Item Search

NameAudit NamePluginCategory
1.1.2 Ensure two emergency access accounts have been definedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL

1.1.4 Ensure administrative accounts use licenses with a reduced application footprintCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL

1.3.2 Ensure 'Idle session timeout' is set to '3 hours (or less)' for unmanaged devicesCIS Microsoft 365 Foundations v7.0.0 L2 E5microsoft_azure

ACCESS CONTROL

1.3.5 Ensure internal phishing protection for Forms is enabledCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

AWARENESS AND TRAINING, SYSTEM AND INFORMATION INTEGRITY

1.8 Ensure 'Attachment Filtering Agent' is configuredCIS Microsoft Exchange Server 2019 L1 Edge v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

2.1.2 Ensure the Common Attachment Types Filter is enabledCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

SYSTEM AND INFORMATION INTEGRITY

2.1.3 Ensure notifications for internal users sending malware is EnabledCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

SYSTEM AND INFORMATION INTEGRITY

2.1.6 Ensure Exchange Online Spam Policies are set to notify administratorsCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

SYSTEM AND INFORMATION INTEGRITY

2.1.12 Ensure the connection filter IP allow list is not usedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

SYSTEM AND INFORMATION INTEGRITY

2.1.13 Ensure the connection filter safe list is offCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

SYSTEM AND INFORMATION INTEGRITY

2.1.15 Ensure outbound anti-spam message limits are in placeCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

SYSTEM AND INFORMATION INTEGRITY

2.2.1 Ensure emergency access account activity is monitoredCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

AUDIT AND ACCOUNTABILITY

2.3.22.2 Ensure 'Block signing into Office' is set to 'Enabled: Org ID only'CIS Microsoft Office Enterprise v1.2.0 L1Windows

ACCESS CONTROL

2.4.1 Ensure Priority account protection is enabled and configuredCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

SYSTEM AND INFORMATION INTEGRITY

2.4.2 Ensure Priority accounts have 'Strict protection' presets appliedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

SYSTEM AND INFORMATION INTEGRITY

2.4.4 Ensure Zero-hour auto purge for Microsoft Teams is onCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

SYSTEM AND INFORMATION INTEGRITY

2.4.5 Ensure 'AIR' remediation is enabledCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

SYSTEM AND INFORMATION INTEGRITY

3.1.1 Ensure Microsoft 365 audit log search is EnabledCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

AUDIT AND ACCOUNTABILITY

4.2 Ensure device enrollment for personally owned devices is blocked by defaultCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

CONFIGURATION MANAGEMENT

5.1.2.1 Ensure 'Per-user MFA' is disabledCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

CONFIGURATION MANAGEMENT

5.1.2.4 Ensure access to the Entra admin center is restrictedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

5.1.3.1 Ensure users cannot create security groupsCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.3.3 Ensure that 'Owners can manage group membership requests in My Groups' is set to 'No'CIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.3.4 Ensure that 'Users can create Microsoft 365 groups in Azure portals, API or PowerShell' is set to 'No'CIS Microsoft 365 Foundations v7.0.0 L2 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.4.4 Ensure local administrator assignment is limited during Entra joinCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.5.5 Ensure new application passwords are system-generatedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.2.2.2 Ensure multifactor authentication is enabled for all usersCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.2.2.4 Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative usersCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL

5.2.2.6 Enable Identity Protection user risk policiesCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

AUDIT AND ACCOUNTABILITY

5.2.2.7 Enable Identity Protection sign-in risk policiesCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION

5.2.2.9 Ensure a managed device is required for authenticationCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

5.2.2.10 Ensure a managed device is required to register security informationCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

5.2.2.17 Ensure authentication transfer is blockedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

5.2.3.5 Ensure weak authentication methods are disabledCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.3.5 Ensure approval is required for Privileged Role Administrator activationCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

6.1.1 Ensure 'AuditDisabled' organizationally is set to 'False'CIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

AUDIT AND ACCOUNTABILITY

6.2.1 Ensure all forms of mail forwarding are blocked and/or disabledCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL

6.5.1 Ensure modern authentication for Exchange Online is enabledCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL

7.2.1 Ensure modern authentication for SharePoint applications is requiredCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL

7.2.8 Ensure external sharing is restricted by security groupCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

7.2.11 Ensure the SharePoint default sharing link permission is setCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

8.4.1 Ensure app permission policies are configuredCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

CONFIGURATION MANAGEMENT

8.5.5 Ensure meeting chat does not allow anonymous usersCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

ACCESS CONTROL

8.5.8 Ensure external meeting chat is offCIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

CONFIGURATION MANAGEMENT

9.1.1 Ensure guest user access is restrictedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

9.1.3 Ensure guest access to content is restrictedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

9.1.5 Ensure 'Interact with and share R and Python' visuals is 'Disabled'CIS Microsoft 365 Foundations v7.0.0 L2 E3microsoft_azure

CONFIGURATION MANAGEMENT

CIS_Microsoft_Office_365_ProPlus_STIG_v1.1.0_CAT_I.audit from CIS Microsoft Office 365 ProPlus STIG v1.1.0CIS Microsoft Office 365 ProPlus STIG v1.1.0 CAT IWindows
CIS_Microsoft_Office_365_ProPlus_STIG_v1.1.0_CAT_II.audit from CIS Microsoft Office 365 ProPlus STIG v1.1.0CIS Microsoft Office 365 ProPlus STIG v1.1.0 CAT IIWindows
MS.EXO.3.1v1 - DKIM SHOULD be enabled for all domains.CISA SCuBA Microsoft 365 Exchange Online v1.5.0microsoft_azure

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY