SECURITY ASSESSMENT REPORT
Technology: Microsoft 365
Tenant: dynamicpacksnet.onmicrosoft.com
Assessment Date: 03/27/2026 07:11:01
Tests Evaluated:233
This Introduction contains a global summary of the security scans performed on the company infrastructure. Detailed information about the scans can be found in the corresponding section in this report. The assessment was performed according to settings recommended by CIS. More Information about CIS can be found here: CIS Benchmarks. There are tests that also recommended by vendor have been performed too.
3Critical
106High
14Medium
2Low
74Passed
28Manual Check
OVERALL TENANT STATUS
Shows overall score settings that need to be configured correctly in Tenant as per CIS Benchmark. These settings are recommended by CIS.
CIS SECURITY SCORE
Shows overall score settings that need to be configured correctly in Tenant. These settings are recommended by Experts not included in CIS.
SP SECURITY SCORE
Shows overall score for Microsoft 365 Compliance score from portal.
M365 COMPLIANCE SCORE
Technology Categories and Status
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 1.1.1 | Ensure Administrative accounts are separate and cloud-only | Passed | Sync-In Admins:0 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure Administrative accounts are separate and cloud-only Description Administrative accounts are special privileged accounts that could have varying levels of access to data, users, and settings. Regular user accounts should never be utilized for administrative tasks and care should be taken, in the case of a hybrid environment, to keep administrative accounts separate from on-prem accounts. Administrative accounts should not have applications assigned so that they have no access to potentially vulnerable services (EX. email, Teams, SharePoint, etc.) and only access to perform tasks as needed for administrative purposes. Ensure administrative accounts are not `On-premises sync enabled`. Rationale In a hybrid environment, having separate accounts will help ensure that in the event of a breach in the cloud, that the breach does not affect the on-prem environment and vice versa. Impact Administrative users will need to utilize login/logout functionality to switch accounts when performing administrative tasks, which means they will not benefit from SSO. This will require a migration process from the 'daily driver' account to a dedicated admin account. Once the new admin account is created, permission sets should be migrated from the 'daily driver' account to the new admin account. This includes both M365 and Azure RBAC roles. Failure to migrate Azure RBAC roles could prevent an admin from seeing their subscriptions/resources while using their admin account. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https://learn.microsoft.com/en-us/microsoft-365/admin/add-users/add-users?view=o365-worldwide https://learn.microsoft.com/en-us/microsoft-365/enterprise/protect-your-global-administrator-accounts?view=o365-worldwide https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/best-practices#9-use-cloud-native-accounts-for-microsoft-entra-roles https://learn.microsoft.com/en-us/entra/fundamentals/whatis https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference
|
| 1.1.3 | Ensure that between two and four global admins are designated | Passed | Total Global Admins:3 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure that between two and four global admins are designated Description Between two and four global administrators should be designated in the tenant. Ideally, these accounts will not have licenses assigned to them which supports additional controls found in this benchmark. Rationale If there is only one global administrator, they could perform malicious activities without being detected by another admin. Designating multiple global administrators eliminates this risk and ensures redundancy if the sole remaining global administrator leaves the organization. However, to minimize the attack surface, there should be no more than four global admins set for any tenant. A large number of global admins increases the likelihood of a successful account breach by an external attacker. Impact The potential impact associated with ensuring compliance with this requirement is dependent upon the current number of global administrators configured in the tenant. If there is only one global administrator in a tenant, an additional global administrator will need to be identified and configured. If there are more than four global administrators, a review of role requirements for current global administrators will be required to identify which of the users require global administrator access. Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
LINK
https://learn.microsoft.com/en-us/powershell/module/microsoft.graph.identity.directorymanagement/get-mgdirectoryrole?view=graph-powershell-1.0 https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference#all-roles https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/best-practices#5-limit-the-number-of-global-administrators-to-less-than-5
|
| 1.1.4 | Ensure administrative accounts use licenses with a reduced application footprint | Passed | Status:Please check licenses assigned | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure administrative accounts use licenses with a reduced application footprint Description Administrative accounts are special privileged accounts that could have varying levels of access to data, users, and settings. A license can enable an account to gain access to a variety of different applications, depending on the license assigned. The recommended state is to not license a privileged account or use licenses without associated applications such as `Microsoft Entra ID P1` or `Microsoft Entra ID P2`. Rationale Ensuring administrative accounts do not use licenses with applications assigned to them will reduce the attack surface of high privileged identities in the organization's environment. Granting access to a mailbox or other collaborative tools increases the likelihood that privileged users might interact with these applications, raising the risk of exposure to social engineering attacks or malicious content. These activities should be restricted to an unprivileged 'daily driver' account. **Note:** In order to participate in Microsoft 365 security services such as Identity Protection, PIM and Conditional Access an administrative account will need a license attached to it. Ensure that the license used does not include any applications with potentially vulnerable services by using either **Microsoft Entra ID P1** or **Microsoft Entra ID P2** for the cloud-only account with administrator roles. Impact Administrative users will have to switch accounts and utilize login/logout functionality when performing administrative tasks, as well as not benefiting from SSO. **Note:** Alerts will be sent to **TenantAdmins**, including Global Administrators, by default. To ensure proper receipt, configure alerts to be sent to security or operations staff with valid email addresses or a security operations center. Otherwise, after adoption of this recommendation, alerts sent to **TenantAdmins** may go unreceived due to the lack of an application-based license assigned to the Global Administrator accounts. Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
LINK
https://learn.microsoft.com/en-us/microsoft-365/enterprise/protect-your-global-administrator-accounts?view=o365-worldwide https://learn.microsoft.com/en-us/entra/fundamentals/whatis#what-are-the-microsoft-entra-id-licenses https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference https://learn.microsoft.com/en-us/microsoft-365/business-premium/m365bp-protect-admin-accounts?view=o365-worldwide https://learn.microsoft.com/en-us/microsoft-365/enterprise/subscriptions-licenses-accounts-and-tenants-for-microsoft-cloud-offerings?view=o365-worldwide#licenses https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-deployment-plan#principle-of-least-privilege
|
| 1.1.2 | Ensure two emergency access accounts have been defined | Manual Check | NONE | Not defined. | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure two emergency access accounts have been defined Description Emergency access or break glass accounts are limited for emergency scenarios where normal administrative accounts are unavailable. They are not assigned to a specific user and will have a combination of physical and technical controls to prevent them from being accessed outside a true emergency. These emergencies could be due to several things, including: - Technical failures of a cellular provider or Microsoft related service such as MFA. - The last remaining Global Administrator account is inaccessible. Ensure two `Emergency Access` accounts have been defined. **Note:** Microsoft provides several recommendations for these accounts and how to configure them. For more information on this, please refer to the references section. The CIS Benchmark outlines the more critical things to consider. Rationale In various situations, an organization may require the use of a break glass account to gain emergency access. In the event of losing access to administrative functions, an organization may experience a significant loss in its ability to provide support, lose insight into its security posture, and potentially suffer financial losses. Impact Failure to properly implement emergency access accounts can weaken the security posture. Microsoft recommends excluding at least one of the two emergency access accounts from all conditional access rules, necessitating passwords with sufficient entropy and length to protect against random guesses. For a secure passwordless solution, FIDO2 security keys may be used instead of passwords. Recommendation and Steps **Step 1 - Create two emergency access accounts:** 1. Navigate to `Microsoft 365 admin center` https://admin.microsoft.com 2. Expand `Users` > `Active Users` 3. Click `Add user` and create a new user with this criteria: - Name the account in a way that does NOT identify it with a particular person. - Assign the account to the default `.onmicrosoft.com` domain and not the organization's. - The password must be at least 16 characters and generated randomly. - Do not assign a license. - Assign the user the `Global Administrator` role. 4. Repeat the above steps for the second account. **Step 2 - Exclude at least one account from conditional access policies:** 1. Navigate `Microsoft Entra admin center` https://entra.microsoft.com/ 2. Expand `Protection` > `Conditional Access`. 3. Inspect the conditional access policies. 4. For each rule add an exclusion for at least one of the emergency access accounts. 5. `Users` > `Exclude` > `Users and groups` and select one emergency access account. **Step 3 - Ensure the necessary procedures and policies are in place:** - In order for accounts to be effectively used in a break glass situation the proper policies and procedures must be authorized and distributed by senior management. - FIDO2 Security Keys should be locked in a secure separate fireproof location. - Passwords should be at least 16 characters, randomly generated and MAY be separated in multiple pieces to be joined on emergency. **Warning:** As of 10/15/2024 MFA is required for all users including Break Glass Accounts. It is recommended to update these accounts to use?passkey (FIDO2)?or?configure certificate-based authentication for MFA.?Both methods satisfy the MFA requirement. **Additional suggestions for emergency account management:** - Create access reviews for these users. - Exclude users from conditional access rules. - Add the account to a [restricted management administrative unit](https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/admin-units-restricted-management). **Warning**: If CA (conditional access) exclusion is managed by a group, this group should be added to PIM for groups (licensing required) or be created as a role-assignable group. If it is a regular security group, then users with the Group Administrators role are able to bypass CA entirely. Associated Items Affected Objects More Information TEST ID
LINK
https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/security-planning#stage-1-critical-items-to-do-right-now https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/security-emergency-access https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/admin-units-restricted-management https://learn.microsoft.com/en-us/entra/identity/authentication/concept-mandatory-multifactor-authentication#accounts
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 1.2.1 | Ensure that only organizationally managed-approved public groups exist | Medium | Public Groups:1 | Public when created from the Administration portal; private otherwise. | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure that only organizationally managed-approved public groups exist Description Microsoft 365 Groups is the foundational membership service that drives all teamwork across Microsoft 365. With Microsoft 365 Groups, you can give a group of people access to a collection of shared resources. While there are several different group types this recommendation concerns **Microsoft 365 Groups**. In the Administration panel, when a group is created, the default privacy value is Public. Rationale Ensure that only organizationally managed and approved public groups exist. When a group has a public privacy, users may access data related to this group (e.g. SharePoint), through three methods: - By using the Azure portal, and adding themselves into the public group - By requesting access to the group from the Group application of the Access Panel - By accessing the SharePoint URL Administrators are notified when a user uses the Azure Portal. Requesting access to the group forces users to send a message to the group owner, but they still have immediate access to the group. The SharePoint URL is usually guessable and can be found from the Group application of the Access Panel. If group privacy is not controlled, any user may access sensitive information, according to the group they try to access. **Note:** Public in this case means public to the identities within the organization. Impact If the recommendation is applied, group owners could receive more access requests than usual, especially regarding groups originally meant to be public. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft 365 admin center` https://admin.microsoft.com. 2. Click to expand `Teams & groups` select `Active teams & groups`.. 3. On the **Active teams and groups page**, select the group's name that is public. 4. On the popup **groups name page**, Select `Settings`. 5. Under Privacy, select `Private`. Associated Items
Affected Objects
|
| 1.2.2 | Ensure sign-in to shared mailboxes is blocked | Passed | Sign-In Allowed for Total SharedMailbox:0 | AccountEnabled: `True` | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure sign-in to shared mailboxes is blocked Description Shared mailboxes are used when multiple people need access to the same mailbox, such as a company information or support email address, reception desk, or other function that might be shared by multiple people. Users with permissions to the group mailbox can send as or send on behalf of the mailbox email address if the administrator has given that user permissions to do that. This is particularly useful for help and support mailboxes because users can send emails from Contoso Support or Building A Reception Desk. Shared mailboxes are created with a corresponding user account using a system generated password that is unknown at the time of creation. The recommended state is `Sign in blocked` for `Shared mailboxes`. Rationale The intent of the shared mailbox is the only allow delegated access from other mailboxes. An admin could reset the password, or an attacker could potentially gain access to the shared mailbox allowing the direct sign-in to the shared mailbox and subsequently the sending of email from a sender that does not have a unique identity. To prevent this, block sign-in for the account that is associated with the shared mailbox. Impact Recommendation and Steps Associated Items Affected Objects More Information TEST ID
LINK
https://learn.microsoft.com/en-us/microsoft-365/admin/email/about-shared-mailboxes?view=o365-worldwide https://learn.microsoft.com/en-us/microsoft-365/admin/email/create-a-shared-mailbox?view=o365-worldwide#block-sign-in-for-the-shared-mailbox-account https://learn.microsoft.com/en-us/microsoft-365/enterprise/block-user-accounts-with-microsoft-365-powershell?view=o365-worldwide#block-individual-user-accounts
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 1.3.2 | Ensure Idle session timeout is set to 3 hours (or less) for unmanaged devices | High | Idle Timeout Status:1 | Not configured. (Idle sessions will not timeout.) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure Idle session timeout is set to 3 hours (or less) for unmanaged devices Description Idle session timeout allows the configuration of a setting which will timeout inactive users after a pre-determined amount of time. When a user reaches the set idle timeout session, they'll get a notification that they're about to be signed out. They must choose to stay signed in or they'll be automatically signed out of all Microsoft 365 web apps. Combined with a Conditional Access rule this will only impact unmanaged devices. A managed device is considered a device managed by Intune MDM or joined to a domain (Entra ID or Hybrid joined). The following Microsoft 365 web apps are supported. - Outlook Web App - OneDrive - SharePoint - Microsoft Fabric - Microsoft365.com and other start pages - Microsoft 365 web apps (Word, Excel, PowerPoint) - Microsoft 365 Admin Center - M365 Defender Portal - Microsoft Purview Compliance Portal The recommended setting is `3 hours` (or less) for unmanaged devices. **Note:** Idle session timeout doesn't affect Microsoft 365 desktop and mobile apps. Rationale Ending idle sessions through an automatic process can help protect sensitive company data and will add another layer of security for end users who work on unmanaged devices that can potentially be accessed by the public. Unauthorized individuals onsite or remotely can take advantage of systems left unattended over time. Automatic timing out of sessions makes this more difficult. Impact If step 2 in the Audit/Remediation procedure is left out, then there is no issue with this from a security standpoint. However, it will require users on trusted devices to sign in more frequently which could result in credential prompt fatigue. Users don?t get signed out in these cases: - If they get single sign-on (SSO) into the web app from the device joined account. - If they selected Stay signed in at the time of sign-in. For more info on hiding this option for your organization, see Add branding to your organization's sign-in page. - If they're on a managed device, that is compliant or joined to a domain and using a supported browser, like Microsoft Edge, or Google Chrome with the Microsoft Single Sign On extension. **Note:** Idle session timeout also affects the Azure Portal idle timeout if this is not explicitly set to a different timeout. The Azure Portal idle timeout applies to all kind of devices, not just unmanaged. See : [change the directory timeout setting admin](https://learn.microsoft.com/en-us/azure/azure-portal/set-preferences#change-the-directory-timeout-setting-admin) Recommendation and Steps **Step 1 - Configure Idle session timeout:** 1. Navigate to the `Microsoft 365 admin center` https://admin.microsoft.com/. 2. Click to expand `Settings` Select `Org settings`. 3. Click `Security & Privacy` tab. 4. Select `Idle session timeout`. 5. Check the box `Turn on to set the period of inactivity for users to be signed off of Microsoft 365 web apps` 6. Set a maximum value of `3 hours`. 7. Click save. **Step 2 - Ensure the Conditional Access policy is in place:** 1. Navigate to `Microsoft Entra admin center` https://entra.microsoft.com/ 2. Expand `Protect` > `Conditional Access`. 3. Click `New policy` and give the policy a name. - Select `Users` > `All users`. - Select `Cloud apps or actions` > `Select apps` and select `Office 365` - Select `Conditions` > `Client apps` > `Yes` check only `Browser` unchecking all other boxes. - Select `Sessions` and check `Use app enforced restrictions`. 4. Set `Enable policy` to `On` and click `Create`. **Note:** To ensure that idle timeouts affect only unmanaged devices, both steps 1 and 2 must be completed. Otherwise managed devices will also be impacted by the timeout policy. Associated Items
Affected Objects
More Information TEST ID
|
| 1.3.3 | Ensure External sharing of calendars is not available | High | Status:Enabled | Enabled (True) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure External sharing of calendars is not available Description External calendar sharing allows an administrator to enable the ability for users to share calendars with anyone outside of the organization. Outside users will be sent a URL that can be used to view the calendar. Rationale Attackers often spend time learning about organizations before launching an attack. Publicly available calendars can help attackers understand organizational relationships and determine when specific users may be more vulnerable to an attack, such as when they are traveling. Impact This functionality is not widely used. As a result, it is unlikely that implementation of this setting will cause an impact to most users. Users that do utilize this functionality are likely to experience a minor inconvenience when scheduling meetings or synchronizing calendars with people outside the tenant. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft 365 admin center` https://admin.microsoft.com. 2. Click to expand `Settings` select `Org settings`. 3. In the `Services` section click `Calendar`. 4. Uncheck `Let your users share their calendars with people outside of your organization who have Office 365 or Exchange`. 5. Click `Save`. **To remediate using PowerShell:** 1. Connect to Exchange Online using `Connect-ExchangeOnline`. 2. Run the following Exchange Online PowerShell command: ``` Set-SharingPolicy -Identity Default Sharing Policy -Enabled $False ``` Associated Items
Affected Objects More Information TEST ID
|
| 1.3.7 | Ensure third-party storage services are restricted in Microsoft 365 on the web | High | Status:Not Restricted | Enabled - Users are able to open files stored in third-party storage services | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure third-party storage services are restricted in Microsoft 365 on the web Description Third-party storage can be enabled for users in Microsoft 365, allowing them to store and share documents using services such as Dropbox, alongside OneDrive and team sites. Ensure `Microsoft 365 on the web` third-party storage services are restricted. Rationale By using external storage services an organization may increase the risk of data breaches and unauthorized access to confidential information. Additionally, third-party services may not adhere to the same security standards as the organization, making it difficult to maintain data privacy and security. Impact Impact associated with this change is highly dependent upon current practices in the tenant. If users do not use other storage providers, then minimal impact is likely. However, if users do regularly utilize providers outside of the tenant this will affect their ability to continue to do so. Recommendation and Steps **To remediate using the UI:**
1. Navigate to `Microsoft 365 admin center` https://admin.microsoft.com
2. Go to `Settings` > `Org Settings` > `Services` > `Microsoft 365 on the web`
3. Uncheck `Let users open files stored in third-party storage services in Microsoft 365 on the web`
**To remediate using PowerShell:**
1. Connect to Microsoft Graph using `Connect-MgGraph -Scopes Application.ReadWrite.All`
2. Run the following script:
```
$SP = Get-MgServicePrincipal -Filter appId eq 'c1f33bc0-bdb4-4248-ba9b-096807ddb43e'
# If the service principal doesn't exist then create it first.
if (-not $SP) {
$SP = New-MgServicePrincipal -AppId c1f33bc0-bdb4-4248-ba9b-096807ddb43e
}
Update-MgServicePrincipal -ServicePrincipalId $SP.Id -AccountEnabled:$false
```
Associated Items
Affected Objects |
| 1.3.6 | Ensure the customer lockbox feature is enabled | Medium | Status:Disabled | `Require approval for all data access requests` - `Unchecked` `CustomerLockboxEnabled` - `False` | E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure the customer lockbox feature is enabled Description Customer Lockbox is a security feature that provides an additional layer of control and transparency to customer data in Microsoft 365. It offers an approval process for Microsoft support personnel to access organization data and creates an audited trail to meet compliance requirements. Rationale Enabling this feature protects organizational data against data spillage and exfiltration. Impact Administrators will need to grant Microsoft access to the tenant environment prior to a Microsoft engineer accessing the environment for support or troubleshooting. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft 365 admin center` https://admin.microsoft.com. 2. Click to expand `Settings` then select `Org settings`. 3. Select `Security & privacy` tab. 4. Click `Customer lockbox`. 5. Check the box `Require approval for all data access requests`. 6. Click `Save`. **To remediate using PowerShell:** 1. Connect to Exchange Online using `Connect-ExchangeOnline`. 2. Run the following PowerShell command\: ``` Set-OrganizationConfig -CustomerLockBoxEnabled $true ``` Associated Items
Affected Objects More Information TEST ID
|
| 1.3.1 | Ensure the Password expiration policy is set to Set passwords to never expire (recommended) | Passed | Missing Password Policies Domains:0 | If the property is not set, a default value of 90 days will be used | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure the Password expiration policy is set to Set passwords to never expire (recommended) Description Microsoft cloud-only accounts have a pre-defined password policy that cannot be changed. The only items that can change are the number of days until a password expires and whether or whether passwords expire at all. Rationale Organizations such as NIST and Microsoft have updated their password policy recommendations to not arbitrarily require users to change their passwords after a specific amount of time, unless there is evidence that the password is compromised, or the user forgot it. They suggest this even for single factor (Password Only) use cases, with a reasoning that forcing arbitrary password changes on users actually make the passwords less secure. Other recommendations within this Benchmark suggest the use of MFA authentication for at least critical accounts (at minimum), which makes password expiration even less useful as well as password protection for Entra ID. Impact When setting passwords not to expire it is important to have other controls in place to supplement this setting. See below for related recommendations and user guidance. - Ban common passwords. - Educate users to not reuse organization passwords anywhere else. - Enforce Multi-Factor Authentication registration for all users. Recommendation and Steps Associated Items
Affected Objects
|
| 1.3.4 | Ensure User owned apps and services is restricted | Passed | Status:Restricted | `Let users access the Office Store` is `Checked` `Let users start trials on behalf of your organization` is `Checked` | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure User owned apps and services is restricted Description By default, users can install add-ins in their Microsoft Word, Excel, and PowerPoint applications, allowing data access within the application. Do not allow users to install add-ins in Word, Excel, or PowerPoint. Rationale Attackers commonly use vulnerable and custom-built add-ins to access data in user applications. While allowing users to install add-ins by themselves does allow them to easily acquire useful add-ins that integrate with Microsoft applications, it can represent a risk if not used and monitored carefully. Disable future user's ability to install add-ins in Microsoft Word, Excel, or PowerPoint helps reduce your threat-surface and mitigate this risk. Impact Implementation of this change will impact both end users and administrators. End users will not be able to install add-ins that they may want to install. Recommendation and Steps Associated Items
Affected Objects
|
| 1.3.5 | Ensure internal phishing protection for Forms is enabled | Passed | Forms Phishing Protection:0 | Internal Phishing Protection is enabled. | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure internal phishing protection for Forms is enabled Description Microsoft Forms can be used for phishing attacks by asking personal or sensitive information and collecting the results. Microsoft 365 has built-in protection that will proactively scan for phishing attempt in forms such personal information request. Rationale Enabling internal phishing protection for Microsoft Forms will prevent attackers using forms for phishing attacks by asking personal or other sensitive information and URLs. Impact If potential phishing was detected, the form will be temporarily blocked and cannot be distributed, and response collection will not happen until it is unblocked by the administrator or keywords were removed by the creator. Recommendation and Steps Associated Items
Affected Objects
|
| 1.3.8 | Ensure that Sways cannot be shared with people outside of your organization | Manual Check | NONE | `Let people in your organization share their sways with people outside your organization` - Enabled | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure that Sways cannot be shared with people outside of your organization Description Sway is a Microsoft 365 app that lets organizations create interactive, web-based presentations using images, text, videos and other media. Its design engine simplifies the process, allowing for quick customization. Presentations can then be shared via a link. This setting controls user Sway sharing capability, both within and outside of the organization. By default, Sway is enabled for everyone in the organization. Rationale Disable external sharing of Sway documents that can contain sensitive information to prevent accidental or arbitrary data leaks. Impact Interactive reports, presentations, newsletters, and other items created in Sway will not be shared outside the organization by users. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft 365 admin center` https://admin.microsoft.com. 2. Click to expand `Settings` then select `Org settings`. 3. Under Services select `Sway` - Uncheck: `Let people in your organization share their sways with people outside your organization`. 4. Click `Save`. Associated Items Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 2.1.1 | Ensure Safe Links for Office Applications is Enabled | High | Status:Not Enabled | N/A | E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure Safe Links for Office Applications is Enabled Description Enabling Safe Links policy for Office applications allows URL's that exist inside of Office documents and email applications opened by Office, Office Online and Office mobile to be processed against Defender for Office time-of-click verification and rewritten if required. **Note:** E5 Licensing includes a number of Built-in Protection policies. When auditing policies note which policy you are viewing, and keep in mind CIS recommendations often extend the Default or Build-in Policies provided by MS. In order to **Pass** the highest priority policy must match all settings recommended. Rationale Safe Links for Office applications extends phishing protection to documents and emails that contain hyperlinks, even after they have been delivered to a user. Impact User impact associated with this change is minor - users may experience a very short delay when clicking on URLs in Office documents before being directed to the requested site. Users should be informed of the change as, in the event a link is unsafe and blocked, they will receive a message that it has been blocked. Recommendation and Steps **To remediate using the UI:**
1. Navigate to `Microsoft 365 Defender` https://security.microsoft.com
2. Under `Email & collaboration` select `Policies & rules`
3. Select `Threat policies` then `Safe Links`
4. Click on `+Create`
5. Name the policy then click `Next`
6. In `Domains` select all valid domains for the organization and `Next`
7. Ensure the following `URL & click protection settings` are defined:
**Email**
- Checked `On: Safe Links checks a list of known, malicious links when users click links in email. URLs are rewritten by default`
- Checked `Apply Safe Links to email messages sent within the organization`
- Checked `Apply real-time URL scanning for suspicious links and links that point to files`
- Checked `Wait for URL scanning to complete before delivering the message`
- Unchecked `Do not rewrite URLs, do checks via Safe Links API only.`
**Teams**
- Checked `On: Safe Links checks a list of known, malicious links when users click links in Microsoft Teams. URLs are not rewritten`
**Office 365 Apps**
- Checked `On: Safe Links checks a list of known, malicious links when users click links in Microsoft Office apps. URLs are not rewritten`
**Click protection settings**
- Checked `Track user clicks`
- Unchecked `Let users click through the original URL`
- There is no recommendation for organization branding.
8. Click `Next` twice and finally `Submit`
**To remediate using PowerShell:**
1. Connect using `Connect-ExchangeOnline`.
2. Run the following PowerShell script to create a policy at highest priority that will apply to all valid domains on the tenant:
```
# Create the Policy
$params = @{
Name = CIS SafeLinks Policy
EnableSafeLinksForEmail = $true
EnableSafeLinksForTeams = $true
EnableSafeLinksForOffice = $true
TrackClicks = $true
AllowClickThrough = $false
ScanUrls = $true
EnableForInternalSenders = $true
DeliverMessageAfterScan = $true
DisableUrlRewrite = $false
}
New-SafeLinksPolicy @params
# Create the rule for all users in all valid domains and associate with Policy
New-SafeLinksRule -Name CIS SafeLinks -SafeLinksPolicy CIS SafeLinks Policy -RecipientDomainIs (Get-AcceptedDomain).Name -Priority 0
```
Associated Items
Affected Objects More Information TEST ID
LINK
https://learn.microsoft.com/en-us/defender-office-365/safe-links-policies-configure?view=o365-worldwide https://learn.microsoft.com/en-us/powershell/module/exchange/set-safelinkspolicy?view=exchange-ps https://learn.microsoft.com/en-us/defender-office-365/preset-security-policies?view=o365-worldwide
|
| 2.1.2 | Ensure the Common Attachment Types Filter is enabled | High | Status:Not Enabled | Always on | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure the Common Attachment Types Filter is enabled Description The Common Attachment Types Filter lets a user block known and custom malicious file types from being attached to emails. Rationale Blocking known malicious file types can help prevent malware-infested files from infecting a host. Impact Blocking common malicious file types should not cause an impact in modern computing environments. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft 365 Defender` https://security.microsoft.com. 2. Click to expand `Email & collaboration` select `Policies & rules`. 3. On the Policies & rules page select `Threat policies`. 4. Under polices select `Anti-malware` and click on the `Default (Default)` policy. 5. On the Policy page that appears on the right hand pane scroll to the bottom and click on `Edit protection settings`, check the `Enable the common attachments filter`. 6. Click Save. **To remediate using PowerShell:** 1. Connect to Exchange Online using `Connect-ExchangeOnline`. 2. Run the following Exchange Online PowerShell command: ``` Set-MalwareFilterPolicy -Identity Default -EnableFileFilter $true ``` **Note:** Audit and Remediation guidance may focus on the **Default policy** however, if a Custom Policy exists in the organization's tenant, then ensure the setting is set as outlined in the highest priority policy listed. Associated Items
Affected Objects |
| 2.1.3 | Ensure notifications for internal users sending malware is Enabled | High | Status:Not Enabled | ``` EnableInternalSenderAdminNotifications : False InternalSenderAdminAddress : $null ``` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure notifications for internal users sending malware is Enabled Description Exchange Online Protection (EOP) is Microsoft's cloud-based filtering service that protects organizations against spam, malware, and other email threats. EOP is included in all Microsoft 365 organizations with Exchange Online mailboxes. EOP uses flexible anti-malware policies for malware protection settings. These policies can be set to notify Admins of malicious activity. Rationale This setting alerts administrators that an internal user sent a message that contained malware. This may indicate an account or machine compromise that would need to be investigated. Impact Notification of account with potential issues should not have an impact on the user. Recommendation and Steps **To remediate using the UI:**
1. Navigate to `Microsoft 365 Defender` https://security.microsoft.com.
2. Click to expand `E-mail & Collaboration` select `Policies & rules`.
3. On the Policies & rules page select `Threat policies`.
4. Under Policies select `Anti-malware`.
5. Click on the `Default (Default)` policy.
6. Click on `Edit protection settings` and change the settings for `Notify an admin about undelivered messages from internal senders` to `On` and enter the email address of the administrator who should be notified under `Administrator email address`.
7. Click Save.
**To remediate using PowerShell:**
1. Connect to Exchange Online using `Connect-ExchangeOnline`.
2. Run the following command:
```
Set-MalwareFilterPolicy -Identity '{Identity Name}' -EnableInternalSenderAdminNotifications $True -InternalSenderAdminAddress {[email protected]}
```
**Note:** Audit and Remediation guidance may focus on the **Default policy** however, if a Custom Policy exists in the organization's tenant, then ensure the setting is set as outlined in the highest priority policy listed.
Associated Items
Affected Objects |
| 2.1.6 | Ensure Exchange Online Spam Policies are set correctly | High | Status:Not Enabled | ``` BccSuspiciousOutboundAdditionalRecipients : {} BccSuspiciousOutboundMail : False NotifyOutboundSpamRecipients : {} NotifyOutboundSpam : False ``` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure Exchange Online Spam Policies are set correctly Description In Microsoft 365 organizations with mailboxes in Exchange Online or standalone Exchange Online Protection (EOP) organizations without Exchange Online mailboxes, email messages are automatically protected against spam (junk email) by EOP. Configure Exchange Online Spam Policies to copy emails and notify someone when a sender in the organization has been blocked for sending spam emails. Rationale A blocked account is a good indication that the account in question has been breached, and an attacker is using it to send spam emails to other people. Impact Notification of users that have been blocked should not cause an impact to the user. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft 365 Defender` https://security.microsoft.com. 2. Click to expand `Email & collaboration` select `Policies & rules`> `Threat policies`. 3. Under Policies select `Anti-spam`. 4. Click on the `Anti-spam outbound policy (default)`. 5. Select `Edit protection settings` then under `Notifications` 6. Check `Send a copy of suspicious outbound messages or message that exceed these limits to these users and groups` then enter the desired email addresses. 7. Check `Notify these users and groups if a sender is blocked due to sending outbound spam` then enter the desired email addresses. 8. Click `Save`. **To remediate using PowerShell:** 1. Connect to Exchange Online using `Connect-ExchangeOnline`. 2. Run the following PowerShell command: ``` $BccEmailAddress = @( Associated Items
Affected Objects More Information TEST ID
|
| 2.1.9 | Ensure that DKIM is enabled for all Exchange Online Domains | High | Domains Missing DKIM:3 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure that DKIM is enabled for all Exchange Online Domains Description DKIM is one of the trio of Authentication methods (SPF, DKIM and DMARC) that help prevent attackers from sending messages that look like they come from your domain. DKIM lets an organization add a digital signature to outbound email messages in the message header. When DKIM is configured, the organization authorizes it's domain to associate, or sign, its name to an email message using cryptographic authentication. Email systems that get email from this domain can use a digital signature to help verify whether incoming email is legitimate. Use of DKIM in addition to SPF and DMARC to help prevent malicious actors using spoofing techniques from sending messages that look like they are coming from your domain. Rationale By enabling DKIM with Office 365, messages that are sent from Exchange Online will be cryptographically signed. This will allow the receiving email system to validate that the messages were generated by a server that the organization authorized and not being spoofed. Impact There should be no impact of setting up DKIM however, organizations should ensure appropriate setup to ensure continuous mail-flow. Recommendation and Steps **To remediate using a DNS Provider:** 1. For each accepted domain in Exchange Online, two DNS entries are required. ``` Host name: selector1._domainkey Points to address or value: selector1- Associated Items
Affected Objects
|
| 2.1.10 | Ensure DMARC Records for all Exchange Online domains are published | High | Missing Domains for DMARC Records:5 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure DMARC Records for all Exchange Online domains are published Description DMARC, or Domain-based Message Authentication, Reporting, and Conformance, assists recipient mail systems in determining the appropriate action to take when messages from a domain fail to meet SPF or DKIM authentication criteria. Rationale DMARC strengthens the trustworthiness of messages sent from an organization's domain to destination email systems. By integrating DMARC with SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail), organizations can significantly enhance their defenses against email spoofing and phishing attempts. Leaving a DMARC policy set to `p=none` can result in failed action when a spear phishing email fails DMARC but passes SPF and DKIM checks. Having DMARC fully configured is a critical part in preventing business email compromise. Impact There should be no impact of setting up DMARC however, organizations should ensure appropriate setup to ensure continuous mail-flow. Recommendation and Steps **To remediate using a DNS Provider:** 1. For each Exchange Online Accepted Domain, add the following record to DNS: ``` Record: _dmarc.domain1.com Type: TXT Value: v=DMARC1; p=none; rua=mailto: Associated Items
Affected Objects
More Information TEST ID
LINK
https://learn.microsoft.com/en-us/defender-office-365/email-authentication-dmarc-configure?view=o365-worldwide https://learn.microsoft.com/en-us/defender-office-365/step-by-step-guides/how-to-enable-dmarc-reporting-for-microsoft-online-email-routing-address-moera-and-parked-domains?view=o365-worldwide https://media.defense.gov/2024/May/02/2003455483/-1/-1/0/CSA-NORTH-KOREAN-ACTORS-EXPLOIT-WEAK-DMARC.PDF
|
| 2.1.11 | Ensure comprehensive attachment filtering is applied | High | Status:Not Configured Correctly | The following extensions are blocked by default: ace, ani, apk, app, appx, arj, bat, cab, cmd, com, deb, dex, dll, docm, elf, exe, hta, img, iso, jar, jnlp, kext, lha, lib, library, lnk, lzh, macho, msc, msi, msix, msp, mst, pif, ppa, ppam, reg, rev, scf, scr, sct, sys, uif, vb, vbe, vbs, vxd, wsc, wsf, wsh, xll, xz, z | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure comprehensive attachment filtering is applied Description The Common Attachment Types Filter lets a user block known and custom malicious file types from being attached to emails. The policy provided by Microsoft covers 53 extensions, and an additional custom list of extensions can be defined. The list of 184 extensions provided in this recommendation is comprehensive but not exhaustive. Rationale Blocking known malicious file types can help prevent malware-infested files from infecting a host or performing other malicious attacks such as phishing and data extraction. Defining a comprehensive list of attachments can help protect against additional unknown and known threats. Many legacy file formats, binary files and compressed files have been used as delivery mechanisms for malicious software. Organizations can protect themselves from Business E-mail Compromise (BEC) by allow-listing only the file types relevant to their line of business and blocking all others. Impact For file types that are business necessary users will need to use other organizationally approved methods to transfer blocked extension types between business partners. Recommendation and Steps **To Remediate using PowerShell:**
1. Connect to Exchange Online using `Connect-ExchangeOnline`.
2. Run the following script:
```
# Create an attachment policy and associated rule. The rule is
# intentionally disabled allowing the org to enable it when ready
$Policy = @{
Name = CIS L2 Attachment Policy
EnableFileFilter = $true
ZapEnabled = $true
EnableInternalSenderAdminNotifications = $true
InternalSenderAdminAddress = '[email protected]' # Change this.
}
$L2Extensions = @(
7z, a3x, ace, ade, adp, ani, app, appinstaller,
applescript, application, appref-ms, appx, appxbundle, arj,
asd, asx, bas, bat, bgi, bz2, cab, chm, cmd, com,
cpl, crt, cs, csh, daa, dbf, dcr, deb,
desktopthemepackfile, dex, diagcab, dif, dir, dll, dmg,
doc, docm, dot, dotm, elf, eml, exe, fxp, gadget, gz,
hlp, hta, htc, htm, html, hwpx, ics, img,
inf, ins, iqy, iso, isp, jar, jnlp, js, jse, kext,
ksh, lha, lib, library-ms, lnk, lzh, macho, mam, mda,
mdb, mde, mdt, mdw, mdz, mht, mhtml, mof, msc, msi,
msix, msp, msrcincident, mst, ocx, odt, ops, oxps, pcd,
pif, plg, pot, potm, ppa, ppam, ppkg, pps, ppsm, ppt,
pptm, prf, prg, ps1, ps11, ps11xml, ps1xml, ps2,
ps2xml, psc1, psc2, pub, py, pyc, pyo, pyw, pyz,
pyzw, rar, reg, rev, rtf, scf, scpt, scr, sct,
searchConnector-ms, service, settingcontent-ms, sh, shb, shs,
shtm, shtml, sldm, slk, so, spl, stm, svg, swf, sys,
tar, theme, themepack, timer, uif, url, uue, vb, vbe,
vbs, vhd, vhdx, vxd, wbk, website, wim, wiz, ws, wsc,
wsf, wsh, xla, xlam, xlc, xll, xlm, xls, xlsb, xlsm,
xlt, xltm, xlw, xnk, xps, xsl, xz, z
)
# Create the policy
New-MalwareFilterPolicy @Policy -FileTypes $L2Extensions
# Create the rule for all accepted domains
$Rule = @{
Name = $Policy.Name
Enabled = $false
MalwareFilterPolicy = $Policy.Name
RecipientDomainIs = (Get-AcceptedDomain).Name
Priority = 0
}
New-MalwareFilterRule @Rule
```
3. When prepared enable the rule either through the UI or PowerShell.
**Note:** Due to the number of extensions the UI method is not covered. The objects can however be edited in the UI or manually added using the list from the script.
1. Navigate to `Microsoft Defender` at https://security.microsoft.com/
2. Browse to `Policies & rules` > `Threat policies` > `Anti-malware`.
Associated Items
Affected Objects
More Information TEST ID
LINK
https://learn.microsoft.com/en-us/powershell/module/exchange/get-malwarefilterpolicy?view=exchange-ps https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/anti-malware-policies-configure?view=o365-worldwide https://learn.microsoft.com/en-us/office/compatibility/office-file-format-reference
|
| 2.1.8 | Ensure that SPF records are published for all Exchange Domains | Medium | Domains Missing SPF Records:5 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure that SPF records are published for all Exchange Domains Description For each domain that is configured in Exchange, a corresponding Sender Policy Framework (SPF) record should be created. Rationale SPF records allow Exchange Online Protection and other mail systems to know where messages from domains are allowed to originate. This information can be used by that system to determine how to treat the message based on if it is being spoofed or is valid. Impact There should be minimal impact of setting up SPF records however, organizations should ensure proper SPF record setup as email could be flagged as spam if SPF is not setup appropriately. Recommendation and Steps **To remediate using a DNS Provider:** 1. If all email in your domain is sent from and received by Exchange Online, add the following TXT record for each Accepted Domain: ``` v=spf1 include:spf.protection.outlook.com -all ``` 2. If there are other systems that send email in the environment, refer to this article for the proper SPF configuration: [https://docs.microsoft.com/en-us/office365/SecurityCompliance/set-up-spf-in-office-365-to-help-prevent-spoofing](https://docs.microsoft.com/en-us/office365/SecurityCompliance/set-up-spf-in-office-365-to-help-prevent-spoofing). Associated Items
Affected Objects
|
| 2.1.4 | Ensure Safe Attachments policy is enabled | Passed | Status:Not Enabled-Not Implemented | ``` Identity : Built-In Protection Policy Enable : True Action : Block QuarantineTag : AdminOnlyAccessPolicy Priority : (lowest) ``` | E5 Level 2 | CIS v6.0 | YES |
X TEST NAME Ensure Safe Attachments policy is enabled Description The Safe Attachments policy helps protect users from malware in email attachments by scanning attachments for viruses, malware, and other malicious content. When an email attachment is received by a user, Safe Attachments will scan the attachment in a secure environment and provide a verdict on whether the attachment is safe or not. Rationale Enabling Safe Attachments policy helps protect against malware threats in email attachments by analyzing suspicious attachments in a secure, cloud-based environment before they are delivered to the user's inbox. This provides an additional layer of security and can prevent new or unseen types of malware from infiltrating the organization's network. Impact Delivery of email with attachments may be delayed while scanning is occurring. Recommendation and Steps Associated Items
Affected Objects |
| 2.1.7 | Ensure that an anti-phishing policy has been created | Passed | Status:Created | N/A | E5 Level 2 | CIS v6.0 | YES |
X TEST NAME Ensure that an anti-phishing policy has been created Description By default, Office 365 includes built-in features that help protect users from phishing attacks. Set up anti-phishing polices to increase this protection, for example by refining settings to better detect and prevent impersonation and spoofing attacks. The default policy applies to all users within the organization and is a single view to fine-tune anti-phishing protection. Custom policies can be created and configured for specific users, groups or domains within the organization and will take precedence over the default policy for the scoped users. Rationale Protects users from phishing attacks (like impersonation and spoofing) and uses safety tips to warn users about potentially harmful messages. Impact Mailboxes that are used for support systems such as helpdesk and billing systems send mail to internal users and are often not suitable candidates for impersonation protection. Care should be taken to ensure that these systems are excluded from Impersonation Protection. Recommendation and Steps Associated Items
Affected Objects |
| 2.1.12 | Ensure the connection filter IP allow list is not used | Passed | Status:Not Used | IPAllowList : {} | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure the connection filter IP allow list is not used Description In Microsoft 365 organizations with Exchange Online mailboxes or standalone Exchange Online Protection (EOP) organizations without Exchange Online mailboxes, connection filtering and the default connection filter policy identify good or bad source email servers by IP addresses. The key components of the default connection filter policy are **IP Allow List**, **IP Block List** and **Safe list**. The recommended state is `IP Allow List` empty or undefined. Rationale Without additional verification like mail flow rules, email from sources in the IP Allow List skips spam filtering and sender authentication (SPF, DKIM, DMARC) checks. This method creates a high risk of attackers successfully delivering email to the Inbox that would otherwise be filtered. Messages that are determined to be malware or high confidence phishing are filtered. Impact This is the default behavior. IP Allow lists may reduce false positives, however, this benefit is outweighed by the importance of a policy which scans all messages regardless of the origin. This supports the principle of zero trust. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https://learn.microsoft.com/en-us/defender-office-365/connection-filter-policies-configure https://learn.microsoft.com/en-us/defender-office-365/create-safe-sender-lists-in-office-365#use-the-ip-allow-list https://learn.microsoft.com/en-us/defender-office-365/how-policies-and-protections-are-combined#user-and-tenant-settings-conflict
|
| 2.1.13 | Ensure the connection filter safe list is off | Passed | Status:Turned Off | EnableSafeList : False | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure the connection filter safe list is off Description In Microsoft 365 organizations with Exchange Online mailboxes or standalone Exchange Online Protection (EOP) organizations without Exchange Online mailboxes, connection filtering and the default connection filter policy identify good or bad source email servers by IP addresses. The key components of the default connection filter policy are **IP Allow List**, **IP Block List** and **Safe list**. The safe list is a pre-configured allow list that is dynamically updated by Microsoft. The recommended safe list state is: `Off` or `False` Rationale Without additional verification like mail flow rules, email from sources in the IP Allow List skips spam filtering and sender authentication (SPF, DKIM, DMARC) checks. This method creates a high risk of attackers successfully delivering email to the Inbox that would otherwise be filtered. Messages that are determined to be malware or high confidence phishing are filtered. The safe list is managed dynamically by Microsoft, and administrators do not have visibility into which sender are included. Incoming messages from email servers on the safe list bypass spam filtering. Impact This is the default behavior. IP Allow lists may reduce false positives, however, this benefit is outweighed by the importance of a policy which scans all messages regardless of the origin. This supports the principle of zero trust. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https://learn.microsoft.com/en-us/defender-office-365/connection-filter-policies-configure https://learn.microsoft.com/en-us/defender-office-365/create-safe-sender-lists-in-office-365#use-the-ip-allow-list https://learn.microsoft.com/en-us/defender-office-365/how-policies-and-protections-are-combined#user-and-tenant-settings-conflict
|
| 2.1.14 | Ensure inbound anti-spam policies do not contain allowed domains | Passed | Status:Not Allowed | AllowedSenderDomains : {} | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure inbound anti-spam policies do not contain allowed domains Description Anti-spam protection is a feature of Exchange Online that utilizes policies to help to reduce the amount of junk email, bulk and phishing emails a mailbox receives. These policies contain lists to allow or block specific senders or domains. - The allowed senders list - The allowed domains list - The blocked senders list - The blocked domains list The recommended state is: Do not define any `Allowed domains` Rationale Messages from entries in the allowed senders list or the allowed domains list bypass most email protection (except malware and high confidence phishing) and email authentication checks (SPF, DKIM and DMARC). Entries in the allowed senders list or the allowed domains list create a high risk of attackers successfully delivering email to the Inbox that would otherwise be filtered. The risk is increased even more when allowing common domain names as these can be easily spoofed by attackers. Microsoft specifies in its documentation that allowed domains should be used for testing purposes only. Impact This is the default behavior. Allowed domains may reduce false positives, however, this benefit is outweighed by the importance of having a policy which scans all messages regardless of the origin. As an alternative consider sender based lists. This supports the principle of zero trust. Recommendation and Steps Associated Items
Affected Objects
|
| 2.1.5 | Ensure Safe Attachments for SharePoint-OneDrive-Microsoft Teams is Enabled | Manual Check | NONE | N/A | E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure Safe Attachments for SharePoint-OneDrive-Microsoft Teams is Enabled Description Safe Attachments for SharePoint, OneDrive, and Microsoft Teams scans these services for malicious files. Rationale Safe Attachments for SharePoint, OneDrive, and Microsoft Teams protect organizations from inadvertently sharing malicious files. When a malicious file is detected that file is blocked so that no one can open, copy, move, or share it until further actions are taken by the organization's security team. Impact Impact associated with Safe Attachments is minimal, and equivalent to impact associated with anti-virus scanners in an environment. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft 365 Defender` https://security.microsoft.com 2. Under `Email & collaboration` select `Policies & rules` 3. Select Threat policies then `Safe Attachments`. 4. Click on `Global settings` 5. Click to `Enable` `Turn on Defender for Office 365 for SharePoint, OneDrive, and Microsoft Teams` 6. Click to `Enable` `Turn on Safe Documents for Office clients` 7. Click to `Disable` `Allow people to click through Protected View even if Safe Documents identified the file as malicious`. 8. Click `Save` **To remediate using PowerShell:** 1. Connect to Exchange Online using `Connect-ExchangeOnline`. 2. Run the following PowerShell command: ``` Set-AtpPolicyForO365 -EnableATPForSPOTeamsODB $true -EnableSafeDocs $true -AllowSafeDocsOpen $false ``` Associated Items Affected Objects More Information TEST ID
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 2.2.1 | Ensure emergency access account activity is monitored | Manual Check | NONE | A policy to monitor emergency access accounts does not exist by default. | E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure emergency access account activity is monitored Description Organizations should monitor sign-in and audit log activity from the emergency accounts and trigger notifications to other administrators. When you monitor the activity for emergency access accounts, you can verify these accounts are only used for testing or actual emergencies. You can use Azure Monitor, Microsoft Sentinel, Defender for Cloud Apps or other tools to monitor the sign-in logs and trigger email and SMS alerts to your administrators whenever emergency access accounts sign in. This recommendation uses Defender for Cloud Apps Policies to alert on emergency access account activity. The recommended state is to monitor `Activity type` `Log on` on break-glass or emergency access accounts. Rationale Emergency access accounts should be used in very few scenarios, for example, the last Global Administrator has left the organization and the account is inaccessible. All activity on an emergency access account should be reviewed at the time of the event to ensure the sign on is legitimate and authorized. Impact There is no real world impact to monitoring these accounts beyond allocating staff. The frequency of emergency account sign on should be so low that any activity raises a red flag that is treated with the highest priority. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft 365 Defender` https://security.microsoft.com 2. Under the **Cloud Apps** section select `Policies` -> `Policy management`. 3. Click on `All policies` and then `Create policy` -> `Activity policy`. 4. Give the policy a name and set the following: - Policy severity to `High severity`. - Category to `Privileged accounts`. - Act on `Single activity`. - Click `Select a filter` -> `Activity type` `equals` `Log on`. - Click `Add a filter` -> `User` `Name` `equals` Associated Items Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 2.4.1 | Ensure Priority account protection is enabled and configured | High | Priority Account Status:Not Enabled-Not Implemented | By default, priority accounts are undefined. | E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure Priority account protection is enabled and configured Description Identify _priority accounts_ to utilize Microsoft 365's advanced custom security features. This is an essential tool to bolster protection for users who are frequently targeted due to their critical positions, such as executives, leaders, managers, or others who have access to sensitive, confidential, financial, or high-priority information. Once these accounts are identified, several services and features can be enabled, including threat policies, enhanced sign-in protection through conditional access policies, and alert policies, enabling faster response times for incident response teams. Rationale Enabling priority account protection for users in Microsoft 365 is necessary to enhance security for accounts with access to sensitive data and high privileges, such as CEOs, CISOs, CFOs, and IT admins. These priority accounts are often targeted by spear phishing or whaling attacks and require stronger protection to prevent account compromise. To address this, Microsoft 365 and Microsoft Defender for Office 365 offer several key features that provide extra security, including the identification of incidents and alerts involving priority accounts and the use of built-in custom protections designed specifically for them. Impact Recommendation and Steps _Remediate with a 3-step process_ **Step 1: Enable Priority account protection in Microsoft 365 Defender:** 1. Navigate to `Microsoft 365 Defender` https://security.microsoft.com/ 2. Click to expand `System` select `Settings`. 3. Select `E-mail & Collaboration` > `Priority account protection` 4. Ensure `Priority account protection` is set to `On` **Step 2: Tag priority accounts:** 5. Select `User tags` 6. Select the `PRIORITY ACCOUNT` tag and click `Edit` 7. Select `Add members` to add users, or groups. **Groups are recommended.** 8. Repeat the previous 2 steps for any additional tags needed, such as Finance or HR. 9. `Next` and `Submit`. **Step 3: Configure E-mail alerts for Priority Accounts:** 10. Expand `E-mail & Collaboration` on the left column. 11. Select `Policies & rules` > `Alert policy` 12. Select `New Alert Policy` 13. Enter a valid policy Name & Description. Set `Severity` to `High` and `Category` to `Threat management`. 14. Set `Activity is` to `Detected malware in an e-mail message` 15. Mail direction is `Inbound` 16. Select `Add Condition` and `User: recipient tags are` 17. In the `Selection option` field add chosen priority tags such as Priority account. 18. Select `Every time an activity matches the rule`. 19. `Next` and verify valid recipient(s) are selected. 20. `Next` and select `Yes, turn it on right away.` Click `Submit` to save the alert. 21. Repeat steps 12 - 18 to create a 2nd alert for the Activity field `Activity is`: `Phishing email detected at time of delivery` **Note:** Any additional activity types may be added as needed. Above are the minimum recommended. Associated Items
Affected Objects |
| 2.4.4 | Ensure Zero-hour auto purge for Microsoft Teams is on | Passed | Status:License Not Available - Control Not Applicable | On (Default) | E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure Zero-hour auto purge for Microsoft Teams is on Description Zero-hour auto purge (ZAP) is a protection feature that retroactively detects and neutralizes malware and high confidence phishing. When ZAP for Teams protection blocks a message, the message is blocked for everyone in the chat. The initial block happens right after delivery, but ZAP occurs up to 48 hours after delivery. Rationale ZAP is intended to protect users that have received zero-day malware messages or content that is weaponized after being delivered to users. It does this by continually monitoring spam and malware signatures taking automated retroactive action on messages that have already been delivered. Impact As with any anti-malware or anti-phishing product, false positives may occur. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https://learn.microsoft.com/en-us/defender-office-365/zero-hour-auto-purge?view=o365-worldwide#zero-hour-auto-purge-zap-in-microsoft-teams https://learn.microsoft.com/en-us/defender-office-365/mdo-support-teams-about?view=o365-worldwide#configure-zap-for-teams-protection-in-defender-for-office-365-plan-2
|
| Not Available | Ensure the Account Provisioning Activity report is reviewed and actioned | Passed | Account Provisioning Items:0 | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure the Account Provisioning Activity report is reviewed and actioned Description Rationale Impact Auditing Process needs to be created and followed. Recommendation and Steps Associated Items
Affected Objects |
| Not Available | Ensure non-global administrator role group assignments are reviewed and actioned | Passed | Status:Found non-admin Global Role assignments found in past 7 days | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure non-global administrator role group assignments are reviewed and actioned Description Rationale Impact Auditing Process needs to be created and followed. Recommendation and Steps Associated Items
Affected Objects |
| 2.4.3 | Ensure Microsoft Defender for Cloud Apps is Enabled | Manual Check | NONE | Disabled | E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure Microsoft Defender for Cloud Apps is Enabled Description Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB). It provides visibility into suspicious activity in Microsoft 365, enabling investigation into potential security issues and facilitating the implementation of remediation measures if necessary. Some risk detection methods provided by Entra Identity Protection also require Microsoft Defender for Cloud Apps: - Suspicious manipulation of inbox rules - Suspicious inbox forwarding - New country detection - Impossible travel detection - Activity from anonymous IP addresses - Mass access to sensitive files Rationale Security teams can receive notifications of triggered alerts for atypical or suspicious activities, see how the organization's data in Microsoft 365 is accessed and used, suspend user accounts exhibiting suspicious activity, and require users to log back in to Microsoft 365 apps after an alert has been triggered. Impact Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft 365 Defender` https://security.microsoft.com/ 2. Click to expand `System` select `Settings` > `Cloud apps`. 3. Scroll to `Information Protection` and select `Files`. 4. Check `Enable file monitoring`. 5. Scroll up to `Cloud Discovery` and select `Microsoft Defender for Endpoint.` 6. Check `Enforce app access`, configure a Notification URL and `Save`. **Note:** Defender for Endpoint requires a Defender for Endpoint license. **Configure App Connectors:** 1. Scroll to `Connected apps` and select `App connectors`. 2. Click on `Connect an app` and select `Microsoft 365`. 3. Check all Azure and Office 365 boxes then click `Connect Office 365`. 4. Repeat for the `Microsoft Azure` application. Associated Items Affected Objects More Information TEST ID
LINK
https://learn.microsoft.com/en-us/defender-cloud-apps/protect-office-365#connect-microsoft-365-to-microsoft-defender-for-cloud-apps https://learn.microsoft.com/en-us/defender-cloud-apps/protect-azure#connect-azure-to-microsoft-defender-for-cloud-apps https://learn.microsoft.com/en-us/defender-cloud-apps/best-practices https://learn.microsoft.com/en-us/defender-cloud-apps/get-started https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Not Available | Ensure user role group changes are reviewed and actioned | High | Status:There are user role group changes found in past 7 days | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure user role group changes are reviewed and actioned Description Rationale Impact By performing regular reviews, the Administrators assigning rights to users will need to inevitably provide justification for those changes to security auditors. Documentation that includes detailed policies, procedures, and change requests will need to be considered in order to keep a secure organization functioning within its planned operational level. Recommendation and Steps Role-Based Access Control allows for permissions to be assigned to users based on their roles within an organization. It is a more manageable form of access control that is less prone to errors. These user roles can be audited inside of Microsoft Purview to provide a security auditor insight into user privilege change. Associated Items
Affected Objects More Information TEST ID
|
| 3.1.1 | Ensure Microsoft 365 audit log search is Enabled | Passed | Status:Enabled | 180 days | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure Microsoft 365 audit log search is Enabled Description When audit log search is enabled in the Microsoft Purview compliance portal, user and admin activity within the organization is recorded in the audit log and retained for 180 days by default. However, some organizations may prefer to use a third-party security information and event management (SIEM) application to access their auditing data. In this scenario, a global admin can choose to turn off audit log search in Microsoft 365. Rationale Enabling audit log search in the Microsoft Purview compliance portal can help organizations improve their security posture, meet regulatory compliance requirements, respond to security incidents, and gain valuable operational insights. Impact Recommendation and Steps Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 3.2.1 | Ensure DLP policies are enabled | High | Status:The DLP Policy is NOT Enabled | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure DLP policies are enabled Description Data Loss Prevention (DLP) policies allow Exchange Online and SharePoint Online content to be scanned for specific types of data like social security numbers, credit card numbers, or passwords. Rationale Enabling DLP policies alerts users and administrators that specific types of data should not be exposed, helping to protect the data from accidental exposure. Impact Enabling a Teams DLP policy will allow sensitive data in Exchange Online and SharePoint Online to be detected or blocked. Always ensure to follow appropriate procedures during testing and implementation of DLP policies based on organizational standards. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Purview` https://purview.microsoft.com/ 2. Click `Solutions` > `Data loss prevention` then `Policies`. 3. Click `Create policy`. 4. Create a policy that is specific to the types of data the organization wishes to protect. Associated Items
Affected Objects More Information TEST ID
|
| 3.2.2 | Ensure DLP policies are enabled for Microsoft Teams | High | Status:No DLP Policy Found | Enabled (On) | E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure DLP policies are enabled for Microsoft Teams Description The default Teams Data Loss Prevention (DLP) policy rule in Microsoft 365 is a preconfigured rule that is automatically applied to all Teams conversations and channels. The default rule helps prevent accidental sharing of sensitive information by detecting and blocking certain types of content that are deemed sensitive or inappropriate by the organization. By default, the rule includes a check for the sensitive info type _Credit Card Number_ which is pre-defined by Microsoft. Rationale Enabling the default Teams DLP policy rule in Microsoft 365 helps protect an organization's sensitive information by preventing accidental sharing or leakage Credit Card information in Teams conversations and channels. DLP rules are not one size fits all, but at a minimum something should be defined. The organization should identify sensitive information important to them and seek to intercept it using DLP. Impact End-users may be prevented from sharing certain types of content, which may require them to adjust their behavior or seek permission from administrators to share specific content. Administrators may receive requests from end-users for permission to share certain types of content or to modify the policy to better fit the needs of their teams. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Purview` compliance portal https://purview.microsoft.com/ 2. Under `Solutions` select `Data loss prevention` then `Policies`. 3. Click `Policies` tab. 4. Check `Default policy for Teams` then click `Edit policy`. 5. The edit policy window will appear click Next 6. At the `Choose locations to apply the policy` page, turn the status toggle to `On` for `Teams chat and channel messages` location and then click Next. 7. On Customized advanced DLP rules page, ensure the `Default Teams DLP policy rule` Status is `On` and click Next. 9. On the Policy mode page, select the radial for `Turn it on right away` and click Next. 10. Review all the settings for the created policy on the Review your policy and create it page, and then click submit. 11. Once the policy has been successfully submitted click Done. **Note:** Some tenants may not have a default policy for teams as Microsoft started creating these by default at a particular point in time. In this case a new policy will have to be created that includes a rule to protect data important to the organization such as credit cards and PII. Associated Items
Affected Objects |
| Not Available | Ensure DLP Policy is enabled for OneDrive | High | Status:Not Enabled | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure DLP Policy is enabled for OneDrive Description Rationale Impact Data Loss Prevention (DLP) capabilities protect your data where it is stored, when it is moved, and when it is shared. Recommendation and Steps It is recommended to enable DLP for OneDrive. Associated Items
Affected Objects |
| Not Available | Ensure DLP Policy is configured for SharePoint | High | Status:Not Enabled | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure DLP Policy is configured for SharePoint Description Rationale Impact As businesses continue to digitize their operations, data protection has become a top priority. Microsoft SharePoint Online, a cloud-based collaboration and document management solution, offers a built-in Data Loss Prevention (DLP) solution to help safeguard sensitive information. DLP in SharePoint Online is important because it helps organizations protect their sensitive information from being shared with unauthorized parties. This is especially critical in industries that are highly regulated, such as healthcare and finance. Recommendation and Steps It is recommended to enable DLP Policy for SharePoint. Associated Items
Affected Objects |
| Not Available | Ensure Custom Anti-Malware Policy is Present | High | Status:Not Defined | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Custom Anti-Malware Policy is Present Description Rationale Impact It is possible to create custom anti-malware policies in Exchange Online to provide additional protection against threats that may be received via email. No anti-malware policy besides the Microsoft Default Anti-Malware Policy was detected in the O365 Tenant. Although the default anti-malware policy can provide some protection, each organization should consider creating an anti-malware policy that is customized to suit the nature of their day-to-day activities. Recommendation and Steps Follow the 'Configure anti-malware policies in Exchange Online Protection' guide below for a full introduction to creating a custom anti-malware policy. It is possible to create an anti-malware policy and enable it through the Exchange administration center or via Exchange Online PowerShell using the Set-MalwareFilterPolicy or New-MalwareFilterPolicy commands. Associated Items
Affected Objects |
| Not Available | Ensure Custom Anti-Phishing Policy is Present | High | Status:Not Defined | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Custom Anti-Phishing Policy is Present Description Rationale Impact It is possible to create custom Anti-Phishing Policies in Exchange Online to provide additional protection against threats that may be received via email. No Anti-Phishing Policy besides the Microsoft Default Anti-Phishing Policy was detected in the O365 tenant. Although the default Anti-Phishing Policy can provide some protection, each organization should consider creating an Anti-Phishing Policy that is customized to suit the nature of their day-to-day activities. Recommendation and Steps Follow the 'Anti-Phishing Policies in Microsoft 365' article below to begin constructing a custom Anti-Phishing Policy. Associated Items
Affected Objects |
| Not Available | Ensure Custom DLP Policies are Present | High | Status:Not Defined-Not Implemented | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Custom DLP Policies are Present Description Rationale Impact Organizations have sensitive information under their control such as financial data, proprietary data, credit card numbers, health records, or social security numbers. To help protect this sensitive data and reduce risk, they need a way to prevent their users from inappropriately sharing it with people who should not have it. Default configurations may not meet the business needs, or compliance requirements of the organization. Custom policies can be configured to address any gaps that default settings do not remediate. Recommendation and Steps Determine if a custom DLP policy is beneficial for the Tenant, identify any gaps between desired end state and default policy configurations, and implement any new policies as needed. Associated Items
Affected Objects More Information TEST ID
|
| Not Available | Ensure Custom DLP Sensitive Information Types are Defined | High | Status:Not Defined-Not Implemented | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Custom DLP Sensitive Information Types are Defined Description Rationale Impact Organizations have sensitive information under their control such as financial data, proprietary data, credit card numbers, health records, or social security numbers. Default configurations may not meet the business needs, or compliance requirements of the organization. Custom-defined information types may be configured to mitigate any gaps that default settings do not address. Recommendation and Steps Determine if there is a need for custom DLP Sensitive Information types and add as needed. Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 3.3.1 | Ensure Information Protection sensitivity label policies are published | Manual Check | NONE | The Global sensitivity label policy exists by default. | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure Information Protection sensitivity label policies are published Description Sensitivity labels enable organizations to classify and label content across Microsoft 365 based on its sensitivity and business impact. These labels can be applied manually by users or automatically based on the content. When applied, labels can automatically encrypt content, provide Confidential watermarks, restrict access, and offer various data protection features. Labels can be scoped to data assets and containers: - Files & other data assets in Microsoft 365, Fabric, Azure, AWS and other platforms - Email messages sent from all versions of Outlook - Meeting calendar events and schedules in Outlook and Teams - Teams, Microsoft 365 Groups and SharePoint sites Rationale Consistent usage of sensitivity labels can help reduce the risk of data loss or exposure and enable more effective incident response if a breach does occur. They can also help organizations comply with regulatory requirements and provide visibility and control over sensitive information. Impact Encryption configurations (control access, DKE, BYOK) in the individual labels may impact users? ability to access site documents and information. Careful consideration of the individual sensitivity label configurations should be exercised prior to applying an auto labeling policy, publishing policy, sensitivity label configuration, or PowerShell based label settings to SharePoint sites. Additionally, when updating or deleting Sensitivity Labels, an assessment of the potential impacts should be conducted to avoid unintended consequences. If tenants are configured for sharing with guests or external domains and Sensitivity Labels have encryption applied, this can affect the ability to share documents via email stored in SharePoint. Some recipients may be unable to open the document depending on their email client, which could trigger Purview Advanced Encryptions and OME flows based on the recipient type and the cloud license from which the email is sent (e.g., government clouds vs. commercial clouds). Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Purview` compliance portal https://purview.microsoft.com/ 2. Select `Information protection` > `Sensitivity labels`. 3. Click `Create a label` to create a label. 4. Click `Publish labels` and select any newly created labels to publish according to the organization's information protection needs. Associated Items Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 4.1 | Ensure devices without a compliance policy are marked not compliant | High | Compliance Policy Default Behavior:1 | UI: Compliant Graph: secureByDefault = $false | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure devices without a compliance policy are marked not compliant Description Compliance policies are sets of rules and conditions that are used to evaluate the configuration of managed devices. These policies can help secure organizational data and resources from devices that don't meet those configuration requirements. Managed devices must satisfy the conditions you set in your policies to be considered compliant by Intune. When combined with conditional access, this allows more control over how non-compliant devices are treated. The recommended state is `Mark devices with no compliance policy assigned as` as `Not compliant` Rationale Implementing this setting is a first step in adopting compliance policies for devices. When used in together with Conditional Access policies the attack surface can be reduced by forcing an action to be taken for non-compliant devices. **Note:** This section does not focus on which compliance policies to use, only that an organization should adopt and enforce them to their needs. Impact Any devices without a compliance policy will be marked not compliant. Care should be taken to first deploy any new compliance policies with a Conditional Access (CA) policy that is in the **Report-only** state. After the environment's device compliance is better understood it is then appropriate to finally align with `Mark devices with no compliance policy assigned as` and enable any CA policies that enforce actions based on device compliance. If a mature environment already has an existing device compliance CA policy and a large number of devices without an assigned compliance policy, this could cause disruption as those devices would then be suddenly considered not compliant. Recommendation and Steps **To remediate using the UI:**
1. Navigate to?`Microsoft Intune admin center` https://intune.microsoft.com/
2. Select `Devices` and then?under **Manage devices** click `Compliance`
3. Click `Compliance settings`.
4. Set `Mark devices with no compliance policy assigned as` to `Not compliant`.
**To remediate using PowerShell:**
1. Connect to Microsoft Graph using `Connect-MgGraph -Scopes DeviceManagementConfiguration.ReadWrite.All`
2. Run the following commands:
```
$Uri = 'https://graph.microsoft.com/v1.0/deviceManagement'
$Body = @{
settings = @{
secureByDefault = $true
}
} | ConvertTo-Json
Invoke-MgGraphRequest -Uri $Uri -Method PATCH -Body $Body
```
Associated Items
Affected Objects
More Information TEST ID
|
| Not Available | Ensure Security Defaults is disabled on Azure Active Directory | Passed | Status:Security Defaults are disabled. | Enabled. | N/A | SP v1.0 | YES |
X TEST NAME Ensure Security Defaults is disabled on Azure Active Directory Description Rationale Impact The potential impact associated with disabling of Security Defaults is dependent upon the security controls implemented in the environment. It is likely that most organizations disabling Security Defaults plan to implement equivalent controls to replace Security Defaults. It may be necessary to check settings in other Microsoft products, such as Azure, to ensure settings and functionality are as expected when disabling security defaults for MS365. Recommendation and Steps Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 5.1.2.3 | Ensure Restrict non-admin users from creating tenants is set to Yes | High | Permission Status:Enabled-Not Ok | No - Non-administrators can create tenants. `AllowedToCreateTenants` is `True` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure Restrict non-admin users from creating tenants is set to Yes Description Non-privileged users can create tenants in the Microsoft Entra ID and Microsoft Entra administration portal under Manage tenant. The creation of a tenant is recorded in the Audit log as category DirectoryManagement and activity Create Company. By default, the user who creates a Microsoft Entra tenant is automatically assigned the Global Administrator role. The newly created tenant doesn't inherit any settings or configurations. Rationale Restricting tenant creation prevents unauthorized or uncontrolled deployment of resources and ensures that the organization retains control over its infrastructure. User generation of shadow IT could lead to multiple, disjointed environments that can make it difficult for IT to manage and secure the organization's data, especially if other users in the organization began using these tenants for business purposes under the misunderstanding that they were secured by the organization's security team. Impact Non-admin users will need to contact I.T. if they have a valid reason to create a tenant. Recommendation and Steps **To remediate using the UI:**
1. Navigate to `Microsoft Entra admin center` https://entra.microsoft.com/
2. Click to expand `Identity`> `Users` > `User settings`.
3. Set `Restrict non-admin users from creating tenants` to `Yes` then `Save`.
**To remediate using PowerShell:**
1. Connect to Microsoft Graph using `Connect-MgGraph -Scopes Policy.ReadWrite.Authorization`
2. Run the following commands:
```
# Create hashtable and update the auth policy
$params = @{ AllowedToCreateTenants = $false }
Update-MgPolicyAuthorizationPolicy -DefaultUserRolePermissions $params
```
Associated Items Affected Objects More Information TEST ID
|
| 5.1.2.1 | Ensure Per-user MFA is disabled | Passed | Total Users Not Enabled with Per MFA:0 | Disabled | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure Per-user MFA is disabled Description Legacy per-user Multi-Factor Authentication (MFA) can be configured to require individual users to provide multiple authentication factors, such as passwords and additional verification codes, to access their accounts. It was introduced in earlier versions of Office 365, prior to the more comprehensive implementation of Conditional Access (CA). Rationale Both security defaults and conditional access with security defaults turned off are not compatible with per-user multi-factor authentication (MFA), which can lead to undesirable user authentication states. The CIS Microsoft 365 Benchmark explicitly employs Conditional Access for MFA as an enhancement over security defaults and as a replacement for the outdated per-user MFA. To ensure a consistent authentication state disable per-user MFA on all accounts. Impact Accounts using per-user MFA will need to be migrated to use CA. Prior to disabling per-user MFA the organization must be prepared to implement conditional access MFA to avoid security gaps and allow for a smooth transition. This will help ensure relevant accounts are covered by MFA during the change phase from disabling per-user MFA to enabling CA MFA. Section 5.2.2 in this document covers the creation of a CA rule for both administrators and all users in the tenant. Microsoft has documentation on migrating from per-user MFA [Convert users from per-user MFA to Conditional Access based MFA](https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-getstarted#convert-users-from-per-user-mfa-to-conditional-access-based-mfa) Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https://learn.microsoft.com/en-us/entra/identity/authentication/howto-mfa-userstates#convert-users-from-per-user-mfa-to-conditional-access https://learn.microsoft.com/en-us/microsoft-365/admin/security-and-compliance/set-up-multi-factor-authentication?view=o365-worldwide#use-conditional-access-policies https://learn.microsoft.com/en-us/entra/identity/authentication/howto-mfa-userstates#convert-per-user-mfa-enabled-and-enforced-users-to-disabled
|
| 5.1.2.2 | Ensure third party integrated applications are not allowed | Passed | Status:Not Allowed | Yes (Users can register applications.) | E3 Level 2-E5 Level 2 | CIS v6.0 | YES |
X TEST NAME Ensure third party integrated applications are not allowed Description App registration allows users to register custom-developed applications for use within the directory. Rationale Third-party integrated applications connection to services should be disabled unless there is a very clear value and robust security controls are in place. While there are legitimate uses, attackers can grant access from breached accounts to third party applications to exfiltrate data from your tenancy without having to maintain the breached account. Impact The implementation of this change will impact both end users and administrators. End users will not be able to integrate third-party applications that they may wish to use. Administrators are likely to receive requests from end users to grant them permission to the necessary third-party applications. Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
|
| 5.1.2.4 | Ensure access to the Entra admin center is restricted | Manual Check | NONE | No - Non-administrators can access the Microsoft Entra admin center. | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure access to the Entra admin center is restricted Description Restrict non-privileged users from signing into the Microsoft Entra admin center. **Note:** This recommendation only affects access to the web portal. It does not prevent privileged users from using other methods such as Rest API or PowerShell to obtain information. Those channels are addressed elsewhere in this document. Rationale The Microsoft Entra admin center contains sensitive data and permission settings, which are still enforced based on the user's role. However, an end user may inadvertently change properties or account settings that could result in increased administrative overhead. Additionally, a compromised end user account could be used by a malicious attacker as a means to gather additional information and escalate an attack. **Note:** Users will still be able to sign into Microsoft Entra admin center but will be unable to see directory information. Impact In the event there are resources a user owns that need to be changed in the Entra Admin center, then an administrator would need to make those changes. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Entra admin center` https://entra.microsoft.com/ 2. Click to expand `Identity`> `Users` > `User settings`. 3. Set `Restrict access to Microsoft Entra admin center` to `Yes` then `Save`. Associated Items Affected Objects More Information TEST ID
|
| 5.1.2.5 | Ensure the option to remain signed in is hidden | Manual Check | NONE | Users may select `stay signed in` | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure the option to remain signed in is hidden Description The option for the user to `Stay signed in`, or the `Keep me signed in` option, will prompt a user after a successful login. When the user selects this option, a persistent refresh token is created. The refresh token lasts for 90 days by default and does not prompt for sign-in or multifactor. Rationale Allowing users to select this option presents risk, especially if the user signs into their account on a publicly accessible computer/web browser. In this case it would be trivial for an unauthorized person to gain access to any associated cloud data from that account. Impact Once this setting is hidden users will no longer be prompted upon sign-in with the message `Stay signed in?`. This may mean users will be forced to sign in more frequently. Important: some features of SharePoint Online and Office 2010 have a dependency on users remaining signed in. If you hide this option, users may get additional and unexpected sign in prompts. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Entra admin center` https://entra.microsoft.com/. 2. Click to expand `Identity`> `Users` > `User settings`. 3. Set `Show keep user signed in` to `No`. 4. Click `Save`. Associated Items Affected Objects |
| 5.1.2.6 | Ensure LinkedIn account connections is disabled | Manual Check | NONE | LinkedIn integration is enabled by default. | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure LinkedIn account connections is disabled Description LinkedIn account connections allow users to connect their Microsoft work or school account with LinkedIn. After a user connects their accounts, information and highlights from LinkedIn are available in some Microsoft apps and services. Rationale Disabling LinkedIn integration prevents potential phishing attacks and risk scenarios where an external party could accidentally disclose sensitive information. Impact Users will not be able to sync contacts or use LinkedIn integration. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Entra admin center` https://entra.microsoft.com/. 2. Click to expand `Identity` > `Users` select `User settings`. 3. Under `LinkedIn account connections` select `No`. 4. Click `Save`. Associated Items Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 5.1.3.1 | Ensure a dynamic group for guest users is created | High | Status:Dynamic Groups for Guest users not found | Undefined | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure a dynamic group for guest users is created Description A dynamic group is a dynamic configuration of security group membership for Microsoft Entra ID. Administrators can set rules to populate groups that are created in Entra ID based on user attributes (such as userType, department, or country/region). Members can be automatically added to or removed from a security group based on their attributes. The recommended state is to create a dynamic group that includes guest accounts. Rationale Dynamic groups allow for an automated method to assign group membership. Guest user accounts will be automatically added to this group and through this existing conditional access rules, access controls and other security measures will ensure that new guest accounts are restricted in the same manner as existing guest accounts. Impact Recommendation and Steps **To remediate using the UI:**
1. Navigate to `Microsoft Entra admin center` https://entra.microsoft.com/.
2. Click to expand `Identity` > `Groups` select `All groups`.
3. Select `New group` and assign the following values:
- Group type: `Security`
- Microsoft Entra roles can be assigned to the group: `No`
- Membership type: `Dynamic User`
4. Select `Add dynamic query`.
5. Above the `Rule syntax` text box, select `Edit`.
6. Place the following expression in the box:
```
(user.userType -eq Guest)
```
7. Select `OK` and `Save`
**To remediate using PowerShell:**
1. Connect to Microsoft Graph using `Connect-MgGraph -Scopes Group.ReadWrite.All`
2. In the script below edit `DisplayName` and `MailNickname` as needed and run:
```
$params = @{
DisplayName = Dynamic Test Group
MailNickname = DynGuestUsers
MailEnabled = $false
SecurityEnabled = $true
GroupTypes = DynamicMembership
MembershipRule = '(user.userType -eq Guest)'
MembershipRuleProcessingState = On
}
New-MgGroup @params
```
Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 5.1.5.1 | Ensure user consent to apps accessing company data on their behalf is not allowed | Medium | Status: Not Configured | UI - `Allow user consent for apps` | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure user consent to apps accessing company data on their behalf is not allowed Description Control when end users and group owners are allowed to grant consent to applications, and when they will be required to request administrator review and approval. Allowing users to grant apps access to data helps them acquire useful applications and be productive but can represent a risk in some situations if it's not monitored and controlled carefully. Rationale Attackers commonly use custom applications to trick users into granting them access to company data. Restricting user consent mitigates this risk and helps to reduce the threat-surface. Impact If user consent is disabled, previous consent grants will still be honored but all future consent operations must be performed by an administrator. Tenant-wide admin consent can be requested by users through an integrated administrator consent request workflow or through organizational support processes. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Entra admin center` https://entra.microsoft.com/. 2. Click to expand `Identity` > `Applications` select `Enterprise applications`. 3. Under `Security` select `Consent and permissions` > `User consent settings`. 4. Under `User consent for applications` select `Do not allow user consent`. 5. Click the `Save` option at the top of the window. Associated Items
Affected Objects More Information TEST ID
|
| 5.1.5.2 | Ensure the admin consent workflow is enabled | Passed | Status:Enabled | '- `Users can request admin consent to apps they are unable to consent to`: `No` - `Selected users to review admin consent requests`: `None` - `Selected users will receive email notifications for requests`: `Yes` - `Selected users will receive request expiration reminders`: `Yes` - `Consent request expires after (days)`: `30` | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure the admin consent workflow is enabled Description The admin consent workflow gives admins a secure way to grant access to applications that require admin approval. When a user tries to access an application but is unable to provide consent, they can send a request for admin approval. The request is sent via email to admins who have been designated as reviewers. A reviewer takes action on the request, and the user is notified of the action. Rationale The admin consent workflow (Preview) gives admins a secure way to grant access to applications that require admin approval. When a user tries to access an application but is unable to provide consent, they can send a request for admin approval. The request is sent via email to admins who have been designated as reviewers. A reviewer acts on the request, and the user is notified of the action. Impact To approve requests, a reviewer must be a global administrator, cloud application administrator, or application administrator. The reviewer must already have one of these admin roles assigned; simply designating them as a reviewer doesn't elevate their privileges. Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 5.1.6.3 | Ensure guest user invitations are limited to the Guest Inviter role | High | Status:Mot Restricted | '- UI: `Anyone in the organization can invite guest users including guests and non-admins (most inclusive)` - PowerShell: `everyone` | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure guest user invitations are limited to the Guest Inviter role Description By default, all users in the organization, including B2B collaboration guest users, can invite external users to B2B collaboration. The ability to send invitations can be limited by turning it on or off for everyone, or by restricting invitations to certain roles. The recommended state for guest invite restrictions is `Only users assigned to specific admin roles can invite guest users`. Rationale Restricting who can invite guests limits the exposure the organization might face from unauthorized accounts. Impact This introduces an obstacle to collaboration by restricting who can invite guest users to the organization. Designated Guest Inviters must be assigned, and an approval process established and clearly communicated to all users. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Entra admin center` https://entra.microsoft.com/. 2. Click to expand `Identity` > `External Identities` select `External collaboration settings`. 3. Under **Guest invite settings** set `Guest invite restrictions` to `Only users assigned to specific admin roles can invite guest users`. **To remediate using PowerShell:** 1. Connect to Microsoft Graph using `Connect-MgGraph -Scopes Policy.ReadWrite.Authorization` 2. Run the following command: ``` Update-MgPolicyAuthorizationPolicy -AllowInvitesFrom 'adminsAndGuestInviters' ``` **Note:** The more restrictive position of the value will also pass audit, it is however not required. Associated Items
Affected Objects
|
| 5.1.6.2 | Ensure that guest user access is restricted | Passed | Status:Restricted | '- UI: `Guest users have limited access to properties and memberships of directory objects` - PowerShell: `10dae51f-b6af-4016-8d66-8c2a99b929b3` | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure that guest user access is restricted Description Microsoft Entra ID, part of Microsoft Entra, allows you to restrict what external guest users can see in their organization in Microsoft Entra ID. Guest users are set to a limited permission level by default in Microsoft Entra ID, while the default for member users is the full set of user permissions. These directory level permissions are enforced across Microsoft Entra services including Microsoft Graph, PowerShell v2, the Azure portal, and My Apps portal. Microsoft 365 services leveraging Microsoft 365 groups for collaboration scenarios are also affected, specifically Outlook, Microsoft Teams, and SharePoint. They do not override the SharePoint or Microsoft Teams guest settings. The recommended state is at least `Guest users have limited access to properties and memberships of directory objects` or more restrictive. Rationale By limiting guest access to the _most restrictive_ state this helps prevent malicious group and user object enumeration in the Microsoft 365 environment. This first step, known as _reconnaissance_ in The Cyber Kill Chain, is often conducted by attackers prior to more advanced targeted attacks. Impact The default is `Guest users have limited access to properties and memberships of directory objects`. When using the 'most restrictive' setting, guests will only be able to access their own profiles and will not be allowed to see other users' profiles, groups, or group memberships. There are some known issues with Yammer that will prevent guests that are signed in from leaving the group. Recommendation and Steps Associated Items
Affected Objects
|
| 5.1.6.1 | Ensure that collaboration invitations are sent to allowed domains only | Manual Check | NONE | Allow invitations to be sent to any domain (most inclusive) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure that collaboration invitations are sent to allowed domains only Description B2B collaboration is a feature within Microsoft Entra External ID that allows for guest invitations to an organization. Ensure users can only send invitations to `specified domains`. **Note:** This list works independently from OneDrive for Business and SharePoint Online allow/block lists. To restrict individual file sharing in SharePoint Online, set up an allow or blocklist for OneDrive for Business and SharePoint Online. For instance, in SharePoint or OneDrive users can still share with external users from prohibited domains by using Anyone links if they haven't been disabled. Rationale By specifying allowed domains for collaborations, external user's companies are explicitly identified. Also, this prevents internal users from inviting unknown external users such as personal accounts and granting them access to resources. Impact This could make collaboration more difficult if the setting is not quickly updated when a new domain is identified as allowed. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Entra admin center` https://entra.microsoft.com/. 2. Click to expand `Identity` > `External Identities` select `External collaboration settings`. 3. Under **Collaboration restrictions**, select `Allow invitations only to the specified domains (most restrictive)` is selected. Then specify the allowed domains under `Target domains`. Associated Items Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 5.1.8.1 | Ensure that password hash sync is enabled for hybrid deployments | Passed | Status:Password Hash Sync is enabled. | '- Microsoft Entra Connect sync `disabled` by default - Password Hash Sync is Microsoft's recommended setting for new deployments | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure that password hash sync is enabled for hybrid deployments Description Password hash synchronization is one of the sign-in methods used to accomplish hybrid identity synchronization. Microsoft Entra Connect synchronizes a hash, of the hash, of a user's password from an on-premises Active Directory instance to a cloud-based Entra ID instance. **Note:** Audit and remediation procedures in this recommendation only apply to Microsoft 365 tenants operating in a hybrid configuration using Entra Connect sync, and do not apply to federated domains. Rationale Password hash synchronization helps by reducing the number of passwords your users need to maintain to just one and enables leaked credential detection for your hybrid accounts. Leaked credential protection is leveraged through Entra ID Protection and is a subset of that feature which can help identify if an organization's user account passwords have appeared on the dark web or public spaces. Using other options for your directory synchronization may be less resilient as Microsoft can still process sign-ins to 365 with Hash Sync even if a network connection to your on-premises environment is not available. This minimizes downtime and ensures business continuity. Impact Compliance or regulatory restrictions may exist, depending on the organization's business sector, that preclude hashed versions of passwords from being securely transmitted to cloud data centers. Recommendation and Steps Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 5.2.2.1 | Ensure multifactor authentication is enabled for all users in administrative roles | High | Admins Without MFA:You have 7 out of 7 users with administrative roles that aren?t registered and protected with MFA. | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure multifactor authentication is enabled for all users in administrative roles Description Multifactor authentication is a process that requires an additional form of identification during the sign-in process, such as a code from a mobile device or a fingerprint scan, to enhance security. Ensure users in administrator roles have MFA capabilities enabled. Rationale Multifactor authentication requires an individual to present a minimum of two separate forms of authentication before access is granted. Multifactor authentication provides additional assurance that the individual attempting to gain access is who they claim to be. With multifactor authentication, an attacker would need to compromise at least two different authentication mechanisms, increasing the difficulty of compromise and thus reducing the risk. Impact Implementation of multifactor authentication for all users in administrative roles will necessitate a change to user routine. All users in administrative roles will be required to enroll in multifactor authentication using phone, SMS, or an authentication application. After enrollment, use of multifactor authentication will be required for future access to the environment. Recommendation and Steps **To remediate using the UI:** 1. Navigate to the `Microsoft Entra admin center` https://entra.microsoft.com. 2. Click expand `Protection` > `Conditional Access` select `Policies`. 3. Click `New policy`. - Under `Users` include `Select users and groups` and check `Directory roles`. - At a minimum, include the directory roles listed below in this section of the document. - Under `Target resources` include `All resources (formerly 'All cloud apps')` and do not create any exclusions. - Under `Grant` select `Grant Access` and check either `Require multifactor authentication` or `Require authentication strength`. - Click `Select` at the bottom of the pane. 4. Under `Enable policy` set it to `Report-only` until the organization is ready to enable it. 5. Click `Create`. **At minimum these directory roles should be included for MFA:** - Application administrator - Authentication administrator - Billing administrator - Cloud application administrator - Conditional Access administrator - Exchange administrator - Global administrator - Global reader - Helpdesk administrator - Password administrator - Privileged authentication administrator - Privileged role administrator - Security administrator - SharePoint administrator - User administrator **Note:** Report-only is an acceptable first stage when introducing any CA policy. The control, however, is not complete until the policy is on. Associated Items
Affected Objects More Information TEST ID
|
| 5.2.2.2 | Ensure multifactor authentication is enabled for all users | High | Status:Multifactor Authentication is not enabled for all users | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure multifactor authentication is enabled for all users Description Enable multifactor authentication for all users in the Microsoft 365 tenant. Users will be prompted to authenticate with a second factor upon logging in to Microsoft 365 services. The second factor is most commonly a text message to a registered mobile phone number where they type in an authorization code, or with a mobile application like Microsoft Authenticator. Rationale Multifactor authentication requires an individual to present a minimum of two separate forms of authentication before access is granted. Multifactor authentication provides additional assurance that the individual attempting to gain access is who they claim to be. With multifactor authentication, an attacker would need to compromise at least two different authentication mechanisms, increasing the difficulty of compromise and thus reducing the risk. Impact Implementation of multifactor authentication for all users will necessitate a change to user routine. All users will be required to enroll in multifactor authentication using phone, SMS, or an authentication application. After enrollment, use of multifactor authentication will be required for future authentication to the environment. External identities that attempt to access documents that utilize Purview Information Protection (Sensitivity Labels) will find their access disrupted. In order to mitigate this create an exclusion for `Microsoft Rights Management Services` ID: 00000012-0000-0000-c000-000000000000 **Note:** Organizations that struggle to enforce MFA globally due to budget constraints preventing the provision of company-owned mobile devices to every user, or due to regulations, unions, or policies that prevent forcing end users to use their personal devices, have another option. FIDO2 security keys can be used as an alternative. They are more secure, phishing-resistant, and affordable for organizations to issue to every end user. Recommendation and Steps **To remediate using the UI:** 1. Navigate to the `Microsoft Entra admin center` https://entra.microsoft.com. 2. Click expand `Protection` > `Conditional Access` select `Policies`. 3. Click `New policy`. - Under `Users` include `All users`. - Under `Target resources` include `All resources (formerly 'All cloud apps')` and do not create any exclusions. - Under `Grant` select `Grant Access` and check either `Require multifactor authentication` or `Require authentication strength`. - Click `Select` at the bottom of the pane. 4. Under `Enable policy` set it to `Report-only` until the organization is ready to enable it. 5. Click `Create`. **Note:** Break-glass accounts should be excluded from all Conditional Access policies. Associated Items
Affected Objects More Information TEST ID
|
| 5.2.2.3 | Enable Conditional Access policies to block legacy authentication | High | Block Legacy Authentication Status:You have 14822 of 14822 users that don't have legacy authentication blocked. | Basic authentication is disabled by default as of January 2023. | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Enable Conditional Access policies to block legacy authentication Description Entra ID supports the most widely used authentication and authorization protocols including legacy authentication. This authentication pattern includes basic authentication, a widely used industry-standard method for collecting username and password information. The following messaging protocols support legacy authentication: - Authenticated SMTP - Used to send authenticated email messages. - Autodiscover - Used by Outlook and EAS clients to find and connect to mailboxes in Exchange Online. - Exchange ActiveSync (EAS) - Used to connect to mailboxes in Exchange Online. - Exchange Online PowerShell - Used to connect to Exchange Online with remote PowerShell. If you block Basic authentication for Exchange Online PowerShell, you need to use the Exchange Online PowerShell Module to connect. For instructions, see Connect to Exchange Online PowerShell using multifactor authentication. - Exchange Web Services (EWS) - A programming interface that's used by Outlook, Outlook for Mac, and third-party apps. - IMAP4 - Used by IMAP email clients. - MAPI over HTTP (MAPI/HTTP) - Primary mailbox access protocol used by Outlook 2010 SP2 and later. - Offline Address Book (OAB) - A copy of address list collections that are downloaded and used by Outlook. - Outlook Anywhere (RPC over HTTP) - Legacy mailbox access protocol supported by all current Outlook versions. - POP3 - Used by POP email clients. - Reporting Web Services - Used to retrieve report data in Exchange Online. - Universal Outlook - Used by the Mail and Calendar app for Windows 10. - Other clients - Other protocols identified as utilizing legacy authentication. Rationale Legacy authentication protocols do not support multi-factor authentication. These protocols are often used by attackers because of this deficiency. Blocking legacy authentication makes it harder for attackers to gain access. **Note:** Basic authentication is now disabled in all tenants. Before December 31 2022, you could re-enable the affected protocols if users and apps in your tenant couldn't connect. Now no one (you or Microsoft support) can re-enable Basic authentication in your tenant. Impact Enabling this setting will prevent users from connecting with older versions of Office, ActiveSync or using protocols like IMAP, POP or SMTP and may require upgrades to older versions of Office, and use of mobile mail clients that support modern authentication. This will also cause multifunction devices such as printers from using scan to e-mail function if they are using a legacy authentication method. Microsoft has mail flow best practices in the link below which can be used to configure a MFP to work with modern authentication: https://learn.microsoft.com/en-us/exchange/mail-flow-best-practices/how-to-set-up-a-multifunction-device-or-application-to-send-email-using-microsoft-365-or-office-365 Recommendation and Steps **To remediate using the UI:** 1. Navigate to the `Microsoft Entra admin center` https://entra.microsoft.com. 2. Click expand `Protection` > `Conditional Access` select `Policies`. 3. Create a new policy by selecting `New policy`. - Under `Users` include `All users`. - Under `Target resources` include `All resources (formerly 'All cloud apps')`. - Under `Conditions` select `Client apps` and check the boxes for `Exchange ActiveSync clients` and `Other clients`. - Under `Grant` select `Block Access`. - Click `Select`. 4. Set the policy `On` and click `Create`. **Note:** Break-glass accounts should be excluded from all Conditional Access policies. Associated Items
Affected Objects More Information TEST ID
LINK
https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/disable-basic-authentication-in-exchange-online https://learn.microsoft.com/en-us/exchange/mail-flow-best-practices/how-to-set-up-a-multifunction-device-or-application-to-send-email-using-microsoft-365-or-office-365 https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/deprecation-of-basic-authentication-exchange-online
|
| 5.2.2.4 | Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative users | High | Status:Policy Not Enabled | The default configuration for user sign-in frequency is a rolling window of 90 days. | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative users Description In complex deployments, organizations might have a need to restrict authentication sessions. Conditional Access policies allow for the targeting of specific user accounts. Some scenarios might include: - Resource access from an unmanaged or shared device - Access to sensitive information from an external network - High-privileged users - Business-critical applications **Note:** This CA policy can be added to the previous CA policy in this benchmark Ensure multifactor authentication is enabled for all users in administrative roles Rationale Forcing a time out for MFA will help ensure that sessions are not kept alive for an indefinite period of time, ensuring that browser sessions are not persistent will help in prevention of drive-by attacks in web browsers, this also prevents creation and saving of session cookies leaving nothing for an attacker to take. Impact Users with Administrative roles will be prompted at the frequency set for MFA. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Entra admin center` https://entra.microsoft.com/. 2. Click to expand `Protection` > `Conditional Access` Select `Policies`. 3. Click `New policy`. - Under `Users` include `Select users and groups` and check `Directory roles`. - At a minimum, include the directory roles listed below in this section of the document. - Under `Target resources` include `All resources (formerly 'All cloud apps')`. - Under `Grant` select `Grant Access` and check `Require multifactor authentication`. - Under `Session` select `Sign-in frequency` select `Periodic reauthentication` and set it to `4` `hours` (or less). - Check `Persistent browser session` then select `Never persistent` in the drop-down menu. 4. Under `Enable policy` set it to `Report-only` until the organization is ready to enable it. **At minimum these directory roles should be included in the policy:** - Application administrator - Authentication administrator - Billing administrator - Cloud application administrator - Conditional Access administrator - Exchange administrator - Global administrator - Global reader - Helpdesk administrator - Password administrator - Privileged authentication administrator - Privileged role administrator - Security administrator - SharePoint administrator - User administrator **Note:** Break-glass accounts should be excluded from all Conditional Access policies. Associated Items
Affected Objects More Information TEST ID
|
