You're viewing a demo with sample data from Contoso Corporation.

Assessment Demo

Security Assessment

55 checks • Score: 72/100

All tiersStarter+
Professional+

Score

72

Passed

33

Failed

14

Warnings

8

Results by Workload

Check IDNameSeverityStatusWorkload
BT.ENTRA.1.1Block Legacy AuthenticationcriticalFailEntra ID
BT.ENTRA.2.1Require MFA for All UserscriticalFailEntra ID
BT.ENTRA.2.3Enforce MFA for Admin RolescriticalFailEntra ID
BT.ENTRA.3.1Limit Global Admin CounthighFailEntra ID
BT.ENTRA.3.2Use PIM for Privileged RoleshighFailEntra ID
BT.ENTRA.4.1Configure Password Expiration PolicymediumPassEntra ID
BT.ENTRA.5.1Enable Self-Service Password ResetlowPassEntra ID
BT.ENTRA.6.1Configure Sign-In Risk PolicyhighWarningEntra ID
BT.ENTRA.6.2Configure User Risk PolicyhighWarningEntra ID
BT.ENTRA.7.1Restrict Guest AccessmediumPassEntra ID
BT.ENTRA.7.2Restrict Guest Invite SettingsmediumPassEntra ID
BT.ENTRA.8.1Restrict App RegistrationmediumPassEntra ID
BT.ENTRA.8.2Require Admin Approval for App ConsenthighPassEntra ID
BT.ENTRA.9.1Maintain Break-Glass AccountshighPassEntra ID
BT.ENTRA.9.2Monitor Break-Glass AccountsmediumWarningEntra ID
BT.EXO.1.1Block Auto-Forwarding to External DomainscriticalPassExchange
BT.EXO.2.1Enable DKIM for All DomainshighPassExchange
BT.EXO.2.2Configure SPF RecordhighPassExchange
BT.EXO.2.3Configure DMARChighWarningExchange
BT.EXO.3.1Enable Audit LoggingmediumPassExchange
BT.EXO.4.1Enable Safe AttachmentshighFailExchange
BT.EXO.4.2Enable Safe LinkshighFailExchange
BT.EXO.5.1Enable External Sender CalloutslowPassExchange
BT.EXO.6.1Configure Anti-Phishing PolicyhighPassExchange
BT.EXO.7.1Block Direct Sign-In for Shared MailboxesmediumFailExchange
BT.EXO.8.1Configure Retention PolicymediumPassExchange
BT.EXO.9.1Restrict OWA File AccesslowWarningExchange
BT.SPO.1.1Manage External SharinghighFailSharePoint
BT.SPO.1.2Default Sharing Links to Company-OnlymediumPassSharePoint
BT.SPO.2.1Configure Guest Sharing ExpirationmediumWarningSharePoint
BT.SPO.3.1Restrict OneDrive Sync to Managed DevicesmediumPassSharePoint
BT.SPO.4.1Configure DLP PolicieshighFailSharePoint
BT.SPO.5.1Enable VersioninglowPassSharePoint
BT.SPO.5.2Restrict Site CreationlowPassSharePoint
BT.SPO.6.1Apply Conditional AccesshighPassSharePoint
BT.SPO.7.1Configure Sensitivity LabelsmediumWarningSharePoint
BT.SPO.8.1Block Legacy Authentication for SharePointhighPassSharePoint
BT.TEAMS.1.1Restrict External AccessmediumPassTeams
BT.TEAMS.1.2Control Guest AccessmediumPassTeams
BT.TEAMS.2.1Enable Meeting LobbymediumFailTeams
BT.TEAMS.2.2Restrict Anonymous Meeting JoinmediumWarningTeams
BT.TEAMS.3.1Manage Third-Party AppsmediumPassTeams
BT.TEAMS.3.2Restrict Custom AppslowPassTeams
BT.TEAMS.4.1Manage Cloud Recording StoragelowPassTeams
BT.TEAMS.5.1Extend DLP Policies to TeamshighFailTeams
BT.TEAMS.6.1Apply Retention Policies to TeamsmediumPassTeams
BT.TEAMS.7.1Evaluate Communication CompliancelowPassTeams
BT.DEF.1.1Enable Unified Audit LogcriticalPassDefender
BT.DEF.2.1Configure Alert PolicieshighPassDefender
BT.DEF.3.1Enable Threat InvestigationmediumPassDefender
BT.DEF.4.1Review Secure Score RecommendationslowPassDefender
BT.DEF.5.1Configure Device Compliance PolicieshighFailDefender
BT.DEF.6.1Require Compliant Devices via Conditional AccesshighFailDefender
BT.DEF.7.1Evaluate Information BarrierslowPassDefender
BT.DEF.8.1Restrict eDiscovery RolesmediumPassDefender