10110010011101001011001101101110101018200.devFrom Enterprise.Systems
Azure AD logo

Azure AD

서비스 중ID 및 액세스

Azure AD 커넥터 — 읽기 전용, 에이전트리스

Audits your Azure AD (Microsoft Entra ID) directory — MFA coverage and Conditional Access, legacy-auth blocking, privileged-role sprawl (Global Admins, admins without MFA, PIM), over-privileged app identities, guests and external collaboration, Identity Protection risk (at-risk / compromised users), group hygiene, and audit-log retention. Identity-infrastructure posture, read-only — distinct from the Microsoft 365 file/content scan.

스캔 대상

  • User, group, and role directory metadata — MFA-registration state, guest vs member, sign-in recency, and privileged-role assignments (never credentials)
  • Conditional Access, external-collaboration and authorization policies, Identity Protection risk state, app (service-principal) role holdings, and audit-log configuration

읽기 전용 모니터링 — 자동 교정을 활성화하고 쓰기 액세스를 별도로 허용하지 않는 한 Azure AD 데이터는 변경되지 않습니다.

보안 탐지 항목

22개의 탐지 규칙이 모든 Azure AD 스캔 시 실행됩니다. 각 탐지 항목에는 쉬운 언어로 된 설명, 이를 뒷받침하는 증거, 그리고 조치 단계가 함께 제공됩니다.

  • CRITICALOver permission

    Excessive number of Global Administrators

  • CRITICALOver permission

    Privileged admin account without MFA

  • CRITICALMisconfig

    User with a confirmed account compromise

  • HIGHMisconfig

    Users without multi-factor authentication registered

  • HIGHMisconfig

    User has MFA explicitly disabled

  • HIGHMisconfig

    Legacy (basic) authentication is still allowed

  • HIGHMisconfig

    No Conditional Access policy requires MFA for all users

  • HIGHOver permission

    Excessive number of Privileged Role Administrators

  • HIGHAI agent

    Service principal holds an owner-equivalent directory role

  • HIGHExternal access

    Guest (external) user holds a privileged role

  • HIGHMisconfig

    User flagged at-risk by Identity Protection

  • MEDIUMMisconfig

    No enforced Conditional Access policy exists

  • MEDIUMMisconfig

    Privileged Identity Management is not enabled

  • MEDIUMExternal access

    Guests are allowed to invite other guests

  • MEDIUMExternal access

    Dynamic group silently includes guest members

  • MEDIUMMisconfig

    Microsoft 365 group has public visibility

  • MEDIUMMisconfig

    Audit-log retention is shorter than 30 days

  • MEDIUMMisconfig

    Vendor AI-training data-contribution posture

  • LOWStale access

    Guest account inactive for over 90 days

  • LOWMisconfig

    Group has no owners

  • LOWMisconfig

    No diagnostic settings export the logs

  • LOWMisconfig

    Sign-in logs are unavailable

Azure AD 연결 방법

  1. 1단계

    8200.dev에 가입하거나 로그인하십시오

  2. 2단계

    커넥터 → Azure AD(으)로 이동하십시오

  3. 3단계

    연결을 클릭하고 Azure AD의 동의 화면을 통해 인증하십시오

  4. 4단계

    8200.dev가 자동으로 스캔합니다 — 결과는 몇 분 내에 표시됩니다

몇 분 안에 첫 번째 소스를 연결하십시오 — 무료, 읽기 전용, 영업 상담 불필요.