| 1.1.1 Ensure Administrative accounts are cloud-only | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL |
| 1.2.1 Ensure that only organizationally managed/approved public groups exist | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL, MEDIA PROTECTION |
| 1.3.3 Ensure 'External sharing' of calendars is not available | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 1.3.4 Ensure 'User owned apps and services' is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 1.3.7 Ensure 'third-party storage services' are restricted in 'Microsoft 365 on the web' | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL, MEDIA PROTECTION |
| 2.1.1 Ensure Safe Links for Office Applications is Enabled | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| 2.1.8 Ensure that SPF records are published for all Exchange Domains | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.1.9 Ensure that DKIM is enabled for all Exchange Online Domains | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.3.25.1.1 Ensure 'Allow users to submit feedback to Microsoft' is set to 'Disabled' | CIS Microsoft Office Enterprise v1.2.0 L1 | Windows | CONFIGURATION MANAGEMENT |
| 2.3.39.1 (L1) Ensure 'Send Office Feedback' is set to 'Disabled' | CIS Microsoft Intune for Office v1.1.0 L1 | Windows | CONFIGURATION MANAGEMENT |
| 2.4.3 Ensure Microsoft Defender for Cloud Apps is enabled and configured | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | AUDIT AND ACCOUNTABILITY, INCIDENT RESPONSE, SYSTEM AND INFORMATION INTEGRITY |
| 3.2.1 Ensure DLP policies are enabled | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.1.2.2 Ensure users cannot register applications | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| 5.1.3.2 Ensure that 'Restrict user ability to access groups features in My Groups' is set to 'Yes' | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.4.1 Ensure the ability to join devices to Entra is restricted | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.4.2 Ensure the maximum number of devices per user is limited | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.5.4 Ensure password lifetime for applications does not exceed 180 days | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.1.6.2 Ensure that guest user access is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION |
| 5.1.6.3 Ensure guest user invitations are limited | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION |
| 5.2.2.3 Enable Conditional Access policies to block legacy authentication | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 5.2.2.5 Ensure 'Phishing-resistant MFA strength' is required for Administrators | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.2.11 Ensure sign-in frequency for Intune Enrollment is set to 'Every time' | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.2.13 Ensure that periodic reauthentication is required for all users | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL |
| 5.2.2.16 Ensure Token Protection is enforced for session tokens | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.3.1 Ensure Microsoft Authenticator is configured to protect against MFA fatigue | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.3.7 Ensure the email OTP authentication method is disabled | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.4.4 Ensure that users are notified on password resets | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.3.2 Ensure 'Access reviews' for guest users are configured | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.3.3 Ensure 'Access reviews' for privileged roles are configured | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 6.1.2 Ensure mailbox audit actions are configured | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | AUDIT AND ACCOUNTABILITY |
| 6.1.3 Ensure 'AuditBypassEnabled' is not enabled on mailboxes | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | AUDIT AND ACCOUNTABILITY |
| 6.2.3 Ensure email from external senders is identified | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 7.2.3 Ensure external content sharing is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, MEDIA PROTECTION |
| 7.2.5 Ensure that SharePoint guest users cannot share items they don't own | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL, MEDIA PROTECTION |
| 7.2.6 Ensure SharePoint external sharing is restricted | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL, MEDIA PROTECTION |
| 7.2.10 Ensure reauthentication with verification code is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 8.2.1 Ensure external domains are restricted in the Teams admin center | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL, CONFIGURATION MANAGEMENT, MEDIA PROTECTION |
| 8.5.4 Ensure users dialing in can't bypass the lobby | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL |
| 8.5.6 Ensure only organizers and co-organizers can present | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 8.5.7 Ensure external participants can't give or request control | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL |
| 8.5.8 Ensure external meeting chat is off | CIS Microsoft 365 Foundations v7.0.0 L2 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 8.6.1 Ensure users can report security concerns in Teams | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | INCIDENT RESPONSE |
| 9.1.9 Ensure 'Block ResourceKey Authentication' is 'Enabled' | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 18.10.43.6 Ensure 'Turn on Microsoft Defender Application Guard in Managed Mode' is set to 'Enabled: 1' | CIS Microsoft Windows 11 Enterprise v5.1.0 L1 | Windows | SYSTEM AND INFORMATION INTEGRITY |
| DTOO403 - The video informing a user about signing into Office365 must be disabled. | DISA STIG Microsoft Office System 2013 v2r2 | Windows | CONFIGURATION MANAGEMENT |
| DTOO405 - The ability to sign into Office365 must be disabled. | DISA STIG Microsoft Office System 2013 v2r2 | Windows | CONFIGURATION MANAGEMENT |
| EDGE-00-000069 - Access to Microsoft 365 Copilot writing assistance must be disabled. | DISA Microsoft Edge STIG v2r5 | Windows | CONFIGURATION MANAGEMENT |
| MS.AAD.5.2v1 - Only administrators SHALL be allowed to consent to applications. | CISA SCuBA Microsoft 365 Entra ID v1.5.0 | microsoft_azure | ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| MS.DEFENDER.3.1v1 - Safe attachments SHOULD be enabled for SharePoint, OneDrive, and Microsoft Teams. | CISA SCuBA Microsoft 365 Defender v1.5.0 | microsoft_azure | ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY |
| MS.EXO.12.1v1 - IP allow lists SHOULD NOT be created. | CISA SCuBA Microsoft 365 Exchange Online v1.5.0 | microsoft_azure | CONFIGURATION MANAGEMENT |