| 5.2.2.5 | Ensure Phishing-resistant MFA strength is required for Administrators | High | Status:Phishing-resistant MFA policy is not configured for administrators | N/A | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure Phishing-resistant MFA strength is required for Administrators Description Authentication strength is a Conditional Access control that allows administrators to specify which combination of authentication methods can be used to access a resource. For example, they can make only phishing-resistant authentication methods available to access a sensitive resource. But to access a non-sensitive resource, they can allow less secure multifactor authentication (MFA) combinations, such as password + SMS. Microsoft has 3 built-in authentication strengths. MFA strength, Passwordless MFA strength, and Phishing-resistant MFA strength. Ensure administrator roles are using a CA policy with `Phishing-resistant MFA strength`. Administrators can then enroll using one of 3 methods: - FIDO2 Security Key - Windows Hello for Business - Certificate-based authentication (Multi-Factor) **Note:** Additional steps to configure methods such as FIDO2 keys are not covered here but can be found in related MS articles in the references section. The Conditional Access policy only ensures 1 of the 3 methods is used. **Warning:** Administrators should be pre-registered for a strong authentication mechanism before this Conditional Access Policy is enforced. Additionally, as stated elsewhere in the CIS Benchmark a break-glass administrator account should be excluded from this policy to ensure unfettered access in the case of an emergency. Rationale Sophisticated attacks targeting MFA are more prevalent as the use of it becomes more widespread. These 3 methods are considered phishing-resistant as they remove passwords from the login workflow. It also ensures that public/private key exchange can only happen between the devices and a registered provider which prevents login to fake or phishing websites. Impact If administrators aren't pre-registered for a strong authentication method prior to a conditional access policy being created, then a condition could occur where a user can't register for strong authentication because they don't meet the conditional access policy requirements and therefore are prevented from signing in. Additionally, Internet Explorer based credential prompts in PowerShell do not support prompting for a security key. Implementing phishing-resistant MFA with a security key may prevent admins from running their existing sets of PowerShell scripts. Device Authorization Grant Flow can be used as a workaround in some instances. Recommendation and Steps **To remediate using the UI:** 1. Navigate to the `Microsoft Entra admin center` https://entra.microsoft.com. 2. Click expand `Protection` > `Conditional Access` select `Policies`. 3. Click `New policy`. - Under `Users` include `Select users and groups` and check `Directory roles`. - At a minimum, include the directory roles listed below in this section of the document. - Under `Target resources` include `All resources (formerly 'All cloud apps')` and do not create any exclusions. - Under `Grant` select `Grant Access` and check `Require authentication strength` and set `Phishing-resistant MFA` in the dropdown box. - Click `Select`. 4. Under `Enable policy` set it to `Report-only` until the organization is ready to enable it. 5. Click `Create`. **At minimum these directory roles should be included for the policy:** - Application administrator - Authentication administrator - Billing administrator - Cloud application administrator - Conditional Access administrator - Exchange administrator - Global administrator - Global reader - Helpdesk administrator - Password administrator - Privileged authentication administrator - Privileged role administrator - Security administrator - SharePoint administrator - User administrator **Warning:** Ensure administrators are pre-registered with strong authentication before enforcing the policy. After which the policy must be set to `On`. Associated Items
Affected Objects More Information TEST ID
LINK
https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-passwordless#fido2-security-keys https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-enable-passkey-fido2 https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-strengths https://learn.microsoft.com/en-us/entra/id-protection/howto-identity-protection-configure-mfa-policy
|
| Not Available | Ensure Microsoft Azure Management is limited to administrative roles | High | Permission Status:No Policy Found | No - Non-administrators can access the Azure AD administration portal. | N/A | SP v1.0 | NO |
X TEST NAME Ensure Microsoft Azure Management is limited to administrative roles Description Rationale Impact The Microsoft Azure Management application governs various Azure services and can be secured through the implementation of a Conditional Access policy. This policy can restrict specific user accounts from accessing the related portals and applications. When Conditional Access policy is targeted to the Microsoft Azure Management application, within the Conditional Access policy app picker the policy will be enforced for tokens issued to application IDs of a set of services closely bound to the portal. - Azure Resource Manager - Azure portal, which also covers the Microsoft Entra admin center - Azure Data Lake - Application Insights API - Log Analytics API Microsoft Azure Management should be restricted to specific pre-determined administrative roles. NOTE: Blocking Microsoft Azure Management will prevent non-privileged users from signing into most portals other than Microsoft 365 Defender and Microsoft Purview. Blocking sign-in to Azure Management applications and portals enhances security of sensitive data by restricting access to privileged users. This mitigates potential exposure due to administrative errors or software vulnerabilities, as well as acting as a defense in depth measure against security breaches. PIM functionality will be impacted unless non-privileged users are first assigned to a permanent group or role that is excluded from this policy. When attempting to checkout a role in the Entra ID PIM area they will receive the message Because the policy is applied to the Azure management portal and API, services, or clients with an Azure API service dependency, can indirectly be impacted: Classic deployment model APIs Azure PowerShell Azure CLI Azure DevOps Azure Data Factory portal Azure Event Hubs Azure Service Bus Azure SQL Database SQL Managed Instance Azure Synapse Visual Studio subscriptions administrator portal Microsoft IoT Central Recommendation and Steps To enable Microsoft Azure Management restrictions: 1. Navigate to the Microsoft Entra admin center https://entra.microsoft.com. 2. Click expand Protection > Conditional Access select Policies. 3. Click New Policy and then name the policy. 4. Select Users > Include > All Users 5. Select Users > Exclude > Directory roles and select only administrative roles. See audit section for more information. 6. Select Cloud apps or actions > Select apps > Select then click the box next to Microsoft Azure Management. 7. Click Select. 8. Select Grant > Block access and click Select. 9. Ensure Enable Policy is On then click Create. WARNING: Exclude Global Administrator at a minimum to avoid being locked out. Report-only is a good option to use when testing any Conditional Access policy for the first time. Associated Items Affected Objects More Information TEST ID
|
| 5.2.2.6 | Enable Identity Protection user risk policies | Passed | Status: Configured Correctly | N/A | E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Enable Identity Protection user risk policies Description Microsoft Entra ID Protection user risk policies detect the probability that a user account has been compromised. **Note:** While Identity Protection also provides two risk policies with limited conditions, Microsoft highly recommends setting up risk-based policies in Conditional Access as opposed to the legacy method for the following benefits: - Enhanced diagnostic data - Report-only mode integration - Graph API support - Use more Conditional Access attributes like sign-in frequency in the policy Rationale With the user risk policy turned on, Entra ID protection detects the probability that a user account has been compromised. Administrators can configure a user risk conditional access policy to automatically respond to a specific user risk level. Impact Upon policy activation, account access will be either blocked or the user will be required to use multi-factor authentication (MFA) and change their password. Users without registered MFA will be denied access, necessitating an admin to recover the account. To avoid inconvenience, it is advised to configure the MFA registration policy for all users under the User Risk policy. Additionally, users identified in the Risky Users section will be affected by this policy. To gain a better understanding of the impact on the organization's environment, the list of Risky Users should be reviewed before enforcing the policy. Recommendation and Steps Associated Items
Affected Objects |
| 5.2.2.7 | Enable Identity Protection sign-in risk policies | Passed | Status: Configured Correctly | N/A | E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Enable Identity Protection sign-in risk policies Description Microsoft Entra ID Protection sign-in risk detects risks in real-time and offline. A risky sign-in is an indicator for a sign-in attempt that might not have been performed by the legitimate owner of a user account. **Note:** While Identity Protection also provides two risk policies with limited conditions, Microsoft highly recommends setting up risk-based policies in Conditional Access as opposed to the legacy method for the following benefits: - Enhanced diagnostic data - Report-only mode integration - Graph API support - Use more Conditional Access attributes like sign-in frequency in the policy Rationale Turning on the sign-in risk policy ensures that suspicious sign-ins are challenged for multi-factor authentication. Impact When the policy triggers, the user will need MFA to access the account. In the case of a user who hasn't registered MFA on their account, they would be blocked from accessing their account. It is therefore recommended that the MFA registration policy be configured for all users who are a part of the Sign-in Risk policy. Recommendation and Steps Associated Items
Affected Objects |
| 5.2.2.8 | Ensure sign-in risk is blocked for medium and high risk | Passed | Status: Configured Correctly | N/A | E5 Level 2 | CIS v6.0 | YES |
X TEST NAME Ensure sign-in risk is blocked for medium and high risk Description Microsoft Entra ID Protection sign-in risk detects risks in real-time and offline. A risky sign-in is an indicator for a sign-in attempt that might not have been performed by the legitimate owner of a user account. **Note:** While Identity Protection also provides two risk policies with limited conditions, Microsoft highly recommends setting up risk-based policies in Conditional Access as opposed to the legacy method for the following benefits: - Enhanced diagnostic data - Report-only mode integration - Graph API support - Use more Conditional Access attributes like sign-in frequency in the policy Rationale Sign-in risk is determined at the time of sign-in and includes criteria across both real-time and offline detections for risk. Blocking sign-in to accounts that have risk can prevent undesired access from potentially compromised devices or unauthorized users. Impact Sign-in risk is heavily dependent on detecting risk based on atypical behaviors. Due to this it is important to run this policy in a report-only mode to better understand how the organization's environment and user activity may influence sign-in risk before turning the policy on. Once it's understood what actions may trigger a medium or high sign-in risk event I.T. can then work to create an environment to reduce false positives. For example, employees might be required to notify security personnel when they intend to travel with intent to access work resources. **Note:** Break-glass accounts should always be excluded from risk detection. Recommendation and Steps Associated Items
Affected Objects |
| 5.2.2.9 | Ensure a managed device is required for authentication | Manual Check | NONE | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure a managed device is required for authentication Description Conditional Access (CA) can be configured to enforce access based on the device's compliance status or whether it is Entra hybrid joined. Collectively this allows CA to classify devices as managed or unmanaged, providing more granular control over authentication policies. When using `Require device to be marked as compliant`, the device must pass checks configured in **Compliance** policies defined within Intune (Endpoint Manager). Before these checks can be applied, the device must first be enrolled in Intune MDM. By selecting `Require Microsoft Entra hybrid joined device` this means the device must first be synchronized from an on-premises Active Directory to qualify for authentication. When configured to the recommended state below only one condition needs to be met for the user to authenticate from the device. This functions as an OR operator. The recommended state is: - `Require device to be marked as compliant` - `Require Microsoft Entra hybrid joined device` - `Require one of the selected controls` Rationale Managed devices are considered more secure because they often have additional configuration hardening enforced through centralized management such as Intune or Group Policy. These devices are also typically equipped with MDR/EDR, managed patching and alerting systems. As a result, they provide a safer environment for users to authenticate and operate from. This policy also ensures that attackers must first gain access to a compliant or trusted device before authentication is permitted, reducing the risk posed by compromised account credentials. When combined with other distinct Conditional Access (CA) policies, such as requiring multi-factor authentication, this adds one additional factor before authentication is permitted. **Note:** Avoid combining these two settings with other `Grant` settings in the same policy. In a single policy you can only choose between `Require all the selected controls` or `Require one of the selected controls`, which limits the ability to integrate this recommendation with others in this benchmark. CA policies function as an AND operator across multiple policies. The goal here is to both (Require MFA for all users) **AND** (Require device to be marked as compliant **OR** Require Microsoft Entra hybrid joined device). Impact Unmanaged devices will not be permitted as a valid authenticator. As a result this may require the organization to mature their device enrollment and management. The following devices can be considered managed: - Entra hybrid joined from Active Directory - Entra joined and enrolled in Intune, with compliance policies - Entra registered and enrolled in Intune, with compliances policies If `Guest or external users` are collaborating with the organization, they must either be excluded or onboarded with a compliant device to authenticate. Failure to adequately survey the environment and test the Conditional Access (CA) policy in the `Report-only` state could result in access disruptions for these guest users. Recommendation and Steps **To remediate using the UI:** 1. Navigate to the `Microsoft Entra admin center` https://entra.microsoft.com. 2. Click expand `Protection` > `Conditional Access` select `Policies`. 3. Create a new policy by selecting `New policy`. - Under `Users` include `All users`. - Under `Target resources` include `All resources (formerly 'All cloud apps')`. - Under `Grant` select `Grant access`. - Select only the checkboxes `Require device to be marked as compliant` and `Require Microsoft Entra hybrid joined device`. - Choose `Require one of the selected controls` and click `Select` at the bottom. 4. Under `Enable policy` set it to `Report-only` until the organization is ready to enable it. 5. Click `Create`. **Note:** Guest user accounts, if collaborating with the organization, should be considered when testing this policy. Associated Items Affected Objects More Information TEST ID
LINK
https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-conditional-access-grant#require-device-to-be-marked-as-compliant https://learn.microsoft.com/en-us/entra/identity/devices/concept-hybrid-join https://learn.microsoft.com/en-us/mem/intune/fundamentals/deployment-guide-enrollment
|
| 5.2.2.10 | Ensure a managed device is required to register security information | Manual Check | NONE | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure a managed device is required to register security information Description Conditional Access (CA) can be configured to enforce access based on the device's compliance status or whether it is Entra hybrid joined. Collectively this allows CA to classify devices as managed or not, providing more granular control over whether or not a user can register MFA on a device. When using `Require device to be marked as compliant`, the device must pass checks configured in **Compliance** policies defined within Intune (Endpoint Manager). Before these checks can be applied, the device must first be enrolled in Intune MDM. By selecting `Require Microsoft Entra hybrid joined device` this means the device must first be synchronized from an on-premises Active Directory to qualify for authentication. When configured to the recommended state below only one condition needs to be met for the user to register MFA from the device. This functions as an OR operator. The recommended state is to restrict `Register security information` to a device that is marked as compliant or Entra hybrid joined. Rationale Requiring registration on a managed device significantly reduces the risk of bad actors using stolen credentials to register security information. Accounts that are created but never registered with an MFA method are particularly vulnerable to this type of attack. Enforcing this requirement will both reduce the attack surface for fake registrations and ensure that legitimate users register using trusted devices which typically have additional security measures in place already. Impact The organization will be required to have a mature device management process. New devices provided to users will need to be pre-enrolled in Intune, auto-enrolled or be Entra hybrid joined. Otherwise, the user will be unable to complete registration, requiring additional resources from I.T. This could be more disruptive in remote worker environments where the MDM maturity is low. In these cases where the person enrolling in MFA (enrollee) doesn't have physical access to a managed device, a help desk process can be created using a Teams meeting to complete enrollment using: 1) a durable process to verify the enrollee's identity including government identification with a photograph held up to the camera, information only the enrollee should know, and verification by the enrollee's direct manager in the same meeting; 2) complete enrollment in the same Teams meeting with the enrollee being granted screen and keyboard access to the help desk person's InPrivate Edge browser session. Recommendation and Steps **To remediate using the UI:** 1. Navigate to the `Microsoft Entra admin center` https://entra.microsoft.com. 2. Click expand `Protection` > `Conditional Access` select `Policies`. 3. Create a new policy by selecting `New policy`. - Under `Users` include `All users`. - Under `Target resources` select `User actions` and check `Register security information`. - Under `Grant` select `Grant access`. - Check only `Require multifactor authentication` and `Require Microsoft Entra hybrid joined device`. - Choose `Require one of the selected controls` and click `Select` at the bottom. 4. Under `Enable policy` set it to `Report-only` until the organization is ready to enable it. 5. Click `Create`. **Note:** Break-glass accounts should be excluded from all Conditional Access policies. Associated Items Affected Objects More Information TEST ID
LINK
https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-conditional-access-grant#require-device-to-be-marked-as-compliant https://learn.microsoft.com/en-us/entra/identity/devices/concept-hybrid-join https://learn.microsoft.com/en-us/mem/intune/fundamentals/deployment-guide-enrollment https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-conditional-access-cloud-apps#user-actions
|
| 5.2.2.11 | Ensure sign-in frequency for Intune Enrollment is set to Every time | Manual Check | NONE | Sign-in frequency defaults to 90 days. | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure sign-in frequency for Intune Enrollment is set to Every time Description Sign-in frequency defines the time period before a user is asked to sign in again when attempting to access a resource. The Microsoft Entra ID default configuration for user sign-in frequency is a rolling window of 90 days. The recommended state is a `Sign-in frequency` of `Every time` for `Microsoft Intune Enrollment` **Note:** Microsoft accounts for a five-minute clock skew when 'every time' is selected in a conditional access policy, ensuring that users are not prompted more frequently than once every five minutes. Rationale Intune Enrollment is considered a sensitive action and should be safeguarded. An attack path exists that allows for a bypass of device compliance Conditional Access rule. This could allow compromised credentials to be used through a newly registered device enrolled in Intune, enabling persistence and privilege escalation. Setting sign-in frequency to every time limits the timespan an attacker could use fresh credentials to enroll a new device to Intune. Impact New users enrolling into Intune through an automated process may need to sign-in again if the enrollment process goes on for too long. Recommendation and Steps **To remediate using the UI:** 1. Navigate to the `Microsoft Entra admin center` https://entra.microsoft.com. 2. Click expand `Protection` > `Conditional Access` select `Policies`. 3. Create a new policy by selecting `New policy`. - Under `Users` include `All users`. - Under `Target resources` select `Resources (formerly cloud apps)`, choose `Select resources` and add `Microsoft Intune Enrollment` to the list. - Under `Grant` select `Grant access`. - Check either `Require multifactor authentication` or `Require authentication strength`. - Under `Session` check `Sign-in frequency` and select `Every time`. 4. Under `Enable policy` set it to `Report-only` until the organization is ready to enable it. 5. Click `Create`. **Note:** If the Microsoft Intune Enrollment cloud app isn't available then it must be created. To add the app for new tenants, a Microsoft Entra administrator must create a service principal object, with app ID `d4ebce55-015a-49b5-a083-c84d1797ae8c`, in PowerShell or Microsoft Graph. **Note:** Break-glass accounts should be excluded from all Conditional Access policies. Associated Items Affected Objects More Information TEST ID
LINK
https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-session-lifetime#require-reauthentication-every-time https://www.blackhat.com/eu-24/briefings/schedule/#unveiling-the-power-of-intune-leveraging-intune-for-breaking-into-your-cloud-and-on-premise-42176 https://www.glueckkanja.com/blog/security/2025/01/compliant-device-bypass-en/
|
| 5.2.2.12 | Ensure the device code sign-in flow is blocked | Manual Check | NONE | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure the device code sign-in flow is blocked Description The Microsoft identity platform supports the device authorization grant, which allows users to sign in to input-constrained devices such as a smart TV, IoT device, or a printer. To enable this flow, the device has the user visit a webpage in a browser on another device to sign in. Once the user signs in, the device is able to get access tokens and refresh tokens as needed. The recommended state is to `Block access` for `Device code flow` in Conditional Access. Rationale Since August 2024, Microsoft has observed threat actors, such as Storm-2372, employing device code phishing attacks. These attacks deceive users into logging into productivity applications, capturing authentication tokens to gain further access to compromised accounts. To mitigate this specific attack, block authentication code flows and permit only those from devices within trusted environments, identified by specific IP addresses. Impact Some administrative overhead will be required for stricter management of these devices. Since exclusions do not violate compliance, this feature can still be utilized effectively within a controlled environment. Recommendation and Steps **To remediate using the UI:** 1. Navigate to the `Microsoft Entra admin center` https://entra.microsoft.com. 2. Click expand `Protection` > `Conditional Access` select `Policies`. 3. Create a new policy by selecting `New policy`. - Under `Users` include `All users`. - Under `Target resources` > `Resources (formerly cloud apps)` include `All resources (formerly 'All cloud apps')`. - Under `Conditions` > `Authentication flows` set `Configure` is set to `Yes`, select `Device code flow` and click `Save`. - Under `Grant` select `Block access` and click `Select`. 4. Under `Enable policy` set it to `Report-only` until the organization is ready to enable it. 5. Click `Create`. **Note:** Break-glass accounts should be excluded from all Conditional Access policies. Associated Items Affected Objects More Information TEST ID
LINK
https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-device-code https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-authentication-flows https://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/ https://securing365.com/secure-your-device-code-auth-flows-now/ https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-block-authentication-flows#device-code-flow-policies
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 5.2.3.1 | Ensure Microsoft Authenticator is configured to protect against MFA fatigue | High | Status:Microsoft Authenticator is disabled. | Microsoft-managed | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure Microsoft Authenticator is configured to protect against MFA fatigue Description Microsoft provides supporting settings to enhance the configuration of the Microsoft Authenticator application. These settings provide users with additional information and context when they receive MFA passwordless and push requests, including the geographic location of the request, the requesting application, and a requirement for number matching. Ensure the following are `Enabled`. - `Require number matching for push notifications` - `Show application name in push and passwordless notifications` - `Show geographic location in push and passwordless notifications` **NOTE:** On February 27, 2023 Microsoft started enforcing number matching tenant-wide for all users using Microsoft Authenticator. Rationale As the use of strong authentication has become more widespread, attackers have started to exploit the tendency of users to experience MFA fatigue. This occurs when users are repeatedly asked to provide additional forms of identification, leading them to eventually approve requests without fully verifying the source. To counteract this, number matching can be employed to ensure the security of the authentication process. With this method, users are prompted to confirm a number displayed on their original device and enter it into the device being used for MFA. Additionally, other information such as geolocation and application details are displayed to enhance the end user's awareness. Among these 3 options, number matching provides the strongest net security gain. Impact Additional interaction will be required by end users using number matching as opposed to simply pressing Approve for login attempts. Recommendation and Steps **To remediate using the UI:** 1. Navigate to the `Microsoft Entra admin center` https://entra.microsoft.com. 2. Click to expand `Protection` > `Authentication methods` select `Policies`. 3. Select `Microsoft Authenticator` 4. Under `Enable and Target` ensure the setting is set to `Enable`. 5. Select `Configure` 6. Set the following Microsoft Authenticator settings: - `Require number matching for push notifications` Status is set to `Enabled`, Target `All users` - `Show application name in push and passwordless notifications` is set to `Enabled`, Target `All users` - `Show geographic location in push and passwordless notifications` is set to `Enabled`, Target `All users` **Note:** Valid groups such as break glass accounts can be excluded per organization policy. Associated Items
Affected Objects More Information TEST ID
LINK
https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-default-enablement https://techcommunity.microsoft.com/t5/microsoft-entra-blog/defend-your-users-from-mfa-fatigue-attacks/ba-p/2365677 https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-mfa-number-match
|
| 5.2.3.2 | Ensure custom banned passwords lists are used | High | Status:Custom banned passwords setting is disabled. | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure custom banned passwords lists are used Description With Entra Password Protection, default global banned password lists are automatically applied to all users in an Entra ID tenant. To support business and security needs, custom banned password lists can be defined. When users change or reset their passwords, these banned password lists are checked to enforce the use of strong passwords. A custom banned password list should include some of the following examples: - Brand names - Product names - Locations, such as company headquarters - Company-specific internal terms - Abbreviations that have specific company meaning Rationale Creating a new password can be difficult regardless of one's technical background. It is common to look around one's environment for suggestions when building a password, however, this may include picking words specific to the organization as inspiration for a password. An adversary may employ what is called a 'mangler' to create permutations of these specific words in an attempt to crack passwords or hashes making it easier to reach their goal. Impact If a custom banned password list includes too many common dictionary words, or short words that are part of compound words, then perfectly secure passwords may be blocked. The organization should consider a balance between security and usability when creating a list. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Entra admin center` https://entra.microsoft.com/ 2. Click to expand `Protection` > `Authentication methods` 3. Select `Password protection` 4. Set `Enforce custom list` to `Yes` 5. In `Custom banned password list` create a list using suggestions outlined in this document. 6. Click `Save` **Note:** Below is a list of examples that can be used as a starting place. The references section contains more suggestions. - Brand names - Product names - Locations, such as company headquarters - Company-specific internal terms - Abbreviations that have specific company meaning Associated Items
Affected Objects |
| 5.2.3.4 | Ensure all member users are MFA capable | High | Total Users not MFA Capable:1 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure all member users are MFA capable Description Microsoft defines Multifactor authentication capable as being registered and enabled for a strong authentication method. The method must also be allowed by the authentication methods policy. Ensure all member users are `MFA capable`. Rationale Multifactor authentication requires an individual to present a minimum of two separate forms of authentication before access is granted. Users who are not `MFA Capable` have never registered a strong authentication method for multifactor authentication that is within policy and may not be using MFA. This could be a result of having never signed in, exclusion from a Conditional Access (CA) policy requiring MFA, or a CA policy does not exist. Reviewing this list of users will help identify possible lapses in policy or procedure. Impact When using the UI audit method guest users will appear in the report and unless the organization is applying MFA rules to guests then they will need to be manually filtered. Accounts that provide on-premises directory synchronization also appear in these reports. Recommendation and Steps Remediation steps will depend on the status of the personnel in question or configuration of Conditional Access policies and will not be covered in detail. Administrators should review each user identified on a case-by-case basis using the conditions below. **User has never signed on:** - Employment status should be reviewed, and appropriate action taken on the user account's roles, licensing and enablement. **Conditional Access policy applicability:** - Ensure a CA policy is in place requiring all users to use MFA. - Ensure the user is not excluded from the CA MFA policy. - Ensure the policy's state is set to `On`. - Use `What if` to determine applicable CA policies. (Protection > Conditional Access > Policies) - Review the user account in `Sign-in logs`. Under the `Activity Details` pane click the `Conditional Access` tab to view applied policies. **Note:** Conditional Access is covered step by step in section 5.2.2 Associated Items
Affected Objects
More Information TEST ID
LINK
https://learn.microsoft.com/en-us/powershell/module/microsoft.graph.reports/update-mgreportauthenticationmethoduserregistrationdetail?view=graph-powershell-1.0#-ismfacapable https://learn.microsoft.com/en-us/entra/identity/monitoring-health/how-to-view-applied-conditional-access-policies https://learn.microsoft.com/en-us/entra/identity/conditional-access/what-if-tool https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-methods-activity
|
| 5.2.3.5 | Ensure weak authentication methods are disabled | High | Weak Authentication Methods Disabled:1 | '- SMS : Disabled - Voice Call : Disabled - Email OTP : Enabled | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure weak authentication methods are disabled Description Authentication methods support a wide variety of scenarios for signing in to Microsoft 365 resources. Some of these methods are inherently more secure than others but require more investment in time to get users enrolled and operational. SMS and Voice Call rely on telephony carrier communication methods to deliver the authenticating factor. The email one-time passcode feature is a way to authenticate B2B collaboration users when they can't be authenticated through other means, such as Microsoft Entra ID, Microsoft account (MSA), or social identity providers. When a B2B guest user tries to redeem your invitation or sign in to your shared resources, they can request a temporary passcode, which is sent to their email address. Then they enter this passcode to continue signing in. The recommended state is to `Disable` these methods: - SMS - Voice Call - Email OTP Rationale The SMS and Voice call methods are vulnerable to SIM swapping which could allow an attacker to gain access to your Microsoft 365 account. Impact Disabling Email OTP will prevent one-time pass codes from being sent to unverified guest users accessing Microsoft 365 resources on the tenant such as @yahoo.com. They will be required to use a personal Microsoft account, a managed Microsoft Entra account, be part of a federation or be configured as a guest in the host tenant's Microsoft Entra ID. Recommendation and Steps **To remediate using the UI:**
1. Navigate to `Microsoft Entra admin center` https://entra.microsoft.com/.
2. Click to expand `Protection` select `Authentication methods`.
3. Select `Policies`.
4. Inspect each method that is out of compliance and remediate:
- Click on the method to open it.
- Change the `Enable` toggle to the off position.
- Click `Save`.
**Note:** If the save button remains greyed out after toggling a method off, then first turn it back on and then change the position of the `Target` selection (all users or select groups). Turn the method off again and save. This was observed to be a bug in the UI at the time this document was published.
**To remediate using Powershell:**
1. Connect to Graph using `Connect-MgGraph -Scopes Policy.ReadWrite.AuthenticationMethod`
2. Run the following to disable all three authentication methods:
```
$params = @(
@{ Id = Sms; State = disabled },
@{ Id = Voice; State = disabled },
@{ Id = Email; State = disabled }
)
Update-MgPolicyAuthenticationMethodPolicy -AuthenticationMethodConfigurations $params
```
Associated Items
Affected Objects
|
| 5.2.3.3 | Ensure that password protection is enabled for Active Directory | Manual Check | NONE | Enable - Yes Mode - Audit | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure that password protection is enabled for Active Directory Description Microsoft Entra Password Protection provides a global and custom banned password list. A password change request fails if there's a match in these banned password list. To protect on-premises Active Directory Domain Services (AD DS) environment, install and configure Entra Password Protection. **Note**: This recommendation applies to Hybrid deployments only and will have no impact unless working with on-premises Active Directory. Rationale This feature protects an organization by prohibiting the use of weak or leaked passwords. In addition, organizations can create custom banned password lists to prevent their users from using easily guessed passwords that are specific to their industry. Deploying this feature to Active Directory will strengthen the passwords that are used in the environment. Impact The potential impact associated with implementation of this setting is dependent upon the existing password policies in place in the environment. For environments that have strong password policies in place, the impact will be minimal. For organizations that do not have strong password policies in place, implementation of Microsoft Entra Password Protection may require users to change passwords and adhere to more stringent requirements than they have been accustomed to. Recommendation and Steps **To remediate using the UI:** - Download and install the `Azure AD Password Proxies` and `DC Agents` from the following location: https://www.microsoft.com/download/details.aspx?id=57071 After installed follow the steps below. 1. Navigate to `Microsoft Entra admin center` https://entra.microsoft.com/. 2. Click to expand `Protection` select `Authentication methods`. 3. Select `Password protection` and set `Enable password protection on Windows Server Active Directory` to `Yes` and `Mode` to `Enforced`. Associated Items Affected Objects More Information TEST ID
|
| 5.2.3.6 | Ensure system-preferred multifactor authentication is enabled | Manual Check | NONE | Microsoft Managed (Enabled) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure system-preferred multifactor authentication is enabled Description System-preferred multifactor authentication (MFA) prompts users to sign in by using the most secure method they registered. The user is prompted to sign-in with the most secure method according to the below order. The order of authentication methods is dynamic. It's updated by Microsoft as the security landscape changes, and as better authentication methods emerge. 1. Temporary Access Pass 2. Passkey (FIDO2) 3. Microsoft Authenticator notifications 4. External authentication methods 5. Time-based one-time password (TOTP) 6. Telephony 7. Certificate-based authentication The recommended state is `Enabled`. Rationale Regardless of the authentication method enabled by an administrator or set as preferred by the user, the system will dynamically select the most secure option available at the time of authentication. This approach acts as an additional safeguard to prevent the use of weaker methods, such as voice calls, SMS, and email OTPs, which may have been inadvertently left enabled due to misconfiguration or lack of configuration hardening. Enforcing the default behavior also ensures the feature is not disabled. Impact The Microsoft managed value of system-preferred MFA is Enabled and as such enforces the default behavior. No additional impact is expected. **Note:** Due to known issues with certificate-based authentication (CBA) and system-preferred MFA, Microsoft moved CBA to the bottom of the list. It is still considered a strong authentication method. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Entra admin center` https://entra.microsoft.com/. 2. Click to expand `Protection` select `Authentication methods`. 3. Select `Settings`. 4. Set the **System-preferred multifactor authentication** `State` to `Enabled` and include `All users`. 5. Any users exclusions should be documented and reviewed annually. Associated Items Affected Objects More Information TEST ID
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 5.2.4.1 | Ensure Self service password reset enabled is set to All | High | Self-Service Password Status:You have 143 of 14822 users who don't have self-service password reset enabled. | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure Self service password reset enabled is set to All Description Enabling self-service password reset allows users to reset their own passwords in Entra ID. When users sign in to Microsoft 365, they will be prompted to enter additional contact information that will help them reset their password in the future. If combined registration is enabled additional information, outside of multi-factor, will not be needed. **Note:** Effective Oct. 1st, 2022, Microsoft will begin to enable combined registration for all users in Entra ID tenants created before August 15th, 2020. Tenants created after this date are enabled with combined registration by default. Rationale Users will no longer need to engage the helpdesk for password resets, and the password reset mechanism will automatically block common, easily guessable passwords. Impact Users will be required to provide additional contact information to enroll in self-service password reset. Additionally, minor user education may be required for users that are used to calling a help desk for assistance with password resets. **Note:** This is unavailable if using Entra Connect / Sync in a hybrid environment. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Entra admin center` https://entra.microsoft.com/. 2. Click to expand `Protection` > `Password reset` select `Properties`. 3. Set `Self service password reset enabled` to `All` Associated Items
Affected Objects More Information TEST ID
|
| Not Available | Ensure the self-service password reset activity report is reviewed and actioned | Passed | Status:Changed Password Found via SSPR | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure the self-service password reset activity report is reviewed and actioned Description Rationale Impact Auditing Process needs to be created and followed. Recommendation and Steps Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Not Available | Ensure the Azure AD Risky sign-ins report is reviewed at least weekly | Passed | Status:No Risky user found | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure the Azure AD Risky sign-ins report is reviewed at least weekly Description Rationale Impact Auditing Process needs to be created and followed. Recommendation and Steps Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 5.3.1 | Ensure Privileged Identity Management is used to manage roles | Medium | Status:No permanent active role assignments found. | N/A | E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure Privileged Identity Management is used to manage roles Description Microsoft Entra Privileged Identity Management can be used to audit roles, allow just in time activation of roles and allow for periodic role attestation. Organizations should remove permanent members from privileged Office 365 roles and instead make them eligible, through a JIT activation workflow. Rationale Organizations want to minimize the number of people who have access to secure information or resources, because that reduces the chance of a malicious actor getting that access, or an authorized user inadvertently impacting a sensitive resource. However, users still need to carry out privileged operations in Entra ID. Organizations can give users just-in-time (JIT) privileged access to roles. There is a need for oversight for what those users are doing with their administrator privileges. PIM helps to mitigate the risk of excessive, unnecessary, or misused access rights. Impact The implementation of Just in Time privileged access is likely to necessitate changes to administrator routine. Administrators will only be granted access to administrative roles when required. When administrators request role activation, they will need to document the reason for requiring role access, anticipated time required to have the access, and to reauthenticate to enable role access. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Entra admin center` https://entra.microsoft.com/. 2. Click to expand `Identity Governance` select `Privileged Identity Management`. 3. Under **Manage** select `Microsoft Entra Roles`. 4. Under **Manage** select `Roles`. 5. Inspect at a minimum the following sensitive roles. For each of the members that have an `ASSIGNMENT TYPE` of `Permanent`, click on the `...` and choose `Make eligible`: - `Application Administrator` - `Authentication Administrator` - `Azure Information Protection Administrator` - `Billing Administrator` - `Cloud Application Administrator` - `Cloud Device Administrator` - `Compliance Administrator` - `Customer LockBox Access Approver` - `Exchange Administrator` - `Fabric Administrator` - `Global Administrator` - `HelpDesk Administrator` - `Intune Administrator` - `Kaizala Administrator` - `License Administrator` - `Microsoft Entra Joined Device Local Administrator` - `Password Administrator` - `Privileged Authentication Administrator` - `Privileged Role Administrator` - `Security Administrator` - `SharePoint Administrator` - `Skype for Business Administrator` - `Teams Administrator` - `User Administrator` Associated Items
Affected Objects More Information TEST ID
|
| 5.3.2 | Ensure Access reviews for Guest Users are configured | Passed | Status:Access Reviews were found | By default access reviews are not configured. | E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure Access reviews for Guest Users are configured Description Access reviews enable administrators to establish an efficient automated process for reviewing group memberships, access to enterprise applications, and role assignments. These reviews can be scheduled to recur regularly, with flexible options for delegating the task of reviewing membership to different members of the organization. Ensure `Access reviews` for Guest Users are configured to be performed no less frequently than `monthly`. Rationale Access to groups and applications for guests can change over time. If a guest user's access to a particular folder goes unnoticed, they may unintentionally gain access to sensitive data if a member adds new files or data to the folder or application. Access reviews can help reduce the risks associated with outdated assignments by requiring a member of the organization to conduct the reviews. Furthermore, these reviews can enable a fail-closed mechanism to remove access to the subject if the reviewer does not respond to the review. Impact Access reviews that are ignored may cause guest users to lose access to resources temporarily. Recommendation and Steps Associated Items
Affected Objects |
| 5.3.3 | Ensure Access reviews for high privileged Azure AD roles are configured | Passed | Status:Access Reviews were found | By default access reviews are not configured. | E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure Access reviews for high privileged Azure AD roles are configured Description Access reviews enable administrators to establish an efficient automated process for reviewing group memberships, access to enterprise applications, and role assignments. These reviews can be scheduled to recur regularly, with flexible options for delegating the task of reviewing membership to different members of the organization. Ensure `Access reviews` for high privileged Entra ID roles are done `monthly` or more frequently. These reviews should include **at a minimum** the roles listed below: - Global Administrator - Exchange Administrator - SharePoint Administrator - Teams Administrator - Security Administrator **Note:** An access review is created for each role selected after completing the process. Rationale Regular review of critical high privileged roles in Entra ID will help identify role drift, or potential malicious activity. This will enable the practice and application of separation of duties where even non-privileged users like security auditors can be assigned to review assigned roles in an organization. Furthermore, if configured these reviews can enable a fail-closed mechanism to remove access to the subject if the reviewer does not respond to the review. Impact In order to avoid disruption reviewers who have the authority to revoke roles should be trusted individuals who understand the significance of access reviews. Additionally, the principle of separation of duties should be applied to ensure that no administrator is responsible for reviewing their own access levels. This will cause additional administrative overhead. If the reviews are configured to automatically revoke highly privileged roles like the Global Administrator role, then this could result in removing all Global Administrators from the organization. Care should be taken when configuring this setting especially in the case of break-glass accounts which would be included by association. Recommendation and Steps Associated Items
Affected Objects |
| 5.3.4 | Ensure approval is required for Global Administrator role activation | Manual Check | NONE | `Require approval to activate` : `No`. | E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure approval is required for Global Administrator role activation Description Microsoft Entra Privileged Identity Management can be used to audit roles, allow just in time activation of roles and allow for periodic role attestation. Requiring approval before activation allows one of the selected approvers to first review and then approve the activation prior to PIM granted the role. The approver doesn't have to be a group member or owner. The recommended state is `Require approval to activate` for the `Global Administrator` role. Rationale Requiring approval for Global Administrator role activation enhances visibility and accountability every time this highly privileged role is used. This process reduces the risk of an attacker elevating a compromised account to the highest privilege level, as any activation must first be reviewed and approved by a trusted party. **Note:** This only acts as protection for eligible users that are activating a role. Directly assigning a role does require an approval workflow so therefore it is important to implement and use PIM correctly. Impact Approvers do not need to be assigned the same role or be members of the same group. It's important to have at least two approvers and an emergency access (break-glass) account to prevent a scenario where no Global Administrators are available. For example, if the last active Global Administrator leaves the organization, and only eligible but inactive Global Administrators remain, a trusted approver without the Global Administrator role or an emergency access account would be essential to avoid delays in critical administrative tasks. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Entra admin center` https://entra.microsoft.com/. 2. Click to expand `Identity Governance` select `Privileged Identity Management`. 3. Under **Manage** select `Microsoft Entra Roles`. 4. Under **Manage** select `Roles`. 5. Select `Global Administrator` in the list. 6. Select `Role settings` and click `Edit`. 7. Check the `Require approval to activate` box. 8. Add at least two approvers. 9. Click `Update`. Associated Items Affected Objects |
| 5.3.5 | Ensure approval is required for Privileged Role Administrator activation | Manual Check | NONE | `Require approval to activate` : `No`. | E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure approval is required for Privileged Role Administrator activation Description Microsoft Entra Privileged Identity Management can be used to audit roles, allow just in time activation of roles and allow for periodic role attestation. Requiring approval before activation allows one of the selected approvers to first review and then approve the activation prior to PIM granted the role. The approver doesn't have to be a group member or owner. The recommended state is `Require approval to activate` for the `Privileged Role Administrator` role. Rationale This role grants the ability to manage assignments for all Microsoft Entra roles including the Global Administrator role. This role does not include any other privileged abilities in Microsoft Entra ID like creating or updating users. However, users assigned to this role can grant themselves or others additional privilege by assigning additional roles. Requiring approval for activation enhances visibility and accountability every time this highly privileged role is used. This process reduces the risk of an attacker elevating a compromised account to the highest privilege level, as any activation must first be reviewed and approved by a trusted party. **Note:** This only acts as protection for eligible users that are activating a role. Directly assigning a role does require an approval workflow so therefore it is important to implement and use PIM correctly. Impact Requiring approvers for automatic role assignment can slightly increase administrative overhead and add delays to tasks. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Entra admin center` https://entra.microsoft.com/. 2. Click to expand `Identity Governance` select `Privileged Identity Management`. 3. Under **Manage** select `Microsoft Entra Roles`. 4. Under **Manage** select `Roles`. 5. Select `Privileged Role Administrator` in the list. 6. Select `Role settings` and click `Edit`. 7. Check the `Require approval to activate` box. 8. Add at least two approvers. 9. Click `Update`. Associated Items Affected Objects |
| Not Available | Use Just In Time privileged access to Microsoft 365 roles | Manual Check | NONE | N/A | N/A | SP v1.0 | NO |
X TEST NAME Use Just In Time privileged access to Microsoft 365 roles Description Rationale Impact Implementation of Just in Time privileged access is likely to necessitate changes to administrator routine. Administrators will only be granted access to administrative roles when required. When administrators request role activation, they will need to document the reason for requiring role access, anticipated time required to have the access, and to reauthenticate to enable role access. Recommendation and Steps Azure Active Directory Privileged Identity Management can be used to audit roles, allow just in time activation of roles and allow for periodic role attestation. Organizations should remove permanent members from privileged Microsoft 365 roles and instead make them eligible, through a JIT activation workflow. Organizations want to minimize the number of people who have access to secure information or resources, because that reduces the chance of a malicious actor getting that access, or an authorized user inadvertently impacting a sensitive resource. However, users still need to carry out privileged operations in Azure AD and Microsoft 365. Organizations can give users just-in-time (JIT) privileged access to roles. Associated Items Affected Objects More Information TEST ID
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 6.1.3 | Ensure AuditBypassEnabled is not enabled on mailboxes | High | Status:AuditBypass is enabled on some mailboxes | AuditBypassEnabled `False` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure AuditBypassEnabled is not enabled on mailboxes Description When configuring a user or computer account to bypass mailbox audit logging, the system will not record any access, or actions performed by the said user or computer account on any mailbox. Administratively this was introduced to reduce the volume of entries in the mailbox audit logs on trusted user or computer accounts. Ensure `AuditBypassEnabled` is not enabled on accounts without a written exception. Rationale If a mailbox audit bypass association is added for an account, the account can access any mailbox in the organization to which it has been assigned access permissions, without generating any mailbox audit logging entries for such access or recording any actions taken, such as message deletions. Enabling this parameter, whether intentionally or unintentionally, could allow insiders or malicious actors to conceal their activity on specific mailboxes. Ensuring proper logging of user actions and mailbox operations in the audit log will enable comprehensive incident response and forensics. Impact None - this is the default behavior. Recommendation and Steps Disable Audit Bypass on all mailboxes using PowerShell:
1. Connect to Exchange Online using Connect-ExchangeOnline.
2. The following example PowerShell script will disable AuditBypass for all mailboxes which currently have it enabled:
# Get mailboxes with AuditBypassEnabled set to $true
$MBXAudit = Get-MailboxAuditBypassAssociation -ResultSize unlimited | Where-Object { $_.AuditBypassEnabled -eq $true }
foreach ($mailbox in $MBXAudit) {
$mailboxName = $mailbox.Name
Set-MailboxAuditBypassAssociation -Identity $mailboxName -AuditBypassEnabled $false
Write-Host -ForegroundColor Green
}
Associated Items
Affected Objects More Information TEST ID
|
| 6.1.3 | Ensure AuditBypassEnabled is not enabled on mailboxes | High | Status:AuditBypass is enabled on some mailboxes | AuditBypassEnabled False | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure AuditBypassEnabled is not enabled on mailboxes Description When configuring a user or computer account to bypass mailbox audit logging, the system will not record any access, or actions performed by the said user or computer account on any mailbox. Administratively this was introduced to reduce the volume of entries in the mailbox audit logs on trusted user or computer accounts. Ensure `AuditBypassEnabled` is not enabled on accounts without a written exception. Rationale If a mailbox audit bypass association is added for an account, the account can access any mailbox in the organization to which it has been assigned access permissions, without generating any mailbox audit logging entries for such access or recording any actions taken, such as message deletions. Enabling this parameter, whether intentionally or unintentionally, could allow insiders or malicious actors to conceal their activity on specific mailboxes. Ensuring proper logging of user actions and mailbox operations in the audit log will enable comprehensive incident response and forensics. Impact None - this is the default behavior. Recommendation and Steps Disable Audit Bypass on all mailboxes using PowerShell:
1. Connect to Exchange Online using Connect-ExchangeOnline.
2. The following example PowerShell script will disable AuditBypass for all mailboxes which currently have it enabled:
# Get mailboxes with AuditBypassEnabled set to $true
$MBXAudit = Get-MailboxAuditBypassAssociation -ResultSize unlimited | Where-Object { $_.AuditBypassEnabled -eq $true }
foreach ($mailbox in $MBXAudit) {
$mailboxName = $mailbox.Name
Set-MailboxAuditBypassAssociation -Identity $mailboxName -AuditBypassEnabled $false
Write-Host -ForegroundColor Green
}
Associated Items
Affected Objects More Information TEST ID
|
| 6.1.1 | Ensure AuditDisabled organizationally is set to False | Passed | Status:Enabled | FALSE | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure AuditDisabled organizationally is set to False Description The value False indicates that mailbox auditing on by default is turned on for the organization. Mailbox auditing on by default in the organization overrides the mailbox auditing settings on individual mailboxes. For example, if mailbox auditing is turned off for a mailbox (the AuditEnabled property on the mailbox is False), the default mailbox actions are still audited for the mailbox, because mailbox auditing on by default is turned on for the organization. Turning off mailbox auditing on by default ($true) has the following results: - Mailbox auditing is turned off for your organization. - From the time you turn off mailbox auditing on by default, no mailbox actions are audited, even if mailbox auditing is enabled on a mailbox (the AuditEnabled property on the mailbox is True). - Mailbox auditing isn't turned on for new mailboxes and setting the AuditEnabled property on a new or existing mailbox to True is ignored. - Any mailbox audit bypass association settings (configured by using the Set-MailboxAuditBypassAssociation cmdlet) are ignored. - Existing mailbox audit records are retained until the audit log age limit for the record expires. The recommended state for this setting is `False` at the organization level. This will enable auditing and enforce the default. Rationale Enforcing the default ensures auditing was not turned off intentionally or accidentally. Auditing mailbox actions will allow forensics and IR teams to trace various malicious activities that can generate TTPs caused by inbox access and tampering. **Note:** Without advanced auditing (E5 function) the logs are limited to 90 days. Impact None - this is the default behavior as of 2019. Recommendation and Steps Associated Items
Affected Objects |
| 6.1.2 | Ensure mailbox audit actions are configured | Passed | Mailbox Audit Config Issues:26106 | `AuditEnabled`: `True` for all mailboxes except below: - Resource Mailboxes - Public Folder Mailboxes - DiscoverySearch Mailbox **AuditAdmin:** ApplyRecord, Create, HardDelete, MailItemsAccessed, MoveToDeletedItems, Send, SendAs, SendOnBehalf, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules **AuditDelegate:** ApplyRecord, Create, HardDelete, MailItemsAccessed, MoveToDeletedItems, SendAs, SendOnBehalf, SoftDelete, Update, UpdateFolderPermissions, UpdateInboxRules **AuditOwner:** ApplyRecord, HardDelete, MailItemsAccessed, MoveToDeletedItems, Send, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure mailbox audit actions are configured Description Mailbox audit logging is turned on by default in all organizations. This effort started in January 2019, and means that certain actions performed by mailbox owners, delegates, and admins are automatically logged. The corresponding mailbox audit records are available for admins to search in the mailbox audit log. Mailboxes and shared mailboxes have actions assigned to them individually in order to audit the data the organization determines valuable at the mailbox level. The recommended state per mailbox is `AuditEnabled` to `True` including all default audit actions with additional actions outlined below in the audit and remediation sections. **Note:** Audit (Standard) licensing allows for up to 180 days log retention as of October 2023. Rationale Whether it is for regulatory compliance or for tracking unauthorized configuration changes in Microsoft 365, enabling mailbox auditing and ensuring the proper mailbox actions are accounted for allows for Microsoft 365 teams to run security operations, forensics or general investigations on mailbox activities. The following mailbox types ignore the organizational default and must have `AuditEnabled` set to `True` at the mailbox level in order to capture relevant audit data. - Resource Mailboxes - Public Folder Mailboxes - DiscoverySearch Mailbox Impact Adding additional audit action types and increasing the AuditLogAgeLimit from 90 to 180 days will have a limited impact on mailbox storage. Mailbox audit log records are stored in a subfolder (named Audits) in the Recoverable Items folder in each user's mailbox. - Mailbox audit records count against the storage quota of the Recoverable Items folder. - Mailbox audit records also count against the folder limit for the Recoverable Items folder. A maximum of 3 million items (audit records) can be stored in the Audits subfolder. The following cmdlet in Exchange Online PowerShell can be run to display the size and number of items in the Audits subfolder in the Recoverable Items folder: ``` Get-MailboxFolderStatistics -Identity Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
|
| Not Available | Ensure mailbox auditing for E3 users is Enabled | Passed | Missing Mailbox Auditing:0 | AuditEnabled: True for all mailboxes except below: - Resource Mailboxes - Public Folder Mailboxes - DiscoverySearch Mailbox **AuditAdmin:** ApplyRecord, Create, HardDelete, MoveToDeletedItems, SendAs, SendOnBehalf, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules **AuditDelegate:** ApplyRecord, Create, HardDelete, MoveToDeletedItems, SendAs, SendOnBehalf, SoftDelete, Update, UpdateFolderPermissions, UpdateInboxRules **AuditOwner:** ApplyRecord, HardDelete, MoveToDeletedItems, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules | N/A | SP v1.0 | YES |
X TEST NAME Ensure mailbox auditing for E3 users is Enabled Description Rationale Impact Mailbox audit logging is turned on by default in all organizations. This effort started in January 2019, and means that certain actions performed by mailbox owners, delegates, and admins are automatically logged. The corresponding mailbox audit records are available for admins to search in the mailbox audit log. Mailboxes and shared mailboxes have actions assigned to them individually in order to audit the data the organization determines valuable at the mailbox level. The recommended state is AuditEnabled to True on all user mailboxes along with additional audit actions beyond the Microsoft defaults. Note: Due to some differences in defaults for audit actions this recommendation is specific to users assigned an E3 license only. Whether it is for regulatory compliance or for tracking unauthorized configuration changes in Microsoft 365, enabling mailbox auditing, and ensuring the proper mailbox actions are accounted for allows for Microsoft 365 teams to run security operations, forensics or general investigations on mailbox activities. The following mailbox types ignore the organizational default and must have AuditEnabled set to True at the mailbox level in order to capture relevant audit data. - Resource Mailboxes - Public Folder Mailboxes - DiscoverySearch Mailbox Note: Without advanced auditing (E5 function) the logs are limited to 90 days. None - this is the default behavior. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Not Available | Ensure mailbox auditing for E5 users is Enabled | Passed | Missing Mailbox Auditing:0 | AuditEnabled: True for all mailboxes except below: - Resource Mailboxes - Public Folder Mailboxes - DiscoverySearch Mailbox **AuditAdmin:** ApplyRecord, Create, HardDelete, MailItemsAccessed, MoveToDeletedItems, Send, SendAs, SendOnBehalf, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules **AuditDelegate:** ApplyRecord, Create, HardDelete, MailItemsAccessed, MoveToDeletedItems, SendAs, SendOnBehalf, SoftDelete, Update, UpdateFolderPermissions, UpdateInboxRules **AuditOwner:** ApplyRecord, HardDelete, MailItemsAccessed, MoveToDeletedItems, Send, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules | N/A | SP v1.0 | YES |
X TEST NAME Ensure mailbox auditing for E5 users is Enabled Description Rationale Impact Mailbox audit logging is turned on by default in all organizations. This effort started in January 2019, and means that certain actions performed by mailbox owners, delegates, and admins are automatically logged. The corresponding mailbox audit records are available for admins to search in the mailbox audit log. Mailboxes and shared mailboxes have actions assigned to them individually in order to audit the data the organization determines valuable at the mailbox level. The recommended state is AuditEnabled to True on all user mailboxes along with additional audit actions beyond the Microsoft defaults. Note: Due to some differences in defaults for audit actions this recommendation is specific to users assigned an E5 license, or auditing addon license, only. Whether it is for regulatory compliance or for tracking unauthorized configuration changes in Microsoft 365, enabling mailbox auditing and ensuring the proper mailbox actions are accounted for allows for Microsoft 365 teams to run security operations, forensics or general investigations on mailbox activities. The following mailbox types ignore the organizational default and must have AuditEnabled set to True at the mailbox level in order to capture relevant audit data. - Resource Mailboxes - Public Folder Mailboxes - DiscoverySearch Mailbox NOTE: Without advanced auditing (E5 function) the logs are limited to 90 days. None - this is the default behavior. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 6.2.3 | Ensure email from external senders is identified | High | Status:Not Configured Correctly | Disabled (False) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure email from external senders is identified Description External callouts provide a native experience to identify emails from senders outside the organization. This is achieved by presenting a new tag on emails called External (the string is localized based on the client language setting) and exposing related user interface at the top of the message reading view to see and verify the real sender's email address. The recommended state is `ExternalInOutlook` set to `Enabled` `True` Rationale Tagging emails from external senders helps to inform end users about the origin of the email. This can allow them to proceed with more caution and make informed decisions when it comes to identifying spam or phishing emails. Mail flow rules are often used by Exchange administrators to accomplish the External email tagging by appending a tag to the front of a subject line. There are limitations to this outlined [here.](https://techcommunity.microsoft.com/t5/exchange-team-blog/native-external-sender-callouts-on-email-in-outlook/ba-p/2250098) The preferred method in the CIS Benchmark is to use the native experience. **Note:** Existing emails in a user's inbox from external senders are not tagged retroactively. Impact Mail flow rules using external tagging must be disabled, along with third-party mail filtering tools that offer similar features, to avoid duplicate [External] tags. External tags can consume additional screen space on systems with limited real estate, such as thin clients or mobile devices. After enabling this feature via PowerShell, it may take 24-48 hours for users to see the External sender tag in emails from outside your organization. Rolling back the feature takes the same amount of time. **Note:** Third-party tools that provide similar functionality will also meet compliance requirements, although Microsoft recommends using the native experience for better interoperability. Recommendation and Steps **To remediate using PowerShell:** 1. Connect to Exchange online using `Connect-ExchangeOnline`. 2. Run the following PowerShell command: ``` Set-ExternalInOutlook -Enabled $true ``` Associated Items
Affected Objects
|
| Not Available | Ensure Safe Attachments is Enabled | High | Status:Not Configured - No ATP License | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Safe Attachments is Enabled Description Rationale Impact The Microsoft Office 365 Safe Attachments feature is not enabled. Safe Attachments is a Microsoft feature that uses behavioral analysis and detonation in a virtual environment to add another layer of defense against malware on top of existing Exchange Online anti-malware policies. It is recommended to enable this feature. This finding may also indicate that the O365 license tier does not enable ATP features. Recommendation and Steps Safe Attachments can be configured by navigating to the Threat Management portal in the Office 365 Security and Compliance center. The first reference below is a detailed guide to configuring ATP Safe Attachments. Associated Items
Affected Objects |
| Not Available | Ensure Safe Links is Enabled | High | Status:Not Configured - No ATP License | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Safe Links is Enabled Description Rationale Impact Safe Links is a feature of O365 that enables real-time detection of malicious links in incoming Exchange emails and other Office 365 applications, such as Microsoft Teams. Safe Links is not enabled in the O365 tenant. This may be because the organization does not have the appropriate license level to use the feature, or because it has been disabled. This lowers the amount of built-in protection O365 offers the organization against phishing and other attacks. Recommendation and Steps Safe Links can be configured by navigating to the Threat Management portal in the Office 365 Security and Compliance center. The first guide below is a quick introduction to enabling Safe Links while the second is a detailed reference. Associated Items
Affected Objects More Information TEST ID
|
| Not Available | Ensure Safe Links Click-Through is Not Allowed | High | Status:Not Configured - No ATP License | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Safe Links Click-Through is Not Allowed Description Rationale Impact Advanced Threat Protection Safe Links (ATP Safe Links) is an Office 365 feature that enables the detection of suspicious links used in attacks delivered via Exchange Email and Teams, such as phishing attacks. ATP Safe Links is configured to allow users to click through a link flagged as unsafe if they choose. It is recommended to disable this ability, as users will often click through to potentially unsafe links if they are given the choice, partially negating the benefit of Safe Links. Recommendation and Steps Use the Set-SafeLinksPolicy function in the Exchange Online PowerShell module as follows Set-SafeLinksPolicy -AllowClickThrough $false. Associated Items
Affected Objects More Information TEST ID
|
| Not Available | Ensure Safe Links Flags Links in Real Time | High | Status:Not Configured - No ATP License | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Safe Links Flags Links in Real Time Description Rationale Impact Safe Links is an Office 365 feature that enables the detection of suspicious links used in attacks delivered via Exchange Email and Teams, such as phishing attacks. ATP Safe Links can be configured to flag dangerous links in email and guarantee that the email will not be delivered until the Safe Links scanning is complete. This is the ideal Safe Links setting. However, this setting is currently disabled, which means it is possible for emails to be delivered before Safe Links protections have been applied. It is also possible that this inspector finding was generated because ATP Safe Links is not enabled or the organization does not have an appropriate O365 license tier to use ATP Safe Links features, in which case the remediation described below would not apply. Recommendation and Steps Use the Set-SafeLinksPolicy function in the Exchange Online PowerShell module as follows Set-SafeLinksPolicy -DeliverMessageAfterScan $false. Associated Items
Affected Objects More Information TEST ID
|
| 6.5.4 | Ensure SMTP Authentication is disabled Globally | High | Status:Not Disabled | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure SMTP Authentication is disabled Globally Description This setting enables or disables authenticated client SMTP submission (SMTP AUTH) at an organization level in Exchange Online. The recommended state is `Turn off SMTP AUTH protocol for your organization` (checked). Rationale SMTP AUTH is a legacy protocol. Disabling it at the organization level supports the principle of least functionality and serves to further back additional controls that block legacy protocols, such as in Conditional Access. Virtually all modern email clients that connect to Exchange Online mailboxes in Microsoft 365 can do so without using SMTP AUTH. Impact This enforces the default behavior, so no impact is expected unless the organization is using it globally. A per-mailbox setting exists that overrides the tenant-wide setting, allowing an individual mailbox SMTP AUTH capability for special cases. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Exchange admin center` https://admin.exchange.microsoft.com. 2. Select `Settings` > `Mail flow`. 3. Uncheck `Turn off SMTP AUTH protocol for your organization`. **To remediate using PowerShell:** 1. Connect to Exchange Online using `Connect-ExchangeOnline`. 2. Run the following PowerShell command: ``` Set-TransportConfig -SmtpClientAuthenticationDisabled $true ``` Associated Items
Affected Objects More Information TEST ID
|
| Not Available | Ensure automatic forwarding options are disabled | High | Status:Not Disabled | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure automatic forwarding options are disabled Description Rationale Impact Care should be taken before implementation to ensure there is no business need for case- by-case auto-forwarding. Recommendation and Steps Disabling auto-forwarding to remote domains will affect all users in an organization. Associated Items
Affected Objects More Information TEST ID
|
| Not Available | Ensure the Client Rules Forwarding Block is enabled | High | Status:Disabled | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure the Client Rules Forwarding Block is enabled Description Rationale Impact Care should be taken before implementation to ensure there is no business need for case- by-case auto-forwarding. Disabling auto-forwarding to remote domains will affect all users in an organization. Recommendation and Steps You should set your Exchange Online mail transport rules to not forward email to domains outside of your organization. Automatic forwarding to prevent users from auto-forwarding mail via Outlook or Outlook on the web should also be disabled. Alongside this Client Rules Forwarding Block, which prevents the use of any client-side rules that forward email to an external domain, should also be enabled. Associated Items
