CIS Microsoft 365 Foundations v7.0.0 L1 E3

Audit Details

Name: CIS Microsoft 365 Foundations v7.0.0 L1 E3

Updated: 8/13/2026

Authority: CIS

Plugin: microsoft_azure

Revision: 1.0

Estimated Item Count: 100

File Details

Filename: CIS_Microsoft_365_Foundations_v7.0.0_L1_E3.audit

Size: 398 kB

MD5: 30001c5eae4ab158f8c6de7680dece71
SHA256: c8b708165cf0a069a07e9658e9da4b097bba8bd7739ec25bcae1a92a27587784

Audit Items

DescriptionCategories
1.1.1 Ensure Administrative accounts are cloud-only

ACCESS CONTROL

1.1.2 Ensure two emergency access accounts have been defined

ACCESS CONTROL

1.1.3 Ensure that between two and four global admins are designated

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

1.1.4 Ensure administrative accounts use licenses with a reduced application footprint

ACCESS CONTROL

1.2.2 Ensure sign-in to shared mailboxes is blocked

CONFIGURATION MANAGEMENT

1.3.1 Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)'

IDENTIFICATION AND AUTHENTICATION

1.3.4 Ensure 'User owned apps and services' is restricted

CONFIGURATION MANAGEMENT

1.3.5 Ensure internal phishing protection for Forms is enabled

AWARENESS AND TRAINING, SYSTEM AND INFORMATION INTEGRITY

1.3.9 Ensure shared bookings pages are restricted to select users

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.1.2 Ensure the Common Attachment Types Filter is enabled

SYSTEM AND INFORMATION INTEGRITY

2.1.3 Ensure notifications for internal users sending malware is Enabled

SYSTEM AND INFORMATION INTEGRITY

2.1.6 Ensure Exchange Online Spam Policies are set to notify administrators

SYSTEM AND INFORMATION INTEGRITY

2.1.8 Ensure that SPF records are published for all Exchange Domains

SYSTEM AND COMMUNICATIONS PROTECTION

2.1.9 Ensure that DKIM is enabled for all Exchange Online Domains

SYSTEM AND COMMUNICATIONS PROTECTION

2.1.10 Ensure DMARC records for all Exchange Online domains are published

SYSTEM AND COMMUNICATIONS PROTECTION

2.1.12 Ensure the connection filter IP allow list is not used

SYSTEM AND INFORMATION INTEGRITY

2.1.13 Ensure the connection filter safe list is off

SYSTEM AND INFORMATION INTEGRITY

2.1.14 Ensure inbound anti-spam policies do not contain allowed domains

SYSTEM AND INFORMATION INTEGRITY

2.1.15 Ensure outbound anti-spam message limits are in place

SYSTEM AND INFORMATION INTEGRITY

3.1.1 Ensure Microsoft 365 audit log search is Enabled

AUDIT AND ACCOUNTABILITY

3.2.1 Ensure DLP policies are enabled

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.3.1 Ensure Information Protection sensitivity label policies are published

RISK ASSESSMENT

4.1 Ensure devices without a compliance policy are marked 'not compliant'

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

4.2 Ensure device enrollment for personally owned devices is blocked by default

CONFIGURATION MANAGEMENT

5.1.2.1 Ensure 'Per-user MFA' is disabled

CONFIGURATION MANAGEMENT

5.1.2.2 Ensure users cannot register applications

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

5.1.2.3 Ensure 'Restrict non-admin users from creating tenants' is set to 'Yes'

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.2.4 Ensure access to the Entra admin center is restricted

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

5.1.3.1 Ensure users cannot create security groups

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.3.3 Ensure that 'Owners can manage group membership requests in My Groups' is set to 'No'

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.4.2 Ensure the maximum number of devices per user is limited

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.4.3 Ensure the GA role is not added as a local administrator during Entra join

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.4.4 Ensure local administrator assignment is limited during Entra join

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.4.5 Ensure Local Administrator Password Solution is enabled

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

5.1.5.2 Ensure the admin consent workflow is enabled

ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

5.1.5.4 Ensure password lifetime for applications does not exceed 180 days

IDENTIFICATION AND AUTHENTICATION

5.1.5.5 Ensure new application passwords are system-generated

IDENTIFICATION AND AUTHENTICATION

5.1.5.6 Ensure maximum certificate lifetime for applications does not exceed 180 days

IDENTIFICATION AND AUTHENTICATION

5.1.6.2 Ensure that guest user access is restricted

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

5.1.8.1 Ensure that password hash sync is enabled for hybrid deployments

ACCESS CONTROL

5.2.2.1 Ensure multifactor authentication is enabled for all users in administrative roles

IDENTIFICATION AND AUTHENTICATION

5.2.2.2 Ensure multifactor authentication is enabled for all users

IDENTIFICATION AND AUTHENTICATION

5.2.2.3 Enable Conditional Access policies to block legacy authentication

CONFIGURATION MANAGEMENT

5.2.2.4 Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative users

ACCESS CONTROL

5.2.2.9 Ensure a managed device is required for authentication

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

5.2.2.10 Ensure a managed device is required to register security information

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

5.2.2.11 Ensure sign-in frequency for Intune Enrollment is set to 'Every time'

IDENTIFICATION AND AUTHENTICATION

5.2.2.12 Ensure the device code sign-in flow is blocked

CONFIGURATION MANAGEMENT

5.2.2.13 Ensure that periodic reauthentication is required for all users

ACCESS CONTROL

5.2.2.17 Ensure authentication transfer is blocked

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY