Remediation DeploymentEnterprise
Job ID: demo-remediation-0423
Remediation Results
Compliance Score Impact
After runbooks shows the projected score once every generated runbook’s steps have been completed and a subsequent scan has verified the configuration change. Runbook generation alone does not change a control’s status.
Deployment Summary
89
Deployed
2
Runbook Generated
0
Already Compliant
0
Failed
Executive Summary
Download a visual executive report with before/after score comparison, domain breakdown charts, and remediation outcome analysis.
Export Report
Export remediation results as a standalone report. HTML and Markdown include collapsible sections for failed controls. PDF expands all sections.
Control Results (174)
| Control | |
|---|---|
| ✅ | Block legacy authentication protocols CIS-1.1.2medium Report-only — requires enforcementdemo-pol... |
| ✅ | Configure sign-in risk Conditional Access policy CIS-1.2.1medium Report-only — requires enforcementdemo-pol... |
| ✅ | Configure user-risk Conditional Access policy CIS-1.2.2low Report-only — requires enforcementdemo-pol... |
| ✅ | Block legacy auth endpoints at the authentication methods policy EIDSCA-AP03medium Report-only — requires enforcementdemo-pol... |
| ✅ | Block external mail auto-forwarding org-wide CIS-3.3.1low Report-only — requires enforcementdemo-pol... |
| 📄 | Extend Unified Audit Log retention to 12 months CIS-3.1.2low |
| ✅ | Enable Conditional Access for SharePoint access by unmanaged devices CIS-5.4.1low Report-only — requires enforcementdemo-pol... |
| 📄 | Block iCloud keychain sync on corporate iOS devices VT-INTUNE-831low |
| 📄 | Review access privileges via Access Reviews NIST-AC-2.5low |
| ✅ | Require MFA for Global Administrator sign-ins CIS-1.1.10medium Report-only — requires enforcementdemo-pol... |
| ✅ | Require MFA for Exchange Administrator sign-ins CIS-1.1.11low Report-only — requires enforcementdemo-pol... |
| ✅ | Require MFA for SharePoint Administrator sign-ins CIS-1.1.12low Report-only — requires enforcementdemo-pol... |
| 📄 | Require MFA for Teams Administrator sign-ins CIS-1.1.13low |
| 📄 | Require MFA for Compliance Administrator sign-ins CIS-1.1.14low |
| 📄 | Require MFA for Security Administrator sign-ins CIS-1.1.15low |
| ✅ | Enforce Conditional Access for unmanaged devices CIS-1.1.16medium Report-only — requires enforcementdemo-pol... |
| ✅ | Block authentication from anonymous IP ranges CIS-1.1.17low Report-only — requires enforcementdemo-pol... |
| ✅ | Require compliant device for privileged role activation CIS-1.1.18low Report-only — requires enforcementdemo-pol... |
| 📄 | Enforce maximum sign-in frequency for privileged sessions CIS-1.1.19low |
| 📄 | Require password change on high user risk CIS-1.1.20low |
| 📄 | Disable self-service sign-up for guest users CIS-1.1.21low |
| ✅ | Enforce guest user access review cadence CIS-1.3.1medium Report-only — requires enforcementdemo-pol... |
| ✅ | Restrict guest user invitation to specific admin roles CIS-1.3.2low Report-only — requires enforcementdemo-pol... |
| 📄 | Require admin approval for app consent requests CIS-1.3.4low |
| 📄 | Block unmanaged browser access to SharePoint and OneDrive CIS-1.3.5low |
| 📄 | Enforce sign-in session lifetime for browser-based access CIS-1.3.6low |
| ✅ | Block legacy POP3 authentication to mailboxes CIS-1.3.7medium Report-only — requires enforcementdemo-pol... |
| ✅ | Block legacy IMAP authentication to mailboxes CIS-1.3.8low Report-only — requires enforcementdemo-pol... |
| ✅ | Block legacy SMTP AUTH authentication CIS-1.3.9low Report-only — requires enforcementdemo-pol... |
| 📄 | Block authentication attempts from countries not on allowlist CIS-1.3.10low |
