Control: 1.20 Ensure that 'Require Multi-Factor Auth to join devices' is set to 'Yes'
Description
Joining devices to the active directory should require Multi-factor authentication.
Multi-factor authentication is recommended when adding devices to Azure AD. When set to Yes
, users who are adding devices from the internet must first use the second method of authentication before their device is successfully added to the directory. This ensures that rogue devices are not added to the directory for a compromised user account
Remediation
From Console
- Log in to Azure Active Directory
- Go to
Devices
in left bar - Go to
Device settings
in left bar - Set
Devices to be Azure AD joined or Azure AD registered require Multi-Factor Authentication
to Yes
Note: By default, Devices to be Azure AD joined or Azure AD registered require Multi-Factor Authentication
is set to No
.
Usage
Run the control in your terminal:
powerpipe control run azure_compliance.control.cis_v130_1_20
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run azure_compliance.control.cis_v130_1_20 --share
SQL
This control uses a named query:
ad_manual_control