Οι 85 αποκλίσεις σας δεν είναι 85 προβλήματα: ανάγονται σε τέσσερις βαθύτερη(-ες) αιτία(-ες). Αντιμετωπίστε τες με τη σειρά και εξουδετερώνετε το ουσιαστικό του κινδύνου με συγκεντρωμένη προσπάθεια, χωρίς να τα ξανακάνετε όλα.
Μία απόδειξη, τρεις αναγνώστες. Αυτός ο φάκελος έχει σχεδιαστεί ώστε να παρουσιαστεί σε έναν ασφαλιστή κυβερνοασφάλειας (μορφή ασφάλισης), σε έναν εντολέα που σας ζητά απόδειξη της στάσης σας (μετάδοση στην αλυσίδα προμηθευτών, NIS2 άρθρο 21 - εκδοχή διαμοιράσιμη), και σε έναν ορκωτό ελεγκτή ή εξωτερικό ελεγκτή. Κάθε διαπίστωση παρακάτω είναι επαληθεύσιμη στα δικά σας μητρώα Microsoft: αντιτάξιμη, όχι δηλωτική.
195 συμμορφούμενος(οι) έλεγχος(οι) από 280 κριθέντες ελέγχους - η επαληθεύσιμη βάση που μπορεί ήδη να παρουσιαστεί σε ασφαλιστή, σημείο προς σημείο, με αποδεικτικά στοιχεία. Στάση βαθμολογημένη ως C, χωρίς κολακεία, μόνο με βάση τα κριθέντα.
85 μη συμμόρφωση(ώσεις) διαπιστωμένη(ες) και 63 έλεγχος(οι) μη μετρημένος(οι) παραμένουν μια έκθεση μη καλυπτόμενη από αντιτάξιμη απόδειξη: όσο οι παρακάτω βαθύτερες αιτίες δεν αντιμετωπίζονται, αυτή η έκθεση δεν μπορεί να βεβαιωθεί.
| Σημείο αναφοράς | Σημείο ελέγχου | Σοβαρότητα |
|---|---|---|
| M365SEC:2.4.2M365SAT, Monkey365 | MEx 2.4.2 - Priority accounts do not have 'Strict protection' presets applied | Υψηλή |
| M365SEC:7.3.2M365SAT, Monkey365 | MSp 7.3.2 - OneDrive for Business sync from unmanaged devices is not blocked | Υψηλή |
| MT.1037Maester | Only users with Presenter role are allowed to present in Teams meetings | Υψηλή |
| MT.1034Maester | MT.1034.$($EmergencyAccessUsers.IndexOf($_)): Emergency access users should not be blocked ($($_.userPrincipalName)) | Προς αποκατάσταση |
| M365SEC:5.2.2.2M365SAT, Monkey365 | MAz 5.2.2.2 - MultiFactor Authentication (MFA) is not enabled for all users non-administrative roles | Κρίσιμο |
| CISA:MS.AAD.3.2Maester, ScubaGear | If phishing-resistant MFA has not been enforced, an alternative MFA method SHALL be enforced for all users. | Κρίσιμο |
| M365SEC:5.1.5.2M365SAT, Maester, Monkey365 | CISMAz 5.1.5.2 - User consent to apps accessing company data on their behalf is allowed! | Υψηλή |
| M365SEC:5.2.3.4M365SAT, Monkey365 | MAz 5.2.3.4 - Not all member users are 'MFA capable' | Υψηλή |
| ORCA.140Maester | High Confidence Spam action set to Quarantine message. | Υψηλή |
| ORCA.189.2Maester | Safe Links is not bypassed. | Υψηλή |
| Σημείο αναφοράς | Σημείο ελέγχου | Κατάσταση |
|---|---|---|
| M365SEC:1.3.5M365SAT, Maester, Monkey365 | MOff 1.3.5 - Internal phishing protection for Forms is disabled | Μη μετρημένο |
| M365SEC:2.4.1M365SAT, Monkey365 | MEx 2.4.1 - Priority account protection is not enabled and configured! | Μη μετρημένο |
| M365SEC:3.2.1M365SAT, Monkey365 | MEx 3.2.1 - DLP Policy is not enabled! | Μη μετρημένο |
| M365SEC:7.2.7M365SAT, Maester, Monkey365 | MSp 7.2.7 - Ensure link sharing is not restricted in SharePoint and OneDrive! | Μη μετρημένο |
| CISA:MS.AAD.4.1Maester, ScubaGear | Security logs SHALL be sent to the agency's security operations center for monitoring. | Μη μετρημένο |
| M365SEC:6.2.1M365SAT, Monkey365 | MEx 6.2.1 - Forms of mail forwarding are not blocked and/or not disabled | Μη μετρημένο |
| CISA:MS.EXO.13.1Maester, ScubaGear | Mailbox auditing SHALL be enabled. | Μη μετρημένο |
| M365SEC:4.2Monkey365 | Devices enrollment personal devices not blocked | Μη μετρημένο |
| M365SEC:7.2.11Maester, Monkey365 | Ensure the SharePoint default sharing link permission is set | Μη μετρημένο |
| MT.1027Maester | No Service Principal with Client Secret and permanent role assignment on Control Plane. | Μη μετρημένο |
| Σημείο αναφοράς | Σημείο ελέγχου | Σοβαρότητα |
|---|---|---|
| ANSSI R13ANSSI/NIS2 ANSSI R13 | ANSSI R13 | Συμμορφούμενο |
| ANSSI R14ANSSI/NIS2 ANSSI R14 | ANSSI R14 | Συμμορφούμενο |
| ANSSI R16ANSSI/NIS2 ANSSI R16 | ANSSI R16 | Συμμορφούμενο |
| ANSSI R24ANSSI/NIS2 ANSSI R24 | ANSSI R24 | Συμμορφούμενο |
| ANSSI R29ANSSI/NIS2 ANSSI R29 | ANSSI R29 | Συμμορφούμενο |
| ANSSI R36ANSSI/NIS2 ANSSI R36 | ANSSI R36 | Συμμορφούμενο |
| ANSSI R5ANSSI/NIS2 ANSSI R5 | ANSSI R5 | Συμμορφούμενο |
| ANSSI R8ANSSI/NIS2 ANSSI R8 | ANSSI R8 | Συμμορφούμενο |
| M365SEC:5.1.1.1M365SAT CISMAz5111 | CISMAz 5.1.1.1 - The Security Defaults are enabled on Azure Active Directory Tenant | Συμμορφούμενο |
| M365SEC:6.1.4M365SAT CISMEx614 | MEx 6.1.4 - Des boîtes aux lettres portent-elles 'AuditBypassEnabled', qui les exclut du journal d'audit ? | Συμμορφούμενο |
| CISA:MS.EXO.10.1Maester CISA.MS.EXO.10.1 | Emails SHALL be scanned for malware. | Συμμορφούμενο |
| CISA:MS.EXO.10.2Maester CISA.MS.EXO.10.2 | Emails identified as containing malware SHALL be quarantined or dropped. | Συμμορφούμενο |
| CISA:MS.EXO.10.3Maester CISA.MS.EXO.10.3 | Email scanning SHALL be capable of reviewing emails after delivery. | Συμμορφούμενο |
| CISA:MS.EXO.11.1Maester CISA.MS.EXO.11.1 | Impersonation protection checks SHOULD be used. | Συμμορφούμενο |
| CISA:MS.EXO.11.2Maester CISA.MS.EXO.11.2 | User warnings, comparable to the user safety tips included with EOP, SHOULD be displayed. | Συμμορφούμενο |
| CISA:MS.EXO.11.3Maester CISA.MS.EXO.11.3 | The phishing protection solution SHOULD include an AI-based phishing detection tool comparable to EOP Mailbox Intelligence. | Συμμορφούμενο |
| CISA:MS.EXO.12.1Maester CISA.MS.EXO.12.1 | IP allow lists SHOULD NOT be created. | Συμμορφούμενο |
| CISA:MS.EXO.14.1Maester CISA.MS.EXO.14.1 | A spam filter SHALL be enabled. | Συμμορφούμενο |
| CISA:MS.EXO.14.2Maester CISA.MS.EXO.14.2 | Spam and high confidence spam SHALL be moved to either the junk email folder or the quarantine folder. | Συμμορφούμενο |
| CISA:MS.EXO.14.3Maester CISA.MS.EXO.14.3 | Allowed domains SHALL NOT be added to inbound anti-spam protection policies. | Συμμορφούμενο |
| CISA:MS.EXO.15.1Maester CISA.MS.EXO.15.1 | URL comparison with a block-list SHOULD be enabled. | Συμμορφούμενο |
| CISA:MS.EXO.15.2Maester CISA.MS.EXO.15.2 | Direct download links SHOULD be scanned for malware. | Συμμορφούμενο |
| CISA:MS.EXO.15.3Maester CISA.MS.EXO.15.3 | User click tracking SHOULD be enabled. | Συμμορφούμενο |
| CISA:MS.EXO.16.1Maester CISA.MS.EXO.16.1 | Alerts SHALL be enabled. | Συμμορφούμενο |
| CISA:MS.EXO.16.2Maester CISA.MS.EXO.16.2 | Alerts SHOULD be sent to a monitored address or incorporated into a security information and event management (SIEM) system. | Συμμορφούμενο |
| CISA:MS.EXO.17.1Maester CISA.MS.EXO.17.1 | Microsoft Purview Audit (Standard) logging SHALL be enabled. | Συμμορφούμενο |
| CISA:MS.EXO.2.1Maester CISA.MS.EXO.2.1 | A list of approved IP addresses for sending mail SHALL be maintained. | Συμμορφούμενο |
| EIDSCA.AF01Maester EIDSCA.AF01 | Authentication method - FIDO2 security key - State. | Συμμορφούμενο |
| EIDSCA.AF02Maester EIDSCA.AF02 | Authentication Method - FIDO2 security key - Allow self-service set up. | Συμμορφούμενο |
| EIDSCA.AF03Maester EIDSCA.AF03 | Authentication method - FIDO2 security key - Enforce attestation. | Συμμορφούμενο |
| EIDSCA.AF04Maester EIDSCA.AF04 | Authentication method - FIDO2 security key - Enforce key restrictions. | Συμμορφούμενο |
| EIDSCA.AF05Maester EIDSCA.AF05 | Authentication method - FIDO2 security key - Restricted. | Συμμορφούμενο |
| EIDSCA.AF06Maester EIDSCA.AF06 | Authentication Method - FIDO2 security key - Restrict specific keys. | Συμμορφούμενο |
| EIDSCA.AG01Maester EIDSCA.AG01 | Authentication method - General settings - Manage migration. | Συμμορφούμενο |
| EIDSCA.AG02Maester EIDSCA.AG02 | Authentication method - General settings - Report suspicious activity - State. | Συμμορφούμενο |
| EIDSCA.AM01Maester EIDSCA.AM01 | Authentication method - Microsoft Authenticator - State. | Συμμορφούμενο |
| EIDSCA.AM02Maester EIDSCA.AM02 | Authentication method - Microsoft Authenticator - Allow use of Microsoft Authenticator OTP. | Συμμορφούμενο |
| EIDSCA.AM03Maester EIDSCA.AM03 | Authentication Method - Microsoft Authenticator - Require number matching for push notifications. | Συμμορφούμενο |
| EIDSCA.AM04Maester EIDSCA.AM04 | Authentication Method - Microsoft Authenticator - Included users/groups of number matching for push notifications. | Συμμορφούμενο |
| EIDSCA.AM06Maester EIDSCA.AM06 | Authentication Method - Microsoft Authenticator - Show application name in push and passwordless notifications. | Συμμορφούμενο |
| EIDSCA.AM07Maester EIDSCA.AM07 | Authentication method - Microsoft Authenticator - Users and groups included for showing the application name in push and passwordless notifications. | Συμμορφούμενο |
| EIDSCA.AM09Maester EIDSCA.AM09 | Authentication Method - Microsoft Authenticator - Show geographic location in push and passwordless notifications. | Συμμορφούμενο |
| EIDSCA.AM10Maester EIDSCA.AM10 | Authentication method - Microsoft Authenticator - Users and groups included for showing the geographic location in push and passwordless notifications. | Συμμορφούμενο |
| EIDSCA.AP01Maester EIDSCA.AP01 | Default authorization settings - Self-service password reset enabled for administrators. | Συμμορφούμενο |
| EIDSCA.AP04Maester EIDSCA.AP04 | Default Authorization Settings - Guest invite restrictions. | Συμμορφούμενο |
| EIDSCA.AP06Maester EIDSCA.AP06 | Default Authorization Settings - User can join the tenant by email validation. | Συμμορφούμενο |
| EIDSCA.AP08Maester EIDSCA.AP08 | Default authorization settings - User consent policy assigned for applications. | Συμμορφούμενο |
| EIDSCA.AP10Maester EIDSCA.AP10 | Default Authorization Settings - Default User Role Permissions - Allowed to create Apps. | Συμμορφούμενο |
| EIDSCA.AS04Maester EIDSCA.AS04 | Authentication Method - SMS - Use for sign-in. | Συμμορφούμενο |
| EIDSCA.AT01Maester EIDSCA.AT01 | Authentication method - Temporary Access Pass - State. | Συμμορφούμενο |
| EIDSCA.AT02Maester EIDSCA.AT02 | Authentication method - Temporary Access Pass - One-time use. | Συμμορφούμενο |
| EIDSCA.AV01Maester EIDSCA.AV01 | Authentication method - Voice call - State. | Συμμορφούμενο |
| EIDSCA.CP01Maester EIDSCA.CP01 | Default settings - Consent policy settings - Group owner consent for apps accessing data. | Συμμορφούμενο |
| EIDSCA.CP03Maester EIDSCA.CP03 | Default Settings - Consent Policy Settings - Block user consent for risky apps. | Συμμορφούμενο |
| EIDSCA.PR02Maester EIDSCA.PR02 | Default Settings - Password Rule Settings - Password Protection - Enable password protection on Windows Server Active Directory. | Συμμορφούμενο |
| EIDSCA.PR03Maester EIDSCA.PR03 | Default settings - Password rule settings - Enforce custom list. | Συμμορφούμενο |
| EIDSCA.PR05Maester EIDSCA.PR05 | Default Settings - Password Rule Settings - Smart Lockout - Lockout duration in seconds. | Συμμορφούμενο |
| EIDSCA.PR06Maester EIDSCA.PR06 | Default settings - Password rule settings - Smart Lockout - Lockout threshold. | Συμμορφούμενο |
| EIDSCA.ST08Maester EIDSCA.ST08 | Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to become Group Owner. | Συμμορφούμενο |
| EIDSCA.ST09Maester EIDSCA.ST09 | Default settings - Classification and M365 groups - M365 groups - Allow guests to access group content. | Συμμορφούμενο |
| M365SEC:1.1.1Maester M365.1.1.1 | MOff 1.1.1 - Ensure Administrative accounts are separate and cloud-only | Συμμορφούμενο |
| M365SEC:1.1.3Maester M365.1.1.3 | Ensure that between two and four global admins are designated | Συμμορφούμενο |
| M365SEC:1.3.1Maester M365.1.3.1 | Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)' | Συμμορφούμενο |
| M365SEC:1.3.3Maester M365.1.3.3 | Ensure 'External sharing' of calendars is not available | Συμμορφούμενο |
| M365SEC:1.3.4Maester M365.1.3.4 | MOff 1.3.4 - User owned apps and services are not restricted | Συμμορφούμενο |
| M365SEC:2.1.1Maester M365.2.1.1 | Ensure Safe Links for Office Applications is Enabled (Only Checks Default Policy) | Συμμορφούμενο |
| M365SEC:2.1.11Maester M365.2.1.11 | Ensure comprehensive attachment filtering is applied | Συμμορφούμενο |
| M365SEC:2.1.2Maester M365.2.1.2 | Ensure the Common Attachment Types Filter is enabled (Only Checks Default Policy) | Συμμορφούμενο |
| M365SEC:2.1.3Maester M365.2.1.3 | Ensure notifications for internal users sending malware is Enabled (Only Checks Default Policy) | Συμμορφούμενο |
| M365SEC:2.1.4Maester M365.2.1.4 | Ensure Safe Attachments policy is enabled (Only Checks Default Policy) | Συμμορφούμενο |
| M365SEC:2.1.5Maester M365.2.1.5 | Ensure Safe Attachments for SharePoint, OneDrive, and Microsoft Teams is Enabled | Συμμορφούμενο |
| M365SEC:2.1.6Maester M365.2.1.6 | Ensure Exchange Online Spam Policies are set to notify administrators (Only Checks Default Policy) | Συμμορφούμενο |
| M365SEC:2.1.7Maester M365.2.1.7 | Ensure that an anti-phishing policy has been created (Only Checks Default Policy) | Συμμορφούμενο |
| M365SEC:3.1.1Maester M365.3.1.1 | MEx 3.1.1 - Microsoft 365 audit log search is Disabled! | Συμμορφούμενο |
| M365SEC:4.1Maester M365.4.1 | Ensure devices without a compliance policy are marked | Συμμορφούμενο |
| M365SEC:5.1.2.2Maester M365.5.1.2.2 | MAz 5.1.2.2 - Third party integrated applications are allowed! | Συμμορφούμενο |
| M365SEC:5.1.5.1Maester M365.5.1.5.1 | Ensure user consent to apps accessing company data on their behalf is not allowed | Συμμορφούμενο |
| M365SEC:5.1.6.2Maester M365.5.1.6.2 | Ensure that guest user access is restricted | Συμμορφούμενο |
| M365SEC:5.2.3.5Maester M365.5.2.3.5 | Ensure weak authentication methods are disabled | Συμμορφούμενο |
| M365SEC:7.2.2Maester M365.7.2.2 | MSp 7.2.2 - SharePoint and OneDrive integration with Azure AD B2B is not enabled! | Συμμορφούμενο |
| M365SEC:7.2.5Maester M365.7.2.5 | Ensure that SharePoint guest users cannot share items they don | Συμμορφούμενο |
| M365SEC:7.2.9Maester M365.7.2.9 | MSp 7.2.9 - Guest access to a site or OneDrive does not expire automatically | Συμμορφούμενο |
| M365SEC:7.3.1Maester M365.7.3.1 | MSp 7.3.1 - Office 365 SharePoint infected files are NOT disallowed for download | Συμμορφούμενο |
| M365SEC:8.4.1Maester M365.8.4.1 | Ensure all or a majority of third-party and custom apps are blocked | Συμμορφούμενο |
| M365SEC:8.6.1Maester M365.8.6.1 | Ensure users can report security concerns in Teams to internal destination | Συμμορφούμενο |
| MT.1003Maester MT.1003 | At least one Conditional Access policy is configured with All Apps. | Συμμορφούμενο |
| MT.1004Maester MT.1004 | At least one Conditional Access policy is configured with All Apps and All Users. | Συμμορφούμενο |
| MT.1006Maester MT.1006 | At least one Conditional Access policy is configured to require MFA for administrators. | Συμμορφούμενο |
| MT.1007Maester MT.1007 | At least one Conditional Access policy is configured to require MFA for all users. | Συμμορφούμενο |
| MT.1008Maester MT.1008 | At least one Conditional Access policy is configured to require MFA for Azure management. | Συμμορφούμενο |
| MT.1009Maester MT.1009 | At least one Conditional Access policy is configured to block other legacy authentication. | Συμμορφούμενο |
| MT.1010Maester MT.1010 | At least one Conditional Access policy is configured to block legacy authentication for Exchange ActiveSync. | Συμμορφούμενο |
| MT.1011Maester MT.1011 | At least one Conditional Access policy is configured to secure security info registration only from a trusted location. | Συμμορφούμενο |
| MT.1014Maester MT.1014 | At least one Conditional Access policy is configured to require compliant or Entra hybrid joined devices for administrators. | Συμμορφούμενο |
| MT.1015Maester MT.1015 | At least one Conditional Access policy is configured to block access from unknown or unsupported device platforms. | Συμμορφούμενο |
| MT.1016Maester MT.1016 | At least one Conditional Access policy is configured to require MFA for guest access. | Συμμορφούμενο |
| MT.1020Maester MT.1020 | All Conditional Access policies are configured to exclude directory synchronisation accounts, or do not target them. | Συμμορφούμενο |
| MT.1022Maester MT.1022 | MT.1022 | Συμμορφούμενο |
| MT.1025Maester MT.1025 | No external user with permanent role assignment on Control Plane. | Συμμορφούμενο |
| MT.1026Maester MT.1026 | No hybrid user with permanent role assignment on Control Plane. | Συμμορφούμενο |
| MT.1031Maester MT.1031 | Control Plane privileged roles are managed by PIM only. | Συμμορφούμενο |
| MT.1032Maester MT.1032 | A limited number of Global Administrators is assigned. | Συμμορφούμενο |
| MT.1044Maester MT.1044 | Ensure modern authentication for Exchange Online is enabled | Συμμορφούμενο |
| MT.1045Maester MT.1045 | Only guest users should be admitted automatically to Teams meetings | Συμμορφούμενο |
| MT.1050Maester MT.1050 | Applications with high-risk permissions having a direct path to Global Administrator. | Συμμορφούμενο |
| MT.1051Maester MT.1051 | Applications with high-risk permissions having an indirect path to Global Administrator. | Συμμορφούμενο |
| MT.1052Maester MT.1052 | At least one Conditional Access policy targets the Device Code authentication flow. | Συμμορφούμενο |
| MT.1061Maester MT.1061 | The device registration MFA control conflicts with Conditional Access policies. | Συμμορφούμενο |
| MT.1066Maester MT.1066 | Conditional Access policies should not include or exclude deleted users, groups or roles. | Συμμορφούμενο |
| MT.1071Maester MT.1071 | At least one Conditional Access policy explicitly includes Azure DevOps. | Συμμορφούμενο |
| MT.1072Maester MT.1072 | Conditional Access policies should not use the deprecated Approved Client App grant. | Συμμορφούμενο |
| MT.1075Maester MT.1075 | Third-party Entra applications should have explicitly assigned users rather than All Users. | Συμμορφούμενο |
| MT.1105Maester MT.1105 | The MDM authority should be set to Microsoft Intune | Συμμορφούμενο |
| ORCA.101Maester ORCA.101 | Bulk is marked as spam. | Συμμορφούμενο |
| ORCA.102Maester ORCA.102 | Advanced Spam filter options are turned off. | Συμμορφούμενο |
