and User Configuration sections are empty) add unnecessary complexity to Group Policy processing and may indicate abandoned configuration efforts or testing artifacts that were never cleaned up
Current Value
Misconfigured
Recommended Value
No empty GPOs in the domain; all GPOs contain at least one configured setting
Remediation Steps
Identify GPOs with no configured settings using Get-GPOReport in XML format and checking for empty ExtensionData elements. Verify that empty GPOs are not placeholders for future use. Delete truly empty GPOs after confirming they are not referenced by any automation or documentation.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-2 CM-7
MITRE ATT&CK: T1484.001
Unknown ADGPO-003 Unlinked GPOs AD Group Policy Low FAIL Misconfigured
Description
GPOs that are not linked to any site, domain, or OU are not being applied and represent unused configuration. Unlinked GPOs may contain sensitive settings, credentials in GPP, or scripts that could be leveraged if an attacker later links them to a target OU
Current Value
Misconfigured
Recommended Value
No unlinked GPOs unless documented as templates or backups with appropriate access controls
Remediation Steps
Identify unlinked GPOs by comparing all GPO GUIDs against gPLink attributes on all OUs, sites, and the domain root. Review each unlinked GPO to determine if it should be linked, archived, or deleted. Remove sensitive content from unlinked GPOs that are kept as templates.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-2 CM-7
MITRE ATT&CK: T1484.001
Unknown ADGPO-004 Disabled GPOs with Content AD Group Policy Low FAIL Misconfigured
Description
GPOs where either the User Configuration or Computer Configuration section is disabled but still contains configured settings may indicate incomplete decommissioning or unintentional disabling. If re-enabled by an attacker with GPO edit permissions, the dormant settings would take effect
Current Value
Misconfigured
Recommended Value
No GPOs with disabled sections that contain configured settings; disabled sections should be empty
Remediation Steps
Review all GPOs where GpoStatus is UserSettingsDisabled or ComputerSettingsDisabled. Verify that the disabled section does not contain active settings. Either re-enable the section if the settings are needed, or remove the settings from the disabled section. Document the reason for any intentionally disabled sections.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-2 CM-6
MITRE ATT&CK: T1484.001
Unknown ADGPO-005 Duplicated GPOs AD Group Policy Low FAIL Misconfigured
Description
Multiple GPOs with substantially similar or identical settings create management overhead, increase the risk of configuration drift, and complicate troubleshooting. Duplicate GPOs may also result in conflicting settings that produce unpredictable behavior
Current Value
Misconfigured
Recommended Value
No duplicate GPOs; each GPO has a unique purpose and non-overlapping settings
Remediation Steps
Export all GPO reports in XML format and compare settings across GPOs to identify duplicates. Consolidate duplicate GPOs into a single GPO where possible. Update OU links to reference the consolidated GPO. Test the consolidated GPO in a staging OU before removing the duplicates.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-2 CM-3
MITRE ATT&CK: T1484.001
Unknown ADGPO-024 GPO WMI Filter Review AD Group Policy Low FAIL Misconfigured
Description
WMI filters control GPO application based on WQL queries evaluated on target systems. Malicious or misconfigured WMI filters can selectively prevent security GPOs from applying to specific systems, creating targeted security gaps. WMI filters should be reviewed for correctness, performance impact, and potential abuse
Current Value
Misconfigured
Recommended Value
All WMI filters documented, tested, and producing expected results; no WMI filters that block security-critical GPOs
Remediation Steps
Inventory all WMI filters using Get-ADObject -Filter 'objectClass -eq "msWMI-Som"'. Review the WQL query in each filter for correctness and test against representative target systems. Verify that WMI filters are not blocking security-critical GPOs from applying. Remove unused WMI filters. Document the purpose and expected behavior of each active WMI filter.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-6 CM-3
MITRE ATT&CK: T1484.001
Unknown ADMIN-007 OU Structure Review Admin & User Management Low FAIL Not configured
Description
The organizational unit structure should be reviewed to ensure policies can be effectively applied at the appropriate scope
Current Value
Not configured
Recommended Value
OU structure documented with clear policy mapping
Remediation Steps
Admin Console > Directory > Organizational units > Review OU hierarchy and ensure it aligns with policy application needs
Compliance Mappings
NIST SP 800-53: CM-6 AC-2
MITRE ATT&CK: T1087.004
CIS Benchmark: 4.7
Unknown ADMIN-009 User Profile Visibility Admin & User Management Low FAIL Not configured
Description
User profile information visibility should be controlled to limit reconnaissance potential from external actors
Current Value
Not configured
Recommended Value
User profile visibility restricted to internal users
Remediation Steps
Admin Console > Directory > Directory settings > Profile sharing > Restrict profile visibility
Compliance Mappings
NIST SP 800-53: AC-22 AC-3
MITRE ATT&CK: T1589.002
CIS Benchmark: 4.9
Unknown ADMIN-018 Data at-rest region configured (GWS.COMMONCONTROLS.15.1) Admin & User Management Low FAIL Not configured
Description
SCuBA GWS.COMMONCONTROLS.15.1: setting a data-at-rest region enforces where organizational data is stored (residency/compliance). Reads data_regions.data_at_rest_region; warns where no region preference is set.
Current Value
Not configured
Recommended Value
A specific data-at-rest region is configured per organizational policy
Remediation Steps
In Admin console > Data > Data regions, set the data-at-rest region required by your organization's residency policy rather than leaving it unset.
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-28 AC-3
Unknown ADMIN-019 Data processing restricted to storage region (GWS.COMMONCONTROLS.15.2) Admin & User Management Low FAIL Not configured
Description
SCuBA GWS.COMMONCONTROLS.15.2 requires that data be processed in the same region selected for data at rest, so processing does not move covered data outside the chosen jurisdiction. This check reads the data_regions.data_processing_region Cloud Identity policy and flags any organizational unit where processing is not limited to the storage region.
Current Value
Not configured
Recommended Value
Data processing limited to the storage region (limitToStorageRegion = true) in all organizational units.
Remediation Steps
In the Google Admin console, under Account > Data regions, enable 'Process data only in the selected region' so processing stays within the region chosen for data at rest.
Remediation URL
Compliance Mappings
NIST SP 800-53: SA-9 AC-4
Unknown ADPWD-018 Windows LAPS vs Legacy LAPS AD Password & Lockout Policies Low FAIL Not configured
Description
Windows LAPS (built into Windows Server 2019+ and Windows 10/11 with April 2023 update) provides improvements over legacy LAPS including password encryption, password history, and DSRM password management. Organizations should migrate from legacy LAPS to Windows LAPS for enhanced security features
Current Value
Not configured
Recommended Value
Windows LAPS deployed with password encryption enabled. Legacy LAPS migration completed
Remediation Steps
Verify which LAPS version is deployed by checking for the msLAPS-Password attribute (Windows LAPS) versus ms-Mcs-AdmPwd (Legacy LAPS). Plan migration to Windows LAPS. Update the AD schema for Windows LAPS attributes. Deploy Windows LAPS GPO settings with encryption enabled. Decommission legacy LAPS components after migration
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-5(1) SC-28
MITRE ATT&CK: T1078.003
CisAd: 5.7.3
Unknown ADSTALE-009 Abandoned OUs AD Stale & Obsolete Objects Low FAIL Not configured
Description
Empty or near-empty Organizational Units that no longer serve a purpose add complexity to the AD structure, complicate Group Policy analysis, and may have delegated permissions that are no longer monitored. Abandoned OUs from past organizational restructuring or decommissioned projects can confuse administrators and create potential targets for GPO linking attacks
Current Value
Not configured
Recommended Value
No empty OUs without a documented purpose; OU structure reflects current organizational requirements
Remediation Steps
Enumerate all OUs and count their child objects. Identify OUs with zero or very few objects. Review OU descriptions and any associated documentation to determine if the OU is planned for future use. Remove delegated permissions from abandoned OUs. Delete empty OUs that have no documented purpose after verifying they are not referenced by GPO links, scripts, or automation. Update OU structure documentation
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-2
CisAd: 9.5.1
Unknown ADSTALE-010 Printer Objects AD Stale & Obsolete Objects Low FAIL Not configured
Description
Printer objects published in Active Directory expose printer share paths and server names that can be used for reconnaissance. The PrintNightmare vulnerability family (CVE-2021-34527 and related) demonstrated that printer-related objects and configurations can be exploited for remote code execution. Stale printer objects referencing decommissioned print servers provide misleading information and unnecessary attack surface
Current Value
Not configured
Recommended Value
Only active, managed printer objects published in AD; stale printer objects removed
Remediation Steps
Enumerate all printQueue objects in AD using Get-ADObject -Filter {objectClass -eq 'printQueue'}. Verify that each printer object references an active, accessible print server and printer. Remove printer objects for decommissioned printers or print servers. Review whether printer publishing in AD is required for the environment. Ensure print servers are patched against PrintNightmare vulnerabilities
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-8
MITRE ATT&CK: T1557
CisAd: 9.5.2
Unknown AUTH-015 2SV Enrollment Grace Period Authentication & Access Controls Low FAIL Not configured
Description
The grace period before newly added users must enroll in 2SV should be short. A long grace period leaves accounts unprotected by MFA for an extended window after creation
Current Value
Not configured
Recommended Value
Grace period of 7 days (168 hours) or less
Remediation Steps
Security > Authentication > 2-step verification > Set the new-user enrollment grace period to 7 days or less
Compliance Mappings
NIST SP 800-53: IA-2(1)
MITRE ATT&CK: T1078.004
CIS Benchmark: 1.2
Unknown AUTH-016 Advanced Protection Self-Enrollment Authentication & Access Controls Low FAIL Not configured
Description
Allowing self-enrollment in the Advanced Protection Program lets high-risk users adopt the strongest available account protections without admin intervention
Current Value
Not configured
Recommended Value
Advanced Protection self-enrollment allowed in all organizational units
Remediation Steps
Security > Authentication > Advanced Protection Program > Allow users to self-enroll in Advanced Protection
Compliance Mappings
NIST SP 800-53: IA-2(1)
MITRE ATT&CK: T1078.004
CIS Benchmark: 1.14
Unknown COLLAB-007 Chat App Installation Settings Collaboration & Communication Security Low FAIL Unreviewed permissions
Description
Chat app (bot) installation should be controlled to prevent unauthorized integrations from accessing conversation data
Current Value
Unreviewed permissions
Recommended Value
Chat app installation restricted to admin-approved apps
Remediation Steps
Admin Console > Apps > Google Workspace > Google Chat > Chat settings > Apps > Restrict app installation to approved apps
Compliance Mappings
NIST SP 800-53: CM-7 CM-11
MITRE ATT&CK: T1195.002
CIS Benchmark: 5.7
Unknown COLLAB-010 Calendar Appointment Slots External Visibility Collaboration & Communication Security Low FAIL Anyone (no restrictions)
Description
Calendar appointment slot visibility should be controlled to limit external exposure of availability and scheduling details
Current Value
Anyone (no restrictions)
Recommended Value
Appointment slot external visibility restricted
Remediation Steps
Admin Console > Apps > Google Workspace > Calendar > Sharing settings > Review appointment slot visibility settings
Compliance Mappings
NIST SP 800-53: AC-22
MITRE ATT&CK: T1589.002
CIS Benchmark: 5.10
Unknown COLLAB-011 Meet External Participant Labeling Collaboration & Communication Security Low FAIL Anyone (no restrictions)
Description
External participants in meetings should be visibly labeled so hosts and attendees can readily identify outsiders and avoid disclosing sensitive information
Current Value
Anyone (no restrictions)
Recommended Value
External participant labeling enabled
Remediation Steps
Apps > Google Workspace > Google Meet > Meet safety settings > External participants > Enable labeling of external participants
Compliance Mappings
NIST SP 800-53: AC-22
MITRE ATT&CK: T1199
CIS Benchmark: 6.1
Unknown COLLAB-014 Chat space history is on (GWS.CHAT.3.1) Collaboration & Communication Security Low FAIL Not configured
Description
SCuBA GWS.CHAT.3.1 requires that history for Chat spaces be always on so conversations are retained for oversight, investigation, and eDiscovery. This check reads chat.space_history and warns any organizational unit where space history is not set to HISTORY_ALWAYS_ON.
Current Value
Not configured
Recommended Value
Chat space history set to HISTORY_ALWAYS_ON
Remediation Steps
In Google Chat settings, set space history to always on so conversations are retained and available for oversight and eDiscovery.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-11 AU-12
Unknown COLLAB-016 Meet automatic transcription off by default (GWS.MEET.5.2) Collaboration & Communication Security Low FAIL Not configured
Description
SCuBA GWS.MEET.5.2 recommends that automatic transcription in Google Meet be off by default. Auto-transcribing meetings captures and stores conversation content — sensitive when students are present — without a deliberate decision. This check reads meet.automatic_transcription and warns any organizational unit where it is enabled by default.
Current Value
Not configured
Recommended Value
Automatic transcription disabled by default
Remediation Steps
In Google Meet settings, disable automatic transcription by default so meeting content is captured only when a host deliberately enables it.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-12 SC-28
Unknown COLLAB-017 Calendar external interoperability managed (GWS.CALENDAR.3.1) Collaboration & Communication Security Low FAIL Anyone (no restrictions)
Description
SCuBA GWS.CALENDAR.3.1 requires that Calendar Interop (sharing free/busy and calendar data with an external system such as Microsoft Exchange) be off unless it is deliberately managed. Interop bridges calendar data to an outside platform. This check reads calendar.interoperability and warns any organizational unit where enableInteroperability is on.
Current Value
Anyone (no restrictions)
Recommended Value
Calendar interoperability disabled unless deliberately managed
Remediation Steps
In the Admin console under Apps > Google Workspace > Calendar > Calendar Interop management, disable interoperability unless a reviewed integration requires it.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-4 SC-7
Unknown COLLAB-018 Calendar appointment payments disabled (GWS.CALENDAR.4.1) Collaboration & Communication Security Low FAIL Unreviewed permissions
Description
SCuBA GWS.CALENDAR.4.1 recommends that paid appointment schedules be disabled. This check reads calendar.appointment_schedules and warns any organizational unit where enablePayments is on.
Current Value
Unreviewed permissions
Recommended Value
Paid appointment schedules disabled
Remediation Steps
In Google Calendar appointment-schedule settings, disable payments unless the organization deliberately uses paid appointments.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-7
Unknown COLLAB-019 Meet automatic recording off by default (GWS.MEET.5.1) Collaboration & Communication Security Low FAIL Not configured
Description
SCuBA GWS.MEET.5.1 recommends that automatic recording in Google Meet be off by default. Auto-recording captures and stores meeting video/audio — sensitive when students are present — without a deliberate decision. This check reads meet.automatic_recording and warns any organizational unit where it is enabled by default.
