Skip to content

Commit df3738d

Browse files
Merge pull request KelvinTegelaar#366 from CyberDrain/dev
fix: dev to hotfix Synced from CyberDrain/CIPP@8bf90d4
1 parent 63a1fcc commit df3738d

92 files changed

Lines changed: 1977 additions & 231 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

Config/BaselineStandards/Defender Standards/AntiPhishPolicy.json

Lines changed: 14 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -4,8 +4,19 @@
44
"cat": "Defender Standards",
55
"tag": [
66
"CIS M365 7.0.0 (2.1.7)",
7-
"mdo_antiphishingpolicy",
8-
"NIST CSF 2.0 (DE.CM-09)"
7+
"NIST CSF 2.0 (DE.CM-09)",
8+
"mdo_antiphishingpolicies",
9+
"mdo_phishthresholdlevel",
10+
"mdo_enablemailboxintelligence",
11+
"mdo_mailboxintelligenceprotection",
12+
"mdo_mailboxintelligenceprotectionaction",
13+
"mdo_targetedusersprotection",
14+
"mdo_enabledomainstoprotect",
15+
"mdo_targeteduserprotectionaction",
16+
"mdo_targeteddomainprotectionaction",
17+
"mdo_similaruserssafetytips",
18+
"mdo_similardomainssafetytips",
19+
"mdo_unusualcharacterssafetytips"
920
],
1021
"impact": "Low Impact",
1122
"helpText": "This creates an Anti-Phishing policy. On tenants without Defender for Office 365 only the settings that exist there are graded; impersonation and mailbox-intelligence protection are skipped.",
@@ -27,7 +38,7 @@
2738
"EXCHANGE_S_ENTERPRISE_GOV",
2839
"EXCHANGE_LITE"
2940
],
30-
"secureScoreImpact": 0,
41+
"secureScoreImpact": 72,
3142
"compare": "subset",
3243
"variables": {
3344
"name": {

Config/BaselineStandards/Defender Standards/AtpPolicyForO365.json

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,9 @@
44
"cat": "Defender Standards",
55
"tag": [
66
"CIS M365 7.0.0 (2.1.5)",
7-
"NIST CSF 2.0 (DE.CM-09)"
7+
"NIST CSF 2.0 (DE.CM-09)",
8+
"mdo_atpprotection",
9+
"mdo_safedocuments"
810
],
911
"impact": "Low Impact",
1012
"helpText": "This creates a Atp policy that enables Defender for Office 365 for SharePoint, OneDrive and Microsoft Teams.",
@@ -36,7 +38,7 @@
3638
"THREAT_INTELLIGENCE_GOV"
3739
]
3840
],
39-
"secureScoreImpact": 0,
41+
"secureScoreImpact": 10,
4042
"compare": "subset",
4143
"variables": {
4244
"AllowSafeDocsOpen": {

Config/BaselineStandards/Defender Standards/DefenderASRPolicy.json

Lines changed: 21 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,26 @@
22
"name": "DefenderASRPolicy",
33
"label": "Defender Attack Surface Reduction Rules",
44
"cat": "Defender Standards",
5-
"tag": [],
5+
"tag": [
6+
"scid_2500",
7+
"scid_2501",
8+
"scid_2502",
9+
"scid_2503",
10+
"scid_2504",
11+
"scid_2505",
12+
"scid_2506",
13+
"scid_2507",
14+
"scid_2508",
15+
"scid_2509",
16+
"scid_2510",
17+
"scid_2511",
18+
"scid_2512",
19+
"scid_2513",
20+
"scid_2514",
21+
"scid_2515",
22+
"scid_2516",
23+
"scid_2517"
24+
],
625
"impact": "High Impact",
726
"helpText": "Deploys and enforces Microsoft Defender Attack Surface Reduction (ASR) rules via Intune. Controls 20 individual ASR rules that protect against common attack vectors.",
827
"executiveText": "Blocks the techniques malware abuses most - obfuscated scripts, Office macro exploitation, credential theft, ransomware behaviour - across every managed device.",
@@ -17,7 +36,7 @@
1736
"warn": false,
1837
"remediate": false
1938
},
20-
"secureScoreImpact": 0,
39+
"secureScoreImpact": 162,
2140
"compare": "subset",
2241
"variables": {
2342
"Mode": {

Config/BaselineStandards/Defender Standards/DefenderAVPolicy.json

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,14 @@
22
"name": "DefenderAVPolicy",
33
"label": "Defender Antivirus Policy",
44
"cat": "Defender Standards",
5-
"tag": [],
5+
"tag": [
6+
"scid_2012",
7+
"scid_2016",
8+
"scid_91",
9+
"scid_92",
10+
"scid_89",
11+
"scid_2011"
12+
],
613
"impact": "High Impact",
714
"helpText": "Deploys and enforces a Microsoft Defender Antivirus configuration policy via Intune. Controls scanning behaviour, real-time protection, cloud protection, network protection, signature updates, CPU priority, and threat remediation actions.",
815
"executiveText": "Ensures every company device runs a consistent, hardened antivirus configuration, protecting against malware while balancing performance.",
@@ -17,7 +24,7 @@
1724
"warn": false,
1825
"remediate": false
1926
},
20-
"secureScoreImpact": 0,
27+
"secureScoreImpact": 50,
2128
"compare": "subset",
2229
"variables": {
2330
"ScanArchives": {

Config/BaselineStandards/Defender Standards/DefenderEDRPolicy.json

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
"name": "DefenderEDRPolicy",
33
"label": "Defender EDR Configuration",
44
"cat": "Defender Standards",
5-
"tag": [],
5+
"tag": [
6+
"scid_20000"
7+
],
68
"impact": "High Impact",
79
"helpText": "Deploys and enforces a Microsoft Defender for Endpoint EDR configuration policy via Intune. Controls auto-configuration from the MDE connector and sample sharing.",
810
"executiveText": "Ensures consistent Endpoint Detection and Response onboarding across managed Windows devices, so security teams see every endpoint.",
@@ -17,7 +19,7 @@
1719
"warn": false,
1820
"remediate": false
1921
},
20-
"secureScoreImpact": 0,
22+
"secureScoreImpact": 9,
2123
"compare": "subset",
2224
"variables": {
2325
"Config": {

Config/BaselineStandards/Defender Standards/EmptyFilterIPAllowList.json

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,8 @@
33
"label": "Ensure connection filter IP allow list is empty",
44
"cat": "Defender Standards",
55
"tag": [
6-
"CIS M365 7.0.0 (2.1.12)"
6+
"CIS M365 7.0.0 (2.1.12)",
7+
"mdo_connectionfilter"
78
],
89
"impact": "Medium Impact",
910
"helpText": "Ensures the connection filter IP allow list is not used. IPs on this list bypass spam, spoof, and authentication checks.",
@@ -25,7 +26,7 @@
2526
"EXCHANGE_S_ENTERPRISE_GOV",
2627
"EXCHANGE_LITE"
2728
],
28-
"secureScoreImpact": 0,
29+
"secureScoreImpact": 1,
2930
"compare": "subset",
3031
"expected": {
3132
"IPAllowList": []

Config/BaselineStandards/Defender Standards/MalwareFilterPolicy.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@
2828
"EXCHANGE_S_ENTERPRISE_GOV",
2929
"EXCHANGE_LITE"
3030
],
31-
"secureScoreImpact": 0,
31+
"secureScoreImpact": 11,
3232
"compare": "subset",
3333
"variables": {
3434
"name": {

Config/BaselineStandards/Defender Standards/SafeAttachmentPolicy.json

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -4,10 +4,9 @@
44
"cat": "Defender Standards",
55
"tag": [
66
"CIS M365 7.0.0 (2.1.4)",
7-
"mdo_safedocuments",
8-
"mdo_commonattachmentsfilter",
97
"mdo_safeattachmentpolicy",
10-
"NIST CSF 2.0 (DE.CM-09)"
8+
"NIST CSF 2.0 (DE.CM-09)",
9+
"mdo_safeattachments"
1110
],
1211
"impact": "Low Impact",
1312
"helpText": "This creates a Safe Attachment policy. An existing policy carrying a legacy CIPP or Microsoft default name is adopted and updated rather than duplicated.",
@@ -40,7 +39,7 @@
4039
"THREAT_INTELLIGENCE_GOV"
4140
]
4241
],
43-
"secureScoreImpact": 0,
42+
"secureScoreImpact": 13,
4443
"compare": "subset",
4544
"variables": {
4645
"name": {

Config/BaselineStandards/Defender Standards/SafeLinksPolicy.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@
3636
"THREAT_INTELLIGENCE_GOV"
3737
]
3838
],
39-
"secureScoreImpact": 0,
39+
"secureScoreImpact": 12,
4040
"compare": "subset",
4141
"variables": {
4242
"name": {

Config/BaselineStandards/Defender Standards/SpamFilterPolicy.json

Lines changed: 10 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -4,8 +4,15 @@
44
"cat": "Defender Standards",
55
"tag": [
66
"CIS M365 7.0.0 (2.1.6)",
7-
"mdo_spamfilterpolicy",
8-
"NIST CSF 2.0 (DE.CM-09)"
7+
"NIST CSF 2.0 (DE.CM-09)",
8+
"mdo_spamaction",
9+
"mdo_highconfidencespamaction",
10+
"mdo_bulkspamaction",
11+
"mdo_phisspamacation",
12+
"mdo_highconfidencephishaction",
13+
"mdo_quarantineretentionperiod",
14+
"mdo_zapspam",
15+
"mdo_zapphish"
916
],
1017
"impact": "Low Impact",
1118
"helpText": "This creates a Spam filter policy. When the adopted policy is the built-in \"Default\", Exchange owns its scoping and no rule is graded or written.",
@@ -27,7 +34,7 @@
2734
"EXCHANGE_S_ENTERPRISE_GOV",
2835
"EXCHANGE_LITE"
2936
],
30-
"secureScoreImpact": 0,
37+
"secureScoreImpact": 28,
3138
"compare": "subset",
3239
"variables": {
3340
"name": {

0 commit comments

Comments
 (0)