| ORCA.104Maester ORCA.104 | High Confidence Phish action set to Quarantine message. | Συμμορφούμενο |
| ORCA.108.1Maester ORCA.108.1 | DNS Records have been set up to support DKIM. | Συμμορφούμενο |
| ORCA.109Maester ORCA.109 | Senders are not unsafely allow listed. | Συμμορφούμενο |
| ORCA.111Maester ORCA.111 | Anti-phishing policy exists and EnableUnauthenticatedSender is true. | Συμμορφούμενο |
| ORCA.112Maester ORCA.112 | Anti-spoofing protection action is configured to Move message to the recipients' Junk Email folders in Anti-phishing policy. | Συμμορφούμενο |
| ORCA.118.1Maester ORCA.118.1 | Domains are not unsafely allow listed in anti-spam policies. | Συμμορφούμενο |
| ORCA.118.3Maester ORCA.118.3 | Your own domains are not unsafely allow listed in anti-spam policies. | Συμμορφούμενο |
| ORCA.121Maester ORCA.121 | A supported filter policy action is in use. | Συμμορφούμενο |
| ORCA.124Maester ORCA.124 | Safe Attachments unknown malware response is set to block messages. | Συμμορφούμενο |
| ORCA.139Maester ORCA.139 | The spam action is set to move the message to the Junk Email folder or to quarantine. | Συμμορφούμενο |
| ORCA.141Maester ORCA.141 | Bulk action set to Move message to Junk Email Folder. | Συμμορφούμενο |
| ORCA.143Maester ORCA.143 | Safety Tips are enabled. | Συμμορφούμενο |
| ORCA.158Maester ORCA.158 | Safe Attachments is enabled for SharePoint and Teams. | Συμμορφούμενο |
| ORCA.180Maester ORCA.180 | Anti-phishing policy exists and EnableSpoofIntelligence is true. | Συμμορφούμενο |
| ORCA.221Maester ORCA.221 | Mailbox Intelligence is enabled in anti-phishing policies. | Συμμορφούμενο |
| ORCA.225Maester ORCA.225 | Safe Documents is enabled for Office clients. | Συμμορφούμενο |
| ORCA.226Maester ORCA.226 | Every domain has a Safe Links policy applied to it. | Συμμορφούμενο |
| ORCA.227Maester ORCA.227 | Every domain has a Safe Attachments policy applied to it. | Συμμορφούμενο |
| ORCA.228Maester ORCA.228 | No trusted senders in Anti-phishing policy. | Συμμορφούμενο |
| ORCA.229Maester ORCA.229 | No trusted domains in Anti-phishing policy. | Συμμορφούμενο |
| ORCA.230Maester ORCA.230 | Each domain has a Anti-phishing policy applied to it, or the default policy is being used. | Συμμορφούμενο |
| ORCA.231Maester ORCA.231 | Each domain has a anti-spam policy applied to it, or the default policy is being used. | Συμμορφούμενο |
| ORCA.232Maester ORCA.232 | Each domain has a malware filter policy applied to it, or the default policy is being used. | Συμμορφούμενο |
| ORCA.234Maester ORCA.234 | Click through is disabled for Safe Documents. | Συμμορφούμενο |
| ORCA.236Maester ORCA.236 | Safe Links is enabled for emails. | Συμμορφούμενο |
| ORCA.237Maester ORCA.237 | Safe Links is enabled for teams messages. | Συμμορφούμενο |
| ORCA.238Maester ORCA.238 | Safe Links is enabled for office documents. | Συμμορφούμενο |
| ORCA.240Maester ORCA.240 | Outlook is configured to display external tags for external emails. | Συμμορφούμενο |
| ORCA.242Maester ORCA.242 | The significant protection alerts responsible for AIR activity are enabled. | Συμμορφούμενο |
| ORCA.244Maester ORCA.244 | Policies are configured to honour the DMARC policy of sending domains. | Συμμορφούμενο |
| M365SEC:5.2.2.3Monkey365 eid-cap-block-legacy-authentication-not-enabled | MAz 5.2.2.3 - No Conditional Access policies to block legacy authentication | Συμμορφούμενο |
| M365SEC:5.2.2.4Monkey365 eid-cap-lack-sign-in-frequency-browser-persistent-session | MAz 5.2.2.4 - Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative users | Συμμορφούμενο |
