Skillplan M365 Checklist
2026-07-20 19:25
M365
Checklist Sécurité Microsoft 365
de
en
fr
it
Système En ligne
← Retour aux sections
Mesures de mitigation · Section 12 sur 17
Defender for Identity
Progression de l'évaluation
0
/ 136 éléments
0%
Conformité jusqu'à présent
0
/ 0 contrôles
0%
Expliquer ce contrôle
Install Defender for Identity sensors on every Domain Controller and ADFS server.
Non remplie
Remplie
Accepté
Use a Group Managed Service Account (gMSA) for the Directory Service account; do not use a standard user.
Non remplie
Remplie
Accepté
Enable Honeytoken decoy accounts for early-warning detection of credential probing.
Non remplie
Remplie
Accepté
Configure the 'Suspected DCSync attack' alert to page on-call, not only the dashboard.
Non remplie
Remplie
Accepté
Allow the Defender for Identity learning period to run at least 30 days before treating alerts as actionable.
Non remplie
Remplie
Accepté
Restrict access to the Defender for Identity portal to a dedicated Tier 0 admin group.
Non remplie
Remplie
Accepté
Forward Defender for Identity alerts to the SIEM and the SOC ticketing queue.
Non remplie
Remplie
Accepté
Review the Lateral Movement Paths report monthly and remediate exposed administrator paths.
Non remplie
Remplie
Accepté
Enregistrer et continuer →