Generated on 27/07/2026 14:32 — 64 controls.
Controls are grouped by source referential (the originating benchmark). Each control appears in a single section.
| Entra | Require compliant or hybrid-joined devices CIS Active Directory · NIST AC-2, AC-12 · ISO 27001 A.8.2, A.8.5 · CISA SCuBA MS.AAD.3.7 · DORA Art. 9 · NIS2 21.2(h) | Compliant |
| Entra | Require an approved app or an app protection policy CIS Active Directory · NIST AC-2, AC-12 · ISO 27001 A.8.2, A.8.5 · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| Entra | Block legacy authentication CIS Active Directory · NIST AC-2, AC-12 · ISO 27001 A.8.2, A.8.5 · CISA SCuBA MS.AAD.1.1 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j) | Not assessed |
| Entra | Enable number matching in Microsoft Authenticator CIS Active Directory · NIST IA-2 · ISO 27001 A.8.5 · CISA SCuBA MS.AAD.3.3 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j) | Compliant |
| Entra | Provide break-glass emergency access accounts CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| Entra | Eliminate permanent privileged assignments CIS Active Directory 1.1.4 · NIST AC-6(1) · ISO 27001 A.8.2 · CISA SCuBA MS.AAD.7.4 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| Entra | Require MFA for all users CIS Active Directory · NIST IA-2 · ISO 27001 A.8.5 · CISA SCuBA MS.AAD.3.2 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j) | Non-compliant |
| Entra | Prohibit insecure redirect URIs (HTTP) CIS Active Directory · NIST CM-7, AC-6 · ISO 27001 A.8.19 · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| Entra | Require MFA for device join and registration CIS Active Directory · NIST IA-2 · ISO 27001 A.8.5 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j) | Non-compliant |
| Entra | Alert on Conditional Access policy changes CIS Active Directory · NIST AU-6 · ISO 27001 A.8.15 · ANSSI MFA · DORA Art. 10 · NIS2 21.2(b) | Compliant |
| Entra | Prohibit guests in privileged roles CIS Active Directory 1.1.3 · NIST AC-6 · ISO 27001 A.5.15 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i) | Warning |
| Entra | Enable report suspicious activity CIS Entra · NIST IR-6 · ISO 27001 A.6.8 · DORA Art. 10 · NIS2 21.2(b) | Compliant |
| Entra | Control federation relationships and ADFS configuration CIS Active Directory · NIST CM-6 · ISO 27001 A.8.9 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i) | Non-compliant |
| Entra | Restrict Active Directory group creation CIS Active Directory · NIST CM-6 · ISO 27001 A.8.9 · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| Entra | Configure Entra diagnostic settings to Azure Monitor CIS Active Directory · NIST AU-2 · ISO 27001 A.8.15 · CISA SCuBA MS.AAD.4.1 · ANSSI Journalisation · DORA Art. 10 · NIS2 21.2(b) | Compliant |
| Entra | Eliminate weak auth methods on privileged accounts CIS Active Directory 1.1.6 · NIST IA-2(8) · ISO 27001 A.8.5 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(j) | Compliant |
| Entra | Limit the number of global administrators to between two and four CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · CISA SCuBA MS.AAD.7.1 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i) | Not assessed |
| Entra | Audit high-permission service principals with active credentials CIS Entra · NIST IA-5 · ISO 27001 A.8.2 · ANSSI Journalisation · DORA Art. 10 · NIS2 21.2(b) | Compliant |
| Entra | Use dedicated, cloud-only administrator accounts CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · CISA SCuBA MS.AAD.7.3 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| Entra | Prevent non-administrator users from creating domains CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| Entra | Limit the maximum PIM role activation duration CIS Active Directory · NIST AC-6 · ISO 27001 A.5.15 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i) | Non-compliant |
| Entra | Require MFA for external and guest users CIS Active Directory · NIST AC-2, AC-12 · ISO 27001 A.8.2, A.8.5 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j) | Compliant |
| Entra | Prevent users from recovering BitLocker keys CIS Entra · NIST AC-6 · ISO 27001 A.8.2 · DORA Art. 9 · NIS2 21.2(h) | Compliant |
| OneDrive | Enforce app-enforced restrictions on unmanaged devices CIS Active Directory · CISA SCuBA · NIST AC-3 · ISO 27001 A.8.5 · DORA Art. 9 · NIS2 21.2(h) | Compliant |
| Purview | Enable the unified audit log CIS Active Directory · NIST AU-2 · ISO 27001 A.8.15 · CISA SCuBA MS.DEFENDER.6.1 · ANSSI Journalisation · DORA Art. 10 · NIS2 21.2(b) | Compliant |
| Teams | Limit public teams CIS Active Directory · NIST AC-3 · ISO 27001 A.5.15 · DORA Art. 9 · NIS2 21.2(i) | Warning |
| Exchange | Enable Safe Attachments CIS Active Directory · NIST SI-3 · ISO 27001 A.8.7 · DORA Art. 10 · NIS2 21.2(b) | Compliant |
| Teams | Control channel sharing with external users CIS Active Directory · NIST AC-3 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| OneDrive | Notify OneDrive owners of external shares CIS Active Directory · NIST AC-21 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| Teams | Block personal-scope RSC consent for Teams apps CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| Exchange | Disallow mail flow rules that allowlist domains or IPs CIS Active Directory · NIST SI-8 · ISO 27001 A.8.12 · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| Exchange | Disable auto-forwarding via remote domains CIS Active Directory · NIST AC-4 · ISO 27001 A.8.12 · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| Exchange | Inventory mailboxes with forwarding configured CIS Active Directory · NIST AC-4 · ISO 27001 A.8.12 · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| Exchange | Enable MailTips for users CIS Active Directory · NIST AT-2 · ISO 27001 A.6.3 · DORA Art. 9 · NIS2 21.2(i) | Warning |
| Teams | Block guest access to group content CIS Active Directory · NIST AC-21 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| SharePoint | Limit SharePoint access from unmanaged devices CIS Active Directory · NIST AC-3 · ISO 27001 A.8.5 · DORA Art. 9 · NIS2 21.2(h) | Compliant |
| Purview | Publish retention labels CIS Active Directory · NIST SI-12 · ISO 27001 A.5.33 · DORA Art. 9 · NIS2 21.2(h) | Compliant |
| Exchange | Deploy an authentication policy blocking legacy authentication CIS Active Directory · NIST IA-2 · ISO 27001 A.8.5 · DORA Art. 9 · NIS2 21.2(j) | Compliant |
| SharePoint | Sign out idle sessions CIS Active Directory · NIST AC-12 · ISO 27001 A.8.5 · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| Teams | Define guest usage guidelines CIS Active Directory · NIST AC-21 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i) | Warning |
| SharePoint | Restrict external sharing domains CIS Active Directory · NIST AC-21 · ISO 27001 A.5.14 · CISA SCuBA MS.SHAREPOINT.1.3 · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| OneDrive | Set a default OneDrive storage limit CIS Active Directory · NIST PM-1 · ISO 27001 A.5.1 · DORA Art. 10 · NIS2 21.2(b) | Compliant |
| Teams | Control anonymous user access to meetings CIS Active Directory · NIST AC-14 · ISO 27001 A.8.3 · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| Intune | Analyze configuration profile assignments CIS Intune · NIST CM-6 · ISO 27001 A.8.9 · DORA Art. 9 · NIS2 21.2(i) | Non-compliant |
| Intune | Require multi-admin approval for destructive actions CIS Intune · NIST AC-6 · ISO 27001 A.8.2 · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| Intune | Deploy app protection policies CIS Intune · NIST AC-19 · ISO 27001 A.8.1 · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| Intune | Enumerate non-compliant devices CIS Intune · NIST CM-6 · ISO 27001 A.8.9 · DORA Art. 9 · NIS2 21.2(h) | Non-compliant |
| Intune | Review deployed PowerShell scripts CIS Intune · NIST CM-7 · ISO 27001 A.8.19 · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| SharePoint | Set a default storage limit for new sites Microsoft Secure Score · NIST PM-1 · ISO 27001 A.5.1 · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| SharePoint | Hide the site creation UI Microsoft Secure Score · NIST PM-1 · ISO 27001 A.5.1 · DORA Art. 9 · NIS2 21.2(i) | Non-compliant |
| Defender | Strengthen Apps secure-score controls Microsoft Secure Score · NIST · ISO 27001 A.8.9 · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| Defender | Tolerate no active high-severity incident NIST IR-4 · ISO 27001 A.5.26 · DORA Art. 10 · NIS2 21.2(b) | Warning |
| Defender | Work down stale active incidents NIST IR-4 · ISO 27001 A.5.26 · DORA Art. 10 · NIS2 21.2(b) | Compliant |
| Defender | Enable Safe Links for Office apps and Teams CIS Active Directory 2.1.1 · NIST SI-3 · ISO 27001 A.8.7 · DORA Art. 10 · NIS2 21.2(b) | Compliant |
| Defender | Block accounts exceeding outbound sending limits CIS Active Directory 2.1.3 · NIST SI-4 · ISO 27001 A.8.16 · DORA Art. 10 · NIS2 21.2(b) | Compliant |
| Purview | Set a blocking action on DLP rules CIS Active Directory 3.2 · NIST AC-4 · ISO 27001 A.8.12 · CISA SCuBA MS.DEFENDER.4.2 · DORA Art. 9 · NIS2 21.2(h) | Compliant |
| Purview | Enable auto-labelling of sensitive documents CIS Active Directory 3.5 · NIST MP-3 · ISO 27001 A.5.12 · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| Exchange | Tag messages coming from outside CIS Active Directory 6.2.3 · NIST SI-8 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i) | Warning |
| Exchange | Disable legacy protocols per mailbox CIS Active Directory 6.5.x · NIST IA-2 · ISO 27001 A.5.17 · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| Exchange | Control inbound and outbound mail connectors CIS Active Directory 6.x · NIST SC-8 · ISO 27001 A.8.20 · DORA Art. 9 · NIS2 21.2(i) | Non-compliant |
| Entra | Remove disabled accounts from privileged roles NIST AC-2 · ISO 27001 A.5.18 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i) | Non-compliant |
| Entra | Block the device code authentication flow NIST AC-3 · ISO 27001 A.5.15 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j) | Non-compliant |
| Entra | Use restricted management administrative units NIST AC-6 · ISO 27001 A.8.2 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i) | Compliant |
| Exchange | Enable litigation hold on sensitive mailboxes NIST SI-12 · ISO 27001 A.5.33 · DORA Art. 9 · NIS2 21.2(i) | Warning |