Skip to content

Microsoft 365 identity, MFA & sign-in security checks

Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.

On Microsoft 365, Black Cat runs 5 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Microsoft 365 connector needs.

Checks (5)

severity: high Security Defaults Disabled fix difficulty: easy #

Enable Microsoft Entra Security Defaults (or replace with equivalent Conditional Access policies) to enforce baseline MFA and block legacy auth

  1. Navigate to Microsoft Entra Admin Center > Identity > Overview > Properties
  2. Select Manage security defaults
  3. Set Security defaults to Enabled and save
  4. If using Conditional Access (Entra ID P1+) instead, ensure equivalent MFA + legacy-auth-block policies are in place before disabling

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium Guest Email OTP Not Enabled fix difficulty: easy #

Enable email one-time passcode for M365 guest users who lack Microsoft accounts

  1. Navigate to Microsoft Entra Admin Center > External Identities > All Identity Providers
  2. Enable Email One-Time Passcode for guest users
  3. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: high CA MFA Not Enforced fix difficulty: medium #

Create an M365 Conditional Access policy to require MFA for all users and cloud apps

  1. Navigate to Microsoft Entra Admin Center > Protection > Conditional Access
  2. Create a new policy targeting All Users and All resources (formerly All cloud apps)
  3. Set Grant to Require Multi-Factor Authentication
  4. Exclude break-glass accounts
  5. Enable the policy

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium Weak Authentication Factors Enabled fix difficulty: medium #

Disable weak M365 authentication methods such as SMS and voice call, and enable FIDO2

  1. Navigate to Microsoft Entra Admin Center > Protection > Authentication Methods
  2. Disable weak methods such as SMS, Voice Call, and Email OTP
  3. Enable strong methods such as FIDO2, Microsoft Authenticator, or Windows Hello
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium MFA Suspicious Activity Reporting Disabled fix difficulty: easy #

Enable M365 suspicious activity reporting to automatically block users who report fake MFA prompts

  1. Navigate to Microsoft Entra Admin Center > Protection > Authentication Methods > Settings
  2. Enable Report Suspicious Activity
  3. Configure the system to automatically block users who report suspicious MFA requests
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1d HIPAA (SaaS Security) HIPAA-308.a5 NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

More Microsoft 365 checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial