Microsoft 365 access control & privilege security checks
Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.
On Microsoft 365, Black Cat runs 62 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Microsoft 365 connector needs.
Checks (62)
severity: high Guest User Permissions Not Restricted fix difficulty: easy #
Restrict M365 guest user permissions to Most Restrictive in External Identities settings
- Navigate to Microsoft Entra Admin Center > External Identities > External Collaboration Settings
- Set Guest User Access Restrictions to Most Restrictive
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Guest Invitation Not Restricted fix difficulty: easy #
Restrict M365 guest invitations to only users assigned to specific admin roles
- Navigate to Microsoft Entra Admin Center > External Identities > External Collaboration Settings
- Set Guest Invite Restrictions to Only Users Assigned to Specific Admin Roles
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Users Can Create Security Groups fix difficulty: easy #
Prevent non-admin M365 users from creating security groups in Azure portals
- Navigate to Microsoft Entra Admin Center > Groups > General Settings
- Set Users Can Create Security Groups in Azure Portals to No
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Users Can Register Applications fix difficulty: easy #
Prevent non-admin M365 users from registering applications in Entra ID
- Navigate to Microsoft Entra Admin Center > Users > User Settings
- Set Users Can Register Applications to No
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-308.a4 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high User Consent to Apps Not Restricted fix difficulty: medium #
Disable M365 user consent to apps and require admin approval for OAuth grants
- Navigate to Microsoft Entra Admin Center > Enterprise Applications > Consent and Permissions
- Set User Consent to Do Not Allow User Consent
- Configure an Admin Consent Workflow so users can request access
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Guest Group Privileges Not Restricted fix difficulty: easy #
Restrict M365 guest user access to limited directory properties and memberships
- Navigate to Microsoft Entra Admin Center > External Identities > External Collaboration Settings
- Set Guest User Access to Limited Access to Properties and Memberships
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Admin Consent Requests Disabled fix difficulty: easy #
Enable M365 admin consent workflow so users can request app access
- Navigate to Microsoft Entra Admin Center > Enterprise Applications > Admin Consent Settings
- Enable Users Can Request Admin Consent
- Configure designated admin reviewers
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Users Can Create Tenants fix difficulty: easy #
Prevent M365 users from creating new Azure AD tenants
- Navigate to Microsoft Entra Admin Center > Users > User Settings
- Set Users Can Create Tenants to No
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium M365 Group Creation Not Restricted fix difficulty: medium #
Restrict M365 group creation to a specific security group of approved users
- Connect to Microsoft Graph PowerShell or use Entra Admin Center
- Create a security group for users allowed to create M365 groups
- Set the GroupCreationAllowedGroupId in directory settings to that group
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium MSOL PowerShell Not Blocked fix difficulty: medium #
Block legacy MSOL PowerShell access in M365 using Conditional Access policies
- Navigate to Microsoft Entra Admin Center > Users > User Settings
- Set Restrict Access to Azure AD Administration Portal to Yes
- Use Conditional Access to block legacy PowerShell protocols
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Self-Service Sign Up Enabled fix difficulty: easy #
Disable guest self-service sign-up flows in M365 External Identities settings
- Navigate to Microsoft Entra Admin Center > External Identities > External Collaboration Settings
- Disable Enable Guest Self-Service Sign Up via User Flows
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Guest Access to Groups Not Restricted fix difficulty: easy #
Restrict M365 guest user access to group properties and memberships
- Navigate to Microsoft Entra admin center > Identity > External Identities > External collaboration settings
- Under Guest user access restrictions, choose the most restrictive guest access option
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-28.3 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Global Admin Redundancy Missing fix difficulty: easy #
Ensure at least two M365 Global Administrator accounts exist for redundancy
- Navigate to Microsoft Entra Admin Center > Roles and Administrators
- Verify at least two Global Administrator accounts exist
- If only one exists, assign a second trusted user the Global Admin role
- Ensure both use cloud-only accounts with MFA enabled