| M365SEC:5.2.2.12Monkey365 eid-device-code-sign-in-flow-not-enabled | Eid device code sign in flow not enabled | Συμμορφούμενο |
| M365SEC:5.2.2.1Monkey365 eid-ensure-mfa-for-high-privileged-users-missing-cap | MAz 5.2.2.1 - MultiFactor Authentication (MFA) is not enabled for all users in administrative roles | Συμμορφούμενο |
| M365SEC:5.2.2.5Monkey365 eid-ensure-phishing-resistant-mfa-for-high-privileged-users-missing-cap | MAz 5.2.2.5 - Phishing-resistant MFA strength must be required for Administrators | Συμμορφούμενο |
| M365SEC:5.1.6.3Monkey365 eid-guest-invite-restriction-disabled | Eid guest invite restriction disabled | Συμμορφούμενο |
| M365SEC:5.2.3.1Monkey365 eid-microsoft-authenticator-lack-mfa-fatigue-protection | MAz 5.2.3.1 - Microsoft Authenticator is not configured to protect against MFA fatigue | Συμμορφούμενο |
| M365SEC:5.1.8.1Monkey365 eid-password-hash-sync-disabled | MAz 5.1.8.1 - Password Synchronization Disabled | Συμμορφούμενο |
| M365SEC:5.2.2.9Monkey365 eid-require-device-compliant-all-apps-missing-cap | Eid require device compliant all apps missing cap | Συμμορφούμενο |
| M365SEC:5.2.2.10Monkey365 eid-require-device-compliant-to-register-security-info-missing-cap | Eid require device compliant to register security info missing cap | Συμμορφούμενο |
| M365SEC:5.1.6.1Monkey365 eid-restrict-collaboration-specific-domains-disabled | MAz 5.1.6.1 - Collaboration invitations are not sent to allowed domains only | Συμμορφούμενο |
| M365SEC:5.2.2.11Monkey365 eid-sign-in-frequency-intune-enrollment-missing-cap | Eid sign in frequency intune enrollment missing cap | Συμμορφούμενο |
| M365SEC:5.2.4.1Monkey365 eid-sspr-enabled-set-to-all | MAz 5.2.4.1 - Self Service Password Reset is not set to be enabled for all users | Συμμορφούμενο |
| M365SEC:6.1.3Monkey365 exchange-audit-bypass-enabled | Exchange audit bypass enabled | Συμμορφούμενο |
| M365SEC:6.1.1Monkey365 exchange-audit-enabled-globally | MEx 6.1.1 - Mailbox auditing is not Enabled for all users | Συμμορφούμενο |
| M365SEC:6.2.3Monkey365 exchange-external-email-sender-configured | MEx 6.2.3 - Email from external senders cannot be identified | Συμμορφούμενο |
| M365SEC:6.5.1Monkey365 exchange-modern-authentication-disabled | Exchange modern authentication disabled | Συμμορφούμενο |
| M365SEC:2.1.14Monkey365 exhange-inbound-anti-spam-policies-allowed-domains | MEx 2.1.14 - No comprehensive attachment filtering is applied! | Συμμορφούμενο |
| M365SEC:7.2.8Monkey365 sharepoint-external-sharing-not-restricted-by-security-group | MSp 7.2.8 - Ensure external sharing is restricted by security group! | Συμμορφούμενο |
| M365SEC:7.2.1Monkey365 sharepoint-modern-authentication-required | SharePoint modern authentication required | Συμμορφούμενο |
| M365SEC:8.5.1Monkey365 teams-anonymous-users-cant-join-meeting | CISM Tm 8.5.1 - Anonymous users can join a meeting | Συμμορφούμενο |
| CISA:MS.AAD.1.1ScubaGear MS.AAD.1.1v1 | Legacy authentication SHALL be blocked. | Συμμορφούμενο |
| CISA:MS.AAD.3.1ScubaGear MS.AAD.3.1v1 | Phishing-resistant MFA SHALL be enforced for all users. | Συμμορφούμενο |
| CISA:MS.AAD.3.3ScubaGear MS.AAD.3.3v2 | If Microsoft Authenticator is enabled, it SHALL be configured to show login context information. | Συμμορφούμενο |
| CISA:MS.AAD.3.4ScubaGear MS.AAD.3.4v1 | The Authentication Methods Manage Migration feature SHALL be set to Migration Complete. | Συμμορφούμενο |
| CISA:MS.AAD.3.6ScubaGear MS.AAD.3.6v1 | Phishing-resistant MFA SHALL be required for highly privileged roles. | Συμμορφούμενο |
| CISA:MS.AAD.3.7ScubaGear MS.AAD.3.7v1 | Managed devices SHOULD be required for authentication. | Συμμορφούμενο |
