| Contoso Legal LLP
|
1131312 |
MFA is enforced for all users: Fail (medium, 1) · Enforced by Require MFA for all users, with 1 exclusion to review
Legacy authentication is blocked: Fail (high, 1) · Legacy authentication is allowed
Every active user has MFA registered: Fail (high, 4) · 4 users without MFA
No unexpected changes to how domains sign in: Fail (high, 1) · 1 domain had sign-in settings changed in the last 30 days
Nobody relies on a text or call as their only second factor: Fail (low, 3) · 3 people can only use a text or call as a second factor
No risky sign-ins succeeded: Not checked · Sign-in risk needs Entra ID P2
No accounts are at risk in Entra ID Protection: Not checked · Risky users need Entra ID P2 |
Every admin has MFA registered: Fail (critical, 2) · 1 admin without MFA, and 1 whose registration isn't known
Between 2 and 4 Global Administrators: Pass · 2 Global Administrators
No guests hold admin roles: Fail (high, 1) · 1 guest with admin roles
Apps with admin roles are reviewed: Fail (medium, 1) · 1 app with privileged roles
Every admin is covered by an MFA policy: Fail (high, 1) · 1 admin not covered by MFA
Admins use phishing-resistant sign-in methods: Fail (medium, 2) · 2 admins without a phishing-resistant method |
No inactive accounts: Fail (medium, 2) · 2 accounts inactive for 90+ days or never used
No account reports to a blocked manager: Fail (low, 1) · 1 account reports to a blocked manager |
No licences on disabled accounts: Fail (medium, 1) · 1 disabled account still licensed
No paid licences sit unassigned: Fail (low, 2) · 2 subscriptions with spare licences
Every licence assignment works: Pass · Every licence assignment worked
No subscriptions are about to lapse: Pass · 2 subscriptions checked; none is lapsing |
No mail is forwarded outside the organisation: Fail (high, 3) · 3 external forwards
No inbox rules hide mail: Fail (high, 1) · 1 suspicious inbox rule
Automatic forwarding to outside addresses is off: Pass · The default outbound policy blocks automatic external forwarding
Shared mailboxes can't be signed in to: Pass · All 3 shared mailboxes block sign-in
Mailbox auditing is on: Pass · Mailbox auditing is on for the organisation
SMTP AUTH is turned off: Fail (low, 1) · SMTP AUTH is on for the organisation
Mail domains require encrypted delivery (MTA-STS): Fail (low, 1) · 1 of 1 mail domain doesn't fully enforce MTA-STS
Encrypted delivery failures are reported (TLS-RPT): Not checked · TLS-RPT is checked on mail domains that use MTA-STS, and none do yet
Every domain has a working SPF record: Fail (low, 1) · 1 domain with SPF problems
Every domain enforces DMARC: Fail (medium, 2) · 2 domains without DMARC enforcement
DKIM signing is on for every mail domain: Fail (medium, 1) · 1 mail domain without DKIM |
Third-party apps hold only the access they need: Fail (high, 1) · 1 app with access to mail, files or the directory
Users can't consent to apps on their own: Fail (medium, 1) · Users can consent to any app
App secrets and certificates are current: Fail (low, 1) · 1 app registration with expiring or expired credentials |
Users can't create new tenants: Not checked · Microsoft didn't return this setting
Users can't register apps: Fail (low, 1) · Any user can register an app
Guests have limited directory access: Pass · Guests have limited access to directory objects (the default)
People can't join the tenant just by verifying an email address: Not checked · Microsoft didn't return this setting
Users have a way to get apps approved: Pass · Users can consent to most apps themselves, so admin consent requests are off (see the user consent check) |
Files can't be shared with anonymous links: Fail (medium, 1) · Anyone, including anonymous links
No files are shared with anyone links: Fail (high, 3) · 3 files and folders shared with anyone
Every site has at least two owners: Fail (high, 3) · 1 site with no owner, 2 sites with one owner
Guests don't have full control of sites: Fail (high, 1) · 1 guest with full control of 1 site
People outside can only view shared files: Fail (medium, 1) · 1 file or folder outside people can edit |
Only admins and members can invite guests: Fail (low, 1) · Anyone, including guests, can invite guests
No old, unaccepted guest invitations: Pass · No stale guest invitations
No guest owns a team or group: Pass · No guest owns any of 9 teams and groups |