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Excessive Global Administrators fix difficulty: medium #
Reduce M365 Global Admin count to 2-4 accounts by demoting unnecessary admins
- Navigate to Microsoft Entra Admin Center > Roles and Administrators > Global Administrator
- Review the list of Global Admins
- Demote unnecessary Global Admins to more specific admin roles
- Keep only 2-4 Global Admin accounts
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Global Admin Not Cloud-Only fix difficulty: hard #
Replace synced M365 Global Admin accounts with cloud-only admin accounts
- Navigate to Microsoft Entra Admin Center > Roles and Administrators > Global Administrator
- Identify Global Admins that are synced from on-premises AD
- Create cloud-only admin accounts for these users
- Remove the Global Admin role from synced accounts
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high External Users With Admin Role fix difficulty: medium #
Remove admin roles from external M365 guest users and create internal accounts
- Navigate to Microsoft Entra Admin Center > Users > All Users
- Filter for external/guest users with admin roles
- Remove admin roles from external users
- Create internal accounts if admin access is required
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Guest Users Present fix difficulty: medium #
Review and remove M365 guest accounts that no longer require access
- Navigate to Microsoft Entra Admin Center > Users > All Users
- Filter for guest users
- Review each guest user and confirm they still need access
- Remove guest accounts that are no longer required
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Copilot License on Guest User fix difficulty: easy #
Remove Copilot licenses from M365 guest accounts to prevent data exposure
- Navigate to Microsoft 365 Admin Center > Billing > Licenses
- Identify guest users with Copilot licenses
- Remove Copilot license from guest accounts
- Reassign to internal users if needed
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high CA Block High Risk Users Missing fix difficulty: medium #
Create an M365 Conditional Access policy to block high-risk users from signing in
- Navigate to Microsoft Entra Admin Center > Protection > Conditional Access
- Create a new policy targeting All Users
- Set Conditions > User Risk to High
- Set Grant to Block Access
- Enable the policy
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high CA Block Risky Sign-ins Missing fix difficulty: medium #
Create an M365 Conditional Access policy to block or require MFA for risky sign-ins
- Navigate to Microsoft Entra Admin Center > Protection > Conditional Access
- Create a new policy targeting All Users
- Set Conditions > Sign-In Risk to High and Medium
- Set Grant to Block Access or Require MFA
- Enable the policy
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-33.1 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium CA Legacy Auth Not Blocked fix difficulty: medium #
Create an M365 Conditional Access policy to block legacy authentication protocols
- Navigate to Microsoft Entra Admin Center > Protection > Conditional Access
- Create a new policy targeting All Users
- Set Conditions > Client Apps to Exchange ActiveSync and Other Clients
- Set Grant to Block Access
- Enable the policy
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium CA Session Duration Not Set fix difficulty: easy #
Configure M365 Conditional Access sign-in frequency to a maximum of 12 hours
- Navigate to Microsoft Entra Admin Center > Protection > Conditional Access
- Edit or create a policy targeting All Users
- Set Session > Sign-In Frequency to a maximum of 12 hours
- Enable Persistent Browser Session as needed
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium CA Compliant Devices Not Required fix difficulty: hard #
Create an M365 Conditional Access policy to require compliant devices for all cloud apps
- Navigate to Microsoft Entra Admin Center > Protection > Conditional Access
- Create a policy targeting All Users and All Cloud Apps
- Set Grant to Require Device to Be Marked as Compliant
- Ensure device compliance policies are configured in Intune
- Enable the policy
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium CA Device Code Flow Not Blocked fix difficulty: easy #
Create an M365 Conditional Access policy to block the device code authentication flow
- Navigate to Microsoft Entra Admin Center > Protection > Conditional Access
- Create a new policy targeting All Users
- Set Conditions > Authentication Flows > Device Code Flow
- Set Grant to Block Access
- Enable the policy
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Auth Methods Migration Incomplete fix difficulty: hard #
Complete the M365 migration from legacy MFA to the unified Authentication Methods policy
- Navigate to Microsoft Entra Admin Center > Protection > Authentication Methods > Policies
- Check the migration status from legacy MFA/SSPR to Authentication Methods
- Complete the migration by enabling all required methods in the new policy
- Disable the legacy MFA policies
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high TAP Enabled for All Users fix difficulty: easy #
Restrict M365 Temporary Access Pass to specific admin groups rather than all users
- Navigate to Microsoft Entra Admin Center > Protection > Authentication Methods
- Select Temporary Access Pass
- Restrict TAP to specific admin groups rather than All Users
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high TAP Not One-Time Use fix difficulty: easy #
Configure M365 Temporary Access Pass to be usable only once
- Navigate to Microsoft Entra Admin Center > Protection > Authentication Methods
- Select Temporary Access Pass
- Enable the Is Usable Once setting
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium TAP Global Policy Enabled fix difficulty: easy #
Disable the M365 global TAP policy and use targeted group assignments instead
- Navigate to Microsoft Entra Admin Center > Protection > Authentication Methods
- Select Temporary Access Pass
- Disable the global TAP policy and use targeted group assignments instead
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium TAP Maximum Lifetime Too Long fix difficulty: easy #
Set M365 Temporary Access Pass maximum lifetime to 1 hour or less
- Navigate to Microsoft Entra Admin Center > Protection > Authentication Methods
- Select Temporary Access Pass
- Set Maximum Lifetime to 1 hour or less
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium TAP Character Length Too Short fix difficulty: easy #
Set M365 Temporary Access Pass minimum character length to at least 8 characters
- Navigate to Microsoft Entra Admin Center > Protection > Authentication Methods
- Select Temporary Access Pass
- Set Minimum Character Length to at least 8 characters
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Password Expiration Policy Enabled fix difficulty: easy #
Disable M365 password expiration policy per NIST guidance and rely on MFA instead
- Navigate to Microsoft 365 Admin Center > Settings > Org Settings > Security & Privacy
- Select Password Expiration Policy
- Set passwords to never expire (per NIST 800-63B guidance)
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Password Lockout Threshold Too High fix difficulty: easy #
Set M365 password lockout threshold to 10 or fewer failed attempts
- Navigate to Microsoft Entra Admin Center > Protection > Authentication Methods > Password Protection
- Set the lockout threshold to 10 or fewer failed attempts
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Lockout Duration Too Short fix difficulty: easy #
Set M365 password lockout duration to at least 60 seconds
- Navigate to Microsoft Entra Admin Center > Protection > Authentication Methods > Password Protection
- Set the lockout duration to at least 60 seconds
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Custom Banned Passwords Not Enforced fix difficulty: easy #
Enable M365 custom banned password list enforcement to block organization-specific terms
- Navigate to Microsoft Entra Admin Center > Protection > Authentication Methods > Password Protection
- Enable Enforce Custom Banned Password List
- Add organization-specific terms to the banned password list
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Password Protection On-Prem Disabled fix difficulty: hard #
Enable M365 password protection for on-premises Windows Server Active Directory
- Navigate to Microsoft Entra Admin Center > Protection > Authentication Methods > Password Protection
- Enable Password Protection for Windows Server Active Directory
- Deploy Azure AD Password Protection proxy agents on-premises
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Password Protection Mode Audit Only fix difficulty: easy #
Switch M365 on-premises password protection mode from Audit to Enforced
- Navigate to Microsoft Entra Admin Center > Protection > Authentication Methods > Password Protection
- Change Mode from Audit to Enforced
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high SP Using Password Credentials fix difficulty: hard #
Replace M365 service principal password credentials with certificate-based authentication
- Navigate to Microsoft Entra Admin Center > App Registrations
- Select the application associated with the service principal
- Navigate to Certificates & Secrets
- Add a certificate credential and remove the password credential
- Update the application configuration to use certificate-based auth
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low SP Expired Password Credentials fix difficulty: easy #
Delete expired password credentials from M365 service principals
- Navigate to Microsoft Entra Admin Center > App Registrations
- Select the application with expired secrets
- Navigate to Certificates & Secrets
- Delete the expired password credential
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low SP Expired Certificate Credentials fix difficulty: medium #
Replace expired M365 service principal certificate credentials with a new certificate
- Navigate to Microsoft Entra Admin Center > App Registrations
- Select the application with expired certificates
- Navigate to Certificates & Secrets
- Upload a new certificate and remove the expired one
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium SP Long-Lived Password Credentials fix difficulty: medium #
Rotate M365 service principal secrets that exceed 90 days and set shorter expiry
- Navigate to Microsoft Entra Admin Center > App Registrations
- Select the application with long-lived secrets
- Navigate to Certificates & Secrets
- Create a new secret with a shorter expiry (90 days recommended)
- Update the application and delete the long-lived secret
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium SP Long-Lived Certificate Credentials fix difficulty: medium #
Rotate M365 service principal certificates exceeding 1 year and set shorter validity
- Navigate to Microsoft Entra Admin Center > App Registrations
- Select the application with long-lived certificates
- Generate a new certificate with a shorter validity period (1 year recommended)
- Upload the new certificate and remove the long-lived one
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low SP Password Credentials Expiring Soon fix difficulty: medium #
Renew M365 service principal secrets expiring soon and update the application configuration
- Navigate to Microsoft Entra Admin Center > App Registrations
- Select the application with secrets expiring soon
- Navigate to Certificates & Secrets
- Create a new secret and update the application configuration
- Delete the old secret after migration
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low SP Certificate Credentials Expiring Soon fix difficulty: medium #
Renew M365 service principal certificates expiring soon and update the application
- Navigate to Microsoft Entra Admin Center > App Registrations
- Select the application with certificates expiring soon
- Generate and upload a new certificate
- Update the application configuration and remove the old certificate
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium App Using Password Credentials fix difficulty: medium #
Replace M365 app registration password credentials with certificate-based authentication
- Navigate to Microsoft Entra Admin Center > App Registrations
- Select the application using password credentials
- Navigate to Certificates & Secrets
- Add a certificate credential to replace the password
- Update the application to use certificate-based authentication
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium App Long-Lived Password Credentials fix difficulty: medium #
Rotate M365 app registration secrets that exceed 90 days and set shorter expiry
- Navigate to Microsoft Entra Admin Center > App Registrations
- Select the application with long-lived secrets
- Create a new secret with a shorter expiry (90 days recommended)
- Update the application and delete the long-lived secret
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium App Long-Lived Certificate Credentials fix difficulty: medium #
Rotate M365 app registration certificates exceeding 1 year and set shorter validity
- Navigate to Microsoft Entra Admin Center > App Registrations
- Select the application with long-lived certificates
- Generate a new certificate with a shorter validity period
- Upload the new certificate and remove the long-lived one
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low App Expired Password Credentials fix difficulty: easy #
Delete expired password credentials from M365 app registrations
- Navigate to Microsoft Entra Admin Center > App Registrations
- Select the application with expired secrets
- Navigate to Certificates & Secrets
- Delete the expired secret
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low App Expired Certificate Credentials fix difficulty: easy #
Replace expired M365 app registration certificates with a new certificate
- Navigate to Microsoft Entra Admin Center > App Registrations
- Select the application with expired certificates
- Upload a new certificate and remove the expired one
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low App Password Credentials Expiring Soon fix difficulty: medium #
Renew M365 app registration secrets expiring soon and update the application configuration
- Navigate to Microsoft Entra Admin Center > App Registrations
- Select the application with secrets expiring soon
- Create a new secret and update the application configuration
- Delete the old secret after confirming the new one works
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low App Certificate Credentials Expiring Soon fix difficulty: medium #
Renew M365 app registration certificates expiring soon and update the application
- Navigate to Microsoft Entra Admin Center > App Registrations
- Select the application with certificates expiring soon
- Generate and upload a new certificate
- Remove the old certificate after confirming the new one works
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium OAuth App AI With Data Scopes fix difficulty: medium #
Revoke sensitive Microsoft Graph API scopes from AI OAuth apps in Microsoft Entra
- Navigate to Microsoft Entra Admin Center > Enterprise Applications
- Search for and select the flagged AI application
- Navigate to Permissions and review the granted Microsoft Graph scopes
- Click Grant admin consent revocation or remove sensitive scope delegations
- Require users to re-consent with reduced scopes if the app is still needed
- Consider restricting user consent for high-risk scopes organisation-wide
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-308.a4 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium OWA Session Timeout Disabled fix difficulty: easy #
Enable activity-based session timeout for M365 Outlook Web Access with a 30-minute limit
- Navigate to Exchange Admin Center > Recipients > Mailboxes > OWA Mailbox Policy
- Edit the default OWA mailbox policy
- Set ActivityBasedTimeout to Enabled with a 30-minute timeout
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Shared Mailbox Sign-In Enabled fix difficulty: easy #
Block direct sign-in for M365 shared mailbox accounts and enforce delegation-only access
- Navigate to Microsoft Entra Admin Center > Users
- Find the shared mailbox user account
- Block sign-in for the account
- Verify shared mailbox access works via delegation only
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Users Can Install Outlook Add-ins fix difficulty: easy #
Prevent M365 users from installing Outlook add-ins by disabling user install in OWA policy
- Connect to Exchange Online PowerShell
- Run Set-OwaMailboxPolicy -Identity OwaMailboxPolicy-Default -UserInstallEnabled $false
- Verify with Get-OwaMailboxPolicy | Select UserInstallEnabled
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Direct File Access on Public Computers fix difficulty: easy #
Disable direct file access from public computers in M365 OWA mailbox policy
- Connect to Exchange Online PowerShell
- Run Set-OwaMailboxPolicy -Identity OwaMailboxPolicy-Default -DirectFileAccessOnPublicComputersEnabled $false
- Verify with Get-OwaMailboxPolicy | Select DirectFileAccessOnPublicComputersEnabled
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium WAC Viewing on Public Computers fix difficulty: easy #
Disable Office document viewing on public computers in M365 OWA mailbox policy
- Connect to Exchange Online PowerShell
- Run Set-OwaMailboxPolicy -Identity OwaMailboxPolicy-Default -WacViewingOnPublicComputersEnabled $false
- Verify with Get-OwaMailboxPolicy | Select WacViewingOnPublicComputersEnabled
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Mobile Device Allows Non-Provisionable fix difficulty: easy #
Configure M365 mobile device policies to block non-provisionable devices
- Navigate to Exchange Admin Center > Mobile > Mobile Device Mailbox Policies
- Edit the default mobile device policy
- Set Allow Non-Provisionable Devices to No
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium ActiveSync Does Not Block Unmanaged Devices fix difficulty: medium #
Configure M365 ActiveSync to block unmanaged devices from accessing Exchange
- Navigate to Exchange Admin Center > Mobile > Mobile Device Access
- Set the default access level to Block for unmanaged devices
- Configure device access rules for approved device types
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Copilot Agent Excessive Connectors fix difficulty: medium #
Reduce the number of connector operations below 5
- Open Power Platform Admin Center > Copilot Studio
- Select the agent and review its connector operations
- Remove unnecessary connectors or reduce operations
Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3
severity: high Copilot Agent Sensitive Connector Write Access fix difficulty: medium #
Remove write access to sensitive connectors or restrict to read-only
- Open Power Platform Admin Center > Copilot Studio
- Select the agent and review connector operations
- Change sensitive connector operations to Knowledge (read-only) instead of Tool/TopicTool
Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3
severity: high Copilot Agent Maker Provided Credentials fix difficulty: medium #
Switch from maker-provided credentials to per-user authentication
- Open Power Platform Admin Center > Copilot Studio
- Select the agent and go to connector settings
- Change connection provider from Maker to User for each flagged connector
Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3
severity: medium Copilot Agent No User Consent Required fix difficulty: easy #
Enable end-user consent for connector operations
- Open Power Platform Admin Center > Copilot Studio
- Select the agent and review operations
- Enable requiresEndUserConsent for operations that access user data
Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3