SAMPLE REPORT — domain information blurred, real AdGUARD output
AdGUARD
adguard.eu
Audited domain
Contoso Industries
contoso-industries.onmicrosoft.com
SECURITY AUDIT REPORT

Active Directory Security

Executive summary for management and CISO

Report date
27/07/2026
Scope
Active Directory, Exchange, Teams, SharePoint, OneDrive, Defender, Intune, Purview
Applied baseline
Baseline “CIS — level 1” — 64 controls run
WEIGHTED COMPLIANCE SCORE
75%
45 compliant
7 warnings
10 non-compliant
2 not assessed
Report generated by AdGUARD — adguard.eu — read-only audit.

Executive summary

Compliance
75%
Compliant
45
Warnings
7
Non-comp.
10
Not assessed
2
Controls
64
Methodology : weighted score by criticality — foundational (L1) controls weigh 3× more than hardening (L2). A warning counts for half its points. Read-only audit.

Compliance by referential

Breakdown of compliant, warning and non-compliant controls

Entra65%
17 compliant1 warnings6 non-compliant
Exchange60%
6 compliant3 warnings1 non-compliant
Teams67%
4 compliant2 warnings0 non-compliant
Defender80%
4 compliant1 warnings0 non-compliant
Intune60%
3 compliant0 warnings2 non-compliant
SharePoint80%
4 compliant0 warnings1 non-compliant
Purview100%
4 compliant0 warnings0 non-compliant
OneDrive100%
3 compliant0 warnings0 non-compliant

Action priorities

The 8 most critical non-compliances to address first

1
ENTRA · L1
Remove disabled accounts from privileged roles
Remediation : Remove role assignments from disabled accounts.
2
ENTRA · L1
Require MFA for all users
Remediation : Conditional Access: a policy targeting all users (with break-glass exclusions) requiring MFA, ideally via a phishing-resistant authentication strength.
3
ENTRA · L1
Require MFA for device join and registration
Remediation : Conditional Access: create a policy on the "Register or join devices" user action requiring MFA.
4
ENTRA · L1
Block the device code authentication flow
Remediation : Entra portal > Conditional Access: create a policy targeting device code authentication flows with the Block grant.
5
EXCHANGE · L1
Control inbound and outbound mail connectors
Remediation : Exchange admin center > Mail flow > Connectors: enforce TLS and restrict source domains or IP addresses.
6
INTUNE · L1
Enumerate non-compliant devices
Remediation : Configure this in the Microsoft Intune admin center.
7
INTUNE · L2
Analyze configuration profile assignments
Remediation : Configure this in the Microsoft Intune admin center.
8
ENTRA · L2
Control federation relationships and ADFS configuration
Remediation : Audit federated domains (authenticationType) and migrate to cloud authentication (PHS/PTA + seamless SSO) where possible.

Controls detail

ReferentialControlLvlStatus
Defender
Enable Safe Links for Office apps and Teams
CIS Active Directory 2.1.1 · NIST SI-3 · ISO 27001 A.8.7 · DORA Art. 10 · NIS2 21.2(b)
L1Compliant
Defender
Block accounts exceeding outbound sending limits
CIS Active Directory 2.1.3 · NIST SI-4 · ISO 27001 A.8.16 · DORA Art. 10 · NIS2 21.2(b)
L1Compliant
Defender
Tolerate no active high-severity incident
→ Defender portal > Incidents: mobilize response on any high-severity incident (containment, eradication, post-mortem).
NIST IR-4 · ISO 27001 A.5.26 · DORA Art. 10 · NIS2 21.2(b)
L1
Defender
Work down stale active incidents
NIST IR-4 · ISO 27001 A.5.26 · DORA Art. 10 · NIS2 21.2(b)
L2Compliant
Defender
Strengthen Apps secure-score controls
Microsoft Secure Score · NIST · ISO 27001 A.8.9 · DORA Art. 9 · NIS2 21.2(i)
L2Compliant
Entra
Remove disabled accounts from privileged roles
→ Remove role assignments from disabled accounts.
NIST AC-2 · ISO 27001 A.5.18 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
L1Non-compliant
Entra
Require MFA for all users
→ Conditional Access: a policy targeting all users (with break-glass exclusions) requiring MFA, ideally via a phishing-resistant authentication strength.
CIS Active Directory · NIST IA-2 · ISO 27001 A.8.5 · CISA SCuBA MS.AAD.3.2 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j)
L1Non-compliant
Entra
Require MFA for device join and registration
→ Conditional Access: create a policy on the "Register or join devices" user action requiring MFA.
CIS Active Directory · NIST IA-2 · ISO 27001 A.8.5 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j)
L1Non-compliant
Entra
Block the device code authentication flow
→ Entra portal > Conditional Access: create a policy targeting device code authentication flows with the Block grant.
NIST AC-3 · ISO 27001 A.5.15 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j)
L1Non-compliant
Entra
Control federation relationships and ADFS configuration
→ Audit federated domains (authenticationType) and migrate to cloud authentication (PHS/PTA + seamless SSO) where possible.
CIS Active Directory · NIST CM-6 · ISO 27001 A.8.9 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
L2Non-compliant
Entra
Limit the maximum PIM role activation duration
→ Entra > PIM > Role settings > Activation: lower 'Activation maximum duration' to 8 hours or less.
CIS Active Directory · NIST AC-6 · ISO 27001 A.5.15 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
L2Non-compliant
Entra
Require compliant or hybrid-joined devices
CIS Active Directory · NIST AC-2, AC-12 · ISO 27001 A.8.2, A.8.5 · CISA SCuBA MS.AAD.3.7 · DORA Art. 9 · NIS2 21.2(h)
L2Compliant
Entra
Require an approved app or an app protection policy
CIS Active Directory · NIST AC-2, AC-12 · ISO 27001 A.8.2, A.8.5 · DORA Art. 9 · NIS2 21.2(i)
L2Compliant
Entra
Block legacy authentication
→ Conditional Access: create a policy targeting legacy authentication clients (Exchange ActiveSync and others) with the "Block" grant.
CIS Active Directory · NIST AC-2, AC-12 · ISO 27001 A.8.2, A.8.5 · CISA SCuBA MS.AAD.1.1 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j)
L1Not assessed
Entra
Enable number matching in Microsoft Authenticator
CIS Active Directory · NIST IA-2 · ISO 27001 A.8.5 · CISA SCuBA MS.AAD.3.3 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j)
L1Compliant
Entra
Provide break-glass emergency access accounts
CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
L1Compliant
Entra
Eliminate permanent privileged assignments
CIS Active Directory 1.1.4 · NIST AC-6(1) · ISO 27001 A.8.2 · CISA SCuBA MS.AAD.7.4 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
L2Compliant
Entra
Prohibit insecure redirect URIs (HTTP)
CIS Active Directory · NIST CM-7, AC-6 · ISO 27001 A.8.19 · DORA Art. 9 · NIS2 21.2(i)
L2Compliant
Entra
Alert on Conditional Access policy changes
CIS Active Directory · NIST AU-6 · ISO 27001 A.8.15 · ANSSI MFA · DORA Art. 10 · NIS2 21.2(b)
L2Compliant
Entra
Prohibit guests in privileged roles
→ Remove guest accounts from privileged roles and create dedicated internal accounts.
CIS Active Directory 1.1.3 · NIST AC-6 · ISO 27001 A.5.15 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
L1
Entra
Enable report suspicious activity
CIS Entra · NIST IR-6 · ISO 27001 A.6.8 · DORA Art. 10 · NIS2 21.2(b)
L1Compliant
Entra
Restrict Active Directory group creation
CIS Active Directory · NIST CM-6 · ISO 27001 A.8.9 · DORA Art. 9 · NIS2 21.2(i)
L2Compliant
Entra
Configure Entra diagnostic settings to Azure Monitor
CIS Active Directory · NIST AU-2 · ISO 27001 A.8.15 · CISA SCuBA MS.AAD.4.1 · ANSSI Journalisation · DORA Art. 10 · NIS2 21.2(b)
L1Compliant
Entra
Use restricted management administrative units
NIST AC-6 · ISO 27001 A.8.2 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
L2Compliant
Entra
Eliminate weak auth methods on privileged accounts
CIS Active Directory 1.1.6 · NIST IA-2(8) · ISO 27001 A.8.5 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(j)
L2Compliant
Entra
Limit the number of global administrators to between two and four
→ Entra portal > Roles and administrators > Global Administrator: remove superfluous accounts to keep only 2 to 4 holders, and replace permanent assignments with PIM eligibility.
CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · CISA SCuBA MS.AAD.7.1 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
L1Not assessed
Entra
Audit high-permission service principals with active credentials
CIS Entra · NIST IA-5 · ISO 27001 A.8.2 · ANSSI Journalisation · DORA Art. 10 · NIS2 21.2(b)
L2Compliant
Entra
Use dedicated, cloud-only administrator accounts
CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · CISA SCuBA MS.AAD.7.3 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
L1Compliant
Entra
Prevent non-administrator users from creating domains
CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
L1Compliant
Entra
Require MFA for external and guest users
CIS Active Directory · NIST AC-2, AC-12 · ISO 27001 A.8.2, A.8.5 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j)
L1Compliant
Entra
Prevent users from recovering BitLocker keys
CIS Entra · NIST AC-6 · ISO 27001 A.8.2 · DORA Art. 9 · NIS2 21.2(h)
L2Compliant
Exchange
Control inbound and outbound mail connectors
→ Exchange admin center > Mail flow > Connectors: enforce TLS and restrict source domains or IP addresses.
CIS Active Directory 6.x · NIST SC-8 · ISO 27001 A.8.20 · DORA Art. 9 · NIS2 21.2(i)
L1Non-compliant
Exchange
Enable Safe Attachments
CIS Active Directory · NIST SI-3 · ISO 27001 A.8.7 · DORA Art. 10 · NIS2 21.2(b)
L1Compliant
Exchange
Disallow mail flow rules that allowlist domains or IPs
CIS Active Directory · NIST SI-8 · ISO 27001 A.8.12 · DORA Art. 9 · NIS2 21.2(i)
L2Compliant
Exchange
Disable auto-forwarding via remote domains
CIS Active Directory · NIST AC-4 · ISO 27001 A.8.12 · DORA Art. 9 · NIS2 21.2(i)
L1Compliant
Exchange
Inventory mailboxes with forwarding configured
CIS Active Directory · NIST AC-4 · ISO 27001 A.8.12 · DORA Art. 9 · NIS2 21.2(i)
L2Compliant
Exchange
Enable MailTips for users
→ Set-OrganizationConfig -MailTipsAllTipsEnabled $true -MailTipsExternalRecipientsTipsEnabled $true.
CIS Active Directory · NIST AT-2 · ISO 27001 A.6.3 · DORA Art. 9 · NIS2 21.2(i)
L2
Exchange
Deploy an authentication policy blocking legacy authentication
CIS Active Directory · NIST IA-2 · ISO 27001 A.8.5 · DORA Art. 9 · NIS2 21.2(j)
L1Compliant
Exchange
Disable legacy protocols per mailbox
CIS Active Directory 6.5.x · NIST IA-2 · ISO 27001 A.5.17 · DORA Art. 9 · NIS2 21.2(i)
L1Compliant
Exchange
Tag messages coming from outside
→ Exchange Online PowerShell: Set-ExternalInOutlook -Enabled $true.
CIS Active Directory 6.2.3 · NIST SI-8 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i)
L1
Exchange
Enable litigation hold on sensitive mailboxes
→ Exchange admin center > Mailboxes > Features: enable litigation hold on sensitive accounts.
NIST SI-12 · ISO 27001 A.5.33 · DORA Art. 9 · NIS2 21.2(i)
L2
Intune
Analyze configuration profile assignments
→ Configure this in the Microsoft Intune admin center.
CIS Intune · NIST CM-6 · ISO 27001 A.8.9 · DORA Art. 9 · NIS2 21.2(i)
L2Non-compliant
Intune
Enumerate non-compliant devices
→ Configure this in the Microsoft Intune admin center.
CIS Intune · NIST CM-6 · ISO 27001 A.8.9 · DORA Art. 9 · NIS2 21.2(h)
L1Non-compliant
Intune
Require multi-admin approval for destructive actions
CIS Intune · NIST AC-6 · ISO 27001 A.8.2 · DORA Art. 9 · NIS2 21.2(i)
L2Compliant
Intune
Deploy app protection policies
CIS Intune · NIST AC-19 · ISO 27001 A.8.1 · DORA Art. 9 · NIS2 21.2(i)
L1Compliant
Intune
Review deployed PowerShell scripts
CIS Intune · NIST CM-7 · ISO 27001 A.8.19 · DORA Art. 9 · NIS2 21.2(i)
L2Compliant
OneDrive
Enforce app-enforced restrictions on unmanaged devices
CIS Active Directory · CISA SCuBA · NIST AC-3 · ISO 27001 A.8.5 · DORA Art. 9 · NIS2 21.2(h)
L2Compliant
OneDrive
Notify OneDrive owners of external shares
CIS Active Directory · NIST AC-21 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i)
L2Compliant
OneDrive
Set a default OneDrive storage limit
CIS Active Directory · NIST PM-1 · ISO 27001 A.5.1 · DORA Art. 10 · NIS2 21.2(b)
L2Compliant
Purview
Enable the unified audit log
CIS Active Directory · NIST AU-2 · ISO 27001 A.8.15 · CISA SCuBA MS.DEFENDER.6.1 · ANSSI Journalisation · DORA Art. 10 · NIS2 21.2(b)
L1Compliant
Purview
Enable auto-labelling of sensitive documents
CIS Active Directory 3.5 · NIST MP-3 · ISO 27001 A.5.12 · DORA Art. 9 · NIS2 21.2(i)
L2Compliant
Purview
Publish retention labels
CIS Active Directory · NIST SI-12 · ISO 27001 A.5.33 · DORA Art. 9 · NIS2 21.2(h)
L2Compliant
Purview
Set a blocking action on DLP rules
CIS Active Directory 3.2 · NIST AC-4 · ISO 27001 A.8.12 · CISA SCuBA MS.DEFENDER.4.2 · DORA Art. 9 · NIS2 21.2(h)
L1Compliant
SharePoint
Hide the site creation UI
→ SharePoint admin center > Settings > Site creation: hide the 'Create site' command from users.
Microsoft Secure Score · NIST PM-1 · ISO 27001 A.5.1 · DORA Art. 9 · NIS2 21.2(i)
L2Non-compliant
SharePoint
Limit SharePoint access from unmanaged devices
CIS Active Directory · NIST AC-3 · ISO 27001 A.8.5 · DORA Art. 9 · NIS2 21.2(h)
L2Compliant
SharePoint
Set a default storage limit for new sites
Microsoft Secure Score · NIST PM-1 · ISO 27001 A.5.1 · DORA Art. 9 · NIS2 21.2(i)
L2Compliant
SharePoint
Sign out idle sessions
CIS Active Directory · NIST AC-12 · ISO 27001 A.8.5 · DORA Art. 9 · NIS2 21.2(i)
L1Compliant
SharePoint
Restrict external sharing domains
CIS Active Directory · NIST AC-21 · ISO 27001 A.5.14 · CISA SCuBA MS.SHAREPOINT.1.3 · DORA Art. 9 · NIS2 21.2(i)
L2Compliant
Teams
Limit public teams
→ Review public teams and switch non-legitimate ones to 'Private' (team settings or Set-Team -Visibility Private).
CIS Active Directory · NIST AC-3 · ISO 27001 A.5.15 · DORA Art. 9 · NIS2 21.2(i)
L2
Teams
Control channel sharing with external users
CIS Active Directory · NIST AC-3 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i)
L2Compliant
Teams
Block personal-scope RSC consent for Teams apps
CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · DORA Art. 9 · NIS2 21.2(i)
L2Compliant
Teams
Block guest access to group content
CIS Active Directory · NIST AC-21 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i)
L2Compliant
Teams
Define guest usage guidelines
→ Group.Unified directory setting: set GuestUsageGuidelinesUrl to your guest usage guidelines page.
CIS Active Directory · NIST AC-21 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i)
L2
Teams
Control anonymous user access to meetings
CIS Active Directory · NIST AC-14 · ISO 27001 A.8.3 · DORA Art. 9 · NIS2 21.2(i)
L2Compliant