1. Identity and Access Management

Ensure that 'Users can register applications' is set to 'No'
Description: The Users can register applications setting in Microsoft Entra ID controls whether users can create new application registrations. When enable...
Tue, 23 Dec, 2025 at 11:54 AM
1.12 Ensure that 'Guest user permissions are limited' is set to 'Yes'
Description: Limit guest user permissions. Rationale: Limiting guest access ensures that guest accounts do not have permission for certain directory t...
Tue, 21 Sep, 2021 at 3:02 AM
1.13 Ensure that 'Members can invite' is set to 'No'
Description: Azure AD allows you to restrict what external guest users can see in your Azure AD directory. By default, guest users are set to a limited per...
Mon, 20 Sep, 2021 at 3:57 AM
1.14 Ensure that 'Guests can invite' is set to 'No'
Description: Azure AD allows you to restrict what external guest users can see in your Azure AD directory. By default, guest users are set to a limited per...
Mon, 20 Sep, 2021 at 4:08 AM
Ensure that 'Restrict access to Azure AD administration portal' is set to 'Yes'
Description: In Azure Active Directory (Azure AD), all users are granted a set of default permissions. A user’s access consists of the type of user, their ...
Tue, 23 Dec, 2025 at 12:16 PM
Ensure that 'Restrict user ability to access groups features in the Access Pane' is set to 'No'
Description: This setting in Microsoft Entra ID (Azure AD) controls whether non-admin users can access and manage group-related features through the Access...
Tue, 23 Dec, 2025 at 12:20 PM
Ensure that 'Users can create security groups in Azure portals, API or PowerShell' is set to 'No' .
Description: This setting controls whether regular users can create security groups in Microsoft Entra ID. When it is set to No, only administrators c...
Tue, 23 Dec, 2025 at 12:25 PM
Ensure that 'Owners can manage group membership requests in the Access Panel' is set to 'No'
Description: This setting controls whether group owners can approve or deny membership requests in the Access Panel (My Groups). When it is set to No, only...
Tue, 23 Dec, 2025 at 12:32 PM
Ensure that 'Users can create Microsoft 365 groups in Azure portals, API or PowerShell' is set to 'No' .
Description: This setting controls whether regular users can create Microsoft 365 groups. When it is set to No, only administrators can create these groups...
Tue, 23 Dec, 2025 at 12:39 PM
Ensure that 'Require Multi-Factor Authentication to register or join devices with Azure AD' is set to 'Yes'
Description: Requiring multifactor authentication (MFA) to register or join devices with Microsoft Entra ensures that only verified and trusted users can a...
Tue, 23 Dec, 2025 at 12:47 PM