| 1.1.1 Ensure Administrative accounts are cloud-only | ACCESS CONTROL |
| 1.1.2 Ensure two emergency access accounts have been defined | ACCESS CONTROL |
| 1.1.3 Ensure that between two and four global admins are designated | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 1.1.4 Ensure administrative accounts use licenses with a reduced application footprint | ACCESS CONTROL |
| 1.2.2 Ensure sign-in to shared mailboxes is blocked | CONFIGURATION MANAGEMENT |
| 1.3.1 Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)' | IDENTIFICATION AND AUTHENTICATION |
| 1.3.4 Ensure 'User owned apps and services' is restricted | CONFIGURATION MANAGEMENT |
| 1.3.5 Ensure internal phishing protection for Forms is enabled | AWARENESS AND TRAINING, SYSTEM AND INFORMATION INTEGRITY |
| 1.3.9 Ensure shared bookings pages are restricted to select users | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 2.1.2 Ensure the Common Attachment Types Filter is enabled | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.3 Ensure notifications for internal users sending malware is Enabled | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.6 Ensure Exchange Online Spam Policies are set to notify administrators | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.8 Ensure that SPF records are published for all Exchange Domains | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.1.9 Ensure that DKIM is enabled for all Exchange Online Domains | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.1.10 Ensure DMARC records for all Exchange Online domains are published | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.1.12 Ensure the connection filter IP allow list is not used | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.13 Ensure the connection filter safe list is off | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.14 Ensure inbound anti-spam policies do not contain allowed domains | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.15 Ensure outbound anti-spam message limits are in place | SYSTEM AND INFORMATION INTEGRITY |
| 2.2.1 Ensure emergency access account activity is monitored | AUDIT AND ACCOUNTABILITY |
| 2.4.1 Ensure Priority account protection is enabled and configured | SYSTEM AND INFORMATION INTEGRITY |
| 2.4.2 Ensure Priority accounts have 'Strict protection' presets applied | SYSTEM AND INFORMATION INTEGRITY |
| 2.4.4 Ensure Zero-hour auto purge for Microsoft Teams is on | SYSTEM AND INFORMATION INTEGRITY |
| 2.4.5 Ensure 'AIR' remediation is enabled | SYSTEM AND INFORMATION INTEGRITY |
| 3.1.1 Ensure Microsoft 365 audit log search is Enabled | AUDIT AND ACCOUNTABILITY |
| 3.2.1 Ensure DLP policies are enabled | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 3.2.2 Ensure DLP policies are enabled for Microsoft Teams | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 3.2.3 Ensure DLP policies are published for Copilot users | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 3.3.1 Ensure Information Protection sensitivity label policies are published | RISK ASSESSMENT |
| 4.1 Ensure devices without a compliance policy are marked 'not compliant' | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 4.2 Ensure device enrollment for personally owned devices is blocked by default | CONFIGURATION MANAGEMENT |
| 5.1.2.1 Ensure 'Per-user MFA' is disabled | CONFIGURATION MANAGEMENT |
| 5.1.2.2 Ensure users cannot register applications | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| 5.1.2.3 Ensure 'Restrict non-admin users from creating tenants' is set to 'Yes' | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.2.4 Ensure access to the Entra admin center is restricted | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION |
| 5.1.3.1 Ensure users cannot create security groups | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.3.3 Ensure that 'Owners can manage group membership requests in My Groups' is set to 'No' | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.4.2 Ensure the maximum number of devices per user is limited | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.4.3 Ensure the GA role is not added as a local administrator during Entra join | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.4.4 Ensure local administrator assignment is limited during Entra join | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.4.5 Ensure Local Administrator Password Solution is enabled | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION |
| 5.1.5.2 Ensure the admin consent workflow is enabled | ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION |
| 5.1.5.4 Ensure password lifetime for applications does not exceed 180 days | IDENTIFICATION AND AUTHENTICATION |
| 5.1.5.5 Ensure new application passwords are system-generated | IDENTIFICATION AND AUTHENTICATION |
| 5.1.5.6 Ensure maximum certificate lifetime for applications does not exceed 180 days | IDENTIFICATION AND AUTHENTICATION |
| 5.1.6.2 Ensure that guest user access is restricted | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION |
| 5.1.8.1 Ensure that password hash sync is enabled for hybrid deployments | ACCESS CONTROL |
| 5.2.2.1 Ensure multifactor authentication is enabled for all users in administrative roles | IDENTIFICATION AND AUTHENTICATION |
| 5.2.2.2 Ensure multifactor authentication is enabled for all users | IDENTIFICATION AND AUTHENTICATION |
| 5.2.2.3 Enable Conditional Access policies to block legacy authentication | CONFIGURATION MANAGEMENT |