L2
Enhanced Security
Security-conscious teams ready for just-in-time access.
Adds time-limited admin access and advanced threat detection. Admins activate permissions only when needed, reducing your attack window.
Moderate operational impact, significantly improved security
46
Controls
13
Critical
20
Auto-Fix
20
New at L2
What's Included
- Everything in Level 1
- PIM required for privileged roles
- Phishing-resistant MFA for admins
- Device compliance requirements
- Automated stale account disabling
Not Included
- Phishing-resistant MFA for all users
- Hardware key requirements
- Full just-in-time access model
Framework Alignment
CIS Microsoft Entra ID Foundations Benchmark (Level 2)Microsoft Zero TrustNIST 800-63B
Controls (46)
Conditional Access10
CA-01Require MFA via Conditional Access Policy
CriticalCA-02Require MFA for All Administrators
CriticalCA-08Block Access from High-Risk Countries
MediumCA-11Enforce Session Lifetime Limits for Guests and Admins
MediumDV-01Require Compliant Devices for Admin Access
HighCA-03Block or Require MFA for Risky Sign-Ins
HighCA-04Remediate High-Risk Users Automatically
HighCA-10Enable Token Protection
HighDV-02Require Compliant Devices for Global Admins
CriticalCA-05Require App Protection for Mobile Access
HighWorkload Identity & Applications9
APP-01Application Ownership for Apps with Credentials
LowAPP-02Enforce Application Credential Expiration
CriticalAPP-05Service Principal Credential Hygiene
CriticalAPP-08Restrict User Application Consent
HighAPP-09Enforce Certificate Credentials for Applications
MediumAPP-03Internal App Registration Permissions
HighAPP-04Enable Admin Consent Workflow
MediumAPP-06Third-Party Enterprise App Permissions
HighAPP-07Identify Unused Service Principals
MediumReady to implement this baseline?
TrueConfig scans your Microsoft 365 tenant and shows which controls need attention.