
Microsoft 365 security review
Exempelbolaget AB
Scanned 2026-09-14 09:18 · 31 controls across 6 areas · 20 computers
Summary
The important part of the scan, on one page.
Needs action
out of 100
2
gaps
17
partly in place
7
passing
0
not evaluated
Biggest gaps
Ordered by severity — start at the top.
- 3.3 · MFA and Conditional Access Gap
Legacy authentication blocked
Neither Conditional Access nor security defaults blocks legacy authentication. Where the old mail protocols are still enabled in Exchange they can be used with a password alone, whatever MFA requirements exist elsewhere.
Old mail protocols such as IMAP, POP and SMTP cannot present a second factor. As long as they are open there is a way past every MFA policy in the environment — Microsoft reports that over 97 per cent of all password attacks use them.
- 1.4 · Identity and admins Gap
Administrators without registered MFA
2 of 7 administrators have no registered MFA method, and no policy requires MFA for administrators.
An administrator who signs in with a password alone is one phishing email away from the whole environment being taken over. Admin accounts are the most attractive target in a tenant.
- 3.1 · MFA and Conditional Access Partial
MFA enforced for all users
MFA is required for all users, but the policy exempts one or more groups. Securenix cannot see how many people that covers — check the group members by hand.
Without enforced multi-factor authentication a stolen password is enough to sign in as anyone in the organisation. Passwords leak in breaches at completely unrelated services and are then tried systematically against Microsoft 365.
- 3.2 · MFA and Conditional Access Partial
MFA enforced for administrators
MFA is required for administrators, but the policy exempts one or more groups. Check the group members by hand.
An administrator account without enforced MFA is the shortest path to the whole environment. Whoever gets the password can read all mail, add their own accounts and lock the organisation out of its own environment.
- 5.3 · Domains and email security Partial
DMARC policy for the organisation's domains
exempelbolaget.se has DMARC with p=none. Mail is monitored but nothing is stopped — forged mail is still delivered.
DMARC is what tells the recipient what to do with mail that fails SPF or DKIM. Without a policy that rejects or quarantines, forged mail in the organisation's name is delivered — which is how most invoice fraud begins.
- 3.5 · MFA and Conditional Access Partial
Users without a registered MFA method
38 of 457 reviewed licensed accounts (8 %) have no usable MFA method and are protected by their password alone.
An account without a usable MFA method is protected by its password alone. Those are also the accounts that lock themselves out the day an MFA requirement is switched on.
+12 more in the list below
Top on-premises risks
Servers and Active Directory on site. Each row covers every computer the same problem was found on.
- AD-PRV-001 · 1 computers Gap
Many Domain or Enterprise Admins
Every extra account with full control of the domain is another route an attacker or an insider can take to everything.
- AD-PWD-001 · 1 computers Gap
Weak minimum password length
Short passwords are cracked quickly once a hash is obtained.
- SRV-EOL-001 · 2 computers Gap
End-of-life software installed
No security fixes; a frequent audit and cyber-insurance finding.
- SRV-EPP-001 · 1 computers Gap
Endpoint protection not active
The server is unprotected against malware and ransomware.
- SRV-FW-001 · 2 computers Gap
Firewall profile disabled
Increases exposure during network consolidation and change.
- SRV-PATCH-001 · 4 computers Gap
No recent updates installed
Unpatched systems increase cyber, compliance and deal-execution risk.
+19 more in the list below
This is in place
Controls and areas with nothing against them.
- Identity and admins
Number of Global Administrators
4 Global Administrators, which is within the recommended range of 2–4.
- Intune and device management
Intune is used for device management
420 devices are managed by Intune.
- Intune and device management
Compliance policies exist and are assigned
Each of the 3 platforms with enrolled devices has at least one assigned compliance policy.
- MFA and Conditional Access
Legacy authentication used in the last 30 days
No successful interactive sign-ins with legacy protocols in the last 30 days.