| CISA:MS.AAD.3.8ScubaGear MS.AAD.3.8v1 | Managed Devices SHOULD be required to register MFA. | Συμμορφούμενο |
| CISA:MS.AAD.3.9ScubaGear MS.AAD.3.9v1 | Device code authentication SHOULD be blocked. | Συμμορφούμενο |
| CISA:MS.AAD.5.1ScubaGear MS.AAD.5.1v1 | Only administrators SHALL be allowed to register applications. | Συμμορφούμενο |
| CISA:MS.AAD.5.2ScubaGear MS.AAD.5.2v1 | Only administrators SHALL be allowed to consent to applications. | Συμμορφούμενο |
| CISA:MS.AAD.6.1ScubaGear MS.AAD.6.1v1 | User passwords SHALL NOT expire. | Συμμορφούμενο |
| CISA:MS.AAD.7.1ScubaGear MS.AAD.7.1v1 | A minimum of two users and a maximum of eight users SHALL be provisioned with the Global Administrator role. | Συμμορφούμενο |
| CISA:MS.AAD.7.2ScubaGear MS.AAD.7.2v1 | Privileged users SHALL be provisioned with finer-grained roles instead of Global Administrator. | Συμμορφούμενο |
| CISA:MS.AAD.7.4ScubaGear MS.AAD.7.4v1 | Permanent active role assignments SHALL NOT be allowed for highly privileged roles. | Συμμορφούμενο |
| CISA:MS.AAD.8.1ScubaGear MS.AAD.8.1v1 | Guest users SHOULD have limited or restricted access to Microsoft Entra ID directory objects. | Συμμορφούμενο |
| CISA:MS.AAD.8.2ScubaGear MS.AAD.8.2v1 | Only users with the Guest Inviter role SHOULD be able to invite guest users. | Συμμορφούμενο |
| CISA:MS.AAD.8.3ScubaGear MS.AAD.8.3v1 | Guest invites SHOULD only be allowed to specific external domains that have been authorized by the agency for legitimate business purposes. | Συμμορφούμενο |
| CISA:MS.DEFENDER.2.2ScubaGear MS.DEFENDER.2.2v1 | Domain impersonation protection SHOULD be enabled for agency-owned domains in standard and strict policies. | Συμμορφούμενο |
| CISA:MS.DEFENDER.2.3ScubaGear MS.DEFENDER.2.3v1 | Domain impersonation protection SHOULD be added for key suppliers and partners in standard and strict policies. | Συμμορφούμενο |
| CISA:MS.DEFENDER.3.1ScubaGear MS.DEFENDER.3.1v1 | Safe attachments SHOULD be enabled for SharePoint, OneDrive, and Microsoft Teams. | Συμμορφούμενο |
| CISA:MS.DEFENDER.5.1ScubaGear MS.DEFENDER.5.1v1 | Alerts required by Exchange Online baseline SHALL be enabled at minimum. | Συμμορφούμενο |
| CISA:MS.DEFENDER.5.2ScubaGear MS.DEFENDER.5.2v1 | Alerts SHOULD be sent to a monitored address or incorporated into SIEM. | Συμμορφούμενο |
| CISA:MS.DEFENDER.6.1ScubaGear MS.DEFENDER.6.1v1 | Unified Audit logging SHALL be enabled. | Συμμορφούμενο |
| CISA:MS.EXO.1.1ScubaGear MS.EXO.1.1v2 | Automatic forwarding to external domains SHALL be disabled. | Συμμορφούμενο |
| CISA:MS.EXO.6.1ScubaGear MS.EXO.6.1v1 | Contact folders SHALL NOT be shared with all domains. | Συμμορφούμενο |
| CISA:MS.EXO.6.2ScubaGear MS.EXO.6.2v1 | Calendar details SHALL NOT be shared with all domains. | Συμμορφούμενο |
| CISA:MS.EXO.7.1ScubaGear MS.EXO.7.1v1 | External sender warnings SHALL be implemented. | Συμμορφούμενο |
| CISA:MS.SHAREPOINT.1.3ScubaGear MS.SHAREPOINT.1.3v1 | External sharing SHALL be restricted to approved external domains and/or users in approved security groups per interagency collaboration needs. | Συμμορφούμενο |
| CISA:MS.TEAMS.1.3ScubaGear MS.TEAMS.1.3v1 | Anonymous users and dial-in callers SHOULD NOT be admitted automatically. | Συμμορφούμενο |
Η επαληθεύσιμη απόδειξη είναι το επιχείρημα. Αυτή η διάγνωση δεν είδε ποτέ τα δεδομένα σας: μόνο παράμετροι διαμόρφωσης διαβάστηκαν, ποτέ προσωπικό περιεχόμενο. Κάθε διαπίστωση παραπάνω είναι επαληθεύσιμη στα δικά σας μητρώα Microsoft, άρα αντιτάξιμη - είτε ο αναγνώστης είναι ασφαλιστής, εντολέας που σας ελέγχει, είτε ορκωτός ελεγκτής.