EXEMPLE : entreprise et chiffres inventés. Ce document montre la forme exacte du rapport livré, ce n’est pas un audit réel.
Les 5 lectures du même audit : Pour le dirigeant · Pour le RSSI · Pour l'informaticien · Pour le DPO / la conformité · Pour l'assureur / le donneur d'ordre
SYAGA Audit
Bericht Drittbestätigung
Ohne Einsicht in Ihre Daten · Ref. SYAGA-DEMO-QUESTIONNAIRE-0001
Feststellung zur Microsoft-365-SicherheitslageDatiertes und überprüfbares Dokument
Geprüfte Einheit
Entreprise Démonstration (exemple, non client) (tenant d3m0a1b2-c3d4-4e5f-8a9b-0c1d2e3f4a5b)
Datum des Audits
17 juillet 2026
Aussteller
SYAGA CONSULTING · SIREN 518 489 471
Überprüfbar in
Ihren eigenen Microsoft-Audit-Protokollen · syaga.eu
Das Urteil, vor der Beweisakte

Vier strukturelle Schwachstellen gefährden Ihre Versicherbarkeit Microsoft 365.

Ihre 85 Abweichungen sind nicht 85 Probleme: Sie lassen sich auf vier Grundursaches zurückführen. Behandeln Sie sie der Reihe nach, und Sie neutralisieren den Großteil des Risikos mit gebündeltem Aufwand, ohne alles neu zu machen.

Versicherbarkeitslage
70/100
Zu stärken
solide Grundlagen, aber es bleiben offene Schwachstellen

Ein Nachweis, drei Leser. Diese Akte ist so konzipiert, dass sie einem Cyber-Versicherer (Zeichnungsformat), einem Auftraggeber, der von Ihnen den Nachweis Ihrer Sicherheitslage verlangt (Weitergabe in der Lieferkette, NIS2 Art. 21 - teilbare Version), sowie einem Wirtschaftsprüfer oder externen Auditor vorgelegt werden kann. Jede nachstehende Feststellung ist in Ihren eigenen Microsoft-Protokollen überprüfbar: belastbar, nicht deklarativ.

195
Konforme Kontrollpunkte
4
Grundursachen, die die Versicherbarkeit belasten
85
Bisher festgestellte Nichtkonformitäten
Was heute nachweisbar ist

195 konforme(r) Kontrollpunkt(e) von 280 bewerteten Kontrollpunkten - die überprüfbare Basis, die einem Versicherer bereits Punkt für Punkt mit Nachweis vorgelegt werden kann. Sicherheitslage bewertet mit C, ohne Beschönigung, allein auf Basis der bewerteten Kontrollpunkte.

Was Ihre Akte gefährdet

85 festgestellte Nichtkonformität(en) und 63 nicht gemessene(r) Kontrollpunkt(e) bleiben eine Gefährdung ohne belastbaren Nachweis: Solange die nachstehenden Grundursachen nicht behoben sind, kann diese Gefährdung nicht bescheinigt werden.

I

Konfigurationshärtung

34 gebündelte Abweichung(en) - Konfiguration & Compliance
Die Gefährdung: eine ungehärtete Basis vergrößert die Angriffsfläche lautlos, ohne sichtbaren Alarm.
Heute: In diesem Themenfeld sind die folgenden Compliance-Anforderungen nicht erfüllt: S'assurer que les comptes prioritaires bénéficient des paramètres prédéfinis de protection stricte (Strict protection) ; S'assurer que la synchronisation OneDrive est restreinte pour les appareils non gérés ; Seuls les utilisateurs ayant le rôle Présentateur sont autorisés à présenter dans les réunions Teams ; Les comptes d'accès d'urgence (break-glass) ne doivent pas être bloqués.
Was das Audit festgestellt hat: Sensibiliser les utilisateurs aux bonnes pratiques élémentaires (hameçonnage, gestion des mots de passe, MFA, signalement) par des campagnes récurrentes et des simulations ; mesure principalement organisationnelle. Appliquer le preset de protection Strict aux comptes prioritaires pour leur garantir le niveau de filtrage le plus élevé. Bloquer la synchronisation OneDrive depuis les appareils non gérés via une politique d'accès conditionnel (AllowLimitedAccess) limitant l'accès au web sans téléchargement/synchronisation.
Aufwand MittelWirkung Moderat
II

Identität und Zugriff

31 gebündelte Abweichung(en) - Identität & Zugriff
Die Gefährdung: die Übernahme eines Kontos ist der häufigste Einstiegspunkt für einen Angriff; dies ist das einzige Thema, bei dem ein begrenzter Aufwand eine ganze Risikoklasse auf einmal schließt.
Heute: In diesem Themenfeld sind die folgenden Compliance-Anforderungen nicht erfüllt: S'assurer que l'authentification multifacteur est activée pour tous les utilisateurs ; La MFA DOIT être imposée pour tous les utilisateurs ; S'assurer que le flux de consentement administrateur est activé ; S'assurer que tous les utilisateurs membres sont 'compatibles MFA' (MFA capable).
Was das Audit festgestellt hat: Le MFA doit être exigé pour l'ensemble des utilisateurs via une politique d'accès conditionnel afin de bloquer la grande majorité des attaques par compromission d'identité. Activer le flux de consentement administrateur dans Entra ID pour qu'une demande d'accès bloquée côté utilisateur soit routée vers un réviseur plutôt que simplement rejetée sans suite. Au moins deux comptes d'accès d'urgence (break-glass) cloud-only en *.onmicrosoft.com, exclus des politiques CA bloquantes, doivent être définis pour éviter un verrouillage total de l'administration.
Aufwand GeringWirkung Erheblich
III

