Also contributed to
- CIS.M365.1.1.1(L1) Ensure Administrative accounts are cloud-only
- CIS.M365.1.1.3(L1) Ensure that between two and four global admins are designated
- CIS.M365.1.2.1(L2) Ensure that only organizationally managed/approved public groups exist
- CIS.M365.1.2.2(L1) Ensure sign-in to shared mailboxes is blocked
- CIS.M365.1.3.1(L1) Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)'
- CIS.M365.1.3.3(L2) Ensure 'External sharing' of calendars is not available
- CIS.M365.1.3.4Ensure
- CIS.M365.1.3.5Ensure internal phishing protection for Forms is enabled
- CIS.M365.1.3.6(L2) Ensure the customer lockbox feature is enabled
- CIS.M365.2.1.1(L2) Ensure Safe Links for Office Applications is Enabled (Only Checks Default Policy)
- CIS.M365.2.1.2(L1) Ensure the Common Attachment Types Filter is enabled (Only Checks Default Policy)
- CIS.M365.2.1.3(L1) Ensure notifications for internal users sending malware is Enabled (Only Checks Default Policy)
- CIS.M365.2.1.4(L2) Ensure Safe Attachments policy is enabled (Only Checks Default Policy)
- CIS.M365.2.1.5(L2) Ensure Safe Attachments for SharePoint, OneDrive, and Microsoft Teams is Enabled
- CIS.M365.2.1.6(L1) Ensure Exchange Online Spam Policies are set to notify administrators (Only Checks Default Policy)
- CIS.M365.2.1.7(L1) Ensure that an anti-phishing policy has been created (Only Checks Default Policy)
- CIS.M365.2.1.9(L1) Ensure that DKIM is enabled for all Exchange Online Domains
- CIS.M365.2.1.11(L2) Ensure comprehensive attachment filtering is applied
- CIS.M365.2.1.12(L1) Ensure the connection filter IP allow list is not used (Only Checks Default Policy)
- CIS.M365.2.1.13(L1) Ensure the connection filter safe list is off (Only Checks Default Policy)
- CIS.M365.2.4.4(L1) Ensure Zero-hour auto purge for Microsoft Teams is on (Only Checks ZAP is enabled)
- CIS.M365.3.1.1(L1) Ensure Microsoft 365 audit log search is Enabled
- CIS.M365.4.1Ensure devices without a compliance policy are marked
- CIS.M365.5.1.2.2Ensure third party integrated applications are not allowed
- CIS.M365.5.1.2.3Ensure
- CIS.M365.5.1.3.1Ensure a dynamic group for guest users is created
- CIS.M365.5.1.4.6Ensure users are restricted from recovering BitLocker keys
- CIS.M365.5.1.5.1Ensure user consent to apps accessing company data on their behalf is not allowed
- CIS.M365.5.1.5.2Ensure the admin consent workflow is enabled
- CIS.M365.5.1.6.2Ensure that guest user access is restricted
- CIS.M365.5.2.3.5Ensure weak authentication methods are disabled
- CIS.M365.6.5.3Ensure additional storage providers are restricted in Outlook on the web
- CIS.M365.7.2.2Ensure SharePoint and OneDrive integration with Azure AD B2B is enabled
- CIS.M365.7.2.5Ensure that SharePoint guest users cannot share items they don
- CIS.M365.7.2.7Ensure link sharing is restricted in SharePoint and OneDrive
- CIS.M365.7.2.9Ensure guest access to a site or OneDrive will expire automatically
- CIS.M365.7.2.11Ensure the SharePoint default sharing link permission is set
- CIS.M365.7.3.1Ensure Office 365 SharePoint infected files are disallowed for download
- CIS.M365.8.1.1(L2) Ensure external file sharing in Teams is enabled for only approved cloud storage services
- CIS.M365.8.2.2(L1) Ensure communication with unmanaged Teams users is disabled
- CIS.M365.8.2.3Ensure external Teams users cannot initiate conversations
- CIS.M365.8.4.1(L1) Ensure all or a majority of third-party and custom apps are blocked
- CIS.M365.8.5.3(L1) Ensure only people in my org can bypass the lobby
- CIS.M365.8.6.1(L1) Ensure users can report security concerns in Teams to internal destination
- CISA.MS.AAD.1.1Legacy authentication SHALL be blocked.
