Generated on 27/07/2026 14:32 — 64 controls.
| Referential | Control | Level | Status | Result & remediation |
|---|---|---|---|---|
| Entra | Require compliant or hybrid-joined devices | L2 | Compliant | Frameworks : CIS Active Directory · NIST AC-2, AC-12 · ISO 27001 A.8.2, A.8.5 · CISA SCuBA MS.AAD.3.7 · DORA Art. 9 · NIS2 21.2(h) |
| Defender | Enable Safe Links for Office apps and Teams | L1 | Compliant | Frameworks : CIS Active Directory 2.1.1 · NIST SI-3 · ISO 27001 A.8.7 · DORA Art. 10 · NIS2 21.2(b) |
| OneDrive | Enforce app-enforced restrictions on unmanaged devices | L2 | Compliant | Frameworks : CIS Active Directory · CISA SCuBA · NIST AC-3 · ISO 27001 A.8.5 · DORA Art. 9 · NIS2 21.2(h) |
| Purview | Enable the unified audit log | L1 | Compliant | Frameworks : CIS Active Directory · NIST AU-2 · ISO 27001 A.8.15 · CISA SCuBA MS.DEFENDER.6.1 · ANSSI Journalisation · DORA Art. 10 · NIS2 21.2(b) |
| Teams | Limit public teams | L2 | Warning | Remediation : Review public teams and switch non-legitimate ones to 'Private' (team settings or Set-Team -Visibility Private). Frameworks : CIS Active Directory · NIST AC-3 · ISO 27001 A.5.15 · DORA Art. 9 · NIS2 21.2(i) |
| Entra | Require an approved app or an app protection policy | L2 | Compliant | Frameworks : CIS Active Directory · NIST AC-2, AC-12 · ISO 27001 A.8.2, A.8.5 · DORA Art. 9 · NIS2 21.2(i) |
| Entra | Block legacy authentication | L1 | Not assessed | Remediation : Conditional Access: create a policy targeting legacy authentication clients (Exchange ActiveSync and others) with the "Block" grant. Frameworks : CIS Active Directory · NIST AC-2, AC-12 · ISO 27001 A.8.2, A.8.5 · CISA SCuBA MS.AAD.1.1 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j) |
| Entra | Enable number matching in Microsoft Authenticator | L1 | Compliant | Frameworks : CIS Active Directory · NIST IA-2 · ISO 27001 A.8.5 · CISA SCuBA MS.AAD.3.3 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j) |
| Exchange | Enable Safe Attachments | L1 | Compliant | Frameworks : CIS Active Directory · NIST SI-3 · ISO 27001 A.8.7 · DORA Art. 10 · NIS2 21.2(b) |
| Intune | Analyze configuration profile assignments | L2 | Non-compliant | Remediation : Configure this in the Microsoft Intune admin center. Frameworks : CIS Intune · NIST CM-6 · ISO 27001 A.8.9 · DORA Art. 9 · NIS2 21.2(i) |
| Teams | Control channel sharing with external users | L2 | Compliant | Frameworks : CIS Active Directory · NIST AC-3 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i) |
| Defender | Block accounts exceeding outbound sending limits | L1 | Compliant | Frameworks : CIS Active Directory 2.1.3 · NIST SI-4 · ISO 27001 A.8.16 · DORA Art. 10 · NIS2 21.2(b) |
| OneDrive | Notify OneDrive owners of external shares | L2 | Compliant | Frameworks : CIS Active Directory · NIST AC-21 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i) |
| Teams | Block personal-scope RSC consent for Teams apps | L2 | Compliant | Frameworks : CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · DORA Art. 9 · NIS2 21.2(i) |
| Entra | Remove disabled accounts from privileged roles | L1 | Non-compliant | Remediation : Remove role assignments from disabled accounts. Frameworks : NIST AC-2 · ISO 27001 A.5.18 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i) |
| Entra | Provide break-glass emergency access accounts | L1 | Compliant | Frameworks : CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i) |
| Entra | Eliminate permanent privileged assignments | L2 | Compliant | Frameworks : CIS Active Directory 1.1.4 · NIST AC-6(1) · ISO 27001 A.8.2 · CISA SCuBA MS.AAD.7.4 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i) |
| Exchange | Disallow mail flow rules that allowlist domains or IPs | L2 | Compliant | Frameworks : CIS Active Directory · NIST SI-8 · ISO 27001 A.8.12 · DORA Art. 9 · NIS2 21.2(i) |
| Exchange | Disable auto-forwarding via remote domains | L1 | Compliant | Frameworks : CIS Active Directory · NIST AC-4 · ISO 27001 A.8.12 · DORA Art. 9 · NIS2 21.2(i) |
| Entra | Require MFA for all users | L1 | Non-compliant | Remediation : Conditional Access: a policy targeting all users (with break-glass exclusions) requiring MFA, ideally via a phishing-resistant authentication strength. Frameworks : CIS Active Directory · NIST IA-2 · ISO 27001 A.8.5 · CISA SCuBA MS.AAD.3.2 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j) |
| Entra | Prohibit insecure redirect URIs (HTTP) | L2 | Compliant | Frameworks : CIS Active Directory · NIST CM-7, AC-6 · ISO 27001 A.8.19 · DORA Art. 9 · NIS2 21.2(i) |
| Entra | Require MFA for device join and registration | L1 | Non-compliant | Remediation : Conditional Access: create a policy on the "Register or join devices" user action requiring MFA. Frameworks : CIS Active Directory · NIST IA-2 · ISO 27001 A.8.5 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j) |
| Entra | Alert on Conditional Access policy changes | L2 | Compliant | Frameworks : CIS Active Directory · NIST AU-6 · ISO 27001 A.8.15 · ANSSI MFA · DORA Art. 10 · NIS2 21.2(b) |
| Exchange | Inventory mailboxes with forwarding configured | L2 | Compliant | Frameworks : CIS Active Directory · NIST AC-4 · ISO 27001 A.8.12 · DORA Art. 9 · NIS2 21.2(i) |
| Entra | Prohibit guests in privileged roles | L1 | Warning | Remediation : Remove guest accounts from privileged roles and create dedicated internal accounts. Frameworks : CIS Active Directory 1.1.3 · NIST AC-6 · ISO 27001 A.5.15 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i) |
| Exchange | Enable MailTips for users | L2 | Warning | Remediation : Set-OrganizationConfig -MailTipsAllTipsEnabled $true -MailTipsExternalRecipientsTipsEnabled $true. Frameworks : CIS Active Directory · NIST AT-2 · ISO 27001 A.6.3 · DORA Art. 9 · NIS2 21.2(i) |
| Purview | Enable auto-labelling of sensitive documents | L2 | Compliant | Frameworks : CIS Active Directory 3.5 · NIST MP-3 · ISO 27001 A.5.12 · DORA Art. 9 · NIS2 21.2(i) |
| Defender | Tolerate no active high-severity incident | L1 | Warning | Remediation : Defender portal > Incidents: mobilize response on any high-severity incident (containment, eradication, post-mortem). Frameworks : NIST IR-4 · ISO 27001 A.5.26 · DORA Art. 10 · NIS2 21.2(b) |
| Entra | Block the device code authentication flow | L1 | Non-compliant | Remediation : Entra portal > Conditional Access: create a policy targeting device code authentication flows with the Block grant. Frameworks : NIST AC-3 · ISO 27001 A.5.15 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j) |
| Intune | Require multi-admin approval for destructive actions | L2 | Compliant | Frameworks : CIS Intune · NIST AC-6 · ISO 27001 A.8.2 · DORA Art. 9 · NIS2 21.2(i) |
| Exchange | Control inbound and outbound mail connectors | L1 | Non-compliant | Remediation : Exchange admin center > Mail flow > Connectors: enforce TLS and restrict source domains or IP addresses. Frameworks : CIS Active Directory 6.x · NIST SC-8 · ISO 27001 A.8.20 · DORA Art. 9 · NIS2 21.2(i) |
| Teams | Block guest access to group content | L2 | Compliant | Frameworks : CIS Active Directory · NIST AC-21 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i) |
| Entra | Enable report suspicious activity | L1 | Compliant | Frameworks : CIS Entra · NIST IR-6 · ISO 27001 A.6.8 · DORA Art. 10 · NIS2 21.2(b) |
| Entra | Control federation relationships and ADFS configuration | L2 | Non-compliant | Remediation : Audit federated domains (authenticationType) and migrate to cloud authentication (PHS/PTA + seamless SSO) where possible. Frameworks : CIS Active Directory · NIST CM-6 · ISO 27001 A.8.9 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i) |
| Entra | Restrict Active Directory group creation | L2 | Compliant | Frameworks : CIS Active Directory · NIST CM-6 · ISO 27001 A.8.9 · DORA Art. 9 · NIS2 21.2(i) |
| Entra | Configure Entra diagnostic settings to Azure Monitor | L1 | Compliant | Frameworks : CIS Active Directory · NIST AU-2 · ISO 27001 A.8.15 · CISA SCuBA MS.AAD.4.1 · ANSSI Journalisation · DORA Art. 10 · NIS2 21.2(b) |
| SharePoint | Limit SharePoint access from unmanaged devices | L2 | Compliant | Frameworks : CIS Active Directory · NIST AC-3 · ISO 27001 A.8.5 · DORA Art. 9 · NIS2 21.2(h) |
| Purview | Publish retention labels | L2 | Compliant | Frameworks : CIS Active Directory · NIST SI-12 · ISO 27001 A.5.33 · DORA Art. 9 · NIS2 21.2(h) |
| Intune | Deploy app protection policies | L1 | Compliant | Frameworks : CIS Intune · NIST AC-19 · ISO 27001 A.8.1 · DORA Art. 9 · NIS2 21.2(i) |
| Exchange | Deploy an authentication policy blocking legacy authentication | L1 | Compliant | Frameworks : CIS Active Directory · NIST IA-2 · ISO 27001 A.8.5 · DORA Art. 9 · NIS2 21.2(j) |
| Entra | Use restricted management administrative units | L2 | Compliant | Frameworks : NIST AC-6 · ISO 27001 A.8.2 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i) |
| Exchange | Disable legacy protocols per mailbox | L1 | Compliant | Frameworks : CIS Active Directory 6.5.x · NIST IA-2 · ISO 27001 A.5.17 · DORA Art. 9 · NIS2 21.2(i) |
| Exchange | Tag messages coming from outside | L1 | Warning | Remediation : Exchange Online PowerShell: Set-ExternalInOutlook -Enabled $true. Frameworks : CIS Active Directory 6.2.3 · NIST SI-8 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i) |
| Entra | Eliminate weak auth methods on privileged accounts | L2 | Compliant | Frameworks : CIS Active Directory 1.1.6 · NIST IA-2(8) · ISO 27001 A.8.5 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(j) |
| Entra | Limit the number of global administrators to between two and four | L1 | Not assessed | Remediation : Entra portal > Roles and administrators > Global Administrator: remove superfluous accounts to keep only 2 to 4 holders, and replace permanent assignments with PIM eligibility. Frameworks : CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · CISA SCuBA MS.AAD.7.1 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i) |
| Entra | Audit high-permission service principals with active credentials | L2 | Compliant | Frameworks : CIS Entra · NIST IA-5 · ISO 27001 A.8.2 · ANSSI Journalisation · DORA Art. 10 · NIS2 21.2(b) |
| Entra | Use dedicated, cloud-only administrator accounts | L1 | Compliant | Frameworks : CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · CISA SCuBA MS.AAD.7.3 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i) |
| Intune | Enumerate non-compliant devices | L1 | Non-compliant | Remediation : Configure this in the Microsoft Intune admin center. Frameworks : CIS Intune · NIST CM-6 · ISO 27001 A.8.9 · DORA Art. 9 · NIS2 21.2(h) |
| Entra | Prevent non-administrator users from creating domains | L1 | Compliant | Frameworks : CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i) |
| SharePoint | Set a default storage limit for new sites | L2 | Compliant | Frameworks : Microsoft Secure Score · NIST PM-1 · ISO 27001 A.5.1 · DORA Art. 9 · NIS2 21.2(i) |
| Defender | Work down stale active incidents | L2 | Compliant | Frameworks : NIST IR-4 · ISO 27001 A.5.26 · DORA Art. 10 · NIS2 21.2(b) |
| SharePoint | Sign out idle sessions | L1 | Compliant | Frameworks : CIS Active Directory · NIST AC-12 · ISO 27001 A.8.5 · DORA Art. 9 · NIS2 21.2(i) |
| Teams | Define guest usage guidelines | L2 | Warning | Remediation : Group.Unified directory setting: set GuestUsageGuidelinesUrl to your guest usage guidelines page. Frameworks : CIS Active Directory · NIST AC-21 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i) |
| SharePoint | Restrict external sharing domains | L2 | Compliant | Frameworks : CIS Active Directory · NIST AC-21 · ISO 27001 A.5.14 · CISA SCuBA MS.SHAREPOINT.1.3 · DORA Art. 9 · NIS2 21.2(i) |
| Purview | Set a blocking action on DLP rules | L1 | Compliant | Frameworks : CIS Active Directory 3.2 · NIST AC-4 · ISO 27001 A.8.12 · CISA SCuBA MS.DEFENDER.4.2 · DORA Art. 9 · NIS2 21.2(h) |
| OneDrive | Set a default OneDrive storage limit | L2 | Compliant | Frameworks : CIS Active Directory · NIST PM-1 · ISO 27001 A.5.1 · DORA Art. 10 · NIS2 21.2(b) |
| Entra | Limit the maximum PIM role activation duration | L2 | Non-compliant | Remediation : Entra > PIM > Role settings > Activation: lower 'Activation maximum duration' to 8 hours or less. Frameworks : CIS Active Directory · NIST AC-6 · ISO 27001 A.5.15 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i) |
| Entra | Require MFA for external and guest users | L1 | Compliant | Frameworks : CIS Active Directory · NIST AC-2, AC-12 · ISO 27001 A.8.2, A.8.5 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j) |
| SharePoint | Hide the site creation UI | L2 | Non-compliant | Remediation : SharePoint admin center > Settings > Site creation: hide the 'Create site' command from users. Frameworks : Microsoft Secure Score · NIST PM-1 · ISO 27001 A.5.1 · DORA Art. 9 · NIS2 21.2(i) |
| Teams | Control anonymous user access to meetings | L2 | Compliant | Frameworks : CIS Active Directory · NIST AC-14 · ISO 27001 A.8.3 · DORA Art. 9 · NIS2 21.2(i) |
| Intune | Review deployed PowerShell scripts | L2 | Compliant | Frameworks : CIS Intune · NIST CM-7 · ISO 27001 A.8.19 · DORA Art. 9 · NIS2 21.2(i) |
| Entra | Prevent users from recovering BitLocker keys | L2 | Compliant | Frameworks : CIS Entra · NIST AC-6 · ISO 27001 A.8.2 · DORA Art. 9 · NIS2 21.2(h) |
| Exchange | Enable litigation hold on sensitive mailboxes | L2 | Warning | Remediation : Exchange admin center > Mailboxes > Features: enable litigation hold on sensitive accounts. Frameworks : NIST SI-12 · ISO 27001 A.5.33 · DORA Art. 9 · NIS2 21.2(i) |
| Defender | Strengthen Apps secure-score controls | L2 | Compliant | Frameworks : Microsoft Secure Score · NIST · ISO 27001 A.8.9 · DORA Art. 9 · NIS2 21.2(i) |