> For the complete documentation index, see [llms.txt](https://helpdesk.augmentt.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://helpdesk.augmentt.com/modules/secure/security-posture/all-posture-checks.md).

# All Posture Checks

This is the full list of individual checks behind [Compliance Audit](/modules/secure/security-posture/compliance-audit.md) and the legacy [Audit](/modules/secure/security-posture/audit-legacy.md) tool — every setting Augmentt evaluates on a connected Microsoft 365 tenant, what it verifies, and (where the check comes from the open-source [Maester](https://maester.dev) project) a link to Maester's own documentation for the deepest level of detail.

{% hint style="info" %}
Check names below match what you'll see in the app; descriptions are written in plain language for this guide rather than reproduced verbatim. For the authoritative wording and current pass/fail logic for any check, open it directly in **Compliance Audit > Audit** — its detail panel's **Overview** tab has the full explanation, and **Instructions** has the manual fix if Augmentt can't remediate it directly.
{% endhint %}

Checks fall into two families:

* **Native checks** — built and maintained by Augmentt directly against the Microsoft Graph and other M365 APIs.
* **Maester-powered checks** — Augmentt runs the open-source [Maester](https://maester.dev) test suite against the tenant and surfaces the results alongside its native checks. Most of these map to a published baseline — Microsoft's own Entra/Exchange recommendations, CISA's SCuBA M365 baseline, or the EIDSCA Entra ID configuration analyzer — and Maester's docs are the canonical reference for exactly what each one does.

## Native checks

### Identity & access

| Check                                                                            | Description                                                                                                                                                        |
| -------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Admin MFA** `adminmfa`                                                         | All accounts with an administrative role have MFA enforced, via Security Defaults, Conditional Access, or per-user MFA/Duo.                                        |
| **User MFA** `usermfa`                                                           | All non-admin user accounts have MFA enforced, using the same set of enforcement methods as Admin MFA.                                                             |
| **Block Legacy Authentication** `blocklegacyauthentication`                      | A policy (Security Defaults or Conditional Access) blocks legacy authentication protocols that don't support MFA.                                                  |
| **MFA Number Matching** `mfanumbermatching`                                      | Number matching is required in Microsoft Authenticator push approvals, preventing MFA-fatigue approval attacks.                                                    |
| **Microsoft MFA Campaign** `mfacampaign`                                         | Microsoft's MFA/SSPR registration campaign is enabled or Microsoft-managed, nudging unregistered users to enroll.                                                  |
| **Self Service Password Reset** `selfservepasswordreset`                         | Self-service password reset (SSPR) is enabled, letting users reset a forgotten or compromised password without an admin.                                           |
| **Risky IP Address Policy** `riskyips`                                           | A Conditional Access policy restricts or blocks sign-in from IP ranges flagged as risky.                                                                           |
| **Risky Country Policy** `riskycountries`                                        | A Conditional Access policy restricts or blocks sign-in from countries the tenant doesn't operate in.                                                              |
| **Temporary Access Pass** `temporaryaccesspass`                                  | Temporary Access Pass is enabled, giving users a time-limited passcode to register passwordless methods or recover account access.                                 |
| **Idle Session Timeout** `activitybasedtimeoutpolicy`                            | An activity-based sign-out policy signs users out of Microsoft 365 web apps after a period of inactivity.                                                          |
| **Entra ID Guest User Access Permissions** `entraIdGuestUserAccessPermissions`   | Guest users' visibility into directory objects, and who can invite guests, are both restricted to what collaboration actually requires.                            |
| **Login Portal Branding** `loginportalbranding`                                  | The Microsoft sign-in page is customized with the organization's logo and background, helping users spot fake login pages.                                         |
| **Connected Apps & User Consent** `connectedappsadminconsent`                    | Only admins — not end users — can consent to third-party application integrations requesting access to tenant data.                                                |
| **PowerShell Access for Non-Admins** `powershellaccessfornonadmins`              | Non-admin users can't run Exchange Online PowerShell against the tenant, closing off a common ransomware/attacker tool.                                            |
| **Inactive Accounts** `inactiveaccounts`                                         | Flags accounts with no sign-in or app activity in the last 30 days, which are prime targets for unauthorized reuse.                                                |
| **Break Glass Accounts** `breakglassaccounts`                                    | At least one emergency-access ("break glass") account is configured and monitored, so admins aren't locked out if MFA or Conditional Access misfires.              |
| **Security Defaults Enabled** `securitydefaultsenabled`                          | Microsoft Security Defaults are turned on for tenants that rely on that baseline instead of custom Conditional Access.                                             |
| **Security Defaults Disabled** `securitydefaultsdisabled`                        | Security Defaults are turned off for tenants that have replaced them with their own Conditional Access policies (the two checks are mutually exclusive by design). |
| **User Owned Apps and Services Restricted** `userownedappsandservicesrestricted` | Users can't install Office Store add-ins or start org-wide app trials without admin oversight.                                                                     |
| **Ensure users cannot create security groups** `AUG.CIS.M365.5.1.3.2`            | Only admins — not standard users — can create Entra ID security groups, which can otherwise open unintended Conditional Access or sharing paths.                   |
| **Per-user MFA disabled** `AUG.CIS.M365.5.1.2.1`                                 | Legacy per-user MFA is turned off tenant-wide in favor of Conditional Access-based MFA, avoiding the inconsistent auth states the two can create together.         |
| **System-preferred multifactor authentication** `AUG.CIS.M365.5.2.3.6`           | System-preferred MFA is enabled so Entra ID prompts each user with their strongest registered method at sign-in, with no exclusions.                               |
| **Ensure the device code sign-in flow is blocked** `AUG.CIS.M365.5.2.2.12`       | Sign-in via the device authorization ("device code") flow is blocked in Conditional Access, closing off a flow that's frequently abused for phishing.              |