Current Value
Not configured
Recommended Value
Automatic recording disabled by default
Remediation Steps
In Google Meet settings, disable automatic recording by default so meetings are recorded only when a host deliberately starts a recording.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-12 SC-28
Unknown DEVICE-011 Company-Owned Device Inventory Device & Endpoint Management Low FAIL Not enrolled
Description
Company-owned devices should be inventoried to maintain visibility over organizational assets accessing corporate data
Current Value
Not enrolled
Recommended Value
Complete inventory of all company-owned devices maintained
Remediation Steps
Admin Console > Devices > Mobile devices > Review device inventory > Ensure all company-owned devices are registered and accounted for
Compliance Mappings
NIST SP 800-53: CM-8 PM-5
MITRE ATT&CK: T1087
CIS Benchmark: 6.11
Unknown DRIVE-012 Drive Add-ons Settings Drive Security & Data Protection Low FAIL Not configured
Description
Drive add-ons can access file content and should be controlled to prevent data exposure through untrusted extensions
Current Value
Not configured
Recommended Value
Drive add-on installation restricted to admin-approved add-ons
Remediation Steps
Admin Console > Apps > Google Workspace > Drive and Docs > Features and Applications > Add-ons > Configure installation restrictions
Compliance Mappings
NIST SP 800-53: CM-7 CM-11
MITRE ATT&CK: T1195.002
CIS Benchmark: 2.12
Unknown DRIVE-015 Drive external-file warning enabled (GWS.DRIVEDOCS.1.9) Drive Security & Data Protection Low FAIL Disabled
Description
SCuBA GWS.DRIVEDOCS.1.9: warning users when they share files externally is a low-friction data-loss control. Reads drive_and_docs.external_file_warning; warns where highlightingEnabled is off.
Current Value
Disabled
Recommended Value
External-file sharing warning enabled
Remediation Steps
In Drive sharing settings, enable warnings when users share files with people outside the organization.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-22 SI-10
Unknown EIDSCA-AF02 EIDSCA AF02: Authentication Method - FIDO2 security key - Allow self-service set up EIDSCA Baseline Low FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AF02): evaluates 'isSelfServiceRegistrationAllowed' on the Fido2 authentication method against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq true
Remediation Steps
Configure the Fido2 authentication method so 'isSelfServiceRegistrationAllowed' is set to true. (Entra ID security-configuration baseline, control EIDSCA AF02.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AF05 EIDSCA AF05: Authentication Method - FIDO2 security key - Restricted EIDSCA Baseline Low FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AF05): evaluates 'keyRestrictions.aaGuids' on the Fido2 authentication method against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
notempty
Remediation Steps
Ensure 'keyRestrictions.aaGuids' on the Fido2 authentication method is configured (non-empty). (Entra ID security-configuration baseline, control EIDSCA AF05.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AF06 EIDSCA AF06: Authentication Method - FIDO2 security key - Restrict specific keys EIDSCA Baseline Low FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AF06): evaluates 'keyRestrictions' on the Fido2 authentication method against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
fido2-aaguid-enforced
Remediation Steps
Ensure 'keyRestrictions' on the Fido2 authentication method is enforced with an AAGUID allow/block list. (Entra ID security-configuration baseline, control EIDSCA AF06.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AM09 EIDSCA AM09: Authentication Method - Microsoft Authenticator - Show geographic location in push and passwordless notifications EIDSCA Baseline Low FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AM09): evaluates 'featureSettings.displayLocationInformationRequiredState.state' on the MicrosoftAuthenticator authentication method against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq enabled
Remediation Steps
Configure the MicrosoftAuthenticator authentication method so 'featureSettings.displayLocationInformationRequiredState.state' is set to enabled. (Entra ID security-configuration baseline, control EIDSCA AM09.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AM10 EIDSCA AM10: Authentication Method - Microsoft Authenticator - Included users/groups to show geographic location in push and passwordless notifications EIDSCA Baseline Low FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AM10): evaluates 'featureSettings.displayLocationInformationRequiredState.includeTarget.id' on the MicrosoftAuthenticator authentication method against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq all_users
Remediation Steps
Configure the MicrosoftAuthenticator authentication method so 'featureSettings.displayLocationInformationRequiredState.includeTarget.id' is set to all_users. (Entra ID security-configuration baseline, control EIDSCA AM10.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AP14 EIDSCA AP14: Default Authorization Settings - Default User Role Permissions - Allowed to read other users EIDSCA Baseline Low FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AP14): evaluates 'defaultUserRolePermissions.allowedToReadOtherUsers' on the Entra ID authorization policy against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq true
Remediation Steps
Configure the Entra ID authorization policy so 'defaultUserRolePermissions.allowedToReadOtherUsers' is set to true. (Entra ID security-configuration baseline, control EIDSCA AP14.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-AT01 EIDSCA AT01: Authentication Method - Temporary Access Pass - State EIDSCA Baseline Low FAIL Vulnerable configuration
Description
Entra ID security-configuration control (EIDSCA AT01): evaluates 'state' on the TemporaryAccessPass authentication method against the recommended secure value.
Current Value
Vulnerable configuration
Recommended Value
eq enabled
Remediation Steps
Configure the TemporaryAccessPass authentication method so 'state' is set to enabled. (Entra ID security-configuration baseline, control EIDSCA AT01.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-CR02 EIDSCA CR02: Consent Framework - Admin Consent Request - Reviewers will receive email notifications for requests EIDSCA Baseline Low FAIL Excessive permissions found
Description
Entra ID security-configuration control (EIDSCA CR02): evaluates 'notifyReviewers' on the Entra ID admin consent request policy against the recommended secure value.
Current Value
Excessive permissions found
Recommended Value
eq true
Remediation Steps
Configure the Entra ID admin consent request policy so 'notifyReviewers' is set to true. (Entra ID security-configuration baseline, control EIDSCA CR02.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-CR03 EIDSCA CR03: Consent Framework - Admin Consent Request - Reviewers will receive email notifications when admin consent requests are about to expire EIDSCA Baseline Low FAIL Never
Description
Entra ID security-configuration control (EIDSCA CR03): evaluates 'remindersEnabled' on the Entra ID admin consent request policy against the recommended secure value.
Current Value
Never
Recommended Value
eq true
Remediation Steps
Configure the Entra ID admin consent request policy so 'remindersEnabled' is set to true. (Entra ID security-configuration baseline, control EIDSCA CR03.)
Remediation URL
Compliance Mappings
Unknown EIDSCA-CR04 EIDSCA CR04: Consent Framework - Admin Consent Request - Consent request duration (days) EIDSCA Baseline Low FAIL Excessive permissions found
Description
Entra ID security-configuration control (EIDSCA CR04): evaluates 'requestDurationInDays' on the Entra ID admin consent request policy against the recommended secure value.
Current Value
Excessive permissions found
Recommended Value
le 30
Remediation Steps
Configure the Entra ID admin consent request policy so 'requestDurationInDays' is at most 30. (Entra ID security-configuration baseline, control EIDSCA CR04.)
Remediation URL
Compliance Mappings
Unknown EIDTNT-014 User Password Expiration Disabled (Passwords Never Expire) Entra ID Tenant Configuration Low FAIL Never
Description
Mandatory periodic password rotation drives users toward predictable, weaker, and reused passwords and provides little defensive value when MFA and modern credential protections are in place. Aligned with NIST SP 800-63B and OMB M-22-09 guidance, user passwords should be configured to never expire. In Entra ID this is governed per verified domain by the passwordValidityPeriodInDays property; the value 2147483647 indicates passwords are set to never expire. This check inspects every managed domain and flags any domain that still enforces a finite password expiration period.
Current Value
Never
Recommended Value
passwordValidityPeriodInDays set to 2147483647 (never expire) on all managed domains
Remediation Steps
Set the password expiration policy so passwords never expire, satisfying SCuBA MS.AAD.6.1. In the Microsoft 365 admin center go to Settings > Org settings > Security & privacy > Password expiration policy and select 'Set passwords to never expire'. Equivalently, for each managed domain set passwordValidityPeriodInDays to 2147483647 (never expire). Ensure compensating controls remain in place: enforced MFA, banned-password protection, and risk-based credential remediation.
Compliance Mappings
NIST SP 800-53: IA-5 IA-5(1)
CisM365: 1.3.1
Unknown EMAIL-020 Gmail Confidential Mode Email Security Low FAIL Not configured
Description
Gmail confidential mode allows senders to set expiration dates and revoke access to messages. Review whether this feature is enabled or restricted per organizational policy
Current Value
Not configured
Recommended Value
Gmail confidential mode enabled for users who handle sensitive data
Remediation Steps
Admin Console > Apps > Google Workspace > Gmail > End User Access > Review Gmail confidential mode settings and enable or restrict based on organizational requirements
Compliance Mappings
NIST SP 800-53: AC-4 SC-28
MITRE ATT&CK: T1114.002
CIS Benchmark: 2.20
Unknown EMAIL-021 S/MIME Settings Email Security Low FAIL Not configured
Description
S/MIME provides end-to-end email encryption and digital signatures. If required by compliance, S/MIME certificates should be properly configured and managed
Current Value
Not configured
Recommended Value
S/MIME enabled if required by compliance; certificates properly managed
Remediation Steps
Admin Console > Apps > Google Workspace > Gmail > End User Access > S/MIME > Enable hosted S/MIME if required and ensure certificates are uploaded and valid
Compliance Mappings
NIST SP 800-53: SC-8(1) SC-12
MITRE ATT&CK: T1557 T1040
CIS Benchmark: 2.21
Unknown EMAIL-027 Gmail user email/contacts import disabled (GWS.GMAIL.8.1) Email Security Low FAIL Not configured
Description
SCuBA GWS.GMAIL.8.1: user email uploads (importing mail and contacts from external accounts) pulls outside data into the tenant and can exfiltrate in reverse. Reads gmail.user_email_uploads; warns where enableMailAndContactsImport is on.
Current Value
Not configured
Recommended Value
User email/contacts import disabled
Remediation Steps
In Gmail settings, disable the ability for users to import mail and contacts from other accounts unless required.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-4 SC-7
Unknown EMAIL-028 Google Workspace Sync for Outlook disabled (GWS.GMAIL.10.1) Email Security Low FAIL Not configured
Description
SCuBA GWS.GMAIL.10.1: Google Workspace Sync for Microsoft Outlook (GWSMO) bridges mailbox data to an Outlook client, expanding the data surface and bypassing some web protections. Reads gmail.workspace_sync_for_outlook; warns where it is enabled.
Current Value
Not configured
Recommended Value
GWSMO disabled unless required
Remediation Steps
In Gmail end-user access settings, disable Google Workspace Sync for Microsoft Outlook unless a reviewed need exists.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-3 CM-7
Unknown EMAIL-029 Gmail spam-override sender lists reviewed (GWS.GMAIL.18.1) Email Security Low FAIL Not configured
Description
SCuBA GWS.GMAIL.18.1: approved-sender / spam-override lists cause mail from listed domains to bypass spam filtering, a phishing bypass if over-broad. Reads gmail.spam_override_lists; warns where override sender domains are configured.
Current Value
Not configured
Recommended Value
Spam-override sender lists absent or minimal and reviewed
Remediation Steps
In Gmail spam settings, review and minimize approved-sender / bypass lists so trusted-domain mail is not blanket-exempted from spam filtering.
Remediation URL
Compliance Mappings
NIST SP 800-53: SI-8 SC-7
Unknown GROUP-004 Group creation restricted to administrators (GWS.GROUPS.2.1) Collaboration & Communication Security Low FAIL Excessive permissions found
Description
SCuBA GWS.GROUPS.2.1 recommends restricting who can create Groups for Business to administrators. When any user can create groups, group sprawl outpaces governance and external-sharing defaults may be applied without review. This check flags organizational units where the create-groups access level is not ADMIN_ONLY.
Current Value
Excessive permissions found
Recommended Value
Group creation access level set to ADMIN_ONLY
Remediation Steps
In Groups for Business settings, set 'who can create groups' to admins only, so new groups are created deliberately and inherit reviewed sharing settings.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-2 AC-6 PM-10
Unknown GROUP-005 Group conversation visibility defaults to members (GWS.GROUPS.3.1) Collaboration & Communication Security Low FAIL Not configured
Description
SCuBA GWS.GROUPS.3.1 requires that the default permission for viewing group conversations be restricted to group members rather than the whole domain or the public. Overly-open conversation visibility exposes discussion archives — which can contain sensitive student and staff information. This check reads viewTopicsDefaultAccessLevel from the groups_for_business.groups_sharing policy and warns where the default is broader than group members.
Current Value
Not configured
Recommended Value
Default conversation view access set to GROUP_MEMBERS
Remediation Steps
In Groups for Business settings, set the default 'who can view conversations' permission to group members.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-3 AC-22
Unknown GROUP-006 Groups are visible in the directory (GWS.GROUPS.4.1) Collaboration & Communication Security Low FAIL Not configured
Description
SCuBA GWS.GROUPS.4.1 requires that groups not be hideable from the directory — hidden groups undermine transparency and oversight of who can be reached and what access exists. This check reads the groups_for_business.groups_sharing policy and warns any organizational unit where owners can hide groups (ownersCanHideGroups) or new groups are hidden by default (newGroupsAreHidden).