Every team and Microsoft 365 group has an owner: Fail (medium, 4) · 4 teams and groups without an owner
Only chosen people can create teams and groups: Pass · Only admins and members of Group creators can create teams and groups
Unused groups and teams expire: Pass · Unused teams and groups expire after 365 days |
Managed devices meet compliance policies: Fail (medium, 3) · 3 of 20 managed devices not compliant
Company computers are encrypted: Fail (high, 2) · 2 of 19 computers not encrypted
Windows computers still get security updates: Fail (high, 11) · 3 of 19 Windows computers past end of support
Joined computers are managed by Intune: Fail (low, 1) · 1 of 20 joined computers not in Intune
Managed devices check in with Intune: Fail (low, 2) · 2 devices haven't checked in for 30+ days
No old devices left in Entra ID: Fail (low, 1) · 1 of 22 device records unused for 90+ days |
Directory sync is running: Not checked · Cloud-only tenant: directory sync isn't turned on
Password hash sync is on: Not checked · Cloud-only tenant: directory sync isn't turned on
Admin accounts are cloud-only: Pass · Cloud-only tenant: no accounts are synced from on-premises AD |
SharePoint storage isn't nearly full: Pass · 28% of about 1.18 TB used (1 TB + 10 GB × 18 licences)
No mailbox is nearly full: Fail (medium, 3) · 3 mailboxes at or over 90% of quota
No OneDrive is nearly full: Pass · None of 19 OneDrives is over 90% of its quota |
| Northwind Traders
|
1131312 |
MFA is enforced for all users: Fail (medium, 1) · Enforced by Require MFA for all users, with 1 exclusion to review
Legacy authentication is blocked: Fail (high, 1) · Legacy authentication is allowed
Every active user has MFA registered: Fail (high, 14) · 14 users without MFA
No unexpected changes to how domains sign in: Fail (high, 1) · 1 domain had sign-in settings changed in the last 30 days
Nobody relies on a text or call as their only second factor: Fail (low, 3) · 3 people can only use a text or call as a second factor
No risky sign-ins succeeded: Not checked · Sign-in risk needs Entra ID P2
No accounts are at risk in Entra ID Protection: Not checked · Risky users need Entra ID P2 |
Every admin has MFA registered: Fail (critical, 2) · 1 admin without MFA, and 1 whose registration isn't known
Between 2 and 4 Global Administrators: Pass · 2 Global Administrators
No guests hold admin roles: Fail (high, 1) · 1 guest with admin roles
Apps with admin roles are reviewed: Fail (medium, 1) · 1 app with privileged roles
Every admin is covered by an MFA policy: Fail (high, 1) · 1 admin not covered by MFA
Admins use phishing-resistant sign-in methods: Fail (medium, 2) · 2 admins without a phishing-resistant method |
No inactive accounts: Fail (medium, 4) · 4 accounts inactive for 90+ days or never used
No account reports to a blocked manager: Fail (low, 1) · 1 account reports to a blocked manager |
No licences on disabled accounts: Fail (medium, 1) · 1 disabled account still licensed
No paid licences sit unassigned: Fail (low, 2) · 2 subscriptions with spare licences
Every licence assignment works: Pass · Every licence assignment worked
No subscriptions are about to lapse: Pass · 2 subscriptions checked; none is lapsing |
No mail is forwarded outside the organisation: Fail (high, 4) · 4 external forwards
No inbox rules hide mail: Fail (high, 1) · 1 suspicious inbox rule
Automatic forwarding to outside addresses is off: Pass · The default outbound policy blocks automatic external forwarding
Shared mailboxes can't be signed in to: Pass · All 3 shared mailboxes block sign-in
Mailbox auditing is on: Pass · Mailbox auditing is on for the organisation
SMTP AUTH is turned off: Fail (low, 1) · SMTP AUTH is on for the organisation
Mail domains require encrypted delivery (MTA-STS): Fail (low, 1) · 1 of 1 mail domain doesn't fully enforce MTA-STS
Encrypted delivery failures are reported (TLS-RPT): Not checked · TLS-RPT is checked on mail domains that use MTA-STS, and none do yet
Every domain has a working SPF record: Fail (low, 1) · 1 domain with SPF problems
Every domain enforces DMARC: Fail (medium, 2) · 2 domains without DMARC enforcement
DKIM signing is on for every mail domain: Fail (medium, 1) · 1 mail domain without DKIM |
Third-party apps hold only the access they need: Fail (high, 1) · 1 app with access to mail, files or the directory