Affected Objects |
| 6.2.1 | Ensure all forms of mail forwarding are blocked and-or disabled | Passed | Mails Forwarding Rules Enabled:0 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure all forms of mail forwarding are blocked and-or disabled Description Exchange Online offers several methods of managing the flow of email messages. These are Remote domain, Transport Rules, and Anti-spam outbound policies. These methods work together to provide comprehensive coverage for potential automatic forwarding channels: - Outlook forwarding using inbox rules. - Outlook forwarding configured using OOF rule. - OWA forwarding setting (ForwardingSmtpAddress). - Forwarding set by the admin using EAC (ForwardingAddress). - Forwarding using Power Automate / Flow. Ensure a `Transport rule` and `Anti-spam outbound policy` are used to block mail forwarding. **NOTE:** Any exclusions should be implemented based on organizational policy. Rationale Attackers often create these rules to exfiltrate data from your tenancy, this could be accomplished via access to an end-user account or otherwise. An insider could also use one of these methods as a secondary channel to exfiltrate sensitive data. Impact Care should be taken before implementation to ensure there is no business need for case-by-case auto-forwarding. Disabling auto-forwarding to remote domains will affect all users and in an organization. Any exclusions should be implemented based on organizational policy. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
LINK
https://learn.microsoft.com/en-us/exchange/security-and-compliance/mail-flow-rules/mail-flow-rules https://techcommunity.microsoft.com/t5/exchange-team-blog/all-you-need-to-know-about-automatic-email-forwarding-in/ba-p/2074888# https:~ https:text=%20%20%20Automatic%20forwarding%20option%20%20,% https://learn.microsoft.com/en-us/defender-office-365/outbound-spam-policies-external-email-forwarding?view=o365-worldwide
|
| 6.2.2 | Ensure mail transport rules do not whitelist specific domains | Passed | Whitelist Domains:0 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure mail transport rules do not whitelist specific domains Description Mail flow rules (transport rules) in Exchange Online are used to identify and take action on messages that flow through the organization. Rationale Whitelisting domains in transport rules bypasses regular malware and phishing scanning, which can enable an attacker to launch attacks against your users from a safe haven domain. **Note:** If an organization identifies a business need for an exception, the domain should only be whitelisted if inbound emails from that domain originate from a specific IP address. These exceptions should be documented and regularly reviewed. Impact Care should be taken before implementation to ensure there is no business need for case-by-case whitelisting. Removing all whitelisted domains could affect incoming mail flow to an organization although modern systems sending legitimate mail should have no issue with this. Recommendation and Steps Associated Items
Affected Objects
|
| Not Available | Ensure Transport Rules to Block Exchange Auto-Forwarding is configured | Passed | Status:Configured | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Transport Rules to Block Exchange Auto-Forwarding is configured Description Rationale Impact No Exchange Online Transport Rules are in place to block email auto-forwarding. Cyber adversaries often configure compromised Office 365 accounts to forward emails to external persons. It is therefore advisable to configure an Exchange transport rule that blocks auto-forwarded emails. Recommendation and Steps Associated Items
Affected Objects |
| Not Available | Ensure Do Not Bypass the Safe Attachments Filter is not configured | Passed | Status:Not Configured | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Do Not Bypass the Safe Attachments Filter is not configured Description Rationale Impact In Exchange, it is possible to create mail transport rules that bypass the Safe Attachments detection capability. The rules listed above bypass the Safe Attachments capability. Consider reviewing these rules, as bypassing the Safe Attachments capability even for a subset of senders could be considered insecure depending on the context or may be an indicator of compromise. Recommendation and Steps Associated Items
Affected Objects |
| Not Available | Ensure Do Not Bypass the Safe Links Feature is not configured | Passed | Status:Not Configured | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Do Not Bypass the Safe Links Feature is not configured Description Rationale Impact In Exchange, it is possible to create mail transport rules that bypass the Safe Links detection capability. The rules listed above bypass the Safe Links capability. Consider reviewing these rules, as bypassing the Safe Links capability even for a subset of senders should be considered dangerous. Recommendation and Steps Associated Items
Affected Objects |
| Not Available | Ensure Exchange Modern Authentication is Enabled | Passed | Status:Enabled | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Exchange Modern Authentication is Enabled Description Rationale Impact Modern Authentication is an Exchange feature that allows authentication capabilities such as Multi-Factor Authentication, smart cards, and certificate-based authentication to function. It is recommended that Modern Authentication be enabled for Exchange Online in order to provide these capabilities. Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
|
| Not Available | Ensure Transport Rules to Block Executable Attachments are configured | Passed | Status:Configured | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Transport Rules to Block Executable Attachments are configured Description Rationale Impact No Exchange Online Transport Rules are in place to block email containing executable attachments. Executable attachments can be used to deliver malicious payloads and exfiltrate company data. Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
|
| Not Available | Ensure Malware Filter Policies Alert for Internal Users Sending Malware is configured | Passed | Status:Configured | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Malware Filter Policies Alert for Internal Users Sending Malware is configured Description Rationale Impact Malware being sent by an internal user's email account is often an indication that a security event has occurred. For this reason, it is strongly recommended that each organization have malware filter policies that alert administrators when malware is being sent by an internal user's account. It is possible to configure malware filter policies in O365 that generate these alerts. The malware filter policies listed herein do not alert an administrator when an internal user sends malware. Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
|
| Not Available | Ensure Mailbox Auditing is Enabled at Tenant Level | Passed | Status:Enabled | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Mailbox Auditing is Enabled at Tenant Level Description Rationale Impact Mailbox Auditing is an Exchange mailbox feature that, when activated, generates audit logs for events related to a user's use of email. This is one of the most oft-recommended security improvements to Exchange because mailbox audit logs can contain information critical in a detection or response scenario such as triaging a business email compromise. Mailbox auditing can be globally enabled at the Tenant level, which supersedes all per-mailbox settings, but it is not currently enabled. Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
|
| Not Available | Ensure Mailboxes without Mailbox Auditing are not present | Passed | Mailboxes Without Auditing:0 | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Mailboxes without Mailbox Auditing are not present Description Rationale Impact The Exchange mailboxes listed above do not have Mailbox Auditing enabled. Mailbox Auditing enables the logging of certain actions performed by mailbox owners and administrators and is a valuable source of data for the investigation and analysis of security incidents such as business email compromises. It is recommended that Mailbox Auditing be enabled for the affected mailboxes. Note that it is possible mailbox auditing is enabled globally, which would supersede these findings. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Not Available | Ensure mail transport rules do not forward email to external domains | Passed | Mails Forwarding Rules Enabled:0 | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure mail transport rules do not forward email to external domains Description Rationale Impact No Exchange Online Transport Rules are in place to block email auto-forwarding. Cyber adversaries often configure compromised Office 365 accounts to forward emails to external persons. It is therefore advisable to configure an Exchange transport rule that blocks auto-forwarded emails. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| Not Available | Ensure the Advanced Threat Protection Safe Links policy is enabled | Passed | Status:Not Enabled-Not Implemented | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure the Advanced Threat Protection Safe Links policy is enabled Description Rationale Impact When enabling and configuring ATP Safe Links, the impact to the end-user should be low. Users should be informed of the change as in the event a link is unsafe and blocked, they will receive a message that it has been blocked. Recommendation and Steps Associated Items
Affected Objects More Information TEST ID
|
| Not Available | Ensure the Advanced Threat Protection SafeAttachments policy is enabled | Passed | Status:Not Enabled-Not Implemented | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure the Advanced Threat Protection SafeAttachments policy is enabled Description Rationale Impact Delivery of email with attachments may be delayed while scanning is occurring. Delay is very Minute after enabling. 60 Sec to 1 Min Recommendation and Steps Associated Items
Affected Objects |
| 2.1.7 | Ensure that an anti-phishing policy has been created | Passed | Status:Created | N/A | E5 Level 2 | CIS v6.0 | YES |
X TEST NAME Ensure that an anti-phishing policy has been created Description By default, Office 365 includes built-in features that help protect users from phishing attacks. Set up anti-phishing polices to increase this protection, for example by refining settings to better detect and prevent impersonation and spoofing attacks. The default policy applies to all users within the organization and is a single view to fine-tune anti-phishing protection. Custom policies can be created and configured for specific users, groups or domains within the organization and will take precedence over the default policy for the scoped users. Rationale Protects users from phishing attacks (like impersonation and spoofing) and uses safety tips to warn users about potentially harmful messages. Impact Mailboxes that are used for support systems such as helpdesk and billing systems send mail to internal users and are often not suitable candidates for impersonation protection. Care should be taken to ensure that these systems are excluded from Impersonation Protection. Recommendation and Steps Associated Items
Affected Objects |
| Not Available | Ensure mailbox auditing for all users is Enabled | Passed | Missing Mailbox Auditing:0 | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure mailbox auditing for all users is Enabled Description Rationale Impact Auditing Process needs to be created and followed. Recommendation and Steps Associated Items
Affected Objects
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 6.3.1 | Ensure users installing Outlook add-ins is not allowed | High | Status:Allowed to Install Outlook Add-in | UI - `My Custom Apps`, `My Marketplace Apps`, and `My ReadWriteMailboxApps` are checked PowerShell - `My Custom Apps` `My Marketplace Apps` and `My ReadWriteMailboxApps` are assigned | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure users installing Outlook add-ins is not allowed Description Specify the administrators and users who can install and manage add-ins for Outlook in Exchange Online By default, users can install add-ins in their Microsoft Outlook Desktop client, allowing data access within the client application. Rationale Attackers exploit vulnerable or custom add-ins to access user data. Disabling user-installed add-ins in Microsoft Outlook reduces this threat surface. Impact Implementing this change will impact both end users and administrators. End users will be unable to integrate third-party applications they desire, and administrators may receive requests to grant permission for necessary third-party apps. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Exchange admin center` https://admin.exchange.microsoft.com. 2. Click to expand `Roles` select `User roles`. 3. Select `Default Role Assignment Policy`. 4. In the properties pane on the right click on `Manage permissions`. 5. Under _Other roles_ uncheck `My Custom Apps`, `My Marketplace Apps` and `My ReadWriteMailboxApps`. 6. Click `Save changes`. **To remediate using PowerShell:** 1. Connect to Exchange Online using `Connect-ExchangeOnline`. 2. Run the following command: ``` $policy = Role Assignment Policy - Prevent Add-ins $roles = MyTextMessaging, MyDistributionGroups, ` MyMailSubscriptions, MyBaseOptions, MyVoiceMail, ` MyProfileInformation, MyContactInformation, MyRetentionPolicies, ` MyDistributionGroupMembership New-RoleAssignmentPolicy -Name $policy -Roles $roles Set-RoleAssignmentPolicy -id $policy -IsDefault # Assign new policy to all mailboxes Get-EXOMailbox -ResultSize Unlimited | Set-Mailbox -RoleAssignmentPolicy $policy ``` **If you have other Role Assignment Policies modify the last line to filter out your custom policies** Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 6.5.4 | Ensure SMTP Authentication is disabled Globally | High | Status:Not Disabled | SmtpClientAuthenticationDisabled : True | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure SMTP Authentication is disabled Globally Description This setting enables or disables authenticated client SMTP submission (SMTP AUTH) at an organization level in Exchange Online. The recommended state is `Turn off SMTP AUTH protocol for your organization` (checked). Rationale SMTP AUTH is a legacy protocol. Disabling it at the organization level supports the principle of least functionality and serves to further back additional controls that block legacy protocols, such as in Conditional Access. Virtually all modern email clients that connect to Exchange Online mailboxes in Microsoft 365 can do so without using SMTP AUTH. Impact This enforces the default behavior, so no impact is expected unless the organization is using it globally. A per-mailbox setting exists that overrides the tenant-wide setting, allowing an individual mailbox SMTP AUTH capability for special cases. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Exchange admin center` https://admin.exchange.microsoft.com. 2. Select `Settings` > `Mail flow`. 3. Uncheck `Turn off SMTP AUTH protocol for your organization`. **To remediate using PowerShell:** 1. Connect to Exchange Online using `Connect-ExchangeOnline`. 2. Run the following PowerShell command: ``` Set-TransportConfig -SmtpClientAuthenticationDisabled $true ``` Associated Items
Affected Objects More Information TEST ID
|
| Not Available | Ensure Email Security Checks are Bypassed Based on Sender Domain are not configured | High | Status:Configured | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Email Security Checks are Bypassed Based on Sender Domain are not configured Description Rationale Impact In the Exchange transport rules settings, it is possible to implement transport rules that bypass spam filtering and other email security capabilities (Exchange Online Protection) based on an IP address or domain (allowlisting). This makes a significan not assumption of trust that should be reviewed and reconsidered. The transport rules listed herein bypass email security based on a domain allowlist. Recommendation and Steps Locate the rules 365Inspect has identified (they are listed in this report) and determine who created the rules. Pursue a dialogue or analysis of whether the Exchange Online Protection is necessary for continued operations and whether another solution is possible. If the rules are not necessary, remove the rules. Associated Items
Affected Objects More Information TEST ID
|
| Not Available | Ensure Email Security Checks are Bypassed Based on Sender IP are not configured | High | Status:Configured | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Email Security Checks are Bypassed Based on Sender IP are not configured Description Rationale Impact In the Exchange transport rules settings, it is possible to implement transport rules that bypass spam filtering and other email security capabilities (Exchange Online Protection) based on an IP address or domain (allowlisting). This makes a significan not assumption of trust that should be reviewed and reconsidered. The transport rules listed herein bypass email security based on an IP address allowlist. Recommendation and Steps Locate the rules 365Inspect has identified (they are listed in this report) and determine who created the rules. Pursue a dialogue or analysis of whether the allowlisting is necessary for continued operations and whether another solution is possible. If the rules are not necessary, remove the rules. Associated Items
Affected Objects More Information TEST ID
|
| Not Available | Ensure No Exchange Mailboxes with FullAccess Delegates are present | High | Number of Mailboxes with FullAccess Delegates:0 | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure No Exchange Mailboxes with FullAccess Delegates are present Description Rationale Impact The Exchange Online mailboxes listed above have delegated Full Access permissions to another account. Recommendation and Steps This finding refers to individual mailboxes that have Full Access delegated permissions. For these mailboxes, verify that the delegate access is expected, appropriate, and does not violate company policy. Remediation can be accomplished by running the listed PowerShell command. A list of affected email addresses is included in this report. Associated Items
Affected Objects More Information TEST ID
|
| Not Available | Ensure No Exchange Mailboxes with SendAs Delegates are present | High | Number of Mailboxes with SendAs Delegates: | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure No Exchange Mailboxes with SendAs Delegates are present Description Rationale Impact The Exchange Online mailboxes listed above have delegated SendAs permissions to another account. Recommendation and Steps This finding refers to individual mailboxes that have SendAs delegated permissions. For these mailboxes, verify that the delegate access is expected, appropriate, and does not violate company policy. Remediation can be accomplished by running the listed PowerShell command. A list of affected email addresses is included in this report. Associated Items
Affected Objects More Information TEST ID
|
| Not Available | Ensure No Exchange Mailboxes with SendOnBehalfOf Delegates are present | High | Number of Mailboxes with SendOnBehalfOf Delegates:0 | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure No Exchange Mailboxes with SendOnBehalfOf Delegates are present Description Rationale Impact The Exchange Online mailboxes listed above have delegated SendOnBehalfOf permissions to another account. Recommendation and Steps This finding refers to individual mailboxes that have SendOnBehalfOf delegated permissions. For these mailboxes, verify that the delegate access is expected, appropriate, and does not violate company policy. Remediation can be accomplished by running the listed PowerShell command. A list of affected email addresses is included in this report. Associated Items
Affected Objects More Information TEST ID
|
| 6.5.2 | Ensure MailTips are enabled for end users | Medium | Status:Not All MailTips Enabled | MailTipsAllTipsEnabled: True MailTipsExternalRecipientsTipsEnabled: False MailTipsGroupMetricsEnabled: True MailTipsLargeAudienceThreshold: 25 | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure MailTips are enabled for end users Description MailTips are informative messages displayed to users while they're composing a message. While a new message is open and being composed, Exchange analyzes the message (including recipients). If a potential problem is detected, the user is notified with a MailTip prior to sending the message. Using the information in the MailTip, the user can adjust the message to avoid undesirable situations or non-delivery reports (also known as NDRs or bounce messages). Rationale Setting up MailTips gives a visual aid to users when they send emails to large groups of recipients or send emails to recipients not within the tenant. Impact Not applicable. Recommendation and Steps **To remediate using PowerShell:**
1. Connect to Exchange Online using `Connect-ExchangeOnline`.
2. Run the following PowerShell command:
```
$TipsParams = @{
MailTipsAllTipsEnabled = $true
MailTipsExternalRecipientsTipsEnabled = $true
MailTipsGroupMetricsEnabled = $true
MailTipsLargeAudienceThreshold = '25'
}
Set-OrganizationConfig @TipsParams
```
Associated Items
Affected Objects |
| 6.5.3 | Ensure external storage providers available in Outlook on the Web are restricted | Medium | Status:Not Restricted | `Additional Storage Providers` - `True` | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure external storage providers available in Outlook on the Web are restricted Description This setting allows users to open certain external files while working in Outlook on the web. If allowed, keep in mind that ?Microsoft? doesn't control the use terms or privacy policies of those third-party services. Ensure `AdditionalStorageProvidersAvailable` are restricted. Rationale By default, additional storage providers are allowed in Office on the Web (such as Box, Dropbox, Facebook, Google Drive, OneDrive Personal, etc.). This could lead to information leakage and additional risk of infection from organizational non-trusted storage providers. Restricting this will inherently reduce risk as it will narrow opportunities for infection and data leakage. Impact The impact associated with this change is highly dependent upon current practices in the tenant. If users do not use other storage providers, then minimal impact is likely. However, if users do regularly utilize providers outside of the tenant this will affect their ability to continue to do so. Recommendation and Steps **To remediate using PowerShell:** 1. Connect to Exchange Online using `Connect-ExchangeOnline`. 2. Run the following PowerShell command: ``` Set-OwaMailboxPolicy -Identity OwaMailboxPolicy-Default -AdditionalStorageProvidersAvailable $false ``` Associated Items
Affected Objects |
| 6.5.1 | Ensure modern authentication for Exchange Online is enabled | Passed | Status:Enabled | TRUE | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure modern authentication for Exchange Online is enabled Description Modern authentication in Microsoft 365 enables authentication features like multifactor authentication (MFA) using smart cards, certificate-based authentication (CBA), and third-party SAML identity providers. When you enable modern authentication in Exchange Online, Outlook 2016 and Outlook 2013 use modern authentication to log in to Microsoft 365 mailboxes. When you disable modern authentication in Exchange Online, Outlook 2016 and Outlook 2013 use basic authentication to log in to Microsoft 365 mailboxes. When users initially configure certain email clients, like Outlook 2013 and Outlook 2016, they may be required to authenticate using enhanced authentication mechanisms, such as multifactor authentication. Other Outlook clients that are available in Microsoft 365 (for example, Outlook Mobile and Outlook for Mac 2016) always use modern authentication to log in to Microsoft 365 mailboxes. Rationale Strong authentication controls, such as the use of multifactor authentication, may be circumvented if basic authentication is used by Exchange Online email clients such as Outlook 2016 and Outlook 2013. Enabling modern authentication for Exchange Online ensures strong authentication mechanisms are used when establishing sessions between email clients and Exchange Online. Impact Users of older email clients, such as Outlook 2013 and Outlook 2016, will no longer be able to authenticate to Exchange using Basic Authentication, which will necessitate migration to modern authentication practices. Recommendation and Steps Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? | ||||||||||||
| Not Available | Ensure Mailboxes External Address Forwarding is not configured | High | Mailboxes Forwarding To External Domains:1 | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Mailboxes External Address Forwarding is not configured Description Rationale Impact It is a security risk. Mailboxes must not be configured with forwarding to prevent data loss. Recommendation and Steps Please review the list and make sure to remove forwarding from these mailboxes. Associated Items
Affected Objects
| |||||||||||
| Not Available | Ensure Exchange Online Mailboxes on Litigation Hold | High | Mailboxes On Litigation Hold:1 | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Exchange Online Mailboxes on Litigation Hold Description Rationale Impact Refer issue details. Recommendation and Steps Please review the list provided. Associated Items
Affected Objects | |||||||||||
| Not Available | Ensure Exchange Online SPAM Domains are identified | High | Inbound and Outbound SPAM Items:3 | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Exchange Online SPAM Domains are identified Description Rationale Impact It is a security risk. Recommendation and Steps Identify the SPAM domains and block them. Associated Items
Affected Objects
| |||||||||||
| Not Available | Ensure Microsoft 365 Hidden Mailboxes are Identified | Medium | Hidden Mailboxes:1 | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Microsoft 365 Hidden Mailboxes are Identified Description Rationale Impact These mailboxes will not appear in the address list. Recommendation and Steps Please review the list provided. Associated Items
Affected Objects
| |||||||||||
| Not Available | Ensure mail forwarding rules are reviewed and actioned | Passed | Forwarding Rules To External Domains:0 | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure mail forwarding rules are reviewed and actioned Description Rationale Impact Auditing Process needs to be created and followed. Recommendation and Steps Associated Items
Affected Objects | |||||||||||
| Not Available | Ensure the Malware Detections report is reviewed at least weekly | Passed | Malware Report Items:0 | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure the Malware Detections report is reviewed at least weekly Description Rationale Impact Auditing Process needs to be created and followed. Recommendation and Steps Associated Items
Affected Objects | |||||||||||
| Not Available | Ensure Microsoft 365 Deleted Mailboxes are identified and Verified | Passed | Deleted Mailboxes:0 | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Microsoft 365 Deleted Mailboxes are identified and Verified Description Rationale Impact Refer issue details. Recommendation and Steps Associated Items
Affected Objects
| |||||||||||
| Not Available | Ensure Exchange Online Mailbox Auditing is enabled | Passed | Mailboxes Without Auditing:0 | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Exchange Online Mailbox Auditing is enabled Description Rationale Impact Auditing is required for mailboxes in order to see changes that have been taking place. Recommendation and Steps Associated Items
Affected Objects
| |||||||||||
| Not Available | Microsoft 365 Exchange Online Admin Success and Failure Attempts | Passed | Failures for Online Admins:0 | N/A | N/A | SP v1.0 | YES |
X TEST NAME Microsoft 365 Exchange Online Admin Success and Failure Attempts Description Rationale Impact It is a security risk. Recommendation and Steps Associated Items
Affected Objects
| |||||||||||
| Not Available | Microsoft 365 Exchange Online External Access Admin Success and Failure Attempts | Passed | Failures for External Admins:0 | N/A | N/A | SP v1.0 | YES |
X TEST NAME Microsoft 365 Exchange Online External Access Admin Success and Failure Attempts Description Rationale Impact It is a security risk. Recommendation and Steps Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 7.2.1 | Ensure modern authentication for SharePoint applications is required | High | Status:Disabled | True (Apps that don't use modern authentication are allowed) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure modern authentication for SharePoint applications is required Description Modern authentication in Microsoft 365 enables authentication features like multifactor authentication (MFA) using smart cards, certificate-based authentication (CBA), and third-party SAML identity providers. Rationale Strong authentication controls, such as the use of multifactor authentication, may be circumvented if basic authentication is used by SharePoint applications. Requiring modern authentication for SharePoint applications ensures strong authentication mechanisms are used when establishing sessions between these applications, SharePoint, and connecting users. Impact Implementation of modern authentication for SharePoint will require users to authenticate to SharePoint using modern authentication. This may cause a minor impact to typical user behavior. This may also prevent third-party apps from accessing SharePoint Online resources. Also, this will also block apps using the SharePointOnlineCredentials class to access SharePoint Online resources. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `SharePoint admin center` https://admin.microsoft.com/sharepoint. 2. Click to expand `Policies` select `Access control`. 3. Select `Apps that don't use modern authentication`. 4. Select the radio button for `Block access`. 5. Click `Save`. **To remediate using PowerShell:** 1. Connect to SharePoint Online using `Connect-SPOService -Url https://tenant-admin.sharepoint.com` replacing tenant with your value. 2. Run the following SharePoint Online PowerShell command: ``` Set-SPOTenant -LegacyAuthProtocolsEnabled $false ``` Associated Items
Affected Objects More Information TEST ID
|
| 7.2.3 | Ensure external content sharing is restricted | High | Status:Not Configured Correctly | Anyone (ExternalUserAndGuestSharing) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure external content sharing is restricted Description The external sharing settings govern sharing for the organization overall. Each site has its own sharing setting that can be set independently, though it must be at the same or more restrictive setting as the organization. The new and existing guests option requires people who have received invitations to sign in with their work or school account (if their organization uses Microsoft 365) or a Microsoft account, or to provide a code to verify their identity. Users can share with guests already in your organization's directory, and they can send invitations to people who will be added to the directory if they sign in. The recommended state is `New and existing guests` or less permissive. Rationale Forcing guest authentication on the organization's tenant enables the implementation of controls and oversight over external file sharing. When a guest is registered with the organization, they now have an identity which can be accounted for. This identity can also have other restrictions applied to it through group membership and conditional access rules. Impact When using B2B integration, Entra ID external collaboration settings, such as guest invite settings and collaboration restrictions apply. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `SharePoint admin center` https://admin.microsoft.com/sharepoint 2. Click to expand `Policies` > `Sharing`. 3. Locate the `External sharing section`. 4. Under SharePoint, move the slider bar to `New and existing guests` or a less permissive level. - OneDrive will also be moved to the same level and can never be more permissive than SharePoint. **To remediate using PowerShell:** 1. Connect to SharePoint Online service using `Connect-SPOService`. 2. Run the following cmdlet to establish the minimum recommended state: ``` Set-SPOTenant -SharingCapability ExternalUserSharingOnly ``` **Note:** Other acceptable values for this parameter that are more restrictive include: `Disabled` and `ExistingExternalUserSharingOnly`. Associated Items
Affected Objects |
| 7.2.4 | Ensure OneDrive content sharing is restricted | High | Status:Not Disabled | Anyone (ExternalUserAndGuestSharing) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure OneDrive content sharing is restricted Description This setting governs the global permissiveness of OneDrive content sharing in the organization. OneDrive content sharing can be restricted independent of SharePoint but can never be more permissive than the level established with SharePoint. The recommended state is `Only people in your organization`. Rationale OneDrive, designed for end-user cloud storage, inherently provides less oversight and control compared to SharePoint, which often involves additional content overseers or site administrators. This autonomy can lead to potential risks such as inadvertent sharing of privileged information by end users. Restricting external OneDrive sharing will require users to transfer content to SharePoint folders first which have those tighter controls. Impact Users will be required to take additional steps to share OneDrive content or use other official channels. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `SharePoint admin center` https://admin.microsoft.com/sharepoint 2. Click `Settings` then select `OneDrive - Sync`. 3. Check the `Allow syncing only on computers joined to specific domains`. 4. Use the `Get-ADDomain` PowerShell command on the on-premises server to obtain the GUID for each on-premises domain. 5. Click `Save`. **To remediate using PowerShell:** 1. Connect to SharePoint Online using `Connect-SPOService` 2. Run the following PowerShell command and provide the DomainGuids from the Get-AADomain command: ``` Set-SPOTenantSyncClientRestriction -Enable -DomainGuids 786548DD-877B-4760-A749-6B1EFBC1190A; 877564FF-877B-4760-A749-6B1EFBC1190A ``` **Note:** Utilize the `-BlockMacSync:$true` parameter if you are not using conditional access to ensure Macs cannot sync. Associated Items
Affected Objects |
| 7.2.5 | Ensure that SharePoint guest users cannot share items they dont own | High | Status:Not Enabled | Checked (False) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure that SharePoint guest users cannot share items they dont own Description SharePoint gives users the ability to share files, folders, and site collections. Internal users can share with external collaborators, and with the right permissions could share to other external parties. Rationale Sharing and collaboration are key; however, file, folder, or site collection owners should have the authority over what external users get shared with to prevent unauthorized disclosures of information. Impact The impact associated with this change is highly dependent upon current practices. If users do not regularly share with external parties, then minimal impact is likely. However, if users do regularly share with guests/externally, minimum impacts could occur as those external users will be unable to 're-share' content. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `SharePoint admin center` https://admin.microsoft.com/sharepoint 2. Click to expand `Policies` then select `Sharing`. 3. Expand `More external sharing settings`, uncheck `Allow guests to share items they don't own`. 4. Click `Save`. **To remediate using PowerShell:** 1. Connect to SharePoint Online service using `Connect-SPOService`. 2. Run the following SharePoint Online PowerShell command: ``` Set-SPOTenant -PreventExternalUsersFromResharing $True ``` Associated Items
Affected Objects |
| 7.2.6 | Ensure document sharing is being controlled by domains with whitelist or blacklist | High | Status:Not Controlled | Limit external sharing by domain is unchecked
SharingDomainRestrictionMode: `None`
SharingDomainRestrictionMode: |
E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure document sharing is being controlled by domains with whitelist or blacklist Description Control sharing of documents to external domains by either blocking domains or only allowing sharing with specific named domains. Rationale Attackers will often attempt to expose sensitive information to external entities through sharing, and restricting the domains that users can share documents with will reduce that surface area. Impact Enabling this feature will prevent users from sharing documents with domains outside of the organization unless allowed. Recommendation and Steps You should control sharing of documents to external domains by either blocking domains or only allowing sharing with specific named domains. Enabling this feature will prevent users from sharing documents with domains outside of the organization unless allowed. Attackers will often attempt to expose sensitive information to external entities through sharing, and restricting the domains that your users can share documents with will reduce that surface area. Associated Items
Affected Objects
|
| 7.2.7 | Ensure link sharing is restricted in SharePoint and OneDrive | High | Status:Not Restricted-AnonymousAccess | Only people in your organization (Internal) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure link sharing is restricted in SharePoint and OneDrive Description This setting sets the default link type that a user will see when sharing content in OneDrive or SharePoint. It does not restrict or exclude any other options. The recommended state is `Specific people (only the people the user specifies)` or `Only people in your organization` (more restrictive). Rationale By defaulting to specific people, the user will first need to consider whether or not the content being shared should be accessible by the entire organization versus select individuals. This aids in reinforcing the concept of least privilege. Impact Recommendation and Steps **To remediate using the UI:** 1. Navigate to `SharePoint admin center` https://admin.microsoft.com/sharepoint 2. Click to expand `Policies` > `Sharing`. 3. Scroll to `File and folder links`. 4. Set `Choose the type of link that's selected by default when users share files and folders in SharePoint and OneDrive` to `Specific people (only the people the user specifies)` or `Only people in your organization`. **To remediate using PowerShell:** 1. Connect to SharePoint Online using `Connect-SPOService`. 2. Run the following PowerShell command: ``` Set-SPOTenant -DefaultSharingLinkType Direct ``` 3. Or, to set a more restrictive state: ``` Set-SPOTenant -DefaultSharingLinkType Internal ``` Associated Items
Affected Objects More Information TEST ID
|
| 7.2.9 | Ensure guest access to a site or OneDrive will expire automatically | High | Status:Do not expire Automatically | ExternalUserExpirationRequired `$false` ExternalUserExpireInDays `60` days | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure guest access to a site or OneDrive will expire automatically Description This policy setting configures the expiration time for each guest that is invited to the SharePoint site or with whom users share individual files and folders with. The recommended state is `30` or less. Rationale This setting ensures that guests who no longer need access to the site or link no longer have access after a set period of time. Allowing guest access for an indefinite amount of time could lead to loss of data confidentiality and oversight. **Note:** Guest membership applies at the Microsoft 365 group level. Guests who have permission to view a SharePoint site or use a sharing link may also have access to a Microsoft Teams team or security group. Impact Site collection administrators will have to renew access to guests who still need access after 30 days. They will receive an e-mail notification once per week about guest access that is about to expire. **Note:** The guest expiration policy only applies to guests who use sharing links or guests who have direct permissions to a SharePoint site after the guest policy is enabled. The guest policy does not apply to guest users that have pre-existing permissions or access through a sharing link before the guest expiration policy is applied. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `SharePoint admin center` https://admin.microsoft.com/sharepoint 2. Click to expand `Policies` > `Sharing`. 3. Scroll to and expand `More external sharing settings`. 4. Set `Guest access to a site or OneDrive will expire automatically after this many days` to `30` **To remediate using PowerShell:** 1. Connect to SharePoint Online service using `Connect-SPOService`. 2. Run the following cmdlet: ``` Set-SPOTenant -ExternalUserExpireInDays 30 -ExternalUserExpirationRequired $True ``` Associated Items
Affected Objects
|