Current Value
Not configured
Recommended Value
Owners cannot hide groups and new groups are not hidden by default
Remediation Steps
In Groups for Business settings, prevent group owners from hiding groups from the directory and ensure new groups are not hidden by default, preserving directory transparency.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-22 AU-6
Unknown LOG-006 Reporting API Access Logging, Alerting & Monitoring Low FAIL Not configured
Description
Access to the Reports API should be reviewed to ensure only authorized service accounts and applications can retrieve audit and usage data
Current Value
Not configured
Recommended Value
Reports API access restricted to authorized service accounts only
Remediation Steps
Admin Console > Security > API controls > Domain-wide delegation > Review grants with Reports API scopes > Remove unauthorized access
Compliance Mappings
NIST SP 800-53: AU-9 AC-3
MITRE ATT&CK: T1530
CIS Benchmark: 7.6
Unknown ADCS-001 CA Server Inventory AD Certificate Services Info FAIL Vulnerable configuration
Description
An inventory of all Certificate Authority servers in the environment provides the foundation for AD CS security assessment. This includes Enterprise CAs, Standalone CAs, their roles (Root vs Subordinate), operating system versions, and published certificate templates. Understanding the PKI hierarchy is essential for identifying the attack surface
Current Value
Vulnerable configuration
Recommended Value
Complete CA inventory documented with CA type, role, OS version, and published templates for each CA server
Remediation Steps
Enumerate all CA servers by querying the PKI Enrollment Services container in AD (CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=Configuration). Document each CA's type (Enterprise/Standalone), role (Root/Subordinate), hostname, operating system version, and published certificate templates. Verify that all CA servers are running supported OS versions and have current patches.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-8 CM-8(1) IA-5(2)
MITRE ATT&CK: T1649
Unknown ADCS-019 Certificate Template Enumeration AD Certificate Services Info FAIL Vulnerable configuration
Description
A comprehensive enumeration of all certificate templates with their security-relevant attributes provides the baseline for ESC vulnerability assessment. This includes template schema version, enrollment permissions, EKU configuration, name flags, enrollment flags, authorized signatures requirement, and validity period. This information feeds into all ESC-specific checks
Current Value
Vulnerable configuration
Recommended Value
Complete template inventory with security attributes documented; all templates reviewed for least-privilege enrollment and appropriate EKU
Remediation Steps
Enumerate all certificate templates from CN=Certificate Templates,CN=Public Key Services,CN=Services,CN=Configuration using certutil -template or PowerShell. For each template, document: display name, schema version, enrollment permissions, EKU, name flags (ENROLLEE_SUPPLIES_SUBJECT), enrollment flags, authorized signatures requirement, validity period, and renewal period. Cross-reference published templates on each CA.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-8 CM-8(1) IA-5(2)
MITRE ATT&CK: T1649
Unknown ADDOM-006 FSMO Role Holder Identification AD Domain & Forest Configuration Info FAIL Permanent assignments found
Description
The five FSMO roles (Schema Master, Domain Naming Master, RID Master, PDC Emulator, Infrastructure Master) should be documented and placed on appropriate domain controllers. Knowing role placement is essential for disaster recovery and operational awareness
Current Value
Permanent assignments found
Recommended Value
All FSMO roles documented, placed on reliable DCs, and included in DR planning
Remediation Steps
Run 'netdom query fsmo' or query the AD schema and domain partitions to identify role holders. Document roles and verify they are on highly available DCs. Transfer roles if current holders are inappropriate
Remediation URL
Compliance Mappings
NIST SP 800-53: CP-2 CM-8
MITRE ATT&CK: T1018
CisAd: 1.1.4
Unknown ADGPO-001 GPO Inventory with Link Status AD Group Policy Info FAIL Misconfigured
Description
A comprehensive inventory of all Group Policy Objects with their link status, scope, and enforcement state provides the foundation for GPO security analysis. Understanding which GPOs are linked, enforced, or disabled is essential for assessing the effective security posture delivered through Group Policy
Current Value
Misconfigured
Recommended Value
Complete GPO inventory documented with link status, scope, and owner for each GPO
Remediation Steps
Generate a full GPO inventory using Get-GPO -All and Get-GPOReport. Document each GPO's purpose, owner, link locations, and enforcement status. Establish a GPO naming convention and ensure all GPOs conform to it. Implement a GPO change management process.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-8 CM-8(1)
MITRE ATT&CK: T1484.001
Unknown ADKERB-011 Computer SPN Audit AD Kerberos Security Info FAIL Disabled
Description
Service Principal Names on computer accounts define the services registered to run on each machine. Duplicate SPNs cause Kerberos authentication failures, while unauthorized SPNs may indicate rogue services or compromised machines. A clean SPN configuration is essential for Kerberos to function correctly and for maintaining an accurate service inventory
Current Value
Disabled
Recommended Value
No duplicate SPNs across the domain. All SPNs on computer accounts correspond to legitimate, documented services
Remediation Steps
Scan for duplicate SPNs using setspn -X in the forest or Get-ADObject queries. Remove or reassign duplicate SPNs to the correct accounts. Review SPNs on computer objects to identify any unauthorized or unexpected services. Use setspn -L <computername> to list SPNs per computer. Document all non-default SPNs with their business purpose
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-8
CisAd: 7.1.3
Unknown ADPWD-020 BitLocker Recovery Keys in AD AD Password & Lockout Policies Info FAIL Not configured
Description
BitLocker recovery keys stored in Active Directory should be inventoried to ensure disk encryption is properly deployed and recovery keys are available. The presence of recovery keys also indicates which machines have BitLocker enabled, providing visibility into encryption coverage
Current Value
Not configured
Recommended Value
BitLocker recovery keys present in AD for all workstations and laptops. Recovery key access restricted to authorized administrators
Remediation Steps
Query AD for BitLocker recovery information objects using Get-ADObject -Filter {objectClass -eq 'msFVE-RecoveryInformation'} -SearchBase 'DC=domain,DC=com'. Cross-reference with computer inventory to identify machines without BitLocker. Review ACLs on recovery key objects to ensure only authorized administrators can read them
Remediation URL
Compliance Mappings
NIST SP 800-53: SC-28 SC-28(1)
MITRE ATT&CK: T1005
CisAd: 5.8.1
Unknown ADSCRIPT-003 Logon Script Inventory AD Logon Scripts & Network Shares Info FAIL Disabled
Description
An inventory of all logon scripts referenced by user accounts (scriptPath attribute), Group Policy logon/logoff scripts, and startup/shutdown scripts provides visibility into all code that executes automatically in the environment. Scripts that exist in NETLOGON but are not referenced may be orphaned or indicators of past compromise
Current Value
Disabled
Recommended Value
Complete inventory of all logon scripts with documented purpose, owner, and last modification date
Remediation Steps
Enumerate all user scriptPath attributes using Get-ADUser -Filter {scriptPath -like '*'} -Properties scriptPath. List all GPO-configured scripts from GPO reports. Inventory all files in the NETLOGON share. Cross-reference to identify orphaned scripts, unused scripts, and scripts referenced by user accounts but missing from NETLOGON. Document each script's purpose and owner.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-8 CM-8(1) CM-3
MITRE ATT&CK: T1059
Unknown ADTRUST-001 Trust Relationships Enumeration AD Trust Relationships Info FAIL SID filtering disabled
Description
All trust relationships should be inventoried to establish a complete picture of the authentication boundary. Undocumented trusts expand the attack surface by allowing users from external domains to access resources
Current Value
SID filtering disabled
Recommended Value
All trust relationships documented with business justification, direction, type, and owner
Remediation Steps
Run Get-ADTrust -Filter * to enumerate all trusts. Document each trust with its direction, type (forest, external, shortcut, realm), transitivity, and business justification. Review and remove any trusts that no longer serve a business need
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-20 CA-3
MITRE ATT&CK: T1482
CisAd: 3.1.1
Unknown ADTRUST-011 Trust Hierarchy Visualization AD Trust Relationships Info FAIL SID filtering disabled
Description
A complete trust topology map should be maintained showing all trust relationships, directions, types, and transitivity paths. This visualization is essential for understanding the full authentication boundary and identifying unexpected access paths
Current Value
SID filtering disabled
Recommended Value
Up-to-date trust topology diagram maintained and reviewed quarterly
Remediation Steps
Generate a trust topology map using automated tools or manually document all trust relationships including direction, type, transitivity, SID filtering status, and selective authentication status. Update the diagram whenever trusts are added, modified, or removed. Include the map in security documentation and review quarterly
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-20 PL-2
MITRE ATT&CK: T1482
CisAd: 3.1.5
Unknown AZIAM-008 Management group structure review Azure IAM & Resource Security Info FAIL Not configured
Description
Management groups provide a hierarchical structure for organizing subscriptions and applying governance controls at scale. A poorly designed or flat management group structure makes it difficult to enforce differentiated policies for production, development, and sandbox environments. Reviewing the hierarchy ensures that policy inheritance and role assignments align with organizational security requirements.
Current Value
Not configured
Recommended Value
Implement a management group hierarchy that separates production, development, and sandbox environments with appropriate policy assignments
Remediation Steps
Review the current management group hierarchy and ensure it reflects organizational boundaries such as business units, environments, and workload classifications. Apply restrictive policies at higher management group levels for broad enforcement and allow exceptions at lower levels only with documented justification. Ensure the root management group has minimal direct role assignments and that sensitive subscriptions are placed in appropriately governed management groups.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-2
Unknown EIDAPP-001 Application Registration Inventory Entra ID Application & Service Principal Security Info FAIL Unreviewed permissions
Description
A complete inventory of all application registrations provides foundational visibility into the applications integrated with your Entra ID tenant. Without a comprehensive inventory, organizations cannot assess their application attack surface or identify unauthorized, abandoned, or shadow IT applications. This baseline enables all subsequent application security checks and should be maintained as a living document.
Current Value
Unreviewed permissions
Recommended Value
All application registrations inventoried with documented owners, purpose, and business justification
Remediation Steps
Navigate to Entra ID > Applications > App registrations and export the full list of registered applications. Review each registration to confirm it has an assigned owner, a documented business purpose, and is still actively required. Remove or disable any registrations that are no longer needed or lack identifiable ownership.
Compliance Mappings
NIST SP 800-53: CM-8
Unknown EIDAPP-016 Managed Identity Inventory and Permissions Entra ID Application & Service Principal Security Info FAIL Not configured
Description
Managed identities provide Azure resources with automatically managed credentials for authenticating to services that support Entra ID authentication. While managed identities eliminate the need for stored credentials, they can still be over-permissioned or assigned to resources that no longer require them. A comprehensive inventory of managed identities and their permission assignments ensures least-privilege access and identifies orphaned identities associated with deleted resources.
Current Value
Not configured
Recommended Value
All managed identities inventoried with documented resource associations and least-privilege permission assignments
Remediation Steps
Enumerate all system-assigned and user-assigned managed identities across Azure subscriptions using Azure Resource Graph or the Azure portal. Review the role assignments and API permissions granted to each managed identity and verify they follow least-privilege principles. Remove role assignments from managed identities associated with deleted or decommissioned resources and document the purpose and permission requirements for each active managed identity.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-8
CisAzure: 8.5
Unknown EIDAPP-017 Service Principal Sign-In Activity Entra ID Application & Service Principal Security Info FAIL Not required
Description
Monitoring service principal sign-in activity provides visibility into which applications are actively authenticating and from which IP addresses. Unusual sign-in patterns such as authentication from unexpected geographic locations, abnormal request volumes, or sign-ins from applications that should be dormant can indicate credential compromise or unauthorized use. This baseline activity data is essential for detecting anomalies and investigating incidents.
Current Value
Not required
Recommended Value
Service principal sign-in logs reviewed regularly with baseline activity profiles established for critical applications
Remediation Steps
Review service principal sign-in logs in Entra ID > Monitoring > Sign-in logs > Service principal sign-ins. Establish baseline activity profiles for critical applications including normal authentication frequency, source IP ranges, and target resources. Configure alerts for anomalous service principal sign-in patterns such as authentication from new IP addresses, unusual time-of-day activity, or sign-ins from applications that have been dormant.
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-6
Unknown EIDAUTH-001 Authentication Methods Policy Audit Entra ID Authentication Methods & MFA Info FAIL Disabled
Description
The authentication methods policy defines which methods are available to users for sign-in and MFA. A misconfigured policy may allow weak or deprecated methods, increasing the attack surface. This check audits the current policy state against recognized Entra ID security baselines.
Current Value
Disabled
Recommended Value
Authentication methods policy reviewed and aligned with organizational security baseline
Remediation Steps
Navigate to Entra ID > Protection > Authentication methods > Policies. Review each enabled method and disable any that are not required by your organization. Ensure phishing-resistant methods such as FIDO2 and Microsoft Authenticator are prioritized over SMS and voice.
Compliance Mappings
NIST SP 800-53: IA-2
CisM365: 5.2.1
Unknown EIDAUTH-003 MFA Method Distribution Analysis Entra ID Authentication Methods & MFA Info FAIL Not enforced
Description
Understanding the distribution of MFA methods across users helps assess the overall strength of authentication controls. Organizations should track adoption of phishing-resistant methods like FIDO2 and Authenticator push versus weaker methods like SMS. This visibility enables targeted campaigns to migrate users to stronger methods.
Current Value
Not enforced
Recommended Value
Majority of users registered with phishing-resistant MFA methods (FIDO2, Microsoft Authenticator, Windows Hello)
Remediation Steps
Review method distribution via Entra ID > Protection > Authentication methods > User registration details. Identify users relying solely on weaker methods and create migration plans. Use authentication method activity reports to track adoption progress.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-2(1)
Unknown EIDAUTH-006 FIDO2 Security Key Inventory and Audit Entra ID Authentication Methods & MFA Info FAIL Disabled
Description
FIDO2 security keys provide phishing-resistant authentication but must be inventoried and managed throughout their lifecycle. Untracked keys may remain associated with departed employees or become lost without detection. Regular audits ensure only authorized keys are active and properly assigned to current users.
Current Value
Disabled
Recommended Value
All registered FIDO2 keys inventoried with documented owner assignments and regular attestation reviews
Remediation Steps
Review FIDO2 key registrations via Entra ID > Protection > Authentication methods > FIDO2 security key. Cross-reference registered keys with your hardware asset inventory and remove keys for departed users. Implement key registration policies that restrict allowed AAGUID values to approved vendor models.
Remediation URL
Compliance Mappings
NIST SP 800-53: IA-2(6)
Unknown EIDCA-001 Full CA Policy Inventory Entra ID Conditional Access Info FAIL Vulnerable configuration
Description
A complete inventory of all Conditional Access policies with their settings should be maintained. This provides visibility into the security posture and enables gap analysis, change tracking, and compliance auditing across the tenant.
Current Value
Vulnerable configuration
Recommended Value
All Conditional Access policies documented with state, conditions, grant controls, and session controls
Remediation Steps
Navigate to the Entra admin center Conditional Access blade and export all policies. Review each policy for correct naming conventions, descriptions, and appropriate state (enabled, disabled, or report-only). Maintain a versioned record of all policy configurations for audit purposes.
Compliance Mappings
CisM365: 5.2.1
Unknown EIDCA-015 CA What-If Simulation for Attack Scenarios Entra ID Conditional Access Info FAIL Vulnerable configuration
Description
The Conditional Access What-If tool allows simulation of sign-in scenarios to validate policy behavior against common attack patterns. Without regular what-if testing, policy misconfigurations or gaps may go undetected until exploited by an attacker.
Current Value
Vulnerable configuration
Recommended Value
Quarterly what-if simulations covering common attack scenarios including external attacker, compromised device, and legacy auth attempts
Remediation Steps
Use the Conditional Access What-If tool to simulate sign-in scenarios for common attack patterns such as external MFA bypass, legacy authentication attempts, unmanaged device access, and compromised credential usage. Document the results of each simulation and remediate any policies that fail to block the simulated attack. Incorporate what-if testing into the change management process for all CA policy modifications.
Compliance Mappings
NIST SP 800-53: CA-8
MITRE ATT&CK: T1078.004
Unknown EIDCA-016 CA Policy Documentation Export Entra ID Conditional Access Info FAIL Vulnerable configuration
Description
A complete export of all Conditional Access policies should be generated for documentation, disaster recovery, and compliance audit purposes. Without documented policy exports, rebuilding CA policies after a tenant compromise or accidental deletion requires significant effort and may result in security gaps.
Current Value
Vulnerable configuration
Recommended Value
Full CA policy export generated and stored in a secure, versioned repository updated after each policy change
Remediation Steps
Export all Conditional Access policies using Microsoft Graph API or the Entra admin center and store the output in a secure, version-controlled repository. Establish an automated process to capture policy snapshots on a regular schedule or triggered by policy modifications. Include the export in your tenant disaster recovery plan and validate that policies can be restored from the export.
