maester
maester copied to clipboard
No status indication of the M365 platform tests?
As the continuation from this thread: https://github.com/maester365/maester/issues/457
I wonder what I can do to ensure that these checks are executed successfully every day.
Some of the test has the indication when not executed. but not these tests:
As you can see the above, there is no status or even error thrown after the execution.
These tests (without the duplicate:
- EIDSCA.AF02: Authentication Method - FIDO2 security key - Allow self-service set up.
- EIDSCA.AF03: Authentication Method - FIDO2 security key - Enforce attestation.
- EIDSCA.AF04: Authentication Method - FIDO2 security key - Enforce key restrictions.
- EIDSCA.AF05: Authentication Method - FIDO2 security key - Restricted.
- EIDSCA.AF06: Authentication Method - FIDO2 security key - Restrict specific keys.
- EIDSCA.AT02: Authentication Method - Temporary Access Pass - One-time.
- EIDSCA.CP01: Default Settings - Consent Policy Settings - Group owner consent for apps accessing data.
- MS.AAD.4.1: Security logs SHALL be sent to the agency's security operations center for monitoring.
- MS.EXO.1.1: Automatic forwarding to external domains SHALL be disabled.
- MS.EXO.12.1: IP allow lists SHOULD NOT be created.
- MS.EXO.12.2: Safe lists SHOULD NOT be enabled.
- MS.EXO.13.1: Mailbox auditing SHALL be enabled.
- MS.EXO.2.1: A list of approved IP addresses for sending mail SHALL be maintained.
- MS.EXO.2.2: An SPF policy SHALL be published for each domain, designating only these addresses as approved senders.
- MS.EXO.3.1: DKIM SHOULD be enabled for all domains.
- MS.EXO.4.1: A DMARC policy SHALL be published for every second-level domain.
- MS.EXO.4.2: The DMARC message rejection option SHALL be p=reject.
- MS.EXO.4.3: The DMARC point of contact for aggregate reports SHALL include [email protected].
- MS.EXO.5.1: SMTP AUTH SHALL be disabled.
- MS.EXO.6.1: Contact folders SHALL NOT be shared with all domains.
- MS.EXO.6.2: Calendar details SHALL NOT be shared with all domains.
- MS.EXO.7.1: External sender warnings SHALL be implemented.
- MS.EXO.8.1: A DLP solution SHALL be used.
- MT.1002: App management restrictions on applications and service principals is configured and enabled.
- MT.1021: Security Defaults are enabled.