Description:

This check verifies that end users cannot run PowerShell against the M365 organization.

Why:

Exchange Online PowerShell enables you to manage your Exchange Online organization from the command line. By default, all accounts you create in Microsoft 365 are allowed to use Exchange Online PowerShell. Attackers can utilize this tool to run malicious commands, access the file system, registry, and more. Ransomware is often distributed throughout the network via PowerShell. As part of a least privileged access approach to security, non-admin users that do not require this functionality should have it disabled.

Status detail shown in Augmentt: You have N of M non-admin accounts that have Powershell disabled

This check reports a count rather than a simple pass/fail. It is Configured when every in-scope item is compliant, Partially Configured when some are, and Not Configured when none are.

Scoring: Scored proportionally — the check contributes according to how many of the in-scope items are compliant, so a partially compliant tenant earns partial credit.

Category: General

Microsoft Licensing: Works with Basic licensing

Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.

Remediation in Augmentt: Configure directly in Augmentt (Configure tab)

Compliance Frameworks:

  • NIST CSF 2.0 — PR.AA-05

  • HIPAA Security Rule — 164.312(a)(1)

  • CMMC Level 1 — AC.L1-b.1.ii

  • CMMC Level 2 — AC.L2-3.1.7

Microsoft documentation: