Microsoft 365 identity, MFA & sign-in security checks
Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.
On Microsoft 365, Black Cat runs 5 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Microsoft 365 connector needs.
Checks (5)
severity: high Security Defaults Disabled fix difficulty: easy #
Enable Microsoft Entra Security Defaults (or replace with equivalent Conditional Access policies) to enforce baseline MFA and block legacy auth
- Navigate to Microsoft Entra Admin Center > Identity > Overview > Properties
- Select Manage security defaults
- Set Security defaults to Enabled and save
- If using Conditional Access (Entra ID P1+) instead, ensure equivalent MFA + legacy-auth-block policies are in place before disabling
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: medium Guest Email OTP Not Enabled fix difficulty: easy #
Enable email one-time passcode for M365 guest users who lack Microsoft accounts
- Navigate to Microsoft Entra Admin Center > External Identities > All Identity Providers
- Enable Email One-Time Passcode for guest users
- Save changes
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: high CA MFA Not Enforced fix difficulty: medium #
Create an M365 Conditional Access policy to require MFA for all users and cloud apps
- Navigate to Microsoft Entra Admin Center > Protection > Conditional Access
- Create a new policy targeting All Users and All resources (formerly All cloud apps)
- Set Grant to Require Multi-Factor Authentication
- Exclude break-glass accounts
- Enable the policy
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: medium Weak Authentication Factors Enabled fix difficulty: medium #
Disable weak M365 authentication methods such as SMS and voice call, and enable FIDO2
- Navigate to Microsoft Entra Admin Center > Protection > Authentication Methods
- Disable weak methods such as SMS, Voice Call, and Email OTP
- Enable strong methods such as FIDO2, Microsoft Authenticator, or Windows Hello
- Save changes
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4
severity: medium MFA Suspicious Activity Reporting Disabled fix difficulty: easy #
Enable M365 suspicious activity reporting to automatically block users who report fake MFA prompts
- Navigate to Microsoft Entra Admin Center > Protection > Authentication Methods > Settings
- Enable Report Suspicious Activity
- Configure the system to automatically block users who report suspicious MFA requests
- Save changes
Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1d HIPAA (SaaS Security) HIPAA-308.a5 NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4