| 1.1.1 Ensure Administrative accounts are cloud-only | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL |
| 1.3.1 Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)' | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 2.1.3 Ensure notifications for internal users sending malware is Enabled | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.6 Ensure Exchange Online Spam Policies are set to notify administrators | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.8 Ensure that SPF records are published for all Exchange Domains | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.1.9 Ensure that DKIM is enabled for all Exchange Online Domains | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.1.10 Ensure DMARC records for all Exchange Online domains are published | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.1.12 Ensure the connection filter IP allow list is not used | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 2.1.14 Ensure inbound anti-spam policies do not contain allowed domains | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | SYSTEM AND INFORMATION INTEGRITY |
| 3.3.1 Ensure Information Protection sensitivity label policies are published | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | RISK ASSESSMENT |
| 5.1.1 Ensure that 'security defaults' is Enabled in Microsoft Entra ID | CIS Microsoft Azure Foundations v6.0.0 L1 | microsoft_azure | CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION |
| 5.1.2.2 Ensure users cannot register applications | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| 5.1.2.3 Ensure 'Restrict non-admin users from creating tenants' is set to 'Yes' | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.3.3 Ensure that 'Owners can manage group membership requests in My Groups' is set to 'No' | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.4 Ensure that 'Allow users to remember multifactor authentication on devices they trust' is Disabled | CIS Microsoft Azure Foundations v6.0.0 L1 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.1.4.2 Ensure the maximum number of devices per user is limited | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 5.1.4.5 Ensure Local Administrator Password Solution is enabled | CIS Microsoft 365 Foundations v7.0.0 L1 E5 | microsoft_azure | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION |
| 5.1.4.5 Ensure Local Administrator Password Solution is enabled | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION |
| 5.1.5.2 Ensure the admin consent workflow is enabled | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION |
| 5.1.5.4 Ensure password lifetime for applications does not exceed 180 days | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.1.5.5 Ensure new application passwords are system-generated | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.1.8.1 Ensure that password hash sync is enabled for hybrid deployments | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL |
| 5.2.2.3 Enable Conditional Access policies to block legacy authentication | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 5.2.2.12 Ensure the device code sign-in flow is blocked | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 5.2.2.13 Ensure that periodic reauthentication is required for all users | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL |
| 5.2.3.2 Ensure custom banned passwords lists are used | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.3.5 Ensure weak authentication methods are disabled | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.3.6 Ensure system-preferred multifactor authentication is enabled | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.3.10 Ensure Microsoft Authenticator on companion applications is disabled | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 5.2.4.1 Ensure 'Self service password reset enabled' is set to 'All' | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | AWARENESS AND TRAINING |
| 5.2.4.3 Ensure SSPR registration and authentication re-confirmation are required | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL |
| 5.2.4.4 Ensure that users are notified on password resets | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | IDENTIFICATION AND AUTHENTICATION |
| 6.5.4 Ensure SMTP AUTH is disabled | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 7.2.7 Ensure link sharing is restricted in SharePoint and OneDrive | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, MEDIA PROTECTION |
| 7.2.11 Ensure the SharePoint default sharing link permission is set | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, MEDIA PROTECTION |
| 8.2.4 Ensure the organization cannot communicate with accounts in trial Teams tenants | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | CONFIGURATION MANAGEMENT |
| 8.5.7 Ensure external participants can't give or request control | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL |
| 9.1.8 Ensure enabling of external data sharing is restricted | CIS Microsoft 365 Foundations v7.0.0 L1 E3 | microsoft_azure | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MEDIA PROTECTION |
| CIS_Microsoft_Intune_for_Windows_10_v5.0.0_BL.audit from CIS Microsoft Intune for Windows 10 v5.0.0 | CIS Microsoft Intune for Windows 10 v5.0.0 BL | Windows | |
| CIS_Microsoft_Intune_for_Windows_10_v5.0.0_L1.audit from CIS Microsoft Intune for Windows 10 v5.0.0 | CIS Microsoft Intune for Windows 10 v5.0.0 L1 | Windows | |
| CIS_Microsoft_Intune_for_Windows_10_v5.0.0_NG.audit from CIS Microsoft Intune for Windows 10 v5.0.0 | CIS Microsoft Intune for Windows 10 v5.0.0 NG | Windows | |
| CIS_Microsoft_Intune_for_Windows_11_v5.0.0_BL.audit from CIS Microsoft Intune for Windows 11 v5.0.0 | CIS Microsoft Intune for Windows 11 v5.0.0 BL | Windows | |
| CIS_Microsoft_Intune_for_Windows_11_v5.0.0_L1.audit from CIS Microsoft Intune for Windows 11 v5.0.0 | CIS Microsoft Intune for Windows 11 v5.0.0 L1 | Windows | |
| CIS_Microsoft_Intune_for_Windows_11_v5.0.0_L2.audit from CIS Microsoft Intune for Windows 11 v5.0.0 | CIS Microsoft Intune for Windows 11 v5.0.0 L2 | Windows | |
| CIS_Microsoft_Windows_Server_2019_v5.0.0_L1_DC.audit from CIS Microsoft Windows Server 2019 v5.0.0 | CIS Microsoft Windows Server 2019 v5.0.0 L1 DC | Windows | |
| CIS_Microsoft_Windows_Server_2019_v5.0.0_L1_MS.audit from CIS Microsoft Windows Server 2019 v5.0.0 | CIS Microsoft Windows Server 2019 v5.0.0 L1 MS | Windows | |
| CIS_Microsoft_Windows_Server_2019_v5.0.0_L2_DC.audit from CIS Microsoft Windows Server 2019 v5.0.0 | CIS Microsoft Windows Server 2019 v5.0.0 L2 DC | Windows | |
| CIS_Microsoft_Windows_Server_2019_v5.0.0_L2_MS.audit from CIS Microsoft Windows Server 2019 v5.0.0 | CIS Microsoft Windows Server 2019 v5.0.0 L2 MS | Windows | |
| CIS_Microsoft_Windows_Server_2019_v5.0.0_NG_DC.audit from CIS Microsoft Windows Server 2019 v5.0.0 | CIS Microsoft Windows Server 2019 v5.0.0 NG DC | Windows | |
| CIS_Microsoft_Windows_Server_2019_v5.0.0_NG_MS.audit from CIS Microsoft Windows Server 2019 v5.0.0 | CIS Microsoft Windows Server 2019 v5.0.0 NG MS | Windows | |