Microsoft 365
서비스 중생산성 및 협업Microsoft 365 커넥터 — 읽기 전용, 에이전트리스
Scans SharePoint / OneDrive sharing, inventories Entra (Azure AD) app registrations, service principals and their consented scopes, and audits the tenant security posture (Security Defaults, Conditional Access, MFA coverage, app consent, admin roles).
스캔 대상
- SharePoint / OneDrive file and sharing metadata (never file contents)
- Entra app registrations, service principals, and their consented OAuth scopes
- Tenant security configuration: Security Defaults, Conditional Access, MFA registration, app-consent policy, and privileged role assignments
읽기 전용 모니터링 — 자동 교정을 활성화하고 쓰기 액세스를 별도로 허용하지 않는 한 Microsoft 365 데이터는 변경되지 않습니다.
보안 탐지 항목
26개의 탐지 규칙이 모든 Microsoft 365 스캔 시 실행됩니다. 각 탐지 항목에는 쉬운 언어로 된 설명, 이를 뒷받침하는 증거, 그리고 조치 단계가 함께 제공됩니다.
- CRITICALPublic exposure
Public link with edit/owner access
- CRITICALExternal access
External principal holds ownership
- CRITICALIdentity
A material share of users have not registered for multi-factor authentication
Users who have never registered an MFA method cannot be challenged for a second factor, so any policy requiring MFA silently fails for them. Aim for near-complete registration.
- HIGHPublic exposure
Public link share (link-only)
- HIGHPublic exposure
Public + web-discoverable share
- HIGHExternal access
External access to sensitive data
- HIGHExternal access
External collaborator with edit access
- HIGHOver permission
Sensitive resource editable org-wide
- HIGHOver permission
Broad group access to sensitive data
- HIGHAI agent
Service account with broad write access
- HIGHAI agent
AI agent with access to sensitive data
- HIGHAI agent
AI agent with edit/owner access
- HIGHExternal access
Access granted to a look-alike (typosquat) domain
- HIGHIdentity
Security Defaults are off and no Conditional Access baseline is enforced
A tenant with Security Defaults disabled and no enabled Conditional Access policy has no baseline MFA/identity protection — a single phished password can sign in unchallenged.
- HIGHAccess
Legacy authentication is not blocked
Legacy authentication protocols (IMAP, POP, SMTP AUTH, older Office clients) cannot enforce MFA and are the vector for the majority of password-spray compromises. An enabled Conditional Access policy should block them.
- HIGHAccess
No enabled Conditional Access policy requires multi-factor authentication
Without an enforced policy requiring MFA, users authenticate with a password alone. Report-only and disabled policies do not enforce anything.
- HIGHApplications
Users can consent to third-party apps themselves
When user consent is left enabled, any employee can grant a third-party app (including an AI assistant) access to their mailbox or files with one click — the primary shadow-AI / OAuth-phishing vector. Route consent through an admin review workflow instead.
- MEDIUMOver permission
Broad org-wide edit access (aggregate)
- MEDIUMOver permission
Resource with multiple owners
- MEDIUMStale access
Stale external read access
- MEDIUMStale access
Dormant privileged internal account
- MEDIUMMisconfig
Direct share breaks folder inheritance
- MEDIUMAccess
Anyone in the organization can invite external guests
When every member (not just admins or designated inviters) can invite B2B guests, external identities accumulate without review — a quiet expansion of the access boundary.
- MEDIUMSharing
SharePoint / OneDrive allows anonymous "Anyone" sharing links org-wide
When the tenant external-sharing capability permits "Anyone" links, any user can mint a no-sign-in URL to a document, and that URL leaks data the moment it is forwarded.
- MEDIUMAdmin
More Global Administrators than recommended
Global Administrator is the most powerful role in the tenant. Microsoft recommends keeping it to a small number (around 2–4, with break-glass accounts excluded). Every extra holder is a high-value phishing target with tenant-wide blast radius.
- MEDIUMMisconfig
Vendor AI-training data-contribution posture
Related guide
Microsoft 365 연결 방법
1단계
8200.dev에 가입하거나 로그인하십시오
2단계
커넥터 → Microsoft 365(으)로 이동하십시오
3단계
연결을 클릭하고 Microsoft 365의 동의 화면을 통해 인증하십시오
4단계
8200.dev가 자동으로 스캔합니다 — 결과는 몇 분 내에 표시됩니다
몇 분 안에 첫 번째 소스를 연결하십시오 — 무료, 읽기 전용, 영업 상담 불필요.