Item Search

NameAudit NamePluginCategory
1.1.1 Ensure Administrative accounts are cloud-onlyCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL

1.2.1 Ensure that only organizationally managed/approved public groups existCIS Microsoft 365 Foundations v7.0.0 L2 E5microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

1.3.3 Ensure 'External sharing' of calendars is not availableCIS Microsoft 365 Foundations v7.0.0 L2 E5microsoft_azure

CONFIGURATION MANAGEMENT

1.3.4 Ensure 'User owned apps and services' is restrictedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

CONFIGURATION MANAGEMENT

1.3.7 Ensure 'third-party storage services' are restricted in 'Microsoft 365 on the web'CIS Microsoft 365 Foundations v7.0.0 L2 E5microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

2.1.1 Ensure Safe Links for Office Applications is EnabledCIS Microsoft 365 Foundations v7.0.0 L2 E5microsoft_azure

SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

2.1.8 Ensure that SPF records are published for all Exchange DomainsCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

SYSTEM AND COMMUNICATIONS PROTECTION

2.1.9 Ensure that DKIM is enabled for all Exchange Online DomainsCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

SYSTEM AND COMMUNICATIONS PROTECTION

2.3.25.1.1 Ensure 'Allow users to submit feedback to Microsoft' is set to 'Disabled'CIS Microsoft Office Enterprise v1.2.0 L1Windows

CONFIGURATION MANAGEMENT

2.3.39.1 (L1) Ensure 'Send Office Feedback' is set to 'Disabled'CIS Microsoft Intune for Office v1.1.0 L1Windows

CONFIGURATION MANAGEMENT

2.4.3 Ensure Microsoft Defender for Cloud Apps is enabled and configuredCIS Microsoft 365 Foundations v7.0.0 L2 E5microsoft_azure

AUDIT AND ACCOUNTABILITY, INCIDENT RESPONSE, SYSTEM AND INFORMATION INTEGRITY

3.2.1 Ensure DLP policies are enabledCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.1.2.2 Ensure users cannot register applicationsCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

5.1.3.2 Ensure that 'Restrict user ability to access groups features in My Groups' is set to 'Yes'CIS Microsoft 365 Foundations v7.0.0 L2 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.4.1 Ensure the ability to join devices to Entra is restrictedCIS Microsoft 365 Foundations v7.0.0 L2 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.4.2 Ensure the maximum number of devices per user is limitedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.1.5.4 Ensure password lifetime for applications does not exceed 180 daysCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.1.6.2 Ensure that guest user access is restrictedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION

5.1.6.3 Ensure guest user invitations are limitedCIS Microsoft 365 Foundations v7.0.0 L2 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION

5.2.2.3 Enable Conditional Access policies to block legacy authenticationCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

CONFIGURATION MANAGEMENT

5.2.2.5 Ensure 'Phishing-resistant MFA strength' is required for AdministratorsCIS Microsoft 365 Foundations v7.0.0 L2 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.2.2.11 Ensure sign-in frequency for Intune Enrollment is set to 'Every time'CIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.2.2.13 Ensure that periodic reauthentication is required for all usersCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL

5.2.2.16 Ensure Token Protection is enforced for session tokensCIS Microsoft 365 Foundations v7.0.0 L2 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.2.3.1 Ensure Microsoft Authenticator is configured to protect against MFA fatigueCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.2.3.7 Ensure the email OTP authentication method is disabledCIS Microsoft 365 Foundations v7.0.0 L2 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.2.4.4 Ensure that users are notified on password resetsCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

5.3.2 Ensure 'Access reviews' for guest users are configuredCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

5.3.3 Ensure 'Access reviews' for privileged roles are configuredCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

6.1.2 Ensure mailbox audit actions are configuredCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

AUDIT AND ACCOUNTABILITY

6.1.3 Ensure 'AuditBypassEnabled' is not enabled on mailboxesCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

AUDIT AND ACCOUNTABILITY

6.2.3 Ensure email from external senders is identifiedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

CONFIGURATION MANAGEMENT

7.2.3 Ensure external content sharing is restrictedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

7.2.5 Ensure that SharePoint guest users cannot share items they don't ownCIS Microsoft 365 Foundations v7.0.0 L2 E5microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

7.2.6 Ensure SharePoint external sharing is restrictedCIS Microsoft 365 Foundations v7.0.0 L2 E5microsoft_azure

ACCESS CONTROL, MEDIA PROTECTION

7.2.10 Ensure reauthentication with verification code is restrictedCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

IDENTIFICATION AND AUTHENTICATION

8.2.1 Ensure external domains are restricted in the Teams admin centerCIS Microsoft 365 Foundations v7.0.0 L2 E5microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION

8.5.4 Ensure users dialing in can't bypass the lobbyCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL

8.5.6 Ensure only organizers and co-organizers can presentCIS Microsoft 365 Foundations v7.0.0 L2 E5microsoft_azure

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

8.5.7 Ensure external participants can't give or request controlCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

ACCESS CONTROL

8.5.8 Ensure external meeting chat is offCIS Microsoft 365 Foundations v7.0.0 L2 E5microsoft_azure

CONFIGURATION MANAGEMENT

8.6.1 Ensure users can report security concerns in TeamsCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

INCIDENT RESPONSE

9.1.9 Ensure 'Block ResourceKey Authentication' is 'Enabled'CIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

CONFIGURATION MANAGEMENT

18.10.43.6 Ensure 'Turn on Microsoft Defender Application Guard in Managed Mode' is set to 'Enabled: 1'CIS Microsoft Windows 11 Enterprise v5.1.0 L1Windows

SYSTEM AND INFORMATION INTEGRITY

DTOO403 - The video informing a user about signing into Office365 must be disabled.DISA STIG Microsoft Office System 2013 v2r2Windows

CONFIGURATION MANAGEMENT

DTOO405 - The ability to sign into Office365 must be disabled.DISA STIG Microsoft Office System 2013 v2r2Windows

CONFIGURATION MANAGEMENT

EDGE-00-000069 - Access to Microsoft 365 Copilot writing assistance must be disabled.DISA Microsoft Edge STIG v2r5Windows

CONFIGURATION MANAGEMENT

MS.AAD.5.2v1 - Only administrators SHALL be allowed to consent to applications.CISA SCuBA Microsoft 365 Entra ID v1.5.0microsoft_azure

ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

MS.DEFENDER.3.1v1 - Safe attachments SHOULD be enabled for SharePoint, OneDrive, and Microsoft Teams.CISA SCuBA Microsoft 365 Defender v1.5.0microsoft_azure

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

MS.EXO.12.1v1 - IP allow lists SHOULD NOT be created.CISA SCuBA Microsoft 365 Exchange Online v1.5.0microsoft_azure

CONFIGURATION MANAGEMENT