<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Azure Active Directory (EntraID) Assessment Setup on SolCyber Knowledgebase</title><link>https://kb.solcyber.com/active-directory-assessment-setup-guide/azure-active-directory-entraid-assessment-setup/</link><description>Recent content in Azure Active Directory (EntraID) Assessment Setup on SolCyber Knowledgebase</description><generator>Hugo</generator><language>en</language><atom:link href="https://kb.solcyber.com/active-directory-assessment-setup-guide/azure-active-directory-entraid-assessment-setup/index.xml" rel="self" type="application/rss+xml"/><item><title>Exposures Assessed - Azure AD Assessment</title><link>https://kb.solcyber.com/active-directory-assessment-setup-guide/azure-active-directory-entraid-assessment-setup/exposures-assessed-azure-ad-assessment/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://kb.solcyber.com/active-directory-assessment-setup-guide/azure-active-directory-entraid-assessment-setup/exposures-assessed-azure-ad-assessment/</guid><description>&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th width="537"&gt;Exposure&lt;/th&gt;&lt;th width="232"&gt;Required Azure AD License&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Azure AD Tenant without User Risk Policies enabled&lt;/td&gt;&lt;td&gt;Premium P1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Standard users without Multi Factor authentication&lt;/td&gt;&lt;td&gt;Premium P2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;New Azure AD Local Admin Added to Azure AD Devices&lt;/td&gt;&lt;td&gt;Premium P2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Subscription Admin Users without MFA enabled&lt;/td&gt;&lt;td&gt;Premium P2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;High Number of Subscription Owners in the Tenant&lt;/td&gt;&lt;td&gt;Premium P2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Tenant with Legacy Authentication Methods Enabled&lt;/td&gt;&lt;td&gt;Premium P2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Azure AD Tenant without Sign-In Risk Policies enabled&lt;/td&gt;&lt;td&gt;Premium P2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Privileged Users without Multi-Factor Authentication (MFA)&lt;/td&gt;&lt;td&gt;Premium P2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Self Service Password Reset (SSPR) Is Disabled&lt;/td&gt;&lt;td&gt;Premium P2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Guest Users Found in the Azure AD&lt;/td&gt;&lt;td&gt;Premium P2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Custom Banned Password not configured for the Tenant&lt;/td&gt;&lt;td&gt;Premium P2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Block Legacy Authentication with Conditional Access&lt;/td&gt;&lt;td&gt;Premium P2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;On-Prem Active Directory Password Protection Disabled&lt;/td&gt;&lt;td&gt;Premium P2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;New Classic Administrators Added Recently&lt;/td&gt;&lt;td&gt;Requires subscription&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;External Accounts with Dangerous Permissions on Subscription&lt;/td&gt;&lt;td&gt;Requires subscription&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;New Delegated Permissions Added Recently&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Global Administrator Role Must Be Assigned to at Least 3 Cloud-Only Accounts&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Restrict Access to Azure Portal with conditional access&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Password Sync feature is disabled for Tenant&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Usage of Smart Lockout in Azure AD&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;High Number of Users in Privileged Azure AD Roles&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Stale service principals with password credentials&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Active Directory Privileged users with Privileged roles in Azure&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Active Directory Privileged users synced to Azure&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Unlimited Sessions allowed for Portal Sessions&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Non Usage of Administrative Unit to delegate Tasks&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Standard Users Allowed to Invite External Users&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;New Azure AD Application registered&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;New App role Assignment Detected&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Standard Users Allowed to Create Apps&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Azure AD Trusted IP Configuration changes&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Security Defaults Disabled for Administrators and Users&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Users Are Allowed to Consent to Applications&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Microsoft Accounts in Administrator Roles&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Short Lived User Accounts found in Tenant&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Standard Users Allowed to Create Security Groups&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Admin Consent Workflow is Disabled for Enterprise Applications&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Stale Devices in Azure AD&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Recent Changes to Azure Administrator roles&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Non-Usage of Managed Identity for Azure Resources&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Service Principals with Azure AD admin Roles&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Azure AD Applications with Write Graph App Roles&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Azure AD User with Application Owner Permissions&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Non-Admin users Sign-in &amp;#x26; usage of Azure AD PowerShell&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Azure AD Users with Password Set to Never Expire&lt;/td&gt;&lt;td&gt;Free license&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;</description></item></channel></rss>