Users can't consent to apps on their own: Fail (medium, 1) · Users can consent to any app
App secrets and certificates are current: Fail (low, 1) · 1 app registration with expiring or expired credentials |
Users can't create new tenants: Not checked · Microsoft didn't return this setting
Users can't register apps: Fail (low, 1) · Any user can register an app
Guests have limited directory access: Pass · Guests have limited access to directory objects (the default)
People can't join the tenant just by verifying an email address: Not checked · Microsoft didn't return this setting
Users have a way to get apps approved: Pass · Users can consent to most apps themselves, so admin consent requests are off (see the user consent check) |
Files can't be shared with anonymous links: Fail (medium, 1) · Anyone, including anonymous links
No files are shared with anyone links: Fail (high, 3) · 3 files and folders shared with anyone
Every site has at least two owners: Fail (high, 3) · 1 site with no owner, 2 sites with one owner
Guests don't have full control of sites: Fail (high, 1) · 1 guest with full control of 1 site
People outside can only view shared files: Fail (medium, 1) · 1 file or folder outside people can edit |
Only admins and members can invite guests: Fail (low, 1) · Anyone, including guests, can invite guests
No old, unaccepted guest invitations: Pass · No stale guest invitations
No guest owns a team or group: Pass · No guest owns any of 9 teams and groups |
Every team and Microsoft 365 group has an owner: Fail (medium, 4) · 4 teams and groups without an owner
Only chosen people can create teams and groups: Pass · Only admins and members of Group creators can create teams and groups
Unused groups and teams expire: Pass · Unused teams and groups expire after 365 days |
Managed devices meet compliance policies: Fail (medium, 6) · 6 of 37 managed devices not compliant
Company computers are encrypted: Fail (high, 4) · 4 of 36 computers not encrypted
Windows computers still get security updates: Fail (high, 25) · 5 of 36 Windows computers past end of support
Joined computers are managed by Intune: Fail (low, 1) · 1 of 37 joined computers not in Intune
Managed devices check in with Intune: Fail (low, 3) · 3 devices haven't checked in for 30+ days
No old devices left in Entra ID: Fail (low, 1) · 1 of 39 device records unused for 90+ days |
Directory sync is running: Not checked · Cloud-only tenant: directory sync isn't turned on
Password hash sync is on: Not checked · Cloud-only tenant: directory sync isn't turned on
Admin accounts are cloud-only: Pass · Cloud-only tenant: no accounts are synced from on-premises AD |
SharePoint storage isn't nearly full: Pass · 41% of about 1.31 TB used (1 TB + 10 GB × 32 licences)
No mailbox is nearly full: Fail (medium, 3) · 3 mailboxes at or over 90% of quota
No OneDrive is nearly full: Pass · None of 36 OneDrives is over 90% of its quota |
| Fabrikam Dental Group
|
1121512 |
MFA is enforced for all users: Fail (medium, 1) · Enforced by Require MFA for all users, with 1 exclusion to review
Legacy authentication is blocked: Fail (high, 1) · Legacy authentication is allowed
Every active user has MFA registered: Fail (high, 27) · 27 users without MFA
No unexpected changes to how domains sign in: Fail (high, 1) · 1 domain had sign-in settings changed in the last 30 days
Nobody relies on a text or call as their only second factor: Fail (low, 4) · 4 people can only use a text or call as a second factor
No risky sign-ins succeeded: Not checked · Sign-in risk needs Entra ID P2
No accounts are at risk in Entra ID Protection: Not checked · Risky users need Entra ID P2 |
Every admin has MFA registered: Fail (critical, 2) · 1 admin without MFA, and 1 whose registration isn't known
Between 2 and 4 Global Administrators: Pass · 2 Global Administrators
No guests hold admin roles: Fail (high, 1) · 1 guest with admin roles
Apps with admin roles are reviewed: Fail (medium, 1) · 1 app with privileged roles
Every admin is covered by an MFA policy: Fail (high, 1) · 1 admin not covered by MFA
Admins use phishing-resistant sign-in methods: Fail (medium, 2) · 2 admins without a phishing-resistant method |
No inactive accounts: Fail (medium, 7) · 7 accounts inactive for 90+ days or never used
No account reports to a blocked manager: Fail (low, 1) · 1 account reports to a blocked manager |
