Skip to main content
Version: 2.1.0

Entra ID Security Config Analyzer Tests

These tests are based on the Entra ID Security Config Analyzer and verify Microsoft Entra mitigations for common identity attack scenarios.

Tests​

Test IDTitleSeverityCategory
EIDSCA.AF01Authentication Method - FIDO2 security key - State.HighGeneral
EIDSCA.AF02Authentication Method - FIDO2 security key - Allow self-service set up.MediumGeneral
EIDSCA.AF03Authentication Method - FIDO2 security key - Enforce attestation.HighGeneral
EIDSCA.AF04Authentication Method - FIDO2 security key - Enforce key restrictions.HighGeneral
EIDSCA.AF05Authentication Method - FIDO2 security key - Restricted.HighGeneral
EIDSCA.AF06Authentication Method - FIDO2 security key - Restrict specific keys.MediumGeneral
EIDSCA.AG01Authentication Method - General Settings - Manage migration.HighGeneral
EIDSCA.AG02Authentication Method - General Settings - Report suspicious activity - State.MediumGeneral
EIDSCA.AG03Authentication Method - General Settings - Report suspicious activity - Included users/groups.MediumGeneral
EIDSCA.AM01Authentication Method - Microsoft Authenticator - State.HighGeneral
EIDSCA.AM02Authentication Method - Microsoft Authenticator - Allow use of Microsoft Authenticator OTP.MediumGeneral
EIDSCA.AM03Authentication Method - Microsoft Authenticator - Require number matching for push notifications.MediumGeneral
EIDSCA.AM04Authentication Method - Microsoft Authenticator - Included users/groups of number matching for push notifications.MediumGeneral
EIDSCA.AM06Authentication Method - Microsoft Authenticator - Show application name in push and passwordless notifications.MediumGeneral
EIDSCA.AM07Authentication Method - Microsoft Authenticator - Included users/groups to show application name in push and passwordless notifications.MediumGeneral
EIDSCA.AM09Authentication Method - Microsoft Authenticator - Show geographic location in push and passwordless notifications.MediumGeneral
EIDSCA.AM10Authentication Method - Microsoft Authenticator - Included users/groups to show geographic location in push and passwordless notifications.MediumGeneral
EIDSCA.AP01Default Authorization Settings - Enabled Self service password reset for administrators.HighGeneral
EIDSCA.AP04Default Authorization Settings - Guest invite restrictions.MediumGeneral
EIDSCA.AP05Default Authorization Settings - Sign-up for email based subscription.MediumGeneral
EIDSCA.AP06Default Authorization Settings - User can join the tenant by email validation.MediumGeneral
EIDSCA.AP07Default Authorization Settings - Guest user access.HighGeneral
EIDSCA.AP08Default Authorization Settings - User consent policy assigned for applications.MediumGeneral
EIDSCA.AP09Default Authorization Settings - Allow user consent on risk-based apps.MediumGeneral
EIDSCA.AP10Default Authorization Settings - Default User Role Permissions - Allowed to create Apps.HighGeneral
EIDSCA.AP14Default Authorization Settings - Default User Role Permissions - Allowed to read other users.HighGeneral
EIDSCA.AS04Authentication Method - SMS - Use for sign-in.HighGeneral
EIDSCA.AT01Authentication Method - Temporary Access Pass - State.HighGeneral
EIDSCA.AT02Authentication Method - Temporary Access Pass - One-time.HighGeneral
EIDSCA.AV01Authentication Method - Voice call - State.HighGeneral
EIDSCA.CP01Default Settings - Consent Policy Settings - Group owner consent for apps accessing data.HighGeneral
EIDSCA.CP03Default Settings - Consent Policy Settings - Block user consent for risky apps.HighGeneral
EIDSCA.CP04Default Settings - Consent Policy Settings - Users can request admin consent to apps they are unable to consent to.MediumGeneral
EIDSCA.CR01Consent Framework - Admin Consent Request - Policy to enable or disable admin consent request feature.HighGeneral
EIDSCA.CR02Consent Framework - Admin Consent Request - Reviewers will receive email notifications for requests.MediumGeneral
EIDSCA.CR03Consent Framework - Admin Consent Request - Reviewers will receive email notifications when admin consent requests are about to expire.MediumGeneral
EIDSCA.CR04Consent Framework - Admin Consent Request - Consent request duration (days).HighGeneral
EIDSCA.PR01Default Settings - Password Rule Settings - Password Protection - Mode.HighGeneral
EIDSCA.PR02Default Settings - Password Rule Settings - Password Protection - Enable password protection on Windows Server Active Directory.HighGeneral
EIDSCA.PR03Default Settings - Password Rule Settings - Enforce custom list.MediumGeneral
EIDSCA.PR05Default Settings - Password Rule Settings - Smart Lockout - Lockout duration in seconds.MediumGeneral
EIDSCA.PR06Default Settings - Password Rule Settings - Smart Lockout - Lockout threshold.MediumGeneral
EIDSCA.ST08Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to become Group Owner.MediumGeneral
EIDSCA.ST09Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to have access to groups content.MediumGeneral