| 1.1.2 Ensure two emergency access accounts have been defined | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL |
| 1.1.3 Ensure that between two and four global admins are designated | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 1.1.4 Ensure administrative accounts use licenses with a reduced application footprint | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL |
| 1.2.2 Ensure sign-in to shared mailboxes is blocked | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 1.3.9 Ensure shared bookings pages are restricted to select users | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 2.1.2 Ensure the Common Attachment Types Filter is enabled | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.13 Ensure the connection filter safe list is off | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.15 Ensure outbound anti-spam message limits are in place | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 3.1.1 Ensure Microsoft 365 audit log search is Enabled | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | AUDIT AND ACCOUNTABILITY |
| 3.2.1 Ensure DLP policies are enabled | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.1 Ensure devices without a compliance policy are marked 'not compliant' | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 4.2 Ensure device enrollment for personally owned devices is blocked by default | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 5.1.2.1 Ensure 'Per-user MFA' is disabled | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 5.1.2.4 Ensure access to the Entra admin center is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION |
| 5.1.4.3 Ensure the GA role is not added as a local administrator during Entra join | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.4.4 Ensure local administrator assignment is limited during Entra join | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.5.6 Ensure maximum certificate lifetime for applications does not exceed 180 days | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.1.6.2 Ensure that guest user access is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION |
| 5.2.2.1 Ensure multifactor authentication is enabled for all users in administrative roles | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.2.2 Ensure multifactor authentication is enabled for all users | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.2.4 Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative users | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL |
| 5.2.2.9 Ensure a managed device is required for authentication | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 5.2.2.11 Ensure sign-in frequency for Intune Enrollment is set to 'Every time' | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.2.17 Ensure authentication transfer is blocked | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 5.2.3.1 Ensure Microsoft Authenticator is configured to protect against MFA fatigue | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.3.3 Ensure password protection is enabled for on-prem Active Directory | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.3.4 Ensure all member users are 'MFA capable' | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.3.8 Ensure that Account 'Lockout threshold' is '10' or less | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL |
| 5.2.3.9 Ensure that Account 'Lockout duration in seconds' is at least 60 seconds | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL |
| 6.1.1 Ensure 'AuditDisabled' organizationally is set to 'False' | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | AUDIT AND ACCOUNTABILITY |
| 6.2.1 Ensure all forms of mail forwarding are blocked and/or disabled | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL |
| 6.2.2 Ensure mail transport rules do not whitelist specific domains | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 6.3.2 Ensure the ability to add personal email accounts and calendars is disabled | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION |
| 6.5.1 Ensure modern authentication for Exchange Online is enabled | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL |
| 6.5.2 Ensure MailTips are enabled for end users | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 7.2.1 Ensure modern authentication for SharePoint applications is required | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL |
| 7.2.2 Ensure SharePoint and OneDrive integration with Azure AD B2B is enabled | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 7.2.9 Ensure guest access to a site or OneDrive will expire automatically | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL |
| 7.2.10 Ensure reauthentication with verification code is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 8.2.2 Ensure communication with unmanaged Teams users is disabled | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION |
| 8.2.3 Ensure external Teams users cannot initiate conversations | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION |
| 8.5.2 Ensure anonymous users and dial-in callers can't start a meeting | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL |
| 8.5.3 Ensure only people in my org can bypass the lobby | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 8.5.4 Ensure users dialing in can't bypass the lobby | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL |
| 9.1.1 Ensure guest user access is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION |
| 9.1.4 Ensure 'Publish to web' is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION |
| 9.1.6 Ensure 'Allow users to apply sensitivity labels for content' is 'Enabled' | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | RISK ASSESSMENT |
| 9.1.9 Ensure 'Block ResourceKey Authentication' is 'Enabled' | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 9.1.11 Ensure service principals cannot create and use profiles | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| 9.1.12 Ensure service principals ability to create workspaces, connections and deployment pipelines is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |