Discord access control & privilege security checks
Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.
On Discord, Black Cat runs 15 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Discord connector needs.
Checks (15)
severity: high MFA Not Required for Admins fix difficulty: easy #
Enable 2FA requirement for moderator actions in Server Settings
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "Safety Setup" in the left panel
- Under "Moderation", enable "Require 2FA/MFA for moderator actions"
- Confirm the change; Discord will enforce 2FA for all users with elevated permissions
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Low Verification Level fix difficulty: easy #
Raise the server verification level to Medium or higher in Safety Setup
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "Safety Setup" in the left panel
- Under "Verification Level", select "Medium" or higher
- Save the changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Member Verification Gate Disabled fix difficulty: easy #
Enable Membership Screening to require new members to accept server rules
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "Safety Setup" in the left panel
- Under "Membership Screening", click "Set Up Membership Screening"
- Define your server rules and enable the screening gate
- Save the changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Role Has Administrator Permission fix difficulty: medium #
Remove the Administrator permission from roles that do not require full server control
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "Roles" in the left panel
- Click the role flagged by this policy
- Under "General Permissions", disable the "Administrator" toggle
- Grant only the specific permissions the role requires instead
- Save the changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Role Has Dangerous Permissions fix difficulty: medium #
Remove dangerous permissions from the role and grant only what is necessary
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "Roles" in the left panel
- Click the flagged role to open its permission settings
- Disable permissions such as Manage Server, Manage Channels, Manage Roles, Kick Members, Ban Members that the role does not need
- Apply the principle of least privilege and save the changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: critical Everyone Role Has Dangerous Permissions fix difficulty: medium #
Remove all dangerous permissions from the @everyone role immediately
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "Roles" in the left panel
- Click the "@everyone" role at the bottom of the role list
- Disable all elevated permissions (e.g. Administrator, Manage Server, Manage Channels, Kick/Ban Members)
- Ensure @everyone has only basic permissions such as Read Messages and Send Messages if appropriate
- Save the changes and assign elevated permissions to named roles instead
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Excessive Admin Roles fix difficulty: medium #
Reduce the number of roles with Administrator permission to the minimum necessary
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "Roles" in the left panel
- Review all roles that have the "Administrator" permission enabled
- For each excess admin role, disable Administrator and grant only the specific permissions required
- Consolidate admin responsibilities into one or two clearly named admin roles
- Save the changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Role Can Mention Everyone fix difficulty: easy #
Disable the Mention Everyone permission for roles that do not need it
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "Roles" in the left panel
- Click the flagged role to open its permission settings
- Under "Text Permissions", disable "Mention @everyone, @here, and All Roles"
- Save the changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Permanent Invite fix difficulty: easy #
Delete permanent invites and replace them with time-limited invites
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "Invites" in the left panel
- Locate invites with no expiration (showing "Never" under "Expires")
- Click the delete icon next to each permanent invite
- Create a new invite with an appropriate expiration (e.g. 1 day, 7 days, 30 days)
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Unlimited Use Invite fix difficulty: easy #
Set a maximum use count on all server invites to control membership growth
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "Invites" in the left panel
- Identify invites showing unlimited uses (no max use count set)
- Delete the unlimited invite using the delete icon
- Create a replacement invite and set a "Max number of uses" appropriate to your needs
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Channel Everyone Overwrite fix difficulty: medium #
Remove elevated permission overwrites for @everyone on the flagged channel
- Open Discord and locate the flagged channel in the channel list
- Right-click the channel and select "Edit Channel"
- Navigate to the "Permissions" tab
- Click on the "@everyone" entry under "Roles / Members"
- Remove any elevated permissions (e.g. Manage Messages, Mention Everyone) by toggling them to neutral or denied
- Save the changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Overly Permissive Channel fix difficulty: medium #
Restrict channel access so only appropriate roles can read and send messages
- Open Discord and locate the flagged channel in the channel list
- Right-click the channel and select "Edit Channel"
- Navigate to the "Permissions" tab
- Review the "@everyone" and other role overwrites
- Deny "View Channel" for @everyone and add specific role allows for roles that should have access
- Save the changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Excessive Admins fix difficulty: medium #
Reduce the number of members with admin-level roles to the minimum required
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "Members" in the left panel
- Filter members by roles that have Administrator or Manage Server permissions
- Remove admin roles from members who no longer need elevated access
- Reassign members to roles with only the specific permissions they require
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Admin Role High Member Count fix difficulty: medium #
Reduce the number of members assigned to admin roles to the minimum necessary
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "Members" in the left panel
- Filter by the flagged admin role
- Remove the role from members who do not need full Administrator access
- Create lower-privilege roles for members who need specific permissions only
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Bot-Managed Role With Admin fix difficulty: medium #
Remove Administrator permission from bot-managed roles and configure specific permissions instead
- Open Discord and right-click your server icon in the left sidebar
- Select "Server Settings" from the context menu
- Navigate to "Roles" in the left panel
- Find the bot-managed role with Administrator permission
- Disable Administrator and grant only the specific permissions the bot requires
- Test the bot to verify it still functions correctly
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2