| 📄 | Require number matching for Microsoft Authenticator push CIS-1.3.11low |
| 📄 | Disable SMS as a primary authentication method CIS-1.3.12low |
| ✅ | Disable voice call as a primary authentication method CIS-1.3.13medium Report-only — requires enforcementdemo-pol... |
| ✅ | Enforce Authenticator app for passwordless sign-in CIS-1.3.14low Report-only — requires enforcementdemo-pol... |
| ✅ | Enforce FIDO2 security keys for privileged users CIS-1.3.15low Report-only — requires enforcementdemo-pol... |
| 📄 | Require temporary access passes to expire within 24 hours CIS-1.4.2low |
| 📄 | Configure password protection banned-password list CIS-1.4.3low |
| 📄 | Require on-premises password protection agent CIS-1.4.4low |
| ✅ | Enforce authenticator app lockout policy CIS-1.4.5medium Report-only — requires enforcementdemo-pol... |
| ✅ | Configure privileged access workstations for tier-0 admins CIS-1.4.6low Report-only — requires enforcementdemo-pol... |
| ✅ | Require compliant device for admin access to Microsoft 365 admin center CIS-1.4.7low Report-only — requires enforcementdemo-pol... |
| 📄 | Configure named locations for trusted IP ranges CIS-1.4.8low |
| 📄 | Require MFA for external partner tenant access (B2B) CIS-1.4.9low |
| 📄 | Disable cross-tenant inbound B2B invitations by default CIS-1.4.10low |
| ✅ | Enforce persistent browser sessions off for unmanaged devices CIS-1.4.11medium Report-only — requires enforcementdemo-pol... |
| ✅ | Configure Identity Protection weekly digest to Security Operations CIS-1.4.12low Report-only — requires enforcementdemo-pol... |
| ✅ | Investigate every flagged-for-review sign-in within 24 hours CIS-1.4.13low Report-only — requires enforcementdemo-pol... |
| 📄 | Route Identity Protection alerts to the SIEM EIDSCA-AG10low |
| 📄 | Enforce just-in-time access for Exchange Administrator role EIDSCA-AP11low |
| 📄 | Enforce just-in-time access for Global Reader role EIDSCA-AM12low |
| ✅ | Enforce maximum eligible assignment duration for privileged roles EIDSCA-CR13medium Report-only — requires enforcementdemo-pol... |
| ✅ | Require approval workflow for privileged role activation EIDSCA-AF14low Report-only — requires enforcementdemo-pol... |
| ✅ | Notify role administrators on privileged role assignment changes EIDSCA-PS15low Report-only — requires enforcementdemo-pol... |
| 📄 | Require justification for privileged role activation EIDSCA-AG16low |
| 📄 | Configure activation notification recipients for all privileged roles EIDSCA-AP17low |
| 📄 | Require MFA for Global Administrator sign-ins EIDSCA-AM18low |
| ✅ | Require MFA for Exchange Administrator sign-ins EIDSCA-CR19medium Report-only — requires enforcementdemo-pol... |
| ✅ | Require MFA for SharePoint Administrator sign-ins EIDSCA-AF20low Report-only — requires enforcementdemo-pol... |
| ✅ | Require MFA for Teams Administrator sign-ins EIDSCA-PS21low Report-only — requires enforcementdemo-pol... |
| 📄 | Require MFA for Compliance Administrator sign-ins EIDSCA-AG22low |
| 📄 | Require MFA for Security Administrator sign-ins EIDSCA-AP23low |
| 📄 | Enforce Conditional Access for unmanaged devices EIDSCA-AM24low |
| ✅ | Block authentication from anonymous IP ranges EIDSCA-CR25medium Report-only — requires enforcementdemo-pol... |
| ✅ | Require compliant device for privileged role activation EIDSCA-AF26low Report-only — requires enforcementdemo-pol... |
| ✅ | Enforce maximum sign-in frequency for privileged sessions EIDSCA-PS27low Report-only — requires enforcementdemo-pol... |
| 📄 | Disable self-service sign-up for guest users EIDSCA-AP29low |
| 📄 | Enforce guest user access review cadence NIST-IA-2low |
| ✅ | Restrict guest user invitation to specific admin roles NIST-IA-3medium Report-only — requires enforcementdemo-pol... |
| ✅ | Prohibit user consent to unverified publisher apps NIST-IA-4low Report-only — requires enforcementdemo-pol... |
| ✅ | Require admin approval for app consent requests NIST-IA-5low Report-only — requires enforcementdemo-pol... |
| 📄 | Block unmanaged browser access to SharePoint and OneDrive NIST-IA-6low |
| 📄 | Block legacy POP3 authentication to mailboxes NIST-IA-8low |
| ✅ | Block legacy IMAP authentication to mailboxes NIST-IA-9medium Report-only — requires enforcementdemo-pol... |
| ✅ | Block legacy SMTP AUTH authentication NIST-IA-10low Report-only — requires enforcementdemo-pol... |
| 📄 | Require MFA for SharePoint Administrator sign-ins CSF-ID.AM-8low |
| ✅ | Disable self-service sign-up for guest users CISA-AAD.12.3low Report-only — requires enforcementdemo-pol... |
| ✅ | Require device lock password policy on Android CIS-6.8.1low Report-only — requires enforcementdemo-pol... |
| ✅ | Enforce firewall policy on Windows endpoints VT-INTUNE-044medium Report-only — requires enforcementdemo-pol... |
| 📄 | Restrict local administrator accounts on Windows VT-INTUNE-048low |
| 📄 | Restrict cut-copy-paste outside managed apps VT-INTUNE-061low |
| ✅ | Require BitLocker encryption on Windows endpoints VT-INTUNE-APP-ANDROID-MAILlow Report-only — requires enforcementdemo-pol... |
| ✅ | Require FileVault encryption on macOS endpoints VT-INTUNE-APP-MACOS-BROWSERlow Report-only — requires enforcementdemo-pol... |
| ✅ | Require biometric authentication for mobile devices VT-INTUNE-APP-MACOS-MAILmedium Report-only — requires enforcementdemo-pol... |
| ✅ | Block personal OneDrive sync on corporate Windows VT-INTUNE-APP-WINDOWS-BROWSERlow Report-only — requires enforcementdemo-pol... |
| ✅ | Require Windows Update for Business ring assignment VT-INTUNE-APP-ANDROID-OFFICElow Report-only — requires enforcementdemo-pol... |
| ✅ | Block external USB storage on corporate devices VT-INTUNE-COMP-010low Report-only — requires enforcementdemo-pol... |
| 📄 | Deploy Microsoft Edge baseline security profile VT-INTUNE-COMP-013low |
| ✅ | Configure app configuration policy for Edge (managed) VT-INTUNE-CFG-112low Report-only — requires enforcementdemo-pol... |
| 📄 | Block personal iCloud drive on corporate iOS NIST-CM-3low |
| ✅ | Require device lock password policy on Android NIST-CM-11low Report-only — requires enforcementdemo-pol... |
| 📄 | Block personal OneDrive sync on corporate Windows ISO-A.8.22low |
| ✅ | Enforce Microsoft Defender for Endpoint on macOS devices ISO-A.8.25low Report-only — requires enforcementdemo-pol... |
| 📄 | Block external USB storage on corporate devices ISO-A.8.29low |
| ✅ | Deploy Microsoft Edge baseline security profile HIPAA-164.310.1.Alow Report-only — requires enforcementdemo-pol... |
| 📄 | Deploy Office 365 app baseline security profile HIPAA-164.310.2.Blow |
| 📄 | Restrict local administrator accounts on Windows HIPAA-164.310.3.Clow |
| ✅ | Enable mailbox audit logging on all mailboxes CIS-3.2.2low Report-only — requires enforcementdemo-pol... |
| ✅ | Configure mailbox audit actions to log admin and delegate activity CIS-3.2.3low Report-only — requires enforcementdemo-pol... |
| 📄 | Restrict calendar sharing to internal users only CIS-3.3.3low |
| ✅ | Configure SPF hard-fail for all accepted domains CIS-3.4.3low Report-only — requires enforcementdemo-pol... |
| 📄 | Configure DMARC with p=reject for all accepted domains CIS-3.5.1low |
| 📄 | Disable Basic Auth for POP3 at mailbox level CIS-3.5.2low |
| ✅ | Disable EWS (Exchange Web Services) legacy auth CIS-3.6.4low Report-only — requires enforcementdemo-pol... |
| 📄 | Block mail forwarding to external domains by transport rule CIS-3.6.6low |
| ✅ | Require quarantine on detected malware attachments CIS-3.6.9low Report-only — requires enforcementdemo-pol... |
| ✅ | Configure Safe Attachments policy for all recipients CIS-3.6.10low Report-only — requires enforcementdemo-pol... |
| 📄 | Configure Safe Links policy with click-time protection CIS-3.6.11low |
| 📄 | Enable anti-phishing policy with impersonation protection CIS-3.6.12low |
| ✅ | Enable spoofing prevention for hybrid deployments CIS-3.6.14medium Report-only — requires enforcementdemo-pol... |
| 📄 | Enforce litigation hold retention for 365 days minimum CIS-3.7.8low |
| 📄 | Enforce retention policy on Exchange mailboxes CIS-3.7.9low |
| ✅ | Configure mail flow rule to append external-sender banner CIS-3.7.11low Report-only — requires enforcementdemo-pol... |
| ✅ | Restrict external direct-send relay via receive connectors CIS-3.7.12low Report-only — requires enforcementdemo-pol... |
| ✅ | Configure mailbox audit actions to log admin and delegate activity CISA-EXO.1.1medium Report-only — requires enforcementdemo-pol... |
| ✅ | Require MFA for Exchange administrators CISA-EXO.1.2low Report-only — requires enforcementdemo-pol... |
| 📄 | Configure DKIM signing for all accepted domains CISA-EXO.2.3low |
| ✅ | Configure SPF hard-fail for all accepted domains CISA-EXO.3.1medium Report-only — requires enforcementdemo-pol... |
| ✅ | Configure DMARC with p=reject for all accepted domains CISA-EXO.3.2low Report-only — requires enforcementdemo-pol... |
| ✅ | Disable Basic Auth for POP3 at mailbox level CISA-EXO.3.3low Report-only — requires enforcementdemo-pol... |
| 📄 | Disable Basic Auth for SMTP AUTH at mailbox level CISA-EXO.4.2low |
| 📄 | Disable Exchange ActiveSync legacy authentication CISA-EXO.4.3low |
| ✅ | Disable EWS (Exchange Web Services) legacy auth NIST-AU-2medium Report-only — requires enforcementdemo-pol... |
| 📄 | Block automatic mail forwarding at mailbox level NIST-AU-5low |
| ✅ | Configure Safe Attachments policy for all recipients NIST-AU-8medium Report-only — requires enforcementdemo-pol... |
| 📄 | Enable anti-phishing mailbox intelligence NIST-AU-11low |
| 📄 | Block authentication from high-risk IP ranges NIST-SI-3low |
| ✅ | Disable PowerShell remote connections for non-admin mailboxes NIST-SI-4medium Report-only — requires enforcementdemo-pol... |
| ✅ | Restrict mailbox delegation to approved roles NIST-SI-5low Report-only — requires enforcementdemo-pol... |
| ✅ | Restrict external direct-send relay via receive connectors NIST-SI-10medium Report-only — requires enforcementdemo-pol... |
| ✅ | Enable Unified Audit Log tenant-wide ISO-A.8.35low Report-only — requires enforcementdemo-pol... |
| ✅ | Disable anonymous calendar sharing ISO-A.8.39medium Report-only — requires enforcementdemo-pol... |
| ✅ | Disable Basic Auth for POP3 at mailbox level SOC2-CC7.1medium Report-only — requires enforcementdemo-pol... |
| ✅ | Disable Basic Auth for SMTP AUTH at mailbox level SOC2-CC7.3low Report-only — requires enforcementdemo-pol... |
| 📄 | Disable OAB (Offline Address Book) legacy auth SOC2-CC7.6low |
| ✅ | Restrict anti-malware bypass list to approved senders SOC2-CC7.9low Report-only — requires enforcementdemo-pol... |
| ✅ | Require lobby admission for external meeting participants CIS-4.1.3low Report-only — requires enforcementdemo-pol... |
| ✅ | Enable Safe Links scanning in Teams messages CIS-4.3.3low Report-only — requires enforcementdemo-pol... |
| ✅ | Disable Teams guest access tenant-wide when not needed CIS-4.5.2low Report-only — requires enforcementdemo-pol... |
| ✅ | Block screen sharing from anonymous meeting participants CIS-4.5.3low Report-only — requires enforcementdemo-pol... |
| 📄 | Block Teams live events creation to approved producers only CIS-4.5.6low |
| 📄 | Enable DLP policy for Teams chats and channels CIS-4.5.10low |
| 📄 | Configure Teams data residency for in-region tenants CIS-4.6.2low |
| 📄 | Restrict Teams federation to allow-listed domains CIS-4.6.7low |
| ✅ | Disable recording for anonymous meeting participants CIS-4.6.10low Report-only — requires enforcementdemo-pol... |
| ✅ | Restrict recording transcription to organizers and presenters CISA-TEAMS.1.1low Report-only — requires enforcementdemo-pol... |
| 📄 | Block consumer OneDrive access in Teams channels CISA-TEAMS.1.3low |
| 📄 | Restrict guest access to specific team channels CISA-TEAMS.3.3low |
| 📄 | Disable Teams guest access tenant-wide when not needed CISA-TEAMS.4.1low |
| 📄 | Block Teams live events creation to approved producers only ISO-A.5.28low |
| ✅ | Enable communication compliance policy for Teams ISO-A.5.31medium Report-only — requires enforcementdemo-pol... |
| ✅ | Enable DLP policy for Teams chats and channels ISO-A.5.32low Report-only — requires enforcementdemo-pol... |
| 📄 | Configure Teams data residency for in-region tenants ISO-A.5.34low |
| 📄 | Enable anti-phishing impersonation protection for VIPs CIS-2.2.2low |
| 📄 | Configure DKIM alignment enforcement CIS-2.2.3low |
| ✅ | Enable automatic investigation and remediation (AIR) CIS-2.3.3low Report-only — requires enforcementdemo-pol... |
| ✅ | Configure email authentication alert rule to SOC CIS-2.5.2low Report-only — requires enforcementdemo-pol... |
| ✅ | Enable Attack Simulation Training user outcome tracking CIS-2.4.6low Report-only — requires enforcementdemo-pol... |
| 📄 | Configure Explorer search persistent queries for IR CIS-2.4.8low |
| 📄 | Enable Defender for Office 365 Plan 2 AIR investigations CIS-2.4.9low |
| ✅ | Configure spam confidence level thresholds CIS-2.4.11medium Report-only — requires enforcementdemo-pol... |
| ✅ | Enable automated investigation for URL compromises CIS-2.5.4medium Report-only — requires enforcementdemo-pol... |
| ✅ | Configure incident response playbook for mailbox takeover CIS-2.5.5low Report-only — requires enforcementdemo-pol... |
| ✅ | Configure incident response playbook for BEC attempts CIS-2.5.6low Report-only — requires enforcementdemo-pol... |
| ✅ | Enable standard preset security policy for all users CIS-2.5.10medium Report-only — requires enforcementdemo-pol... |
| ✅ | Enable anti-phishing impersonation protection for VIPs CIS-2.5.11low Report-only — requires enforcementdemo-pol... |
| ✅ | Configure DKIM alignment enforcement CIS-2.5.12low Report-only — requires enforcementdemo-pol... |
| ✅ | Enable Defender for Cloud Apps integration with Defender CISA-DEFENDER.2.2low Report-only — requires enforcementdemo-pol... |
| ✅ | Enable Defender for Identity integration with Entra ID CISA-DEFENDER.2.3low Report-only — requires enforcementdemo-pol... |
| 📄 | Configure spam confidence level thresholds NIST-IR-8low |
| 📄 | Enable bulk complaint level (BCL) filtering NIST-IR-9low |
| 📄 | Enable intra-organization spoof protection NIST-IR-10low |
| ✅ | Enable external-sender tagging in Outlook NIST-IR-11medium Report-only — requires enforcementdemo-pol... |
| ✅ | Disable SharePoint App Catalog self-service CIS-5.5.3low Report-only — requires enforcementdemo-pol... |
| ✅ | Require expiration dates on anonymous share links CIS-5.6.9medium Report-only — requires enforcementdemo-pol... |
See a report like this from your own tenant
Connect read-only, watch the same scan run live against your data, and we'll walk through the results together.
