7.11 Ensure that devices connecting have AV and a local firewall enabled

Information

You should configure your mobile device management policies to require the PC to have anti-virus and have a firewall enabled.

Rationale:

If you do not require this, users will be able to connect from devices that are vulnerable to basic internet attacks, leading to potential breaches of accounts and data.

Impact:

Impact should be minimal however, in the event that a device is not running appropriate protection it will be blocked from connecting.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To set mobile device management policies, use the Microsoft 365 Admin Center:

Under Admin Centers select Endpoint Management.

Select Devices and then select Compliance policies

Select Create Policy

Set a Name for the policy, choose the appropriate PC Platform

Select System Security under Settings.

Under Device Security set the values for Firewall, Antivirus, and Antispyware all to Require.

See Also

https://workbench.cisecurity.org/files/3433