Skillplan M365 Checklist
2026-07-20 19:25
M365
Microsoft 365 Security Checklist
de
en
fr
it
System Online
← Back to sections
Mitigation Controls · Section 12 of 17
Defender for Identity
Assessment Progress
0
/ 136 items
0%
Fulfillment so far
0
/ 0 controls
0%
Explain this control
Install Defender for Identity sensors on every Domain Controller and ADFS server.
Not Fulfilled
Fulfilled
Accepted
Use a Group Managed Service Account (gMSA) for the Directory Service account; do not use a standard user.
Not Fulfilled
Fulfilled
Accepted
Enable Honeytoken decoy accounts for early-warning detection of credential probing.
Not Fulfilled
Fulfilled
Accepted
Configure the 'Suspected DCSync attack' alert to page on-call, not only the dashboard.
Not Fulfilled
Fulfilled
Accepted
Allow the Defender for Identity learning period to run at least 30 days before treating alerts as actionable.
Not Fulfilled
Fulfilled
Accepted
Restrict access to the Defender for Identity portal to a dedicated Tier 0 admin group.
Not Fulfilled
Fulfilled
Accepted
Forward Defender for Identity alerts to the SIEM and the SOC ticketing queue.
Not Fulfilled
Fulfilled
Accepted
Review the Lateral Movement Paths report monthly and remediate exposed administrator paths.
Not Fulfilled
Fulfilled
Accepted
Save and Continue →