Microsoft Entra ID (Azure AD) — SCuBA Security Checklist
15 items · Security · Hard difficulty · 4 hours
Essential Entra ID security tasks to harden your Azure AD configuration.
-
Enable multi-factor authentication for all users
Require MFA for interactive sign-ins and critical roles.
-
Disable legacy authentication protocols
Block basic auth (IMAP, POP, SMTP AUTH, etc.) to reduce credential theft.
-
Enforce Conditional Access policies for sign-ins and device compliance
Require compliant devices and MFA for risky or privileged access.
-
Enable Azure AD Identity Protection
Activate tenant-level risk detection and reporting.
-
Configure sign-in risk and user risk policies
Define actions (require MFA, block) for risk detections.
-
Harden administrative accounts
Apply strict controls and monitoring to privileged identities.
-
Remove unnecessary global administrators
Reduce number of permanent global admins; use least privilege.
-
Enable Privileged Identity Management (PIM) for elevated roles
Require just-in-time elevation and approval for admin roles.
-
Review and restrict application permissions and consent policies
Audit app permissions and block excessive delegated permissions.
-
Enable auditing and logging for sign-ins and directory changes
Stream logs to a SIEM and enable adequate retention.
-
Require device compliance and enroll devices in Intune
Use device compliance policy checks in Conditional Access.
-
Configure password protection and smart lockout
Enforce banned password lists and lockout thresholds.
-
Review external collaboration and guest user settings
Limit guest access scope and require guest MFA where appropriate.
-
Apply cross-tenant access settings for inbound/outbound collaboration
Configure trusted tenant relationships and default restrictions.
-
Monitor Secure Score and implement recommended remediations
Track improvements and prioritize high-impact fixes.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.