- CISA.MS.AAD.2.1Users detected as high risk SHALL be blocked.
- CISA.MS.AAD.2.2A notification SHOULD be sent to the administrator when high-risk users are detected.
- CISA.MS.AAD.2.3Sign-ins detected as high risk SHALL be blocked.
- CISA.MS.AAD.3.1Phishing-resistant MFA SHALL be enforced for all users.
- CISA.MS.AAD.3.2If phishing-resistant MFA has not been enforced, an alternative MFA method SHALL be enforced for all users.
- CISA.MS.AAD.3.4The Authentication Methods Manage Migration feature SHALL be set to Migration Complete.
- CISA.MS.AAD.3.6Phishing-resistant MFA SHALL be required for highly privileged roles.
- CISA.MS.AAD.3.7Managed devices SHOULD be required for authentication.
- CISA.MS.AAD.3.8Managed Devices SHOULD be required to register MFA.
- CISA.MS.AAD.5.2Only administrators SHALL be allowed to consent to applications.
- CISA.MS.AAD.6.1User passwords SHALL NOT expire.
- CISA.MS.AAD.7.2Privileged users SHALL be provisioned with finer-grained roles instead of Global Administrator.
- CISA.MS.AAD.7.4Permanent active role assignments SHALL NOT be allowed for highly privileged roles.
- CISA.MS.AAD.7.5Provisioning users to highly privileged roles SHALL NOT occur outside of a PAM system.
- CISA.MS.AAD.7.6Activation of the Global Administrator role SHALL require approval.
- CISA.MS.AAD.7.8User activation of the Global Administrator role SHALL trigger an alert.
- CISA.MS.AAD.7.9User activation of other highly privileged roles SHOULD trigger an alert.
- CISA.MS.EXO.2.1A list of approved IP addresses for sending mail SHALL be maintained.
- CISA.MS.EXO.2.2An SPF policy SHALL be published for each domain, designating only these addresses as approved senders.
- CISA.MS.EXO.3.1DKIM SHOULD be enabled for all domains.
- CISA.MS.EXO.4.1A DMARC policy SHALL be published for every second-level domain.
- CISA.MS.EXO.9.1Emails SHALL be filtered by attachment file types.
- CISA.MS.EXO.9.2The attachment filter SHOULD attempt to determine the true file type and assess the file extension.
- CISA.MS.EXO.9.3Disallowed file types SHALL be determined and enforced.
- CISA.MS.EXO.9.4Alternatively chosen filtering solutions SHOULD offer services comparable to Microsoft Defender's Common Attachment Filter.
- CISA.MS.EXO.9.5At a minimum, click-to-run files SHOULD be blocked (e.g., .exe, .cmd, and .vbe).
- CISA.MS.EXO.10.1Emails SHALL be scanned for malware.
- CISA.MS.EXO.10.2Emails identified as containing malware SHALL be quarantined or dropped.
- CISA.MS.EXO.10.3Email scanning SHALL be capable of reviewing emails after delivery.
- CISA.MS.EXO.11.1Impersonation protection checks SHOULD be used.
- CISA.MS.EXO.11.2User warnings, comparable to the user safety tips included with EOP, SHOULD be displayed.
- CISA.MS.EXO.11.3The phishing protection solution SHOULD include an AI-based phishing detection tool comparable to EOP Mailbox Intelligence.
- CISA.MS.EXO.13.1Mailbox auditing SHALL be enabled.
- CISA.MS.EXO.14.1A spam filter SHALL be enabled.
- CISA.MS.EXO.14.2Spam and high confidence spam SHALL be moved to either the junk email folder or the quarantine folder.
- CISA.MS.EXO.14.3Allowed domains SHALL NOT be added to inbound anti-spam protection policies.
- CISA.MS.EXO.14.4If a third-party party filtering solution is used, the solution SHOULD offer services comparable to the native spam filtering offered by Microsoft.
- CISA.MS.EXO.17.2Microsoft Purview Audit (Premium) logging SHALL be enabled.
- CISA.MS.EXO.17.3Audit logs SHALL be maintained for at least the minimum duration dictated by OMB M-21-31 (Appendix C).
- EIDSCA.AF01Authentication Method - FIDO2 security key - State.
- EIDSCA.AF02Authentication Method - FIDO2 security key - Allow self-service set up.
- EIDSCA.AF03Authentication Method - FIDO2 security key - Enforce attestation.
- EIDSCA.AF04Authentication Method - FIDO2 security key - Enforce key restrictions.
- EIDSCA.AF05Authentication Method - FIDO2 security key - Restricted.
- EIDSCA.AF06Authentication Method - FIDO2 security key - Restrict specific keys.
- EIDSCA.AG01Authentication Method - General Settings - Manage migration.
- EIDSCA.AG02Authentication Method - General Settings - Report suspicious activity - State.
- EIDSCA.AG03Authentication Method - General Settings - Report suspicious activity - Included users/groups.
- EIDSCA.AM01Authentication Method - Microsoft Authenticator - State.
- EIDSCA.AM02Authentication Method - Microsoft Authenticator - Allow use of Microsoft Authenticator OTP.
- EIDSCA.AM03Authentication Method - Microsoft Authenticator - Require number matching for push notifications.
- EIDSCA.AM04Authentication Method - Microsoft Authenticator - Included users/groups of number matching for push notifications.
- EIDSCA.AM06Authentication Method - Microsoft Authenticator - Show application name in push and passwordless notifications.
- EIDSCA.AM07Authentication Method - Microsoft Authenticator - Included users/groups to show application name in push and passwordless notifications.
- EIDSCA.AM09Authentication Method - Microsoft Authenticator - Show geographic location in push and passwordless notifications.
- EIDSCA.AM10Authentication Method - Microsoft Authenticator - Included users/groups to show geographic location in push and passwordless notifications.
- EIDSCA.AP01Default Authorization Settings - Enabled Self service password reset for administrators.
- EIDSCA.AP04Default Authorization Settings - Guest invite restrictions.
- EIDSCA.AP05Default Authorization Settings - Sign-up for email based subscription.
- EIDSCA.AP06Default Authorization Settings - User can join the tenant by email validation.
- EIDSCA.AP07Default Authorization Settings - Guest user access.
- EIDSCA.AP08Default Authorization Settings - User consent policy assigned for applications.
- EIDSCA.AP09Default Authorization Settings - Allow user consent on risk-based apps.
- EIDSCA.AP10Default Authorization Settings - Default User Role Permissions - Allowed to create Apps.
- EIDSCA.AP14Default Authorization Settings - Default User Role Permissions - Allowed to read other users.
- EIDSCA.AS04Authentication Method - SMS - Use for sign-in.
- EIDSCA.AT01Authentication Method - Temporary Access Pass - State.
- EIDSCA.AT02Authentication Method - Temporary Access Pass - One-time.
- EIDSCA.AV01Authentication Method - Voice call - State.
- EIDSCA.CP01Default Settings - Consent Policy Settings - Group owner consent for apps accessing data.
- EIDSCA.CP03Default Settings - Consent Policy Settings - Block user consent for risky apps.
- EIDSCA.CP04Default Settings - Consent Policy Settings - Users can request admin consent to apps they are unable to consent to.
- EIDSCA.CR01Consent Framework - Admin Consent Request - Policy to enable or disable admin consent request feature.
- EIDSCA.CR02Consent Framework - Admin Consent Request - Reviewers will receive email notifications for requests.
- EIDSCA.CR03Consent Framework - Admin Consent Request - Reviewers will receive email notifications when admin consent requests are about to expire.
- EIDSCA.CR04Consent Framework - Admin Consent Request - Consent request duration (days).
- EIDSCA.PR01Default Settings - Password Rule Settings - Password Protection - Mode.
- EIDSCA.PR02Default Settings - Password Rule Settings - Password Protection - Enable password protection on Windows Server Active Directory.
- EIDSCA.PR03Default Settings - Password Rule Settings - Enforce custom list.
- EIDSCA.PR05Default Settings - Password Rule Settings - Smart Lockout - Lockout duration in seconds.
- EIDSCA.PR06Default Settings - Password Rule Settings - Smart Lockout - Lockout threshold.
- EIDSCA.ST08Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to become Group Owner.
- EIDSCA.ST09Default Settings - Classification and M365 Groups - M365 groups - Allow Guests to have access to groups content.
- MT.1001At least one Conditional Access policy is configured with device compliance.
- MT.1002App management restrictions on applications and service principals is configured and enabled.
- MT.1003At least one Conditional Access policy is configured with All Apps.
- MT.1004At least one Conditional Access policy is configured with All Apps and All Users.
- MT.1005All Conditional Access policies are configured to exclude at least one emergency/break glass account or group.
- MT.1006At least one Conditional Access policy is configured to require MFA for admins.
- MT.1007At least one Conditional Access policy is configured to require MFA for all users.
- MT.1008At least one Conditional Access policy is configured to require MFA for Azure management.
- MT.1009At least one Conditional Access policy is configured to block other legacy authentication.
- MT.1010At least one Conditional Access policy is configured to block legacy authentication for Exchange ActiveSync.
- MT.1011At least one Conditional Access policy is configured to secure security info registration only from a trusted location.
- MT.1012At least one Conditional Access policy is configured to require MFA for risky sign-ins.
- MT.1013At least one Conditional Access policy is configured to require new password when user risk is high.
- MT.1014At least one Conditional Access policy is configured to require compliant or Entra hybrid joined devices for admins.
- MT.1015At least one Conditional Access policy is configured to block access for unknown or unsupported device platforms.
- MT.1016At least one Conditional Access policy is configured to require MFA for guest access.
- MT.1017At least one Conditional Access policy is configured to enforce non persistent browser session for non-corporate devices.
- MT.1018At least one Conditional Access policy is configured to enforce sign-in frequency for non-corporate devices.
- MT.1019At least one Conditional Access policy is configured to enable application enforced restrictions.
- MT.1020All Conditional Access policies are configured to exclude directory synchronization accounts or do not scope them.
- MT.1021Security Defaults are enabled.
- MT.1025No external user with permanent role assignment on Control Plane.
- MT.1026No hybrid user with permanent role assignment on Control Plane.
- MT.1027No Service Principal with Client Secret and permanent role assignment on Control Plane.
- MT.1028No user with mailbox and permanent role assignment on Control Plane.
- MT.1029Stale accounts are not assigned to privileged roles.
- MT.1030Eligible role assignments on Control Plane are in use by administrators.
- MT.1031Privileged role on Control Plane are managed by PIM only.
- MT.1032Limited number of Global Admins are assigned.
- MT.1033MT.1033.$($RegularUsers.IndexOf($_)): User should be blocked from using legacy authentication ($($_.userPrincipalName))
- MT.1034MT.1034.$($EmergencyAccessUsers.IndexOf($_)): Emergency access users should not be blocked ($($_.userPrincipalName))
- MT.1035All security groups assigned to Conditional Access Policies should be protected by RMAU.
- MT.1036All excluded objects should have a fallback include in another policy.
- MT.1037Only users with Presenter role are allowed to present in Teams meetings
- MT.1038Conditional Access policies should not include or exclude deleted groups.
- MT.1039Ensure MailTips are enabled for end users
- MT.1041Ensure users installing Outlook add-ins is not allowed
- MT.1043Ensure Spam confidence level (SCL) is configured in mail transport rules with specific domains
- MT.1044Ensure modern authentication for Exchange Online is enabled
- MT.1049Conditional Access policies for User Risk and Sign-in Risk should be configured separately.
- MT.1050Apps with high-risk permissions having a direct path to Global Administrator
- MT.1051Apps with high-risk permissions having an indirect path to Global Administrator
- MT.1052At least one Conditional Access policy is targeting the Device Code authentication flow.
- MT.1053Ensure intune device clean-up rule is configured
- MT.1054Ensure built-in Device Compliance Policy marks devices with no compliance policy assigned as 'Not compliant'
- MT.1055Microsoft 365 Group (and Team) creation should be restricted to approved users.
- MT.1056Ensure that no person has permanent access to all Azure subscriptions at the root scope
- MT.1059Microsoft Defender for Identity health issues should be resolved
- MT.1061Device registration MFA control conflicts with Conditional Access policies
- MT.1062Ensure Direct Send is set to be rejected
- MT.1063All app registration owners should have MFA registered
- MT.1064Management group creation should be limited to users with explicit write access
- MT.1065Soft Delete should be enabled on all Recovery Services Vaults
- MT.1066Conditional Access policies should not include or exclude deleted users, groups, or roles.
- MT.1068Restrict non-admin users from creating tenants
- MT.1069Restrict non-admin users from creating security groups.
- MT.1070Restrict device join to selected users/groups or none.
- MT.1071At least one Conditional Access policy explicitly includes Azure DevOps.
- MT.1072Conditional Access policies should not use the deprecated Approved Client App grant.
- MT.1073Soft- and hard-matching of synchronized objects should be blocked.
- MT.1077App registrations with privileged API permissions should not have owners
- MT.1078App registrations with highly privileged directory roles should not have owners
- MT.1079Privileged API permissions on service principals should not remain unused
- MT.1080Credentials, tokens, or cookies from highly privileged users should not be exposed on vulnerable endpoints
- MT.1081Hybrid users should not be assigned Entra ID role assignments
- MT.1083Ensure Delicensing Resiliency is enabled
- MT.1085Pending approvals for Critical Asset Management should not be present
- MT.1089Devices with critical credentials should be protected by Credential Guard.
- MT.1090Global Administrator role should not be added as local administrator on the device during Microsoft Entra join
- MT.1092Intune APNS certificate should be valid for more than 30 days
- MT.1093Apple Automated Device Enrollment Tokens should be valid for more than 30 days
- MT.1094Apple Volume Purchase Program Tokens should be valid for more than 30 days
- MT.1095Android Enterprise Account Connection should be healthy
- MT.1097Certificate Connectors should be healthy and running supported versions
- MT.1100Intune Audit Logs should be retained
- MT.1102Windows Feature Update Policy Settings should not reference end of support builds
- MT.1103Intune RBAC groups should be protected by Restricted Management Administrative Units or Role Assignable groups
- MT.1111High privileged user should be linked to an identity
- MT.1118AI agents should avoid using author (maker) authentication for tools
- MT.1119AI agents should not have hard-coded credentials in topics
- MT.1120AI agents should not use MCP server tools without review
- MT.1121AI agents with generative orchestration should have custom instructions
- MT.1123Ensure BitLocker full disk encryption is configured via Intune
- MT.1147Do not sync krbtgt_AzureAD to Entra ID
- MT.1172Unified audit log ingestion is enabled
- MT.1173Sensitivity labels are published for files used by Microsoft 365 Copilot
- MT.1174Insider Risk Management policy for Risky AI usage is enabled
- MT.1175DLP policy is configured for the Microsoft 365 Copilot location
- MT.1176Retention policy is configured for the Microsoft Copilot location
- MT.1177Ensure LAPS Configuration Policy is properly set
- MT.1178Ensure ASR Rules are configured correctly
- MT.1179Ensure App Control for Business is enabled
- MT.1180Ensure Managed Installer Rules are configured correctly
- MT.1181Conditional Access policy is present that blocks high agent risk signins
- MT.1182Entra managed and verified domains should have mature DMARC policy (p=reject, pct=100).
- MT.1183Temporary bypass for onPremisesObjectIdentifier updates should be disabled
- MT.1184Conditional Access policy without any target resources configured
- MT.1185Block legacy MSOnline (MSOL) PowerShell module
- MT.1186High-privilege first-party Entra Apps should only have explicitly assigned users instead of All Users.
- MT.1187The Microsoft 365 traffic forwarding profile in Global Secure Access should be enabled
- MT.1188Entra Private Access applications should be covered by a Conditional Access policy that requires a managed device
- MT.1191Break-glass accounts should be excluded from the Compliant Network Conditional Access policy
- MT.1195The Quick Access app should not be subject to a sign-in frequency Conditional Access control
- ORCA.118.2Domains are not being allow listed in an unsafe manner in Transport Rules.
- ORCA.118.4Your own domains are not being allow listed in an unsafe manner in Transport Rules.
- ORCA.240Outlook is configured to display external tags for external emails.
- ORCA.241Anti-phishing policy exists and EnableFirstContactSafetyTips is true.
- ORCA.242Important protection alerts responsible for AIR activities are enabled.
- ORCA.243Authenticated Receive Chain is set up for domains not pointing to EOP/MDO, or all domains point to EOP/MDO.