Demo Mode

Every screen, flow, export, and remediation path is the real Veri-Guard product. The specific findings, scores, and runbooks shown are curated to illustrate a typical before/after story. Your tenant scan produces your own numbers.

Get started
← Veri-Guard

Remediation DeploymentEnterprise

Job ID: demo-remediation-0423

succeeded

Remediation Results

Compliance Score Impact

67%
Before
84%
After Remediation
100%
If Runbooks Used
+17.0% improvement

After runbooks shows the projected score once every generated runbook’s steps have been completed and a subsequent scan has verified the configuration change. Runbook generation alone does not change a control’s status.

Deployment Summary

89

Deployed

2

Runbook Generated

0

Already Compliant

0

Failed

Deployed:

Break-glass: [REDACTED]

View source assessment →

Executive Summary

Download a visual executive report with before/after score comparison, domain breakdown charts, and remediation outcome analysis.

Export Report

Export remediation results as a standalone report. HTML and Markdown include collapsible sections for failed controls. PDF expands all sections.

Control Results (174)

||
Control

Block legacy authentication protocols

CIS-1.1.2medium
Report-only — requires enforcementdemo-pol...

Configure sign-in risk Conditional Access policy

CIS-1.2.1medium
Report-only — requires enforcementdemo-pol...

Configure user-risk Conditional Access policy

CIS-1.2.2low
Report-only — requires enforcementdemo-pol...

Block legacy auth endpoints at the authentication methods policy

EIDSCA-AP03medium
Report-only — requires enforcementdemo-pol...

Block external mail auto-forwarding org-wide

CIS-3.3.1low
Report-only — requires enforcementdemo-pol...
📄

Extend Unified Audit Log retention to 12 months

CIS-3.1.2low

Enable Conditional Access for SharePoint access by unmanaged devices

CIS-5.4.1low
Report-only — requires enforcementdemo-pol...
📄

Block iCloud keychain sync on corporate iOS devices

VT-INTUNE-831low
📄

Review access privileges via Access Reviews

NIST-AC-2.5low

Require MFA for Global Administrator sign-ins

CIS-1.1.10medium
Report-only — requires enforcementdemo-pol...

Require MFA for Exchange Administrator sign-ins

CIS-1.1.11low
Report-only — requires enforcementdemo-pol...

Require MFA for SharePoint Administrator sign-ins

CIS-1.1.12low
Report-only — requires enforcementdemo-pol...
📄

Require MFA for Teams Administrator sign-ins

CIS-1.1.13low
📄

Require MFA for Compliance Administrator sign-ins

CIS-1.1.14low
📄

Require MFA for Security Administrator sign-ins

CIS-1.1.15low

Enforce Conditional Access for unmanaged devices

CIS-1.1.16medium
Report-only — requires enforcementdemo-pol...

Block authentication from anonymous IP ranges

CIS-1.1.17low
Report-only — requires enforcementdemo-pol...

Require compliant device for privileged role activation

CIS-1.1.18low
Report-only — requires enforcementdemo-pol...
📄

Enforce maximum sign-in frequency for privileged sessions

CIS-1.1.19low
📄

Require password change on high user risk

CIS-1.1.20low
📄

Disable self-service sign-up for guest users

CIS-1.1.21low

Enforce guest user access review cadence

CIS-1.3.1medium
Report-only — requires enforcementdemo-pol...

Restrict guest user invitation to specific admin roles

CIS-1.3.2low
Report-only — requires enforcementdemo-pol...
📄

Require admin approval for app consent requests

CIS-1.3.4low
📄

Block unmanaged browser access to SharePoint and OneDrive

CIS-1.3.5low
📄

Enforce sign-in session lifetime for browser-based access

CIS-1.3.6low

Block legacy POP3 authentication to mailboxes

CIS-1.3.7medium
Report-only — requires enforcementdemo-pol...

Block legacy IMAP authentication to mailboxes

CIS-1.3.8low
Report-only — requires enforcementdemo-pol...

Block legacy SMTP AUTH authentication

CIS-1.3.9low
Report-only — requires enforcementdemo-pol...
📄

Block authentication attempts from countries not on allowlist

CIS-1.3.10low
📄

Require number matching for Microsoft Authenticator push

CIS-1.3.11low
📄

Disable SMS as a primary authentication method

CIS-1.3.12low

Disable voice call as a primary authentication method

CIS-1.3.13medium
Report-only — requires enforcementdemo-pol...

Enforce Authenticator app for passwordless sign-in

CIS-1.3.14low
Report-only — requires enforcementdemo-pol...

Enforce FIDO2 security keys for privileged users

CIS-1.3.15low
Report-only — requires enforcementdemo-pol...
📄

Require temporary access passes to expire within 24 hours

CIS-1.4.2low
📄

Configure password protection banned-password list

CIS-1.4.3low
📄

Require on-premises password protection agent

CIS-1.4.4low

Enforce authenticator app lockout policy

CIS-1.4.5medium
Report-only — requires enforcementdemo-pol...

Configure privileged access workstations for tier-0 admins

CIS-1.4.6low
Report-only — requires enforcementdemo-pol...

Require compliant device for admin access to Microsoft 365 admin center

CIS-1.4.7low
Report-only — requires enforcementdemo-pol...
📄

Configure named locations for trusted IP ranges

CIS-1.4.8low
📄

Require MFA for external partner tenant access (B2B)

CIS-1.4.9low
📄

Disable cross-tenant inbound B2B invitations by default

CIS-1.4.10low

Enforce persistent browser sessions off for unmanaged devices

CIS-1.4.11medium
Report-only — requires enforcementdemo-pol...

Configure Identity Protection weekly digest to Security Operations

CIS-1.4.12low
Report-only — requires enforcementdemo-pol...

Investigate every flagged-for-review sign-in within 24 hours

CIS-1.4.13low
Report-only — requires enforcementdemo-pol...
📄

Route Identity Protection alerts to the SIEM

EIDSCA-AG10low
📄

Enforce just-in-time access for Exchange Administrator role

EIDSCA-AP11low
📄

Enforce just-in-time access for Global Reader role

EIDSCA-AM12low

Enforce maximum eligible assignment duration for privileged roles

EIDSCA-CR13medium
Report-only — requires enforcementdemo-pol...

Require approval workflow for privileged role activation

EIDSCA-AF14low
Report-only — requires enforcementdemo-pol...

Notify role administrators on privileged role assignment changes

EIDSCA-PS15low
Report-only — requires enforcementdemo-pol...
📄

Require justification for privileged role activation

EIDSCA-AG16low
📄

Configure activation notification recipients for all privileged roles

EIDSCA-AP17low
📄

Require MFA for Global Administrator sign-ins

EIDSCA-AM18low

Require MFA for Exchange Administrator sign-ins

EIDSCA-CR19medium
Report-only — requires enforcementdemo-pol...

Require MFA for SharePoint Administrator sign-ins

EIDSCA-AF20low
Report-only — requires enforcementdemo-pol...

Require MFA for Teams Administrator sign-ins

EIDSCA-PS21low
Report-only — requires enforcementdemo-pol...
📄

Require MFA for Compliance Administrator sign-ins

EIDSCA-AG22low
📄

Require MFA for Security Administrator sign-ins

EIDSCA-AP23low
📄

Enforce Conditional Access for unmanaged devices

EIDSCA-AM24low

Block authentication from anonymous IP ranges

EIDSCA-CR25medium
Report-only — requires enforcementdemo-pol...

Require compliant device for privileged role activation

EIDSCA-AF26low
Report-only — requires enforcementdemo-pol...

Enforce maximum sign-in frequency for privileged sessions

EIDSCA-PS27low
Report-only — requires enforcementdemo-pol...
📄

Disable self-service sign-up for guest users

EIDSCA-AP29low
📄

Enforce guest user access review cadence

NIST-IA-2low

Restrict guest user invitation to specific admin roles

NIST-IA-3medium
Report-only — requires enforcementdemo-pol...

