The checks Identity & Authentication Privileged Access Data Protection Device & Endpoint Collaboration & Sharing Threat Protection Licensing & Cost Governance & Operations Identity & Authentication (34) Multi-factor authentication registration coverage Fix: Approved fix from the finding NL-IDN-001 Enforcement of multi-factor authentication for all users Fix: Approved fix from the finding NL-IDN-002 Blocking of legacy authentication Fix: Approved fix from the finding NL-IDN-003 Identity baseline: security defaults or Conditional Access Fix: Approved fix from the finding NL-IDN-004 Self-service password reset registration Fix: Approved fix from the finding NL-IDN-005 Phishing-resistant authentication for administrators Fix: Approved fix from the finding NL-IDN-006 Identity Protection risk policies Fix: Approved fix from the finding NL-IDN-007 Conditional Access policies left in report-only or disabled state Fix: Approved fix, started from another page NL-IDN-008 User consent to third-party applications Fix: Approved fix from the finding NL-IDN-009 Application registration by non-administrators Fix: Approved fix from the finding NL-IDN-010 Password expiration policy Fix: Approved fix from the finding NL-IDN-011 Guest access to the directory Fix: Approved fix from the finding NL-IDN-012 Self-service sign-up to the tenant Fix: Approved fix from the finding NL-IDN-013 Text message, voice call and email codes for sign-in Fix: Approved fix from the finding NL-IDN-015 Sign-in details shown in Microsoft Authenticator Fix: Approved fix from the finding NL-IDN-016 Device code sign-in blocked Fix: Approved fix from the finding NL-IDN-017 Security info registration protected Fix: Approved fix from the finding NL-IDN-018 Phishing-resistant MFA for everyone Fix: Approved fix from the finding NL-IDN-019 Admin consent workflow Fix: Approved fix from the finding NL-IDN-020 Group and team owners consenting to apps Fix: Approved fix from the finding NL-IDN-021 Idle session timeout for Microsoft 365 on the web NL-IDN-102 Dynamic group of guest accounts NL-IDN-106 Users creating security groups Fix: Approved fix from the finding NL-IDN-107 User risk policy (secure password change for high risk) Fix: Approved fix from the finding NL-IDN-117 Sign-in risk policy (MFA for medium and high risk) Fix: Approved fix from the finding NL-IDN-118 Medium and high-risk sign-ins blocked Fix: Approved fix from the finding NL-IDN-119 Managed device required to register security info Fix: Approved fix from the finding NL-IDN-121 Custom banned password list NL-IDN-123 Password protection for on-premises Active Directory NL-IDN-124 System-preferred multifactor authentication Fix: Approved fix from the finding NL-IDN-125 Authentication methods migration complete NL-IDN-126 Access reviews for guests NL-IDN-129 Sign-in to shared mailboxes Fix: Approved fix from the finding NL-EXO-101 Modern authentication for Exchange Online Fix: Approved fix from the finding NL-EXO-121 Privileged Access (21) Administrators without registered multi-factor authentication Fix: Approved fix from the finding NL-ACC-001 Number of Global Administrators Fix: Approved fix from the finding NL-ACC-002 Privileged roles held by synchronised on-premises accounts Fix: Approved fix from the finding NL-ACC-003 Just-in-time privileged access (PIM) Fix: Approved fix from the finding NL-ACC-004 Emergency access (break-glass) accounts Fix: Approved fix from the finding NL-ACC-005 Disabled or dormant accounts holding privileged roles Fix: Approved fix from the finding NL-ACC-006 Applications holding high-privilege Graph permissions Fix: Approved fix, started from another page NL-ACC-007 Expired or expiring application credentials Fix: Approved fix from the finding NL-ACC-008 Tenant-wide consent grants carrying high-risk scopes Fix: Approved fix from the finding NL-ACC-009 Risky apps with access to company data Fix: Approved fix from the finding NL-ACC-011 Apps users consented to that read mail or files Fix: Approved fix from the finding NL-ACC-012 Unused apps still holding permissions Fix: Approved fix from the finding NL-ACC-013 Conditional Access for workload identities Fix: Approved fix from the finding NL-ACC-010 Administrator accounts with application licences NL-IDN-101 MFA required for administrator roles by Conditional Access Fix: Approved fix from the finding NL-IDN-115 Administrator sign-in frequency and browser sessions Fix: Approved fix from the finding NL-IDN-116 Approval to activate Global Administrator and Privileged Role Administrator NL-IDN-127 Alerts on privileged role assignment and activation NL-IDN-128 Access reviews for privileged roles NL-IDN-130 Client secrets on applications NL-IDN-131 Application