|
22 | 22 | "ruleSettings": { |
23 | 23 | "rules": "rules/", |
24 | 24 | "azureDefaultRuleset": "rules/rulesets/cis_azure_3.0.json", |
25 | | - "m365DefaultRuleset": "rules/rulesets/cis_m365_4.0.json" |
| 25 | + "m365DefaultRuleset": "rules/rulesets/cis_m365_5.0.json" |
26 | 26 | }, |
27 | 27 | "logging": { |
28 | 28 | "default":[ |
|
56 | 56 | "sitePermissionsOptions": { |
57 | 57 | "scanAllSites": "false", |
58 | 58 | "excludeFolders": "true", |
59 | | - "includeLists": "false", |
60 | | - "includeListItems": "false", |
| 59 | + "includeLists": "true", |
| 60 | + "includeListItems": "true", |
61 | 61 | "includeInheritedPermissions": "true" |
62 | 62 | }, |
63 | 63 | "Identity": { |
|
75 | 75 | }, |
76 | 76 | "ExchangeOnline": { |
77 | 77 | "GetExchangeGroups": "true", |
78 | | - "GetPurViewGroups": "false" |
| 78 | + "GetPurViewGroups": "false", |
| 79 | + "userRoleAssignmentPolicy":{ |
| 80 | + "excludedRoles":[ |
| 81 | + "My Custom Apps", |
| 82 | + "My Marketplace Apps", |
| 83 | + "My ReadWriteMailbox Apps" |
| 84 | + ] |
| 85 | + } |
79 | 86 | } |
80 | 87 | }, |
81 | 88 | "entraId": { |
82 | | - "useMsGraph": "true", |
83 | 89 | "forceRequestMFA": "false", |
84 | | - "getUsersWithAADInternalAPI": "false", |
85 | 90 | "auditLog":{ |
86 | 91 | "enabled": "false", |
87 | 92 | "AuditLogDaysAgo": "-7" |
|
93 | 98 | "Application.Read.All", |
94 | 99 | "Policy.Read.All", |
95 | 100 | "Organization.Read.All", |
| 101 | + "OrgSettings-AppsAndServices.Read.All", |
96 | 102 | "RoleManagement.Read.Directory", |
97 | 103 | "GroupMember.Read.All", |
98 | 104 | "Directory.Read.All", |
|
101 | 107 | "RoleManagementPolicy.Read.AzureADGroup", |
102 | 108 | "Group.Read.All", |
103 | 109 | "SecurityEvents.Read.All", |
104 | | - "IdentityRiskEvent.Read.All" |
| 110 | + "IdentityRiskEvent.Read.All", |
| 111 | + "UserAuthenticationMethod.Read.All", |
| 112 | + "AuditLog.Read.All", |
| 113 | + "AccessReview.Read.All" |
105 | 114 | ] |
106 | 115 | }, |
107 | 116 | "provider": { |
108 | | - "graph":{ |
109 | | - "api_version": "1.6", |
110 | | - "internal_api_version": "1.61-internal" |
111 | | - }, |
112 | 117 | "portal":{ |
113 | 118 | "GetManagedApplicationsByPrincipalId": "true" |
114 | 119 | }, |
|
121 | 126 | { |
122 | 127 | "name": "azureDocumentDB", |
123 | 128 | "resource": { |
124 | | - "api_version": "2024-12-01-preview", |
| 129 | + "api_version": "2025-11-01-preview", |
125 | 130 | "provider": "Microsoft.DocumentDB" |
126 | 131 | } |
127 | 132 | }, |
128 | 133 | { |
129 | 134 | "name": "azureBotServices", |
130 | 135 | "resource": { |
131 | | - "api_version": "2017-12-01", |
| 136 | + "api_version": "2023-09-15-preview", |
132 | 137 | "provider": "Microsoft.BotService" |
133 | 138 | } |
134 | 139 | }, |
|
138 | 143 | "api_version": "2024-04-01", |
139 | 144 | "provider": "Microsoft.Web" |
140 | 145 | } |
| 146 | + }, |
| 147 | + { |
| 148 | + "name": "azureAppServiceEnvironment", |