### Email & Exchange

| Check                                                                     | Description                                                                                                                                                                |
| ------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Block Sign-in on Shared Mailboxes** `blocksigninsharedmailboxes`        | Every shared mailbox has direct sign-in blocked, since they're rarely monitored and make an attractive target if compromised.                                              |
| **Mailbox Auditing Default** `mailboxaudit`                               | Mailbox audit logging is enabled at the organization level, recording owner, delegate, and admin actions on every mailbox.                                                 |
| **Ensure mailbox audit actions are configured** `AUG.CIS.M365.6.1.2`      | Beyond just being enabled, mailbox auditing is capturing the specific admin, delegate, and owner actions Augmentt expects to see logged.                                   |
| **Exchange External Sender Tag** `externalMailTag`                        | Outlook visibly tags messages from external senders, prompting users to double-check before acting on them.                                                                |
| **DKIM** `dkim`                                                           | DKIM signing is configured for every domain capable of it, helping receiving servers confirm mail wasn't spoofed.                                                          |
| **Modern Authentication for Exchange/Outlook** `enableexchangemodernauth` | Modern authentication is enabled for Exchange Online, allowing Conditional Access and MFA to apply to mail clients instead of legacy basic auth.                           |
| **Unified Audit Log** `unifiedauditlog`                                   | Audit logging is turned on in Microsoft Purview, recording user and admin activity tenant-wide for later investigation.                                                    |
| **MailTips Enabled** `mailtipsenabled`                                    | Exchange Online MailTips are set to the recommended configuration, warning senders before they email large groups or external recipients.                                  |
| **Reject Direct Send** `rejectDirectSend`                                 | Unauthenticated "direct send" mail — messages injected straight into Exchange Online without going through a mail client or connector — is rejected rather than delivered. |
| **Connection Filter IP Allow List** `connectionfilteripallowlist`         | The Exchange connection filter's IP allow list isn't in use, since an allow-listed sender bypasses normal spam filtering entirely.                                         |
| **Connection filter safe list off** `AUG.CIS.M365.2.1.13`                 | The connection filter's safe list — a Microsoft-maintained bypass list — is turned off so its senders still go through normal spam filtering.                              |
| **Comprehensive Attachment Filtering** `comprehensiveattachmentfiltering` | Anti-malware attachment filtering is configured broadly enough to catch the file types attackers commonly weaponize.                                                       |
| **Inbound Anti-Spam Allowed Domains** `inboundantispamalloweddomains`     | No domains are blanket-allow-listed in inbound anti-spam policies, which would let spoofed mail from those domains skip filtering.                                         |
| **Outbound Anti-Spam Message Limits** `outboundantispammessagelimits`     | Outbound message and recipient limits are set to catch a compromised mailbox being used to send spam before it damages the tenant's sending reputation.                    |

