| Checked | Name | Title |
|---|
| ☐ | SV-270200r1085610_rule | Microsoft Entra ID must initiate a session lock after a 15-minute period of inactivity. |
| ☐ | SV-270204r1085660_rule | Microsoft Entra ID must automatically disable accounts after a 35-day period of account inactivity. |
| ☐ | SV-270208r1085616_rule | Microsoft Entra ID must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period. |
| ☐ | SV-270209r1085618_rule | Microsoft Entra ID must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the application. |
| ☐ | SV-270227r1085728_rule | Microsoft Entra ID must be configured to transfer logs to another server for storage, analysis, and reporting. |
| ☐ | SV-270233r1085634_rule | Microsoft Entra ID must be configured to use multifactor authentication (MFA). |
| ☐ | SV-270239r1085663_rule | Microsoft Entra ID must enforce a 60-day maximum password lifetime restriction. |
| ☐ | SV-270255r1085626_rule | Microsoft Entra ID must notify system administrators (SAs) and the information system security officer (ISSO) when privileges are being requested. |
| ☐ | SV-270335r1085641_rule | Microsoft Entra ID must use Privileged Identity Management (PIM). |
| ☐ | SV-270475r1085680_rule | Microsoft Entra ID must, for password-based authentication, verify when users create or update passwords that the passwords are not found on the list of commonly used, expected, or compromised passwords. |