No licences on disabled accounts: Fail (medium, 1) · 1 disabled account still licensed
No paid licences sit unassigned: Fail (low, 2) · 2 subscriptions with spare licences
Every licence assignment works: Pass · Every licence assignment worked
No subscriptions are about to lapse: Pass · 2 subscriptions checked; none is lapsing |
No mail is forwarded outside the organisation: Fail (high, 5) · 5 external forwards
No inbox rules hide mail: Fail (high, 1) · 1 suspicious inbox rule
Automatic forwarding to outside addresses is off: Pass · The default outbound policy blocks automatic external forwarding
Shared mailboxes can't be signed in to: Pass · All 3 shared mailboxes block sign-in
Mailbox auditing is on: Pass · Mailbox auditing is on for the organisation
SMTP AUTH is turned off: Fail (low, 1) · SMTP AUTH is on for the organisation
Mail domains require encrypted delivery (MTA-STS): Fail (low, 1) · 1 of 1 mail domain doesn't fully enforce MTA-STS
Encrypted delivery failures are reported (TLS-RPT): Not checked · TLS-RPT is checked on mail domains that use MTA-STS, and none do yet
Every domain has a working SPF record: Fail (low, 1) · 1 domain with SPF problems
Every domain enforces DMARC: Fail (medium, 2) · 2 domains without DMARC enforcement
DKIM signing is on for every mail domain: Fail (medium, 1) · 1 mail domain without DKIM |
Third-party apps hold only the access they need: Fail (high, 1) · 1 app with access to mail, files or the directory
Users can't consent to apps on their own: Fail (medium, 1) · Users can consent to any app
App secrets and certificates are current: Fail (low, 1) · 1 app registration with expiring or expired credentials |
Users can't create new tenants: Not checked · Microsoft didn't return this setting
Users can't register apps: Fail (low, 1) · Any user can register an app
Guests have limited directory access: Pass · Guests have limited access to directory objects (the default)
People can't join the tenant just by verifying an email address: Not checked · Microsoft didn't return this setting
Users have a way to get apps approved: Pass · Users can consent to most apps themselves, so admin consent requests are off (see the user consent check) |
Files can't be shared with anonymous links: Fail (medium, 1) · Anyone, including anonymous links
No files are shared with anyone links: Fail (medium, 2) · 2 files and folders shared with anyone
Every site has at least two owners: Fail (high, 4) · 2 sites with no owner, 2 sites with one owner
Guests don't have full control of sites: Fail (high, 1) · 1 guest with full control of 1 site
People outside can only view shared files: Fail (medium, 2) · 2 files and folders outside people can edit |
Only admins and members can invite guests: Fail (low, 1) · Anyone, including guests, can invite guests
No old, unaccepted guest invitations: Pass · No stale guest invitations
No guest owns a team or group: Pass · No guest owns any of 9 teams and groups |
Every team and Microsoft 365 group has an owner: Fail (medium, 4) · 4 teams and groups without an owner
Only chosen people can create teams and groups: Pass · Only admins and members of Group creators can create teams and groups
Unused groups and teams expire: Pass · Unused teams and groups expire after 365 days |
Managed devices meet compliance policies: Fail (medium, 9) · 9 of 55 managed devices not compliant
Company computers are encrypted: Fail (high, 6) · 6 of 54 computers not encrypted
Windows computers still get security updates: Fail (high, 36) · 7 of 54 Windows computers past end of support
Joined computers are managed by Intune: Fail (low, 1) · 1 of 55 joined computers not in Intune
Managed devices check in with Intune: Fail (low, 5) · 5 devices haven't checked in for 30+ days
No old devices left in Entra ID: Fail (low, 1) · 1 of 57 device records unused for 90+ days |
Directory sync is running: Not checked · Cloud-only tenant: directory sync isn't turned on
Password hash sync is on: Not checked · Cloud-only tenant: directory sync isn't turned on
Admin accounts are cloud-only: Pass · Cloud-only tenant: no accounts are synced from on-premises AD |
SharePoint storage isn't nearly full: Fail (medium, 6) · 88% of about 1.45 TB used (1 TB + 10 GB × 46 licences)
No mailbox is nearly full: Fail (medium, 3) · 3 mailboxes at or over 90% of quota
No OneDrive is nearly full: Pass · None of 54 OneDrives is over 90% of its quota |