Entra ID Security Config Analyzer
Microsoft Entra ID security configuration checks maintained by the identity security community with Microsoft endorsement.
Official documentation50
Controls
45
Auto-Remediable
1
Domains
Entra ID(50)
EIDSCA-AF01Authentication Method - FIDO2 security key - State.
EIDSCA-AF02Authentication Method - FIDO2 security key - Allow self-service set up.
EIDSCA-AF03Authentication Method - FIDO2 security key - Enforce attestation.
EIDSCA-AF04Authentication Method - FIDO2 security key - Enforce key restrictions.
EIDSCA-AF05Authentication Method - FIDO2 security key - Restricted.
EIDSCA-AF06Authentication Method - FIDO2 security key - Restrict specific keys.
EIDSCA-AG01Authentication Method - General Settings - Manage migration.
EIDSCA-AG02Authentication Method - General Settings - Report suspicious activity - State.
EIDSCA-AG03Authentication Method - General Settings - Report suspicious activity - Included users/groups.
EIDSCA-AM01Authentication Method - Microsoft Authenticator - State.
EIDSCA-AM02Authentication Method - Microsoft Authenticator - Allow use of Microsoft Authenticator OTP.
EIDSCA-AM03Authentication Method - Microsoft Authenticator - Require number matching for push notifications.
EIDSCA-AM04Authentication Method - Microsoft Authenticator - Included users/groups of number matching for push notifications.
EIDSCA-AM06Authentication Method - Microsoft Authenticator - Show application name in push and passwordless notifications.
EIDSCA-AM07Authentication Method - Microsoft Authenticator - Included users/groups to show application name in push and passwordless notifications.
EIDSCA-AM09Authentication Method - Microsoft Authenticator - Show geographic location in push and passwordless notifications.
EIDSCA-AM10Authentication Method - Microsoft Authenticator - Included users/groups to show geographic location in push and passwordless notifications.
EIDSCA-AP01Microsoft Authenticator enabled
EIDSCA-AP04Authenticator shows application name in notifications
EIDSCA-AP05Authenticator shows geographic location in notifications
EIDSCA-AP06Default Authorization Settings - User can join the tenant by email validation.
EIDSCA-AP07Temporary Access Pass enabled for emergency access
EIDSCA-AP08Default Authorization Settings - User consent policy assigned for applications.
EIDSCA-AP09Email OTP enabled for guest users
EIDSCA-AP10X.509 Certificate-based authentication enabled
EIDSCA-AP11Software OATH tokens authentication method should be disabled
EIDSCA-AP14Authenticator requires number matching for MFA
EIDSCA-AS04Authentication Method - SMS - Disable for sign-in.
EIDSCA-AT01Authentication Method - Temporary Access Pass - State.
EIDSCA-AT02Authentication Method - Temporary Access Pass - One-time.
EIDSCA-AV01Authentication Method - Voice call - State.
EIDSCA-CP01Default Settings - Consent Policy Settings - Group owner consent for apps accessing data.
EIDSCA-CP03Default Settings - Consent Policy Settings - Block user consent for risky apps.
EIDSCA-CP04Default Settings - Consent Policy Settings - Users can request admin consent to apps they are unable to consent to.
EIDSCA-CR01Consent Framework - Admin Consent Request - Policy to enable or disable admin consent request feature.
EIDSCA-CR02Consent Framework - Admin Consent Request - Reviewers will receive email notifications for requests.
EIDSCA-CR03Consent Framework - Admin Consent Request - Reviewers will receive email notifications when admin consent requests are about to expire.
EIDSCA-CR04Consent Framework - Admin Consent Request - Consent request duration (days).
EIDSCA-PR01Block MSOL PowerShell legacy protocol
EIDSCA-PR02Restrict users from registering applications
EIDSCA-PR03Block email-verified users from joining the tenant
EIDSCA-PR04Restrict guest invitations to admins only
EIDSCA-PR05Restrict users from creating security groups
EIDSCA-PR06Users cannot create tenants
EIDSCA-PR07Self-service password reset enabled
EIDSCA-PR08Email-based subscription sign-up disabled
EIDSCA-PR09BitLocker key self-service read restricted
EIDSCA-PR10User consent for risky apps blocked
EIDSCA-ST08Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to become Group Owner.
EIDSCA-ST09Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to have access to groups content.