| 7.2.10 | Ensure reauthentication with verification code is restricted | High | Status:Not Restricted-False | EmailAttestationRequired : `False` EmailAttestationReAuthDays : `30` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure reauthentication with verification code is restricted Description This setting configures if guests who use a verification code to access the site or links are required to reauthenticate after a set number of days. The recommended state is `15` or less. Rationale By increasing the frequency of times guests need to reauthenticate this ensures guest user access to data is not prolonged beyond an acceptable amount of time. Impact Guests who use Microsoft 365 in their organization can sign in using their work or school account to access the site or document. After the one-time passcode for verification has been entered for the first time, guests will authenticate with their work or school account and have a guest account created in the host's organization. **Note:** If OneDrive and SharePoint integration with Entra ID B2B is enabled as per the CIS Benchmark the one-time-passcode experience will be replaced. Please visit [Secure external sharing in SharePoint - SharePoint in Microsoft 365 | Microsoft Learn](https://learn.microsoft.com/en-US/sharepoint/what-s-new-in-sharing-in-targeted-release?WT.mc_id=365AdminCSH_spo) for more information. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `SharePoint admin center` https://admin.microsoft.com/sharepoint 2. Click to expand `Policies` > `Sharing`. 3. Scroll to and expand `More external sharing settings`. 4. Set `People who use a verification code must reauthenticate after this many days` to `15` or less. **To remediate using PowerShell:** 1. Connect to SharePoint Online service using `Connect-SPOService`. 2. Run the following cmdlet: ``` Set-SPOTenant -EmailAttestationRequired $true -EmailAttestationReAuthDays 15 ``` Associated Items
Affected Objects More Information TEST ID
|
| 7.2.11 | Ensure the SharePoint default sharing link permission is set | High | Status:Not Restricted | DefaultLinkPermission : Edit | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure the SharePoint default sharing link permission is set Description This setting configures the permission that is selected by default for sharing link from a SharePoint site. The recommended state is `View`. Rationale Setting the view permission as the default ensures that users must deliberately select the edit permission when sharing a link. This approach reduces the risk of unintentionally granting edit privileges to a resource that only requires read access, supporting the principle of least privilege. Impact Not applicable. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `SharePoint admin center` https://admin.microsoft.com/sharepoint 2. Click to expand `Policies` > `Sharing`. 3. Scroll to **File and folder links**. 4. Set `Choose the permission that's selected by default for sharing links` to `View`. **To remediate using PowerShell:** 1. Connect to SharePoint Online service using `Connect-SPOService`. 2. Run the following cmdlet: ``` Set-SPOTenant -DefaultLinkPermission View ``` Associated Items
Affected Objects
More Information TEST ID
|
| 7.2.6 | Ensure document sharing is being controlled by domains with whitelist or blacklist | High | Status:Not Controlled | Limit external sharing by domain is unchecked
SharingDomainRestrictionMode: None
SharingDomainRestrictionMode: |
E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure document sharing is being controlled by domains with whitelist or blacklist Description Control sharing of documents to external domains by either blocking domains or only allowing sharing with specific named domains. Rationale Attackers will often attempt to expose sensitive information to external entities through sharing, and restricting the domains that users can share documents with will reduce that surface area. Impact Enabling this feature will prevent users from sharing documents with domains outside of the organization unless allowed. Recommendation and Steps You should control sharing of documents to external domains by either blocking domains or only allowing sharing with specific named domains. Enabling this feature will prevent users from sharing documents with domains outside of the organization unless allowed. Attackers will often attempt to expose sensitive information to external entities through sharing, and restricting the domains that your users can share documents with will reduce that surface area. Associated Items
Affected Objects
|
| Not Available | Ensure expiration time for external sharing links is set | Medium | Status:Expiration Time for Links NOT Set | ExternalUserExpirationRequired $false ExternalUserExpireInDays 60 days | N/A | SP v1.0 | NO |
X TEST NAME Ensure expiration time for external sharing links is set Description Rationale Impact Enabling this feature will ensure that link expire within the defined number of days. This will have an effect on links that were previously not set with an expiration. Recommendation and Steps The external sharing features of Microsoft SharePoint let users in your organization share content with people outside the organization (such as partners, vendors, clients, or customers). External sharing in SharePoint is part of secure collaboration with Microsoft 365. An attacker can compromise a user account for a short period of time, send anonymous sharing links to an external account, then take their time accessing the data. They can also compromise external accounts and steal the anonymous sharing links sent to those external entities well after the data has been shared. Restricting how long the links are valid can reduce the window of opportunity for attackers. Associated Items
Affected Objects |
| 7.2.2 | Ensure SharePoint and OneDrive integration with Azure AD B2B is enabled | Passed | Status:Enabled | FALSE | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure SharePoint and OneDrive integration with Azure AD B2B is enabled Description Entra ID B2B provides authentication and management of guests. Authentication happens via one-time passcode when they don't already have a work or school account or a Microsoft account. Integration with SharePoint and OneDrive allows for more granular control of how guest user accounts are managed in the organization's AAD, unifying a similar guest experience already deployed in other Microsoft 365 services such as Teams. **Note:** Global Reader role currently can't access SharePoint using PowerShell. Rationale External users assigned guest accounts will be subject to Entra ID access policies, such as multi-factor authentication. This provides a way to manage guest identities and control access to SharePoint and OneDrive resources. Without this integration, files can be shared without account registration, making it more challenging to audit and manage who has access to the organization's data. Impact B2B collaboration is used with other Entra services so should not be new or unusual. Microsoft also has made the experience seamless when turning on integration on SharePoint sites that already have active files shared with guest users. The referenced Microsoft article on the subject has more details on this. Recommendation and Steps Associated Items
Affected Objects |
| 7.2.8 | Ensure external sharing is restricted by security group | Manual Check | NONE | Unchecked/Undefined | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure external sharing is restricted by security group Description External sharing of content can be restricted to specific security groups. This setting is global, applies to sharing in both SharePoint and OneDrive and cannot be set at the site level in SharePoint. The recommended state is `Enabled` or `Checked`. **Note:** Users in these security groups must be allowed to invite guests in the guest invite settings in Microsoft Entra. Identity > External Identities > External collaboration settings Rationale Organizations wishing to create tighter security controls for external sharing can set this to enforce role-based access control by using security groups already defined in Microsoft Entra. Impact OneDrive will also be governed by this and there is no granular control at the SharePoint site level. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `SharePoint admin center` https://admin.microsoft.com/sharepoint 2. Click to expand `Policies` > `Sharing`. 3. Scroll to and expand `More external sharing settings`. 4. Set the following: - Check `Allow only users in specific security groups to share externally` - Define `Manage security groups` in accordance with company procedure. Associated Items Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Not Available | SharePoint External Sharing is not Enabled at Global Level | Critical | Status:Enabled - : Sharing capability is ExternalUserAndGuestSharing (Anyone). | N/A | N/A | SP v1.0 | NO |
X TEST NAME SharePoint External Sharing is not Enabled at Global Level Description Rationale Impact SharePoint is the organization's hub for sharing files amongst each other. SharePoint can also permit users to share content with anonymous outsiders or members of other organizations (commonly referred to as \external users\). Sharing with external users and guests is currently enabled in this instance of SharePoint. This setting may increase the probability of sensitive information being shared outside of the organization, either accidentally or as a means of data exfiltration by a cyber adversary with access to the organizational environment. Consider disabling this setting for the sake of preventing such occurrences if there is no intention of sharing information outside of the organization as part of the organization's mission. However, note that some degree of external sharing is vital for many organizations. Furthermore, disabling external sharing is not necessarily a panacea for problems related to confidential information, as users may still mistakenly or maliciously share confidential information through a number of channels. Continue to apply good sense in data loss prevention and other forms of monitoring even if external sharing is disabled. Recommendation and Steps First, look at the \Affected Objects\ section of the report for this finding; it should indicate which global sharing permission level the organization has currently enabled in SharePoint. If this is too permissive for the organization's use cases, consider taking action. There are multiple ways to change this setting. Navigate to Settings; Services; Sites in the O365 Admin portal, or the Sharing page of the SharePoint Administration Center. Doing either should present a list of global sharing capabilities, where \Share with Anyone\ is the default; change this to a more restrictive setting. Before taking this action, it is advised to engage with other stakeholders in the organization to determine if SharePoint external sharing is used for an organizational function. An appropriate workaround or alternative course of action may need to be determined. Additionally, sharing settings besides the global-level settings are available; consider reading the \Limit sharing in Microsoft 365\ guide below if additional granularity in sharing settings is required. Associated Items
Affected Objects |
| Not Available | SharePoint External User Resharing is not Permitted | Critical | Status:Permitted | N/A | N/A | SP v1.0 | NO |
X TEST NAME SharePoint External User Resharing is not Permitted Description Rationale Impact SharePoint is the organization's hub for sharing files amongst each other. SharePoint can also permit users to share content with anonymous outsiders or members of other organizations (commonly referred to as \external users\). Current SharePoint settings are configured such that, if users share a file with an external user, that external user can re-share the file arbitrarily with other external users. This is a highly permissive setting that could result in the unsafe propagation of the organization's confidential information in ways that may not be fully intended. Recommendation and Steps Depending on the organization's use case, external user resharing may be disabled. This is most easily accomplished with the Set-SPOTenant PowerShell commandlet from the SharePoint Online administration module. Associated Items
Affected Objects |
| Not Available | SharePoint Legacy Authentication is not Enabled | Critical | Status:Enabled | N/A | N/A | SP v1.0 | NO |
X TEST NAME SharePoint Legacy Authentication is not Enabled Description Rationale Impact SharePoint legacy authentication is enabled. Cyber adversaries frequently attempt credential stuffing and other attacks against legacy authentication protocols because they are subject to less scrutiny and are typically exempt from Multi-Factor Authentication and other modern access requirements. It is recommended to globally disable SharePoint legacy authentication. Recommendation and Steps Consider using the SharePoint PowerShell module to disable legacy authentication protocols. Note that globally disabling legacy authentication could have an adverse effect on some users or applications that require legacy authentication to perform their functions. In such cases, it is possible to more granularly set up a Conditional Access Policy that blocks legacy authentication for only those users and applications who do not strictly require it. Documentation for both approaches is provided in the references below. Associated Items
Affected Objects |
| 7.3.1 | Ensure Microsoft 365 SharePoint infected files are disallowed for download | High | Status:WARNING:Allowed | FALSE | E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure Microsoft 365 SharePoint infected files are disallowed for download Description By default, SharePoint online allows files that Defender for Office 365 has detected as infected to be downloaded. Rationale Defender for Office 365 for SharePoint, OneDrive, and Microsoft Teams protects your organization from inadvertently sharing malicious files. When an infected file is detected that file is blocked so that no one can open, copy, move, or share it until further actions are taken by the organization's security team. Impact The only potential impact associated with implementation of this setting is potential inconvenience associated with the small percentage of false positive detections that may occur. Recommendation and Steps **To remediate using PowerShell:** 1. Connect to SharePoint Online using `Connect-SPOService -Url https://tenant-admin.sharepoint.com`, replacing tenant with the appropriate value. 2. Run the following PowerShell command to set the recommended value: ``` Set-SPOTenant ?DisallowInfectedFileDownload $true ``` **Note:** The Global Reader role cannot access SharePoint using PowerShell according to Microsoft. See the reference section for more information. Associated Items
Affected Objects More Information TEST ID
LINK
https://learn.microsoft.com/en-us/defender-office-365/safe-attachments-for-spo-odfb-teams-configure?view=o365-worldwide https://learn.microsoft.com/en-us/defender-office-365/anti-malware-protection-for-spo-odfb-teams-about?view=o365-worldwide https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference#global-reader
|
| 7.2.4 | Ensure OneDrive content sharing is restricted | High | Status:Not Disabled | By default there are no restrictions applied to the syncing of OneDrive. TenantRestrictionEnabled : `False` AllowedDomainList : `{}` | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure OneDrive content sharing is restricted Description This setting governs the global permissiveness of OneDrive content sharing in the organization. OneDrive content sharing can be restricted independent of SharePoint but can never be more permissive than the level established with SharePoint. The recommended state is `Only people in your organization`. Rationale OneDrive, designed for end-user cloud storage, inherently provides less oversight and control compared to SharePoint, which often involves additional content overseers or site administrators. This autonomy can lead to potential risks such as inadvertent sharing of privileged information by end users. Restricting external OneDrive sharing will require users to transfer content to SharePoint folders first which have those tighter controls. Impact Users will be required to take additional steps to share OneDrive content or use other official channels. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `SharePoint admin center` https://admin.microsoft.com/sharepoint 2. Click `Settings` then select `OneDrive - Sync`. 3. Check the `Allow syncing only on computers joined to specific domains`. 4. Use the `Get-ADDomain` PowerShell command on the on-premises server to obtain the GUID for each on-premises domain. 5. Click `Save`. **To remediate using PowerShell:** 1. Connect to SharePoint Online using `Connect-SPOService` 2. Run the following PowerShell command and provide the DomainGuids from the Get-AADomain command: ``` Set-SPOTenantSyncClientRestriction -Enable -DomainGuids 786548DD-877B-4760-A749-6B1EFBC1190A; 877564FF-877B-4760-A749-6B1EFBC1190A ``` **Note:** Utilize the `-BlockMacSync:$true` parameter if you are not using conditional access to ensure Macs cannot sync. Associated Items
Affected Objects |
| Not Available | Ensure custom script execution is restricted on personal sites | High | Total Sites allowing custom script execution:55 | Selected `Prevent users from running custom script on self-service created sites` | N/A | SP v1.0 | NO |
X TEST NAME Ensure custom script execution is restricted on personal sites Description This setting controls custom script execution on self-service created sites. Custom scripts can allow users to change the look, feel and behavior of sites and pages. Every script that runs in a SharePoint page (whether it's an HTML page in a document library or a JavaScript in a Script Editor Web Part) always runs in the context of the user visiting the page and the SharePoint application. This means: - Scripts have access to everything the user has access to. - Scripts can access content across several Microsoft 365 services and even beyond with Microsoft Graph integration. The recommended state is `Prevent users from running custom script on self-service created sites`. Rationale Custom scripts could contain malicious instructions unknown to the user or administrator. When users are allowed to run custom script, the organization can no longer enforce governance, scope the capabilities of inserted code, block specific parts of code, or block all custom code that has been deployed. If scripting is allowed the following things can't be audited: - What code has been inserted - Where the code has been inserted - Who inserted the code **Note:** Microsoft recommends using the [SharePoint Framework](https://learn.microsoft.com/en-us/sharepoint/dev/spfx/sharepoint-framework-overview) instead of custom scripts. Impact None - this is the default behavior. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `SharePoint admin center` https://admin.microsoft.com/sharepoint 2. Select `Settings`. 3. At the bottom of the page click the `classic settings page` hyperlink. 4. Scroll to locate the **Custom Script** section. On the right set the following: - Select `Prevent users from running custom script on self-service created sites`. Associated Items
Affected Objects |
| Not Available | Ensure SharePoint sites are not enabled for both External and User Sharing | High | Status:Enabled | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure SharePoint sites are not enabled for both External and User Sharing Description Rationale Impact If you have confidential information that can be shared with external users. Recommendation and Steps Recommended action is to disable SharePoint sites for both external and user sharing. Associated Items
Affected Objects |
| Not Available | External user sharing-share by email-and guest link sharing are both disabled | High | Status:Not Disabled | N/A | N/A | SP v1.0 | NO |
X TEST NAME External user sharing-share by email-and guest link sharing are both disabled Description Rationale Impact When users share with people outside the organization, an invitation is sent to the person in email, which contains a link to the shared item. If you have confidential information that should never be shared externally, we recommend storing the information in a site that has external sharing turned off. Create additional sites as needed to use for external sharing. This helps you to manage security risk by preventing external access to sensitive information. Recommendation and Steps It is recommended to review the sharing policy and adjust accordingly. Associated Items
Affected Objects |
| Not Available | Ensure that external users cannot share files folders and sites they do not own | High | Status:Not Enabled | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure that external users cannot share files folders and sites they do not own Description Rationale Impact Impact associated with this change is highly dependent upon current practices. If users do not regularly share with external parties, then minimal impact is likely. Recommendation and Steps If users do regularly share with guests/externally minimum impacts could occur as those external users will be unable to 're-share' content. Associated Items
Affected Objects |
| Not Available | SharePoint Anyone Shared Links Never Expire is not configured | High | Status:Never Expires | N/A | N/A | SP v1.0 | NO |
X TEST NAME SharePoint Anyone Shared Links Never Expire is not configured Description Rationale Impact The organization's instance of SharePoint is set to never expire links to documents accessible by the 'Anyone' group. 'Anyone' links that exists indefinitely could be abused by an adversary or enable leakage of sensitive information in multiple ways. A value of -1 indicates anonymous links never expire. It is suggested that these links expire eventually to control possible information disclosure. Recommendation and Steps In the SharePoint administration center, navigate to Sharing; Choose expiration and permissions options for Anyone links. Select a link expiry period and save the settings. Prior to taking this action, discuss amongst the organization whether anyone is using non-expiring Anyone links for a legitimate purpose. Associated Items
Affected Objects |
| Not Available | Ensure Sign out inactive users in SharePoint Online is Configured | High | Sign-out Inactive Users Status:The setting is not compliant. | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Sign out inactive users in SharePoint Online is Configured Description Rationale Impact Idle session sign-out lets you specify a time at which users are warned and are later signed out of Microsoft 365 after a period of browser inactivity in SharePoint and OneDrive. Recommendation and Steps This policy is one of several you can use with SharePoint and OneDrive to balance security and user productivity and help keep your data safe, regardless of where users access the data from, what device they're working on, and how secure their network connection is. Associated Items
Affected Objects |
| Not Available | Ensure custom script execution is restricted on site collections | Passed | Not Restricted for Sites:0 | DenyAddAndCustomizePages `$true` or `Enabled` | N/A | SP v1.0 | YES |
X TEST NAME Ensure custom script execution is restricted on site collections Description This setting controls custom script execution on a particular site (previously called site collection). Custom scripts can allow users to change the look, feel and behavior of sites and pages. Every script that runs in a SharePoint page (whether it's an HTML page in a document library or a JavaScript in a Script Editor Web Part) always runs in the context of the user visiting the page and the SharePoint application. This means: - Scripts have access to everything the user has access to. - Scripts can access content across several Microsoft 365 services and even beyond with Microsoft Graph integration. The recommended state is `DenyAddAndCustomizePages` set to `$true`. Rationale Custom scripts could contain malicious instructions unknown to the user or administrator. When users are allowed to run custom script, the organization can no longer enforce governance, scope the capabilities of inserted code, block specific parts of code, or block all custom code that has been deployed. If scripting is allowed the following things can't be audited: - What code has been inserted - Where the code has been inserted - Who inserted the code **Note:** Microsoft recommends using the [SharePoint Framework](https://learn.microsoft.com/en-us/sharepoint/dev/spfx/sharepoint-framework-overview) instead of custom scripts. Impact None - this is the default behavior. Recommendation and Steps Associated Items
Affected Objects |
| Not Available | SharePoint Online Modern Authentication is Enabled | Passed | Status:Enabled | N/A | N/A | SP v1.0 | YES |
X TEST NAME SharePoint Online Modern Authentication is Enabled Description Rationale Impact Modern Authentication is a SharePoint Online setting that allows authentication features such as MFA, smart cards, and certificate-based authentication to function. These authentication features, particularly MFA, are vital for the secure operation of an organization. It is recommended to enable SharePoint modern authentication. Recommendation and Steps Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 8.1.1 | Ensure external file sharing in Teams is enabled for only approved cloud storage services | High | Status:Not Controlled | AllowDropBox : `True` AllowBox : `True` AllowGoogleDrive : `True` AllowShareFile : `True` AllowEgnyte : `True` | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure external file sharing in Teams is enabled for only approved cloud storage services Description Microsoft Teams enables collaboration via file sharing. This file sharing is conducted within Teams, using SharePoint Online, by default; however, third-party cloud services are allowed as well. **Note:** Skype for business is deprecated as of July 31, 2021 although these settings may still be valid for a period of time. See the link in the references section for more information. Rationale Ensuring that only authorized cloud storage providers are accessible from Teams will help to dissuade the use of non-approved storage providers. Impact The impact associated with this change is highly dependent upon current practices in the tenant. If users do not use other storage providers, then minimal impact is likely. However, if users do regularly utilize providers outside of the tenant this will affect their ability to continue to do so. Recommendation and Steps **To remediate using the UI:**
1. Navigate to `Microsoft Teams admin center` https://admin.teams.microsoft.com.
2. Click to expand `Teams` select `Teams settings`.
3. Set any unauthorized providers to `Off`.
**To remediate using PowerShell:**
1. Connect to Teams PowerShell using `Connect-MicrosoftTeams`
2. Run the following PowerShell command to disable external providers that are not authorized. (the example disables Citrix Files, DropBox, Box, Google Drive and Egnyte)
```
$storageParams = @{
AllowGoogleDrive = $false
AllowShareFile = $false
AllowBox = $false
AllowDropBox = $false
AllowEgnyte = $false
}
Set-CsTeamsClientConfiguration @storageParams
```
Associated Items
Affected Objects |
| 8.1.2 | Ensure users cant send emails to a channel email address | High | Status:Can Send Emails | On (True) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure users cant send emails to a channel email address Description Teams channel email addresses are an optional feature that allows users to email the Teams channel directly. Rationale Channel email addresses are not under the tenant?s domain and organizations do not have control over the security settings for this email address. An attacker could email channels directly if they discover the channel email address. Impact Users will not be able to email the channel directly. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Teams admin center` https://admin.teams.microsoft.com. 2. Click to expand `Teams` select `Teams settings`. 3. Under email integration set `Users can send emails to a channel email address` to `Off`. **To remediate using PowerShell:** 1. Connect to Teams PowerShell using `Connect-MicrosoftTeams`. 2. Run the following command to set the recommended state: ``` Set-CsTeamsClientConfiguration -Identity Global -AllowEmailIntoChannel $false ``` Associated Items
Affected Objects More Information TEST ID
LINK
https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/step-by-step-guides/reducing-attack-surface-in-microsoft-teams?view=o365-worldwide#restricting-channel-email-messages-to-approved-domains https://learn.microsoft.com/en-us/powershell/module/skype/set-csteamsclientconfiguration?view=skype-ps https://support.microsoft.com/en-us/office/send-an-email-to-a-channel-in-microsoft-teams-d91db004-d9d7-4a47-82e6-fb1b16dfd51e
|
| Not Available | Ensure End-to-end encryption for Microsoft Teams is enabled | High | Status:Disabled | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure End-to-end encryption for Microsoft Teams is enabled Description Rationale Impact In recent times, Microsoft Teams has emerged as the ultimate workspace for real-time collaboration and communication. Since most of the business communication is carried out by MS teams, security has become a concern. By default, Teams calls over VOIP are encrypted using Transport Layer Security (TLS) and Secure Real-Time Transport Protocol (SRTP). However, these protocols allow admins to configure automatic recording and transcription of calls. Recommendation and Steps It is recommended to enable end-to-end calling encryption enabled for Teams calls. Associated Items
Affected Objects |
| 8.2.1 | Ensure external domains are not allowed in Teams | High | Status:Allowed All Domains | N/A | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure external domains are not allowed in Teams Description This policy controls whether external domains are allowed, blocked or permitted based on an allowlist or denylist. When external domains are allowed, users in your organization can chat, add users to meetings, and use audio video conferencing with users in external organizations. The recommended state is `Allow only specific external domains` or `Block all external domains`. Rationale Allowlisting external domains that an organization is collaborating with allows for stringent controls over who an organization's users are allowed to make contact with. Some real-world attacks and exploits delivered via Teams over external access channels include: - DarkGate malware - Social engineering / Phishing attacks by Midnight Blizzard - GIFShell - Username enumeration Impact The impact in terms of the type of collaboration users are allowed to participate in and the I.T. resources expended to manage an allowlist will increase. If a user attempts to join the inviting organization's meeting they will be prevented from joining unless they were created as a guest in EntraID or their domain was added to the allowed external domains list. **Note** Organizations may choose create additional policies for specific groups needing external access. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Teams admin center` https://admin.teams.microsoft.com/. 2. Click to expand `Users` select `External access`. 3. Select the `Policies` tab 4. Click on the `Global (Org-wide default)` policy. 5. Set `Teams and Skype for Business users in external organizations` to `Off`. 6. Click `Save`. **To remediate using PowerShell:** 1. Connect to Teams PowerShell using `Connect-MicrosoftTeams` 2. Run the following command to configure the Global (Org-wide default)` policy. ``` Set-CsExternalAccessPolicy -Identity Global -EnableFederationAccess $false ``` **Note:** Configuring the organization settings to block external access or to use a domain allowlist is also ni compliance with this control. Associated Items
Affected Objects More Information TEST ID
LINK
https://learn.microsoft.com/en-us/microsoftteams/trusted-organizations-external-meetings-chat?tabs=organization-settings https://cybersecurity.att.com/blogs/security-essentials/darkgate-malware-delivered-via-microsoft-teams-detection-and-response https://www.microsoft.com/en-us/security/blog/2023/08/02/midnight-blizzard-conducts-targeted-social-engineering-over-microsoft-teams/ https://www.bitdefender.com/blog/hotforsecurity/gifshell-attack-lets-hackers-create-reverse-shell-through-microsoft-teams-gifs/
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 8.2.1 | Ensure external domains are not allowed in Teams | High | Status:Allowed All Domains | EnableFederationAccess - $True | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure external domains are not allowed in Teams Description This policy controls whether external domains are allowed, blocked or permitted based on an allowlist or denylist. When external domains are allowed, users in your organization can chat, add users to meetings, and use audio video conferencing with users in external organizations. The recommended state is `Allow only specific external domains` or `Block all external domains`. Rationale Allowlisting external domains that an organization is collaborating with allows for stringent controls over who an organization's users are allowed to make contact with. Some real-world attacks and exploits delivered via Teams over external access channels include: - DarkGate malware - Social engineering / Phishing attacks by Midnight Blizzard - GIFShell - Username enumeration Impact The impact in terms of the type of collaboration users are allowed to participate in and the I.T. resources expended to manage an allowlist will increase. If a user attempts to join the inviting organization's meeting they will be prevented from joining unless they were created as a guest in EntraID or their domain was added to the allowed external domains list. **Note** Organizations may choose create additional policies for specific groups needing external access. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Teams admin center` https://admin.teams.microsoft.com/. 2. Click to expand `Users` select `External access`. 3. Select the `Policies` tab 4. Click on the `Global (Org-wide default)` policy. 5. Set `Teams and Skype for Business users in external organizations` to `Off`. 6. Click `Save`. **To remediate using PowerShell:** 1. Connect to Teams PowerShell using `Connect-MicrosoftTeams` 2. Run the following command to configure the Global (Org-wide default)` policy. ``` Set-CsExternalAccessPolicy -Identity Global -EnableFederationAccess $false ``` **Note:** Configuring the organization settings to block external access or to use a domain allowlist is also ni compliance with this control. Associated Items
Affected Objects More Information TEST ID
LINK
https://learn.microsoft.com/en-us/microsoftteams/trusted-organizations-external-meetings-chat?tabs=organization-settings https://cybersecurity.att.com/blogs/security-essentials/darkgate-malware-delivered-via-microsoft-teams-detection-and-response https://www.microsoft.com/en-us/security/blog/2023/08/02/midnight-blizzard-conducts-targeted-social-engineering-over-microsoft-teams/ https://www.bitdefender.com/blog/hotforsecurity/gifshell-attack-lets-hackers-create-reverse-shell-through-microsoft-teams-gifs/
|
| 8.2.2 | Ensure communication with unmanaged Teams users is disabled | High | Status:Not Restricted | '- EnableTeamsConsumerAccess : `True` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure communication with unmanaged Teams users is disabled Description This policy setting controls chats and meetings with external unmanaged Teams users (those not managed by an organization, such as Microsoft Teams (free)). The recommended state is: `People in my organization can communicate with unmanaged Teams accounts` set to `Off`. Rationale Allowing users to communicate with unmanaged Teams users presents a potential security threat as little effort is required by threat actors to gain access to a trial or free Microsoft Teams account. Some real-world attacks and exploits delivered via Teams over external access channels include: - DarkGate malware - Social engineering / Phishing attacks by Midnight Blizzard - GIFShell - Username enumeration Impact Users will be unable to communicate with Teams users who are not managed by an organization. Organizations may choose create additional policies for specific groups needing to communicating with unmanaged external users. **Note:** The settings that govern chats and meetings with external unmanaged Teams users aren't available in GCC, GCC High, or DOD deployments, or in private cloud environments. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Teams admin center` https://admin.teams.microsoft.com/. 2. Click to expand `Users` select `External access`. 3. Select the `Policies` tab 4. Click on the `Global (Org-wide default)` policy. 5. Set `People in my organization can communicate with unmanaged Teams accounts` to `Off`. 6. Click `Save`. **To remediate using PowerShell:** 1. Connect to Teams PowerShell using `Connect-MicrosoftTeams` 2. Run the following command: ``` Set-CsExternalAccessPolicy -Identity Global -EnableTeamsConsumerAccess $false ``` **Note:** Configuring the organization settings to block communication is also in compliance with this control. Associated Items
Affected Objects
More Information TEST ID
LINK
https://learn.microsoft.com/en-us/microsoftteams/trusted-organizations-external-meetings-chat?tabs=organization-settings https://cybersecurity.att.com/blogs/security-essentials/darkgate-malware-delivered-via-microsoft-teams-detection-and-response https://www.microsoft.com/en-us/security/blog/2023/08/02/midnight-blizzard-conducts-targeted-social-engineering-over-microsoft-teams/ https://www.bitdefender.com/blog/hotforsecurity/gifshell-attack-lets-hackers-create-reverse-shell-through-microsoft-teams-gifs/
|
| 8.2.3 | Ensure external Teams users cannot initiate conversations | High | Status:Not Restricted | '- EnableTeamsConsumerInbound : `True` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure external Teams users cannot initiate conversations Description This setting prevents external users who are not managed by an organization from initiating contact with users in the protected organization. The recommended state is to uncheck `External users with Teams accounts not managed by an organization can contact users in my organization`. **Note:** Disabling this setting is used as an additional stop gap for the previous setting which disables communication with unmanaged Teams users entirely. If an organization chooses to have an exception to **(L1) Ensure communication with unmanaged Teams users is disabled** they can do so while also disabling the ability for the same group of users to initiate contact. Disabling communication entirely will also disable the ability for unmanaged users to initiate contact. Rationale Allowing users to communicate with unmanaged Teams users presents a potential security threat as little effort is required by threat actors to gain access to a trial or free Microsoft Teams account. Some real-world attacks and exploits delivered via Teams over external access channels include: - DarkGate malware - Social engineering / Phishing attacks by Midnight Blizzard - GIFShell - Username enumeration Impact The impact of disabling this is very low. Organizations may choose to create additional policies for specific groups that need to communicate with unmanaged external users. **Note:** Chats and meetings with external unmanaged Teams users isn't available in GCC, GCC High, or DOD deployments, or in private cloud environments. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Teams admin center` https://admin.teams.microsoft.com/. 2. Click to expand `Users` select `External access`. 3. Select the `Policies` tab. 4. Click on the `Global (Org-wide default)` policy. 5. Locate the parent setting **People in my organization can communicate with unmanaged Teams accounts**. 6. Uncheck `External users with Teams accounts not managed by an organization can contact users in my organization`. 7. Click `Save`. **Note:** If `People in my organization can communicate with unmanaged Teams accounts` is already set to `Off` then this setting will not be visible and will satisfy the requirements of this recommendation. **To remediate using PowerShell:** 1. Connect to Teams PowerShell using `Connect-MicrosoftTeams` 2. Run the following command: ``` Set-CsExternalAccessPolicy -Identity Global -EnableTeamsConsumerInbound $false ``` **Note:** Configuring the organization settings to block inbound communication is also in compliance with this control. Associated Items
Affected Objects
More Information TEST ID
LINK
https://learn.microsoft.com/en-us/microsoftteams/trusted-organizations-external-meetings-chat?tabs=organization-settings https://cybersecurity.att.com/blogs/security-essentials/darkgate-malware-delivered-via-microsoft-teams-detection-and-response https://www.microsoft.com/en-us/security/blog/2023/08/02/midnight-blizzard-conducts-targeted-social-engineering-over-microsoft-teams/ https://www.bitdefender.com/blog/hotforsecurity/gifshell-attack-lets-hackers-create-reverse-shell-through-microsoft-teams-gifs/
|
| Not Available | Ensure communication with Skype users is disabled | Passed | Status:Restricted | '- AllowPublicUsers : `True` | N/A | SP v1.0 | YES |
X TEST NAME Ensure communication with Skype users is disabled Description This policy setting controls chat with external unmanaged Skype users. **Note:** Starting in May 2025, Skype will no longer be available. This setting will be removed and users won?t be able to communicate with Skype users. Rationale Skype was deprecated July 31, 2021. Disabling communication with skype users reduces the attack surface of the organization. If a partner organization or satellite office wishes to collaborate and has not yet moved off of Skype, then a valid exception will need to be considered for this recommendation. Impact Teams users will be unable to communicate with Skype users that are not in the same organization. Recommendation and Steps Associated Items
