Os seus 85 desvios não são 85 problemas: reduzem-se a quatro causas-raiz. Trate-os por ordem e neutraliza o essencial do risco com um esforço concentrado, sem refazer tudo.
Uma prova, três leitores. Este dossiê foi concebido para ser apresentado a uma seguradora cibernética (formato de subscrição), a um cliente contratante que exige a prova da sua postura (efeito cascata na cadeia de fornecedores, NIS2 Art. 21 - versão partilhável), e a um revisor oficial de contas ou auditor externo. Cada constatação abaixo é verificável nos seus próprios registos Microsoft: oponível, não declarativa.
195 controlo(s) conforme(s) em 280 controlos avaliados - a base verificável que já pode ser apresentada a uma seguradora, ponto por ponto, com prova. Postura classificada como C, sem lisonja, apenas com base no que foi avaliado.
85 não conformidade(s) constatada(s) e 63 controlo(s) não medido(s) permanecem uma exposição não coberta por prova oponível: enquanto as causas-raiz abaixo não forem tratadas, esta exposição não pode ser atestada.
| Referência | Ponto de controlo | Severidade |
|---|---|---|
| M365SEC:2.4.2M365SAT, Monkey365 | MEx 2.4.2 - Priority accounts do not have 'Strict protection' presets applied | Elevada |
| M365SEC:7.3.2M365SAT, Monkey365 | MSp 7.3.2 - OneDrive for Business sync from unmanaged devices is not blocked | Elevada |
| MT.1037Maester | Only users with Presenter role are allowed to present in Teams meetings | Elevada |
| MT.1034Maester | MT.1034.$($EmergencyAccessUsers.IndexOf($_)): Emergency access users should not be blocked ($($_.userPrincipalName)) | A remediar |
| M365SEC:5.2.2.2M365SAT, Monkey365 | MAz 5.2.2.2 - MultiFactor Authentication (MFA) is not enabled for all users non-administrative roles | Crítica |
| CISA:MS.AAD.3.2Maester, ScubaGear | If phishing-resistant MFA has not been enforced, an alternative MFA method SHALL be enforced for all users. | Crítica |
| M365SEC:5.1.5.2M365SAT, Maester, Monkey365 | CISMAz 5.1.5.2 - User consent to apps accessing company data on their behalf is allowed! | Elevada |
| M365SEC:5.2.3.4M365SAT, Monkey365 | MAz 5.2.3.4 - Not all member users are 'MFA capable' | Elevada |
| ORCA.140Maester | High Confidence Spam action set to Quarantine message. | Elevada |
| ORCA.189.2Maester | Safe Links is not bypassed. | Elevada |
| Referência | Ponto de controlo | Estado |
|---|---|---|
| M365SEC:1.3.5M365SAT, Maester, Monkey365 | MOff 1.3.5 - Internal phishing protection for Forms is disabled | Não medido |
| M365SEC:2.4.1M365SAT, Monkey365 | MEx 2.4.1 - Priority account protection is not enabled and configured! | Não medido |
| M365SEC:3.2.1M365SAT, Monkey365 | MEx 3.2.1 - DLP Policy is not enabled! | Não medido |
| M365SEC:7.2.7M365SAT, Maester, Monkey365 | MSp 7.2.7 - Ensure link sharing is not restricted in SharePoint and OneDrive! | Não medido |
| CISA:MS.AAD.4.1Maester, ScubaGear | Security logs SHALL be sent to the agency's security operations center for monitoring. | Não medido |
| M365SEC:6.2.1M365SAT, Monkey365 | MEx 6.2.1 - Forms of mail forwarding are not blocked and/or not disabled | Não medido |
| CISA:MS.EXO.13.1Maester, ScubaGear | Mailbox auditing SHALL be enabled. | Não medido |
| M365SEC:4.2Monkey365 | Devices enrollment personal devices not blocked | Não medido |
| M365SEC:7.2.11Maester, Monkey365 | Ensure the SharePoint default sharing link permission is set | Não medido |
| MT.1027Maester | No Service Principal with Client Secret and permanent role assignment on Control Plane. | Não medido |
| Referência | Ponto de controlo | Severidade |
|---|---|---|
| ANSSI R13ANSSI/NIS2 ANSSI R13 | ANSSI R13 | Conforme |
| ANSSI R14ANSSI/NIS2 ANSSI R14 | ANSSI R14 | Conforme |
| ANSSI R16ANSSI/NIS2 ANSSI R16 | ANSSI R16 | Conforme |
| ANSSI R24ANSSI/NIS2 ANSSI R24 | ANSSI R24 | Conforme |
| ANSSI R29ANSSI/NIS2 ANSSI R29 | ANSSI R29 | Conforme |
| ANSSI R36ANSSI/NIS2 ANSSI R36 | ANSSI R36 | Conforme |
| ANSSI R5ANSSI/NIS2 ANSSI R5 | ANSSI R5 | Conforme |
| ANSSI R8ANSSI/NIS2 ANSSI R8 | ANSSI R8 | Conforme |
| M365SEC:5.1.1.1M365SAT CISMAz5111 | CISMAz 5.1.1.1 - The Security Defaults are enabled on Azure Active Directory Tenant | Conforme |
| M365SEC:6.1.4M365SAT CISMEx614 | MEx 6.1.4 - Des boîtes aux lettres portent-elles 'AuditBypassEnabled', qui les exclut du journal d'audit ? | Conforme |
| CISA:MS.EXO.10.1Maester CISA.MS.EXO.10.1 | Emails SHALL be scanned for malware. | Conforme |
| CISA:MS.EXO.10.2Maester CISA.MS.EXO.10.2 | Emails identified as containing malware SHALL be quarantined or dropped. | Conforme |
| CISA:MS.EXO.10.3Maester CISA.MS.EXO.10.3 | Email scanning SHALL be capable of reviewing emails after delivery. | Conforme |
| CISA:MS.EXO.11.1Maester CISA.MS.EXO.11.1 | Impersonation protection checks SHOULD be used. | Conforme |
| CISA:MS.EXO.11.2Maester CISA.MS.EXO.11.2 | User warnings, comparable to the user safety tips included with EOP, SHOULD be displayed. | Conforme |
| CISA:MS.EXO.11.3Maester CISA.MS.EXO.11.3 | The phishing protection solution SHOULD include an AI-based phishing detection tool comparable to EOP Mailbox Intelligence. | Conforme |
| CISA:MS.EXO.12.1Maester CISA.MS.EXO.12.1 | IP allow lists SHOULD NOT be created. | Conforme |
| CISA:MS.EXO.14.1Maester CISA.MS.EXO.14.1 | A spam filter SHALL be enabled. | Conforme |
| CISA:MS.EXO.14.2Maester CISA.MS.EXO.14.2 | Spam and high confidence spam SHALL be moved to either the junk email folder or the quarantine folder. | Conforme |
| CISA:MS.EXO.14.3Maester CISA.MS.EXO.14.3 | Allowed domains SHALL NOT be added to inbound anti-spam protection policies. | Conforme |
| CISA:MS.EXO.15.1Maester CISA.MS.EXO.15.1 | URL comparison with a block-list SHOULD be enabled. | Conforme |
| CISA:MS.EXO.15.2Maester CISA.MS.EXO.15.2 | Direct download links SHOULD be scanned for malware. | Conforme |
| CISA:MS.EXO.15.3Maester CISA.MS.EXO.15.3 | User click tracking SHOULD be enabled. | Conforme |
| CISA:MS.EXO.16.1Maester CISA.MS.EXO.16.1 | Alerts SHALL be enabled. | Conforme |
| CISA:MS.EXO.16.2Maester CISA.MS.EXO.16.2 | Alerts SHOULD be sent to a monitored address or incorporated into a security information and event management (SIEM) system. | Conforme |
| CISA:MS.EXO.17.1Maester CISA.MS.EXO.17.1 | Microsoft Purview Audit (Standard) logging SHALL be enabled. | Conforme |
| CISA:MS.EXO.2.1Maester CISA.MS.EXO.2.1 | A list of approved IP addresses for sending mail SHALL be maintained. | Conforme |
| EIDSCA.AF01Maester EIDSCA.AF01 | Authentication method - FIDO2 security key - State. | Conforme |
| EIDSCA.AF02Maester EIDSCA.AF02 | Authentication Method - FIDO2 security key - Allow self-service set up. | Conforme |
| EIDSCA.AF03Maester EIDSCA.AF03 | Authentication method - FIDO2 security key - Enforce attestation. | Conforme |
| EIDSCA.AF04Maester EIDSCA.AF04 | Authentication method - FIDO2 security key - Enforce key restrictions. | Conforme |
| EIDSCA.AF05Maester EIDSCA.AF05 | Authentication method - FIDO2 security key - Restricted. | Conforme |
| EIDSCA.AF06Maester EIDSCA.AF06 | Authentication Method - FIDO2 security key - Restrict specific keys. | Conforme |
| EIDSCA.AG01Maester EIDSCA.AG01 | Authentication method - General settings - Manage migration. | Conforme |
| EIDSCA.AG02Maester EIDSCA.AG02 | Authentication method - General settings - Report suspicious activity - State. | Conforme |
| EIDSCA.AM01Maester EIDSCA.AM01 | Authentication method - Microsoft Authenticator - State. | Conforme |
| EIDSCA.AM02Maester EIDSCA.AM02 | Authentication method - Microsoft Authenticator - Allow use of Microsoft Authenticator OTP. | Conforme |
| EIDSCA.AM03Maester EIDSCA.AM03 | Authentication Method - Microsoft Authenticator - Require number matching for push notifications. | Conforme |
| EIDSCA.AM04Maester EIDSCA.AM04 | Authentication Method - Microsoft Authenticator - Included users/groups of number matching for push notifications. | Conforme |
| EIDSCA.AM06Maester EIDSCA.AM06 | Authentication Method - Microsoft Authenticator - Show application name in push and passwordless notifications. | Conforme |
| EIDSCA.AM07Maester EIDSCA.AM07 | Authentication method - Microsoft Authenticator - Users and groups included for showing the application name in push and passwordless notifications. | Conforme |
| EIDSCA.AM09Maester EIDSCA.AM09 | Authentication Method - Microsoft Authenticator - Show geographic location in push and passwordless notifications. | Conforme |
| EIDSCA.AM10Maester EIDSCA.AM10 | Authentication method - Microsoft Authenticator - Users and groups included for showing the geographic location in push and passwordless notifications. | Conforme |
| EIDSCA.AP01Maester EIDSCA.AP01 | Default authorization settings - Self-service password reset enabled for administrators. | Conforme |
| EIDSCA.AP04Maester EIDSCA.AP04 | Default Authorization Settings - Guest invite restrictions. | Conforme |
| EIDSCA.AP06Maester EIDSCA.AP06 | Default Authorization Settings - User can join the tenant by email validation. | Conforme |
| EIDSCA.AP08Maester EIDSCA.AP08 | Default authorization settings - User consent policy assigned for applications. | Conforme |
| EIDSCA.AP10Maester EIDSCA.AP10 | Default Authorization Settings - Default User Role Permissions - Allowed to create Apps. | Conforme |
| EIDSCA.AS04Maester EIDSCA.AS04 | Authentication Method - SMS - Use for sign-in. | Conforme |
| EIDSCA.AT01Maester EIDSCA.AT01 | Authentication method - Temporary Access Pass - State. | Conforme |
| EIDSCA.AT02Maester EIDSCA.AT02 | Authentication method - Temporary Access Pass - One-time use. | Conforme |
| EIDSCA.AV01Maester EIDSCA.AV01 | Authentication method - Voice call - State. | Conforme |
| EIDSCA.CP01Maester EIDSCA.CP01 | Default settings - Consent policy settings - Group owner consent for apps accessing data. | Conforme |
| EIDSCA.CP03Maester EIDSCA.CP03 | Default Settings - Consent Policy Settings - Block user consent for risky apps. | Conforme |
| EIDSCA.PR02Maester EIDSCA.PR02 | Default Settings - Password Rule Settings - Password Protection - Enable password protection on Windows Server Active Directory. | Conforme |
| EIDSCA.PR03Maester EIDSCA.PR03 | Default settings - Password rule settings - Enforce custom list. | Conforme |
| EIDSCA.PR05Maester EIDSCA.PR05 | Default Settings - Password Rule Settings - Smart Lockout - Lockout duration in seconds. | Conforme |
| EIDSCA.PR06Maester EIDSCA.PR06 | Default settings - Password rule settings - Smart Lockout - Lockout threshold. | Conforme |
| EIDSCA.ST08Maester EIDSCA.ST08 | Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to become Group Owner. | Conforme |
| EIDSCA.ST09Maester EIDSCA.ST09 | Default settings - Classification and M365 groups - M365 groups - Allow guests to access group content. | Conforme |
| M365SEC:1.1.1Maester M365.1.1.1 | MOff 1.1.1 - Ensure Administrative accounts are separate and cloud-only | Conforme |
| M365SEC:1.1.3Maester M365.1.1.3 | Ensure that between two and four global admins are designated | Conforme |
| M365SEC:1.3.1Maester M365.1.3.1 | Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)' | Conforme |
| M365SEC:1.3.3Maester M365.1.3.3 | Ensure 'External sharing' of calendars is not available | Conforme |
| M365SEC:1.3.4Maester M365.1.3.4 | MOff 1.3.4 - User owned apps and services are not restricted | Conforme |
| M365SEC:2.1.1Maester M365.2.1.1 | Ensure Safe Links for Office Applications is Enabled (Only Checks Default Policy) | Conforme |
| M365SEC:2.1.11Maester M365.2.1.11 | Ensure comprehensive attachment filtering is applied | Conforme |
| M365SEC:2.1.2Maester M365.2.1.2 | Ensure the Common Attachment Types Filter is enabled (Only Checks Default Policy) | Conforme |
| M365SEC:2.1.3Maester M365.2.1.3 | Ensure notifications for internal users sending malware is Enabled (Only Checks Default Policy) | Conforme |
| M365SEC:2.1.4Maester M365.2.1.4 | Ensure Safe Attachments policy is enabled (Only Checks Default Policy) | Conforme |
| M365SEC:2.1.5Maester M365.2.1.5 | Ensure Safe Attachments for SharePoint, OneDrive, and Microsoft Teams is Enabled | Conforme |
| M365SEC:2.1.6Maester M365.2.1.6 | Ensure Exchange Online Spam Policies are set to notify administrators (Only Checks Default Policy) | Conforme |
| M365SEC:2.1.7Maester M365.2.1.7 | Ensure that an anti-phishing policy has been created (Only Checks Default Policy) | Conforme |
| M365SEC:3.1.1Maester M365.3.1.1 | MEx 3.1.1 - Microsoft 365 audit log search is Disabled! | Conforme |
| M365SEC:4.1Maester M365.4.1 | Ensure devices without a compliance policy are marked | Conforme |
| M365SEC:5.1.2.2Maester M365.5.1.2.2 | MAz 5.1.2.2 - Third party integrated applications are allowed! | Conforme |
| M365SEC:5.1.5.1Maester M365.5.1.5.1 | Ensure user consent to apps accessing company data on their behalf is not allowed | Conforme |
| M365SEC:5.1.6.2Maester M365.5.1.6.2 | Ensure that guest user access is restricted | Conforme |
| M365SEC:5.2.3.5Maester M365.5.2.3.5 | Ensure weak authentication methods are disabled | Conforme |
| M365SEC:7.2.2Maester M365.7.2.2 | MSp 7.2.2 - SharePoint and OneDrive integration with Azure AD B2B is not enabled! | Conforme |
| M365SEC:7.2.5Maester M365.7.2.5 | Ensure that SharePoint guest users cannot share items they don | Conforme |
| M365SEC:7.2.9Maester M365.7.2.9 | MSp 7.2.9 - Guest access to a site or OneDrive does not expire automatically | Conforme |
| M365SEC:7.3.1Maester M365.7.3.1 | MSp 7.3.1 - Office 365 SharePoint infected files are NOT disallowed for download | Conforme |
| M365SEC:8.4.1Maester M365.8.4.1 | Ensure all or a majority of third-party and custom apps are blocked | Conforme |
| M365SEC:8.6.1Maester M365.8.6.1 | Ensure users can report security concerns in Teams to internal destination | Conforme |
| MT.1003Maester MT.1003 | At least one Conditional Access policy is configured with All Apps. | Conforme |
| MT.1004Maester MT.1004 | At least one Conditional Access policy is configured with All Apps and All Users. | Conforme |
| MT.1006Maester MT.1006 | At least one Conditional Access policy is configured to require MFA for administrators. | Conforme |
| MT.1007Maester MT.1007 | At least one Conditional Access policy is configured to require MFA for all users. | Conforme |
| MT.1008Maester MT.1008 | At least one Conditional Access policy is configured to require MFA for Azure management. | Conforme |
| MT.1009Maester MT.1009 | At least one Conditional Access policy is configured to block other legacy authentication. | Conforme |
| MT.1010Maester MT.1010 | At least one Conditional Access policy is configured to block legacy authentication for Exchange ActiveSync. | Conforme |
| MT.1011Maester MT.1011 | At least one Conditional Access policy is configured to secure security info registration only from a trusted location. | Conforme |
| MT.1014Maester MT.1014 | At least one Conditional Access policy is configured to require compliant or Entra hybrid joined devices for administrators. | Conforme |
| MT.1015Maester MT.1015 | At least one Conditional Access policy is configured to block access from unknown or unsupported device platforms. | Conforme |
| MT.1016Maester MT.1016 | At least one Conditional Access policy is configured to require MFA for guest access. | Conforme |
| MT.1020Maester MT.1020 | All Conditional Access policies are configured to exclude directory synchronisation accounts, or do not target them. | Conforme |
| MT.1022Maester MT.1022 | MT.1022 | Conforme |
| MT.1025Maester MT.1025 | No external user with permanent role assignment on Control Plane. | Conforme |
| MT.1026Maester MT.1026 | No hybrid user with permanent role assignment on Control Plane. | Conforme |
| MT.1031Maester MT.1031 | Control Plane privileged roles are managed by PIM only. | Conforme |
| MT.1032Maester MT.1032 | A limited number of Global Administrators is assigned. | Conforme |
| MT.1044Maester MT.1044 | Ensure modern authentication for Exchange Online is enabled | Conforme |
| MT.1045Maester MT.1045 | Only guest users should be admitted automatically to Teams meetings | Conforme |
| MT.1050Maester MT.1050 | Applications with high-risk permissions having a direct path to Global Administrator. | Conforme |
| MT.1051Maester MT.1051 | Applications with high-risk permissions having an indirect path to Global Administrator. | Conforme |
| MT.1052Maester MT.1052 | At least one Conditional Access policy targets the Device Code authentication flow. | Conforme |
| MT.1061Maester MT.1061 | The device registration MFA control conflicts with Conditional Access policies. | Conforme |
| MT.1066Maester MT.1066 | Conditional Access policies should not include or exclude deleted users, groups or roles. | Conforme |
| MT.1071Maester MT.1071 | At least one Conditional Access policy explicitly includes Azure DevOps. | Conforme |
| MT.1072Maester MT.1072 | Conditional Access policies should not use the deprecated Approved Client App grant. | Conforme |
| MT.1075Maester MT.1075 | Third-party Entra applications should have explicitly assigned users rather than All Users. | Conforme |
| MT.1105Maester MT.1105 | The MDM authority should be set to Microsoft Intune | Conforme |
| ORCA.101Maester ORCA.101 | Bulk is marked as spam. | Conforme |
| ORCA.102Maester ORCA.102 | Advanced Spam filter options are turned off. | Conforme |
| ORCA.104Maester ORCA.104 | High Confidence Phish action set to Quarantine message. | Conforme |
| ORCA.108.1Maester ORCA.108.1 | DNS Records have been set up to support DKIM. | Conforme |
| ORCA.109Maester ORCA.109 | Senders are not unsafely allow listed. | Conforme |
| ORCA.111Maester ORCA.111 | Anti-phishing policy exists and EnableUnauthenticatedSender is true. | Conforme |
| ORCA.112Maester ORCA.112 | Anti-spoofing protection action is configured to Move message to the recipients' Junk Email folders in Anti-phishing policy. | Conforme |
| ORCA.118.1Maester ORCA.118.1 | Domains are not unsafely allow listed in anti-spam policies. | Conforme |
| ORCA.118.3Maester ORCA.118.3 | Your own domains are not unsafely allow listed in anti-spam policies. | Conforme |
| ORCA.121Maester ORCA.121 | A supported filter policy action is in use. | Conforme |
| ORCA.124Maester ORCA.124 | Safe Attachments unknown malware response is set to block messages. | Conforme |
| ORCA.139Maester ORCA.139 | The spam action is set to move the message to the Junk Email folder or to quarantine. | Conforme |
| ORCA.141Maester ORCA.141 | Bulk action set to Move message to Junk Email Folder. | Conforme |
| ORCA.143Maester ORCA.143 | Safety Tips are enabled. | Conforme |
| ORCA.158Maester ORCA.158 | Safe Attachments is enabled for SharePoint and Teams. | Conforme |
| ORCA.180Maester ORCA.180 | Anti-phishing policy exists and EnableSpoofIntelligence is true. | Conforme |
| ORCA.221Maester ORCA.221 | Mailbox Intelligence is enabled in anti-phishing policies. | Conforme |
| ORCA.225Maester ORCA.225 | Safe Documents is enabled for Office clients. | Conforme |
| ORCA.226Maester ORCA.226 | Every domain has a Safe Links policy applied to it. | Conforme |
| ORCA.227Maester ORCA.227 | Every domain has a Safe Attachments policy applied to it. | Conforme |
| ORCA.228Maester ORCA.228 | No trusted senders in Anti-phishing policy. | Conforme |
| ORCA.229Maester ORCA.229 | No trusted domains in Anti-phishing policy. | Conforme |
| ORCA.230Maester ORCA.230 | Each domain has a Anti-phishing policy applied to it, or the default policy is being used. | Conforme |
| ORCA.231Maester ORCA.231 | Each domain has a anti-spam policy applied to it, or the default policy is being used. | Conforme |
| ORCA.232Maester ORCA.232 | Each domain has a malware filter policy applied to it, or the default policy is being used. | Conforme |
| ORCA.234Maester ORCA.234 | Click through is disabled for Safe Documents. | Conforme |
| ORCA.236Maester ORCA.236 | Safe Links is enabled for emails. | Conforme |
| ORCA.237Maester ORCA.237 | Safe Links is enabled for teams messages. | Conforme |
| ORCA.238Maester ORCA.238 | Safe Links is enabled for office documents. | Conforme |
| ORCA.240Maester ORCA.240 | Outlook is configured to display external tags for external emails. | Conforme |
| ORCA.242Maester ORCA.242 | The significant protection alerts responsible for AIR activity are enabled. | Conforme |
| ORCA.244Maester ORCA.244 | Policies are configured to honour the DMARC policy of sending domains. | Conforme |
| M365SEC:5.2.2.3Monkey365 eid-cap-block-legacy-authentication-not-enabled | MAz 5.2.2.3 - No Conditional Access policies to block legacy authentication | Conforme |
| M365SEC:5.2.2.4Monkey365 eid-cap-lack-sign-in-frequency-browser-persistent-session | MAz 5.2.2.4 - Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative users | Conforme |
| M365SEC:5.2.2.12Monkey365 eid-device-code-sign-in-flow-not-enabled | Eid device code sign in flow not enabled | Conforme |
| M365SEC:5.2.2.1Monkey365 eid-ensure-mfa-for-high-privileged-users-missing-cap | MAz 5.2.2.1 - MultiFactor Authentication (MFA) is not enabled for all users in administrative roles | Conforme |
| M365SEC:5.2.2.5Monkey365 eid-ensure-phishing-resistant-mfa-for-high-privileged-users-missing-cap | MAz 5.2.2.5 - Phishing-resistant MFA strength must be required for Administrators | Conforme |
| M365SEC:5.1.6.3Monkey365 eid-guest-invite-restriction-disabled | Eid guest invite restriction disabled | Conforme |
| M365SEC:5.2.3.1Monkey365 eid-microsoft-authenticator-lack-mfa-fatigue-protection | MAz 5.2.3.1 - Microsoft Authenticator is not configured to protect against MFA fatigue | Conforme |
| M365SEC:5.1.8.1Monkey365 eid-password-hash-sync-disabled | MAz 5.1.8.1 - Password Synchronization Disabled | Conforme |
| M365SEC:5.2.2.9Monkey365 eid-require-device-compliant-all-apps-missing-cap | Eid require device compliant all apps missing cap | Conforme |
| M365SEC:5.2.2.10Monkey365 eid-require-device-compliant-to-register-security-info-missing-cap | Eid require device compliant to register security info missing cap | Conforme |
| M365SEC:5.1.6.1Monkey365 eid-restrict-collaboration-specific-domains-disabled | MAz 5.1.6.1 - Collaboration invitations are not sent to allowed domains only | Conforme |
| M365SEC:5.2.2.11Monkey365 eid-sign-in-frequency-intune-enrollment-missing-cap | Eid sign in frequency intune enrollment missing cap | Conforme |
| M365SEC:5.2.4.1Monkey365 eid-sspr-enabled-set-to-all | MAz 5.2.4.1 - Self Service Password Reset is not set to be enabled for all users | Conforme |
| M365SEC:6.1.3Monkey365 exchange-audit-bypass-enabled | Exchange audit bypass enabled | Conforme |
| M365SEC:6.1.1Monkey365 exchange-audit-enabled-globally | MEx 6.1.1 - Mailbox auditing is not Enabled for all users | Conforme |
| M365SEC:6.2.3Monkey365 exchange-external-email-sender-configured | MEx 6.2.3 - Email from external senders cannot be identified | Conforme |
| M365SEC:6.5.1Monkey365 exchange-modern-authentication-disabled | Exchange modern authentication disabled | Conforme |
| M365SEC:2.1.14Monkey365 exhange-inbound-anti-spam-policies-allowed-domains | MEx 2.1.14 - No comprehensive attachment filtering is applied! | Conforme |
| M365SEC:7.2.8Monkey365 sharepoint-external-sharing-not-restricted-by-security-group | MSp 7.2.8 - Ensure external sharing is restricted by security group! | Conforme |
| M365SEC:7.2.1Monkey365 sharepoint-modern-authentication-required | SharePoint modern authentication required | Conforme |
| M365SEC:8.5.1Monkey365 teams-anonymous-users-cant-join-meeting | CISM Tm 8.5.1 - Anonymous users can join a meeting | Conforme |
| CISA:MS.AAD.1.1ScubaGear MS.AAD.1.1v1 | Legacy authentication SHALL be blocked. | Conforme |
| CISA:MS.AAD.3.1ScubaGear MS.AAD.3.1v1 | Phishing-resistant MFA SHALL be enforced for all users. | Conforme |
| CISA:MS.AAD.3.3ScubaGear MS.AAD.3.3v2 | If Microsoft Authenticator is enabled, it SHALL be configured to show login context information. | Conforme |
| CISA:MS.AAD.3.4ScubaGear MS.AAD.3.4v1 | The Authentication Methods Manage Migration feature SHALL be set to Migration Complete. | Conforme |
| CISA:MS.AAD.3.6ScubaGear MS.AAD.3.6v1 | Phishing-resistant MFA SHALL be required for highly privileged roles. | Conforme |
| CISA:MS.AAD.3.7ScubaGear MS.AAD.3.7v1 | Managed devices SHOULD be required for authentication. | Conforme |
| CISA:MS.AAD.3.8ScubaGear MS.AAD.3.8v1 | Managed Devices SHOULD be required to register MFA. | Conforme |
| CISA:MS.AAD.3.9ScubaGear MS.AAD.3.9v1 | Device code authentication SHOULD be blocked. | Conforme |
| CISA:MS.AAD.5.1ScubaGear MS.AAD.5.1v1 | Only administrators SHALL be allowed to register applications. | Conforme |
| CISA:MS.AAD.5.2ScubaGear MS.AAD.5.2v1 | Only administrators SHALL be allowed to consent to applications. | Conforme |
| CISA:MS.AAD.6.1ScubaGear MS.AAD.6.1v1 | User passwords SHALL NOT expire. | Conforme |
| CISA:MS.AAD.7.1ScubaGear MS.AAD.7.1v1 | A minimum of two users and a maximum of eight users SHALL be provisioned with the Global Administrator role. | Conforme |
| CISA:MS.AAD.7.2ScubaGear MS.AAD.7.2v1 | Privileged users SHALL be provisioned with finer-grained roles instead of Global Administrator. | Conforme |
| CISA:MS.AAD.7.4ScubaGear MS.AAD.7.4v1 | Permanent active role assignments SHALL NOT be allowed for highly privileged roles. | Conforme |
| CISA:MS.AAD.8.1ScubaGear MS.AAD.8.1v1 | Guest users SHOULD have limited or restricted access to Microsoft Entra ID directory objects. | Conforme |
| CISA:MS.AAD.8.2ScubaGear MS.AAD.8.2v1 | Only users with the Guest Inviter role SHOULD be able to invite guest users. | Conforme |
| CISA:MS.AAD.8.3ScubaGear MS.AAD.8.3v1 | Guest invites SHOULD only be allowed to specific external domains that have been authorized by the agency for legitimate business purposes. | Conforme |
| CISA:MS.DEFENDER.2.2ScubaGear MS.DEFENDER.2.2v1 | Domain impersonation protection SHOULD be enabled for agency-owned domains in standard and strict policies. | Conforme |
| CISA:MS.DEFENDER.2.3ScubaGear MS.DEFENDER.2.3v1 | Domain impersonation protection SHOULD be added for key suppliers and partners in standard and strict policies. | Conforme |
| CISA:MS.DEFENDER.3.1ScubaGear MS.DEFENDER.3.1v1 | Safe attachments SHOULD be enabled for SharePoint, OneDrive, and Microsoft Teams. | Conforme |
| CISA:MS.DEFENDER.5.1ScubaGear MS.DEFENDER.5.1v1 | Alerts required by Exchange Online baseline SHALL be enabled at minimum. | Conforme |
| CISA:MS.DEFENDER.5.2ScubaGear MS.DEFENDER.5.2v1 | Alerts SHOULD be sent to a monitored address or incorporated into SIEM. | Conforme |
| CISA:MS.DEFENDER.6.1ScubaGear MS.DEFENDER.6.1v1 | Unified Audit logging SHALL be enabled. | Conforme |
| CISA:MS.EXO.1.1ScubaGear MS.EXO.1.1v2 | Automatic forwarding to external domains SHALL be disabled. | Conforme |
| CISA:MS.EXO.6.1ScubaGear MS.EXO.6.1v1 | Contact folders SHALL NOT be shared with all domains. | Conforme |
| CISA:MS.EXO.6.2ScubaGear MS.EXO.6.2v1 | Calendar details SHALL NOT be shared with all domains. | Conforme |
| CISA:MS.EXO.7.1ScubaGear MS.EXO.7.1v1 | External sender warnings SHALL be implemented. | Conforme |
| CISA:MS.SHAREPOINT.1.3ScubaGear MS.SHAREPOINT.1.3v1 | External sharing SHALL be restricted to approved external domains and/or users in approved security groups per interagency collaboration needs. | Conforme |
| CISA:MS.TEAMS.1.3ScubaGear MS.TEAMS.1.3v1 | Anonymous users and dial-in callers SHOULD NOT be admitted automatically. | Conforme |
A prova verificável é o argumento. Este diagnóstico nunca viu os seus dados: apenas foram lidos parâmetros de configuração, nunca um conteúdo pessoal. Cada constatação acima é verificável nos seus próprios registos Microsoft, logo oponível - seja o leitor uma seguradora, um cliente contratante que o audita, ou um revisor oficial de contas.