CSCv7|16.3

Title

Require Multi-factor Authentication

Description

Require multi-factor authentication for all user accounts, on all systems, whether managed onsite or by a third-party provider.

Reference Item Details

Category: Account Monitoring and Control

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1.1 Ensure multifactor authentication is enabled for all users in administrative rolesmicrosoft_azureCIS Microsoft 365 Foundations E3 L1 v1.5.0
1.1.1 Ensure multifactor authentication is enabled for all users in administrative rolesmicrosoft_azureCIS Microsoft 365 Foundations E3 L1 v1.4.0
1.1.1 Ensure multifactor authentication is enabled for all users in administrative rolesmicrosoft_azureCIS Microsoft 365 Foundations E3 L1 v1.3.0
1.1.2 Ensure multifactor authentication is enabled for all users in administrative rolesmicrosoft_azureCIS Microsoft 365 Foundations E3 L1 v2.0.0
1.1.2 Ensure multifactor authentication is enabled for all users in all rolesmicrosoft_azureCIS Microsoft 365 Foundations E3 L2 v1.5.0
1.1.2 Ensure multifactor authentication is enabled for all users in all rolesmicrosoft_azureCIS Microsoft 365 Foundations E3 L2 v1.4.0
1.1.2 Ensure multifactor authentication is enabled for all users in all rolesmicrosoft_azureCIS Microsoft 365 Foundations E3 L2 v1.3.0
1.1.2 Ensure that 'Multi-Factor Auth Status' is 'Enabled' for all Privileged Usersmicrosoft_azureCIS Microsoft Azure Foundations v1.5.0 L1
1.1.2 Ensure that 'Multi-Factor Auth Status' is 'Enabled' for all Privileged Usersmicrosoft_azureCIS Microsoft Azure Foundations v2.0.0 L1
1.1.2 Ensure that 'Multi-Factor Auth Status' is 'Enabled' for all Privileged Usersmicrosoft_azureCIS Microsoft Azure Foundations v2.1.0 L1
1.1.3 Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative usersmicrosoft_azureCIS Microsoft 365 Foundations E3 L1 v2.0.0
1.1.3 Ensure that 'Multi-Factor Auth Status' is 'Enabled' for all Non-Privileged Usersmicrosoft_azureCIS Microsoft Azure Foundations v2.1.0 L2
1.1.3 Ensure that 'Multi-Factor Auth Status' is 'Enabled' for all Non-Privileged Users - List Usersmicrosoft_azureCIS Microsoft Azure Foundations v2.0.0 L2
1.1.3 Ensure that 'Multi-Factor Auth Status' is 'Enabled' for all Non-Privileged Users - List Usersmicrosoft_azureCIS Microsoft Azure Foundations v1.5.0 L2
1.1.3 Ensure that 'Multi-Factor Auth Status' is 'Enabled' for all Non-Privileged Users - Role Assignmentsmicrosoft_azureCIS Microsoft Azure Foundations v1.5.0 L2
1.1.3 Ensure that 'Multi-Factor Auth Status' is 'Enabled' for all Non-Privileged Users - Role Assignmentsmicrosoft_azureCIS Microsoft Azure Foundations v2.0.0 L2
1.1.3 Ensure that 'Multi-Factor Auth Status' is 'Enabled' for all Non-Privileged Users - Role Definitionsmicrosoft_azureCIS Microsoft Azure Foundations v2.0.0 L2
1.1.3 Ensure that 'Multi-Factor Auth Status' is 'Enabled' for all Non-Privileged Users - Role Definitionsmicrosoft_azureCIS Microsoft Azure Foundations v1.5.0 L2
1.1.4 Ensure multifactor authentication is enabled for all usersmicrosoft_azureCIS Microsoft 365 Foundations E3 L1 v2.0.0
1.1.4 Ensure that 'Allow users to remember multi-factor authentication on devices they trust' is Disabledmicrosoft_azureCIS Microsoft Azure Foundations v2.0.0 L1
1.1.4 Ensure that 'Allow users to remember multi-factor authentication on devices they trust' is Disabledmicrosoft_azureCIS Microsoft Azure Foundations v2.1.0 L1
1.1.4 Ensure that 'Restore multi-factor authentication on all remembered devices' is Enabledmicrosoft_azureCIS Microsoft Azure Foundations v1.5.0 L1
