| 1.2.1 Ensure that only organizationally managed/approved public groups exist | ACCESS CONTROL, MEDIA PROTECTION |
| 1.3.2 Ensure 'Idle session timeout' is set to '3 hours (or less)' for unmanaged devices | ACCESS CONTROL |
| 1.3.3 Ensure 'External sharing' of calendars is not available | CONFIGURATION MANAGEMENT |
| 1.3.7 Ensure 'third-party storage services' are restricted in 'Microsoft 365 on the web' | ACCESS CONTROL, MEDIA PROTECTION |
| 1.3.8 Ensure that Sways cannot be shared with people outside of your organization | CONFIGURATION MANAGEMENT |
| 2.1.11 Ensure comprehensive attachment filtering is applied | SYSTEM AND INFORMATION INTEGRITY |
| 5.1.2.5 Ensure the option to remain signed in is hidden | ACCESS CONTROL |
| 5.1.2.6 Ensure 'LinkedIn account connections' is disabled | CONFIGURATION MANAGEMENT |
| 5.1.3.2 Ensure that 'Restrict user ability to access groups features in My Groups' is set to 'Yes' | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.3.4 Ensure that 'Users can create Microsoft 365 groups in Azure portals, API or PowerShell' is set to 'No' | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.4.1 Ensure the ability to join devices to Entra is restricted | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.4.6 Ensure users are restricted from recovering BitLocker keys | ACCESS CONTROL, MEDIA PROTECTION |
| 5.1.5.1 Ensure user consent to apps accessing company data on their behalf is not allowed | CONFIGURATION MANAGEMENT |
| 5.1.5.3 Ensure password addition is blocked for applications | IDENTIFICATION AND AUTHENTICATION |
| 5.1.6.1 Ensure that collaboration invitations are sent to allowed domains only | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION |
| 5.1.6.3 Ensure guest user invitations are limited | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION |
| 5.2.2.5 Ensure 'Phishing-resistant MFA strength' is required for Administrators | IDENTIFICATION AND AUTHENTICATION |
| 5.2.2.14 Ensure trusted 'named locations' are defined | ACCESS CONTROL, CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 5.2.2.15 Ensure exclusionary geographic access controls are utilized | ACCESS CONTROL |
| 5.2.2.16 Ensure Token Protection is enforced for session tokens | IDENTIFICATION AND AUTHENTICATION |
| 5.2.3.7 Ensure the email OTP authentication method is disabled | IDENTIFICATION AND AUTHENTICATION |
| 5.2.4.2 Ensure that 2 methods are required for password reset | IDENTIFICATION AND AUTHENTICATION |
| 6.3.1 Ensure users installing Outlook add-ins is not allowed | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 6.5.3 Ensure additional storage providers are restricted in Outlook on the web | ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION |
| 6.5.5 Ensure Direct Send submissions are rejected | ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 7.2.4 Ensure OneDrive content sharing is restricted | ACCESS CONTROL, MEDIA PROTECTION |
| 7.2.5 Ensure that SharePoint guest users cannot share items they don't own | ACCESS CONTROL, MEDIA PROTECTION |
| 7.2.6 Ensure SharePoint external sharing is restricted | ACCESS CONTROL, MEDIA PROTECTION |
| 7.2.8 Ensure external sharing is restricted by security group | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION |
| 8.1.1 Ensure external file sharing in Teams is enabled for only approved cloud storage services | ACCESS CONTROL, MEDIA PROTECTION |
| 8.2.1 Ensure external domains are restricted in the Teams admin center | ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION |
| 8.5.1 Ensure anonymous users can't join a meeting | ACCESS CONTROL |
| 8.5.5 Ensure meeting chat does not allow anonymous users | ACCESS CONTROL |
| 8.5.6 Ensure only organizers and co-organizers can present | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 8.5.8 Ensure external meeting chat is off | CONFIGURATION MANAGEMENT |
| 8.5.9 Ensure meeting recording is off by default | CONFIGURATION MANAGEMENT |
| 9.1.5 Ensure 'Interact with and share R and Python' visuals is 'Disabled' | CONFIGURATION MANAGEMENT |