Prohibit user consent to unverified publisher apps

NIST-IA-4low
Report-only — requires enforcementdemo-pol...

Require admin approval for app consent requests

NIST-IA-5low
Report-only — requires enforcementdemo-pol...
📄

Block unmanaged browser access to SharePoint and OneDrive

NIST-IA-6low
📄

Block legacy POP3 authentication to mailboxes

NIST-IA-8low

Block legacy IMAP authentication to mailboxes

NIST-IA-9medium
Report-only — requires enforcementdemo-pol...

Block legacy SMTP AUTH authentication

NIST-IA-10low
Report-only — requires enforcementdemo-pol...
📄

Require MFA for SharePoint Administrator sign-ins

CSF-ID.AM-8low

Disable self-service sign-up for guest users

CISA-AAD.12.3low
Report-only — requires enforcementdemo-pol...

Require device lock password policy on Android

CIS-6.8.1low
Report-only — requires enforcementdemo-pol...

Enforce firewall policy on Windows endpoints

VT-INTUNE-044medium
Report-only — requires enforcementdemo-pol...
📄

Restrict local administrator accounts on Windows

VT-INTUNE-048low
📄

Restrict cut-copy-paste outside managed apps

VT-INTUNE-061low

Require BitLocker encryption on Windows endpoints

VT-INTUNE-APP-ANDROID-MAILlow
Report-only — requires enforcementdemo-pol...

Require FileVault encryption on macOS endpoints

VT-INTUNE-APP-MACOS-BROWSERlow
Report-only — requires enforcementdemo-pol...

Require biometric authentication for mobile devices

VT-INTUNE-APP-MACOS-MAILmedium
Report-only — requires enforcementdemo-pol...

Block personal OneDrive sync on corporate Windows

VT-INTUNE-APP-WINDOWS-BROWSERlow
Report-only — requires enforcementdemo-pol...

Require Windows Update for Business ring assignment

VT-INTUNE-APP-ANDROID-OFFICElow
Report-only — requires enforcementdemo-pol...

Block external USB storage on corporate devices

VT-INTUNE-COMP-010low
Report-only — requires enforcementdemo-pol...
📄

Deploy Microsoft Edge baseline security profile

VT-INTUNE-COMP-013low

Configure app configuration policy for Edge (managed)

VT-INTUNE-CFG-112low
Report-only — requires enforcementdemo-pol...
📄

Block personal iCloud drive on corporate iOS

NIST-CM-3low

Require device lock password policy on Android

NIST-CM-11low
Report-only — requires enforcementdemo-pol...
📄

Block personal OneDrive sync on corporate Windows

ISO-A.8.22low

Enforce Microsoft Defender for Endpoint on macOS devices

ISO-A.8.25low
Report-only — requires enforcementdemo-pol...
📄

Block external USB storage on corporate devices

ISO-A.8.29low

Deploy Microsoft Edge baseline security profile

HIPAA-164.310.1.Alow
Report-only — requires enforcementdemo-pol...
📄

Deploy Office 365 app baseline security profile

HIPAA-164.310.2.Blow
📄

Restrict local administrator accounts on Windows

HIPAA-164.310.3.Clow

Enable mailbox audit logging on all mailboxes

CIS-3.2.2low
Report-only — requires enforcementdemo-pol...

Configure mailbox audit actions to log admin and delegate activity

CIS-3.2.3low
Report-only — requires enforcementdemo-pol...
📄

Restrict calendar sharing to internal users only

CIS-3.3.3low

Configure SPF hard-fail for all accepted domains

CIS-3.4.3low
Report-only — requires enforcementdemo-pol...
📄

Configure DMARC with p=reject for all accepted domains

CIS-3.5.1low
📄

Disable Basic Auth for POP3 at mailbox level

CIS-3.5.2low

Disable EWS (Exchange Web Services) legacy auth

CIS-3.6.4low
Report-only — requires enforcementdemo-pol...
📄

Block mail forwarding to external domains by transport rule

CIS-3.6.6low

Require quarantine on detected malware attachments

CIS-3.6.9low
Report-only — requires enforcementdemo-pol...

Configure Safe Attachments policy for all recipients

CIS-3.6.10low
Report-only — requires enforcementdemo-pol...
📄

Configure Safe Links policy with click-time protection

CIS-3.6.11low
📄

Enable anti-phishing policy with impersonation protection

CIS-3.6.12low

Enable spoofing prevention for hybrid deployments

CIS-3.6.14medium
Report-only — requires enforcementdemo-pol...
📄

Enforce litigation hold retention for 365 days minimum

CIS-3.7.8low
📄

Enforce retention policy on Exchange mailboxes

CIS-3.7.9low

Configure mail flow rule to append external-sender banner

CIS-3.7.11low
Report-only — requires enforcementdemo-pol...

Restrict external direct-send relay via receive connectors

CIS-3.7.12low
Report-only — requires enforcementdemo-pol...

Configure mailbox audit actions to log admin and delegate activity

CISA-EXO.1.1medium
Report-only — requires enforcementdemo-pol...

Require MFA for Exchange administrators

CISA-EXO.1.2low
Report-only — requires enforcementdemo-pol...
📄

Configure DKIM signing for all accepted domains

CISA-EXO.2.3low

Configure SPF hard-fail for all accepted domains

CISA-EXO.3.1medium
Report-only — requires enforcementdemo-pol...

Configure DMARC with p=reject for all accepted domains

CISA-EXO.3.2low
Report-only — requires enforcementdemo-pol...

Disable Basic Auth for POP3 at mailbox level

CISA-EXO.3.3low
Report-only — requires enforcementdemo-pol...
📄

Disable Basic Auth for SMTP AUTH at mailbox level

CISA-EXO.4.2low
📄

Disable Exchange ActiveSync legacy authentication

CISA-EXO.4.3low

Disable EWS (Exchange Web Services) legacy auth

NIST-AU-2medium
Report-only — requires enforcementdemo-pol...
📄

Block automatic mail forwarding at mailbox level

NIST-AU-5low

Configure Safe Attachments policy for all recipients

NIST-AU-8medium
Report-only — requires enforcementdemo-pol...
📄

Enable anti-phishing mailbox intelligence

NIST-AU-11low
📄

Block authentication from high-risk IP ranges

NIST-SI-3low

Disable PowerShell remote connections for non-admin mailboxes

NIST-SI-4medium
Report-only — requires enforcementdemo-pol...

Restrict mailbox delegation to approved roles

NIST-SI-5low
Report-only — requires enforcementdemo-pol...

Restrict external direct-send relay via receive connectors

NIST-SI-10medium
Report-only — requires enforcementdemo-pol...

Enable Unified Audit Log tenant-wide

ISO-A.8.35low
Report-only — requires enforcementdemo-pol...

Disable anonymous calendar sharing

ISO-A.8.39medium
Report-only — requires enforcementdemo-pol...

Disable Basic Auth for POP3 at mailbox level

SOC2-CC7.1medium
Report-only — requires enforcementdemo-pol...

Disable Basic Auth for SMTP AUTH at mailbox level

SOC2-CC7.3low
Report-only — requires enforcementdemo-pol...
📄

Disable OAB (Offline Address Book) legacy auth

SOC2-CC7.6low

Restrict anti-malware bypass list to approved senders

SOC2-CC7.9low
Report-only — requires enforcementdemo-pol...

Require lobby admission for external meeting participants

CIS-4.1.3low
Report-only — requires enforcementdemo-pol...

Enable Safe Links scanning in Teams messages

CIS-4.3.3low
Report-only — requires enforcementdemo-pol...

Disable Teams guest access tenant-wide when not needed

CIS-4.5.2low
Report-only — requires enforcementdemo-pol...

Block screen sharing from anonymous meeting participants

CIS-4.5.3low
Report-only — requires enforcementdemo-pol...
📄

Block Teams live events creation to approved producers only

CIS-4.5.6low
📄

Enable DLP policy for Teams chats and channels

CIS-4.5.10low
📄

Configure Teams data residency for in-region tenants

CIS-4.6.2low
📄

Restrict Teams federation to allow-listed domains

CIS-4.6.7low

Disable recording for anonymous meeting participants

CIS-4.6.10low
Report-only — requires enforcementdemo-pol...

Restrict recording transcription to organizers and presenters

CISA-TEAMS.1.1low
Report-only — requires enforcementdemo-pol...
📄

Block consumer OneDrive access in Teams channels

CISA-TEAMS.1.3low
📄

Restrict guest access to specific team channels

CISA-TEAMS.3.3low
📄

Disable Teams guest access tenant-wide when not needed

CISA-TEAMS.4.1low
📄

Block Teams live events creation to approved producers only

ISO-A.5.28low

Enable communication compliance policy for Teams

ISO-A.5.31medium
Report-only — requires enforcementdemo-pol...

Enable DLP policy for Teams chats and channels

ISO-A.5.32low
Report-only — requires enforcementdemo-pol...
📄

Configure Teams data residency for in-region tenants

ISO-A.5.34low
📄

Enable anti-phishing impersonation protection for VIPs

CIS-2.2.2low
📄

Configure DKIM alignment enforcement

CIS-2.2.3low

Enable automatic investigation and remediation (AIR)

CIS-2.3.3low
Report-only — requires enforcementdemo-pol...

Configure email authentication alert rule to SOC

CIS-2.5.2low
Report-only — requires enforcementdemo-pol...

Enable Attack Simulation Training user outcome tracking

CIS-2.4.6low
Report-only — requires enforcementdemo-pol...
📄

Configure Explorer search persistent queries for IR

CIS-2.4.8low
📄

Enable Defender for Office 365 Plan 2 AIR investigations

CIS-2.4.9low

Configure spam confidence level thresholds

CIS-2.4.11medium
Report-only — requires enforcementdemo-pol...

Enable automated investigation for URL compromises

CIS-2.5.4medium
Report-only — requires enforcementdemo-pol...

Configure incident response playbook for mailbox takeover

CIS-2.5.5low
Report-only — requires enforcementdemo-pol...

Configure incident response playbook for BEC attempts

CIS-2.5.6low
Report-only — requires enforcementdemo-pol...

Enable standard preset security policy for all users

CIS-2.5.10medium
Report-only — requires enforcementdemo-pol...

Enable anti-phishing impersonation protection for VIPs

CIS-2.5.11low
Report-only — requires enforcementdemo-pol...

Configure DKIM alignment enforcement

CIS-2.5.12low
Report-only — requires enforcementdemo-pol...

Enable Defender for Cloud Apps integration with Defender

CISA-DEFENDER.2.2low
Report-only — requires enforcementdemo-pol...

Enable Defender for Identity integration with Entra ID

CISA-DEFENDER.2.3low
Report-only — requires enforcementdemo-pol...
📄

Configure spam confidence level thresholds

NIST-IR-8low
📄

Enable bulk complaint level (BCL) filtering

NIST-IR-9low
📄

Enable intra-organization spoof protection

NIST-IR-10low

Enable external-sender tagging in Outlook

NIST-IR-11medium
Report-only — requires enforcementdemo-pol...

Disable SharePoint App Catalog self-service

CIS-5.5.3low
Report-only — requires enforcementdemo-pol...

Require expiration dates on anonymous share links

CIS-5.6.9medium
Report-only — requires enforcementdemo-pol...

See a report like this from your own tenant

Connect read-only, watch the same scan run live against your data, and we'll walk through the results together.