### SharePoint & OneDrive

| Check                                                                                   | Description                                                                                                                                                     |
| --------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **SharePoint External/Guest Sharing** `sharepointexternalguestsharing`                  | Default SharePoint external sharing settings require a deliberate choice to share externally, rather than defaulting wide open.                                 |
| **Resharing by External Users** `resharingbyexternalusers`                              | External users who've been shared a file or folder can't reshare it further with others.                                                                        |
| **OneDrive Content Sharing Restricted** `onedrivecontentsharingrestricted`              | OneDrive content can't be shared anonymously or more broadly than the organization allows.                                                                      |
| **SharePoint Site Creation by Standard Users** `sitecreationforstandardusers`           | Standard users can't create new SharePoint sites without going through an admin.                                                                                |
| **Deleted Users OneDrive Retention** `deleteduseronedriveretention`                     | A deleted user's OneDrive content is retained for a full year before permanent deletion, giving time to recover files after offboarding.                        |
| **SharePoint Domain Allowlist** `sharepointdomainallowlist`                             | External sharing is restricted to an explicit list of approved domains rather than left open to any external recipient.                                         |
| **SharePoint Sync Client Restriction** `sharepointsyncclientrestriction`                | Only sync clients joined to the organization's own domains (via the OneDrive sync client's tenant restriction list) are allowed to sync SharePoint content.     |
| **SharePoint Modern Auth Required** `sharepointmodernauthrequired`                      | SharePoint and OneDrive require modern authentication, so legacy protocols can't bypass Conditional Access.                                                     |
| **SharePoint Default Sharing Link Type** `sharepointdefaultsharinglinktype`             | The default sharing link type is set to the most restrictive option (specific people) rather than "Anyone."                                                     |
| **SharePoint Default Link Permission** `sharepointdefaultlinkpermission`                | The default permission on a new sharing link is view-only rather than edit.                                                                                     |
| **SharePoint Guest Expiration** `sharepointguestexpiration`                             | Guest access to SharePoint content automatically expires after a set period instead of persisting indefinitely.                                                 |
| **SharePoint Guest Reauthentication** `sharepointguestreauthentication`                 | Guests must periodically re-verify their identity (via a verification code) to keep accessing shared content.                                                   |
| **SharePoint Azure AD B2B Integration** `sharepointazureadb2bintegration`               | SharePoint's guest sharing is integrated with Entra ID B2B, so guest access is governed by the same identity and Conditional Access controls as internal users. |
| **SharePoint External Sharing Security Group** `sharepointexternalsharingsecuritygroup` | External sharing is limited to members of a designated security group rather than every user in the tenant.                                                     |
| **SharePoint Disallow Infected File Download** `sharepointdisallowinfectedfiledownload` | Files flagged as malware by Defender for Office 365 are blocked from being downloaded out of SharePoint, OneDrive, or Teams.                                    |

### Teams & collaboration

| Check                                                                  | Description                                                                                                                    |
| ---------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------ |
| **Teams Default External/Guest Options** `teamsdefaultexternaloptions` | Teams' external communication and guest access default settings require a deliberate opt-in rather than being open by default. |

### Device, forms & organization settings

| Check                                                                     | Description                                                                                                                                      |
| ------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Intune Enrollment Sign-in Frequency** `intuneenrollmentsigninfrequency` | Users must re-authenticate every time they enroll a device in Intune, rather than relying on a long-lived session token.                         |
| **Forms Phishing Protection Enabled** `formsphishingprotectionenabled`    | Microsoft's built-in phishing detection for Forms is enabled, catching forms designed to harvest personal or sensitive information.              |
| **Contact Settings** `contactsettings`                                    | The tenant has a security contact configured in Microsoft 365 admin settings, so Microsoft can reach someone directly about security advisories. |

## Maester-powered checks

Every row below is a published Maester test that Augmentt runs against the tenant. The **Reference** column links to that test's page on maester.dev, which has the full pass/fail logic, PowerShell source, and remediation guidance — useful when you want more depth than the in-app Instructions tab gives you.

### Maester core tests (MT.\*)

| Check                                                                          | Description                                                                                        | Reference                                              |
| ------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------- | ------------------------------------------------------ |
| **Require Device Compliance** `MT.1001`                                        | At least one Conditional Access policy is configured requiring device compliance.                  | [maester.dev](https://maester.dev/docs/tests/MT.1001/) |
| **Enforce Credential Configurations on Apps and Service Principals** `MT.1002` | App management restrictions are applied to applications and service principals.                    | [maester.dev](https://maester.dev/docs/tests/MT.1002/) |
| **Policy Targeting All Apps** `MT.1003`                                        | A Conditional Access policy is configured targeting All Apps.                                      | [maester.dev](https://maester.dev/docs/tests/MT.1003/) |
| **Policy Targeting All Apps and All Users** `MT.1004`                          | A Conditional Access policy targets All Apps and All Users together.                               | [maester.dev](https://maester.dev/docs/tests/MT.1004/) |
| **Exclude Emergency/Break Glass Account or Group** `MT.1005`                   | Conditional Access policies explicitly exclude emergency/break-glass accounts.                     | [maester.dev](https://maester.dev/docs/tests/MT.1005/) |
| **Require Security Info Registration from a Trusted Location** `MT.1011`       | A Conditional Access policy secures where users can register their MFA/security info from.         | [maester.dev](https://maester.dev/docs/tests/MT.1011/) |
| **Require New Password When User Risk Is High** `MT.1013`                      | A Conditional Access policy forces a password change when a user is flagged high-risk.             | [maester.dev](https://maester.dev/docs/tests/MT.1013/) |
| **Require Compliant or Entra Hybrid Joined Devices for Admins** `MT.1014`      | A Conditional Access policy requires admins to sign in from compliant or hybrid-joined devices.    | [maester.dev](https://maester.dev/docs/tests/MT.1014/) |
| **Block Access for Unknown or Unsupported Device Platforms** `MT.1015`         | A Conditional Access policy blocks sign-in from unrecognized device platforms.                     | [maester.dev](https://maester.dev/docs/tests/MT.1015/) |
| **Enforce Non-Persistent Browser Session for Non-Corporate Devices** `MT.1017` | Browser sessions on non-corporate devices aren't allowed to persist.                               | [maester.dev](https://maester.dev/docs/tests/MT.1017/) |
| **Enforce Sign-in Frequency for Non-Corporate Devices** `MT.1018`              | A Conditional Access policy enforces a sign-in frequency limit for non-corporate devices.          | [maester.dev](https://maester.dev/docs/tests/MT.1018/) |
| **Application Enforced Restrictions for Unmanaged Devices** `MT.1019`          | App-enforced restrictions (like read-only Outlook web access) apply to unmanaged devices.          | [maester.dev](https://maester.dev/docs/tests/MT.1019/) |
| **Directory Sync Accounts & Conditional Access** `MT.1020`                     | Conditional Access policies exclude directory-sync accounts from interactive sign-in requirements. | [maester.dev](https://maester.dev/docs/tests/MT.1020/) |
| **All Users Utilizing an Entra ID P1 License Should Be Licensed** `MT.1022`    | Every user assigned an Entra ID P1 license is actually using it.                                   | [maester.dev](https://maester.dev/docs/tests/MT.1022/) |
| **All Users Utilizing an Entra ID P2 License Should Be Licensed** `MT.1023`    | Every user assigned an Entra ID P2 license is actually using it.                                   | [maester.dev](https://maester.dev/docs/tests/MT.1023/) |
| **Hybrid User Accounts with Permanent High Privileged Roles** `MT.1026`        | No hybrid (on-prem-synced) user holds a permanent Control Plane role assignment.                   | [maester.dev](https://maester.dev/docs/tests/MT.1026/) |
| **Unused Privileged Role Assignments** `MT.1030`                               | Eligible (PIM) role assignments on Control Plane roles are actively in use, not sitting idle.      | [maester.dev](https://maester.dev/docs/tests/MT.1030/) |
| **Privileged Role on Control Plane Are Managed by PIM Only** `MT.1031`         | Privileged Control Plane roles are managed exclusively through PIM, not standing assignments.      | [maester.dev](https://maester.dev/docs/tests/MT.1031/) |

### CISA SCuBA baseline — Microsoft Entra ID (CISA.MS.AAD.\*)

| Check                                                                    | Description                                                                                                                         | Reference                                                      |
| ------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------- |
| **Block High Risk Users** `CISA.MS.AAD.2.1`                              | High-risk users are automatically blocked.                                                                                          | [maester.dev](https://maester.dev/docs/tests/CISA.MS.AAD.2.1/) |
| **Block Risky Sign-ins** `CISA.MS.AAD.2.3`                               | High-risk sign-ins are automatically blocked.                                                                                       | [maester.dev](https://maester.dev/docs/tests/CISA.MS.AAD.2.3/) |
| **Phishing-Resistant MFA** `CISA.MS.AAD.3.1`                             | Phishing-resistant MFA is enforced for all users.                                                                                   | [maester.dev](https://maester.dev/docs/tests/CISA.MS.AAD.3.1/) |
| **Authenticator Login Context Information** `CISA.MS.AAD.3.3`            | Microsoft Authenticator is configured to show sign-in context (app, location) to the user.                                          | [maester.dev](https://maester.dev/docs/tests/CISA.MS.AAD.3.3/) |
| **Disable Weakest 2FA Authenticators** `CISA.MS.AAD.3.5`                 | SMS, voice call, and email one-time-passcode authentication methods are disabled.                                                   | [maester.dev](https://maester.dev/docs/tests/CISA.MS.AAD.3.5/) |
| **Phishing-Resistant MFA for Highly Privileged Roles** `CISA.MS.AAD.3.6` | Phishing-resistant MFA is required for highly privileged roles.                                                                     | [maester.dev](https://maester.dev/docs/tests/CISA.MS.AAD.3.6/) |
| **Authenticate from Managed Devices** `CISA.MS.AAD.3.7`                  | Managed devices are required for authentication.                                                                                    | [maester.dev](https://maester.dev/docs/tests/CISA.MS.AAD.3.7/) |
| **Register MFA from Managed Devices** `CISA.MS.AAD.3.8`                  | Managed devices are required to register MFA.                                                                                       | [maester.dev](https://maester.dev/docs/tests/CISA.MS.AAD.3.8/) |
| **Only Admins Allowed to Register Applications** `CISA.MS.AAD.5.1`       | Only administrators are allowed to register new applications.                                                                       | [maester.dev](https://maester.dev/docs/tests/CISA.MS.AAD.5.1/) |
| **Configure Application Admin Consent Workflow** `CISA.MS.AAD.5.3`       | An admin consent workflow is configured for applications end users can't consent to themselves.                                     | [maester.dev](https://maester.dev/docs/tests/CISA.MS.AAD.5.3/) |
| **Passwords Should Not Expire** `CISA.MS.AAD.6.1`                        | User passwords are set to not expire, in line with current NIST/CISA password guidance.                                             | [maester.dev](https://maester.dev/docs/tests/CISA.MS.AAD.6.1/) |
| **Number of Global Admins** `CISA.MS.AAD.7.1`                            | Between 2 and 8 users are provisioned with the Global Administrator role — enough for redundancy, few enough to limit blast radius. | [maester.dev](https://maester.dev/docs/tests/CISA.MS.AAD.7.1/) |
| **Least Privilege Access** `CISA.MS.AAD.7.2`                             | Privileged users are provisioned with finer-grained roles instead of blanket Global Admin.                                          | [maester.dev](https://maester.dev/docs/tests/CISA.MS.AAD.7.2/) |
| **Hybrid Global Administrators** `CISA.MS.AAD.7.3`                       | Privileged users authenticate with cloud-only accounts, not on-prem-synced ones.                                                    | [maester.dev](https://maester.dev/docs/tests/CISA.MS.AAD.7.3/) |
| **Permanent Highly Privileged Role Assignments** `CISA.MS.AAD.7.4`       | Privileged roles have no permanent (standing) active assignments — everything goes through just-in-time activation.                 | [maester.dev](https://maester.dev/docs/tests/CISA.MS.AAD.7.4/) |
| **Highly Privileged Roles Outside of PAM** `CISA.MS.AAD.7.5`             | Privileged role provisioning goes through a privileged access management (PAM) system.                                              | [maester.dev](https://maester.dev/docs/tests/CISA.MS.AAD.7.5/) |
| **Global Admin Role Activation** `CISA.MS.AAD.7.6`                       | Activating the Global Administrator role requires approval, not just a PIM request.                                                 | [maester.dev](https://maester.dev/docs/tests/CISA.MS.AAD.7.6/) |
| **Guest Access Restrictions** `CISA.MS.AAD.8.1`                          | Guest users have limited visibility into directory objects.                                                                         | [maester.dev](https://maester.dev/docs/tests/CISA.MS.AAD.8.1/) |
| **Guest Invite Settings** `CISA.MS.AAD.8.2`                              | Only users in the Guest Inviter role can invite guest users.                                                                        | [maester.dev](https://maester.dev/docs/tests/CISA.MS.AAD.8.2/) |

### CISA SCuBA baseline — Exchange Online (CISA.MS.EXO.\*)

| Check                                                         | Description                                                                   | Reference                                                       |
| ------------------------------------------------------------- | ----------------------------------------------------------------------------- | --------------------------------------------------------------- |
| **List of Approved Sender IP Addresses** `CISA.MS.EXO.2.1`    | An approved-senders IP address list is maintained for outbound mail.          | [maester.dev](https://maester.dev/docs/tests/CISA.MS.EXO.2.1/)  |
| **SPF Policies** `CISA.MS.EXO.2.2`                            | An SPF policy is published for every domain.                                  | [maester.dev](https://maester.dev/docs/tests/CISA.MS.EXO.2.2/)  |
| **DMARC Policies for Second-Level Domains** `CISA.MS.EXO.4.1` | A DMARC policy is published for every second-level domain.                    | [maester.dev](https://maester.dev/docs/tests/CISA.MS.EXO.4.1/)  |
| **DMARC Message Rejection** `CISA.MS.EXO.4.2`                 | DMARC is set to reject (`p=reject`) rather than just monitor.                 | [maester.dev](https://maester.dev/docs/tests/CISA.MS.EXO.4.2/)  |
| **DMARC Point of Contact** `CISA.MS.EXO.4.3`                  | The DMARC record's point of contact includes CISA's aggregate-report address. | [maester.dev](https://maester.dev/docs/tests/CISA.MS.EXO.4.3/)  |
| **Disable SMTP Auth** `CISA.MS.EXO.5.1`                       | SMTP AUTH (legacy basic auth for sending mail) is disabled tenant-wide.       | [maester.dev](https://maester.dev/docs/tests/CISA.MS.EXO.5.1/)  |
| **Contact Folders Sharing** `CISA.MS.EXO.6.1`                 | Contact folders aren't shared with all domains by default.                    | [maester.dev](https://maester.dev/docs/tests/CISA.MS.EXO.6.1/)  |
| **Calendar Sharing** `CISA.MS.EXO.6.2`                        | Calendar details aren't shared with all domains by default.                   | [maester.dev](https://maester.dev/docs/tests/CISA.MS.EXO.6.2/)  |
| **External Sender Warnings** `CISA.MS.EXO.7.1`                | External sender warnings are implemented in Outlook.                          | [maester.dev](https://maester.dev/docs/tests/CISA.MS.EXO.7.1/)  |
| **Exchange IP Allow List** `CISA.MS.EXO.12.1`                 | Anti-spam IP allow lists aren't in use.                                       | [maester.dev](https://maester.dev/docs/tests/CISA.MS.EXO.12.1/) |
| **Turn Off Safe Lists** `CISA.MS.EXO.12.2`                    | Anti-spam "safe lists" aren't enabled.                                        | [maester.dev](https://maester.dev/docs/tests/CISA.MS.EXO.12.2/) |

### Entra ID Security Config Analyzer (EIDSCA.\*)

| Check                                                                             | Description                                                                                    | Reference                                                  |
| --------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------- |
| **FIDO2 Security Keys** `EIDSCA.AF01`                                             | FIDO2 security key authentication method's enabled/disabled state.                             | [maester.dev](https://maester.dev/docs/tests/EIDSCA.AF01/) |
| **FIDO2 Self-Service Set Up** `EIDSCA.AF02`                                       | Whether self-service setup of FIDO2 security keys is allowed.                                  | [maester.dev](https://maester.dev/docs/tests/EIDSCA.AF02/) |
| **Users Can Report Suspicious Activities** `EIDSCA.AG02`                          | Whether users can report suspicious MFA activity from the sign-in prompt.                      | [maester.dev](https://maester.dev/docs/tests/EIDSCA.AG02/) |
| **Show Application Name in Push and Passwordless Notifications** `EIDSCA.AM06`    | Whether Microsoft Authenticator shows the requesting application's name in push notifications. | [maester.dev](https://maester.dev/docs/tests/EIDSCA.AM06/) |
| **Show Geographic Location in Push and Passwordless Notifications** `EIDSCA.AM09` | Whether Microsoft Authenticator shows the sign-in's geographic location in push notifications. | [maester.dev](https://maester.dev/docs/tests/EIDSCA.AM09/) |
| **Guest User Access** `EIDSCA.AP07`                                               | Guest user access restrictions setting.                                                        | [maester.dev](https://maester.dev/docs/tests/EIDSCA.AP07/) |
| **User Consent Policy for Applications** `EIDSCA.AP08`                            | Which user-consent policy applies to application requests.                                     | [maester.dev](https://maester.dev/docs/tests/EIDSCA.AP08/) |
| **Risk-Based Step-Up Admin Consent for Risky Apps** `EIDSCA.AP09`                 | Whether users can consent to risk-based application requests.                                  | [maester.dev](https://maester.dev/docs/tests/EIDSCA.AP09/) |
| **Users Are Allowed To Create Apps** `EIDSCA.AP10`                                | Whether the default user role permits creating app registrations.                              | [maester.dev](https://maester.dev/docs/tests/EIDSCA.AP10/) |
| **Read User Information from Directory** `EIDSCA.AP14`                            | Whether the default user role permits reading other users' directory information.              | [maester.dev](https://maester.dev/docs/tests/EIDSCA.AP14/) |
| **Limit Temporary Access Pass to One-Time Use** `EIDSCA.AT02`                     | Whether a Temporary Access Pass is restricted to one-time use.                                 | [maester.dev](https://maester.dev/docs/tests/EIDSCA.AT02/) |
| **Disable Voice Call MFA** `EIDSCA.AV01`                                          | Voice call authentication method's enabled/disabled state.                                     | [maester.dev](https://maester.dev/docs/tests/EIDSCA.AV01/) |
| **Block Risky Apps** `EIDSCA.CP03`                                                | Whether user consent is blocked for apps flagged risky.                                        | [maester.dev](https://maester.dev/docs/tests/EIDSCA.CP03/) |
| **Reviewer App Request Notifications** `EIDSCA.CR02`                              | Whether admin consent request email notifications are enabled.                                 | [maester.dev](https://maester.dev/docs/tests/EIDSCA.CR02/) |
| **Reviewer App Request Reminders** `EIDSCA.CR03`                                  | Whether admin consent request expiration notifications are enabled.                            | [maester.dev](https://maester.dev/docs/tests/EIDSCA.CR03/) |
| **App Request Expiry** `EIDSCA.CR04`                                              | How many days an admin consent request stays open before expiring.                             | [maester.dev](https://maester.dev/docs/tests/EIDSCA.CR04/) |
| **Do Not Allow Banned Passwords** `EIDSCA.PR01`                                   | Password Protection's enforcement mode (audit vs. enforce).                                    | [maester.dev](https://maester.dev/docs/tests/EIDSCA.PR01/) |
| **On-Prem Password Protection** `EIDSCA.PR02`                                     | Whether Password Protection is also enabled for on-prem Windows Server AD.                     | [maester.dev](https://maester.dev/docs/tests/EIDSCA.PR02/) |
| **Banned Password List** `EIDSCA.PR03`                                            | Whether a custom banned-password list is enforced.                                             | [maester.dev](https://maester.dev/docs/tests/EIDSCA.PR03/) |
| **Smart Lockout Duration** `EIDSCA.PR05`                                          | Smart Lockout's lockout duration, in seconds.                                                  | [maester.dev](https://maester.dev/docs/tests/EIDSCA.PR05/) |
| **Smart Lockout Threshold** `EIDSCA.PR06`                                         | Smart Lockout's failed-attempt threshold before locking an account out.                        | [maester.dev](https://maester.dev/docs/tests/EIDSCA.PR06/) |