| 149 | + "resource": { |
| 150 | + "api_version": "2025-03-01", |
| 151 | + "provider": "Microsoft.Web" |
| 152 | + } |
141 | 153 | }, |
142 | 154 | { |
143 | 155 | "name": "azureForSQL", |
144 | 156 | "resource": { |
145 | 157 | "api_version": "2021-05-01-preview", |
146 | 158 | "provider": "Microsoft.Sql" |
147 | 159 | } |
| 160 | + }, |
| 161 | + { |
| 162 | + "name": "managedInstances", |
| 163 | + "resource": { |
| 164 | + "api_version": "2024-11-01-preview", |
| 165 | + "provider": "Microsoft.Sql" |
| 166 | + } |
| 167 | + }, |
| 168 | + { |
| 169 | + "name": "SqlVirtualMachines", |
| 170 | + "resource": { |
| 171 | + "api_version": "2023-10-01", |
| 172 | + "provider": "Microsoft.Sql" |
| 173 | + } |
148 | 174 | }, |
149 | 175 | { |
150 | 176 | "name": "azureForSQLFW", |
|
198 | 224 | { |
199 | 225 | "name": "azureVm", |
200 | 226 | "resource": { |
201 | | - "api_version": "2024-07-01", |
| 227 | + "api_version": "2025-04-01", |
202 | 228 | "provider": "microsoft.Compute" |
203 | 229 | } |
204 | 230 | }, |
|
254 | 280 | { |
255 | 281 | "name": "azureNSG", |
256 | 282 | "resource": { |
257 | | - "api_version": "2017-10-01", |
| 283 | + "api_version": "2025-03-01", |
258 | 284 | "provider": "Microsoft.Network" |
259 | 285 | } |
260 | 286 | }, |
|
268 | 294 | { |
269 | 295 | "name": "azureStorage", |
270 | 296 | "resource": { |
271 | | - "api_version": "2023-05-01", |
| 297 | + "api_version": "2025-06-01", |
272 | 298 | "provider": "Microsoft.Storage" |
273 | 299 | } |
274 | 300 | }, |
|
359 | 385 | { |
360 | 386 | "name": "azureRecommendations", |
361 | 387 | "resource": { |
362 | | - "api_version": "2020-01-01", |
| 388 | + "api_version": "2025-05-01-preview", |
363 | 389 | "provider": "Microsoft.Advisor" |
364 | 390 | } |
| 391 | + }, |
| 392 | + { |
| 393 | + "name": "bastionHost", |
| 394 | + "resource": { |
| 395 | + "api_version": "2025-03-01", |
| 396 | + "provider": "Microsoft.Network" |
| 397 | + } |
365 | 398 | }, |
366 | 399 | { |
367 | 400 | "name": "azureContainers", |
|
457 | 490 | { |
458 | 491 | "name": "azureRedis", |
459 | 492 | "resource": { |
460 | | - "api_version": "2023-08-01", |
| 493 | + "api_version": "2025-08-01-preview", |
461 | 494 | "provider": "Microsoft.Cache" |
462 | 495 | } |
463 | 496 | }, |
|
513 | 546 | { |
514 | 547 | "name": "azureDataBricksAccessConnector", |
515 | 548 | "resource": { |
516 | | - "api_version": "2024-05-01", |
| 549 | + "api_version": "2026-01-01", |
517 | 550 | "provider": "Microsoft.Databricks" |
518 | 551 | } |
519 | 552 | }, |
|
544 | 577 | "api_version": "2020-02-02", |
545 | 578 | "provider": "microsoft.insights" |
546 | 579 | } |
| 580 | + }, |
| 581 | + { |
| 582 | + "name": "azureVault", |
| 583 | + "resource": { |
| 584 | + "api_version": "2025-02-01", |
| 585 | + "provider": "Microsoft.RecoveryServices" |
| 586 | + } |
547 | 587 | } |
548 | 588 | ] |
549 | 589 | } |
0 commit comments