| 1.1.2 Ensure two emergency access accounts have been defined | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL |
| 1.1.4 Ensure administrative accounts use licenses with a reduced application footprint | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL |
| 1.3.2 Ensure 'Idle session timeout' is set to '3 hours (or less)' for unmanaged devices | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL |
| 1.3.5 Ensure internal phishing protection for Forms is enabled | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | AWARENESS AND TRAINING, SYSTEM AND INFORMATION INTEGRITY |
| 1.8 Ensure 'Attachment Filtering Agent' is configured | CIS Microsoft Exchange Server 2019 L1 Edge v1.0.0 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.2 Ensure the Common Attachment Types Filter is enabled | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.3 Ensure notifications for internal users sending malware is Enabled | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.6 Ensure Exchange Online Spam Policies are set to notify administrators | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.12 Ensure the connection filter IP allow list is not used | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.13 Ensure the connection filter safe list is off | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.15 Ensure outbound anti-spam message limits are in place | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 2.2.1 Ensure emergency access account activity is monitored | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | AUDIT AND ACCOUNTABILITY |
| 2.3.22.2 Ensure 'Block signing into Office' is set to 'Enabled: Org ID only' | CIS Microsoft Office Enterprise v1.2.0 L1 | Windows | ACCESS CONTROL |
| 2.4.1 Ensure Priority account protection is enabled and configured | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 2.4.2 Ensure Priority accounts have 'Strict protection' presets applied | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 2.4.4 Ensure Zero-hour auto purge for Microsoft Teams is on | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 2.4.5 Ensure 'AIR' remediation is enabled | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 3.1.1 Ensure Microsoft 365 audit log search is Enabled | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | AUDIT AND ACCOUNTABILITY |
| 4.2 Ensure device enrollment for personally owned devices is blocked by default | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 5.1.2.1 Ensure 'Per-user MFA' is disabled | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 5.1.2.4 Ensure access to the Entra admin center is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION |
| 5.1.3.1 Ensure users cannot create security groups | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.3.3 Ensure that 'Owners can manage group membership requests in My Groups' is set to 'No' | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.3.4 Ensure that 'Users can create Microsoft 365 groups in Azure portals, API or PowerShell' is set to 'No' | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.4.4 Ensure local administrator assignment is limited during Entra join | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.5.5 Ensure new application passwords are system-generated | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.2.2 Ensure multifactor authentication is enabled for all users | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.2.4 Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative users | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL |
| 5.2.2.6 Enable Identity Protection user risk policies | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | AUDIT AND ACCOUNTABILITY |
| 5.2.2.7 Enable Identity Protection sign-in risk policies | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION |
| 5.2.2.9 Ensure a managed device is required for authentication | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 5.2.2.10 Ensure a managed device is required to register security information | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 5.2.2.17 Ensure authentication transfer is blocked | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 5.2.3.5 Ensure weak authentication methods are disabled | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.3.5 Ensure approval is required for Privileged Role Administrator activation | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION |
| 6.1.1 Ensure 'AuditDisabled' organizationally is set to 'False' | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | AUDIT AND ACCOUNTABILITY |
| 6.2.1 Ensure all forms of mail forwarding are blocked and/or disabled | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL |
| 6.5.1 Ensure modern authentication for Exchange Online is enabled | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL |
| 7.2.1 Ensure modern authentication for SharePoint applications is required | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL |
| 7.2.8 Ensure external sharing is restricted by security group | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION |
| 7.2.11 Ensure the SharePoint default sharing link permission is set | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, MEDIA PROTECTION |
| 8.4.1 Ensure app permission policies are configured | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 8.5.5 Ensure meeting chat does not allow anonymous users | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | ACCESS CONTROL |
| 8.5.8 Ensure external meeting chat is off | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 9.1.1 Ensure guest user access is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION |
| 9.1.3 Ensure guest access to content is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION |
| 9.1.5 Ensure 'Interact with and share R and Python' visuals is 'Disabled' | CIS Microsoft 365 Foundations v7.0.0 L2 E3 | microsoft_azure | CONFIGURATION MANAGEMENT |
| CIS_Microsoft_Office_365_ProPlus_STIG_v1.1.0_CAT_I.audit from CIS Microsoft Office 365 ProPlus STIG v1.1.0 | CIS Microsoft Office 365 ProPlus STIG v1.1.0 CAT I | Windows | |
| CIS_Microsoft_Office_365_ProPlus_STIG_v1.1.0_CAT_II.audit from CIS Microsoft Office 365 ProPlus STIG v1.1.0 | CIS Microsoft Office 365 ProPlus STIG v1.1.0 CAT II | Windows | |
| MS.EXO.3.1v1 - DKIM SHOULD be enabled for all domains. | CISA SCuBA Microsoft 365 Exchange Online v1.5.0 | microsoft_azure | ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |