cisagov / ScubaGoggles

SCuBA Secure Configuration Baselines and assessment tool for Google Workspace
https://www.cisa.gov/resources-tools/services/secure-cloud-business-applications-scuba-project
Creative Commons Zero v1.0 Universal
149 stars 20 forks source link

GWS.COMMONCONTROLS.1.1 does not check if MFA is allowed #241

Closed adhilto closed 6 months ago

adhilto commented 6 months ago

🐛 Summary

There are three settings 1.1 depends on: image

Currently the rego just checks 2 & 3.

What's wrong? Please be specific.

To reproduce

Disallow MFA but don't change the other values.

Expected behavior

All three items get checked.