### Augmentt-authored CIS checks (Maester-based, no public reference)

These are custom Maester tests Augmentt wrote in-house to cover specific CIS Microsoft 365 Benchmark controls Maester's public test suite doesn't include. They don't have a maester.dev page, since they aren't part of the open-source project.

| Check                                                                                                                           | Description                                                                                                                                                    |
| ------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Ensure a dynamic group for guest users is created** `AUG.CIS.M365.5.1.3.1`                                                    | A dynamic group automatically includes every guest account, so Conditional Access and other controls scoped to that group extend to new guests automatically.  |
| **Ensure 'Restrict non-admin users from creating tenants' is set to 'Yes'** `AUG.CIS.M365.5.1.2.3`                              | Standard users can't create new Microsoft Entra tenants from the admin portal.                                                                                 |
| **Ensure weak authentication methods are disabled** `AUG.CIS.M365.5.2.3.5`                                                      | Authentication methods considered weak or easily phished are disabled as sign-in options for the tenant.                                                       |
| **Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative users** `AUG.CIS.M365.5.2.2.4` | Sign-in frequency is enabled and browser sessions aren't persistent for administrative users, forcing more frequent re-authentication for privileged sessions. |
| **Ensure 'Idle session timeout' is set to '3 hours (or less)' for unmanaged devices** `AUG.CIS.M365.1.3.2`                      | Idle sessions on unmanaged devices are timed out after 3 hours or less, reducing the window a walked-away, unattended session stays usable.                    |
| **Ensure the customer lockbox feature is enabled** `AUG.CIS.M365.1.3.6`                                                         | Customer Lockbox is turned on, requiring the organization's explicit approval before Microsoft support can access tenant content.                              |

{% hint style="info" %}
This is a first-pass reference covering the checks Augmentt actively evaluates. If you spot a check that's missing or a description that doesn't match what you see in the app, flag it — the app itself (via each check's Overview tab) is always the source of truth for current behavior.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://helpdesk.augmentt.com/modules/secure/security-posture/all-posture-checks.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
