用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-azure-foundations-5-2-8命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-azure-foundations-5.2.8 |
| description | Ensure a Token Protection Conditional Access policy is considered |
| category | cis-azure-foundations |
| version | 5.0.0 |
| author | cyberstrike-official |
| tags | ["cis","azure","identity","conditional-access"] |
| cis_id | 5.2.8 |
| cis_benchmark | CIS Microsoft Azure Foundations Benchmark v5.0.0 |
| tech_stack | ["azure"] |
| cwe_ids | [] |
| chains_with | ["cis-azure-foundations-5.2.7","cis-azure-foundations-5.2.4"] |
| prerequisites | [] |
| severity_boost | {} |
This recommendation ensures that issued tokens are only issued to the intended device.
When properly configured, conditional access can aid in preventing attacks involving token theft, via hijacking or reply, as part of the attack flow. Although currently considered a rare event, the impact from token impersonation can be severe.
A Microsoft Entra ID P1 or P2 license is required.
Start with a Conditional Access policy in "Report Only" mode prior to enforcing for all users.
Conditional Access Administrator.Protection > Conditional Access > Policies.Assignments, review Users or workload identities and
Include, ensure the scope of the users or groups is appropriate for your organization.Exclude, ensure only necessary users and groups (your organization's emergency access or break-glass accounts) are excepted.Target resources > Resources > Include > Select resources: Ensure that both Office 365 Exchange Online and Office 365 SharePoint Online are selected.Conditions > Device Platforms: Ensure Configure is set to Yes and Include indicates Windows platforms.Conditions > Client Apps: Ensure Configure is set to Yes and Mobile Apps and Desktop Clients is selected under Modern Authentication Clients.Access controls > Session, ensure that Require token protection for sign-in sessions is selected.At least one Conditional Access policy should exist with Token Protection configured, targeting Office 365 Exchange Online and SharePoint Online on Windows platforms with mobile apps and desktop clients.
Conditional Access Administrator.Protection > Conditional Access > Policies.New policy.Assignments, select Users or workload identities.
Include, select the users or groups to apply this policy.Exclude, select Users and groups and choose your organization's emergency access or break-glass accounts (if applicable).Target resources > Resources > Include > Select resources
Select, select the following applications:
Select.Conditions:
Device platforms
Configure to Yes.Include > Select device platforms > Windows.Done.Client apps:
Configure to Yes.Mobile apps and desktop clients.Done.Access controls > Session, select Require token protection for sign-in sessions and select Select.On.Create to enable your policy.A Token Protection Conditional Access policy does not exist by default.
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 6.3 Require MFA for Externally-Exposed Applications | x | x | |
| v8 | 6.4 Require MFA for Remote Network Access | x | x | x |
Level 2 | Manual