Überwachung und Protokollierung

14 gebündelte Abweichung(en) - Erkennung & Überwachung
Die Gefährdung: ohne aktive Erkennung und vollständige Protokolle kann ein Angriff gelingen, ohne rechtzeitig blockiert, erkannt oder im Nachhinein nachgewiesen zu werden: ein direkter Nachteil im Schadensfall, bei einer behördlichen Kontrolle oder in einem Versicherungsfall.
Heute: In diesem Themenfeld sind die folgenden Compliance-Anforderungen nicht erfüllt: L'action pour le spam à haut niveau de confiance (High Confidence Spam) est définie sur Mettre le message en quarantaine ; Les liens sûrs (Safe Links) ne sont pas contournés ; L'action en cas d'usurpation de domaine (Domain Impersonation) est définie sur déplacer vers la quarantaine ; L'action en cas d'usurpation d'identité d'utilisateur (User impersonation) est définie sur déplacer vers la quarantaine.
Was das Audit festgestellt hat: Inclure tous les utilisateurs dans la protection Defender for Office 365 via le preset de sécurité Standard ou Strict. Configurer la politique Anti-courrier indésirable (anti-spam) pour appliquer le réglage cible : « Durée de rétention en quarantaine portée à 30 jours ». Configurer la politique Anti-hameçonnage pour appliquer le réglage cible : « Mise en quarantaine des messages détectés comme hameçonnage ».
Aufwand GeringWirkung Hoch
IV

Datenexponierung

6 gebündelte Abweichung(en) - Daten & Exponierung
Die Gefährdung: ein Datum, das das Unternehmen ohne Schutzmechanismus verlässt, ist der banalste und zugleich teuerste Weg für ein Datenleck, sowohl im Image als auch regulatorisch.
Heute: In diesem Themenfeld sind die folgenden Compliance-Anforderungen nicht erfüllt: S'assurer que les stratégies d'étiquettes de confidentialité Information Protection sont publiées ; S'assurer que le partage de contenu OneDrive est restreint ; Une solution de prevention des pertes de données (DLP) DOIT être utilisée ; L'action de la politique personnalisée DEVRAIT être configurée pour bloquer le partage d'informations sensibles avec tout le monde.
Was das Audit festgestellt hat: Publier au moins une politique d'étiquettes de sensibilité (sensitivity labels) auprès des utilisateurs ou groupes cibles, afin de permettre la classification et la protection des documents selon leur niveau de confidentialité. Restreindre le partage de contenu OneDrive au niveau le plus restrictif approprié (au plus 'Invités existants'), sachant qu'OneDrive peut être plus restrictif que SharePoint mais jamais plus permissif. Mettre en place une solution de prévention des pertes de données (DLP) couvrant Exchange Online.
Aufwand MittelWirkung Hoch

Nichtkonformitäten, die die Versicherbarkeit belasten

Reale Feststellungen im Zusammenhang mit den Grundursachen
ReferenzKontrollpunktSchweregrad
M365SEC:2.4.2M365SAT, Monkey365MEx 2.4.2 - Priority accounts do not have 'Strict protection' presets appliedHoch
M365SEC:7.3.2M365SAT, Monkey365Sicherstellen, dass die OneDrive-Synchronisierung für nicht verwaltete Geräte eingeschränkt istHoch
MT.1037MaesterOnly users with Presenter role are allowed to present in Teams meetingsHoch
MT.1034MaesterNotfallzugriffsbenutzer sollten nicht blockiert werden.Zu beheben
M365SEC:5.2.2.2M365SAT, Monkey365Sicherstellen, dass die Multifaktor-Authentifizierung für alle Benutzer aktiviert istKritisch
CISA:MS.AAD.3.2Maester, ScubaGearIf phishing-resistant MFA has not been enforced, an alternative MFA method SHALL be enforced for all users.Kritisch
M365SEC:5.1.5.2M365SAT, Maester, Monkey365Sicherstellen, dass der Admin-Consent-Workflow aktiviert istHoch
M365SEC:5.2.3.4M365SAT, Monkey365Sicherstellen, dass alle Mitgliedsbenutzer 'MFA-fähig' (MFA capable) sindHoch
ORCA.140MaesterDie Aktion fuer Spam mit hoher Zuverlaessigkeit (High Confidence Spam) ist auf 'Nachricht unter Quarantaene stellen' festgelegt.Hoch
ORCA.189.2MaesterSafe Links is not bypassed.Hoch

Blinde Flecken: solange nicht gemessen, nicht durch einen belastbaren Nachweis abgedeckt