- Domains and email security
DKIM selectors for the organisation's domains
exempelbolaget.se publishes both DKIM selectors. Check in Microsoft 365 that signing is switched on for the domain as well.
- Domains and email security
DMARC reporting addresses
exempelbolaget.se sends DMARC reports to a specified address.
+1 more in the list below
Area overview
Where each control area stands. The detail follows in the same order.
- Identity and admins
501 Gap 3 Partial 1 Good 1 Information
- Secure Score
501 Partial 1 Information
- MFA and Conditional Access
461 Gap 3 Partial 1 Good 1 Information
- Domains and email security
653 Partial 2 Good
- Intune and device management
754 Partial 3 Good
- Quick checks
503 Partial 2 Information
- On-premises servers and Active Directory
25 findings across 20 computers59
All controls
Every control in the catalogue, area by area.
Identity and admins
50 % of the area
- Gap
Administrators without registered MFA
Critical 1.42 of 7 administrators have no registered MFA method, and no policy requires MFA for administrators.
Business risk
An administrator who signs in with a password alone is one phishing email away from the whole environment being taken over. Admin accounts are the most attractive target in a tenant.
Recommendation
Require multi-factor authentication for every admin role, preferably with a phishing-resistant method, and make sure every administrator has registered one.
- Partial
Dedicated admin accounts
High 1.62 of 4 Global Administrators sit on accounts that are not named as admin accounts — most likely everyday work accounts.
Business risk
An account that both holds full control of the tenant and is used for email and web browsing can be taken over by a single successful phishing mail. The attacker then controls the whole Microsoft 365 environment: users, mailboxes, files and security settings.
Recommendation
Put Global Administrator on separate admin accounts that are named as such (for example admin-firstname), and remove the role from the everyday work accounts. Day-to-day work happens in the personal account, administration in the admin account.
- Partial
Privileged Identity Management (PIM)
Medium 1.3The tenant has no Entra ID P2 licence and therefore cannot use PIM. This is a licensing question, not a misconfiguration.
This is a licence gap, not a misconfiguration.
Business risk
Permanent admin rights mean a hijacked account is an administrator around the clock. With PIM the privilege is activated only when it is needed, for a limited time and with an audit trail.
Recommendation
Move the admin roles into PIM as eligible rather than permanent assignments, with approval and a time limit. Requires Entra ID P2.
- Partial
Break-glass account
Information 1.5No emergency account could be identified automatically. Check by hand whether one exists.
Business risk
If Conditional Access, the MFA service or directory synchronisation stops working, every administrator can be locked out. An emergency account is then the only way back into the environment.
Recommendation
Make sure at least one cloud-only emergency Global Administrator account exists, excluded from Conditional Access, with a long password stored securely and a documented routine for how it is used and reviewed.
- Information
Administrator roles and who holds them
Information 1.24 administrator roles have members assigned, 4 of them highly privileged.
-
Global Administrator — 4 permanent, 0 via PIM
Maria Karlsson (maria.karlsson@exempelbolaget.se), Anna Andersson (admin) (adm.anna.andersson@exempelbolaget.se), Johan Nilsson (johan.nilsson@exempelbolaget.se), Erik Johansson (admin) (adm.erik.johansson@exempelbolaget.se)
-
Exchange Administrator — 1 permanent, 0 via PIM
Karin Eriksson (karin.eriksson@exempelbolaget.se)
-
Intune Administrator — 1 permanent, 0 via PIM
Sara Olsson (sara.olsson@exempelbolaget.se)
-
SharePoint Administrator — 1 permanent, 0 via PIM
Lars Larsson (lars.larsson@exempelbolaget.se)
-
Checks with no issues
- 1.1 Number of Global Administrators — 4 Global Administrators, which is within the recommended range of 2–4. Good
Secure Score
50 % of the area
- Partial
Microsoft Secure Score
High 2.1Secure Score is 48 % of the attainable maximum (312 of 650 points), calculated on 2026-09-13. A meaningful part of the recommended protection is left unused.
Business risk
Secure Score summarises how much of the protection Microsoft recommends for this tenant is actually switched on. A low score means known attacks — password spraying, mailbox forwarding rules, consent phishing — meet defences that are not there.
Recommendation
Work through the improvement actions with the largest score potential first; those are the ones Microsoft weights highest for this tenant. Aim for at least 65 % of the attainable maximum.
- Information
Largest improvement actions in Secure Score
Information 2.2The actions with the largest score potential are worth 57 points together, out of the 338 points Microsoft still has available for this tenant. The title and description below are Microsoft's own wording, taken from Secure Score in the tenant.
-
Block legacy authentication — 15 points to gain
Create a Conditional Access policy blocking legacy authentication clients.
-
Use separate accounts for administration — 12 points to gain
Give each administrator a cloud-only account used only for administration.
-
Enable attack surface reduction rules — 11 points to gain
Deploy the recommended ASR rules to every managed Windows device.
-
Set up an anti-phishing policy — 10 points to gain
Turn on mailbox intelligence and impersonation protection.
-
Set up DMARC records for all domains — 9 points to gain
Publish a DMARC record and move it from p=none to p=quarantine.
-
MFA and Conditional Access
46 % of the area
- Gap
Legacy authentication blocked
Critical 3.3Neither Conditional Access nor security defaults blocks legacy authentication. Where the old mail protocols are still enabled in Exchange they can be used with a password alone, whatever MFA requirements exist elsewhere.
Business risk
Old mail protocols such as IMAP, POP and SMTP cannot present a second factor. As long as they are open there is a way past every MFA policy in the environment — Microsoft reports that over 97 per cent of all password attacks use them.
Recommendation
Block legacy authentication for all users and all resources with a Conditional Access policy, or turn on security defaults. Check first which clients still use the protocols.
- Partial
MFA enforced for all users
Critical 3.1MFA is required for all users, but the policy exempts one or more groups. Securenix cannot see how many people that covers — check the group members by hand.
Business risk
Without enforced multi-factor authentication a stolen password is enough to sign in as anyone in the organisation. Passwords leak in breaches at completely unrelated services and are then tried systematically against Microsoft 365.
Recommendation
Require MFA for all users and all resources, either with security defaults or with an enabled Conditional Access policy. Exclude only the emergency account that has to remain usable if the policy is misconfigured.
- Partial
MFA enforced for administrators
Critical 3.2MFA is required for administrators, but the policy exempts one or more groups. Check the group members by hand.
Business risk
An administrator account without enforced MFA is the shortest path to the whole environment. Whoever gets the password can read all mail, add their own accounts and lock the organisation out of its own environment.
Recommendation
Require MFA for every directory role, not only Global Administrator. It is the policy Microsoft themselves recommend putting in place first.
- Partial
Users without a registered MFA method
High 3.538 of 457 reviewed licensed accounts (8 %) have no usable MFA method and are protected by their password alone.
Business risk
An account without a usable MFA method is protected by its password alone. Those are also the accounts that lock themselves out the day an MFA requirement is switched on.
Recommendation
Have the users register Microsoft Authenticator before the MFA requirement is switched on. Check as well that the methods already registered are still allowed by the tenant's method policy.
Checks with no issues
- 3.4 Legacy authentication used in the last 30 days — No successful interactive sign-ins with legacy protocols in the last 30 days. Good
- 3.6 Security defaults — Security defaults are off. The tenant has 1 enabled Conditional Access policies and 1 in report-only mode. Information
Domains and email security
65 % of the area
- Partial
DMARC policy for the organisation's domains
Critical 5.3exempelbolaget.se has DMARC with p=none. Mail is monitored but nothing is stopped — forged mail is still delivered.
Business risk
DMARC is what tells the recipient what to do with mail that fails SPF or DKIM. Without a policy that rejects or quarantines, forged mail in the organisation's name is delivered — which is how most invoice fraud begins.
