SAMPLE REPORT — domain information blurred, real AdGUARD output
AdGUARD
adguard.eu

Compliance by framework

Generated on 27/07/2026 14:32 — 64 controls.

Audited domain
Contoso Industries
contoso-industries.onmicrosoft.com
Active Directory, Exchange, Teams, SharePoint, OneDrive, Defender, Intune, Purview
Controls
64
Compliance
75 %

Controls are grouped by source referential (the originating benchmark). Each control appears in a single section.

CIS Active Directory
23 controls
70%
EntraRequire compliant or hybrid-joined devices
CIS Active Directory · NIST AC-2, AC-12 · ISO 27001 A.8.2, A.8.5 · CISA SCuBA MS.AAD.3.7 · DORA Art. 9 · NIS2 21.2(h)
Compliant
EntraRequire an approved app or an app protection policy
CIS Active Directory · NIST AC-2, AC-12 · ISO 27001 A.8.2, A.8.5 · DORA Art. 9 · NIS2 21.2(i)
Compliant
EntraBlock legacy authentication
CIS Active Directory · NIST AC-2, AC-12 · ISO 27001 A.8.2, A.8.5 · CISA SCuBA MS.AAD.1.1 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j)
Not assessed
EntraEnable number matching in Microsoft Authenticator
CIS Active Directory · NIST IA-2 · ISO 27001 A.8.5 · CISA SCuBA MS.AAD.3.3 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j)
Compliant
EntraProvide break-glass emergency access accounts
CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
Compliant
EntraEliminate permanent privileged assignments
CIS Active Directory 1.1.4 · NIST AC-6(1) · ISO 27001 A.8.2 · CISA SCuBA MS.AAD.7.4 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
Compliant
EntraRequire MFA for all users
CIS Active Directory · NIST IA-2 · ISO 27001 A.8.5 · CISA SCuBA MS.AAD.3.2 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j)
Non-compliant
EntraProhibit insecure redirect URIs (HTTP)
CIS Active Directory · NIST CM-7, AC-6 · ISO 27001 A.8.19 · DORA Art. 9 · NIS2 21.2(i)
Compliant
EntraRequire MFA for device join and registration
CIS Active Directory · NIST IA-2 · ISO 27001 A.8.5 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j)
Non-compliant
EntraAlert on Conditional Access policy changes
CIS Active Directory · NIST AU-6 · ISO 27001 A.8.15 · ANSSI MFA · DORA Art. 10 · NIS2 21.2(b)
Compliant
EntraProhibit guests in privileged roles
CIS Active Directory 1.1.3 · NIST AC-6 · ISO 27001 A.5.15 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
Warning
EntraEnable report suspicious activity
CIS Entra · NIST IR-6 · ISO 27001 A.6.8 · DORA Art. 10 · NIS2 21.2(b)
Compliant
EntraControl federation relationships and ADFS configuration
CIS Active Directory · NIST CM-6 · ISO 27001 A.8.9 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
Non-compliant
EntraRestrict Active Directory group creation
CIS Active Directory · NIST CM-6 · ISO 27001 A.8.9 · DORA Art. 9 · NIS2 21.2(i)
Compliant
EntraConfigure Entra diagnostic settings to Azure Monitor
CIS Active Directory · NIST AU-2 · ISO 27001 A.8.15 · CISA SCuBA MS.AAD.4.1 · ANSSI Journalisation · DORA Art. 10 · NIS2 21.2(b)
Compliant
EntraEliminate weak auth methods on privileged accounts
CIS Active Directory 1.1.6 · NIST IA-2(8) · ISO 27001 A.8.5 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(j)
Compliant
EntraLimit the number of global administrators to between two and four
CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · CISA SCuBA MS.AAD.7.1 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
Not assessed
EntraAudit high-permission service principals with active credentials
CIS Entra · NIST IA-5 · ISO 27001 A.8.2 · ANSSI Journalisation · DORA Art. 10 · NIS2 21.2(b)
Compliant
EntraUse dedicated, cloud-only administrator accounts
CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · CISA SCuBA MS.AAD.7.3 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
Compliant
EntraPrevent non-administrator users from creating domains
CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
Compliant
EntraLimit the maximum PIM role activation duration
CIS Active Directory · NIST AC-6 · ISO 27001 A.5.15 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
Non-compliant
EntraRequire MFA for external and guest users
CIS Active Directory · NIST AC-2, AC-12 · ISO 27001 A.8.2, A.8.5 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j)
Compliant
EntraPrevent users from recovering BitLocker keys
CIS Entra · NIST AC-6 · ISO 27001 A.8.2 · DORA Art. 9 · NIS2 21.2(h)
Compliant
CIS Active Directory
20 controls
85%
OneDriveEnforce app-enforced restrictions on unmanaged devices
CIS Active Directory · CISA SCuBA · NIST AC-3 · ISO 27001 A.8.5 · DORA Art. 9 · NIS2 21.2(h)
Compliant
PurviewEnable the unified audit log
CIS Active Directory · NIST AU-2 · ISO 27001 A.8.15 · CISA SCuBA MS.DEFENDER.6.1 · ANSSI Journalisation · DORA Art. 10 · NIS2 21.2(b)
Compliant
TeamsLimit public teams
CIS Active Directory · NIST AC-3 · ISO 27001 A.5.15 · DORA Art. 9 · NIS2 21.2(i)
Warning
ExchangeEnable Safe Attachments
CIS Active Directory · NIST SI-3 · ISO 27001 A.8.7 · DORA Art. 10 · NIS2 21.2(b)
Compliant
TeamsControl channel sharing with external users
CIS Active Directory · NIST AC-3 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i)
Compliant
OneDriveNotify OneDrive owners of external shares
CIS Active Directory · NIST AC-21 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i)
Compliant
TeamsBlock personal-scope RSC consent for Teams apps
CIS Active Directory · NIST AC-6 · ISO 27001 A.8.2 · DORA Art. 9 · NIS2 21.2(i)
Compliant
ExchangeDisallow mail flow rules that allowlist domains or IPs
CIS Active Directory · NIST SI-8 · ISO 27001 A.8.12 · DORA Art. 9 · NIS2 21.2(i)
Compliant
ExchangeDisable auto-forwarding via remote domains
CIS Active Directory · NIST AC-4 · ISO 27001 A.8.12 · DORA Art. 9 · NIS2 21.2(i)
Compliant
ExchangeInventory mailboxes with forwarding configured
CIS Active Directory · NIST AC-4 · ISO 27001 A.8.12 · DORA Art. 9 · NIS2 21.2(i)
Compliant
ExchangeEnable MailTips for users
CIS Active Directory · NIST AT-2 · ISO 27001 A.6.3 · DORA Art. 9 · NIS2 21.2(i)
Warning
TeamsBlock guest access to group content
CIS Active Directory · NIST AC-21 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i)
Compliant
SharePointLimit SharePoint access from unmanaged devices
CIS Active Directory · NIST AC-3 · ISO 27001 A.8.5 · DORA Art. 9 · NIS2 21.2(h)
Compliant
PurviewPublish retention labels
CIS Active Directory · NIST SI-12 · ISO 27001 A.5.33 · DORA Art. 9 · NIS2 21.2(h)
Compliant
ExchangeDeploy an authentication policy blocking legacy authentication
CIS Active Directory · NIST IA-2 · ISO 27001 A.8.5 · DORA Art. 9 · NIS2 21.2(j)
Compliant
SharePointSign out idle sessions
CIS Active Directory · NIST AC-12 · ISO 27001 A.8.5 · DORA Art. 9 · NIS2 21.2(i)
Compliant
TeamsDefine guest usage guidelines
CIS Active Directory · NIST AC-21 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i)
Warning
SharePointRestrict external sharing domains
CIS Active Directory · NIST AC-21 · ISO 27001 A.5.14 · CISA SCuBA MS.SHAREPOINT.1.3 · DORA Art. 9 · NIS2 21.2(i)
Compliant
OneDriveSet a default OneDrive storage limit
CIS Active Directory · NIST PM-1 · ISO 27001 A.5.1 · DORA Art. 10 · NIS2 21.2(b)
Compliant
TeamsControl anonymous user access to meetings
CIS Active Directory · NIST AC-14 · ISO 27001 A.8.3 · DORA Art. 9 · NIS2 21.2(i)
Compliant
CIS Intune
5 controls
60%
IntuneAnalyze configuration profile assignments
CIS Intune · NIST CM-6 · ISO 27001 A.8.9 · DORA Art. 9 · NIS2 21.2(i)
Non-compliant
IntuneRequire multi-admin approval for destructive actions
CIS Intune · NIST AC-6 · ISO 27001 A.8.2 · DORA Art. 9 · NIS2 21.2(i)
Compliant
IntuneDeploy app protection policies
CIS Intune · NIST AC-19 · ISO 27001 A.8.1 · DORA Art. 9 · NIS2 21.2(i)
Compliant
IntuneEnumerate non-compliant devices
CIS Intune · NIST CM-6 · ISO 27001 A.8.9 · DORA Art. 9 · NIS2 21.2(h)
Non-compliant
IntuneReview deployed PowerShell scripts
CIS Intune · NIST CM-7 · ISO 27001 A.8.19 · DORA Art. 9 · NIS2 21.2(i)
Compliant
Microsoft Secure Score
3 controls
67%
SharePointSet a default storage limit for new sites
Microsoft Secure Score · NIST PM-1 · ISO 27001 A.5.1 · DORA Art. 9 · NIS2 21.2(i)
Compliant
SharePointHide the site creation UI
Microsoft Secure Score · NIST PM-1 · ISO 27001 A.5.1 · DORA Art. 9 · NIS2 21.2(i)
Non-compliant
DefenderStrengthen Apps secure-score controls
Microsoft Secure Score · NIST · ISO 27001 A.8.9 · DORA Art. 9 · NIS2 21.2(i)
Compliant
NIST IR-4
2 controls
50%
DefenderTolerate no active high-severity incident
NIST IR-4 · ISO 27001 A.5.26 · DORA Art. 10 · NIS2 21.2(b)
Warning
DefenderWork down stale active incidents
NIST IR-4 · ISO 27001 A.5.26 · DORA Art. 10 · NIS2 21.2(b)
Compliant
CIS Active Directory 2.1.1
1 controls
100%
DefenderEnable Safe Links for Office apps and Teams
CIS Active Directory 2.1.1 · NIST SI-3 · ISO 27001 A.8.7 · DORA Art. 10 · NIS2 21.2(b)
Compliant
CIS Active Directory 2.1.3
1 controls
100%
DefenderBlock accounts exceeding outbound sending limits
CIS Active Directory 2.1.3 · NIST SI-4 · ISO 27001 A.8.16 · DORA Art. 10 · NIS2 21.2(b)
Compliant
CIS Active Directory 3.2
1 controls
100%
PurviewSet a blocking action on DLP rules
CIS Active Directory 3.2 · NIST AC-4 · ISO 27001 A.8.12 · CISA SCuBA MS.DEFENDER.4.2 · DORA Art. 9 · NIS2 21.2(h)
Compliant
CIS Active Directory 3.5
1 controls
100%
PurviewEnable auto-labelling of sensitive documents
CIS Active Directory 3.5 · NIST MP-3 · ISO 27001 A.5.12 · DORA Art. 9 · NIS2 21.2(i)
Compliant
CIS Active Directory 6.2.3
1 controls
0%
ExchangeTag messages coming from outside
CIS Active Directory 6.2.3 · NIST SI-8 · ISO 27001 A.5.14 · DORA Art. 9 · NIS2 21.2(i)
Warning
CIS Active Directory 6.5.x
1 controls
100%
ExchangeDisable legacy protocols per mailbox
CIS Active Directory 6.5.x · NIST IA-2 · ISO 27001 A.5.17 · DORA Art. 9 · NIS2 21.2(i)
Compliant
CIS Active Directory 6.x
1 controls
0%
ExchangeControl inbound and outbound mail connectors
CIS Active Directory 6.x · NIST SC-8 · ISO 27001 A.8.20 · DORA Art. 9 · NIS2 21.2(i)
Non-compliant
NIST AC-2
1 controls
0%
EntraRemove disabled accounts from privileged roles
NIST AC-2 · ISO 27001 A.5.18 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
Non-compliant
NIST AC-3
1 controls
0%
EntraBlock the device code authentication flow
NIST AC-3 · ISO 27001 A.5.15 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j)
Non-compliant
NIST AC-6
1 controls
100%
EntraUse restricted management administrative units
NIST AC-6 · ISO 27001 A.8.2 · ANSSI Administration · DORA Art. 9 · NIS2 21.2(i)
Compliant
NIST SI-12
1 controls
0%
ExchangeEnable litigation hold on sensitive mailboxes
NIST SI-12 · ISO 27001 A.5.33 · DORA Art. 9 · NIS2 21.2(i)
Warning