Compliance Mappings
NIST SP 800-53: CM-2 CM-6
Unknown EIDFED-001 Federated Domain Enumeration Entra ID Federation & Hybrid Identity Info FAIL Not configured
Description
A complete inventory of all federated domains in the tenant provides visibility into how authentication is configured for each domain. Federated domains redirect authentication to external identity providers, which must be properly secured and monitored. This baseline inventory enables assessment of the federation attack surface and identifies domains that may have been configured by attackers as part of a Golden SAML or backdoor federation attack.
Current Value
Not configured
Recommended Value
All federated domains inventoried with documented identity provider endpoints, signing certificates, and business justification
Remediation Steps
Enumerate all domains in the tenant using Microsoft Graph and identify those with federation authentication configured. Document the identity provider endpoint, signing certificate details, and federation protocol for each federated domain. Verify that each federation trust is authorized and corresponds to a known, legitimate identity provider under organizational control.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-8
Unknown EIDFED-012 Cloud-Only vs Synced Account Analysis Entra ID Federation & Hybrid Identity Info FAIL Not configured
Description
Understanding the distribution of cloud-only versus on-premises-synced accounts provides visibility into the hybrid identity landscape and helps identify potential security gaps. Cloud-only accounts are managed entirely in Entra ID while synced accounts originate from on-premises Active Directory and inherit its security posture. This analysis helps identify accounts that should be cloud-only but are being synced, or vice versa, and informs decisions about authentication method selection and security control placement.
Current Value
Not configured
Recommended Value
All accounts categorized as cloud-only or synced with documentation of the expected state for each account type and role
Remediation Steps
Export all user accounts from Entra ID and categorize them by the onPremisesSyncEnabled property to determine which accounts are synced from on-premises versus cloud-only. Verify that privileged administrative accounts are cloud-only to prevent on-premises compromise from affecting cloud administration. Document the expected identity source for each account type and investigate any accounts whose actual source does not match the expected configuration.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-2
Unknown EIDPIM-001 Global Administrator Enumeration Entra ID Privileged Identity Management Info FAIL Excessive permissions found
Description
The Global Administrator role grants unrestricted access to all Microsoft 365 and Entra ID services, making it the highest-privilege role in the tenant. Organizations should maintain a minimum of 2 and a maximum of 4 Global Administrators to balance operational resilience with least-privilege principles. Excessive Global Administrator assignments dramatically expand the attack surface for credential theft and tenant-wide compromise
Current Value
Excessive permissions found
Recommended Value
2-4 Global Admins maximum
Remediation Steps
Navigate to Entra ID > Roles and administrators > Global Administrator and review all assigned users. Remove unnecessary permanent assignments and ensure no more than 4 accounts hold this role. Convert permanent assignments to PIM eligible assignments where possible
Compliance Mappings
NIST SP 800-53: AC-2 AC-6(5)
MITRE ATT&CK: T1078.004
CisM365: 1.1.1
Unknown EIDPIM-002 All Privileged Role Assignments Entra ID Privileged Identity Management Info FAIL Excessive permissions found
Description
A comprehensive inventory of all privileged role assignments including both permanent (active) and eligible (just-in-time) assignments is essential for understanding the privileged access landscape. This enumeration provides visibility into how many users hold elevated permissions and whether assignments follow the principle of least privilege. Regular review of this inventory helps identify role sprawl and over-provisioned accounts
Current Value
Excessive permissions found
Recommended Value
All privileged role assignments documented and reviewed quarterly. Eligible assignments preferred over permanent
Remediation Steps
Review all role assignments in Entra ID > Roles and administrators for each privileged role. Document all permanent and eligible assignments with business justification. Establish a quarterly access review process to validate continued need for each assignment
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-2 AC-6
MITRE ATT&CK: T1078.004
CisM365: 1.1.3
Unknown EIDPIM-011 PIM Eligible Role Activation History Entra ID Privileged Identity Management Info FAIL Permanent assignments found
Description
Reviewing PIM activation history provides insight into how frequently privileged roles are activated, by whom, with what justification, and for what duration. This audit trail is critical for detecting anomalous privileged access patterns such as activations outside business hours, activations without valid justification, or excessive activation frequency that may indicate a compromised account or insider threat
Current Value
Permanent assignments found
Recommended Value
PIM activation logs reviewed regularly. All activations have valid business justification documented
Remediation Steps
Review PIM activation history via Entra ID > Roles and administrators > Audit logs filtered for PIM operations. Investigate any activations with unusual patterns including off-hours activations, activations by unfamiliar accounts, or activations with vague justifications. Establish a regular review cadence for PIM audit logs as part of security operations
Remediation URL
Compliance Mappings
NIST SP 800-53: AU-3 AU-6
MITRE ATT&CK: T1078.004
Unknown EIDTNT-001 Tenant-Wide Settings Export Entra ID Tenant Configuration Info FAIL Not configured
Description
A comprehensive export of all tenant-wide configuration settings establishes a known-good baseline for change detection and disaster recovery. Without a documented baseline, it is impossible to determine whether current settings have drifted from their intended state or whether an attacker has modified tenant configuration to weaken security controls. This baseline should be captured at initial configuration and updated whenever authorized changes are made.
Current Value
Not configured
Recommended Value
Complete tenant configuration baseline exported and stored in a version-controlled repository with regular snapshots
Remediation Steps
Export all tenant-wide settings using Microsoft Graph API including authorization policies, authentication method policies, consent policies, cross-tenant access settings, and directory settings. Store the export in a secure, version-controlled repository and establish a scheduled process to capture periodic snapshots. Compare current settings against the baseline regularly to detect unauthorized or unintended configuration drift.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-2
Unknown EIDTNT-008 License Inventory and Utilization Entra ID Tenant Configuration Info FAIL Not configured
Description
A comprehensive inventory of assigned licenses and their utilization rates provides visibility into available security features and identifies potential gaps where licensed capabilities are not being used. Organizations may be paying for advanced security features such as Entra ID P2, Microsoft Defender for Identity, or Microsoft Sentinel that are not fully deployed or configured. Understanding the license landscape ensures all purchased security capabilities are activated and utilized.
Current Value
Not configured
Recommended Value
All licenses inventoried with utilization tracking and all security-related licensed features fully deployed and configured
Remediation Steps
Review the license assignment summary in the Microsoft 365 admin center or Entra ID > Licenses > Overview. Identify security-relevant licenses such as Entra ID P1/P2, Microsoft Defender for Identity, and Microsoft 365 E5 Security. Verify that features included in each license are actively configured and deployed, and create a plan to activate any unused security capabilities that are already licensed.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-8
Unknown EIDTNT-009 Administrative Unit Configuration Entra ID Tenant Configuration Info FAIL Excessive permissions found
Description
Administrative units provide delegated administrative scope by grouping users, groups, and devices into logical containers with specific administrators assigned to manage only those objects. Without administrative units, delegated administrators may have broader access than intended, or administrative boundaries may not align with organizational structure. Properly configured administrative units enforce least-privilege delegation and prevent administrative overreach.
Current Value
Excessive permissions found
Recommended Value
Administrative units configured to align with organizational delegation model with restricted management administrative units used for sensitive objects
Remediation Steps
Review existing administrative unit configuration in Entra ID > Roles and administrators > Administrative units. Evaluate whether the current structure aligns with your organizational delegation requirements and whether sensitive objects such as privileged accounts are protected by restricted management administrative units. Create or modify administrative units as needed to ensure administrators can only manage objects within their designated scope.
Remediation URL
Compliance Mappings
NIST SP 800-53: AC-2
Unknown EIDTNT-010 Custom Domain Configuration Entra ID Tenant Configuration Info FAIL Not configured
Description
Custom domains registered in the tenant define the email address and sign-in suffixes used by the organization. Unverified or unauthorized domains may indicate misconfiguration or an attacker attempting to establish a presence in the tenant. Each custom domain should be verified through DNS records and periodically reviewed to ensure all domains are still owned by the organization and that DNS verification records remain intact.
Current Value
Not configured
Recommended Value
All custom domains verified, actively managed, and with DNS verification records intact
Remediation Steps
Review all custom domains registered in Entra ID > Custom domain names and verify that each domain is still owned by the organization and that DNS verification records are properly configured. Remove any domains that are no longer in use or that cannot be verified as organization-owned. Ensure that domain DNS registrations are protected with registrar locks and that domain expiration dates are monitored to prevent unintentional domain loss.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-8
Unknown INTUNE-001 Device compliance policy inventory Intune / Endpoint Management Info FAIL Non-compliant
Description
Device compliance policies define the security baseline requirements that enrolled devices must meet, such as OS version, encryption, and password complexity. Without a comprehensive inventory of these policies, organizations cannot verify that all device platforms and user groups have adequate compliance requirements. Missing or incomplete policies leave devices ungoverned and potentially non-compliant.
Current Value
Non-compliant
Recommended Value
At least one compliance policy per supported platform (Windows, iOS, Android, macOS)
Remediation Steps
Review the current inventory of device compliance policies in the Intune admin center and verify that each supported platform has at least one policy assigned. Create compliance policies for any platforms that lack coverage, defining appropriate requirements for OS version, encryption, and device health. Assign policies to the appropriate user or device groups and ensure no devices fall outside of policy scope.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-8
Unknown INTUNE-004 Configuration profile inventory Intune / Endpoint Management Info FAIL Not configured
Description
Configuration profiles push security settings, restrictions, and feature configurations to enrolled devices. An incomplete inventory of configuration profiles can lead to security gaps where critical settings such as screen lock, Wi-Fi security, or certificate deployment are not applied. Understanding the full scope of configuration profiles is necessary for identifying coverage gaps across the device fleet.
Current Value
Not configured
Recommended Value
Documented inventory of all configuration profiles with clear naming conventions and assignment documentation
Remediation Steps
Export the complete list of configuration profiles from Intune and review each profile's purpose, platform target, and current assignment status. Identify any profiles that are unassigned, conflicting, or redundant and consolidate where appropriate. Establish a naming convention and documentation standard for all profiles to facilitate ongoing management and auditing.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-8
Unknown INTUNE-014 Autopilot configuration Intune / Endpoint Management Info FAIL Not configured
Description
Windows Autopilot provides a zero-touch deployment experience that ensures new devices are configured with the correct security baselines from first boot. A poorly configured or missing Autopilot deployment profile means new devices may be provisioned without critical security settings, creating a window of vulnerability. Reviewing Autopilot configurations ensures consistent and secure device provisioning.
Current Value
Not configured
Recommended Value
Autopilot deployment profile configured for all corporate devices with user-driven or self-deploying mode and Azure AD join
Remediation Steps
Review existing Autopilot deployment profiles and verify they are configured for Azure AD join with appropriate user-driven or self-deploying mode settings. Ensure that the Enrollment Status Page is enabled to prevent users from accessing the desktop before all critical policies and applications are installed. Verify that all corporate device hardware hashes are registered with the Autopilot service and assigned to the appropriate deployment profile.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-2
Unknown INTUNE-020 Device categories and grouping Intune / Endpoint Management Info FAIL Not enrolled
Description
Device categories and dynamic groups in Intune organize managed devices for targeted policy and application deployment. Without a structured categorization scheme, policies may be applied inconsistently, and critical security configurations could miss entire segments of the device population. Proper device grouping enables differentiated security postures for different device roles and user populations.
Current Value
Not enrolled
Recommended Value
Defined device categories aligned with organizational needs; dynamic groups based on device properties for automated policy targeting
Remediation Steps
Review and establish device categories that align with organizational device roles such as executive, standard user, kiosk, or shared device. Create dynamic device groups based on device properties including category, OS, ownership type, and compliance status for automated policy and application targeting. Verify that all policy assignments reference appropriate groups and that no devices fall outside of the grouping structure.