63 nicht gemessene(r) Kontrollpunkt(e) im Katalog
ReferenzKontrollpunktStatus
M365SEC:1.3.5M365SAT, Maester, Monkey365Sicherstellen, dass der interne Phishing-Schutz für Forms aktiviert istNicht gemessen
M365SEC:2.4.1M365SAT, Monkey365Sicherstellen, dass der Schutz von Prioritätskonten (Priority account protection) aktiviert und konfiguriert istNicht gemessen
M365SEC:3.2.1M365SAT, Monkey365Sicherstellen, dass die Richtlinien zur Verhinderung von Datenverlust (DLP) aktiviert sindNicht gemessen
M365SEC:7.2.7M365SAT, Maester, Monkey365Sicherstellen, dass die Linkfreigabe in SharePoint und OneDrive eingeschränkt istNicht gemessen
CISA:MS.AAD.4.1Maester, ScubaGearSicherheitsprotokolle MÜSSEN zur Überwachung an das Security Operations Center (SOC) der Behörde gesendet werden.Nicht gemessen
M365SEC:6.2.1M365SAT, Monkey365Exchange-E-Mail-Weiterleitung blockiert und deaktiviertNicht gemessen
CISA:MS.EXO.13.1Maester, ScubaGearMailbox auditing SHALL be enabled.Nicht gemessen
M365SEC:4.2Monkey365Devices enrollment personal devices not blockedNicht gemessen
M365SEC:7.2.11Maester, Monkey365Ensure the SharePoint default sharing link permission is setNicht gemessen
MT.1027MaesterNo Service Principal with Client Secret and permanent role assignment on Control Plane.Nicht gemessen
Die Reihenfolge zum Aufbau der Versicherbarkeitsakte
Zuerst
Die grundkonfiguration. Das stärkste Verhältnis von ausgeräumtem Risiko zu Aufwand. Solange dies nicht erledigt ist, schützt der Rest ein Haus, dessen Tür offen bleibt.
Dann
Die identität. Sobald der erste Hebel erreicht ist, verringern wir die Angriffsfläche, über die sich das Risiko materialisiert.
Dann
Die überwachung. Bleibt, diese Ergebnisse dauerhaft zu verankern: Governance, regelmäßige Überprüfungen und aufbewahrte Nachweise, damit die Position über die Zeit trägt und nicht nur am Tag der Prüfung.
In Konsolidierung
Verbleibende grundlagenvorhaben. die externe Exponierung: zu konsolidieren, sobald die oberen Prioritäten der Liste erledigt sind.

Was dieser Weg vermeidet

Unterbrechung. ein gekapertes Konto, das die Tätigkeit lahmlegt.
Leck. Kundendaten, die ohne Spur nach außen dringen.
Nichtkonformität. eine bei einer Kontrolle belastbare DSGVO- oder NIS2-Abweichung.
Versicherungsverweigerung. ein mangels Nachweisen nicht gedeckter Schadensfall.

