Configuration hardening security checks across 37 apps
Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.
Why it matters
Vendor-recommended secure defaults erode as tenants grow: legacy protocols left on, patch levels behind, housekeeping settings never revisited after the admin who set them left. Hardening checks catch that drift on every scan, before an attacker or an auditor does.
Browse by app
- Microsoft 365 50 checks
- Google Cloud 45 checks
- Azure 38 checks
- AWS 27 checks
- OpenRouter AI 23 checks
- Google Workspace 21 checks
- Zoom 20 checks
- DigitalOcean 16 checks
- Jamf Pro 16 checks
- Akamai 15 checks
- CircleCI 14 checks
- GitHub 13 checks
- Grafana 12 checks
- Terraform Cloud 11 checks
- LastPass 11 checks
- Snowflake 10 checks
- GitLab 10 checks
- Chrome Enterprise 10 checks
- Vercel 9 checks
- OpenAI 9 checks
- Workato 8 checks
- Cisco Duo 8 checks
- Anthropic 7 checks
- Okta 7 checks
- DocuSign 7 checks
- OVH Cloud 7 checks
- PagerDuty 7 checks
- Cloudflare 5 checks
- 1Password 4 checks
- Amazon Bedrock 4 checks
- Teleport 3 checks
- Discord 3 checks
- Cloudflare Access 3 checks
- Notion 3 checks
- JumpCloud 3 checks
- Figma 3 checks
- Mistral AI 3 checks
Highest-severity checks
The 8 most severe Configuration hardening checks across all 37 apps — each links to the connector page where the setting, its remediation and its framework mapping are documented.
- Admin Master Password Never Changed — LastPass severity: critical
- Admin Stale Master Password — LastPass severity: critical
- Admin With Weak Master Password — LastPass severity: critical
- Cloud Project Suspended — OVH Cloud severity: critical
- Firewall Rule Exposes Dangerous Port — Google Cloud severity: critical
- NSG All Ports Open — Azure severity: critical
- NSG Unrestricted RDP — Azure severity: critical
- NSG Unrestricted SSH — Azure severity: critical
Where to start
Connect Microsoft 365 first — it carries the most Configuration hardening checks in the catalog(setup guide, read-only access). A first scan takes about 15 minutes and reports every failing check on this page with its remediation steps.