| 1.2.1 Ensure that only organizationally managed/approved public groups exist | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL, MEDIA PROTECTION |
| 1.3.2 Ensure 'Idle session timeout' is set to '3 hours (or less)' for unmanaged devices | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL |
| 1.3.3 Ensure 'External sharing' of calendars is not available | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 1.3.4 Ensure 'User owned apps and services' is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 1.3.5 Ensure internal phishing protection for Forms is enabled | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | AWARENESS AND TRAINING, SYSTEM AND INFORMATION INTEGRITY |
| 1.3.7 Ensure 'third-party storage services' are restricted in 'Microsoft 365 on the web' | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL, MEDIA PROTECTION |
| 1.3.8 Ensure that Sways cannot be shared with people outside of your organization | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 2.1.11 Ensure comprehensive attachment filtering is applied | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 5.1.2.5 Ensure the option to remain signed in is hidden | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL |
| 5.1.2.6 Ensure 'LinkedIn account connections' is disabled | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 5.1.3 Ensure that 'multifactor authentication' is 'enabled' For All Users | CIS Microsoft Azure Foundations v6.0.0 L1 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.1.3.1 Ensure users cannot create security groups | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.3.2 Ensure that 'Restrict user ability to access groups features in My Groups' is set to 'Yes' | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.3.4 Ensure that 'Users can create Microsoft 365 groups in Azure portals, API or PowerShell' is set to 'No' | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.4.1 Ensure the ability to join devices to Entra is restricted | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.4.6 Ensure users are restricted from recovering BitLocker keys | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL, MEDIA PROTECTION |
| 5.1.5.1 Ensure user consent to apps accessing company data on their behalf is not allowed | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 5.1.5.3 Ensure password addition is blocked for applications | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.1.6.1 Ensure that collaboration invitations are sent to allowed domains only | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION |
| 5.1.6.3 Ensure guest user invitations are limited | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION |
| 5.2.2.5 Ensure 'Phishing-resistant MFA strength' is required for Administrators | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.2.10 Ensure a managed device is required to register security information | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 5.2.2.14 Ensure trusted 'named locations' are defined | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL, CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 5.2.2.15 Ensure exclusionary geographic access controls are utilized | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL |
| 5.2.2.16 Ensure Token Protection is enforced for session tokens | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.3.7 Ensure the email OTP authentication method is disabled | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.4.2 Ensure that 2 methods are required for password reset | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.4.5 Ensure all admins are notified when other admins reset their password | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL |
| 6.1.2 Ensure mailbox audit actions are configured | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | AUDIT AND ACCOUNTABILITY |
| 6.1.3 Ensure 'AuditBypassEnabled' is not enabled on mailboxes | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | AUDIT AND ACCOUNTABILITY |
| 6.2.3 Ensure email from external senders is identified | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 6.3.1 Ensure users installing Outlook add-ins is not allowed | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 6.5.3 Ensure additional storage providers are restricted in Outlook on the web | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION |
| 6.5.5 Ensure Direct Send submissions are rejected | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 7.2.3 Ensure external content sharing is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, MEDIA PROTECTION |
| 7.2.4 Ensure OneDrive content sharing is restricted | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL, MEDIA PROTECTION |
| 7.2.5 Ensure that SharePoint guest users cannot share items they don't own | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL, MEDIA PROTECTION |
| 7.2.6 Ensure SharePoint external sharing is restricted | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL, MEDIA PROTECTION |
| 8.1.1 Ensure external file sharing in Teams is enabled for only approved cloud storage services | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL, MEDIA PROTECTION |
| 8.1.2 Ensure users can't send emails to a channel email address | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 8.2.1 Ensure external domains are restricted in the Teams admin center | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION |
| 8.4.1 Ensure app permission policies are configured | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 8.5.1 Ensure anonymous users can't join a meeting | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL |
| 8.5.6 Ensure only organizers and co-organizers can present | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 8.5.9 Ensure meeting recording is off by default | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 9.1.2 Ensure external user invitations are restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 9.1.3 Ensure guest access to content is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION |
| 9.1.7 Ensure shareable links are restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, MEDIA PROTECTION |
| 9.1.10 Ensure access to APIs by service principals is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| CIS_Microsoft_Intune_for_Windows_10_v5.0.0_L2.audit from CIS Microsoft Intune for Windows 10 v5.0.0 | CIS Microsoft Intune for Windows 10 v5.0.0 L2 | Windows | |