Die 195 konformen Kontrollpunkte, einzeln aufgeführt

Sie müssen uns eine Gesamtzahl nicht glauben. Jede Zeile unten trägt ihre Kennung und das öffentliche Regelwerk, auf dem sie beruht: Ihr Versicherer, Ihr Auftraggeber oder Ihr Wirtschaftsprüfer kann sie einzeln in Ihren eigenen Microsoft-Protokollen überprüfen.
ReferenzKontrollpunktSchweregrad
ANSSI R13ANSSI/NIS2 ANSSI R13ANSSI R13Konform
ANSSI R14ANSSI/NIS2 ANSSI R14ANSSI R14Konform
ANSSI R16ANSSI/NIS2 ANSSI R16ANSSI R16Konform
ANSSI R24ANSSI/NIS2 ANSSI R24ANSSI R24Konform
ANSSI R29ANSSI/NIS2 ANSSI R29ANSSI R29Konform
ANSSI R36ANSSI/NIS2 ANSSI R36ANSSI R36Konform
ANSSI R5ANSSI/NIS2 ANSSI R5ANSSI R5Konform
ANSSI R8ANSSI/NIS2 ANSSI R8ANSSI R8Konform
M365SEC:5.1.1.1M365SAT CISMAz5111CISMAz 5.1.1.1 - The Security Defaults are enabled on Azure Active Directory TenantKonform
M365SEC:6.1.4M365SAT CISMEx614MEx 6.1.4 - Des boîtes aux lettres portent-elles 'AuditBypassEnabled', qui les exclut du journal d'audit ?Konform
CISA:MS.EXO.10.1Maester CISA.MS.EXO.10.1Emails SHALL be scanned for malware.Konform
CISA:MS.EXO.10.2Maester CISA.MS.EXO.10.2Emails identified as containing malware SHALL be quarantined or dropped.Konform
CISA:MS.EXO.10.3Maester CISA.MS.EXO.10.3Email scanning SHALL be capable of reviewing emails after delivery.Konform
CISA:MS.EXO.11.1Maester CISA.MS.EXO.11.1Impersonation protection checks SHOULD be used.Konform
CISA:MS.EXO.11.2Maester CISA.MS.EXO.11.2User warnings, comparable to the user safety tips included with EOP, SHOULD be displayed.Konform
CISA:MS.EXO.11.3Maester CISA.MS.EXO.11.3The phishing protection solution SHOULD include an AI-based phishing detection tool comparable to EOP Mailbox Intelligence.Konform
CISA:MS.EXO.12.1Maester CISA.MS.EXO.12.1IP allow lists SHOULD NOT be created.Konform
CISA:MS.EXO.14.1Maester CISA.MS.EXO.14.1A spam filter SHALL be enabled.Konform
CISA:MS.EXO.14.2Maester CISA.MS.EXO.14.2Spam and high confidence spam SHALL be moved to either the junk email folder or the quarantine folder.Konform
CISA:MS.EXO.14.3Maester CISA.MS.EXO.14.3Allowed domains SHALL NOT be added to inbound anti-spam protection policies.Konform
CISA:MS.EXO.15.1Maester CISA.MS.EXO.15.1URL comparison with a block-list SHOULD be enabled.Konform
CISA:MS.EXO.15.2Maester CISA.MS.EXO.15.2Direct download links SHOULD be scanned for malware.Konform
CISA:MS.EXO.15.3Maester CISA.MS.EXO.15.3User click tracking SHOULD be enabled.Konform
CISA:MS.EXO.16.1Maester CISA.MS.EXO.16.1Alerts SHALL be enabled.Konform
CISA:MS.EXO.16.2Maester CISA.MS.EXO.16.2Alerts SHOULD be sent to a monitored address or incorporated into a security information and event management (SIEM) system.Konform
CISA:MS.EXO.17.1Maester CISA.MS.EXO.17.1Microsoft Purview Audit (Standard) logging SHALL be enabled.Konform
CISA:MS.EXO.2.1Maester CISA.MS.EXO.2.1A list of approved IP addresses for sending mail SHALL be maintained.Konform
EIDSCA.AF01Maester EIDSCA.AF01Authentication method - FIDO2 security key - State.Konform
EIDSCA.AF02Maester EIDSCA.AF02Authentication Method - FIDO2 security key - Allow self-service set up.Konform
EIDSCA.AF03Maester EIDSCA.AF03Authentication method - FIDO2 security key - Enforce attestation.Konform
EIDSCA.AF04Maester EIDSCA.AF04Authentication method - FIDO2 security key - Enforce key restrictions.Konform
EIDSCA.AF05Maester EIDSCA.AF05Authentication method - FIDO2 security key - Restricted.Konform
EIDSCA.AF06Maester EIDSCA.AF06Authentication Method - FIDO2 security key - Restrict specific keys.Konform
EIDSCA.AG01Maester EIDSCA.AG01Authentication method - General settings - Manage migration.Konform
EIDSCA.AG02Maester EIDSCA.AG02Authentication method - General settings - Report suspicious activity - State.Konform
EIDSCA.AM01Maester EIDSCA.AM01Authentication method - Microsoft Authenticator - State.Konform
EIDSCA.AM02Maester EIDSCA.AM02Authentication method - Microsoft Authenticator - Allow use of Microsoft Authenticator OTP.Konform
EIDSCA.AM03Maester EIDSCA.AM03Authentication Method - Microsoft Authenticator - Require number matching for push notifications.Konform
EIDSCA.AM04Maester EIDSCA.AM04Authentication Method - Microsoft Authenticator - Included users/groups of number matching for push notifications.Konform
EIDSCA.AM06Maester EIDSCA.AM06Authentication Method - Microsoft Authenticator - Show application name in push and passwordless notifications.Konform
EIDSCA.AM07Maester EIDSCA.AM07Authentication method - Microsoft Authenticator - Users and groups included for showing the application name in push and passwordless notifications.Konform
EIDSCA.AM09Maester EIDSCA.AM09Authentication Method - Microsoft Authenticator - Show geographic location in push and passwordless notifications.Konform
EIDSCA.AM10Maester EIDSCA.AM10Authentication method - Microsoft Authenticator - Users and groups included for showing the geographic location in push and passwordless notifications.Konform
EIDSCA.AP01Maester EIDSCA.AP01Default authorization settings - Self-service password reset enabled for administrators.Konform
EIDSCA.AP04Maester EIDSCA.AP04Default Authorization Settings - Guest invite restrictions.Konform
EIDSCA.AP06Maester EIDSCA.AP06Default Authorization Settings - User can join the tenant by email validation.Konform
EIDSCA.AP08Maester EIDSCA.AP08Default authorization settings - User consent policy assigned for applications.Konform
EIDSCA.AP10Maester EIDSCA.AP10Default Authorization Settings - Default User Role Permissions - Allowed to create Apps.Konform
EIDSCA.AS04Maester EIDSCA.AS04Authentication Method - SMS - Use for sign-in.Konform
EIDSCA.AT01Maester EIDSCA.AT01Authentication method - Temporary Access Pass - State.Konform
EIDSCA.AT02Maester EIDSCA.AT02Authentication method - Temporary Access Pass - One-time use.Konform
EIDSCA.AV01Maester EIDSCA.AV01Authentication method - Voice call - State.Konform
EIDSCA.CP01Maester EIDSCA.CP01Default settings - Consent policy settings - Group owner consent for apps accessing data.Konform
EIDSCA.CP03Maester EIDSCA.CP03Default Settings - Consent Policy Settings - Block user consent for risky apps.Konform
EIDSCA.PR02Maester EIDSCA.PR02Default Settings - Password Rule Settings - Password Protection - Enable password protection on Windows Server Active Directory.Konform
EIDSCA.PR03Maester EIDSCA.PR03Default settings - Password rule settings - Enforce custom list.Konform
EIDSCA.PR05Maester EIDSCA.PR05Default Settings - Password Rule Settings - Smart Lockout - Lockout duration in seconds.Konform
EIDSCA.PR06Maester EIDSCA.PR06Default settings - Password rule settings - Smart Lockout - Lockout threshold.Konform
EIDSCA.ST08Maester EIDSCA.ST08Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to become Group Owner.Konform
EIDSCA.ST09Maester EIDSCA.ST09Default settings - Classification and M365 groups - M365 groups - Allow guests to access group content.Konform
M365SEC:1.1.1Maester M365.1.1.1MOff 1.1.1 - Ensure Administrative accounts are separate and cloud-onlyKonform
M365SEC:1.1.3Maester M365.1.1.3Ensure that between two and four global admins are designatedKonform
M365SEC:1.3.1Maester M365.1.3.1Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)'Konform
M365SEC:1.3.3Maester M365.1.3.3Ensure 'External sharing' of calendars is not availableKonform
M365SEC:1.3.4Maester M365.1.3.4MOff 1.3.4 - User owned apps and services are not restrictedKonform
M365SEC:2.1.1Maester M365.2.1.1Ensure Safe Links for Office Applications is Enabled (Only Checks Default Policy)Konform
M365SEC:2.1.11Maester M365.2.1.11Ensure comprehensive attachment filtering is appliedKonform
M365SEC:2.1.2Maester M365.2.1.2Ensure the Common Attachment Types Filter is enabled (Only Checks Default Policy)Konform
M365SEC:2.1.3Maester M365.2.1.3Ensure notifications for internal users sending malware is Enabled (Only Checks Default Policy)Konform
M365SEC:2.1.4Maester M365.2.1.4Ensure Safe Attachments policy is enabled (Only Checks Default Policy)Konform
M365SEC:2.1.5Maester M365.2.1.5Ensure Safe Attachments for SharePoint, OneDrive, and Microsoft Teams is EnabledKonform
M365SEC:2.1.6Maester M365.2.1.6Ensure Exchange Online Spam Policies are set to notify administrators (Only Checks Default Policy)Konform
M365SEC:2.1.7Maester M365.2.1.7Ensure that an anti-phishing policy has been created (Only Checks Default Policy)Konform
M365SEC:3.1.1Maester M365.3.1.1MEx 3.1.1 - Microsoft 365 audit log search is Disabled!Konform
M365SEC:4.1Maester M365.4.1Ensure devices without a compliance policy are markedKonform
M365SEC:5.1.2.2Maester M365.5.1.2.2MAz 5.1.2.2 - Third party integrated applications are allowed!Konform
M365SEC:5.1.5.1Maester M365.5.1.5.1Ensure user consent to apps accessing company data on their behalf is not allowedKonform
M365SEC:5.1.6.2Maester M365.5.1.6.2Ensure that guest user access is restrictedKonform
M365SEC:5.2.3.5Maester M365.5.2.3.5Ensure weak authentication methods are disabledKonform
M365SEC:7.2.2Maester M365.7.2.2MSp 7.2.2 - SharePoint and OneDrive integration with Azure AD B2B is not enabled!Konform
M365SEC:7.2.5Maester M365.7.2.5Ensure that SharePoint guest users cannot share items they donKonform
M365SEC:7.2.9Maester M365.7.2.9MSp 7.2.9 - Guest access to a site or OneDrive does not expire automaticallyKonform
M365SEC:7.3.1Maester M365.7.3.1MSp 7.3.1 - Office 365 SharePoint infected files are NOT disallowed for downloadKonform
M365SEC:8.4.1Maester M365.8.4.1Ensure all or a majority of third-party and custom apps are blockedKonform
M365SEC:8.6.1Maester M365.8.6.1Ensure users can report security concerns in Teams to internal destinationKonform
MT.1003Maester MT.1003At least one Conditional Access policy is configured with All Apps.Konform
MT.1004Maester MT.1004At least one Conditional Access policy is configured with All Apps and All Users.Konform
MT.1006Maester MT.1006At least one Conditional Access policy is configured to require MFA for administrators.Konform
MT.1007Maester MT.1007At least one Conditional Access policy is configured to require MFA for all users.Konform
MT.1008Maester MT.1008At least one Conditional Access policy is configured to require MFA for Azure management.Konform
MT.1009Maester MT.1009At least one Conditional Access policy is configured to block other legacy authentication.Konform
MT.1010Maester MT.1010At least one Conditional Access policy is configured to block legacy authentication for Exchange ActiveSync.Konform
MT.1011Maester MT.1011At least one Conditional Access policy is configured to secure security info registration only from a trusted location.Konform
MT.1014Maester MT.1014At least one Conditional Access policy is configured to require compliant or Entra hybrid joined devices for administrators.Konform
MT.1015Maester MT.1015At least one Conditional Access policy is configured to block access from unknown or unsupported device platforms.Konform
MT.1016Maester MT.1016At least one Conditional Access policy is configured to require MFA for guest access.Konform
MT.1020Maester MT.1020All Conditional Access policies are configured to exclude directory synchronisation accounts, or do not target them.Konform
MT.1022Maester MT.1022MT.1022Konform
MT.1025Maester MT.1025No external user with permanent role assignment on Control Plane.Konform
MT.1026Maester MT.1026No hybrid user with permanent role assignment on Control Plane.Konform
MT.1031Maester MT.1031Control Plane privileged roles are managed by PIM only.Konform
MT.1032Maester MT.1032A limited number of Global Administrators is assigned.Konform
MT.1044Maester MT.1044Ensure modern authentication for Exchange Online is enabledKonform
MT.1045Maester MT.1045Only guest users should be admitted automatically to Teams meetingsKonform
MT.1050Maester MT.1050Applications with high-risk permissions having a direct path to Global Administrator.Konform
MT.1051Maester MT.1051Applications with high-risk permissions having an indirect path to Global Administrator.Konform
MT.1052Maester MT.1052At least one Conditional Access policy targets the Device Code authentication flow.Konform
MT.1061Maester MT.1061The device registration MFA control conflicts with Conditional Access policies.Konform
MT.1066Maester MT.1066Conditional Access policies should not include or exclude deleted users, groups or roles.Konform
MT.1071Maester MT.1071At least one Conditional Access policy explicitly includes Azure DevOps.Konform
MT.1072Maester MT.1072Conditional Access policies should not use the deprecated Approved Client App grant.Konform
MT.1075Maester MT.1075Third-party Entra applications should have explicitly assigned users rather than All Users.Konform
MT.1105Maester MT.1105The MDM authority should be set to Microsoft IntuneKonform
ORCA.101Maester ORCA.101Bulk is marked as spam.Konform
ORCA.102Maester ORCA.102Advanced Spam filter options are turned off.Konform
ORCA.104Maester ORCA.104High Confidence Phish action set to Quarantine message.Konform
ORCA.108.1Maester ORCA.108.1DNS Records have been set up to support DKIM.Konform
ORCA.109Maester ORCA.109Senders are not unsafely allow listed.Konform
ORCA.111Maester ORCA.111Anti-phishing policy exists and EnableUnauthenticatedSender is true.Konform
ORCA.112Maester ORCA.112Anti-spoofing protection action is configured to Move message to the recipients' Junk Email folders in Anti-phishing policy.Konform
ORCA.118.1Maester ORCA.118.1Domains are not unsafely allow listed in anti-spam policies.Konform
ORCA.118.3Maester ORCA.118.3Your own domains are not unsafely allow listed in anti-spam policies.Konform
ORCA.121Maester ORCA.121A supported filter policy action is in use.Konform
ORCA.124Maester ORCA.124Safe Attachments unknown malware response is set to block messages.Konform
ORCA.139Maester ORCA.139The spam action is set to move the message to the Junk Email folder or to quarantine.Konform
ORCA.141Maester ORCA.141Bulk action set to Move message to Junk Email Folder.Konform
ORCA.143Maester ORCA.143Safety Tips are enabled.Konform
ORCA.158Maester ORCA.158Safe Attachments is enabled for SharePoint and Teams.Konform
ORCA.180Maester ORCA.180Anti-phishing policy exists and EnableSpoofIntelligence is true.Konform
ORCA.221Maester ORCA.221Mailbox Intelligence is enabled in anti-phishing policies.Konform
ORCA.225Maester ORCA.225Safe Documents is enabled for Office clients.Konform
ORCA.226Maester ORCA.226Every domain has a Safe Links policy applied to it.Konform
ORCA.227Maester ORCA.227Every domain has a Safe Attachments policy applied to it.Konform
ORCA.228Maester ORCA.228No trusted senders in Anti-phishing policy.Konform
ORCA.229Maester ORCA.229No trusted domains in Anti-phishing policy.Konform
ORCA.230Maester ORCA.230Each domain has a Anti-phishing policy applied to it, or the default policy is being used.Konform
ORCA.231Maester ORCA.231Each domain has a anti-spam policy applied to it, or the default policy is being used.Konform
ORCA.232Maester ORCA.232Each domain has a malware filter policy applied to it, or the default policy is being used.Konform
ORCA.234Maester ORCA.234Click through is disabled for Safe Documents.Konform
ORCA.236Maester ORCA.236Safe Links is enabled for emails.Konform
ORCA.237Maester ORCA.237Safe Links is enabled for teams messages.Konform
ORCA.238Maester ORCA.238Safe Links is enabled for office documents.Konform
ORCA.240Maester ORCA.240Outlook is configured to display external tags for external emails.Konform
ORCA.242Maester ORCA.242The significant protection alerts responsible for AIR activity are enabled.Konform
ORCA.244Maester ORCA.244Policies are configured to honour the DMARC policy of sending domains.Konform
M365SEC:5.2.2.3Monkey365 eid-cap-block-legacy-authentication-not-enabledMAz 5.2.2.3 - No Conditional Access policies to block legacy authenticationKonform
M365SEC:5.2.2.4Monkey365 eid-cap-lack-sign-in-frequency-browser-persistent-sessionMAz 5.2.2.4 - Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative usersKonform
M365SEC:5.2.2.12Monkey365 eid-device-code-sign-in-flow-not-enabledEid device code sign in flow not enabledKonform
M365SEC:5.2.2.1Monkey365 eid-ensure-mfa-for-high-privileged-users-missing-capMAz 5.2.2.1 - MultiFactor Authentication (MFA) is not enabled for all users in administrative rolesKonform
M365SEC:5.2.2.5Monkey365 eid-ensure-phishing-resistant-mfa-for-high-privileged-users-missing-capMAz 5.2.2.5 - Phishing-resistant MFA strength must be required for AdministratorsKonform
M365SEC:5.1.6.3Monkey365 eid-guest-invite-restriction-disabledEid guest invite restriction disabledKonform
M365SEC:5.2.3.1Monkey365 eid-microsoft-authenticator-lack-mfa-fatigue-protectionMAz 5.2.3.1 - Microsoft Authenticator is not configured to protect against MFA fatigueKonform
M365SEC:5.1.8.1Monkey365 eid-password-hash-sync-disabledMAz 5.1.8.1 - Password Synchronization DisabledKonform
M365SEC:5.2.2.9Monkey365 eid-require-device-compliant-all-apps-missing-capEid require device compliant all apps missing capKonform
M365SEC:5.2.2.10Monkey365 eid-require-device-compliant-to-register-security-info-missing-capEid require device compliant to register security info missing capKonform
M365SEC:5.1.6.1Monkey365 eid-restrict-collaboration-specific-domains-disabledMAz 5.1.6.1 - Collaboration invitations are not sent to allowed domains onlyKonform
M365SEC:5.2.2.11Monkey365 eid-sign-in-frequency-intune-enrollment-missing-capEid sign in frequency intune enrollment missing capKonform
M365SEC:5.2.4.1Monkey365 eid-sspr-enabled-set-to-allMAz 5.2.4.1 - Self Service Password Reset is not set to be enabled for all usersKonform
M365SEC:6.1.3Monkey365 exchange-audit-bypass-enabledExchange audit bypass enabledKonform
M365SEC:6.1.1Monkey365 exchange-audit-enabled-globallyMEx 6.1.1 - Mailbox auditing is not Enabled for all usersKonform
M365SEC:6.2.3Monkey365 exchange-external-email-sender-configuredExterner Exchange-E-Mail-Absender konfiguriertKonform
M365SEC:6.5.1Monkey365 exchange-modern-authentication-disabledExchange modern authentication disabledKonform
M365SEC:2.1.14Monkey365 exhange-inbound-anti-spam-policies-allowed-domainsMEx 2.1.14 - No comprehensive attachment filtering is applied!Konform
M365SEC:7.2.8Monkey365 sharepoint-external-sharing-not-restricted-by-security-groupMSp 7.2.8 - Ensure external sharing is restricted by security group!Konform
M365SEC:7.2.1Monkey365 sharepoint-modern-authentication-requiredSharePoint modern authentication requiredKonform
M365SEC:8.5.1Monkey365 teams-anonymous-users-cant-join-meetingCISM Tm 8.5.1 - Anonymous users can join a meetingKonform
CISA:MS.AAD.1.1ScubaGear MS.AAD.1.1v1Legacy authentication SHALL be blocked.Konform
CISA:MS.AAD.3.1ScubaGear MS.AAD.3.1v1Phishing-resistant MFA SHALL be enforced for all users.Konform
CISA:MS.AAD.3.3ScubaGear MS.AAD.3.3v2If Microsoft Authenticator is enabled, it SHALL be configured to show login context information.Konform
CISA:MS.AAD.3.4ScubaGear MS.AAD.3.4v1The Authentication Methods Manage Migration feature SHALL be set to Migration Complete.Konform
CISA:MS.AAD.3.6ScubaGear MS.AAD.3.6v1Phishing-resistant MFA SHALL be required for highly privileged roles.Konform
CISA:MS.AAD.3.7ScubaGear MS.AAD.3.7v1Managed devices SHOULD be required for authentication.Konform
CISA:MS.AAD.3.8ScubaGear MS.AAD.3.8v1Managed Devices SHOULD be required to register MFA.Konform
CISA:MS.AAD.3.9ScubaGear MS.AAD.3.9v1Device code authentication SHOULD be blocked.Konform
CISA:MS.AAD.5.1ScubaGear MS.AAD.5.1v1Only administrators SHALL be allowed to register applications.Konform
CISA:MS.AAD.5.2ScubaGear MS.AAD.5.2v1Only administrators SHALL be allowed to consent to applications.Konform
CISA:MS.AAD.6.1ScubaGear MS.AAD.6.1v1User passwords SHALL NOT expire.Konform
CISA:MS.AAD.7.1ScubaGear MS.AAD.7.1v1A minimum of two users and a maximum of eight users SHALL be provisioned with the Global Administrator role.Konform
CISA:MS.AAD.7.2ScubaGear MS.AAD.7.2v1Privileged users SHALL be provisioned with finer-grained roles instead of Global Administrator.Konform
CISA:MS.AAD.7.4ScubaGear MS.AAD.7.4v1Permanent active role assignments SHALL NOT be allowed for highly privileged roles.Konform
CISA:MS.AAD.8.1ScubaGear MS.AAD.8.1v1Guest users SHOULD have limited or restricted access to Microsoft Entra ID directory objects.Konform
CISA:MS.AAD.8.2ScubaGear MS.AAD.8.2v1Only users with the Guest Inviter role SHOULD be able to invite guest users.Konform
CISA:MS.AAD.8.3ScubaGear MS.AAD.8.3v1Guest invites SHOULD only be allowed to specific external domains that have been authorized by the agency for legitimate business purposes.Konform
CISA:MS.DEFENDER.2.2ScubaGear MS.DEFENDER.2.2v1Domain impersonation protection SHOULD be enabled for agency-owned domains in standard and strict policies.Konform
CISA:MS.DEFENDER.2.3ScubaGear MS.DEFENDER.2.3v1Domain impersonation protection SHOULD be added for key suppliers and partners in standard and strict policies.Konform
CISA:MS.DEFENDER.3.1ScubaGear MS.DEFENDER.3.1v1Safe attachments SHOULD be enabled for SharePoint, OneDrive, and Microsoft Teams.Konform
CISA:MS.DEFENDER.5.1ScubaGear MS.DEFENDER.5.1v1Alerts required by Exchange Online baseline SHALL be enabled at minimum.Konform
CISA:MS.DEFENDER.5.2ScubaGear MS.DEFENDER.5.2v1Alerts SHOULD be sent to a monitored address or incorporated into SIEM.Konform
CISA:MS.DEFENDER.6.1ScubaGear MS.DEFENDER.6.1v1Unified Audit logging SHALL be enabled.Konform
CISA:MS.EXO.1.1ScubaGear MS.EXO.1.1v2Automatic forwarding to external domains SHALL be disabled.Konform
CISA:MS.EXO.6.1ScubaGear MS.EXO.6.1v1Contact folders SHALL NOT be shared with all domains.Konform
CISA:MS.EXO.6.2ScubaGear MS.EXO.6.2v1Calendar details SHALL NOT be shared with all domains.Konform
CISA:MS.EXO.7.1ScubaGear MS.EXO.7.1v1Warnhinweise für externe Absender MÜSSEN eingerichtet werden.Konform
CISA:MS.SHAREPOINT.1.3ScubaGear MS.SHAREPOINT.1.3v1External sharing SHALL be restricted to approved external domains and/or users in approved security groups per interagency collaboration needs.Konform
CISA:MS.TEAMS.1.3ScubaGear MS.TEAMS.1.3v1Anonymous users and dial-in callers SHOULD NOT be admitted automatically.Konform

Der überprüfbare Nachweis ist das Argument. Diese Diagnose hat Ihre Daten nie gesehen: Es wurden nur Konfigurationsparameter gelesen, niemals ein persönlicher Inhalt. Jede obige Feststellung ist in Ihren eigenen Microsoft-Protokollen überprüfbar, also belastbar - unabhängig davon, ob der Leser ein Versicherer, ein Auftraggeber, der Sie prüft, oder ein Wirtschaftsprüfer ist.

Methode & Nachweis
Direkte Einsichtnahme, Zero Knowledge
Microsoft-365-Konfiguration über die Graph-API gelesen (Verzeichnis, Exchange, Teams, SharePoint, Purview): kein Datum (E-Mail, Datei) wird gelesen, nur die Einstellungen. Keine Aufbewahrung der Daten über die Erstellung des Berichts hinaus.
Gekreuzte Referenzrahmen
M365-SicherheitsgrundlageCISA SCuBAMaesterMonkey365M365SATSYAGA-Kontrollpunkte
Von SYAGA nach den Open-Source-Prüfwerkzeugen neuformulierte Grundlage, gekreuzt mit der CISA-SCuBA-Baseline.
Bewerteter Umfang
280
bewertete Kontrollpunkte im SYAGA-Katalog
420 = 280 entschieden + 44 mit unterstützter Abdeckung + 63 nicht gemessen + 24 non applicables (licence) + 6 deklarativ (organisatorisch) + 3 en lecture seule
SYAGA CONSULTING bestätigt, dass die obigen Feststellungen aus einer direkten Einsichtnahme der Konfiguration des geprüften Tenants zum angegebenen Datum resultieren, gemäß der beschriebenen Zero-Knowledge-Methode und ohne Aufbewahrung der Daten über die Erstellung dieses Berichts hinaus.
Referenz: SYAGA-DEMO-QUESTIONNAIRE-0001
Score = contrôles conformes / contrôles tranchés (conformes + non conformes), sans pondération ; les contrôles non collectés et non applicables sont exclus du score.
Optionale SharePoint-Ergänzung (3 Kontrollpunkt(e))
Complément optionnel : Microsoft ne propose pas de mode lecture seule pour ces réglages SharePoint par site - y accéder exige un droit d'écriture (limite Microsoft, pas la nôtre). Désactivé par défaut, disponible en option de votre côté, et hors score tant que non activé.
Diese Kontrollpunkte zählen WEDER als konform, NOCH als nicht konform, NOCH als nicht erhoben: Sie bleiben außerhalb der Bewertung, solange Sie die Ergänzung nicht aktivieren (auf Ihre eigene Initiative, bei Ihnen, niemals bei uns).
Nicht anwendbar: Funktion im Tenant nicht vorhanden (24 Kontrollpunkt(e))
Diese Kontrollpunkte gelten nicht für Ihren Tenant: Die betreffende Funktion (Lizenz Microsoft Entra ID P2 / Governance, oder Produkt wie Copilot, Sentinel, Defender for Endpoint, Power Platform ...) ist dort nicht vorhanden. Es gibt daher nichts zu messen: Das ist weder ein Fehlschlag noch ein blinder Fleck.
Diese Kontrollpunkte zählen WEDER als konform, NOCH als nicht konform: Das ist eine Feststellung, kein Fehlschlag. Wir ermutigen Sie nicht, eine zusätzliche Lizenz zu kaufen: Das angestrebte Sicherheitsziel lässt sich oft anders erreichen (Konfiguration, interne Prozedur oder ein manchmal freies und günstigeres Drittanbieter-Tool). Sie würden wieder messbar, sobald die Ressource in Ihrem Tenant vorhanden wäre.
6 point(s) de vigilance organisationnels
Diese Anforderungen (physische Sicherung, Netzsegmentierung, Sensibilisierung, Governance) liegen bei der Organisation und sind durch einen rein lesenden Microsoft-365-Scan NICHT messbar. Sie werden gesondert ausgewiesen, ausserhalb der Bewertung und der Abweichungszahl: durch eine interne Prüfung zu verifizieren.
SYAGA Audit · herausgegeben von SYAGA CONSULTINGÜberprüfbares Audit, niemals eine Zertifizierung