Recommendation
Publish a DMARC record at _dmarc for every domain. Start with p=none and reporting addresses, follow the reports for a few weeks, then tighten to p=quarantine and after that p=reject.
- Partial
SPF for the organisation's domains
High 5.1exempelbolaget.se publishes an SPF record ending in ~all. Mail from other senders is marked but delivered anyway, often straight to the inbox.
Business risk
SPF tells receiving mail servers which servers may send mail for the domain. Without it, or with it set too permissively, anyone can send invoices and password requests that appear to come from the organisation.
Recommendation
Publish exactly one SPF record per domain listing every legitimate sender and ending in -all. Check first that every service sending mail for the organisation is included.
- Partial
Defender for Office 365: Safe Links, Safe Attachments and anti-phishing
High 5.52 of 3 Safe Links, Safe Attachments and anti-phishing controls count as implemented in Microsoft Secure Score. The rest are switched off or only partly configured.
Business risk
Without Safe Links and Safe Attachments, neither the links nor the attachments in incoming mail are inspected when the user clicks, and without an anti-phishing policy nothing stops an attempt to impersonate the manager or a supplier. Those are the routes today's email attacks actually take.
Recommendation
Turn on Safe Links, Safe Attachments and anti-phishing for every recipient — most easily through Microsoft's preset security policies (Standard or Strict) in the Defender portal. If there is no Defender for Office 365 licence, that is the question to settle first.
Checks with no issues
- 5.2 DKIM selectors for the organisation's domains — exempelbolaget.se publishes both DKIM selectors. Check in Microsoft 365 that signing is switched on for the domain as well. Good
- 5.4 DMARC reporting addresses — exempelbolaget.se sends DMARC reports to a specified address. Good
Intune and device management
75 % of the area
- Partial
Microsoft security baselines assigned
High 6.21 of 3 security baselines are assigned. The missing ones leave their settings at the defaults.
Business risk
The baselines are Microsoft's own recommended settings for Windows, Edge and Defender for Endpoint. Without them hundreds of security settings stay at their defaults, which are chosen for backwards compatibility rather than for security.
Recommendation
Create and assign Microsoft's security baselines for Windows, Edge and Defender for Endpoint. A baseline that is created but not assigned protects no device.
- Partial
Endpoint security policies configured and assigned
High 6.33 of 4 endpoint security areas are configured and assigned.
Business risk
Disk encryption, antivirus, firewall and attack surface reduction rules are the four controls that decide whether a stolen computer can be read and whether a malicious macro is allowed to run. Each one missing is a whole class of protection that is not there.
Recommendation
Create and assign endpoint security policies for BitLocker, Defender Antivirus, firewall and attack surface reduction rules. Check that each policy is assigned to a group that actually contains devices.
- Partial
Share of devices meeting the compliance requirements
High 6.583 % of the devices meet the compliance requirements (330 of 398 evaluated). The rest have access despite not reaching the organisation's own requirements.
Business risk
A device that does not meet the requirements is missing something the organisation itself has decided is necessary — usually encryption, a screen lock or updates. It still has access to the organisation's data.
Recommendation
Work through the devices that do not meet the requirements and fix the cause per device. Consider requiring a compliant device in Conditional Access once the level is high enough.
- Partial
Apps with a high share of failed installations
Medium 6.71 of 5 apps have more than 20 % failed installations: Affarssystem - klient.
Business risk
An app that does not install is often a security tool or a business application that is not running on the devices that need it. Nobody notices until it is needed.
Recommendation
Work through the apps below in Intune, read the error code per device and fix the packaging or the assignment. It is often the same cause for every failed installation of an app.
Checks with no issues
- 6.1 Intune is used for device management — 420 devices are managed by Intune. Good
- 6.4 Compliance policies exist and are assigned — Each of the 3 platforms with enrolled devices has at least one assigned compliance policy. Good
- 6.6 Devices that have not checked in for 30 days — 18 of 420 devices have not checked in for 30 days. Good
Quick checks
50 % of the area
- Partial
Who may invite guests
High 7.1Every member may invite guests. Guest accounts can be created without any administrator seeing it.
Business risk
Every guest account is an account outside the organisation's control that nevertheless has access to material in the environment. If everyone may invite guests, nobody has an overview of who they are or why they are still there.
Recommendation
Restrict guest invitations to administrators and the Guest Inviter role. Review the external sharing setting in SharePoint and OneDrive at the same time.
- Partial
Users' ability to consent to applications
High 7.3Users may consent to applications within a restricting policy (ManagePermissionGrantsForSelf.microsoft-user-default-low). That is better than open access, but the requests are still not reviewed by anyone.
Business risk
If users may consent to applications themselves, one employee clicking Accept on a convincing sign-in page is enough for an attacker to read their mail — without ever knowing the password, and without MFA stopping anything.
Recommendation
Turn off users' ability to consent to applications and switch on the admin consent workflow, so the requests reach somebody who can assess them.
- Partial
Dormant accounts with an active licence
Medium 7.433 of 457 licensed accounts have not been used for 90 days, of which 0 have never signed in.
Business risk
An enabled account nobody uses is a way in that nobody watches — a sign-in on that account raises no suspicion. It is also a licence being paid for every month with nobody getting any use from it.
Recommendation
Work through the accounts below. Disable the ones no longer in use and release their licences; keep only the service accounts that are genuinely needed, and document why.
Checks with no issues
- 7.2 Number of guest users — The tenant has 18 guest users and 489 accounts of its own. 3 of the guests are marked as members in Entra ID, so the portal's guest list shows fewer. Information
- 7.5 Recipients for Microsoft's security notices — Microsoft's security and service notices go to 2 address(es), none of which is a monitored shared mailbox. The recipients on Defender's alert policies are a separate setting that cannot be read through Microsoft Graph. Information
On-premises servers and Active Directory
Results from the local review of servers and Active Directory, collected with the Securenix collector script.
20 computers reviewed across 1 collections
Collected 2026-09-14
- High
Many Domain or Enterprise Admins
1 computers
- exempelbolaget.local — 11 accounts are members of Domain Admins, 4 of which have not signed in for over 180 days.
Business risk
Every extra account with full control of the domain is another route an attacker or an insider can take to everything.
Recommendation
Run a privileged access review and move to a tiered administration model with time-limited elevation.
- High
Weak minimum password length
1 computers
- exempelbolaget.local — Minimum password length is 8 characters and complexity is not enforced in the Default Domain Policy.
Business risk
Short passwords are cracked quickly once a hash is obtained.
Recommendation
Raise the minimum length and align with the acquirer's baseline.
- High
End-of-life software installed
2 computers
- EXB-APP07 — Windows Server 2012 R2 Standard reached end of extended support and no longer receives security updates.
- EXB-PRINT01 — Windows Server 2012 R2 Standard reached end of extended support and no longer receives security updates.
Business risk
No security fixes; a frequent audit and cyber-insurance finding.
Recommendation
Upgrade or remove the affected product.
- High
Endpoint protection not active
1 computers
- EXB-APP07 — Microsoft Defender is installed but real-time protection is off.
Business risk
The server is unprotected against malware and ransomware.
Recommendation
Enable real-time protection or deploy the organisation's endpoint protection product.
- High
Firewall profile disabled
2 computers
- EXB-APP07 — The Domain and Private firewall profiles are switched off.
- EXB-BKP01 — The Domain and Private firewall profiles are switched off.
Business risk
Increases exposure during network consolidation and change.
Recommendation
Enable the firewall and validate the approved rule set.
- High
No recent updates installed
4 computers
- EXB-APP02 — 14 security updates are approved but not installed.
- EXB-APP04 — 22 security updates are approved but not installed.
