Skillplan M365 Checklist
2026-07-20 19:32
M365
Checklist Sécurité Microsoft 365
de
en
fr
it
Système En ligne
← Retour aux sections
Mesures de mitigation · Section 2 sur 17
Entra ID — Identity Foundations
Progression de l'évaluation
0
/ 136 éléments
0%
Conformité jusqu'à présent
0
/ 0 contrôles
0%
Expliquer ce contrôle
Block legacy authentication protocols (POP, IMAP, SMTP AUTH, EAS basic) tenant-wide via Conditional Access.
Non remplie
Remplie
Accepté
Enable Entra Password Protection with a custom banned-password list aligned with your organization.
Non remplie
Remplie
Accepté
Require all users to register a strong authentication method (Authenticator, FIDO2, or Windows Hello).
Non remplie
Remplie
Accepté
Disable the 'Stay signed in?' prompt across sign-in branding contexts to reduce token persistence on shared devices.
Non remplie
Remplie
Accepté
Set the password expiration policy aligned with NIST 800-63B (no forced rotation, only on suspicion of compromise).
Non remplie
Remplie
Accepté
Configure tenant restrictions v2 to block sign-ins to external tenants from managed devices.
Non remplie
Remplie
Accepté
Investigate and remediate every 'high' sign-in risk event within 24 hours via Entra ID Protection.
Non remplie
Remplie
Accepté
Disable users' ability to invite external guests unless they hold the Guest Inviter role.
Non remplie
Remplie
Accepté
Enregistrer et continuer →