10110010011101001011001101101110101018200.devFrom Enterprise.Systems
免费开始
Azure AD logo

Azure AD

已上线身份与访问

Azure AD 连接器——只读、无代理

Audits your Azure AD (Microsoft Entra ID) directory — MFA coverage and Conditional Access, legacy-auth blocking, privileged-role sprawl (Global Admins, admins without MFA, PIM), over-privileged app identities, guests and external collaboration, Identity Protection risk (at-risk / compromised users), group hygiene, and audit-log retention. Identity-infrastructure posture, read-only — distinct from the Microsoft 365 file/content scan.

我们扫描的内容

  • User, group, and role directory metadata — MFA-registration state, guest vs member, sign-in recency, and privileged-role assignments (never credentials)
  • Conditional Access, external-collaboration and authorization policies, Identity Protection risk state, app (service-principal) role holdings, and audit-log configuration

只读监控——除非您开启自动修复并单独授予写入权限,否则您的 Azure AD 数据中的任何内容都不会发生变更。

安全发现

每次 Azure AD 扫描会运行 22 条检测规则。每条发现都附带通俗易懂的说明、支撑证据以及修复步骤。

  • CRITICALOver permission

    Excessive number of Global Administrators

  • CRITICALOver permission

    Privileged admin account without MFA

  • CRITICALMisconfig

    User with a confirmed account compromise

  • HIGHMisconfig

    Users without multi-factor authentication registered

  • HIGHMisconfig

    User has MFA explicitly disabled

  • HIGHMisconfig

    Legacy (basic) authentication is still allowed

  • HIGHMisconfig

    No Conditional Access policy requires MFA for all users

  • HIGHOver permission

    Excessive number of Privileged Role Administrators

  • HIGHAI agent

    Service principal holds an owner-equivalent directory role

  • HIGHExternal access

    Guest (external) user holds a privileged role

  • HIGHMisconfig

    User flagged at-risk by Identity Protection

  • MEDIUMMisconfig

    No enforced Conditional Access policy exists

  • MEDIUMMisconfig

    Privileged Identity Management is not enabled

  • MEDIUMExternal access

    Guests are allowed to invite other guests

  • MEDIUMExternal access

    Dynamic group silently includes guest members

  • MEDIUMMisconfig

    Microsoft 365 group has public visibility

  • MEDIUMMisconfig

    Audit-log retention is shorter than 30 days

  • MEDIUMMisconfig

    Vendor AI-training data-contribution posture

  • LOWStale access

    Guest account inactive for over 90 days

  • LOWMisconfig

    Group has no owners

  • LOWMisconfig

    No diagnostic settings export the logs

  • LOWMisconfig

    Sign-in logs are unavailable

如何连接 Azure AD

  1. 第 1 步

    注册或登录 8200.dev

  2. 第 2 步

    前往 连接器 → Azure AD

  3. 第 3 步

    点击 连接 并通过 Azure AD 的授权页面进行授权

  4. 第 4 步

    8200.dev 自动扫描——数分钟内即可看到结果

几分钟内接入您的第一个数据源——免费、只读,无需销售沟通。