Item Search

NameAudit NamePluginCategory
1.2.1 Ensure that only organizationally managed/approved public groups existCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

1.3.2 Ensure 'Idle session timeout' is set to '3 hours (or less)' for unmanaged devicesCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL

1.3.3 Ensure 'External sharing' of calendars is not availableCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

CONFIGURATION MANAGEMENT

1.3.4 Ensure 'User owned apps and services' is restrictedCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

CONFIGURATION MANAGEMENT

1.3.5 Ensure internal phishing protection for Forms is enabledCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

AWARENESS AND TRAINING, SYSTEM AND INFORMATION INTEGRITY

1.3.7 Ensure 'third-party storage services' are restricted in 'Microsoft 365 on the web'CIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

1.3.8 Ensure that Sways cannot be shared with people outside of your organizationCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

CONFIGURATION MANAGEMENT

2.1.11 Ensure comprehensive attachment filtering is appliedCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

SYSTEM AND INFORMATION INTEGRITY

5.1.2.5 Ensure the option to remain signed in is hiddenCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL

5.1.2.6 Ensure 'LinkedIn account connections' is disabledCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

CONFIGURATION MANAGEMENT

5.1.3 Ensure that 'multifactor authentication' is 'enabled' For All UsersCIS Microsoft Azure Foundations v6.0.0 L1microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.1.3.1 Ensure users cannot create security groupsCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.3.2 Ensure that 'Restrict user ability to access groups features in My Groups' is set to 'Yes'CIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.3.4 Ensure that 'Users can create Microsoft 365 groups in Azure portals, API or PowerShell' is set to 'No'CIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.4.1 Ensure the ability to join devices to Entra is restrictedCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.4.6 Ensure users are restricted from recovering BitLocker keysCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

5.1.5.1 Ensure user consent to apps accessing company data on their behalf is not allowedCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

CONFIGURATION MANAGEMENT

5.1.5.3 Ensure password addition is blocked for applicationsCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.1.6.1 Ensure that collaboration invitations are sent to allowed domains onlyCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

5.1.6.3 Ensure guest user invitations are limitedCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION

5.2.2.5 Ensure 'Phishing-resistant MFA strength' is required for AdministratorsCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.2.2.10 Ensure a managed device is required to register security informationCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

5.2.2.14 Ensure trusted 'named locations' are definedCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

5.2.2.15 Ensure exclusionary geographic access controls are utilizedCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL

5.2.2.16 Ensure Token Protection is enforced for session tokensCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.2.3.7 Ensure the email OTP authentication method is disabledCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.2.4.2 Ensure that 2 methods are required for password resetCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.2.4.5 Ensure all admins are notified when other admins reset their passwordCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

ACCESS CONTROL

6.1.2 Ensure mailbox audit actions are configuredCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

AUDIT AND ACCOUNTABILITY

6.1.3 Ensure 'AuditBypassEnabled' is not enabled on mailboxesCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

AUDIT AND ACCOUNTABILITY

6.2.3 Ensure email from external senders is identifiedCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

CONFIGURATION MANAGEMENT

6.3.1 Ensure users installing Outlook add-ins is not allowedCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

6.5.3 Ensure additional storage providers are restricted in Outlook on the webCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION

6.5.5 Ensure Direct Send submissions are rejectedCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

7.2.3 Ensure external content sharing is restrictedCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

7.2.4 Ensure OneDrive content sharing is restrictedCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

7.2.5 Ensure that SharePoint guest users cannot share items they don't ownCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

7.2.6 Ensure SharePoint external sharing is restrictedCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

8.1.1 Ensure external file sharing in Teams is enabled for only approved cloud storage servicesCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

8.1.2 Ensure users can't send emails to a channel email addressCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

CONFIGURATION MANAGEMENT

8.2.1 Ensure external domains are restricted in the Teams admin centerCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION

8.4.1 Ensure app permission policies are configuredCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

CONFIGURATION MANAGEMENT

8.5.1 Ensure anonymous users can't join a meetingCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL

8.5.6 Ensure only organizers and co-organizers can presentCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

8.5.9 Ensure meeting recording is off by defaultCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

CONFIGURATION MANAGEMENT

9.1.2 Ensure external user invitations are restrictedCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

9.1.3 Ensure guest access to content is restrictedCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

9.1.7 Ensure shareable links are restrictedCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

9.1.10 Ensure access to APIs by service principals is restrictedCIS Microsoft 365 Foundations v7.0.0 L1 E3microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

CIS_Microsoft_Intune_for_Windows_10_v5.0.0_L2.audit from CIS Microsoft Intune for Windows 10 v5.0.0CIS Microsoft Intune for Windows 10 v5.0.0 L2Windows