| 1.1.3 Ensure that between two and four global admins are designated | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 1.2.2 Ensure sign-in to shared mailboxes is blocked | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 1.3.1 Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)' | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 1.3.9 Ensure shared bookings pages are restricted to select users | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 2.1.10 Ensure DMARC records for all Exchange Online domains are published | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.1.14 Ensure inbound anti-spam policies do not contain allowed domains | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 3.2.2 Ensure DLP policies are enabled for Microsoft Teams | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 3.2.3 Ensure DLP policies are published for Copilot users | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 3.3.1 Ensure Information Protection sensitivity label policies are published | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | RISK ASSESSMENT |
| 4.1 Ensure devices without a compliance policy are marked 'not compliant' | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 5.1.2.3 Ensure 'Restrict non-admin users from creating tenants' is set to 'Yes' | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.4.3 Ensure the GA role is not added as a local administrator during Entra join | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.5.2 Ensure the admin consent workflow is enabled | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION |
| 5.1.5.6 Ensure maximum certificate lifetime for applications does not exceed 180 days | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.1.8.1 Ensure that password hash sync is enabled for hybrid deployments | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL |
| 5.2.2.1 Ensure multifactor authentication is enabled for all users in administrative roles | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.2.12 Ensure the device code sign-in flow is blocked | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 5.2.3.2 Ensure custom banned passwords lists are used | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.3.3 Ensure password protection is enabled for on-prem Active Directory | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.3.4 Ensure all member users are 'MFA capable' | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.3.6 Ensure system-preferred multifactor authentication is enabled | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.3.8 Ensure that Account 'Lockout threshold' is '10' or less | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL |
| 5.2.3.9 Ensure that Account 'Lockout duration in seconds' is at least 60 seconds | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL |
| 5.2.3.10 Ensure Microsoft Authenticator on companion applications is disabled | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.4.1 Ensure 'Self service password reset enabled' is set to 'All' | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | AWARENESS AND TRAINING |
| 5.2.4.3 Ensure SSPR registration and authentication re-confirmation are required | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL |
| 5.2.4.5 Ensure all admins are notified when other admins reset their password | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL |
| 5.3.4 Ensure approval is required for Global Administrator role activation | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION |
| 6.2.2 Ensure mail transport rules do not whitelist specific domains | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 6.3.2 Ensure the ability to add personal email accounts and calendars is disabled | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION |
| 6.5.2 Ensure MailTips are enabled for end users | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 6.5.4 Ensure SMTP AUTH is disabled | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 7.2.2 Ensure SharePoint and OneDrive integration with Azure AD B2B is enabled | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 7.2.7 Ensure link sharing is restricted in SharePoint and OneDrive | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, MEDIA PROTECTION |
| 7.2.9 Ensure guest access to a site or OneDrive will expire automatically | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL |
| 8.1.2 Ensure users can't send emails to a channel email address | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 8.2.2 Ensure communication with unmanaged Teams users is disabled | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION |
| 8.2.3 Ensure external Teams users cannot initiate conversations | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION |
| 8.2.4 Ensure the organization cannot communicate with accounts in trial Teams tenants | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 8.5.2 Ensure anonymous users and dial-in callers can't start a meeting | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL |
| 8.5.3 Ensure only people in my org can bypass the lobby | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 9.1.2 Ensure external user invitations are restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 9.1.4 Ensure 'Publish to web' is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION |
| 9.1.6 Ensure 'Allow users to apply sensitivity labels for content' is 'Enabled' | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | RISK ASSESSMENT |
| 9.1.7 Ensure shareable links are restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, MEDIA PROTECTION |
| 9.1.8 Ensure enabling of external data sharing is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION |
| 9.1.10 Ensure access to APIs by service principals is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| 9.1.11 Ensure service principals cannot create and use profiles | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| 9.1.12 Ensure service principals ability to create workspaces, connections and deployment pipelines is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| DTOO404 - The first-run prompt to sign into Office365 must be disabled. | DISA STIG Microsoft Office System 2013 v2r2 | Windows | CONFIGURATION MANAGEMENT |