SAMPLE REPORT — domain information blurred, real AdGUARD output
AdGUARD
adguard.eu

Security audit report

Generated on 27/07/2026 14:32 — 64 controls.

Audited domain
Contoso Industries
contoso-industries.onmicrosoft.com
Active Directory, Exchange, Teams, SharePoint, OneDrive, Defender, Intune, Purview
Controls
64
Compliance
75 %
Compliant
45
Non-compliant
10
Warnings
7
ReferentialControlLevelStatusResult & remediation
EntraRequire compliant or hybrid-joined devicesL2Compliant
Frameworks : CIS Active Directory · NIST AC-2, AC-12 · ISO 27001 A.8.2, A.8.5 · CISA SCuBA MS.AAD.3.7 · DORA Art. 9 · NIS2 21.2(h)
DefenderEnable Safe Links for Office apps and TeamsL1Compliant
Frameworks : CIS Active Directory 2.1.1 · NIST SI-3 · ISO 27001 A.8.7 · DORA Art. 10 · NIS2 21.2(b)
OneDriveEnforce app-enforced restrictions on unmanaged devicesL2Compliant
Frameworks : CIS Active Directory · CISA SCuBA · NIST AC-3 · ISO 27001 A.8.5 · DORA Art. 9 · NIS2 21.2(h)
PurviewEnable the unified audit logL1Compliant
Frameworks : CIS Active Directory · NIST AU-2 · ISO 27001 A.8.15 · CISA SCuBA MS.DEFENDER.6.1 · ANSSI Journalisation · DORA Art. 10 · NIS2 21.2(b)
TeamsLimit public teamsL2Warning
Remediation : Review public teams and switch non-legitimate ones to 'Private' (team settings or Set-Team -Visibility Private).
Frameworks : CIS Active Directory · NIST AC-3 · ISO 27001 A.5.15 · DORA Art. 9 · NIS2 21.2(i)
EntraRequire an approved app or an app protection policyL2Compliant
Frameworks : CIS Active Directory · NIST AC-2, AC-12 · ISO 27001 A.8.2, A.8.5 · DORA Art. 9 · NIS2 21.2(i)
EntraBlock legacy authenticationL1Not assessed
Remediation : Conditional Access: create a policy targeting legacy authentication clients (Exchange ActiveSync and others) with the "Block" grant.
Frameworks : CIS Active Directory · NIST AC-2, AC-12 · ISO 27001 A.8.2, A.8.5 · CISA SCuBA MS.AAD.1.1 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j)
EntraEnable number matching in Microsoft AuthenticatorL1Compliant
Frameworks : CIS Active Directory · NIST IA-2 · ISO 27001 A.8.5 · CISA SCuBA MS.AAD.3.3 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j)
ExchangeEnable Safe AttachmentsL1Compliant
Frameworks : CIS Active Directory · NIST SI-3 · ISO 27001 A.8.7 · DORA Art. 10 · NIS2 21.2(b)
IntuneAnalyze configuration profile assignmentsL2Non-compliant
Remediation : Configure this in the Microsoft Intune admin center.
Frameworks : CIS Intune · NIST CM-6 · ISO 27001 A.8.9 · DORA Art. 9 · NIS2 21.2(i)
TeamsControl channel sharing with external usersL2Compliant
Frameworks : CIS Active Directory · NIST AC-3 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i)
DefenderBlock accounts exceeding outbound sending limitsL1Compliant
Frameworks : CIS Active Directory 2.1.3 · NIST SI-4 · ISO 27001 A.8.16 · DORA Art. 10 · NIS2 21.2(b)
OneDriveNotify OneDrive owners of external sharesL2Compliant
Frameworks : CIS Active Directory · NIST AC-21 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i)
TeamsBlock personal-scope RSC consent for Teams appsL2Compliant
Frameworks : CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · DORA Art. 9 · NIS2 21.2(i)
EntraRemove disabled accounts from privileged rolesL1Non-compliant
Remediation : Remove role assignments from disabled accounts.
Frameworks : NIST AC-2 · ISO 27001 A.5.18 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
EntraProvide break-glass emergency access accountsL1Compliant
Frameworks : CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
EntraEliminate permanent privileged assignmentsL2Compliant
Frameworks : CIS Active Directory 1.1.4 · NIST AC-6(1) · ISO 27001 A.8.2 · CISA SCuBA MS.AAD.7.4 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
ExchangeDisallow mail flow rules that allowlist domains or IPsL2Compliant
Frameworks : CIS Active Directory · NIST SI-8 · ISO 27001 A.8.12 · DORA Art. 9 · NIS2 21.2(i)
ExchangeDisable auto-forwarding via remote domainsL1Compliant
Frameworks : CIS Active Directory · NIST AC-4 · ISO 27001 A.8.12 · DORA Art. 9 · NIS2 21.2(i)
EntraRequire MFA for all usersL1Non-compliant
Remediation : Conditional Access: a policy targeting all users (with break-glass exclusions) requiring MFA, ideally via a phishing-resistant authentication strength.
Frameworks : CIS Active Directory · NIST IA-2 · ISO 27001 A.8.5 · CISA SCuBA MS.AAD.3.2 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j)
EntraProhibit insecure redirect URIs (HTTP)L2Compliant
Frameworks : CIS Active Directory · NIST CM-7, AC-6 · ISO 27001 A.8.19 · DORA Art. 9 · NIS2 21.2(i)
EntraRequire MFA for device join and registrationL1Non-compliant
Remediation : Conditional Access: create a policy on the "Register or join devices" user action requiring MFA.
Frameworks : CIS Active Directory · NIST IA-2 · ISO 27001 A.8.5 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j)
EntraAlert on Conditional Access policy changesL2Compliant
Frameworks : CIS Active Directory · NIST AU-6 · ISO 27001 A.8.15 · ANSSI MFA · DORA Art. 10 · NIS2 21.2(b)
ExchangeInventory mailboxes with forwarding configuredL2Compliant
Frameworks : CIS Active Directory · NIST AC-4 · ISO 27001 A.8.12 · DORA Art. 9 · NIS2 21.2(i)
EntraProhibit guests in privileged rolesL1Warning
Remediation : Remove guest accounts from privileged roles and create dedicated internal accounts.
Frameworks : CIS Active Directory 1.1.3 · NIST AC-6 · ISO 27001 A.5.15 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
ExchangeEnable MailTips for usersL2Warning
Remediation : Set-OrganizationConfig -MailTipsAllTipsEnabled $true -MailTipsExternalRecipientsTipsEnabled $true.
Frameworks : CIS Active Directory · NIST AT-2 · ISO 27001 A.6.3 · DORA Art. 9 · NIS2 21.2(i)
PurviewEnable auto-labelling of sensitive documentsL2Compliant
Frameworks : CIS Active Directory 3.5 · NIST MP-3 · ISO 27001 A.5.12 · DORA Art. 9 · NIS2 21.2(i)
DefenderTolerate no active high-severity incidentL1Warning
Remediation : Defender portal > Incidents: mobilize response on any high-severity incident (containment, eradication, post-mortem).
Frameworks : NIST IR-4 · ISO 27001 A.5.26 · DORA Art. 10 · NIS2 21.2(b)
EntraBlock the device code authentication flowL1Non-compliant
Remediation : Entra portal > Conditional Access: create a policy targeting device code authentication flows with the Block grant.
Frameworks : NIST AC-3 · ISO 27001 A.5.15 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j)
IntuneRequire multi-admin approval for destructive actionsL2Compliant
Frameworks : CIS Intune · NIST AC-6 · ISO 27001 A.8.2 · DORA Art. 9 · NIS2 21.2(i)
ExchangeControl inbound and outbound mail connectorsL1Non-compliant
Remediation : Exchange admin center > Mail flow > Connectors: enforce TLS and restrict source domains or IP addresses.
Frameworks : CIS Active Directory 6.x · NIST SC-8 · ISO 27001 A.8.20 · DORA Art. 9 · NIS2 21.2(i)
TeamsBlock guest access to group contentL2Compliant
Frameworks : CIS Active Directory · NIST AC-21 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i)
EntraEnable report suspicious activityL1Compliant
Frameworks : CIS Entra · NIST IR-6 · ISO 27001 A.6.8 · DORA Art. 10 · NIS2 21.2(b)
EntraControl federation relationships and ADFS configurationL2Non-compliant
Remediation : Audit federated domains (authenticationType) and migrate to cloud authentication (PHS/PTA + seamless SSO) where possible.
Frameworks : CIS Active Directory · NIST CM-6 · ISO 27001 A.8.9 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
EntraRestrict Active Directory group creationL2Compliant
Frameworks : CIS Active Directory · NIST CM-6 · ISO 27001 A.8.9 · DORA Art. 9 · NIS2 21.2(i)
EntraConfigure Entra diagnostic settings to Azure MonitorL1Compliant
Frameworks : CIS Active Directory · NIST AU-2 · ISO 27001 A.8.15 · CISA SCuBA MS.AAD.4.1 · ANSSI Journalisation · DORA Art. 10 · NIS2 21.2(b)
SharePointLimit SharePoint access from unmanaged devicesL2Compliant
Frameworks : CIS Active Directory · NIST AC-3 · ISO 27001 A.8.5 · DORA Art. 9 · NIS2 21.2(h)
PurviewPublish retention labelsL2Compliant
Frameworks : CIS Active Directory · NIST SI-12 · ISO 27001 A.5.33 · DORA Art. 9 · NIS2 21.2(h)
IntuneDeploy app protection policiesL1Compliant
Frameworks : CIS Intune · NIST AC-19 · ISO 27001 A.8.1 · DORA Art. 9 · NIS2 21.2(i)
ExchangeDeploy an authentication policy blocking legacy authenticationL1Compliant
Frameworks : CIS Active Directory · NIST IA-2 · ISO 27001 A.8.5 · DORA Art. 9 · NIS2 21.2(j)
EntraUse restricted management administrative unitsL2Compliant
Frameworks : NIST AC-6 · ISO 27001 A.8.2 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
ExchangeDisable legacy protocols per mailboxL1Compliant
Frameworks : CIS Active Directory 6.5.x · NIST IA-2 · ISO 27001 A.5.17 · DORA Art. 9 · NIS2 21.2(i)
ExchangeTag messages coming from outsideL1Warning
Remediation : Exchange Online PowerShell: Set-ExternalInOutlook -Enabled $true.
Frameworks : CIS Active Directory 6.2.3 · NIST SI-8 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i)
EntraEliminate weak auth methods on privileged accountsL2Compliant
Frameworks : CIS Active Directory 1.1.6 · NIST IA-2(8) · ISO 27001 A.8.5 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(j)
EntraLimit the number of global administrators to between two and fourL1Not assessed
Remediation : Entra portal > Roles and administrators > Global Administrator: remove superfluous accounts to keep only 2 to 4 holders, and replace permanent assignments with PIM eligibility.
Frameworks : CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · CISA SCuBA MS.AAD.7.1 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
EntraAudit high-permission service principals with active credentialsL2Compliant
Frameworks : CIS Entra · NIST IA-5 · ISO 27001 A.8.2 · ANSSI Journalisation · DORA Art. 10 · NIS2 21.2(b)
EntraUse dedicated, cloud-only administrator accountsL1Compliant
Frameworks : CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · CISA SCuBA MS.AAD.7.3 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
IntuneEnumerate non-compliant devicesL1Non-compliant
Remediation : Configure this in the Microsoft Intune admin center.
Frameworks : CIS Intune · NIST CM-6 · ISO 27001 A.8.9 · DORA Art. 9 · NIS2 21.2(h)
EntraPrevent non-administrator users from creating domainsL1Compliant
Frameworks : CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
SharePointSet a default storage limit for new sitesL2Compliant
Frameworks : Microsoft Secure Score · NIST PM-1 · ISO 27001 A.5.1 · DORA Art. 9 · NIS2 21.2(i)
DefenderWork down stale active incidentsL2Compliant
Frameworks : NIST IR-4 · ISO 27001 A.5.26 · DORA Art. 10 · NIS2 21.2(b)
SharePointSign out idle sessionsL1Compliant
Frameworks : CIS Active Directory · NIST AC-12 · ISO 27001 A.8.5 · DORA Art. 9 · NIS2 21.2(i)
TeamsDefine guest usage guidelinesL2Warning
Remediation : Group.Unified directory setting: set GuestUsageGuidelinesUrl to your guest usage guidelines page.
Frameworks : CIS Active Directory · NIST AC-21 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i)
SharePointRestrict external sharing domainsL2Compliant
Frameworks : CIS Active Directory · NIST AC-21 · ISO 27001 A.5.14 · CISA SCuBA MS.SHAREPOINT.1.3 · DORA Art. 9 · NIS2 21.2(i)
PurviewSet a blocking action on DLP rulesL1Compliant
Frameworks : CIS Active Directory 3.2 · NIST AC-4 · ISO 27001 A.8.12 · CISA SCuBA MS.DEFENDER.4.2 · DORA Art. 9 · NIS2 21.2(h)
OneDriveSet a default OneDrive storage limitL2Compliant
Frameworks : CIS Active Directory · NIST PM-1 · ISO 27001 A.5.1 · DORA Art. 10 · NIS2 21.2(b)
EntraLimit the maximum PIM role activation durationL2Non-compliant
Remediation : Entra > PIM > Role settings > Activation: lower 'Activation maximum duration' to 8 hours or less.
Frameworks : CIS Active Directory · NIST AC-6 · ISO 27001 A.5.15 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
EntraRequire MFA for external and guest usersL1Compliant
Frameworks : CIS Active Directory · NIST AC-2, AC-12 · ISO 27001 A.8.2, A.8.5 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j)
SharePointHide the site creation UIL2Non-compliant
Remediation : SharePoint admin center > Settings > Site creation: hide the 'Create site' command from users.
Frameworks : Microsoft Secure Score · NIST PM-1 · ISO 27001 A.5.1 · DORA Art. 9 · NIS2 21.2(i)
TeamsControl anonymous user access to meetingsL2Compliant
Frameworks : CIS Active Directory · NIST AC-14 · ISO 27001 A.8.3 · DORA Art. 9 · NIS2 21.2(i)
IntuneReview deployed PowerShell scriptsL2Compliant
Frameworks : CIS Intune · NIST CM-7 · ISO 27001 A.8.19 · DORA Art. 9 · NIS2 21.2(i)
EntraPrevent users from recovering BitLocker keysL2Compliant
Frameworks : CIS Entra · NIST AC-6 · ISO 27001 A.8.2 · DORA Art. 9 · NIS2 21.2(h)
ExchangeEnable litigation hold on sensitive mailboxesL2Warning
Remediation : Exchange admin center > Mailboxes > Features: enable litigation hold on sensitive accounts.
Frameworks : NIST SI-12 · ISO 27001 A.5.33 · DORA Art. 9 · NIS2 21.2(i)
DefenderStrengthen Apps secure-score controlsL2Compliant
Frameworks : Microsoft Secure Score · NIST · ISO 27001 A.8.9 · DORA Art. 9 · NIS2 21.2(i)