Policy: Azure > CIS v5.0 > 5 - Identity Services > 5.01 - Security Defaults (Per-User MFA)
This section covers security recommendations for Microsoft Entra ID Security Defaults and Per-User MFA settings.
Security defaults provide secure default settings that Microsoft manages on behalf of organizations to keep customers safe until they are ready to manage their own identity security settings.
Primary Policy
This policy is used with the following primary policy:
Related Policies
- 5.01.01 - Ensure that 'security defaults' is enabled in Microsoft Entra ID
- 5.01.02 - Ensure that 'multifactor authentication' is 'enabled' for all users
- 5.01.03 - Ensure that 'Allow users to remember multifactor authentication on devices they trust' is disabled
Policy Specification
Schema Type | |
|---|---|
Default | |
Valid Values [YAML] |
|
Examples [YAML] |
|
Category
In Your Workspace
Developers
- tmod:@turbot/cis#/control/categories/cis
- tmod:@turbot/azure-cisv5-0#/policy/types/s0501
- turbot graphql policy-type --id "tmod:@turbot/azure-cisv5-0#/policy/types/s0501"
- turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/azure-cisv5-0#/policy/types/s0501"
Get Policy TypeGet Policy Settings
Category URI
Policy Type URI
GraphQL
CLI