← Strondex

Azure Hardening Checklist

Free preview. You're seeing the first 10 of 88 controls. 88 CIS-based controls for Microsoft Azure — identity to networking to Defender.
Identity (Entra ID / Azure AD) 10 controls
CRITICAL AZ-ID-01 Identity

Require multi-factor authentication for every user.

How to verify / fix

In the Microsoft Entra admin center → Protection → Conditional Access, confirm a policy requires MFA for all users (or enable Security Defaults under Identity → Overview → Properties for small tenants). Check the Authentication methods registration report to find users without MFA registered.

CRITICAL AZ-ID-02 Identity

Enforce MFA on every Global Administrator account.

How to verify / fix

Under Entra → Roles and administrators → Global Administrator, list members, then confirm a Conditional Access policy targeting admin roles requires MFA. Never leave a Global Admin reachable with password alone — these accounts own the tenant.

CRITICAL AZ-ID-03 Identity

Block legacy authentication protocols.

How to verify / fix

Create a Conditional Access policy under Protection → Conditional Access with Client apps = Exchange ActiveSync clients + Other clients and grant Block. Legacy protocols (POP, IMAP, SMTP AUTH, older Office) bypass MFA and are the top vector for password spray. Review the Sign-in logs filtered to legacy clients first to avoid breaking workloads.

HIGH AZ-ID-04 Identity

Assign privileged roles just-in-time through PIM, not permanently.

How to verify / fix

In Entra → Identity Governance → Privileged Identity Management → Microsoft Entra roles, make privileged role holders Eligible rather than Active so they must activate (and re-MFA) for a time-boxed window. Requires Entra ID P2.

HIGH AZ-ID-05 Identity

Keep only 2–4 permanent Global Administrator assignments.

How to verify / fix

In PIM → Microsoft Entra roles → Global Administrator, review Active assignments. Convert extra admins to Eligible and keep just two to four permanent (including break-glass). Too many standing admins widens the breach blast radius.

HIGH AZ-ID-06 Identity

Make admin accounts cloud-only, not synced from on-prem AD.

How to verify / fix

In Entra → Users, filter by On-premises sync enabled = No for accounts holding privileged roles. Adjust Microsoft Entra Connect sync scope to exclude admin OUs so a compromise of on-prem AD can't pivot to cloud admin rights.

HIGH AZ-ID-07 Identity

Maintain documented break-glass accounts excluded from CA policies.

How to verify / fix

Create two cloud-only emergency Global Admin accounts, exclude them from all Conditional Access policies, store credentials offline, and monitor their sign-ins. Set a high-priority alert in Entra → Monitoring → Sign-in logs (or Sentinel) so any use is investigated immediately.

HIGH AZ-ID-08 Identity

Require justification and approval for PIM role activation.

How to verify / fix

In PIM → Microsoft Entra roles → (role) → Role settings, enable Require justification on activation and Require approval to activate, naming approvers. This creates an audit trail and a second pair of eyes for every privilege escalation.

MEDIUM AZ-ID-09 Identity

Run quarterly access reviews on privileged roles.

How to verify / fix

In Entra → Identity Governance → Access reviews, create a recurring (quarterly) review scoped to privileged role assignments, with reviewers required to attest each member is still needed. Auto-remove on denial.

MEDIUM AZ-ID-10 Identity

Run access reviews on guest (external) accounts.

How to verify / fix

Create an Access review targeting Guest users in your directory and groups. Have sponsors confirm continued need; stale B2B guests accumulate access nobody owns. Pair with External collaboration settings review.

78 more controls — unlock the full checklist

The full Azure Hardening Checklist has 88 controls with the interactive self-assessment tool (track Pass / Fail / Partial, see your readiness score, and export a PDF report). One-time purchase, instant access.

Not ready to buy? Try the free Cyber Insurance Readiness Score.