I've been reading CISA's newly published binding operational directive. What I find most interesting is that some of the mandatory items may potentially require a step-up license if not already using a E5/G5 license or an add-on security and compliance license.
"Shall = mandatory, should = recommended, left to agency discretion"
In this example, it requires a Entra P2 license https://lnkd.in/getPjS6N
This one, a compliance add-on if not using E5/G5. https://lnkd.in/geVhh77X.
Read more here https://lnkd.in/gpNyydKb and the required configurations https://lnkd.in/gZUC-5Vg #CISA #Cybersecurity #Entra #Defender #Microsoft #CSPM