Skip to content

Exposures Assessed - Azure AD Assessment

ExposureRequired Azure AD License
Azure AD Tenant without User Risk Policies enabledPremium P1
Standard users without Multi Factor authenticationPremium P2
New Azure AD Local Admin Added to Azure AD DevicesPremium P2
Subscription Admin Users without MFA enabledPremium P2
High Number of Subscription Owners in the TenantPremium P2
Tenant with Legacy Authentication Methods EnabledPremium P2
Azure AD Tenant without Sign-In Risk Policies enabledPremium P2
Privileged Users without Multi-Factor Authentication (MFA)Premium P2
Self Service Password Reset (SSPR) Is DisabledPremium P2
Guest Users Found in the Azure ADPremium P2
Custom Banned Password not configured for the TenantPremium P2
Block Legacy Authentication with Conditional AccessPremium P2
On-Prem Active Directory Password Protection DisabledPremium P2
New Classic Administrators Added RecentlyRequires subscription
External Accounts with Dangerous Permissions on SubscriptionRequires subscription
New Delegated Permissions Added RecentlyFree license
Global Administrator Role Must Be Assigned to at Least 3 Cloud-Only AccountsFree license
Restrict Access to Azure Portal with conditional accessFree license
Password Sync feature is disabled for TenantFree license
Usage of Smart Lockout in Azure ADFree license
High Number of Users in Privileged Azure AD RolesFree license
Stale service principals with password credentialsFree license
Active Directory Privileged users with Privileged roles in AzureFree license
Active Directory Privileged users synced to AzureFree license
Unlimited Sessions allowed for Portal SessionsFree license
Non Usage of Administrative Unit to delegate TasksFree license
Standard Users Allowed to Invite External UsersFree license
New Azure AD Application registeredFree license
New App role Assignment DetectedFree license
Standard Users Allowed to Create AppsFree license
Azure AD Trusted IP Configuration changesFree license
Security Defaults Disabled for Administrators and UsersFree license
Users Are Allowed to Consent to ApplicationsFree license
Microsoft Accounts in Administrator RolesFree license
Short Lived User Accounts found in TenantFree license
Standard Users Allowed to Create Security GroupsFree license
Admin Consent Workflow is Disabled for Enterprise ApplicationsFree license
Stale Devices in Azure ADFree license
Recent Changes to Azure Administrator rolesFree license
Non-Usage of Managed Identity for Azure ResourcesFree license
Service Principals with Azure AD admin RolesFree license
Azure AD Applications with Write Graph App RolesFree license
Azure AD User with Application Owner PermissionsFree license
Non-Admin users Sign-in & usage of Azure AD PowerShellFree license
Azure AD Users with Password Set to Never ExpireFree license