L2
Enhanced Security Baseline
Organizations with dedicated security teams.
Active enforcement for security-conscious organizations. Adds PIM requirements and stricter controls.
Moderate operational impact, significantly improved security
45
Total Controls
11
Critical
19
Auto-Remediable
20
New at L2
What's Included
- Everything in Level 1
- PIM required for privileged roles
- Phishing-resistant MFA for admins
- Device compliance requirements
- Automated stale account disabling
Not Included (Available at Higher Levels)
- Phishing-resistant MFA for all users
- Hardware key requirements
- Full just-in-time access model
Framework Alignment
CIS Microsoft Entra ID Foundations Benchmark (Level 2)Microsoft Zero TrustNIST 800-63B
Controls Included
Identity & Authentication4 controls
Privileged Access6 controls
Conditional Access10 controls
CA-01Require MFA via Conditional Access Policy
Critical
CA-02Require MFA for All Administrators
Critical
CA-08Block Access from High-Risk Countries
Medium
CA-11Enforce Session Lifetime Limits
High
DV-01Require Compliant Devices for Admin Access
High
CA-03Block or Require MFA for Risky Sign-Ins
High
CA-04Remediate High-Risk Users Automatically
High
CA-10Enable Token Protection
High
DV-02Require Compliant Devices for Global Admins
Critical
CA-05Require App Protection for Mobile Access
High
Workload Identity & Applications8 controls
APP-01Assign Owners to All Applications
Medium
APP-02Enforce Application Credential Expiration
High
APP-05Service Principal Credential Hygiene
Critical
APP-08Restrict User Application Consent
High
APP-03Internal App Registration Permissions
High
APP-04Enable Admin Consent Workflow
Medium
APP-06Third-Party Enterprise App Permissions
High
APP-07Identify Unused Service Principals
Medium
Guest & External Access6 controls
Governance & Hygiene5 controls
Logging & Visibility4 controls
Ready to implement the Enhanced Security baseline?
TrueConfig will scan your Microsoft 365 tenant and show you exactly which controls need attention.