EXEMPLE : entreprise et chiffres inventés. Ce document montre la forme exacte du rapport livré, ce n’est pas un audit réel.
Les 5 lectures du même audit : Pour le dirigeant · Pour le RSSI · Pour l'informaticien · Pour le DPO / la conformité · Pour l'assureur / le donneur d'ordre
SYAGA Audit
Έκθεση βεβαίωσης τρίτου μέρους
Χωρίς να βλέπουμε τα δεδομένα σας · Αναφ. SYAGA-DEMO-QUESTIONNAIRE-0001
Διαπίστωση στάσης Microsoft 365Έγγραφο χρονολογημένο και επαληθεύσιμο
Ελεγμένη οντότητα
Entreprise Démonstration (exemple, non client) (tenant d3m0a1b2-c3d4-4e5f-8a9b-0c1d2e3f4a5b)
Ημερομηνία ελέγχου
17 juillet 2026
Εκδότης
SYAGA CONSULTING · SIREN 518 489 471
Επαληθεύσιμο σε
τα δικά σας μητρώα ελέγχου Microsoft · syaga.eu
Η ετυμηγορία, πριν τον φάκελο απόδειξης

Τέσσερις δομικές αδυναμίες εκθέτουν την ασφαλισιμότητά σας Microsoft 365.

Οι 85 αποκλίσεις σας δεν είναι 85 προβλήματα: ανάγονται σε τέσσερις βαθύτερη(-ες) αιτία(-ες). Αντιμετωπίστε τες με τη σειρά και εξουδετερώνετε το ουσιαστικό του κινδύνου με συγκεντρωμένη προσπάθεια, χωρίς να τα ξανακάνετε όλα.

Στάση ασφαλισιμότητας
70/100
Προς ενίσχυση
σωστές βάσεις, αλλά κενά παραμένουν ανοιχτά

Μία απόδειξη, τρεις αναγνώστες. Αυτός ο φάκελος έχει σχεδιαστεί ώστε να παρουσιαστεί σε έναν ασφαλιστή κυβερνοασφάλειας (μορφή ασφάλισης), σε έναν εντολέα που σας ζητά απόδειξη της στάσης σας (μετάδοση στην αλυσίδα προμηθευτών, NIS2 άρθρο 21 - εκδοχή διαμοιράσιμη), και σε έναν ορκωτό ελεγκτή ή εξωτερικό ελεγκτή. Κάθε διαπίστωση παρακάτω είναι επαληθεύσιμη στα δικά σας μητρώα Microsoft: αντιτάξιμη, όχι δηλωτική.

195
Συμμορφούμενοι έλεγχοι
4
Βαθύτερες αιτίες που βαρύνουν την ασφαλισιμότητα
85
Μη συμμορφώσεις διαπιστωμένες μέχρι σήμερα
Τι είναι αποδείξιμο σήμερα

195 συμμορφούμενος(οι) έλεγχος(οι) από 280 κριθέντες ελέγχους - η επαληθεύσιμη βάση που μπορεί ήδη να παρουσιαστεί σε ασφαλιστή, σημείο προς σημείο, με αποδεικτικά στοιχεία. Στάση βαθμολογημένη ως C, χωρίς κολακεία, μόνο με βάση τα κριθέντα.

Τι εκθέτει τον φάκελό σας

85 μη συμμόρφωση(ώσεις) διαπιστωμένη(ες) και 63 έλεγχος(οι) μη μετρημένος(οι) παραμένουν μια έκθεση μη καλυπτόμενη από αντιτάξιμη απόδειξη: όσο οι παρακάτω βαθύτερες αιτίες δεν αντιμετωπίζονται, αυτή η έκθεση δεν μπορεί να βεβαιωθεί.

I

Σκλήρυνση της διαμόρφωσης

34 απόκλιση(εις) ομαδοποιημένη(ες) - Διαμόρφωση & συμμόρφωση
Η έκθεση: μια μη σκληρυμένη βάση διευρύνει την επιφάνεια επίθεσης σιωπηλά, χωρίς ορατή ειδοποίηση.
Σήμερα: Σε αυτό το θέμα, οι ακόλουθες απαιτήσεις συμμόρφωσης δεν καλύπτονται: S'assurer que les comptes prioritaires bénéficient des paramètres prédéfinis de protection stricte (Strict protection) ; S'assurer que la synchronisation OneDrive est restreinte pour les appareils non gérés ; Seuls les utilisateurs ayant le rôle Présentateur sont autorisés à présenter dans les réunions Teams ; Les comptes d'accès d'urgence (break-glass) ne doivent pas être bloqués.
Τι διαπίστωσε ο έλεγχος: Sensibiliser les utilisateurs aux bonnes pratiques élémentaires (hameçonnage, gestion des mots de passe, MFA, signalement) par des campagnes récurrentes et des simulations ; mesure principalement organisationnelle. Appliquer le preset de protection Strict aux comptes prioritaires pour leur garantir le niveau de filtrage le plus élevé. Bloquer la synchronisation OneDrive depuis les appareils non gérés via une politique d'accès conditionnel (AllowLimitedAccess) limitant l'accès au web sans téléchargement/synchronisation.
Προσπάθεια ΜέτριοΕπίπτωση Μέτριο
II

Ταυτότητα και πρόσβαση

31 απόκλιση(εις) ομαδοποιημένη(ες) - Ταυτότητα & πρόσβαση
Η έκθεση: η κατάληψη ελέγχου ενός λογαριασμού είναι η πιο συνηθισμένη πύλη εισόδου μιας επίθεσης· είναι το μόνο θέμα όπου μια περιορισμένη προσπάθεια κλείνει μια ολόκληρη κατηγορία κινδύνων μονομιάς.
Σήμερα: Σε αυτό το θέμα, οι ακόλουθες απαιτήσεις συμμόρφωσης δεν καλύπτονται: S'assurer que l'authentification multifacteur est activée pour tous les utilisateurs ; La MFA DOIT être imposée pour tous les utilisateurs ; S'assurer que le flux de consentement administrateur est activé ; S'assurer que tous les utilisateurs membres sont 'compatibles MFA' (MFA capable).
Τι διαπίστωσε ο έλεγχος: Le MFA doit être exigé pour l'ensemble des utilisateurs via une politique d'accès conditionnel afin de bloquer la grande majorité des attaques par compromission d'identité. Activer le flux de consentement administrateur dans Entra ID pour qu'une demande d'accès bloquée côté utilisateur soit routée vers un réviseur plutôt que simplement rejetée sans suite. Au moins deux comptes d'accès d'urgence (break-glass) cloud-only en *.onmicrosoft.com, exclus des politiques CA bloquantes, doivent être définis pour éviter un verrouillage total de l'administration.
Προσπάθεια ΧαμηλόΕπίπτωση Σημαντικό
III

Εποπτεία και καταγραφή

14 απόκλιση(εις) ομαδοποιημένη(ες) - Ανίχνευση & εποπτεία
Η έκθεση: χωρίς ενεργή ανίχνευση ούτε πλήρη αρχεία καταγραφής, μια επίθεση μπορεί να πετύχει χωρίς να μπλοκαριστεί, ούτε να εντοπιστεί εγκαίρως, ούτε να αποδειχθεί εκ των υστέρων: ένα άμεσο μειονέκτημα σε περίπτωση ζημιάς, κανονιστικού ελέγχου ή ασφαλιστικού φακέλου.
Σήμερα: Σε αυτό το θέμα, οι ακόλουθες απαιτήσεις συμμόρφωσης δεν καλύπτονται: L'action pour le spam à haut niveau de confiance (High Confidence Spam) est définie sur Mettre le message en quarantaine ; Les liens sûrs (Safe Links) ne sont pas contournés ; L'action en cas d'usurpation de domaine (Domain Impersonation) est définie sur déplacer vers la quarantaine ; L'action en cas d'usurpation d'identité d'utilisateur (User impersonation) est définie sur déplacer vers la quarantaine.
Τι διαπίστωσε ο έλεγχος: Inclure tous les utilisateurs dans la protection Defender for Office 365 via le preset de sécurité Standard ou Strict. Configurer la politique Anti-courrier indésirable (anti-spam) pour appliquer le réglage cible : « Durée de rétention en quarantaine portée à 30 jours ». Configurer la politique Anti-hameçonnage pour appliquer le réglage cible : « Mise en quarantaine des messages détectés comme hameçonnage ».
Προσπάθεια ΧαμηλόΕπίπτωση Υψηλό
IV

Έκθεση δεδομένων

6 απόκλιση(εις) ομαδοποιημένη(ες) - Δεδομένα & έκθεση
Η έκθεση: ένα δεδομένο που εξέρχεται από την επιχείρηση χωρίς φραγμό είναι το πιο κοινό, και το πιο δαπανηρό, διαρρέον διάνυσμα, τόσο σε εικόνα όσο και σε κανονιστική συμμόρφωση.
Σήμερα: Σε αυτό το θέμα, οι ακόλουθες απαιτήσεις συμμόρφωσης δεν καλύπτονται: S'assurer que les stratégies d'étiquettes de confidentialité Information Protection sont publiées ; S'assurer que le partage de contenu OneDrive est restreint ; Une solution de prevention des pertes de données (DLP) DOIT être utilisée ; L'action de la politique personnalisée DEVRAIT être configurée pour bloquer le partage d'informations sensibles avec tout le monde.
Τι διαπίστωσε ο έλεγχος: Publier au moins une politique d'étiquettes de sensibilité (sensitivity labels) auprès des utilisateurs ou groupes cibles, afin de permettre la classification et la protection des documents selon leur niveau de confidentialité. Restreindre le partage de contenu OneDrive au niveau le plus restrictif approprié (au plus 'Invités existants'), sachant qu'OneDrive peut être plus restrictif que SharePoint mais jamais plus permissif. Mettre en place une solution de prévention des pertes de données (DLP) couvrant Exchange Online.
Προσπάθεια ΜέτριοΕπίπτωση Υψηλό

Μη συμμορφώσεις που βαρύνουν την ασφαλισιμότητα

Πραγματικές διαπιστώσεις που συνδέονται με τις βαθύτερες αιτίες
Σημείο αναφοράςΣημείο ελέγχουΣοβαρότητα
M365SEC:2.4.2M365SAT, Monkey365MEx 2.4.2 - Priority accounts do not have 'Strict protection' presets appliedΥψηλή
M365SEC:7.3.2M365SAT, Monkey365MSp 7.3.2 - OneDrive for Business sync from unmanaged devices is not blockedΥψηλή
MT.1037MaesterOnly users with Presenter role are allowed to present in Teams meetingsΥψηλή
MT.1034MaesterMT.1034.$($EmergencyAccessUsers.IndexOf($_)): Emergency access users should not be blocked ($($_.userPrincipalName))Προς αποκατάσταση
M365SEC:5.2.2.2M365SAT, Monkey365MAz 5.2.2.2 - MultiFactor Authentication (MFA) is not enabled for all users non-administrative rolesΚρίσιμο
CISA:MS.AAD.3.2Maester, ScubaGearIf phishing-resistant MFA has not been enforced, an alternative MFA method SHALL be enforced for all users.Κρίσιμο
M365SEC:5.1.5.2M365SAT, Maester, Monkey365CISMAz 5.1.5.2 - User consent to apps accessing company data on their behalf is allowed!Υψηλή
M365SEC:5.2.3.4M365SAT, Monkey365MAz 5.2.3.4 - Not all member users are 'MFA capable'Υψηλή
ORCA.140MaesterHigh Confidence Spam action set to Quarantine message.Υψηλή
ORCA.189.2MaesterSafe Links is not bypassed.Υψηλή

Τυφλά σημεία: μη καλυπτόμενα από αντιτάξιμη απόδειξη όσο δεν μετρούνται

63 έλεγχος(οι) μη μετρημένος(οι) στον κατάλογο
Σημείο αναφοράςΣημείο ελέγχουΚατάσταση
M365SEC:1.3.5M365SAT, Maester, Monkey365MOff 1.3.5 - Internal phishing protection for Forms is disabledΜη μετρημένο
M365SEC:2.4.1M365SAT, Monkey365MEx 2.4.1 - Priority account protection is not enabled and configured!Μη μετρημένο
M365SEC:3.2.1M365SAT, Monkey365MEx 3.2.1 - DLP Policy is not enabled!Μη μετρημένο
M365SEC:7.2.7M365SAT, Maester, Monkey365MSp 7.2.7 - Ensure link sharing is not restricted in SharePoint and OneDrive!Μη μετρημένο
CISA:MS.AAD.4.1Maester, ScubaGearSecurity logs SHALL be sent to the agency's security operations center for monitoring.Μη μετρημένο
M365SEC:6.2.1M365SAT, Monkey365MEx 6.2.1 - Forms of mail forwarding are not blocked and/or not disabledΜη μετρημένο
CISA:MS.EXO.13.1Maester, ScubaGearMailbox auditing SHALL be enabled.Μη μετρημένο
M365SEC:4.2Monkey365Devices enrollment personal devices not blockedΜη μετρημένο
M365SEC:7.2.11Maester, Monkey365Ensure the SharePoint default sharing link permission is setΜη μετρημένο
MT.1027MaesterNo Service Principal with Client Secret and permanent role assignment on Control Plane.Μη μετρημένο
Η σειρά με την οποία να χτιστεί ο φάκελος ασφαλισιμότητας
Πρώτα
Η βασική διαμόρφωση. Η ισχυρότερη αναλογία κινδύνου-που-εξαλείφθηκε/προσπάθειας. Όσο δεν γίνεται αυτό, τα υπόλοιπα προστατεύουν ένα σπίτι με την πόρτα ανοιχτή.
Έπειτα
Η ταυτότητα. Μόλις εξασφαλιστεί ο πρώτος μοχλός, μειώνουμε την επιφάνεια μέσω της οποίας υλοποιείται ο κίνδυνος.
Στη συνέχεια
Η εποπτεία. Απομένει να εδραιωθούν αυτά τα επιτεύγματα διαχρονικά: διακυβέρνηση, τακτικές επισκοπήσεις και διατηρούμενα τεκμήρια, ώστε η στάση να κρατά στον χρόνο και όχι μόνο την ημέρα του ελέγχου.
Υπό εδραίωση
Εναπομείναντα θεμελιώδη έργα. η εξωτερική έκθεση: προς εδραίωση μόλις τηρηθούν οι προτεραιότητες της κορυφής της λίστας.

Τι αποφεύγει αυτή η πορεία

Διακοπή. ένας καταληφθείς λογαριασμός που παραλύει τη δραστηριότητα.
Διαρροή. δεδομένα πελατών που εξέρχονται χωρίς να αφήνουν ίχνος.
Μη συμμόρφωση. μια αντιτάξιμη απόκλιση RGPD ή NIS2 σε έλεγχο.
Άρνηση ασφάλισης. ένα ζημιογόνο γεγονός μη καλυπτόμενο ελλείψει αποδεικτικών στοιχείων.

Οι 195 συμμορφούμενοι έλεγχοι, ένας προς έναν

Δεν χρειάζεται να μας πιστέψετε για ένα σύνολο. Κάθε γραμμή παρακάτω φέρει την αναφορά της και το δημόσιο πλαίσιο στο οποίο στηρίζεται: ο ασφαλιστής σας, ο εντολέας σας ή ο ορκωτός ελεγκτής σας μπορεί να τις ελέγξει μία προς μία στα δικά σας αρχεία καταγραφής Microsoft.
Σημείο αναφοράςΣημείο ελέγχουΣοβαρότητα
ANSSI R13ANSSI/NIS2 ANSSI R13ANSSI R13Συμμορφούμενο
ANSSI R14ANSSI/NIS2 ANSSI R14ANSSI R14Συμμορφούμενο
ANSSI R16ANSSI/NIS2 ANSSI R16ANSSI R16Συμμορφούμενο
ANSSI R24ANSSI/NIS2 ANSSI R24ANSSI R24Συμμορφούμενο
ANSSI R29ANSSI/NIS2 ANSSI R29ANSSI R29Συμμορφούμενο
ANSSI R36ANSSI/NIS2 ANSSI R36ANSSI R36Συμμορφούμενο
ANSSI R5ANSSI/NIS2 ANSSI R5ANSSI R5Συμμορφούμενο
ANSSI R8ANSSI/NIS2 ANSSI R8ANSSI R8Συμμορφούμενο
M365SEC:5.1.1.1M365SAT CISMAz5111CISMAz 5.1.1.1 - The Security Defaults are enabled on Azure Active Directory TenantΣυμμορφούμενο
M365SEC:6.1.4M365SAT CISMEx614MEx 6.1.4 - Des boîtes aux lettres portent-elles 'AuditBypassEnabled', qui les exclut du journal d'audit ?Συμμορφούμενο
CISA:MS.EXO.10.1Maester CISA.MS.EXO.10.1Emails SHALL be scanned for malware.Συμμορφούμενο
CISA:MS.EXO.10.2Maester CISA.MS.EXO.10.2Emails identified as containing malware SHALL be quarantined or dropped.Συμμορφούμενο
CISA:MS.EXO.10.3Maester CISA.MS.EXO.10.3Email scanning SHALL be capable of reviewing emails after delivery.Συμμορφούμενο
CISA:MS.EXO.11.1Maester CISA.MS.EXO.11.1Impersonation protection checks SHOULD be used.Συμμορφούμενο
CISA:MS.EXO.11.2Maester CISA.MS.EXO.11.2User warnings, comparable to the user safety tips included with EOP, SHOULD be displayed.Συμμορφούμενο
CISA:MS.EXO.11.3Maester CISA.MS.EXO.11.3The phishing protection solution SHOULD include an AI-based phishing detection tool comparable to EOP Mailbox Intelligence.Συμμορφούμενο
CISA:MS.EXO.12.1Maester CISA.MS.EXO.12.1IP allow lists SHOULD NOT be created.Συμμορφούμενο
CISA:MS.EXO.14.1Maester CISA.MS.EXO.14.1A spam filter SHALL be enabled.Συμμορφούμενο
CISA:MS.EXO.14.2Maester CISA.MS.EXO.14.2Spam and high confidence spam SHALL be moved to either the junk email folder or the quarantine folder.Συμμορφούμενο
CISA:MS.EXO.14.3Maester CISA.MS.EXO.14.3Allowed domains SHALL NOT be added to inbound anti-spam protection policies.Συμμορφούμενο
CISA:MS.EXO.15.1Maester CISA.MS.EXO.15.1URL comparison with a block-list SHOULD be enabled.Συμμορφούμενο
CISA:MS.EXO.15.2Maester CISA.MS.EXO.15.2Direct download links SHOULD be scanned for malware.Συμμορφούμενο
CISA:MS.EXO.15.3Maester CISA.MS.EXO.15.3User click tracking SHOULD be enabled.Συμμορφούμενο
CISA:MS.EXO.16.1Maester CISA.MS.EXO.16.1Alerts SHALL be enabled.Συμμορφούμενο
CISA:MS.EXO.16.2Maester CISA.MS.EXO.16.2Alerts SHOULD be sent to a monitored address or incorporated into a security information and event management (SIEM) system.Συμμορφούμενο
CISA:MS.EXO.17.1Maester CISA.MS.EXO.17.1Microsoft Purview Audit (Standard) logging SHALL be enabled.Συμμορφούμενο
CISA:MS.EXO.2.1Maester CISA.MS.EXO.2.1A list of approved IP addresses for sending mail SHALL be maintained.Συμμορφούμενο
EIDSCA.AF01Maester EIDSCA.AF01Authentication method - FIDO2 security key - State.Συμμορφούμενο
EIDSCA.AF02Maester EIDSCA.AF02Authentication Method - FIDO2 security key - Allow self-service set up.Συμμορφούμενο
EIDSCA.AF03Maester EIDSCA.AF03Authentication method - FIDO2 security key - Enforce attestation.Συμμορφούμενο
EIDSCA.AF04Maester EIDSCA.AF04Authentication method - FIDO2 security key - Enforce key restrictions.Συμμορφούμενο
EIDSCA.AF05Maester EIDSCA.AF05Authentication method - FIDO2 security key - Restricted.Συμμορφούμενο
EIDSCA.AF06Maester EIDSCA.AF06Authentication Method - FIDO2 security key - Restrict specific keys.Συμμορφούμενο
EIDSCA.AG01Maester EIDSCA.AG01Authentication method - General settings - Manage migration.Συμμορφούμενο
EIDSCA.AG02Maester EIDSCA.AG02Authentication method - General settings - Report suspicious activity - State.Συμμορφούμενο
EIDSCA.AM01Maester EIDSCA.AM01Authentication method - Microsoft Authenticator - State.Συμμορφούμενο
EIDSCA.AM02Maester EIDSCA.AM02Authentication method - Microsoft Authenticator - Allow use of Microsoft Authenticator OTP.Συμμορφούμενο
EIDSCA.AM03Maester EIDSCA.AM03Authentication Method - Microsoft Authenticator - Require number matching for push notifications.Συμμορφούμενο
EIDSCA.AM04Maester EIDSCA.AM04Authentication Method - Microsoft Authenticator - Included users/groups of number matching for push notifications.Συμμορφούμενο
EIDSCA.AM06Maester EIDSCA.AM06Authentication Method - Microsoft Authenticator - Show application name in push and passwordless notifications.Συμμορφούμενο
EIDSCA.AM07Maester EIDSCA.AM07Authentication method - Microsoft Authenticator - Users and groups included for showing the application name in push and passwordless notifications.Συμμορφούμενο
EIDSCA.AM09Maester EIDSCA.AM09Authentication Method - Microsoft Authenticator - Show geographic location in push and passwordless notifications.Συμμορφούμενο
EIDSCA.AM10Maester EIDSCA.AM10Authentication method - Microsoft Authenticator - Users and groups included for showing the geographic location in push and passwordless notifications.Συμμορφούμενο
EIDSCA.AP01Maester EIDSCA.AP01Default authorization settings - Self-service password reset enabled for administrators.Συμμορφούμενο
EIDSCA.AP04Maester EIDSCA.AP04Default Authorization Settings - Guest invite restrictions.Συμμορφούμενο
EIDSCA.AP06Maester EIDSCA.AP06Default Authorization Settings - User can join the tenant by email validation.Συμμορφούμενο
EIDSCA.AP08Maester EIDSCA.AP08Default authorization settings - User consent policy assigned for applications.Συμμορφούμενο
EIDSCA.AP10Maester EIDSCA.AP10Default Authorization Settings - Default User Role Permissions - Allowed to create Apps.Συμμορφούμενο
EIDSCA.AS04Maester EIDSCA.AS04Authentication Method - SMS - Use for sign-in.Συμμορφούμενο
EIDSCA.AT01Maester EIDSCA.AT01Authentication method - Temporary Access Pass - State.Συμμορφούμενο
EIDSCA.AT02Maester EIDSCA.AT02Authentication method - Temporary Access Pass - One-time use.Συμμορφούμενο
EIDSCA.AV01Maester EIDSCA.AV01Authentication method - Voice call - State.Συμμορφούμενο
EIDSCA.CP01Maester EIDSCA.CP01Default settings - Consent policy settings - Group owner consent for apps accessing data.Συμμορφούμενο
EIDSCA.CP03Maester EIDSCA.CP03Default Settings - Consent Policy Settings - Block user consent for risky apps.Συμμορφούμενο
EIDSCA.PR02Maester EIDSCA.PR02Default Settings - Password Rule Settings - Password Protection - Enable password protection on Windows Server Active Directory.Συμμορφούμενο
EIDSCA.PR03Maester EIDSCA.PR03Default settings - Password rule settings - Enforce custom list.Συμμορφούμενο
EIDSCA.PR05Maester EIDSCA.PR05Default Settings - Password Rule Settings - Smart Lockout - Lockout duration in seconds.Συμμορφούμενο
EIDSCA.PR06Maester EIDSCA.PR06Default settings - Password rule settings - Smart Lockout - Lockout threshold.Συμμορφούμενο
EIDSCA.ST08Maester EIDSCA.ST08Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to become Group Owner.Συμμορφούμενο
EIDSCA.ST09Maester EIDSCA.ST09Default settings - Classification and M365 groups - M365 groups - Allow guests to access group content.Συμμορφούμενο
M365SEC:1.1.1Maester M365.1.1.1MOff 1.1.1 - Ensure Administrative accounts are separate and cloud-onlyΣυμμορφούμενο
M365SEC:1.1.3Maester M365.1.1.3Ensure that between two and four global admins are designatedΣυμμορφούμενο
M365SEC:1.3.1Maester M365.1.3.1Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)'Συμμορφούμενο
M365SEC:1.3.3Maester M365.1.3.3Ensure 'External sharing' of calendars is not availableΣυμμορφούμενο
M365SEC:1.3.4Maester M365.1.3.4MOff 1.3.4 - User owned apps and services are not restrictedΣυμμορφούμενο
M365SEC:2.1.1Maester M365.2.1.1Ensure Safe Links for Office Applications is Enabled (Only Checks Default Policy)Συμμορφούμενο
M365SEC:2.1.11Maester M365.2.1.11Ensure comprehensive attachment filtering is appliedΣυμμορφούμενο
M365SEC:2.1.2Maester M365.2.1.2Ensure the Common Attachment Types Filter is enabled (Only Checks Default Policy)Συμμορφούμενο
M365SEC:2.1.3Maester M365.2.1.3Ensure notifications for internal users sending malware is Enabled (Only Checks Default Policy)Συμμορφούμενο
M365SEC:2.1.4Maester M365.2.1.4Ensure Safe Attachments policy is enabled (Only Checks Default Policy)Συμμορφούμενο
M365SEC:2.1.5Maester M365.2.1.5Ensure Safe Attachments for SharePoint, OneDrive, and Microsoft Teams is EnabledΣυμμορφούμενο
M365SEC:2.1.6Maester M365.2.1.6Ensure Exchange Online Spam Policies are set to notify administrators (Only Checks Default Policy)Συμμορφούμενο
M365SEC:2.1.7Maester M365.2.1.7Ensure that an anti-phishing policy has been created (Only Checks Default Policy)Συμμορφούμενο
M365SEC:3.1.1Maester M365.3.1.1MEx 3.1.1 - Microsoft 365 audit log search is Disabled!Συμμορφούμενο
M365SEC:4.1Maester M365.4.1Ensure devices without a compliance policy are markedΣυμμορφούμενο
M365SEC:5.1.2.2Maester M365.5.1.2.2MAz 5.1.2.2 - Third party integrated applications are allowed!Συμμορφούμενο
M365SEC:5.1.5.1Maester M365.5.1.5.1Ensure user consent to apps accessing company data on their behalf is not allowedΣυμμορφούμενο
M365SEC:5.1.6.2Maester M365.5.1.6.2Ensure that guest user access is restrictedΣυμμορφούμενο
M365SEC:5.2.3.5Maester M365.5.2.3.5Ensure weak authentication methods are disabledΣυμμορφούμενο
M365SEC:7.2.2Maester M365.7.2.2MSp 7.2.2 - SharePoint and OneDrive integration with Azure AD B2B is not enabled!Συμμορφούμενο
M365SEC:7.2.5Maester M365.7.2.5Ensure that SharePoint guest users cannot share items they donΣυμμορφούμενο
M365SEC:7.2.9Maester M365.7.2.9MSp 7.2.9 - Guest access to a site or OneDrive does not expire automaticallyΣυμμορφούμενο
M365SEC:7.3.1Maester M365.7.3.1MSp 7.3.1 - Office 365 SharePoint infected files are NOT disallowed for downloadΣυμμορφούμενο
M365SEC:8.4.1Maester M365.8.4.1Ensure all or a majority of third-party and custom apps are blockedΣυμμορφούμενο
M365SEC:8.6.1Maester M365.8.6.1Ensure users can report security concerns in Teams to internal destinationΣυμμορφούμενο
MT.1003Maester MT.1003At least one Conditional Access policy is configured with All Apps.Συμμορφούμενο
MT.1004Maester MT.1004At least one Conditional Access policy is configured with All Apps and All Users.Συμμορφούμενο
MT.1006Maester MT.1006At least one Conditional Access policy is configured to require MFA for administrators.Συμμορφούμενο
MT.1007Maester MT.1007At least one Conditional Access policy is configured to require MFA for all users.Συμμορφούμενο
MT.1008Maester MT.1008At least one Conditional Access policy is configured to require MFA for Azure management.Συμμορφούμενο
MT.1009Maester MT.1009At least one Conditional Access policy is configured to block other legacy authentication.Συμμορφούμενο
MT.1010Maester MT.1010At least one Conditional Access policy is configured to block legacy authentication for Exchange ActiveSync.Συμμορφούμενο
MT.1011Maester MT.1011At least one Conditional Access policy is configured to secure security info registration only from a trusted location.Συμμορφούμενο
MT.1014Maester MT.1014At least one Conditional Access policy is configured to require compliant or Entra hybrid joined devices for administrators.Συμμορφούμενο
MT.1015Maester MT.1015At least one Conditional Access policy is configured to block access from unknown or unsupported device platforms.Συμμορφούμενο
MT.1016Maester MT.1016At least one Conditional Access policy is configured to require MFA for guest access.Συμμορφούμενο
MT.1020Maester MT.1020All Conditional Access policies are configured to exclude directory synchronisation accounts, or do not target them.Συμμορφούμενο
MT.1022Maester MT.1022MT.1022Συμμορφούμενο
MT.1025Maester MT.1025No external user with permanent role assignment on Control Plane.Συμμορφούμενο
MT.1026Maester MT.1026No hybrid user with permanent role assignment on Control Plane.Συμμορφούμενο
MT.1031Maester MT.1031Control Plane privileged roles are managed by PIM only.Συμμορφούμενο
MT.1032Maester MT.1032A limited number of Global Administrators is assigned.Συμμορφούμενο
MT.1044Maester MT.1044Ensure modern authentication for Exchange Online is enabledΣυμμορφούμενο
MT.1045Maester MT.1045Only guest users should be admitted automatically to Teams meetingsΣυμμορφούμενο
MT.1050Maester MT.1050Applications with high-risk permissions having a direct path to Global Administrator.Συμμορφούμενο
MT.1051Maester MT.1051Applications with high-risk permissions having an indirect path to Global Administrator.Συμμορφούμενο
MT.1052Maester MT.1052At least one Conditional Access policy targets the Device Code authentication flow.Συμμορφούμενο
MT.1061Maester MT.1061The device registration MFA control conflicts with Conditional Access policies.Συμμορφούμενο
MT.1066Maester MT.1066Conditional Access policies should not include or exclude deleted users, groups or roles.Συμμορφούμενο
MT.1071Maester MT.1071At least one Conditional Access policy explicitly includes Azure DevOps.Συμμορφούμενο
MT.1072Maester MT.1072Conditional Access policies should not use the deprecated Approved Client App grant.Συμμορφούμενο
MT.1075Maester MT.1075Third-party Entra applications should have explicitly assigned users rather than All Users.Συμμορφούμενο
MT.1105Maester MT.1105The MDM authority should be set to Microsoft IntuneΣυμμορφούμενο
ORCA.101Maester ORCA.101Bulk is marked as spam.Συμμορφούμενο
ORCA.102Maester ORCA.102Advanced Spam filter options are turned off.Συμμορφούμενο
ORCA.104Maester ORCA.104High Confidence Phish action set to Quarantine message.Συμμορφούμενο
ORCA.108.1Maester ORCA.108.1DNS Records have been set up to support DKIM.Συμμορφούμενο
ORCA.109Maester ORCA.109Senders are not unsafely allow listed.Συμμορφούμενο
ORCA.111Maester ORCA.111Anti-phishing policy exists and EnableUnauthenticatedSender is true.Συμμορφούμενο
ORCA.112Maester ORCA.112Anti-spoofing protection action is configured to Move message to the recipients' Junk Email folders in Anti-phishing policy.Συμμορφούμενο
ORCA.118.1Maester ORCA.118.1Domains are not unsafely allow listed in anti-spam policies.Συμμορφούμενο
ORCA.118.3Maester ORCA.118.3Your own domains are not unsafely allow listed in anti-spam policies.Συμμορφούμενο
ORCA.121Maester ORCA.121A supported filter policy action is in use.Συμμορφούμενο
ORCA.124Maester ORCA.124Safe Attachments unknown malware response is set to block messages.Συμμορφούμενο
ORCA.139Maester ORCA.139The spam action is set to move the message to the Junk Email folder or to quarantine.Συμμορφούμενο
ORCA.141Maester ORCA.141Bulk action set to Move message to Junk Email Folder.Συμμορφούμενο
ORCA.143Maester ORCA.143Safety Tips are enabled.Συμμορφούμενο
ORCA.158Maester ORCA.158Safe Attachments is enabled for SharePoint and Teams.Συμμορφούμενο
ORCA.180Maester ORCA.180Anti-phishing policy exists and EnableSpoofIntelligence is true.Συμμορφούμενο
ORCA.221Maester ORCA.221Mailbox Intelligence is enabled in anti-phishing policies.Συμμορφούμενο
ORCA.225Maester ORCA.225Safe Documents is enabled for Office clients.Συμμορφούμενο
ORCA.226Maester ORCA.226Every domain has a Safe Links policy applied to it.Συμμορφούμενο
ORCA.227Maester ORCA.227Every domain has a Safe Attachments policy applied to it.Συμμορφούμενο
ORCA.228Maester ORCA.228No trusted senders in Anti-phishing policy.Συμμορφούμενο
ORCA.229Maester ORCA.229No trusted domains in Anti-phishing policy.Συμμορφούμενο
ORCA.230Maester ORCA.230Each domain has a Anti-phishing policy applied to it, or the default policy is being used.Συμμορφούμενο
ORCA.231Maester ORCA.231Each domain has a anti-spam policy applied to it, or the default policy is being used.Συμμορφούμενο
ORCA.232Maester ORCA.232Each domain has a malware filter policy applied to it, or the default policy is being used.Συμμορφούμενο
ORCA.234Maester ORCA.234Click through is disabled for Safe Documents.Συμμορφούμενο
ORCA.236Maester ORCA.236Safe Links is enabled for emails.Συμμορφούμενο
ORCA.237Maester ORCA.237Safe Links is enabled for teams messages.Συμμορφούμενο
ORCA.238Maester ORCA.238Safe Links is enabled for office documents.Συμμορφούμενο
ORCA.240Maester ORCA.240Outlook is configured to display external tags for external emails.Συμμορφούμενο
ORCA.242Maester ORCA.242The significant protection alerts responsible for AIR activity are enabled.Συμμορφούμενο
ORCA.244Maester ORCA.244Policies are configured to honour the DMARC policy of sending domains.Συμμορφούμενο
M365SEC:5.2.2.3Monkey365 eid-cap-block-legacy-authentication-not-enabledMAz 5.2.2.3 - No Conditional Access policies to block legacy authenticationΣυμμορφούμενο
M365SEC:5.2.2.4Monkey365 eid-cap-lack-sign-in-frequency-browser-persistent-sessionMAz 5.2.2.4 - Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative usersΣυμμορφούμενο
M365SEC:5.2.2.12Monkey365 eid-device-code-sign-in-flow-not-enabledEid device code sign in flow not enabledΣυμμορφούμενο
M365SEC:5.2.2.1Monkey365 eid-ensure-mfa-for-high-privileged-users-missing-capMAz 5.2.2.1 - MultiFactor Authentication (MFA) is not enabled for all users in administrative rolesΣυμμορφούμενο
M365SEC:5.2.2.5Monkey365 eid-ensure-phishing-resistant-mfa-for-high-privileged-users-missing-capMAz 5.2.2.5 - Phishing-resistant MFA strength must be required for AdministratorsΣυμμορφούμενο
M365SEC:5.1.6.3Monkey365 eid-guest-invite-restriction-disabledEid guest invite restriction disabledΣυμμορφούμενο
M365SEC:5.2.3.1Monkey365 eid-microsoft-authenticator-lack-mfa-fatigue-protectionMAz 5.2.3.1 - Microsoft Authenticator is not configured to protect against MFA fatigueΣυμμορφούμενο
M365SEC:5.1.8.1Monkey365 eid-password-hash-sync-disabledMAz 5.1.8.1 - Password Synchronization DisabledΣυμμορφούμενο
M365SEC:5.2.2.9Monkey365 eid-require-device-compliant-all-apps-missing-capEid require device compliant all apps missing capΣυμμορφούμενο
M365SEC:5.2.2.10Monkey365 eid-require-device-compliant-to-register-security-info-missing-capEid require device compliant to register security info missing capΣυμμορφούμενο
M365SEC:5.1.6.1Monkey365 eid-restrict-collaboration-specific-domains-disabledMAz 5.1.6.1 - Collaboration invitations are not sent to allowed domains onlyΣυμμορφούμενο
M365SEC:5.2.2.11Monkey365 eid-sign-in-frequency-intune-enrollment-missing-capEid sign in frequency intune enrollment missing capΣυμμορφούμενο
M365SEC:5.2.4.1Monkey365 eid-sspr-enabled-set-to-allMAz 5.2.4.1 - Self Service Password Reset is not set to be enabled for all usersΣυμμορφούμενο
M365SEC:6.1.3Monkey365 exchange-audit-bypass-enabledExchange audit bypass enabledΣυμμορφούμενο
M365SEC:6.1.1Monkey365 exchange-audit-enabled-globallyMEx 6.1.1 - Mailbox auditing is not Enabled for all usersΣυμμορφούμενο
M365SEC:6.2.3Monkey365 exchange-external-email-sender-configuredMEx 6.2.3 - Email from external senders cannot be identifiedΣυμμορφούμενο
M365SEC:6.5.1Monkey365 exchange-modern-authentication-disabledExchange modern authentication disabledΣυμμορφούμενο
M365SEC:2.1.14Monkey365 exhange-inbound-anti-spam-policies-allowed-domainsMEx 2.1.14 - No comprehensive attachment filtering is applied!Συμμορφούμενο
M365SEC:7.2.8Monkey365 sharepoint-external-sharing-not-restricted-by-security-groupMSp 7.2.8 - Ensure external sharing is restricted by security group!Συμμορφούμενο
M365SEC:7.2.1Monkey365 sharepoint-modern-authentication-requiredSharePoint modern authentication requiredΣυμμορφούμενο
M365SEC:8.5.1Monkey365 teams-anonymous-users-cant-join-meetingCISM Tm 8.5.1 - Anonymous users can join a meetingΣυμμορφούμενο
CISA:MS.AAD.1.1ScubaGear MS.AAD.1.1v1Legacy authentication SHALL be blocked.Συμμορφούμενο
CISA:MS.AAD.3.1ScubaGear MS.AAD.3.1v1Phishing-resistant MFA SHALL be enforced for all users.Συμμορφούμενο
CISA:MS.AAD.3.3ScubaGear MS.AAD.3.3v2If Microsoft Authenticator is enabled, it SHALL be configured to show login context information.Συμμορφούμενο
CISA:MS.AAD.3.4ScubaGear MS.AAD.3.4v1The Authentication Methods Manage Migration feature SHALL be set to Migration Complete.Συμμορφούμενο
CISA:MS.AAD.3.6ScubaGear MS.AAD.3.6v1Phishing-resistant MFA SHALL be required for highly privileged roles.Συμμορφούμενο
CISA:MS.AAD.3.7ScubaGear MS.AAD.3.7v1Managed devices SHOULD be required for authentication.Συμμορφούμενο
CISA:MS.AAD.3.8ScubaGear MS.AAD.3.8v1Managed Devices SHOULD be required to register MFA.Συμμορφούμενο
CISA:MS.AAD.3.9ScubaGear MS.AAD.3.9v1Device code authentication SHOULD be blocked.Συμμορφούμενο
CISA:MS.AAD.5.1ScubaGear MS.AAD.5.1v1Only administrators SHALL be allowed to register applications.Συμμορφούμενο
CISA:MS.AAD.5.2ScubaGear MS.AAD.5.2v1Only administrators SHALL be allowed to consent to applications.Συμμορφούμενο
CISA:MS.AAD.6.1ScubaGear MS.AAD.6.1v1User passwords SHALL NOT expire.Συμμορφούμενο
CISA:MS.AAD.7.1ScubaGear MS.AAD.7.1v1A minimum of two users and a maximum of eight users SHALL be provisioned with the Global Administrator role.Συμμορφούμενο
CISA:MS.AAD.7.2ScubaGear MS.AAD.7.2v1Privileged users SHALL be provisioned with finer-grained roles instead of Global Administrator.Συμμορφούμενο
CISA:MS.AAD.7.4ScubaGear MS.AAD.7.4v1Permanent active role assignments SHALL NOT be allowed for highly privileged roles.Συμμορφούμενο
CISA:MS.AAD.8.1ScubaGear MS.AAD.8.1v1Guest users SHOULD have limited or restricted access to Microsoft Entra ID directory objects.Συμμορφούμενο
CISA:MS.AAD.8.2ScubaGear MS.AAD.8.2v1Only users with the Guest Inviter role SHOULD be able to invite guest users.Συμμορφούμενο
CISA:MS.AAD.8.3ScubaGear MS.AAD.8.3v1Guest invites SHOULD only be allowed to specific external domains that have been authorized by the agency for legitimate business purposes.Συμμορφούμενο
CISA:MS.DEFENDER.2.2ScubaGear MS.DEFENDER.2.2v1Domain impersonation protection SHOULD be enabled for agency-owned domains in standard and strict policies.Συμμορφούμενο
CISA:MS.DEFENDER.2.3ScubaGear MS.DEFENDER.2.3v1Domain impersonation protection SHOULD be added for key suppliers and partners in standard and strict policies.Συμμορφούμενο
CISA:MS.DEFENDER.3.1ScubaGear MS.DEFENDER.3.1v1Safe attachments SHOULD be enabled for SharePoint, OneDrive, and Microsoft Teams.Συμμορφούμενο
CISA:MS.DEFENDER.5.1ScubaGear MS.DEFENDER.5.1v1Alerts required by Exchange Online baseline SHALL be enabled at minimum.Συμμορφούμενο
CISA:MS.DEFENDER.5.2ScubaGear MS.DEFENDER.5.2v1Alerts SHOULD be sent to a monitored address or incorporated into SIEM.Συμμορφούμενο
CISA:MS.DEFENDER.6.1ScubaGear MS.DEFENDER.6.1v1Unified Audit logging SHALL be enabled.Συμμορφούμενο
CISA:MS.EXO.1.1ScubaGear MS.EXO.1.1v2Automatic forwarding to external domains SHALL be disabled.Συμμορφούμενο
CISA:MS.EXO.6.1ScubaGear MS.EXO.6.1v1Contact folders SHALL NOT be shared with all domains.Συμμορφούμενο
CISA:MS.EXO.6.2ScubaGear MS.EXO.6.2v1Calendar details SHALL NOT be shared with all domains.Συμμορφούμενο
CISA:MS.EXO.7.1ScubaGear MS.EXO.7.1v1External sender warnings SHALL be implemented.Συμμορφούμενο
CISA:MS.SHAREPOINT.1.3ScubaGear MS.SHAREPOINT.1.3v1External sharing SHALL be restricted to approved external domains and/or users in approved security groups per interagency collaboration needs.Συμμορφούμενο
CISA:MS.TEAMS.1.3ScubaGear MS.TEAMS.1.3v1Anonymous users and dial-in callers SHOULD NOT be admitted automatically.Συμμορφούμενο

Η επαληθεύσιμη απόδειξη είναι το επιχείρημα. Αυτή η διάγνωση δεν είδε ποτέ τα δεδομένα σας: μόνο παράμετροι διαμόρφωσης διαβάστηκαν, ποτέ προσωπικό περιεχόμενο. Κάθε διαπίστωση παραπάνω είναι επαληθεύσιμη στα δικά σας μητρώα Microsoft, άρα αντιτάξιμη - είτε ο αναγνώστης είναι ασφαλιστής, εντολέας που σας ελέγχει, είτε ορκωτός ελεγκτής.

Μέθοδος & απόδειξη
Άμεση ανάγνωση, μηδενική γνώση
Διαμόρφωση Microsoft 365 διαβασμένη μέσω του API Graph (κατάλογος, Exchange, Teams, SharePoint, Purview): κανένα δεδομένο (e-mail, αρχείο) δεν διαβάζεται, μόνο οι ρυθμίσεις. Καμία διατήρηση δεδομένων πέραν της παραγωγής της έκθεσης.
Διασταυρωμένα πλαίσια αναφοράς
Βασικό πρότυπο ασφαλείας M365CISA SCuBAMaesterMonkey365M365SATΈλεγχοι SYAGA
Πρότυπο αναδιατυπωμένο από την SYAGA βάσει των εργαλείων ανοιχτού κώδικα, διασταυρωμένο με το βασικό πρότυπο CISA SCuBA.
Αξιολογημένο πεδίο
280
έλεγχοι κριθέντες στον κατάλογο SYAGA
420 = 280 κριθέντα + 44 με υποβοηθούμενη κάλυψη + 63 μη μετρηθέντα + 24 non applicables (licence) + 6 δηλωτικά (οργανωτικά) + 3 en lecture seule
Η SYAGA CONSULTING βεβαιώνει ότι οι παραπάνω διαπιστώσεις προκύπτουν από άμεση ανάγνωση της διαμόρφωσης του ελεγμένου μισθωτή κατά την αναφερόμενη ημερομηνία, σύμφωνα με την περιγραφόμενη μέθοδο μηδενικής γνώσης, και χωρίς διατήρηση δεδομένων πέραν της παραγωγής της παρούσας έκθεσης.
Αναφορά: SYAGA-DEMO-QUESTIONNAIRE-0001
Score = contrôles conformes / contrôles tranchés (conformes + non conformes), sans pondération ; les contrôles non collectés et non applicables sont exclus du score.
Προαιρετικό συμπλήρωμα SharePoint (3 έλεγχος(οι))
Complément optionnel : Microsoft ne propose pas de mode lecture seule pour ces réglages SharePoint par site - y accéder exige un droit d'écriture (limite Microsoft, pas la nôtre). Désactivé par défaut, disponible en option de votre côté, et hors score tant que non activé.
Αυτοί οι έλεγχοι δεν προσμετρώνται ΟΥΤΕ ως συμμορφούμενοι, ΟΥΤΕ ως μη συμμορφούμενοι, ΟΥΤΕ ως μη συλλεγμένοι: παραμένουν εκτός βαθμολογίας όσο δεν ενεργοποιείτε το συμπλήρωμα (με δική σας πρωτοβουλία, από δικής σας πλευράς, ποτέ από τη δική μας).
Μη εφαρμόσιμο: λειτουργικότητα μη παρούσα στον μισθωτή (24 έλεγχος(οι))
Αυτοί οι έλεγχοι δεν εφαρμόζονται στον μισθωτή σας: η αντίστοιχη λειτουργικότητα (άδεια Microsoft Entra ID P2 / Governance, ή προϊόν όπως Copilot, Sentinel, Defender for Endpoint, Power Platform...) δεν είναι παρούσα εκεί. Δεν υπάρχει λοιπόν τίποτα να μετρηθεί: δεν είναι ούτε αποτυχία, ούτε τυφλό σημείο.
Αυτοί οι έλεγχοι δεν προσμετρώνται ΟΥΤΕ ως συμμορφούμενοι, ΟΥΤΕ ως μη συμμορφούμενοι: πρόκειται για διαπίστωση, όχι αποτυχία. Δεν σας παρακινούμε να αγοράσετε πρόσθετη άδεια: ο επιδιωκόμενος στόχος ασφαλείας μπορεί συχνά να επιτευχθεί διαφορετικά (ρύθμιση, εσωτερική διαδικασία, ή τρίτο εργαλείο, ενίοτε ελεύθερο και λιγότερο δαπανηρό). Θα ξαναγίνονταν μετρήσιμοι αν ο πόρος ήταν παρών στον μισθωτή σας.
6 point(s) de vigilance organisationnels
Αυτές οι απαιτήσεις (φυσική ασφάλεια, τμηματοποίηση δικτύου, ευαισθητοποίηση, διακυβέρνηση) ανήκουν στον οργανισμό και ΔΕΝ είναι μετρήσιμες με σάρωση Microsoft 365 μόνο για ανάγνωση. Αναφέρονται χωριστά, εκτός βαθμολογίας και εκτός καταμέτρησης αποκλίσεων: προς επαλήθευση με εσωτερική επισκόπηση.
SYAGA Audit · εκδίδεται από την SYAGA CONSULTINGΕπαληθεύσιμος έλεγχος, ποτέ πιστοποίηση