Hello,
in the Risk Assessment Dashboard there is one section for "Accounts with never expiring password"
Password change frequency a thing of the past ( see also NIST recommendation or BSI ):
https://auditboard.com/blog/nist-password-guidelines
We also use MFA. The Risk Board should be customisable in a way, that I can either accept the Risk after an assessment or downgrade the Risk.
Same goes for the "Directories with direct access". The normal setup for a users "home" directory on a fileserver is that only the user and admin has access. It would be kind of strange to create a group for a single user to avoid that message. It should be possible to exclude certain paths on the FS from this.