cisagov / ScubaGear

Automation to assess the state of your M365 tenant against CISA's baselines
https://www.cisa.gov/resources-tools/services/secure-cloud-business-applications-scuba-project
Creative Commons Zero v1.0 Universal
1.44k stars 203 forks source link

Refactor the MFA ruleset names in AAD Rego so that they accurately reflect their purpose #1182

Open tkol2022 opened 6 days ago

tkol2022 commented 6 days ago

💡 Summary

In the AAD Rego, usage of the ruleset names PhishingResistantMFA, PhishingResistantMFAPolicies, HasAcceptableMFA and AlternativeMFA makes the AAD Rego code difficult to understand because I'm not sure that their names accurately reflect their purpose. Some of these rulesets are referenced across multiple policies.

Implementation notes