1.1.15 Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative users.microsoft_azureCIS Microsoft 365 Foundations E3 L1 v1.4.0
1.1.15 Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative users.microsoft_azureCIS Microsoft 365 Foundations E3 L1 v1.5.0
1.1.16 Ensure the option to remain signed in is hiddenmicrosoft_azureCIS Microsoft 365 Foundations E3 L2 v1.5.0
1.1.16 Ensure the option to stay signed in is disabledmicrosoft_azureCIS Microsoft 365 Foundations E3 L2 v1.4.0
1.1.19 Ensure the option to remain signed in is hiddenmicrosoft_azureCIS Microsoft 365 Foundations E3 L2 v2.0.0
1.2 Ensure modern authentication for Exchange Online is enabledmicrosoft_azureCIS Microsoft 365 Foundations E3 L1 v1.3.0
1.2 Ensure modern authentication for Exchange Online is enabledmicrosoft_azureCIS Microsoft 365 Foundations E3 L1 v1.5.0
1.2 Ensure modern authentication for Exchange Online is enabledmicrosoft_azureCIS Microsoft 365 Foundations E3 L1 v1.4.0
1.2 Ensure modern authentication for Exchange Online is enabledmicrosoft_azureCIS Microsoft 365 Foundations E3 L1 v2.0.0
1.2 Ensure that Multi-Factor Authentication is 'Enabled' for All Non-Service AccountsGCPCIS Google Cloud Platform v1.3.0 L1
1.2 Ensure that Multi-Factor Authentication is 'Enabled' for All Non-Service AccountsGCPCIS Google Cloud Platform v2.0.0 L1
1.2 Ensure that Multi-Factor Authentication is 'Enabled' for All Non-Service AccountsGCPCIS Google Cloud Platform v3.0.0 L1
1.2 Ensure that multi-factor authentication is enabled for all non-privileged users - List Usersmicrosoft_azureCIS Microsoft Azure Foundations v1.3.1 L2
1.2 Ensure that multi-factor authentication is enabled for all non-privileged users - Role Assignmentsmicrosoft_azureCIS Microsoft Azure Foundations v1.3.1 L2
1.2 Ensure that multi-factor authentication is enabled for all non-privileged users - Role Definitionsmicrosoft_azureCIS Microsoft Azure Foundations v1.3.1 L2
1.2 Ensure that multi-factor authentication is enabled for all non-service accountsGCPCIS Google Cloud Platform v1.1.0 L1
1.2.3 Ensure that A Multi-factor Authentication Policy Exists for Administrative Groupsmicrosoft_azureCIS Microsoft Azure Foundations v1.5.0 L1
1.2.3 Ensure that A Multi-factor Authentication Policy Exists for Administrative Groupsmicrosoft_azureCIS Microsoft Azure Foundations v2.0.0 L1
1.2.3 Ensure that A Multi-factor Authentication Policy Exists for Administrative Groupsmicrosoft_azureCIS Microsoft Azure Foundations v2.1.0 L1
1.2.4 Ensure that A Multi-factor Authentication Policy Exists for All Usersmicrosoft_azureCIS Microsoft Azure Foundations v1.5.0 L1
1.2.4 Ensure that A Multi-factor Authentication Policy Exists for All Usersmicrosoft_azureCIS Microsoft Azure Foundations v2.0.0 L1
1.2.4 Ensure that A Multi-factor Authentication Policy Exists for All Usersmicrosoft_azureCIS Microsoft Azure Foundations v2.1.0 L1
1.2.5 Ensure Multi-factor Authentication is Required for Risky Sign-insmicrosoft_azureCIS Microsoft Azure Foundations v2.1.0 L1
1.2.5 Ensure Multi-factor Authentication is Required for Risky Sign-insmicrosoft_azureCIS Microsoft Azure Foundations v2.0.0 L1
1.2.5 Ensure Multi-factor Authentication is Required for Risky Sign-insmicrosoft_azureCIS Microsoft Azure Foundations v1.5.0 L1
1.10 Ensure required packages for multifactor authentication are installedUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
1.10 Ensure required packages for multifactor authentication are installed - escUnixCIS Amazon Linux 2 STIG v1.0.0 L3
1.10 Ensure required packages for multifactor authentication are installed - pam_pkcs11UnixCIS Amazon Linux 2 STIG v1.0.0 L3