STIGQter STIGQter: STIG Summary:

Microsoft Entra ID Security Technical Implementation Guide

Version: 1

Release: 1 Benchmark Date: 28 Feb 2025

CheckedNameTitle
SV-270200r1085610_ruleMicrosoft Entra ID must initiate a session lock after a 15-minute period of inactivity.
SV-270204r1085660_ruleMicrosoft Entra ID must automatically disable accounts after a 35-day period of account inactivity.
SV-270208r1085616_ruleMicrosoft Entra ID must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.
SV-270209r1085618_ruleMicrosoft Entra ID must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the application.
SV-270227r1085728_ruleMicrosoft Entra ID must be configured to transfer logs to another server for storage, analysis, and reporting.
SV-270233r1085634_ruleMicrosoft Entra ID must be configured to use multifactor authentication (MFA).
SV-270239r1085663_ruleMicrosoft Entra ID must enforce a 60-day maximum password lifetime restriction.
SV-270255r1085626_ruleMicrosoft Entra ID must notify system administrators (SAs) and the information system security officer (ISSO) when privileges are being requested.
SV-270335r1085641_ruleMicrosoft Entra ID must use Privileged Identity Management (PIM).
SV-270475r1085680_ruleMicrosoft Entra ID must, for password-based authentication, verify when users create or update passwords that the passwords are not found on the list of commonly used, expected, or compromised passwords.