Skillplan M365 Checklist
2026-07-20 19:24
M365
Checklist Sicurezza Microsoft 365
de
en
fr
it
Sistema Online
← Torna alle sezioni
Controlli di mitigazione · Sezione 12 di 17
Defender for Identity
Avanzamento valutazione
0
/ 136 elementi
0%
Conformità finora
0
/ 0 controlli
0%
Spiega questo controllo
Install Defender for Identity sensors on every Domain Controller and ADFS server.
Non soddisfatto
Soddisfatto
Accettato
Use a Group Managed Service Account (gMSA) for the Directory Service account; do not use a standard user.
Non soddisfatto
Soddisfatto
Accettato
Enable Honeytoken decoy accounts for early-warning detection of credential probing.
Non soddisfatto
Soddisfatto
Accettato
Configure the 'Suspected DCSync attack' alert to page on-call, not only the dashboard.
Non soddisfatto
Soddisfatto
Accettato
Allow the Defender for Identity learning period to run at least 30 days before treating alerts as actionable.
Non soddisfatto
Soddisfatto
Accettato
Restrict access to the Defender for Identity portal to a dedicated Tier 0 admin group.
Non soddisfatto
Soddisfatto
Accettato
Forward Defender for Identity alerts to the SIEM and the SOC ticketing queue.
Non soddisfatto
Soddisfatto
Accettato
Review the Lateral Movement Paths report monthly and remediate exposed administrator paths.
Non soddisfatto
Soddisfatto
Accettato
Salva e Continua →