Ensure an exclusionary geographic Conditional Access policy is considered
Skills in this repository
CyberStrikeus/CyberStrike - Page 172
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Ensure an exclusionary device code flow policy is considered
Ensure a multifactor authentication policy exists for all users
Ensure multifactor authentication is required for risky sign-ins
Ensure multifactor authentication is required for Windows Azure Service Management API
Ensure multifactor authentication is required to access Microsoft Admin Portals
Ensure a Token Protection Conditional Access policy is considered
Ensure 'Owners can manage group membership requests in My Groups' is set to 'No'
Ensure 'Users can create Microsoft 365 groups in Azure portals, API or PowerShell' is set to 'No'
Ensure 'Require Multifactor Authentication to register or join devices with Microsoft Entra' is set to 'Yes'
Ensure no custom subscription administrator roles exist
Ensure a custom role is assigned permissions for administering resource locks
Ensure 'Subscription leaving/entering Microsoft Entra tenant' is set to 'Permit no one'
Ensure fewer than 5 users have global administrator assignment
Ensure there are between 2 and 3 subscription owners
Ensure passwordless authentication methods are considered
Ensure Azure admin accounts are not used for daily operations
Ensure guest users are reviewed on a regular basis
Ensure use of the 'User Access Administrator' role is restricted
Ensure all 'privileged' role assignments are periodically reviewed
Ensure disabled user accounts do not have read, write, or owner permissions
Ensure 'Tenant Creator' role assignments are periodically reviewed
Ensure all non-privileged role assignments are periodically reviewed
Ensure 'Restrict non-admin users from creating tenants' is set to 'Yes'
Ensure 'Number of methods required to reset' is set to '2'
Ensure account 'Lockout threshold' is less than or equal to '10'
Ensure account 'Lockout duration in seconds' is greater than or equal to '60'
Ensure 'Custom banned password list' is set to 'Enforce'
Ensure 'Number of days before users are asked to re-confirm their authentication information' is not set to '0'
Ensure that a 'Diagnostic Setting' exists for Subscription Activity Logs
Ensure Intune logs are captured and sent to Log Analytics
Ensure Diagnostic Setting captures appropriate categories
Ensure storage account containing activity logs is encrypted with CMK
Ensure that logging for Azure Key Vault is 'Enabled'
Ensure Network Security Group Flow logs are captured and sent to Log Analytics
Ensure logging for Azure AppService 'HTTP logs' is enabled
Ensure virtual network flow logs are captured and sent to Log Analytics
Ensure Microsoft Entra diagnostic setting exists to send Microsoft Graph activity logs
Ensure Microsoft Entra diagnostic setting exists to send Microsoft Entra activity logs
Ensure Activity Log Alert exists for Create Policy Assignment