Item Search

NameAudit NamePluginCategory
1.1.3 Ensure that between two and four global admins are designatedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

1.2.2 Ensure sign-in to shared mailboxes is blockedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

CONFIGURATION MANAGEMENT

1.3.1 Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)'CIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

1.3.9 Ensure shared bookings pages are restricted to select usersCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

2.1.10 Ensure DMARC records for all Exchange Online domains are publishedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

SYSTEM AND COMMUNICATIONS PROTECTION

2.1.14 Ensure inbound anti-spam policies do not contain allowed domainsCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

SYSTEM AND INFORMATION INTEGRITY

3.2.2 Ensure DLP policies are enabled for Microsoft TeamsCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.2.3 Ensure DLP policies are published for Copilot usersCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

3.3.1 Ensure Information Protection sensitivity label policies are publishedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

RISK ASSESSMENT

4.1 Ensure devices without a compliance policy are marked 'not compliant'CIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

5.1.2.3 Ensure 'Restrict non-admin users from creating tenants' is set to 'Yes'CIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.4.3 Ensure the GA role is not added as a local administrator during Entra joinCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.5.2 Ensure the admin consent workflow is enabledCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

5.1.5.6 Ensure maximum certificate lifetime for applications does not exceed 180 daysCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.1.8.1 Ensure that password hash sync is enabled for hybrid deploymentsCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL

5.2.2.1 Ensure multifactor authentication is enabled for all users in administrative rolesCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.2.2.12 Ensure the device code sign-in flow is blockedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

CONFIGURATION MANAGEMENT

5.2.3.2 Ensure custom banned passwords lists are usedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.2.3.3 Ensure password protection is enabled for on-prem Active DirectoryCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.2.3.4 Ensure all member users are 'MFA capable'CIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.2.3.6 Ensure system-preferred multifactor authentication is enabledCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.2.3.8 Ensure that Account 'Lockout threshold' is '10' or lessCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL

5.2.3.9 Ensure that Account 'Lockout duration in seconds' is at least 60 secondsCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL

5.2.3.10 Ensure Microsoft Authenticator on companion applications is disabledCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.2.4.1 Ensure 'Self service password reset enabled' is set to 'All'CIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

AWARENESS AND TRAINING

5.2.4.3 Ensure SSPR registration and authentication re-confirmation are requiredCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL

5.2.4.5 Ensure all admins are notified when other admins reset their passwordCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL

5.3.4 Ensure approval is required for Global Administrator role activationCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

6.2.2 Ensure mail transport rules do not whitelist specific domainsCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

CONFIGURATION MANAGEMENT

6.3.2 Ensure the ability to add personal email accounts and calendars is disabledCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION

6.5.2 Ensure MailTips are enabled for end usersCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

CONFIGURATION MANAGEMENT

6.5.4 Ensure SMTP AUTH is disabledCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

CONFIGURATION MANAGEMENT

7.2.2 Ensure SharePoint and OneDrive integration with Azure AD B2B is enabledCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

CONFIGURATION MANAGEMENT

7.2.7 Ensure link sharing is restricted in SharePoint and OneDriveCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

7.2.9 Ensure guest access to a site or OneDrive will expire automaticallyCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL

8.1.2 Ensure users can't send emails to a channel email addressCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

CONFIGURATION MANAGEMENT

8.2.2 Ensure communication with unmanaged Teams users is disabledCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION

8.2.3 Ensure external Teams users cannot initiate conversationsCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION

8.2.4 Ensure the organization cannot communicate with accounts in trial Teams tenantsCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

CONFIGURATION MANAGEMENT

8.5.2 Ensure anonymous users and dial-in callers can't start a meetingCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL

8.5.3 Ensure only people in my org can bypass the lobbyCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

9.1.2 Ensure external user invitations are restrictedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

9.1.4 Ensure 'Publish to web' is restrictedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

9.1.6 Ensure 'Allow users to apply sensitivity labels for content' is 'Enabled'CIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

RISK ASSESSMENT

9.1.7 Ensure shareable links are restrictedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

9.1.8 Ensure enabling of external data sharing is restrictedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

9.1.10 Ensure access to APIs by service principals is restrictedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

9.1.11 Ensure service principals cannot create and use profilesCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

9.1.12 Ensure service principals ability to create workspaces, connections and deployment pipelines is restrictedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

DTOO404 - The first-run prompt to sign into Office365 must be disabled.DISA STIG Microsoft Office System 2013 v2r2Windows

CONFIGURATION MANAGEMENT