certificate lifetime NL-IDN-132 Data Protection (11) DLP policies switched on NL-PVW-101 DLP for Microsoft Teams NL-PVW-102 DLP across email, files, Teams and devices NL-PVW-103 DLP rules block sharing NL-PVW-104 DLP rules tell people why NL-PVW-105 Sensitivity labels published Fix: Approved fix from the finding NL-PVW-106 Alert policies for compromised mail accounts NL-PVW-107 Mail forwarded outside the organisation Fix: Approved fix from the finding NL-EML-005 Sensitivity labels Fix: Approved fix from the finding NL-COL-009 Data loss prevention policies Fix: Approved fix from the finding NL-COL-010 Purview retention labels Fix: Approved fix from the finding NL-COL-011 Device & Endpoint (20) Device compliance policy coverage Fix: Approved fix from the finding NL-DEV-001 Device compliance rate Fix: Approved fix from the finding NL-DEV-002 Device compliance requirement in Conditional Access Fix: Approved fix from the finding NL-DEV-003 Stale device records Fix: Approved fix from the finding NL-DEV-004 Unmanaged devices in the directory Fix: Approved fix from the finding NL-DEV-005 Device end of life and replacement planning Fix: Approved fix from the finding NL-DEV-006 Devices without disk encryption Fix: Approved fix from the finding NL-DEV-007 Unsupported operating systems in use Fix: Approved fix from the finding NL-DEV-008 Devices with no compliance policy counted as compliant NL-INT-101 Personal devices enrolling in Intune NL-INT-102 BitLocker, firewall and antivirus required on Windows Fix: Approved fix from the finding NL-DEV-009 Windows LAPS for local administrator passwords Fix: Approved fix from the finding NL-DEV-010 Who can join devices to Entra ID NL-IDN-108 Device limit per user NL-IDN-109 Global Administrators made local administrators on joined devices NL-IDN-110 People made local administrator of the devices they join NL-IDN-111 Windows LAPS switched on in Entra ID NL-IDN-112 People reading BitLocker keys of their own devices Fix: Approved fix from the finding NL-IDN-113 Managed device required for every sign-in Fix: Approved fix from the finding NL-IDN-120 Intune enrolment signs in every time Fix: Approved fix from the finding NL-IDN-122 Collaboration & Sharing (36) SharePoint and OneDrive external sharing level Fix: Approved fix from the finding NL-COL-001 Resharing of content by external users Fix: Approved fix from the finding NL-COL-002 Groups and Teams without owners Fix: Approved fix from the finding NL-COL-003 Guest access exposure Fix: Approved fix from the finding NL-COL-004 Restrictions on who can invite guests Fix: Approved fix from the finding NL-COL-005 Stale groups and Teams Fix: Approved fix from the finding NL-COL-006 Restriction of OneDrive sync to managed devices Fix: Approved fix from the finding NL-COL-007 Public groups and Teams open to every employee Fix: Approved fix from the finding NL-COL-012 Sensitivity labels on Teams, groups and sites Fix: Approved fix from the finding NL-COL-013 External sharing limited to approved domains Fix: Approved fix from the finding NL-SPO-101 Third-party cloud storage in Teams NL-TMS-101 Email into Teams channels NL-TMS-102 Teams chat and calls with other organisations NL-TMS-103 Teams chat with personal (unmanaged) accounts NL-TMS-104 Personal Teams accounts starting conversations NL-TMS-105 Teams contact with trial-only organisations NL-TMS-106 Which Teams apps people can install NL-TMS-107 Anonymous people joining Teams meetings NL-TMS-108 Anonymous people and dial-in callers starting Teams meetings NL-TMS-109 Who bypasses the Teams meeting lobby NL-TMS-110 Dial-in callers bypassing the Teams lobby NL-TMS-111 Anonymous people in Teams meeting chat NL-TMS-112 Who can present in Teams meetings NL-TMS-113 External participants controlling shared screens NL-TMS-114 Meeting chat with untrusted organisations NL-TMS-115 Teams meeting recording by default NL-TMS-116 Teams live events always recorded NL-TMS-117 Reporting suspicious Teams messages NL-TMS-118 External access defaults for Teams and B2B Fix: Approved fix from the finding NL-COL-008 Guests accept invitations with the invited account Fix: Approved fix from the finding NL-COL-014 Legacy sign-in to SharePoint and OneDrive Fix: Approved fix from the finding NL-COL-015 Third-party storage in Microsoft 365 on the web NL-IDN-103 Guest invitations limited to allowed domains NL-IDN-114 Calendar sharing with people outside the organisation Fix: Approved fix from the finding NL-EXO-102 Shared Bookings pages Fix: Approved fix from the finding NL-EXO-104 Third-party storage in Outlook on the web Fix: Approved fix from the finding NL-EXO-123 Threat Protection (42) Microsoft Secure Score against peer average Fix: Approved fix, started from another page NL-THR-001 Unresolved risky users Fix: Approved fix from the finding NL-THR-002 Ageing unresolved security alerts Fix: Approved fix from the finding NL-THR-003 Security and compliance notification contacts Fix: Approved fix from the finding NL-THR-004 Defender for Office 365 protections Fix: Approved fix, started from another page NL-THR-005 SPF record on every custom domain Fix: Approved fix from the finding NL-EML-001 DMARC policy enforced Fix: Approved fix from the finding NL-EML-002 DKIM signing for domains that send mail Fix: Approved fix from the finding NL-EML-003 MTA-STS for inbound mail Fix: Approved fix from the finding NL-EML-004 Exchange Online hardening Fix: Approved fix, started from another page NL-EML-006 Unified audit log Fix: Approved fix from the finding NL-THR-006 Audit log retention NL-THR-007 Mailbox auditing Fix: Approved fix from the finding NL-THR-008 SMTP AUTH turned off Fix: Approved fix from the finding NL-EML-007 External sender tag in Outlook Fix: Approved fix from the finding NL-EML-008 Calendar and contact sharing with other organisations Fix: Approved fix from the finding NL-EML-009 Spam filtering skipped for listed senders Fix: Approved fix from the finding NL-EML-010 Automatic forwarding to other domains Fix: Approved fix from the finding NL-EML-011 Dangerous attachment types blocked Fix: Approved fix from the finding NL-EML-012 POP and IMAP for new mailboxes Fix: Approved fix from the finding NL-EML-013 Phishing protection in Microsoft Forms NL-IDN-105 Safe Links for email, Teams and Office apps Fix: Approved fix from the finding NL-EXO-105 Administrators told about internal senders of malware NL-EXO-106 Safe Attachments policy Fix: Approved fix from the finding NL-EXO-107 Safe Attachments for SharePoint, OneDrive and Teams, and Safe Documents Fix: Approved fix from the finding NL-EXO-108 Administrators told about outbound spam NL-EXO-109 Anti-phishing policy with impersonation protection NL-EXO-110 DKIM signing turned on in Exchange Online Fix: Approved fix from the finding NL-EXO-111 Comprehensive attachment filtering Fix: Approved fix from the finding NL-EXO-112 Domains allowed to skip spam filtering Fix: Approved fix from the finding NL-EXO-113 Outbound spam limits Fix: Approved fix from the finding NL-EXO-114 Priority accounts in the strict preset policy NL-EXO-115 Zero-hour auto purge for Teams Fix: Approved fix from the finding NL-EXO-116 Mailbox audit actions NL-EXO-117 Accounts bypassing mailbox auditing Fix: Approved fix from the finding NL-EXO-118 Mail flow rules that skip spam filtering for a domain Fix: Approved fix from the finding NL-EXO-119 People installing Outlook add-ins NL-EXO-120 MailTips Fix: Approved fix from the finding NL-EXO-122 Direct Send rejected Fix: Approved fix from the finding NL-EXO-124 Preset security policies for everyone NL-EXO-125 Impersonation protection in the preset policies NL-EXO-126 DMARC at reject, with report addresses NL-EXO-127 Licensing & Cost (5) Purchased but unassigned licences NL-LIC-001 Licences assigned to disabled accounts Fix: Approved fix from the finding NL-LIC-002 Licences assigned to dormant accounts Fix: Approved fix from the finding NL-LIC-003 Overlapping subscriptions NL-LIC-004 Accounts without a usage location Fix: Approved fix from the finding NL-LIC-005 Governance & Operations (7) Dormant enabled accounts Fix: Approved fix from the finding NL-GOV-001 Named locations for Conditional Access Fix: Approved fix from the finding NL-GOV-002 Directory synchronisation health Fix: Approved fix from the finding NL-GOV-003 Verified custom domain Fix: Approved fix from the finding NL-GOV-004 Leavers not fully offboarded Fix: Approved fix, started from another page NL-GOV-005 Office Store and self-service trials NL-IDN-104 Customer Lockbox Fix: Approved fix from the finding NL-EXO-103 critical Identity & Authentication NL-IDN-001
Multi-factor authentication registration coverage Measures how many enabled member accounts are MFA capable: registered for a multi-factor method that the authentication methods policy allows.
Recommended fix
Drive registration to 100% of enabled member accounts, then enforce it with Conditional Access.
Approved fix from the finding
Frameworks
NIST CSF 2.0 Essential Eight Cyber Essentials CIS Controls v8.1 NCSC 10 Steps ISO 27001:2022 NCSC CAF DSPT DORA NIS2 Microsoft Cloud Security Benchmark Zero Trust SOC 2 PCI DSS 4.0.1 NIST SP 800-171 CMMC Level 2 Secure Score Cyber Essentials Plus CIS M365
A check that could not read its data is reported as not assessed and left out of the score, never counted as a pass. “Fix” marks a check with an approved fix: a dry run, approval and a way back.