| 1.1.1 Ensure Administrative accounts are cloud-only | ACCESS CONTROL |
| 1.1.2 Ensure two emergency access accounts have been defined | ACCESS CONTROL |
| 1.1.3 Ensure that between two and four global admins are designated | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 1.1.4 Ensure administrative accounts use licenses with a reduced application footprint | ACCESS CONTROL |
| 1.2.2 Ensure sign-in to shared mailboxes is blocked | CONFIGURATION MANAGEMENT |
| 1.3.1 Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)' | IDENTIFICATION AND AUTHENTICATION |
| 1.3.4 Ensure 'User owned apps and services' is restricted | CONFIGURATION MANAGEMENT |
| 1.3.5 Ensure internal phishing protection for Forms is enabled | AWARENESS AND TRAINING, SYSTEM AND INFORMATION INTEGRITY |
| 1.3.9 Ensure shared bookings pages are restricted to select users | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 2.1.2 Ensure the Common Attachment Types Filter is enabled | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.3 Ensure notifications for internal users sending malware is Enabled | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.6 Ensure Exchange Online Spam Policies are set to notify administrators | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.8 Ensure that SPF records are published for all Exchange Domains | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.1.9 Ensure that DKIM is enabled for all Exchange Online Domains | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.1.10 Ensure DMARC records for all Exchange Online domains are published | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.1.12 Ensure the connection filter IP allow list is not used | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.13 Ensure the connection filter safe list is off | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.14 Ensure inbound anti-spam policies do not contain allowed domains | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.15 Ensure outbound anti-spam message limits are in place | SYSTEM AND INFORMATION INTEGRITY |
| 3.1.1 Ensure Microsoft 365 audit log search is Enabled | AUDIT AND ACCOUNTABILITY |
| 3.2.1 Ensure DLP policies are enabled | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 3.3.1 Ensure Information Protection sensitivity label policies are published | RISK ASSESSMENT |
| 4.1 Ensure devices without a compliance policy are marked 'not compliant' | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 4.2 Ensure device enrollment for personally owned devices is blocked by default | CONFIGURATION MANAGEMENT |
| 5.1.2.1 Ensure 'Per-user MFA' is disabled | CONFIGURATION MANAGEMENT |
| 5.1.2.2 Ensure users cannot register applications | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| 5.1.2.3 Ensure 'Restrict non-admin users from creating tenants' is set to 'Yes' | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.2.4 Ensure access to the Entra admin center is restricted | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION |
| 5.1.3.1 Ensure users cannot create security groups | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.3.3 Ensure that 'Owners can manage group membership requests in My Groups' is set to 'No' | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.4.2 Ensure the maximum number of devices per user is limited | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.4.3 Ensure the GA role is not added as a local administrator during Entra join | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.4.4 Ensure local administrator assignment is limited during Entra join | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.4.5 Ensure Local Administrator Password Solution is enabled | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION |
| 5.1.5.2 Ensure the admin consent workflow is enabled | ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION |
| 5.1.5.4 Ensure password lifetime for applications does not exceed 180 days | IDENTIFICATION AND AUTHENTICATION |
| 5.1.5.5 Ensure new application passwords are system-generated | IDENTIFICATION AND AUTHENTICATION |
| 5.1.5.6 Ensure maximum certificate lifetime for applications does not exceed 180 days | IDENTIFICATION AND AUTHENTICATION |
| 5.1.6.2 Ensure that guest user access is restricted | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION |
| 5.1.8.1 Ensure that password hash sync is enabled for hybrid deployments | ACCESS CONTROL |
| 5.2.2.1 Ensure multifactor authentication is enabled for all users in administrative roles | IDENTIFICATION AND AUTHENTICATION |
| 5.2.2.2 Ensure multifactor authentication is enabled for all users | IDENTIFICATION AND AUTHENTICATION |
| 5.2.2.3 Enable Conditional Access policies to block legacy authentication | CONFIGURATION MANAGEMENT |
| 5.2.2.4 Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative users | ACCESS CONTROL |
| 5.2.2.9 Ensure a managed device is required for authentication | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 5.2.2.10 Ensure a managed device is required to register security information | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 5.2.2.11 Ensure sign-in frequency for Intune Enrollment is set to 'Every time' | IDENTIFICATION AND AUTHENTICATION |
| 5.2.2.12 Ensure the device code sign-in flow is blocked | CONFIGURATION MANAGEMENT |
| 5.2.2.13 Ensure that periodic reauthentication is required for all users | ACCESS CONTROL |
| 5.2.2.17 Ensure authentication transfer is blocked | ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |