Skip to main content
Version: 2.1.1-preview

Entra ID Security Config Analyzer Tests

These tests are based on the Entra ID Security Config Analyzer and verify Microsoft Entra mitigations for common identity attack scenarios.

Tests

Test IDTitleSeverityCategory
EIDSCA.AF01Authentication Method - FIDO2 security key - State.HighGeneral
EIDSCA.AF02Authentication Method - FIDO2 security key - Allow self-service set up.MediumGeneral
EIDSCA.AF03Authentication Method - FIDO2 security key - Enforce attestation.HighGeneral
EIDSCA.AF04Authentication Method - FIDO2 security key - Enforce key restrictions.HighGeneral
EIDSCA.AF05Authentication Method - FIDO2 security key - Restricted.HighGeneral
EIDSCA.AF06Authentication Method - FIDO2 security key - Restrict specific keys.MediumGeneral
EIDSCA.AG01Authentication Method - General Settings - Manage migration.HighGeneral
EIDSCA.AG02Authentication Method - General Settings - Report suspicious activity - State.MediumGeneral
EIDSCA.AG03Authentication Method - General Settings - Report suspicious activity - Included users/groups.MediumGeneral
EIDSCA.AM01Authentication Method - Microsoft Authenticator - State.HighGeneral
EIDSCA.AM02Authentication Method - Microsoft Authenticator - Allow use of Microsoft Authenticator OTP.MediumGeneral
EIDSCA.AM03Authentication Method - Microsoft Authenticator - Require number matching for push notifications.MediumGeneral
EIDSCA.AM04Authentication Method - Microsoft Authenticator - Included users/groups of number matching for push notifications.MediumGeneral
EIDSCA.AM06Authentication Method - Microsoft Authenticator - Show application name in push and passwordless notifications.MediumGeneral
EIDSCA.AM07Authentication Method - Microsoft Authenticator - Included users/groups to show application name in push and passwordless notifications.MediumGeneral
EIDSCA.AM09Authentication Method - Microsoft Authenticator - Show geographic location in push and passwordless notifications.MediumGeneral
EIDSCA.AM10Authentication Method - Microsoft Authenticator - Included users/groups to show geographic location in push and passwordless notifications.MediumGeneral
EIDSCA.AP01Default Authorization Settings - Enabled Self service password reset for administrators.HighGeneral
EIDSCA.AP04Default Authorization Settings - Guest invite restrictions.MediumGeneral
EIDSCA.AP05Default Authorization Settings - Sign-up for email based subscription.MediumGeneral
EIDSCA.AP06Default Authorization Settings - User can join the tenant by email validation.MediumGeneral
EIDSCA.AP07Default Authorization Settings - Guest user access.HighGeneral
EIDSCA.AP08Default Authorization Settings - User consent policy assigned for applications.MediumGeneral
EIDSCA.AP09Default Authorization Settings - Allow user consent on risk-based apps.MediumGeneral
EIDSCA.AP10Default Authorization Settings - Default User Role Permissions - Allowed to create Apps.HighGeneral
EIDSCA.AP14Default Authorization Settings - Default User Role Permissions - Allowed to read other users.HighGeneral
EIDSCA.AS04Authentication Method - SMS - Use for sign-in.HighGeneral
EIDSCA.AT01Authentication Method - Temporary Access Pass - State.HighGeneral
EIDSCA.AT02Authentication Method - Temporary Access Pass - One-time.HighGeneral
EIDSCA.AV01Authentication Method - Voice call - State.HighGeneral
EIDSCA.CP01Default Settings - Consent Policy Settings - Group owner consent for apps accessing data.HighGeneral
EIDSCA.CP03Default Settings - Consent Policy Settings - Block user consent for risky apps.HighGeneral
EIDSCA.CP04Default Settings - Consent Policy Settings - Users can request admin consent to apps they are unable to consent to.MediumGeneral
EIDSCA.CR01Consent Framework - Admin Consent Request - Policy to enable or disable admin consent request feature.HighGeneral
EIDSCA.CR02Consent Framework - Admin Consent Request - Reviewers will receive email notifications for requests.MediumGeneral
EIDSCA.CR03Consent Framework - Admin Consent Request - Reviewers will receive email notifications when admin consent requests are about to expire.MediumGeneral
EIDSCA.CR04Consent Framework - Admin Consent Request - Consent request duration (days).HighGeneral
EIDSCA.PR01Default Settings - Password Rule Settings - Password Protection - Mode.HighGeneral
EIDSCA.PR02Default Settings - Password Rule Settings - Password Protection - Enable password protection on Windows Server Active Directory.HighGeneral
EIDSCA.PR03Default Settings - Password Rule Settings - Enforce custom list.MediumGeneral
EIDSCA.PR05Default Settings - Password Rule Settings - Smart Lockout - Lockout duration in seconds.MediumGeneral
EIDSCA.PR06Default Settings - Password Rule Settings - Smart Lockout - Lockout threshold.MediumGeneral
EIDSCA.ST08Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to become Group Owner.MediumGeneral
EIDSCA.ST09Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to have access to groups content.MediumGeneral