- EXB-APP07 — 41 security updates are approved but not installed.
- EXB-MON01 — 9 security updates are approved but not installed.
Business risk
Unpatched systems increase cyber, compliance and deal-execution risk.
Recommendation
Review patch governance and clear the update backlog.
- High
RDP without Network Level Authentication
2 computers
- EXB-RDS01 — RDP is reachable without pre-authentication.
- EXB-RDS02 — RDP is reachable without pre-authentication.
Business risk
Exposes the logon screen to unauthenticated clients and known RDP vulnerabilities.
Recommendation
Require NLA and restrict RDP to a jump host or VPN.
- High
SMBv1 enabled
3 computers
- EXB-APP07 — The SMB1 protocol is installed and enabled on this server.
- EXB-FILE01 — The SMB1 protocol is installed and enabled on this server.
- EXB-PRINT01 — The SMB1 protocol is installed and enabled on this server.
Business risk
SMBv1 is the attack vector of WannaCry/NotPetya-class ransomware and blocks cyber-insurance requirements.
Recommendation
Disable SMBv1 after confirming no legacy device depends on it.
- High
WDigest plaintext credential caching enabled
2 computers
- EXB-APP07 — UseLogonCredential is 1, so passwords are held in memory in plain text.
- EXB-PRINT01 — UseLogonCredential is 1, so passwords are held in memory in plain text.
Business risk
Any local administrator or malware can dump clear-text passwords.
Recommendation
Set UseLogonCredential to 0 and investigate why it was enabled.
- Medium
Accounts that do not require a password
1 computers
- exempelbolaget.local — 47 enabled user accounts have not signed in for more than 180 days.
Business risk
Accounts may be accessible without any password.
Recommendation
Clear the flag and set passwords on every listed account.
- Medium
Accounts with non-expiring passwords
1 computers
- exempelbolaget.local — 9 accounts are set to PasswordNeverExpires, 3 of them service accounts with local admin rights.
Business risk
These are usually service accounts with static, shared passwords that survive every staff change.
Recommendation
Inventory the service accounts and move them to group managed service accounts where the application allows it.
- Medium
LAPS not in use
1 computers
- exempelbolaget.local — No LAPS or Windows LAPS policy was found; local administrator passwords are not managed.
Business risk
Without managed local passwords the local administrator password is usually the same on many machines, so one compromised machine unlocks the rest.
Recommendation
Deploy Windows LAPS so every machine gets a unique local administrator password that rotates automatically.
- Medium
System volume not encrypted
6 computers
- EXB-APP07 — BitLocker protection is off on C:.
- EXB-FILE02 — BitLocker protection is off on C:.
- EXB-HV01 — BitLocker protection is off on C:.
- EXB-HV02 — BitLocker protection is off on C:.
- EXB-PRINT01 — BitLocker protection is off on C:.
- EXB-SQL01 — BitLocker protection is off on C:.
Business risk
A disk that is stolen, sent for service or scrapped gives up every file and cached credential on it, which is a reportable personal data breach.
Recommendation
Enable BitLocker on the system volume and escrow the recovery key in Active Directory or Entra ID.
- Medium
Many cached domain logons
2 computers
- EXB-RDS01 — The server caches 10 logons.
- EXB-RDS02 — The server caches 10 logons.
Business risk
Every cached logon is one more credential that can be recovered from a stolen or decommissioned disk.
Recommendation
Reduce the number of cached logons through Group Policy to the level your baseline sets.
- Medium
LLMNR not disabled
14 computers
- EXB-APP03 — Multicast name resolution is enabled and can be poisoned to capture credentials.
- EXB-APP04 — Multicast name resolution is enabled and can be poisoned to capture credentials.
- EXB-APP05 — Multicast name resolution is enabled and can be poisoned to capture credentials.
- EXB-APP06 — Multicast name resolution is enabled and can be poisoned to capture credentials.
- EXB-APP07 — Multicast name resolution is enabled and can be poisoned to capture credentials.
- EXB-DC02 — Multicast name resolution is enabled and can be poisoned to capture credentials.
- EXB-FILE01 — Multicast name resolution is enabled and can be poisoned to capture credentials.
- EXB-FILE02 — Multicast name resolution is enabled and can be poisoned to capture credentials.
- EXB-MON01 — Multicast name resolution is enabled and can be poisoned to capture credentials.
- EXB-PRINT01 — Multicast name resolution is enabled and can be poisoned to capture credentials.
- EXB-RDS01 — Multicast name resolution is enabled and can be poisoned to capture credentials.
- EXB-RDS02 — Multicast name resolution is enabled and can be poisoned to capture credentials.
- EXB-SQL01 — Multicast name resolution is enabled and can be poisoned to capture credentials.
- EXB-SQL02 — Multicast name resolution is enabled and can be poisoned to capture credentials.
Business risk
Enables credential capture via name-resolution poisoning on the local network.
Recommendation
Disable LLMNR via Group Policy (Turn off multicast name resolution).
- Medium
Security event log too small
7 computers
- EXB-APP04 — Maximum size is 128 MB, so events are overwritten within days.
- EXB-APP07 — Maximum size is 64 MB, so events are overwritten within days.
- EXB-BKP01 — Maximum size is 128 MB, so events are overwritten within days.
- EXB-FILE01 — Maximum size is 128 MB, so events are overwritten within days.
- EXB-PRINT01 — Maximum size is 64 MB, so events are overwritten within days.
- EXB-RDS01 — Maximum size is 128 MB, so events are overwritten within days.
- EXB-SQL01 — Maximum size is 128 MB, so events are overwritten within days.
Business risk
A small log overwrites itself, often within hours on a busy server, so the evidence an investigation needs is gone before anyone looks for it.
Recommendation
Raise the Security log size, or forward events to a SIEM where retention is managed centrally.
- Medium
LSA protection not enabled
11 computers
- EXB-APP03 — RunAsPPL is not configured, so LSASS can be read by local administrators.
- EXB-APP04 — RunAsPPL is not configured, so LSASS can be read by local administrators.
- EXB-APP06 — RunAsPPL is not configured, so LSASS can be read by local administrators.
- EXB-APP07 — RunAsPPL is not configured, so LSASS can be read by local administrators.
- EXB-BKP01 — RunAsPPL is not configured, so LSASS can be read by local administrators.
- EXB-FILE01 — RunAsPPL is not configured, so LSASS can be read by local administrators.
- EXB-FILE02 — RunAsPPL is not configured, so LSASS can be read by local administrators.
- EXB-MON01 — RunAsPPL is not configured, so LSASS can be read by local administrators.
- EXB-PRINT01 — RunAsPPL is not configured, so LSASS can be read by local administrators.
- EXB-SQL01 — RunAsPPL is not configured, so LSASS can be read by local administrators.
- EXB-SQL02 — RunAsPPL is not configured, so LSASS can be read by local administrators.
Business risk
An attacker who gains local administrator rights can read credentials straight out of memory and use them elsewhere.
Recommendation
Enable LSA protection after confirming that no security or accessibility driver depends on loading into the LSASS process.
- Medium
LM / NTLMv1 authentication permitted
2 computers
- EXB-APP07 — LmCompatibilityLevel is 2.
- EXB-PRINT01 — LmCompatibilityLevel is 2.
Business risk
Weak hashes can be cracked or relayed to gain credentials.
Recommendation
Set LmCompatibilityLevel to 5 (NTLMv2 only, refuse LM and NTLM).
- Medium
SMB signing not required
6 computers
- EXB-APP03 — RequireSecuritySignature is 0, so SMB sessions can be relayed.
- EXB-APP07 — RequireSecuritySignature is 0, so SMB sessions can be relayed.
- EXB-BKP01 — RequireSecuritySignature is 0, so SMB sessions can be relayed.
- EXB-FILE01 — RequireSecuritySignature is 0, so SMB sessions can be relayed.
- EXB-FILE02 — RequireSecuritySignature is 0, so SMB sessions can be relayed.
- EXB-PRINT01 — RequireSecuritySignature is 0, so SMB sessions can be relayed.
Business risk
Allows SMB relay attacks against the server.
Recommendation
Require SMB signing via Group Policy after testing legacy clients.
- Medium
TLS 1.0 / 1.1 accepted
5 computers
- EXB-APP06 — Deprecated TLS versions are still accepted by the server.
- EXB-APP07 — Deprecated TLS versions are still accepted by the server.
- EXB-PRINT01 — Deprecated TLS versions are still accepted by the server.
- EXB-SQL01 — Deprecated TLS versions are still accepted by the server.
- EXB-SQL02 — Deprecated TLS versions are still accepted by the server.
Business risk
Deprecated protocols fail compliance baselines (PCI DSS, cyber insurance).
Recommendation
Disable TLS 1.0 and 1.1 after verifying client compatibility.
- Low
Stale computer objects
1 computers
- exempelbolaget.local — 23 computer objects have not authenticated in over 180 days.
Business risk
The asset inventory cannot be trusted, which makes both security work and any migration harder to scope.
Recommendation
Verify the stale computer objects and remove the ones that no longer exist.
- Low
Many local administrators
2 computers
- EXB-APP07 — 9 members in the local Administrators group.
- EXB-BKP01 — 7 members in the local Administrators group.
Business risk
Broad admin access complicates separation of duties and access clean-up.
Recommendation
Apply a least-privilege model and reduce the local admin footprint.
- Low
Secure Boot not enabled
2 computers
- EXB-APP07 — The machine boots in legacy BIOS mode without Secure Boot.
- EXB-PRINT01 — The machine boots in legacy BIOS mode without Secure Boot.
Business risk
Nothing verifies the boot chain, so malware that loads before Windows can persist beneath the operating system and survive a rebuild.
Recommendation
Move the machine to UEFI boot and enable Secure Boot; a virtual machine needs to be generation 2.
- Low
NetBIOS over TCP/IP enabled
1 computers
- EXB-PRINT01 — NetBIOS is enabled on 2 adapter(s).
Business risk
NetBIOS name resolution can be poisoned to capture and relay credentials on the local network.
Recommendation
Disable NetBIOS over TCP/IP on each adapter, or push the setting out through DHCP.
- Low
PowerShell script block logging not enabled
3 computers
- EXB-APP06 — Script block logging is not enabled, so PowerShell activity is not recorded.
- EXB-APP07 — Script block logging is not enabled, so PowerShell activity is not recorded.
- EXB-MON01 — Script block logging is not enabled, so PowerShell activity is not recorded.
Business risk
PowerShell is the most common tool in a hands-on attack, and without this logging there is no record of what was run.
Recommendation
Enable script block logging through Group Policy and forward the PowerShell log to wherever you keep security events.
Collections this report is built from
Every collector run included, with the computers it read. The most recent reading per computer applies.
- 2026-09-14 06:22 EXB-SQL02, EXB-RDS02, EXB-RDS01, EXB-FILE01, EXB-DC01, EXB-BKP01, EXB-APP05, EXB-HV02, EXB-APP03, EXB-APP02, EXB-PRINT01, EXB-APP04, EXB-HV01, EXB-APP07, EXB-SQL01, EXB-APP06, EXB-DC02, EXB-APP01, EXB-MON01, EXB-FILE02
Consider a full security review from Technix
This report is an automated read of a selection of security controls. A full security review gives you the complete picture of your security posture, mapped to the CIS Controls. We walk through every gap with you, prioritise by business risk and produce a remediation plan with dated steps — including the parts that cannot be read automatically, such as networks, procedures and a deeper analysis of server environments and multi-cloud.
Contact us at Technix and we will book a full security review.