Remediation URL
Compliance Mappings
NIST SP 800-53: CM-8

Compliance Cross-Reference

PlatformCheck IDCheck NameSeverity NIST SP 800-53MITRE ATT&CKCIS Benchmark
Unknown ADACL-001 Critical Object ACL Audit Critical AC-6 AC-6(5) AU-6 T1222.001 T1003.006
Unknown ADACL-002 GenericAll Permissions on Critical Objects Critical AC-6 AC-6(1) AC-3 T1222.001 T1098
Unknown ADACL-004 WriteDACL Permissions on Critical Objects Critical AC-6 AC-6(1) AC-3 AU-12 T1222.001 T1098
Unknown ADACL-005 WriteOwner Permissions on Critical Objects Critical AC-6 AC-6(1) AC-3 T1222.001 T1098
Unknown ADACL-007 Excessive Delegation to Broad Groups Critical AC-6 AC-6(1) AC-3(7) T1222.001 T1069.002
Unknown ADACL-010 Extended Rights Audit Critical AC-6 AC-6(5) AU-12 T1003.006 T1098
Unknown ADACL-015 Shadow Admins Detection Critical AC-6 AC-6(5) AC-2(7) T1222.001 T1098 T1069.002
Unknown ADACL-016 Attack Path Enumeration Critical AC-6 RA-5 CA-8 T1222.001 T1069.002 T1098
Unknown ADCS-002 ESC1 - Enrollee Supplies Subject Alternative Name Critical AC-6 IA-5(2) CM-6 T1649 T1556
Unknown ADCS-003 ESC2 - Any Purpose Extended Key Usage Critical AC-6 IA-5(2) CM-6 T1649 T1556
Unknown ADCS-006 ESC4 - Vulnerable Certificate Template ACLs Critical AC-6 AC-3 IA-5(2) T1649 T1222.001
Unknown ADCS-007 ESC4 - Vulnerable Certificate Template Ownership Critical AC-6 AC-3 T1649 T1222.001
Unknown ADCS-009 ESC6 - EDITF_ATTRIBUTESUBJECTALTNAME2 Flag Critical CM-6 IA-5(2) AC-6 T1649 T1556
Unknown ADCS-010 ESC7 - Vulnerable CA ACLs Critical AC-6 AC-6(1) AC-5 T1649
Unknown ADCS-011 ESC8 - NTLM Relay to AD CS HTTP Endpoints Critical SC-8 SC-23 IA-5(2) T1649 T1557 T1187
Unknown ADDOM-005 Obsolete OS on Domain Controllers Critical SI-2 CM-6 SA-22 T1210 T1078.002 18.3.1
Unknown ADDOM-013 LDAP Signing Requirements Critical SC-8 SC-8(1) SC-23 T1557 2.3.5.1
Unknown ADDOM-015 SMB Signing Requirements Critical SC-8 SC-8(1) T1557 T1021.002 2.3.8.1 2.3.8.2
Unknown ADDOM-016 NTLMv1 Usage Detection Critical IA-5(2) SC-8 T1557 T1003 2.3.8.4
Unknown ADGPO-012 cPassword/GPP Password Detection Critical IA-5(1) SC-28 T1552.006 T1552.001
Unknown ADKERB-002 Kerberoastable with Weak Encryption Critical IA-5(1) SC-12 T1558.003
Unknown ADKERB-004 Unconstrained Delegation - Computers Critical AC-6 T1558.001
Unknown ADKERB-005 Unconstrained Delegation - Users Critical AC-6 T1558.001
Unknown ADMIN-001 Super Admin Account Inventory Critical AC-2(7) AC-6(1) T1078.004 T1087.004 4.1
Unknown ADNET-001 LDAP Signing Required on Domain Controllers Critical SC-8 SC-23 T1557.001
Unknown ADNET-003 SMB Server Signing Required (Domain Policy) Critical SC-8 SC-23 T1557.001
Unknown ADNET-009 Print Spooler Service on Domain Controllers Critical CM-7 T1210 T1557.001
Unknown ADPATH-001 Escalation Paths to Tier-0 Critical AC-5 AC-6 T1098 T1222.001 T1484.001
Unknown ADPATH-002 Transitive Escalation Chains to Tier-0 Critical AC-5 AC-6 T1098 T1222.001 T1484.001
Unknown ADPRIV-001 Domain Admins Enumeration Critical AC-6(1) AC-6(5) AC-2(7) T1078.002 T1069.002 9.2.1
Unknown ADPRIV-002 Enterprise Admins Enumeration Critical AC-6(1) AC-6(5) AC-2(2) T1078.002 T1069.002 9.2.2
Unknown ADPRIV-010 Privileged Users Password Never Expires Critical IA-5(1) AC-2 T1078.002 1.1.4
Unknown ADPRIV-011 Privileged Users Password Not Required Critical IA-5(1) AC-2 T1078.002
Unknown ADPRIV-012 Privileged Users No Kerberos Pre-Auth Critical IA-5(2) AC-2 T1558.004
Unknown ADPRIV-013 Privileged Users Reversible Encryption Critical IA-5(1) SC-28 T1003.006 T1078.002 1.1.1
Unknown ADPRIV-016 Privileged Accounts Weak Passwords Critical IA-5(1) T1110.001 T1110.003 T1078.002
Unknown ADPRIV-020 AdminSDHolder Protected Object Audit Critical AC-6 AC-3 AU-6 T1222.001 T1078.002
Unknown ADPRIV-022 krbtgt Password Age Critical IA-5(1) SC-12 T1558.001 T1550.003 18.3.1
Unknown ADPRIV-023 krbtgt Account Exposure Assessment Critical SC-12 SC-13 T1558.001 T1550.003
Unknown ADPRIV-028 Users with DCSync Rights Critical AC-6(1) AC-3 T1003.006 18.3.1
Unknown ADPWD-010 Users with Blank Passwords Critical IA-5(1) IA-2 T1078.002 T1078
Unknown ADSCRIPT-004 Hardcoded Credentials in Scripts Critical IA-5(1) SC-28 IA-5(7) T1552.001 T1059
Unknown ADSCRIPT-006 Plaintext Passwords in Scripts Critical IA-5(1) SC-28 IA-5(7) T1552.001 T1059
Unknown ADSCRIPT-007 World-Writable Script Permissions Critical AC-3 AC-6 CM-5 T1222.001 T1059
Unknown ADTIER-001 Azure AD Connect Sync Account (MSOL_) Audit Critical AC-6 IA-5 T1003.006 T1078.004
Unknown ADTIER-002 Backup Software Service Accounts in Privileged Groups Critical AC-6 T1078.002
Unknown ADTIER-004 Configuration Management Service Accounts in Privileged Groups Critical AC-6 T1072 T1078.002
Unknown ADTRADE-001 Group Policy Preferences cpassword Leftovers in SYSVOL Critical IA-5 AC-6 T1552.006
Unknown ADTRADE-006 Shadow Credentials (msDS-KeyCredentialLink) on Privileged Principals Critical IA-5 AC-6 AU-6 T1556 T1098
Unknown ADTRADE-007 BadSuccessor dMSA Migration Escalation Surface Critical AC-6 AC-3 T1098 T1078.002
Unknown ADTRUST-004 SID Filtering Status Critical AC-4 AC-6 T1134.005 18.3.1
Unknown ADTRUST-005 SID History Abuse Detection Critical AC-6 AC-6(1) T1134.005
Unknown AUTH-001 2SV Enforcement Critical IA-2(1) IA-2(2) T1078.004 1.1
Unknown AUTH-012 Super Admin 2SV Enrollment Critical IA-2(1) IA-2(11) T1078.004 1.12
Unknown EIDAPP-002 App Registrations with High-Risk API Permissions Critical AC-6 AC-6(1) T1098.002
Unknown EIDAPP-004 First-Party Microsoft Service Principals with Added Credentials Critical IA-5 T1098.001
Unknown EIDAPP-005 Service Principals with High Privileges and Added Credentials Critical AC-6 IA-5 T1098.001
Unknown EIDAPP-014 Application Impersonation Role Holders Critical AC-6(5) T1098.002
Unknown EIDAUTH-002 MFA Registration Status for All Users Critical IA-2(1) IA-2(2) T1078 T1110
Unknown EIDAUTH-005 Users with No MFA Methods Registered Critical IA-2(1) IA-2(2) T1078 T1110
Unknown EIDAUTH-007 FIDO2 Key ROCA Vulnerability Check Critical IA-2(6) RA-5 T1556
Unknown EIDCA-006 Break-Glass Account CA Exclusion Validation Critical AC-2(2) T1078.004
Unknown EIDCA-007 MFA Enforcement via Conditional Access Critical IA-2(1) IA-2(2) T1078 T1110
Unknown EIDCA-008 Legacy Authentication Blocking via CA Critical IA-2 AC-17(2) T1078 T1110.001
Unknown EIDFED-003 Federation Signing Certificate Issuer/Subject Mismatch Critical IA-5(2) T1556.006
Unknown EIDPIM-004 Privileged Role Assignments to Guest Users Critical AC-6(5) IA-8 T1078.004
Unknown EIDPIM-006 Privileged Users Without MFA Critical IA-2(1) IA-2(2) T1078 T1110
Unknown EIDPIM-012 Emergency Access Account Validation Critical AC-2(2) CP-2 T1078.004
Unknown EIDTNT-007 Security Defaults Enabled/Disabled Status Critical IA-2 AC-2 T1078
Unknown EMAIL-001 SPF Record Validation Critical SI-8 SC-7 T1566.001 T1566.002 2.1
Unknown EMAIL-002 DKIM Signing Enabled Critical SI-8 SC-8 T1566.001 T1566.002 2.2
Unknown EMAIL-003 DMARC Policy Audit Critical SI-8 SC-7 T1566.001 T1566.002 T1036.005 2.3
Unknown EMAIL-017 Spoofing and Authentication Protection Critical SI-8 IA-9 T1566.001 T1566.002 T1036.005 2.17
Unknown INTUNE-008 Windows Defender/Antivirus policy audit Critical SI-3 T1562.001
Unknown INTUNE-010 Endpoint Detection and Response configuration Critical SI-4 T1562.001
Unknown INTUNE-018 PowerShell script deployment audit Critical CM-6 T1059.001
Unknown INTUNE-023 Multi-admin approval for destructive device actions Critical AC-3 AC-6 CM-5 T1485 T1561 16.7
Unknown M365AUDIT-001 Unified Audit Log enabled Critical AU-2 AU-3 T1562.008
Unknown M365EXO-006 DKIM/DMARC/SPF validation Critical SI-8 T1566.001
Unknown M365EXO-007 Auto-forwarding policy Critical AC-4 T1114.003
Unknown M365EXO-015 SPF policy published for each domain (MS.EXO.2.2) Critical SI-8 T1566.001
Unknown M365EXO-017 DMARC policy published for each domain (MS.EXO.4.1) Critical SI-8 T1566.001
Unknown OAUTH-003 OAuth Scope Analysis Critical AC-6 AC-3 T1528 T1114.002 T1530 3.3
Unknown OAUTH-008 Domain-Wide Delegation Grants Audit Critical AC-6(1) AC-2(7) T1098.003 T1134.001 3.8
Unknown ADACL-003 GenericWrite Permissions on Critical Objects High AC-6 AC-6(1) AC-3 T1222.001 T1098
Unknown ADACL-006 ForceChangePassword Rights High AC-6 IA-5(1) T1098 T1078.002
Unknown ADACL-009 Machine Account Quota High CM-6 AC-6 T1098 T1136.002
Unknown ADACL-011 Ownership of Critical Objects High AC-6 AC-3 T1222.001
Unknown ADACL-012 Non-Default Domain Root Permissions High AC-6 AC-3 CM-6 T1222.001 T1003.006
Unknown ADACL-013 GPO Link Permissions High AC-6 CM-5 T1484.001
Unknown ADACL-014 GPO Edit Permissions High AC-6 CM-5 CM-6 T1484.001
Unknown ADCS-004 ESC3 - Enrollment Agent Template Abuse Condition 1 High AC-6 IA-5(2) CM-6 T1649
Unknown ADCS-005 ESC3 - Enrollment Agent Template Abuse Condition 2 High AC-6 IA-5(2) CM-6 T1649
Unknown ADCS-008 ESC5 - Vulnerable PKI Object ACLs High AC-6 AC-3 IA-5(2) T1649 T1222.001
Unknown ADCS-012 ESC9 - No Security Extension High IA-5(2) CM-6 AC-6 T1649 T1098
Unknown ADCS-013 ESC11 - RPC Relay Without Encryption High SC-8 SC-8(1) IA-5(2) T1649 T1557
Unknown ADCS-014 ESC13 - Issuance Policy OID Group Link High AC-6 IA-5(2) CM-6 T1649 T1098
Unknown ADCS-016 ESC16 - UPN SAN Misconfiguration High IA-5(2) CM-6 AC-6 T1649 T1556
Unknown ADCS-017 EKEUwu - Extended Key Usage Abuse High IA-5(2) CM-6 T1649
Unknown ADCS-018 CA Auditing Configuration High AU-2 AU-3 AU-12 T1649 T1562.002
Unknown ADDOM-001 Forest Functional Level High CM-6 SI-2 T1078.002 18.3.1
Unknown ADDOM-002 Domain Functional Level High CM-6 SI-2 T1078.002 18.3.1
Unknown ADDOM-004 Domain Controller Inventory High CM-8 CM-8(1) T1018 T1078.002 1.1
Unknown ADDOM-007 AD Replication Health High SC-36 CP-10 T1207 18.3.1
Unknown ADDOM-012 DNS Zone Security High SC-20 SC-21 T1557 T1584.002 18.5.4
Unknown ADDOM-014 LDAP Channel Binding High SC-8 SC-8(1) SC-23 T1557 18.3.5
Unknown ADDOM-017 NTLMv2 Enforcement High IA-5(2) SC-8 T1557 T1003 2.3.8.4
Unknown ADDOM-018 Null Session Enumeration High AC-3 AC-14 T1087.002 T1069.002 2.3.10.5 2.3.10.6
Unknown ADDOM-019 Print Spooler on Domain Controllers High CM-7 CM-7(1) T1187 T1210 5.2
Unknown ADGPO-007 GPO Permission Inconsistencies High AC-3 CM-6 T1484.001 T1222.001
Unknown ADGPO-011 GPO Settings Security Analysis High CM-6 CM-6(1) AC-3 T1484.001 T1484
Unknown ADGPO-013 Scripts in GPOs Analysis High CM-6 SI-7 CM-5 T1059 T1484.001
Unknown ADGPO-015 Scheduled Tasks in GPOs High CM-6 CM-5 AC-6 T1053.005 T1484.001
Unknown ADGPO-017 Restricted Groups Analysis High AC-6 AC-6(1) CM-6 T1484.001 T1098
Unknown ADGPO-018 Audit Policy Configuration via GPO High AU-2 AU-3 AU-12 T1484.001 T1562.002
Unknown ADGPO-021 PowerShell Logging Configuration High AU-2 AU-3 AU-12 SI-4 T1059.001 T1562.002
Unknown ADGPO-023 LAPS GPO Configuration High AC-6 IA-5(1) CM-6 T1078.003 T1021
Unknown ADKERB-001 Kerberoastable Accounts High IA-5(1) T1558.003
Unknown ADKERB-003 AS-REP Roastable Accounts High IA-5(1) T1558.004
Unknown ADKERB-006 Constrained Delegation Analysis High AC-6 T1550.003
Unknown ADKERB-007 Resource-Based Constrained Delegation High AC-6 T1550.003
Unknown ADKERB-008 Protocol Transition Abuse Paths High AC-6 T1550.003
Unknown ADKERB-009 Kerberos Encryption Types High SC-12 SC-13 T1558
Unknown ADLOG-001 Advanced Audit Policy Configured High AU-2 AU-3 AU-12 T1562.002
Unknown ADLOG-002 PowerShell Script Block Logging Enabled High AU-2 SI-4 T1059.001 T1562.002
