Automated controls
Expand a control to see the exact population, expectation and defaults. A pass requires usable evidence for the selected population. A known contrary observation can prove failure; missing observations or an empty population must not become a pass.MFA required for active accounts
MFA required for active accounts
- Explanation
- Definition
Each selected account should have MFA registered.Part of Alignr Baseline (seeded).Applies toAccounts observed as enabled.What the result tells youThis checks MFA registration, not effective enforcement at every sign-in. Review policy coverage, allowed methods and emergency exclusions separately.
Privileged roles require MFA
Privileged roles require MFA
- Explanation
- Definition
Each selected account should have MFA registered.Part of Alignr Baseline (seeded).Applies toAccounts observed with the Global Administrator role.What the result tells youThis checks MFA registration, not effective enforcement at every sign-in. Review policy coverage, allowed methods and emergency exclusions separately.
Dormant accounts are disabled
Dormant accounts are disabled
- Explanation
- Definition
Accounts selected by the inactivity filter should be disabled.Part of Alignr Baseline (seeded).Applies toAccounts with an enabled-state observation.Only accounts whose recorded last sign-in is older than the configured inactivity limit are selected.Default settings
Client overrides can change these values. Check the effective settings when interpreting a result.What the result tells youReview the selected account population and its business purpose before acting. An automated disabled-state expectation does not authorise disabling an account.
Conditional access is enforced tenant-wide
Conditional access is enforced tenant-wide
- Explanation
- Definition
Each selected policy should be enabled.Part of Alignr Baseline (seeded).Applies toConditional Access policies observed with an All users scope.What the result tells youThe title is broader than the measured condition: an observed All users policy being enabled does not establish all policy interactions, exclusions or sign-in enforcement.
No MFA bypass in effect
No MFA bypass in effect
- Explanation
- Definition
MFA bypass should be off for each selected account.Part of Alignr Baseline (seeded).Applies toSubjects with a recorded mfa bypass enabled observation.What the result tells youA registered factor and an active bypass can coexist. Review approved emergency access and any temporary exception before changing the account.
MFA on active accounts
MFA on active accounts
- Explanation
- Definition
Each selected account should have MFA registered.Part of BIOS Identity Assurance.Applies toAccounts observed as enabled.What the result tells youThis checks MFA registration, not effective enforcement at every sign-in. Review policy coverage, allowed methods and emergency exclusions separately.
Global Administrators use MFA
Global Administrators use MFA
- Explanation
- Definition
Each selected account should have MFA registered.Part of BIOS Identity Assurance.Applies toAccounts observed with the Global Administrator role.What the result tells youThis checks MFA registration, not effective enforcement at every sign-in. Review policy coverage, allowed methods and emergency exclusions separately.
Manual checks
These are human reviews, not automated evidence. The interval below is the template default; review ownership, evidence and suitability for the client.Review effective conditional access coverage
Review effective conditional access coverage
Review every 90 days · BIOS Identity AssuranceVerify the intended account population is covered by enabled policies, required grant controls and approved emergency exclusions. Review policy interactions and test sign-in enforcement. Registration or an enabled policy alone does not prove MFA enforcement.Record: who performed the review, when it was performed, the evidence, the conclusion and any follow-up or approved exception. A due review is not evidence of a completed review.
Review break-glass account governance
Review break-glass account governance
Review every 90 days · BIOS Identity AssuranceConfirm named emergency accounts, exclusions, monitoring and last access test against the approved policy.Record: who performed the review, when it was performed, the evidence, the conclusion and any follow-up or approved exception. A due review is not evidence of a completed review.
Review OAuth consent governance
Review OAuth consent governance
Review every 90 days · BIOS Identity AssuranceReview consent policy, verified publishers, privileged grants and documented exceptions.Record: who performed the review, when it was performed, the evidence, the conclusion and any follow-up or approved exception. A due review is not evidence of a completed review.