Unknown ADLOG-004 Process Creation Auditing with Command Line High AU-2 AU-3 T1059 T1218
Unknown ADLOG-005 Microsoft Defender Tamper Protection Policy High SI-3 SI-4 T1562.001
Unknown ADLOG-006 Windows Event Forwarding (WEF) Subscription Manager High AU-4 AU-6 T1070.001
Unknown ADMIN-002 Admin Role Assignments Audit High AC-6(1) AC-2(7) T1078.004 T1098.003 4.2
Unknown ADMIN-004 Inactive/Suspended Admin Accounts High AC-2(3) AC-2(4) T1078.004 T1098 4.4
Unknown ADMIN-010 Groups Settings and External Membership High AC-3 AC-4 T1530 T1213.003 4.10
Unknown ADMIN-013 Super Admin Count High AC-6(1) AC-2(7) T1078.004 4.13
Unknown ADMIN-020 Access to unconfigured third-party apps blocked (GWS.COMMONCONTROLS.10.4) High AC-3 AC-6
Unknown ADNET-002 LDAP Channel Binding Enforced on Domain Controllers High SC-8 SC-23 T1557.001
Unknown ADNET-004 SMB Client Signing Required (Domain Policy) High SC-8 SC-23 T1557.001
Unknown ADNET-005 LLMNR Disabled by Domain Policy High SC-8 T1557.001
Unknown ADNET-007 IPv6 mitm6 Mitigation Posture High SC-7 SC-8 T1557.001 T1557.003
Unknown ADNET-010 WebClient Service Default State on Workstations High CM-7 T1187 T1557.001
Unknown ADPRIV-003 Schema Admins Enumeration High AC-6(1) AC-6(5) T1078.002 T1069.002 9.2.3
Unknown ADPRIV-004 Account Operators Enumeration High AC-6(1) AC-6(5) T1078.002 T1098 9.2.4
Unknown ADPRIV-005 Server Operators Enumeration High AC-6(1) AC-6(5) T1078.002 T1543.003
Unknown ADPRIV-006 Backup Operators Enumeration High AC-6(1) AC-6(5) T1003.003 T1078.002
Unknown ADPRIV-008 DnsAdmins Group Membership High AC-6(1) AC-6(5) T1543.003 T1078.002
Unknown ADPRIV-009 Nested Group Membership Analysis High AC-6(1) AC-2 T1069.002 T1078.002
Unknown ADPRIV-014 Privileged Users DES-Only Kerberos High SC-12 SC-13 T1558 T1078.002
Unknown ADPRIV-015 Privileged Accounts No MFA Indicator High IA-2(1) IA-2(2) T1078.002 1.1.6
Unknown ADPRIV-017 Privileged Accounts Old Passwords High IA-5(1) T1078.002
Unknown ADPRIV-019 Disabled Accounts in Privileged Groups High AC-2(3) AC-2 T1078.002 T1098
Unknown ADPRIV-024 Service Accounts in Privileged Groups High AC-6(1) AC-6(5) T1078.002 T1078
Unknown ADPRIV-025 Computer Accounts in Privileged Groups High AC-6(1) AC-2 T1078.002
Unknown ADPRIV-026 Privileged Users Local Logon on DCs High AC-6(1) AC-3 T1078.002 T1003 2.2.7
Unknown ADPRIV-027 Privileged Users RDP on DCs High AC-6(1) AC-3 AC-17 T1078.002 T1021.001 2.2.26
Unknown ADPRIV-029 Protected Users Group Audit High AC-6 IA-5(2) T1003 T1550.003 T1078.002 18.3.1
Unknown ADPRIV-030 Privileged Users Not in Protected Users High AC-6 IA-5(2) T1003 T1557 T1078.002
Unknown ADPWD-001 Default Domain Password Policy High IA-5(1) T1110.001 T1110.003 1.1.1 1.1.2 1.1.3 1.1.4 1.1.5
Unknown ADPWD-004 Minimum Password Length High IA-5(1) T1110.001 T1110.003 1.1.4
Unknown ADPWD-005 Password Complexity Requirement High IA-5(1) T1110.001 T1110.003 1.1.5
Unknown ADPWD-006 Account Lockout Policy High AC-7 T1110.001 T1110.003 1.2.1 1.2.2 1.2.3
Unknown ADPWD-009 Users with Password Never Expires High IA-5(1) T1078.002 1.1.4
Unknown ADPWD-011 Duplicate Password Hashes High IA-5(1) T1110.002 T1078.002
Unknown ADPWD-012 Passwords in HaveIBeenPwned Database High IA-5(1) T1110.002 T1078.002
Unknown ADPWD-014 Default/Common Passwords High IA-5(1) T1110.001 T1110.003 T1078.002
Unknown ADPWD-016 LAPS Deployment Status High IA-5(1) AC-6 T1078.003 T1003 18.2.1
Unknown ADPWD-021 Account Lockout Threshold High AC-7 T1110.001 T1110.003 1.2.1
Unknown ADSCRIPT-001 NETLOGON Share Permissions High AC-3 AC-6 CM-5 T1059 T1222.001
Unknown ADSCRIPT-002 SYSVOL Share Permissions High AC-3 AC-6 CM-5 T1484.001 T1222.001
Unknown ADSCRIPT-005 LOLBins Usage in Scripts High CM-6 SI-3 SI-7 T1059 T1218
Unknown ADSCRIPT-008 External Resource References High SC-7 SI-7 CM-5 T1059 T1105
Unknown ADSCRIPT-010 UNC Paths to Non-DC Locations High SC-7 AC-3 CM-5 T1187 T1557 T1059
Unknown ADSTALE-005 Obsolete OS Computers High SI-2 CM-6 T1210
Unknown ADSTALE-006 Unsupported OS Versions High SI-2 T1210
Unknown ADTIER-003 Hypervisor / Virtualization Service Accounts in Privileged Groups High AC-6 T1078.002
Unknown ADTIER-005 SQL / Database Service Accounts in Privileged Groups High AC-6 T1078.002
Unknown ADTIER-006 Tier-0 Admin Accounts Outside a Dedicated Tier-0 OU High AC-3 AC-6 T1078
Unknown ADTIER-007 Service Accounts with Interactive Logon Rights via Privileged Group High AC-6 T1078.002 T1003.001
Unknown ADTRADE-002 DCShadow Indicator (Rogue Configuration-Partition Servers) High SI-4 AU-12 T1207
Unknown ADTRADE-004 RODC Password Replication Policy Hygiene High AC-6 T1003.001
Unknown ADTRADE-005 Entra Seamless SSO Computer Account (AZUREADSSOACC$) Key Rotation High IA-5 AC-6 T1558.002 T1550.003
Unknown ADTRADE-008 Key Admins / Enterprise Key Admins Group Membership High AC-6 AC-2 T1556 T1098
Unknown ADTRADE-009 Cert Publishers Group Membership High AC-6 IA-5 T1649 T1556.004
Unknown ADTRADE-010 group Managed Service Account (gMSA) Posture & Password Exposure High IA-5 AC-6 T1552 T1558.003
Unknown ADTRUST-006 Selective Authentication Status High AC-3 AC-4 AC-6 T1482 T1078.002
Unknown ADTRUST-010 Trust Key Age and Rotation High IA-5(1) SC-12 T1482 T1550.003
Unknown AUTH-002 2SV Enrollment Rate High IA-2(1) T1078.004 1.2
Unknown AUTH-004 Password Minimum Length High IA-5(1) T1110.001 T1110.003 1.4
Unknown AUTH-008 Less Secure Apps Access High IA-5(2) T1078.004 T1110 1.8
Unknown AUTH-010 Recovery Options Configuration High IA-5(1) AC-2(4) T1078.004 T1098 1.10
Unknown AUTH-013 Stale Super Admin Accounts High AC-2(3) AC-2(4) T1078.004 1.13
Unknown AUTH-017 Super Admin Account Self-Recovery High IA-4 AC-6(5) T1078.004 T1098 1.15
Unknown AZIAM-001 Subscription-level role assignments audit High AC-2 AC-6
Unknown AZIAM-004 Azure Key Vault access policy audit High AC-6 SC-12
Unknown AZIAM-005 Storage account security settings High SC-8 SC-28
Unknown AZIAM-006 Network Security Group rules audit High SC-7
Unknown COLLAB-004 Chat External Communication High AC-4 SC-7 T1567 T1048 5.4
Unknown COLLAB-008 Calendar External Sharing High AC-3 AC-22 T1530 T1589 5.8
Unknown COLLAB-013 Chat external file sharing disabled (GWS.CHAT.2.1) High AC-4 SC-7
Unknown COLLAB-015 Meeting join restricted to the organization (GWS.MEET.2.1) High AC-3 AC-14 SC-7
Unknown DEVICE-001 MDM Policy Audit High AC-19 CM-6 T1458 T1078.004 6.1
Unknown DEVICE-002 Device Approval Requirements High AC-19(4) IA-3 T1078.004 6.2
Unknown DEVICE-003 Screen Lock Enforcement High AC-11 AC-7 T1458 6.3
Unknown DEVICE-004 Device Encryption Requirements High SC-28 MP-5 T1005 6.4
Unknown DEVICE-005 Compromised Device Blocking High SI-4 AC-19 T1458 6.5
Unknown DEVICE-006 Jailbroken/Rooted Device Policy High SI-7 AC-19 T1398 6.6
Unknown DEVICE-008 Chrome Extension Whitelist/Blocklist High CM-7 CM-11 T1176 6.8
Unknown DRIVE-001 External Sharing Defaults High AC-3 AC-4 T1567 T1537 2.1
Unknown DRIVE-002 Link Sharing Default Settings High AC-3 AC-6 T1530 2.2
Unknown DRIVE-003 Anyone With the Link Sharing Audit High AC-3 AC-22 T1530 T1213 2.3
Unknown DRIVE-006 Shared Drive External Sharing High AC-3 AC-4 T1537 T1567 2.6
Unknown DRIVE-009 Third-Party App Drive Access High AC-3 AC-20 T1530 T1567.002 2.9
Unknown DRIVE-014 Drive SDK API access disabled (GWS.DRIVEDOCS.4.1) High AC-4 AC-3 SC-7
Unknown EIDAPP-003 App Registrations with Added Credentials High IA-5 T1098.001
Unknown EIDAPP-006 Excessive Microsoft Graph Permissions High AC-6(1) T1098.002
Unknown EIDAPP-007 App Registrations with Azure IAM Role Assignments High AC-6
Unknown EIDAPP-011 Consent Grants Analysis High AC-6 T1098.003
Unknown EIDAPP-012 User Consent Settings Policy High AC-6
Unknown EIDAPP-015 OAuth2 Permission Grants Review High AC-6 T1098.003
Unknown EIDAPP-019 Dangling Reply URLs High CM-6 T1566.002
Unknown EIDAUTH-004 Users with Only SMS/Voice MFA Methods High IA-2(1) T1111 T1078
Unknown EIDAUTH-011 Self-Service Password Reset (SSPR) Configuration High IA-5(1)
Unknown EIDAUTH-013 Password Protection (Banned Passwords) Configuration High IA-5(1) T1110.001 T1110.003
Unknown EIDAUTH-015 Legacy Authentication Protocol Usage High IA-2 AC-17(2) T1078 T1110.001
Unknown EIDAUTH-016 ROPC (Resource Owner Password Credentials) Flow Enabled High IA-2 IA-5 T1078
Unknown EIDCA-002 CA Policy Coverage Gap Analysis High AC-2 AC-3 T1078.004
Unknown EIDCA-004 CA Exclusion Group Analysis High AC-6(1) T1078.004
Unknown EIDCA-005 Unprotected Groups in CA Exclusions High AC-6(1) AC-6(5) T1078.004
Unknown EIDCA-009 Device Compliance Requirement in CA High AC-17(2) CM-6
Unknown EIDCA-012 Sign-In Risk-Based CA Policies High IA-2(13) T1078.004 T1110
Unknown EIDCA-013 User Risk-Based CA Policies High IA-2(13) T1078.004
Unknown EIDFED-002 Federation Signing Certificate Validity Period High IA-5(2) T1556.006
Unknown EIDFED-004 Federation Trust Metadata Analysis High IA-8(4) T1556.006
Unknown EIDFED-005 Azure AD Connect Configuration Review High CM-6 T1078.004
Unknown EIDFED-009 AD FS Server Configuration Assessment High CM-6 IA-8(4)
Unknown EIDFED-013 Entra Connect Sync-Client Version Currency High SI-2 SI-2(2) T1195.002 T1078.004
Unknown EIDPIM-003 Permanent Privileged Role Assignments High AC-2(3) AC-6(1) T1078.004
Unknown EIDPIM-005 Privileged Role Assignments to Synced Accounts High AC-6(5) T1078.004
Unknown EIDPIM-007 Privileged Users with Weak Authentication Methods High IA-2(1) T1111 T1078
Unknown EIDPIM-008 Disabled Accounts in Privileged Roles High AC-2(3) T1078.004
Unknown EIDPIM-010 PIM Configuration Audit High AC-2(4) AC-6(1) T1078.004
Unknown EIDPIM-013 Separate Admin Account Enforcement High AC-5 AC-6(2) T1078.004
Unknown EIDTNT-002 User Settings Review High AC-6
Unknown EIDTNT-003 Guest User Access Restrictions High AC-14 T1078.004
Unknown EIDTNT-005 External Collaboration Settings High AC-20
Unknown EIDTNT-006 Azure B2B Cross-Tenant Access Policies High AC-20
Unknown EIDTNT-011 Diagnostic Settings for Audit and Sign-In Logs High AU-2 AU-3 AU-6 T1562.008
Unknown EIDTNT-012 Audit Log Retention Settings High AU-11
Unknown EIDTNT-015 Privileged Partner Delegated Admin Access (GDAP) High AC-2 AC-3 AC-6 PS-7 SA-9
Unknown EMAIL-005 TLS Enforcement High SC-8 SC-8(1) SC-23 T1557 T1040 2.5
Unknown EMAIL-009 Auto-Forwarding Policy High AC-4 SC-7 T1114.003 T1020 2.9
Unknown EMAIL-011 POP/IMAP Access Settings High AC-17(2) CM-7 T1078.004 T1110 2.11
Unknown EMAIL-012 Spam and Phishing Filter Settings High SI-8 SI-3 T1566.001 T1566.002 2.12
Unknown EMAIL-013 Enhanced Pre-Delivery Message Scanning High SI-3 SI-8 T1566.001 T1204.001 2.13
Unknown EMAIL-015 Attachment Safety Settings High SI-3 SI-8 T1566.001 T1204.002 2.15
Unknown EMAIL-016 Links and External Images Protection High SI-3 SI-8 T1566.002 T1204.001 2.16
Unknown EMAIL-022 Mail Forwarding Rule Enumeration High AC-4 SI-4 AU-6 T1114.003 T1020 2.22
Unknown EMAIL-026 Gmail POP and IMAP access disabled (GWS.GMAIL.9.1) High IA-2 AC-17 AC-14
Unknown GROUP-001 External access to Google Groups restricted (GWS.GROUPS.1.1) High AC-3 AC-22 SC-7
Unknown INTUNE-002 Device compliance status overview High CM-6
Unknown INTUNE-003 Non-compliant device enumeration High CM-6
Unknown INTUNE-006 Windows Update for Business ring configuration High SI-2
Unknown INTUNE-007 BitLocker encryption policy audit High SC-28
Unknown INTUNE-009 Attack Surface Reduction rules configuration High CM-7 T1059
Unknown INTUNE-011 Application protection policies (MAM) High AC-19
Unknown INTUNE-015 Disk encryption status High SC-28
Unknown INTUNE-016 Firewall policy configuration High SC-7
Unknown INTUNE-017 Security baselines compliance High CM-6 SI-2
Unknown INTUNE-021 Remote actions audit (wipe, retire, lock) High AU-6 MP-6
Unknown LOG-001 Audit Log Retention Settings High AU-11 AU-4 T1070 T1562.008 7.1
Unknown LOG-002 Alert Center Rules Inventory High SI-4 IR-5 T1562.008 7.2
Unknown M365AUDIT-002 Audit log retention policy High AU-11
Unknown M365DEF-001 Preset security policy audit High SI-3 SI-8
Unknown M365EXO-001 Anti-spam policy audit High SI-8
Unknown M365EXO-002 Anti-phishing policy audit High SI-8 T1566
Unknown M365EXO-003 Anti-malware policy audit High SI-3 T1204
Unknown M365EXO-004 Safe Attachments policy High SI-3
Unknown M365EXO-005 Safe Links policy High SI-3 T1566.002
Unknown M365EXO-009 Mailbox auditing enabled High AU-2 AU-3
Unknown M365EXO-011 OAuth/SMTP AUTH per-mailbox audit High IA-2 T1078
Unknown M365EXO-012 Remote domains auto-forward setting High AC-4 T1114.003
Unknown M365EXO-013 Automatic forwarding to external domains disabled (MS.EXO.1.1) High AC-4 T1114.003
Unknown M365EXO-016 DKIM enabled for all domains (MS.EXO.3.1) High SI-8 T1566.001
Unknown M365EXO-018 DMARC enforcement set to p=reject (MS.EXO.4.2) High SI-8 T1566.001
Unknown M365EXO-020 SMTP AUTH disabled organization-wide (MS.EXO.5.1) High IA-2 T1078 T1110
Unknown M365EXO-024 Data loss prevention solution in use (MS.EXO.8.1) High SI-4 SC-7 T1048
Unknown M365EXO-025 DLP protects PII and sensitive data types (MS.EXO.8.2) High SI-4 SC-7 MP-6 T1048
Unknown M365EXO-026 Email filtered by attachment file type (MS.EXO.9.1) High SI-3 T1204.002
Unknown M365EXO-028 Disallowed attachment file types set (MS.EXO.9.3) High SI-3 T1204.002
Unknown M365EXO-029 Emails scanned for malware (MS.EXO.10.1) High SI-3 T1566.001
Unknown M365EXO-030 Malware emails quarantined or dropped (MS.EXO.10.2) High SI-3 T1566.001
Unknown M365EXO-031 Post-delivery malware scanning enabled (MS.EXO.10.3) High SI-3 T1566.001
Unknown M365EXO-032 Impersonation protection checks enabled (MS.EXO.11.1) High SI-8 T1656 T1566
Unknown M365EXO-035 No IP allow list in connection filter (MS.EXO.12.1) High SC-7 SI-8 T1566.001
Unknown M365EXO-037 Mailbox auditing enabled organization-wide (MS.EXO.13.1) High AU-2 AU-3 T1114
Unknown M365EXO-038 Inbound spam filter enabled (MS.EXO.14.1) High SI-8 T1566
Unknown M365EXO-041 URL block-list comparison enabled (MS.EXO.15.1) High SI-3 T1566.002
Unknown M365EXO-042 Direct download links scanned for malware (MS.EXO.15.2) High SI-3 T1566.002
Unknown M365EXO-044 Required Exchange Online alerts enabled (MS.EXO.16.1) High SI-4 IR-4 AU-6 T1114.003
Unknown M365EXO-046 Purview Audit (Standard) logging enabled (MS.EXO.17.1) High AU-2 AU-3 AU-12 T1562.008
Unknown M365EXO-050 DLP restricts sharing of SSN, ITIN, and credit-card numbers (MS.EXO.8.4) High SC-7 SI-4 AC-4
Unknown M365PP-001 Environment creation restrictions High CM-7
Unknown M365PP-002 DLP policy configuration High AC-4
Unknown M365PP-003 Tenant isolation settings High AC-20
Unknown M365SPO-001 External sharing settings High AC-21
Unknown M365SPO-005 DLP policy configuration High AC-4 SC-7
Unknown M365TEAMS-001 External access settings High AC-20
Unknown M365TEAMS-002 Guest access settings High AC-14
Unknown M365TEAMS-004 Anonymous meeting join settings High AC-14
Unknown OAUTH-001 OAuth App Whitelist/Blocklist High CM-7 AC-3 T1550.001 T1528 3.1
Unknown OAUTH-002 Installed OAuth Apps Inventory High CM-8 CM-11 T1528 T1550.001 3.2
Unknown OAUTH-004 OAuth App Risk Scoring High RA-3 CM-11 T1528 3.4
Unknown OAUTH-005 Unverified App Access Policy High CM-7 SI-7 T1528 T1204.003 3.5
Unknown OAUTH-009 Service Account Key Enumeration High IA-5(1) AC-2(3) T1078.004 T1552.004 3.9
Unknown OAUTH-010 Connected Apps With Sensitive Scopes High AC-3 AC-6 T1530 T1114.002 T1528 3.10
Unknown ADACL-008 OU Delegation Analysis Medium AC-6 AC-6(3) CM-5 T1222.001
Unknown ADCS-015 ESC15 - Application Policies in Schema v1 Templates Medium CM-6 IA-5(2) T1649
Unknown ADDOM-003 Schema Version Identification Medium CM-6 CM-2 T1078.002 18.3.1
Unknown ADDOM-008 Tombstone Lifetime Configuration Medium CP-9 CP-10 T1485
Unknown ADDOM-009 AD Recycle Bin Status Medium CP-9 CP-10 T1485 18.3.1
Unknown ADDOM-010 Sites and Subnets Configuration Medium SC-7 CM-6 T1557
Unknown ADDOM-020 DSRM Password Configuration Medium IA-5(1) AC-6 T1003 T1078.002
Unknown ADGPO-006 GPOs with Broken Links Medium CM-3 CM-6 T1484.001
Unknown ADGPO-008 GPOs Not Applied Due to WMI Filters Medium CM-6 CM-3 T1484.001
Unknown ADGPO-009 GPOs with No Apply Permission Medium CM-6 AC-3 T1484.001
Unknown ADGPO-010 SYSVOL/AD GPO Version Mismatch Medium CM-3 CM-6 SI-7 T1484.001
Unknown ADGPO-014 MSI Packages in GPOs Medium CM-5 CM-7(5) SI-7 T1484.001 T1072
Unknown ADGPO-016 Registry Settings Security Review Medium CM-6 CM-6(1) T1484.001 T1112
Unknown ADGPO-019 Windows Firewall Configuration via GPO Medium SC-7 SC-7(5) CM-6 T1484.001 T1562.004
Unknown ADGPO-020 PowerShell Execution Policy via GPO Medium CM-6 CM-7 SI-7 T1059.001 T1484.001
Unknown ADGPO-022 AppLocker/WDAC Policy Assessment Medium CM-7(5) CM-7(2) SI-7 T1059 T1204.002
Unknown ADKERB-010 Kerberos Ticket Lifetime Medium AC-12
Unknown ADLOG-003 PowerShell Module Logging Enabled Medium AU-2 SI-4 T1059.001
Unknown ADLOG-007 Sysmon Deployment Indicator Medium AU-2 SI-4 T1562.001
Unknown ADMIN-003 Delegated Admin Permissions Review Medium AC-6(1) AC-3 T1098.003 4.3
Unknown ADMIN-005 User Account Inventory Medium AC-2 CM-8 T1087.004 4.5
Unknown ADMIN-006 Stale User Accounts Medium AC-2(3) T1078.004 4.6
Unknown ADMIN-008 Directory Sharing Settings Medium AC-3 AC-22 T1087.004 T1589 4.8
Unknown ADMIN-011 Group Creation Restrictions Medium CM-7 AC-6 T1136.003 4.11
Unknown ADMIN-012 Groups for Business Settings Medium AC-3 AC-4 T1530 T1213.003 4.12
Unknown ADMIN-014 Assured Controls - Access Approvals Enabled Medium AC-3 AC-6 AU-9 T1199
Unknown ADMIN-015 Assured Controls - Support Access Restricted to U.S. Staff Medium AC-3 SA-9 T1199
Unknown ADMIN-016 Assured Controls - Multi-Region Data Processing Disabled Medium SC-7 AC-4 T1530
Unknown ADMIN-017 Internal apps not auto-trusted (GWS.COMMONCONTROLS.10.3) Medium AC-3 AC-6 CM-7
Unknown ADMIN-021 Additional Google services without individual control restricted (GWS.COMMONCONTROLS.16.1) Medium CM-7 AC-6
Unknown ADMIN-022 Early Access applications disabled (GWS.COMMONCONTROLS.16.2) Medium CM-7 SA-22
Unknown ADNET-006 NetBIOS over TCP/IP Configuration Reviewed Medium SC-8 T1557.001
Unknown ADNET-008 WPAD Auto-Discovery Disabled Medium SC-8 T1557.001 T1557.003
Unknown ADPRIV-007 Print Operators Enumeration Medium AC-6(1) CM-7 T1547.012 T1078.002
Unknown ADPRIV-018 Privileged Accounts Never Logged In Medium AC-2(3) AC-2 T1078.002
Unknown ADPRIV-021 AdminCount Orphans Medium AC-6 AC-3 T1078.002
Unknown ADPWD-002 Fine-Grained Password Policy Enumeration Medium IA-5(1) AC-2 T1110.001
Unknown ADPWD-003 FGPP Application Analysis Medium IA-5(1) AC-2 T1110.001 T1078.002
Unknown ADPWD-007 Password History Enforcement Medium IA-5(1) T1110.001 1.1.1
Unknown ADPWD-008 Maximum Password Age Medium IA-5(1) T1078.002 1.1.2
Unknown ADPWD-013 Custom Dictionary Password Check Medium IA-5(1) T1110.001 T1110.003
Unknown ADPWD-015 Password Last Set Age Distribution Medium IA-5(1) T1078.002
Unknown ADPWD-017 LAPS Password Expiration Medium IA-5(1) T1078.003
Unknown ADPWD-019 Azure AD Password Protection Medium IA-5(1) T1110.001 T1110.003
Unknown ADPWD-022 Lockout Observation Window Medium AC-7 T1110.001 T1110.003 1.2.3
Unknown ADSCRIPT-009 Malformed Scripts Medium CM-3 SI-7 T1059
Unknown ADSCRIPT-011 Script Content Analysis Medium SI-3 SI-7 CM-3 T1059 T1027 T1105
Unknown ADSTALE-001 Inactive User Accounts Medium AC-2(3) T1078.002
Unknown ADSTALE-002 Inactive Computer Accounts Medium AC-2(3) T1078.002
Unknown ADSTALE-003 Disabled Accounts with Group Memberships Medium AC-2(3) AC-6
Unknown ADSTALE-004 Expired Passwords Not Disabled Medium IA-5(1) T1078.002
Unknown ADSTALE-007 Orphaned Foreign Security Principals Medium AC-2
Unknown ADSTALE-008 Orphaned SID History Medium AC-2 T1134.005
Unknown ADSTALE-011 DNS Record Staleness Medium CM-2
Unknown ADTRADE-003 Stale BitLocker Recovery Keys Medium AC-6 MP-6 T1552
Unknown ADTRUST-002 Trust Direction Analysis Medium AC-20 AC-4 T1482 T1078.002
Unknown ADTRUST-003 Trust Transitivity Analysis Medium AC-20 AC-4 T1482 T1078.002
Unknown ADTRUST-007 Azure AD Hybrid Trust Security Medium IA-2 AC-20 SC-8 T1078.004 T1649
Unknown ADTRUST-008 Foreign Domain Trust Enumeration Medium AC-20 CA-3 SA-9 T1482 T1078.002
Unknown ADTRUST-009 Orphaned Trust Detection Medium CM-6 AC-20 T1482
Unknown AUTH-003 2SV Method Strength Medium IA-2(1) IA-2(12) T1111 T1078.004 1.3
Unknown AUTH-005 Password Reuse Restriction Medium IA-5(1) T1110.004 1.5
Unknown AUTH-006 Session Duration Medium AC-12 SC-23 T1550.004 1.6
Unknown AUTH-007 SSO Configuration Medium IA-2(6) IA-8 T1078.004 1.7
Unknown AUTH-009 App Passwords Policy Medium IA-5(1) T1078.004 1.9
Unknown AUTH-011 Login Challenge Settings Medium IA-2(13) T1078.004 1.11
Unknown AUTH-014 2SV Enrollment Allowed Medium IA-2(1) T1078.004 1.2
Unknown AUTH-018 Account self-recovery disabled for users and non-super admins (GWS.COMMONCONTROLS.8.2) Medium IA-5 AC-2
Unknown AZIAM-002 Users with Azure IAM roles directly on resources Medium AC-6(1)
Unknown AZIAM-003 Resource group permission analysis Medium AC-6
Unknown AZIAM-007 Azure Policy compliance status Medium CM-6
Unknown AZIAM-009 Custom RBAC role definitions Medium AC-6
Unknown AZIAM-010 Resource locks configuration Medium CM-6
Unknown COLLAB-001 Meet Recording Settings Medium AC-3 AU-14 T1125 5.1
Unknown COLLAB-002 Meet External Participant Settings Medium AC-3 AC-17 T1040 5.2
Unknown COLLAB-003 Meet Anonymous Join Settings Medium AC-3 IA-2 T1040 5.3
Unknown COLLAB-005 Chat History Settings Medium AU-11 AU-3 T1070.008 5.5
Unknown COLLAB-006 Chat Spaces External Access Medium AC-3 AC-4 T1530 T1213 5.6
Unknown COLLAB-009 Calendar External Invitations Medium AC-4 SI-11 T1589 5.9
Unknown COLLAB-012 Meet Host Management Medium AC-3 T1199 6.2
Unknown DEVICE-007 Chrome Browser Management Medium CM-6 CM-7 T1189 T1185 6.7
Unknown DEVICE-009 Chrome OS Device Policies Medium CM-6 SI-2 T1189 6.9
Unknown DEVICE-010 Endpoint Verification Settings Medium AC-19 IA-3 T1078.004 6.10
Unknown DRIVE-004 Shared Drive Creation Restrictions Medium CM-7 AC-6 T1530 2.4
Unknown DRIVE-005 Shared Drive Member Management Medium AC-3 AC-6(1) T1098 2.5
Unknown DRIVE-007 File Ownership Transfer Settings Medium AC-3 MP-5 T1537 2.7
Unknown DRIVE-008 Drive for Desktop Allowed/Blocked Medium SC-28 MP-7 T1530 T1005 2.8
Unknown DRIVE-010 Drive DLP Rules Audit Medium SC-7 SI-4 T1567 T1048 2.10
Unknown DRIVE-011 Target Audience Settings Medium AC-3 AC-6 T1530 2.11
Unknown DRIVE-013 Offline Access Settings Medium SC-28 AC-19 T1005 T1530 2.13
Unknown DRIVE-016 Drive file security update enforced (GWS.DRIVEDOCS.3.1) Medium AC-3 CM-6
Unknown DRIVE-017 Default file access set to private to owner (GWS.DRIVEDOCS.1.8) Medium AC-3 AC-6
Unknown EIDAPP-008 Credential Expiration Monitoring Medium IA-5(1)
Unknown EIDAPP-009 Stale Application Registrations Medium AC-2(3)
Unknown EIDAPP-010 Multi-Tenant Application Analysis Medium AC-20
Unknown EIDAPP-013 Admin Consent Workflow Configuration Medium AC-6
Unknown EIDAPP-018 Change Tracking on App Registrations and Service Principals Medium CM-3 SI-4 T1098
Unknown EIDAPP-020 Group Owner Consent to Applications Blocked Medium AC-6 AC-3 T1528
Unknown EIDAUTH-008 Passwordless Authentication Readiness Medium IA-2(6)
Unknown EIDAUTH-009 Windows Hello for Business Configuration Medium IA-2(6)
Unknown EIDAUTH-010 Temporary Access Pass (TAP) Policy Audit Medium IA-5(1) T1078
Unknown EIDAUTH-012 SSPR Methods and Requirements Medium IA-5(1)
Unknown EIDAUTH-014 Custom Banned Password List Status Medium IA-5(1)
Unknown EIDAUTH-017 Per-User MFA vs Conditional Access MFA Conflict Detection Medium IA-2(1)
Unknown EIDAUTH-018 Microsoft Authenticator Login Context (Application Name and Location) Medium IA-2(1) IA-2(2) T1621
Unknown EIDCA-010 Location-Based CA Policies Audit Medium AC-2(11) SC-7
Unknown EIDCA-011 Named Locations Configuration Review Medium AC-2(11)
Unknown EIDCA-014 Session Controls Audit Medium AC-12 SC-10
Unknown EIDCA-017 High-Risk User Notification to Administrators Medium SI-4 IR-6 AU-6 T1078.004
Unknown EIDCA-018 Managed Device Required for MFA Registration Medium IA-2(1) IA-5 AC-19 T1556.006
Unknown EIDFED-006 Azure AD Connect Sync Scope Audit Medium AC-2
Unknown EIDFED-007 Password Hash Sync Enabled Status Medium IA-5
Unknown EIDFED-008 Pass-Through Authentication Agent Status Medium IA-2 T1556
Unknown EIDFED-010 AD FS Extranet Lockout Settings Medium AC-7
Unknown EIDFED-011 Hybrid Join Configuration Medium IA-3
Unknown EIDPIM-009 Accounts Never Signed In with Active Privileged Role Medium AC-2(3) T1078.004
Unknown EIDPIM-014 Privileged Role Assignment Notification Settings Medium AU-5 SI-4 T1078.004
Unknown EIDTNT-004 Guest Invitation Restrictions Medium AC-14
Unknown EIDTNT-013 Notification Settings Audit Medium AU-5
Unknown EIDTNT-016 Partner Delegated Admin Grant Hygiene (Long-Lived GDAP) Medium AC-2 AC-2(3) PS-7 SA-9
Unknown EMAIL-004 MTA-STS Policy Medium SC-8 SC-8(1) T1557 T1040 2.4
Unknown EMAIL-006 Email Allowlist/Blocklist Review Medium SI-8 SC-7(5) T1566.001 2.6
Unknown EMAIL-007 Inbound Gateway Configuration Medium SI-8 SC-7 T1566.001 T1566.002 2.7
Unknown EMAIL-008 Email Routing Rules Audit Medium SI-4 AU-6 T1114.003 T1020 2.8
Unknown EMAIL-010 Delegate Access Settings Medium AC-3 AC-6(1) T1098.002 T1114.002 2.10
Unknown EMAIL-014 External Recipient Warning Medium AC-4 AT-2 T1048 T1567 2.14
Unknown EMAIL-018 Compliance Rules Audit Medium AC-4 SI-4 SC-7 T1048 T1567 2.18
Unknown EMAIL-019 DLP Rules Configuration Medium AC-4 SC-7 SI-4 T1048 T1567 T1020 2.19
Unknown EMAIL-023 Per-user outbound gateways disabled (GWS.GMAIL.12.1) Medium AC-4 SC-7 SI-8
Unknown EMAIL-024 Gmail Security Sandbox enabled (GWS.GMAIL.16.1) Medium SI-3 SC-44
Unknown EMAIL-025 Gmail mail delegation disabled (GWS.GMAIL.1.1) Medium AC-3 AC-6
Unknown EMAIL-030 Automatic email forwarding disabled (GWS.GMAIL.11.1) Medium AC-4 SC-7
Unknown EMAIL-031 Enhanced pre-delivery message scanning enabled (GWS.GMAIL.15.1) Medium SI-3 SI-8
Unknown GROUP-002 Group owners cannot add external members (GWS.GROUPS.1.2) Medium AC-2 AC-3 SC-7
Unknown GROUP-003 Groups cannot receive mail from outside the org (GWS.GROUPS.1.3) Medium SC-7 SI-8
Unknown INTUNE-005 Configuration profile assignment analysis Medium CM-6
Unknown INTUNE-012 Conditional launch settings Medium AC-19
Unknown INTUNE-013 Device enrollment restrictions Medium IA-3
Unknown INTUNE-019 Win32 app deployment security review Medium CM-11
Unknown INTUNE-022 OneDrive sync restrictions Medium AC-19
Unknown LOG-003 Activity Rules Coverage Analysis Medium SI-4(5) AU-6 T1562.008 7.3
Unknown LOG-004 Data Export Settings Medium AC-4 MP-5 T1567 T1537 7.4
Unknown LOG-005 Admin Email Alerts Configuration Medium SI-4 AU-5 T1562.008 7.5
Unknown M365AUDIT-003 Audit log search capability Medium AU-6
Unknown M365DEF-002 Alert policy inventory Medium SI-4 AU-5
Unknown M365DEF-003 Threat intelligence configuration Medium SI-5
Unknown M365EXO-008 Transport rules inventory and analysis Medium AC-4
Unknown M365EXO-010 External sender warnings Medium SI-8
Unknown M365EXO-014 Approved sending IP list maintained (MS.EXO.2.1) Medium SI-8 T1566.001
Unknown M365EXO-019 DMARC aggregate report contact configured (MS.EXO.4.3) Medium SI-8 AU-6 T1566.001
Unknown M365EXO-021 Contact folder sharing not open to all domains (MS.EXO.6.1) Medium AC-4 AC-21 T1087
Unknown M365EXO-022 Calendar detail sharing not open to all domains (MS.EXO.6.2) Medium AC-4 AC-21 T1087
Unknown M365EXO-023 External sender warning implemented (MS.EXO.7.1) Medium SI-8 T1566
Unknown M365EXO-027 Attachment filter assesses true file type (MS.EXO.9.2) Medium SI-3 T1036.008
Unknown M365EXO-033 User safety tips/warnings displayed (MS.EXO.11.2) Medium SI-8 T1566
Unknown M365EXO-034 AI-based phishing detection in use (MS.EXO.11.3) Medium SI-8 T1566
Unknown M365EXO-036 Connection filter safe list disabled (MS.EXO.12.2) Medium SC-7 SI-8 T1566.001
Unknown M365EXO-039 Spam routed to junk or quarantine (MS.EXO.14.2) Medium SI-8 T1566
Unknown M365EXO-040 No allowed domains in anti-spam policy (MS.EXO.14.3) Medium SI-8 T1566
Unknown M365EXO-043 User click tracking enabled (MS.EXO.15.3) Medium AU-2 SI-4 T1566.002
Unknown M365EXO-045 Alerts routed to monitored destination (MS.EXO.16.2) Medium SI-4 IR-4 AU-6 T1114.003
Unknown M365EXO-047 Purview Audit (Premium) logging enabled (MS.EXO.17.2) Medium AU-2 AU-3 AU-12 T1114
Unknown M365EXO-048 Audit log retention meets minimum (MS.EXO.17.3) Medium AU-11 T1070
Unknown M365EXO-049 Executable attachment types blocked (MS.EXO.9.5) Medium SI-3 SC-7
Unknown M365SPO-002 Guest access expiration Medium AC-2(3)
Unknown M365SPO-003 Default sharing link type Medium AC-3
Unknown M365SPO-004 Site creation restrictions Medium CM-6
Unknown M365TEAMS-003 External meeting participant settings Medium AC-20
Unknown M365TEAMS-005 Recording and transcription policies Medium AU-2
Unknown M365TEAMS-006 Messaging policies (external communication) Medium AC-20
Unknown M365TEAMS-007 App permission policies Medium CM-7
Unknown M365TEAMS-008 File sharing settings in Teams Medium AC-21
Unknown OAUTH-006 API Access Control Medium AC-3 AC-17 T1106 3.6
Unknown OAUTH-007 Marketplace App Installation Restrictions Medium CM-11 CM-7 T1195.002 T1204.003 3.7
Unknown ADDOM-011 Site Link Configuration Low SC-36 CM-6 T1557
Unknown ADGPO-002 Empty GPOs Low CM-2 CM-7 T1484.001
Unknown ADGPO-003 Unlinked GPOs Low CM-2 CM-7 T1484.001
Unknown ADGPO-004 Disabled GPOs with Content Low CM-2 CM-6 T1484.001
Unknown ADGPO-005 Duplicated GPOs Low CM-2 CM-3 T1484.001
Unknown ADGPO-024 GPO WMI Filter Review Low CM-6 CM-3 T1484.001
Unknown ADMIN-007 OU Structure Review Low CM-6 AC-2 T1087.004 4.7
Unknown ADMIN-009 User Profile Visibility Low AC-22 AC-3 T1589.002 4.9
Unknown ADMIN-018 Data at-rest region configured (GWS.COMMONCONTROLS.15.1) Low SC-28 AC-3
Unknown ADMIN-019 Data processing restricted to storage region (GWS.COMMONCONTROLS.15.2) Low SA-9 AC-4
Unknown ADPWD-018 Windows LAPS vs Legacy LAPS Low IA-5(1) SC-28 T1078.003
Unknown ADSTALE-009 Abandoned OUs Low CM-2
Unknown ADSTALE-010 Printer Objects Low CM-8 T1557
Unknown AUTH-015 2SV Enrollment Grace Period Low IA-2(1) T1078.004 1.2
Unknown AUTH-016 Advanced Protection Self-Enrollment Low IA-2(1) T1078.004 1.14
Unknown COLLAB-007 Chat App Installation Settings Low CM-7 CM-11 T1195.002 5.7
Unknown COLLAB-010 Calendar Appointment Slots External Visibility Low AC-22 T1589.002 5.10
Unknown COLLAB-011 Meet External Participant Labeling Low AC-22 T1199 6.1
Unknown COLLAB-014 Chat space history is on (GWS.CHAT.3.1) Low AU-11 AU-12
Unknown COLLAB-016 Meet automatic transcription off by default (GWS.MEET.5.2) Low SI-12 SC-28
Unknown COLLAB-017 Calendar external interoperability managed (GWS.CALENDAR.3.1) Low AC-4 SC-7
Unknown COLLAB-018 Calendar appointment payments disabled (GWS.CALENDAR.4.1) Low CM-7
Unknown COLLAB-019 Meet automatic recording off by default (GWS.MEET.5.1) Low SI-12 SC-28
Unknown DEVICE-011 Company-Owned Device Inventory Low CM-8 PM-5 T1087 6.11
Unknown DRIVE-012 Drive Add-ons Settings Low CM-7 CM-11 T1195.002 2.12
Unknown DRIVE-015 Drive external-file warning enabled (GWS.DRIVEDOCS.1.9) Low AC-22 SI-10
Unknown EIDTNT-014 User Password Expiration Disabled (Passwords Never Expire) Low IA-5 IA-5(1)
Unknown EMAIL-020 Gmail Confidential Mode Low AC-4 SC-28 T1114.002 2.20
Unknown EMAIL-021 S/MIME Settings Low SC-8(1) SC-12 T1557 T1040 2.21
Unknown EMAIL-027 Gmail user email/contacts import disabled (GWS.GMAIL.8.1) Low AC-4 SC-7
Unknown EMAIL-028 Google Workspace Sync for Outlook disabled (GWS.GMAIL.10.1) Low AC-3 CM-7
Unknown EMAIL-029 Gmail spam-override sender lists reviewed (GWS.GMAIL.18.1) Low SI-8 SC-7
Unknown GROUP-004 Group creation restricted to administrators (GWS.GROUPS.2.1) Low AC-2 AC-6 PM-10
Unknown GROUP-005 Group conversation visibility defaults to members (GWS.GROUPS.3.1) Low AC-3 AC-22
Unknown GROUP-006 Groups are visible in the directory (GWS.GROUPS.4.1) Low AC-22 AU-6
Unknown LOG-006 Reporting API Access Low AU-9 AC-3 T1530 7.6
Unknown ADCS-001 CA Server Inventory Info CM-8 CM-8(1) IA-5(2) T1649
Unknown ADCS-019 Certificate Template Enumeration Info CM-8 CM-8(1) IA-5(2) T1649
Unknown ADDOM-006 FSMO Role Holder Identification Info CP-2 CM-8 T1018
Unknown ADGPO-001 GPO Inventory with Link Status Info CM-8 CM-8(1) T1484.001
Unknown ADKERB-011 Computer SPN Audit Info CM-8
Unknown ADPWD-020 BitLocker Recovery Keys in AD Info SC-28 SC-28(1) T1005
Unknown ADSCRIPT-003 Logon Script Inventory Info CM-8 CM-8(1) CM-3 T1059
Unknown ADTRUST-001 Trust Relationships Enumeration Info AC-20 CA-3 T1482
Unknown ADTRUST-011 Trust Hierarchy Visualization Info AC-20 PL-2 T1482
Unknown AZIAM-008 Management group structure review Info AC-2
Unknown EIDAPP-001 Application Registration Inventory Info CM-8
Unknown EIDAPP-016 Managed Identity Inventory and Permissions Info CM-8
Unknown EIDAPP-017 Service Principal Sign-In Activity Info AU-6
Unknown EIDAUTH-001 Authentication Methods Policy Audit Info IA-2
Unknown EIDAUTH-003 MFA Method Distribution Analysis Info IA-2(1)
Unknown EIDAUTH-006 FIDO2 Security Key Inventory and Audit Info IA-2(6)
Unknown EIDCA-015 CA What-If Simulation for Attack Scenarios Info CA-8 T1078.004
Unknown EIDCA-016 CA Policy Documentation Export Info CM-2 CM-6
Unknown EIDFED-001 Federated Domain Enumeration Info CM-8
Unknown EIDFED-012 Cloud-Only vs Synced Account Analysis Info AC-2
Unknown EIDPIM-001 Global Administrator Enumeration Info AC-2 AC-6(5) T1078.004
Unknown EIDPIM-002 All Privileged Role Assignments Info AC-2 AC-6 T1078.004
Unknown EIDPIM-011 PIM Eligible Role Activation History Info AU-3 AU-6 T1078.004
Unknown EIDTNT-001 Tenant-Wide Settings Export Info CM-2
Unknown EIDTNT-008 License Inventory and Utilization Info CM-8
Unknown EIDTNT-009 Administrative Unit Configuration Info AC-2
Unknown EIDTNT-010 Custom Domain Configuration Info CM-8
Unknown INTUNE-001 Device compliance policy inventory Info CM-8
Unknown INTUNE-004 Configuration profile inventory Info CM-8
Unknown INTUNE-014 Autopilot configuration Info CM-2
Unknown INTUNE-020 Device categories and grouping Info CM-8
⚔ Guerrilla Campaign Report  |  2026-07-11 15:20:21 UTC  |  Generated by Guerrilla v2.0.0  |  599 checks across 3 platforms  |  Score: 0/100 (OVERRUN)
By Jim Tyler, Microsoft MVP  |  GitHub  |  LinkedIn  |  YouTube