Affected Objects
More Information TEST ID
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 8.4.1 | Ensure app permission policies are configured | High | Status:Either some or all settings are Not compliant | Microsoft apps: On Third-party apps: On Custom apps: On | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure app permission policies are configured Description This policy setting controls which class of apps are available for users to install. Rationale Allowing users to install third-party or unverified apps poses a potential risk of introducing malicious software to the environment. Impact Users will only be able to install approved classes of apps. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Teams admin center` https://admin.teams.microsoft.com. 2. Click to expand `Teams apps` select `Manage apps`. 3. In the upper right click `Actions` > `Org-wide app settings`. 4. For `Microsoft apps` set `Let users install and use available apps by default` to `On` or less permissive. 5. For `Third-party apps` set `Let users install and use available apps by default` to `Off`. 6. For `Custom apps` set `Let users install and use available apps by default` to `Off`. 7. For `Custom apps` set `Let users interact with custom apps in preview` to `Off`. Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 8.5.1 | Ensure anonymous users cant join a meeting | High | Status:Not Restricted | On (True) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure anonymous users cant join a meeting Description Anonymous users are users whose identity can't be verified. They may be logged in to an organization without a mutual trust relationship or they may not have an account (guest or user). Anonymous participants appear with (Unverified) appended to their name in meetings. These users could include: - Users who aren't logged in to Teams with a work or school account. - Users from non-trusted organizations (as configured in external access) and from organizations that you trust but which don't trust your organization. When defining trusted organizations for external meetings and chat, ensure both organizations allow each other's domains. Meeting organizers and participants should have user policies that allow external access. These settings prevent attendees from being considered anonymous due to external access settings. For details, see IT Admins - Manage external meetings and chat with people and organizations using Microsoft identities The recommended state is `Anonymous users can join a meeting unverified` set to `Off`. Rationale For meetings that could contain sensitive information, it is best to allow the meeting organizer to vet anyone not directly sent an invite before admitting them to the meeting. This will also prevent the anonymous user from using the meeting link to have meetings at unscheduled times. **Note:** Those companies that don't normally operate at a Level 2 environment, but do deal with sensitive information, may want to consider this policy setting. Impact Individuals who were not sent or forwarded a meeting invite will not be able to join the meeting automatically. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Teams admin center` https://admin.teams.microsoft.com. 2. Click to expand `Meetings` select `Meeting policies`. 3. Click `Global (Org-wide default)` 3. Under meeting join & lobby set `Anonymous users can join a meeting unverified` to `Off`. **To remediate using PowerShell:** 1. Connect to Teams PowerShell using `Connect-MicrosoftTeams` 2. Run the following command to set the recommended state: ``` Set-CsTeamsMeetingPolicy -Identity Global -AllowAnonymousUsersToJoinMeeting $false ``` Associated Items
Affected Objects More Information TEST ID
LINK
https://learn.microsoft.com/en-us/defender-office-365/step-by-step-guides/reducing-attack-surface-in-microsoft-teams?view=o365-worldwide#configure-meeting-settings https://learn.microsoft.com/en-us/microsoftteams/settings-policies-reference?WT.mc_id=TeamsAdminCenterCSH#meeting-join--lobby https://learn.microsoft.com/en-us/MicrosoftTeams/configure-meetings-sensitive-protection https://learn.microsoft.com/en-us/microsoftteams/anonymous-users-in-meetings https://learn.microsoft.com/en-us/microsoftteams/plan-meetings-external-participants
|
| 8.5.3 | Ensure only people in my org can bypass the lobby | High | Status:Not Restricted: EveryoneInCompany | People in my org and guests (EveryoneInCompany) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure only people in my org can bypass the lobby Description This policy setting controls who can join a meeting directly and who must wait in the lobby until they're admitted by an organizer, co-organizer, or presenter of the meeting. The recommended state is `People who were invited` or more restrictive. Rationale For meetings that could contain sensitive information, it is best to allow the meeting organizer to vet anyone not directly sent an invite before admitting them to the meeting. This will also prevent the anonymous user from using the meeting link to have meetings at unscheduled times. Impact Individuals who are not part of the organization will have to wait in the lobby until they're admitted by an organizer, co-organizer, or presenter of the meeting. Any individual who dials into the meeting regardless of status will also have to wait in the lobby. This includes internal users who are considered unauthenticated when dialing in. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Teams admin center` https://admin.teams.microsoft.com. 2. Click to expand `Meetings` select `Meeting policies`. 3. Click `Global (Org-wide default)`. 3. Under meeting join & lobby set `Who can bypass the lobby` to `People who were invited` or a more restrictive value: `People in my org`, `Only organizers and co-organizers`. **To remediate using PowerShell:** 1. Connect to Teams PowerShell using `Connect-MicrosoftTeams`. 2. Run the following command to set the recommended state: ``` Set-CsTeamsMeetingPolicy -Identity Global -AutoAdmittedUsers InvitedUsers ``` **Note:** More restrictive values `EveryoneInCompanyExcludingGuests` or `OrganizerOnly` are also in compliance. Associated Items
Affected Objects |
| 8.5.4 | Ensure users dialing in cant bypass the lobby | High | Status:Not Restricted | Off (False) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure users dialing in cant bypass the lobby Description This policy setting controls if users who dial in by phone can join the meeting directly or must wait in the lobby. Admittance to the meeting from the lobby is authorized by the meeting organizer, co-organizer, or presenter of the meeting. Rationale For meetings that could contain sensitive information, it is best to allow the meeting organizer to vet anyone not directly from the organization. Impact Individuals who are dialing in to the meeting must wait in the lobby until a meeting organizer, co-organizer, or presenter admits them. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Teams admin center` https://admin.teams.microsoft.com. 2. Click to expand `Meetings` select `Meeting policies`. 3. Click `Global (Org-wide default)`. 3. Under meeting join & lobby set `People dialing in can bypass the lobby` to `Off`. **To remediate using PowerShell:** 1. Connect to Teams PowerShell using `Connect-MicrosoftTeams`. 2. Run the following command to set the recommended state: ``` Set-CsTeamsMeetingPolicy -Identity Global -AllowPSTNUsersToBypassLobby $false ``` Associated Items
Affected Objects |
| 8.5.5 | Ensure meeting chat does not allow anonymous users | High | Status:Not Restricted | On for everyone (Enabled) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure meeting chat does not allow anonymous users Description This policy setting controls who has access to read and write chat messages during a meeting. Rationale Ensuring that only authorized individuals can read and write chat messages during a meeting reduces the risk that a malicious user can inadvertently show content that is not appropriate or view sensitive information. Impact Only authorized individuals will be able to read and write chat messages during a meeting. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Teams admin center` https://admin.teams.microsoft.com. 2. Click to expand `Meetings` select `Meeting policies`. 3. Click `Global (Org-wide default)`. 3. Under meeting engagement set `Meeting chat` to `On for everyone but anonymous users`. **To remediate using PowerShell:** 1. Connect to Teams PowerShell using `Connect-MicrosoftTeams`. 2. Run the following command to set the recommended state: ``` Set-CsTeamsMeetingPolicy -Identity Global -MeetingChatEnabledType EnabledExceptAnonymous ``` Associated Items
Affected Objects More Information TEST ID
|
| 8.5.6 | Ensure only organizers and co-organizers can present | High | Status:Not Restricted | Everyone (EveryoneUserOverride) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure only organizers and co-organizers can present Description This policy setting controls who can present in a Teams meeting. **Note:** Organizers and co-organizers can change this setting when the meeting is set up. Rationale Ensuring that only authorized individuals are able to present reduces the risk that a malicious user can inadvertently show content that is not appropriate. Impact Only organizers and co-organizers will be able to present without being granted permission. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Teams admin center` https://admin.teams.microsoft.com. 2. Click to expand `Meetings` select `Meeting policies`. 3. Click `Global (Org-wide default)`. 3. Under content sharing set `Who can present` to `Only organizers and co-organizers`. **To remediate using PowerShell:** 1. Connect to Teams PowerShell using `Connect-MicrosoftTeams`. 2. Run the following command to set the recommended state: ``` Set-CsTeamsMeetingPolicy -Identity Global -DesignatedPresenterRoleMode OrganizerOnlyUserOverride ``` Associated Items
Affected Objects More Information TEST ID
LINK
https://learn.microsoft.com/en-US/microsoftteams/meeting-who-present-request-control https://learn.microsoft.com/en-us/microsoftteams/meeting-who-present-request-control#manage-who-can-present https://learn.microsoft.com/en-us/defender-office-365/step-by-step-guides/reducing-attack-surface-in-microsoft-teams?view=o365-worldwide#configure-meeting-settings-restrict-presenters https://learn.microsoft.com/en-us/powershell/module/skype/set-csteamsmeetingpolicy?view=skype-ps
|
| 8.5.7 | Ensure external participants cant give or request control | High | Status:Not Restricted | Off (False) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure external participants cant give or request control Description This policy setting allows control of who can present in meetings and who can request control of the presentation while a meeting is underway. Rationale Ensuring that only authorized individuals and not external participants are able to present and request control reduces the risk that a malicious user can inadvertently show content that is not appropriate. External participants are categorized as follows: external users, guests, and anonymous users. Impact External participants will not be able to present or request control during the meeting. **Warning:** This setting also affects webinars. **Note:** At this time, to give and take control of shared content during a meeting, both parties must be using the Teams desktop client. Control isn't supported when either party is running Teams in a browser. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Teams admin center` https://admin.teams.microsoft.com. 2. Click to expand `Meetings` select `Meeting policies`. 3. Click `Global (Org-wide default)`. 4. Under content sharing set `External participants can give or request control` to `Off`. **To remediate using PowerShell:** 1. Connect to Teams PowerShell using `Connect-MicrosoftTeams`. 2. Run the following command to set the recommended state: ``` Set-CsTeamsMeetingPolicy -Identity Global -AllowExternalParticipantGiveRequestControl $false ``` Associated Items
Affected Objects |
| 8.5.8 | Ensure external meeting chat is off | High | Status:Not Restricted | On(True) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure external meeting chat is off Description This meeting policy setting controls whether users can read or write messages in external meeting chats with untrusted organizations. If an external organization is on the list of trusted organizations this setting will be ignored. Rationale Restricting access to chat in meetings hosted by external organizations limits the opportunity for an exploit like GIFShell or DarkGate malware from being delivered to users. Impact When joining external meetings users will be unable to read or write chat messages in Teams meetings with organizations that they don't have a trust relationship with. This will completely remove the chat functionality in meetings. From an I.T. perspective both the upkeep of adding new organizations to the trusted list and the decision-making process behind whether to trust or not trust an external partner will increase time expenditure. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Teams admin center` https://admin.teams.microsoft.com. 2. Click to expand `Meetings` select `Meeting policies`. 3. Click `Global (Org-wide default)`. 4. Under meeting engagement set `External meeting chat` to `Off`. **To remediate using PowerShell:** 1. Connect to Teams PowerShell using `Connect-MicrosoftTeams`. 2. Run the following command to set the recommended state: ``` Set-CsTeamsMeetingPolicy -Identity Global -AllowExternalNonTrustedMeetingChat $false ``` Associated Items
Affected Objects
More Information TEST ID
|
| 8.5.9 | Ensure meeting recording is off by default | High | Status:Not Restricted | On (True) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure meeting recording is off by default Description This setting controls the ability for a user to initiate a recording of a meeting in progress. The recommended state is `Off` for the `Global (Org-wide default)` meeting policy. Rationale Disabling meeting recordings in the Global meeting policy ensures that only authorized users, such as organizers, co-organizers, and leads, can initiate a recording. This measure helps safeguard sensitive information by preventing unauthorized individuals from capturing and potentially sharing meeting content. Restricting recording capabilities to specific roles allows organizations to exercise greater control over what is recorded, aligning it with the meeting's confidentiality requirements. **Note:** Creating a separate policy for users or groups who are allowed to record is expected and in compliance. This control is only for the default meeting policy. Impact If there are no additional policies allowing anyone to record, then recording will effectively be disabled. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Teams admin center` https://admin.teams.microsoft.com. 2. Click to expand `Meetings` select `Meeting policies`. 3. Click `Global (Org-wide default)`. 4. Under **Recording & transcription** set `Meeting recording` to `Off`. **To remediate using PowerShell:** 1. Connect to Teams PowerShell using `Connect-MicrosoftTeams`. 2. Run the following command to set the recommended state: ``` Set-CsTeamsMeetingPolicy -Identity Global -AllowCloudRecording $false ``` Associated Items
Affected Objects
More Information TEST ID
|
| 8.5.2 | Ensure anonymous users and dial-in callers cant start a meeting | Passed | Status:Restricted | Off (False) | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
X TEST NAME Ensure anonymous users and dial-in callers cant start a meeting Description This policy setting controls if an anonymous participant can start a Microsoft Teams meeting without someone in attendance. Anonymous users and dial-in callers must wait in the lobby until the meeting is started by someone in the organization or an external user from a trusted organization. Anonymous participants are classified as: - Participants who are not logged in to Teams with a work or school account. - Participants from non-trusted organizations (as configured in external access). - Participants from organizations where there is not mutual trust. **Note:** This setting only applies when `Who can bypass the lobby` is set to `Everyone`. If the `anonymous users can join a meeting` organization-level setting or meeting policy is `Off`, this setting only applies to dial-in callers. Rationale Not allowing anonymous participants to automatically join a meeting reduces the risk of meeting spamming. Impact Anonymous participants will not be able to start a Microsoft Teams meeting. Recommendation and Steps Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 8.6.1 | Ensure users can report security concerns in Teams | High | Status:Cannot Report | On (`True`) Report message destination: `Microsoft Only` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure users can report security concerns in Teams Description User reporting settings allow a user to report a message as malicious for further analysis. This recommendation is composed of 3 different settings and all be configured to pass: - **In the Teams admin center:** On by default and controls whether users are able to report messages from Teams. When this setting is turned off, users can't report messages within Teams, so the corresponding setting in the Microsoft 365 Defender portal is irrelevant. - **In the Microsoft 365 Defender portal:** On by default for new tenants. Existing tenants need to enable it. If user reporting of messages is turned on in the Teams admin center, it also needs to be turned on the Defender portal for user reported messages to show up correctly on the User reported tab on the Submissions page. - **Defender - Report message destinations:** This applies to more than just Microsoft Teams and allows for an organization to keep their reports contained. Due to how the parameters are configured on the backend it is included in this assessment as a requirement. Rationale Users will be able to more quickly and systematically alert administrators of suspicious malicious messages within Teams. The content of these messages may be sensitive in nature and therefore should be kept within the organization and not shared with Microsoft without first consulting company policy. **Note:** - The reported message remains visible to the user in the Teams client. - Users can report the same message multiple times. - The message sender isn't notified that messages were reported. Impact Enabling message reporting has an impact beyond just addressing security concerns. When users of the platform report a message, the content could include messages that are threatening or harassing in nature, possibly stemming from colleagues. Due to this the security staff responsible for reviewing and acting on these reports should be equipped with the skills to discern and appropriately direct such messages to the relevant departments, such as Human Resources (HR). Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Teams admin center` https://admin.teams.microsoft.com. 2. Click to expand `Messaging` select `Messaging policies`. 3. Click `Global (Org-wide default)`. 4. Set `Report a security concern` to `On`. 5. Next, navigate to `Microsoft 365 Defender` https://security.microsoft.com/ 6. Click on `Settings` > `Email & collaboration` > `User reported settings`. 7. Scroll to `Microsoft Teams`. 8. Check `Monitor reported messages in Microsoft Teams` and `Save`. 9. Set `Send reported messages to:` to `My reporting mailbox only` with reports configured to be sent to authorized staff. **To remediate using PowerShell:** 1. Connect to Teams PowerShell using `Connect-MicrosoftTeams`. 2. Connect to Exchange Online PowerShell using `Connect-ExchangeOnline`. 3. Run the following cmdlet: ``` Set-CsTeamsMessagingPolicy -Identity Global -AllowSecurityEndUserReporting $true ``` 4. To configure the Defender reporting policies, edit and run this script: ``` $usersub = [email protected] # Change this. $params = @{ Identity = DefaultReportSubmissionPolicy EnableReportToMicrosoft = $false ReportChatMessageEnabled = $false ReportChatMessageToCustomizedAddressEnabled = $true ReportJunkToCustomizedAddress = $true ReportNotJunkToCustomizedAddress = $true ReportPhishToCustomizedAddress = $true ReportJunkAddresses = $usersub ReportNotJunkAddresses = $usersub ReportPhishAddresses = $usersub } Set-ReportSubmissionPolicy @params New-ReportSubmissionRule -Name DefaultReportSubmissionRule -ReportSubmissionPolicy DefaultReportSubmissionPolicy -SentTo $usersub ``` Associated Items
Affected Objects More Information TEST ID
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? | |||||||
| Not Available | Ensure Microsoft Teams Users Allowed to Invite Anonymous Users is disabled | High | Status:Enabled | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Microsoft Teams Users Allowed to Invite Anonymous Users is disabled Description Rationale Impact Microsoft Teams by default enables and allows anonymous users to join Teams meetings. This finding returns the users within the Tenant that have the ability to invite anonymous users into the Teams environment. Some organizations may wish to disable this functionality, or restrict certain users, members, or roles from allowing anonymous users to join meetings. Changing these settings may have unintended consequences. Speak with shareholders and understand what functionality may be affected before disabling this access. Recommendation and Steps This can be mitigated by navigating to the Teams admin center and turning off 'Anonymous users can join a meeting' under Meeting settings. This disables anonymous access globally. Alternatively, specific users and groups can be targeted by creating a new Meeting Policy and issuing the listed command in PowerShell. Associated Items
Affected Objects | ||||||
| Not Available | Ensure Microsoft Teams Policies Allow Anonymous Members is disabled | High | Status:Enabled | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Microsoft Teams Policies Allow Anonymous Members is disabled Description Rationale Impact Microsoft Teams by default enables and allows authenticated users to invite anonymous users to join Teams meetings. Some organizations may wish to disable this functionality, or restrict certain users, members, or roles from allowing anonymous users to join meetings. Changing these settings may have unintended consequences. Speak with shareholders and understand what functionality may be affected before disabling this access. Recommendation and Steps This can be mitigated by navigating to the Teams admin center and turning off 'Anonymous users can join a meeting' under Meeting settings. This disables anonymous access globally. Alternatively, specific users and groups can be targeted by creating a new Meeting Policy and issuing the listed command in PowerShell. Associated Items
Affected Objects | ||||||
| Not Available | Ensure Microsoft Teams Consumer Communication Policies are configured | High | Status:Not Configured | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Microsoft Teams Consumer Communication Policies are configured Description Rationale Impact Microsoft Teams External Access Policies allow communication with Teams users not managed by an organization. Recommendation and Steps Review Microsoft Teams External Access Policies and validate that all results are expected, and no conflicting rules are in place. Associated Items
Affected Objects More Information TEST ID
| ||||||
| Not Available | Ensure Microsoft Teams Users Allowed to Preview Links in Messages is disabled | High | AllowUrlPreviews Configured in Total Teams Policies:4 | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Microsoft Teams Users Allowed to Preview Links in Messages is disabled Description Rationale Impact Microsoft Teams by default enables and allows users to preview links in messages. Some organizations may wish to disable this functionality. Changing these settings may have unintended consequences. Speak with stakeholders and understand what functionality may be affected before disabling this access. Recommendation and Steps This can be mitigated by navigating to the Teams admin center and turning off 'Allow URL Previews' under Messaging settings. This disables link previews globally. Alternatively, specific users and groups can be targeted by creating a new Messaging Policy and issuing the listed command in PowerShell. Associated Items
Affected Objects | ||||||
| Not Available | Ensure Safe Links for Teams is Enabled | High | Status:Not Configured - No ATP License | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Safe Links for Teams is Enabled Description Rationale Impact Safe Links is a feature of O365 that enables real-time detection of malicious links in incoming Exchange emails and other Office 365 applications. The Safe Links feature can also be enabled for links shared via Microsoft Teams. However, this setting is disabled in the 365 instance. Enabling it can decrease the risk of phishing and other attacks that might utilize malicious links sent via Teams, although it is not a panacea for these attacks. Recommendation and Steps Perhaps the most convenient way to enable this feature is to use the Set-SafeLinksPolicy command in PowerShell as listed below. Note that some organizations may have chosen to disable Safe Links for Teams if it interferes with day-to-day operations, so key stakeholders should be surveyed before enabling Safe Links for Teams. Associated Items
Affected Objects | ||||||
| Not Available | Ensure Microsoft Teams External Domain Communication Policies are configured | Medium | Domains Allowed Status:All Domains Allowed | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Microsoft Teams External Domain Communication Policies are configured Description Rationale Impact Microsoft Teams External Domain Communication Policies. Recommendation and Steps Review Microsoft Teams External Access Policies and validate that all results are expected, and no conflicting rules are in place. Associated Items
Affected Objects More Information TEST ID
| ||||||
| Not Available | Ensure Microsoft Teams External Access Policies are configured | Low | Status:Not Configured:EnableFederationAccess is set to True | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Microsoft Teams External Access Policies are configured Description Rationale Impact Microsoft Teams External Access Policies. Recommendation and Steps Review Microsoft Teams External Access Policies and validate that all results are expected, and no conflicting rules are in place. Associated Items
Affected Objects More Information TEST ID
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 9.1.1 | Ensure guest user access is restricted | High | Status:Not Restricted: 10dae51f-b6af-4016-8d66-8c2a99b929b3 | Enabled for Entire Organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure guest user access is restricted Description This setting allows business-to-business (B2B) guests access to Microsoft Fabric, and contents that they have permissions to. With the setting turned off, B2B guest users receive an error when trying to access Power BI. The recommended state is `Enabled for a subset of the organization` or `Disabled`. Rationale Establishing and enforcing a dedicated security group prevents unauthorized access to Microsoft Fabric for guests collaborating in Azure that are new or assigned guest status from other applications. This upholds the principle of least privilege and uses role-based access control (RBAC). These security groups can also be used for tasks like conditional access, enhancing risk management and user accountability across the organization. Impact Security groups will need to be more closely tended to and monitored. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Fabric` https://app.powerbi.com/admin-portal 2. Select `Tenant settings`. 3. Scroll to `Export and Sharing settings`. 4. Set `Guest users can access Microsoft Fabric` to one of these states: - State 1: `Disabled` - State 2: `Enabled` with `Specific security groups` selected and defined. **Important:** If the organization doesn't actively use this feature it is recommended to keep it `Disabled`. Associated Items
Affected Objects More Information TEST ID
|
| 9.1.2 | Ensure external user invitations are restricted | High | Status:Not Restricted: everyone | Enabled for the entire organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure external user invitations are restricted Description This setting helps organizations choose whether new external users can be invited to the organization through Power BI sharing, permissions, and subscription experiences. This setting only controls the ability to invite through Power BI. The recommended state is `Enabled for a subset of the organization` or `Disabled`. **Note:** To invite external users to the organization, the user must also have the Microsoft Entra Guest Inviter role. Rationale Establishing and enforcing a dedicated security group prevents unauthorized access to Microsoft Fabric for guests collaborating in Azure that are new or assigned guest status from other applications. This upholds the principle of least privilege and uses role-based access control (RBAC). These security groups can also be used for tasks like conditional access, enhancing risk management and user accountability across the organization. Impact Guest user invitations will be limited to only specific employees. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Fabric` https://app.powerbi.com/admin-portal 2. Select `Tenant settings`. 3. Scroll to `Export and Sharing settings`. 4. Set `Users can invite guest users to collaborate through item sharing and permissions` to one of these states: - State 1: `Disabled` - State 2: `Enabled` with `Specific security groups` selected and defined. **Important:** If the organization doesn't actively use this feature it is recommended to keep it `Disabled`. Associated Items
Affected Objects |
| 9.1.6 | Ensure Allow users to apply sensitivity labels for content is Enabled | High | Status:Allow users to apply sensitivity labels for content is disabled. | Disabled | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure Allow users to apply sensitivity labels for content is Enabled Description Information protection tenant settings help to protect sensitive information in the Power BI tenant. Allowing and applying sensitivity labels to content ensures that information is only seen and accessed by the appropriate users. The recommended state is `Enabled` or `Enabled for a subset of the organization`. **Note:** Sensitivity labels and protection are only applied to files exported to Excel, PowerPoint, or PDF files, that are controlled by Export to Excel and Export reports as PowerPoint presentation or PDF documents settings. All other export and sharing options do not support the application of sensitivity labels and protection. **Note 2:** There are some prerequisite steps that need to be completed in order to fully utilize labeling. See [here](https://learn.microsoft.com/en-us/power-bi/enterprise/service-security-enable-data-sensitivity-labels#licensing-and-requirements). Rationale Establishing data classifications and affixing labels to data at creation enables organizations to discern the data's criticality, sensitivity, and value. This initial identification enables the implementation of appropriate protective measures, utilizing technologies like Data Loss Prevention (DLP) to avert inadvertent exposure and enforcing access controls to safeguard against unauthorized access. This practice can also promote user awareness and responsibility in regard to the nature of the data they interact with. Which in turn can foster awareness in other areas of data management across the organization. Impact Additional license requirements like Power BI Pro are required, as outlined in the Licensed and requirements page linked in the description and references sections. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Fabric` https://app.powerbi.com/admin-portal 2. Select `Tenant settings`. 3. Scroll to `Information protection`. 4. Set `Allow users to apply sensitivity labels for content` to one of these states: - State 1: `Enabled` - State 2: `Enabled` with `Specific security groups` selected and defined. Associated Items
Affected Objects More Information TEST ID
LINK
https://learn.microsoft.com/en-us/power-bi/enterprise/service-security-enable-data-sensitivity-labels https://learn.microsoft.com/en-us/fabric/governance/data-loss-prevention-overview https://learn.microsoft.com/en-us/power-bi/enterprise/service-security-enable-data-sensitivity-labels#licensing-and-requirements
|
| 9.1.3 | Ensure guest access to content is restricted | Manual Check | NONE | Disabled | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure guest access to content is restricted Description This setting allows Microsoft Entra B2B guest users to have full access to the browsing experience using the left-hand navigation pane in the organization. Guest users who have been assigned workspace roles or specific item permissions will continue to have those roles and/or permissions, even if this setting is disabled. The recommended state is `Enabled for a subset of the organization` or `Disabled`. Rationale Establishing and enforcing a dedicated security group prevents unauthorized access to Microsoft Fabric for guests collaborating in Entra that are new or assigned guest status from other applications. This upholds the principle of least privilege and uses role-based access control (RBAC). These security groups can also be used for tasks like conditional access, enhancing risk management and user accountability across the organization. Impact Security groups will need to be more closely tended to and monitored. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Fabric` https://app.powerbi.com/admin-portal 2. Select `Tenant settings`. 3. Scroll to `Export and Sharing settings`. 4. Set `Guest users can browse and access Fabric content` to one of these states: - State 1: `Disabled` - State 2: `Enabled` with `Specific security groups` selected and defined. **Important:** If the organization doesn't actively use this feature it is recommended to keep it `Disabled`. Associated Items Affected Objects More Information TEST ID
|
| 9.1.4 | Ensure Publish to web is restricted | Manual Check | NONE | Enabled for the entire organization Only allow existing codes | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure Publish to web is restricted Description Power BI enables users to share reports and materials directly on the internet from both the application's desktop version and its web user interface. This functionality generates a publicly reachable web link that doesn't necessitate authentication or the need to be an Entra ID user in order to access and view it. The recommended state is `Enabled for a subset of the organization` or `Disabled`. Rationale When using Publish to Web anyone on the Internet can view a published report or visual. Viewing requires no authentication. It includes viewing detail-level data that your reports aggregate. By disabling the feature, restricting access to certain users and allowing existing embed codes organizations can mitigate the exposure of confidential or proprietary information. Impact Depending on the organization's utilization administrators may experience more overhead managing embed codes, and requests. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Fabric` https://app.powerbi.com/admin-portal 2. Select `Tenant settings`. 3. Scroll to `Export and Sharing settings`. 4. Set `Publish to web` to one of these states: - State 1: `Disabled` - State 2: `Enabled` with `Choose how embed codes work` set to `Only allow existing codes` **AND** `Specific security groups` selected and defined **Important:** If the organization doesn't actively use this feature it is recommended to keep it `Disabled`. Associated Items Affected Objects |
| 9.1.5 | Ensure Interact with and share R and Python visuals is Disabled | Manual Check | NONE | Enabled | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
X TEST NAME Ensure Interact with and share R and Python visuals is Disabled Description Power BI allows the integration of R and Python scripts directly into visuals. This feature allows data visualizations by incorporating custom calculations, statistical analyses, machine learning models, and more using R or Python scripts. Custom visuals can be created by embedding them directly into Power BI reports. Users can then interact with these visuals and see the results of the custom code within the Power BI interface. Rationale Disabling this feature can reduce the attack surface by preventing potential malicious code execution leading to data breaches, or unauthorized access. The potential for sensitive or confidential data being leaked to unintended users is also increased with the use of scripts. Impact Use of R and Python scripting will require exceptions for developers, along with more stringent code review. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Fabric` https://app.powerbi.com/admin-portal 2. Select `Tenant settings`. 3. Scroll to `R and Python visuals settings`. 4. Set `Interact with and share R and Python visuals` to `Disabled` Associated Items Affected Objects |
| 9.1.7 | Ensure shareable links are restricted | Manual Check | NONE | Enabled for Entire Organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure shareable links are restricted Description Creating a shareable link allows a user to create a link to a report or dashboard, then add that link to an email or another messaging application. There are 3 options that can be selected when creating a shareable link: - People in your organization - People with existing access - Specific people This setting solely deals with restrictions to `People in the organization`. External users by default are not included in any of these categories, and therefore cannot use any of these links regardless of the state of this setting. The recommended state is `Enabled for a subset of the organization` or `Disabled`. Rationale While external users are unable to utilize shareable links, disabling or restricting this feature ensures that a user cannot generate a link accessible by individuals within the same organization who lack the necessary clearance to the shared data. For example, a member of Human Resources intends to share sensitive information with a particular employee or another colleague within their department. The owner would be prompted to specify either `People with existing access` or `Specific people` when generating the link requiring the person clicking the link to pass a first layer access control list. This measure along with proper file and folder permissions can help prevent unintended access and potential information leakage. Impact If the setting is `Enabled` then only specific people in the organization would be allowed to create general links viewable by the entire organization. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Fabric` https://app.powerbi.com/admin-portal 2. Select `Tenant settings`. 3. Scroll to `Export and Sharing settings`. 4. Set `Allow shareable links to grant access to everyone in your organization` to one of these states: - State 1: `Disabled` - State 2: `Enabled` with `Specific security groups` selected and defined. **Important:** If the organization doesn't actively use this feature it is recommended to keep it `Disabled`. Associated Items Affected Objects |
| 9.1.8 | Ensure enabling of external data sharing is restricted | Manual Check | NONE | Enabled for the entire organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure enabling of external data sharing is restricted Description Power BI admins can specify which users or user groups can share datasets externally with guests from a different tenant through the in-place mechanism. Disabling this setting prevents any user from sharing datasets externally by restricting the ability of users to turn on external sharing for datasets they own or manage. The recommended state is `Enabled for a subset of the organization` or `Disabled`. Rationale Establishing and enforcing a dedicated security group prevents unauthorized access to Microsoft Fabric for guests collaborating in Azure that are new or from other applications. This upholds the principle of least privilege and uses role-based access control (RBAC). These security groups can also be used for tasks like conditional access, enhancing risk management and user accountability across the organization. Impact Security groups will need to be more closely tended to and monitored. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Fabric` https://app.powerbi.com/admin-portal 2. Select `Tenant settings`. 3. Scroll to `Export and Sharing settings`. 4. Set `Allow specific users to turn on external data sharing` to one of these states: - State 1: `Disabled` - State 2: `Enabled` with `Specific security groups` selected and defined. **Important:** If the organization doesn't actively use this feature it is recommended to keep it `Disabled`. Associated Items Affected Objects More Information TEST ID
|
| 9.1.9 | Ensure Block ResourceKey Authentication is Enabled | Manual Check | NONE | Disabled for the entire organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure Block ResourceKey Authentication is Enabled Description This setting blocks the use of resource key based authentication. The Block ResourceKey Authentication setting applies to streaming and PUSH datasets. If blocked users will not be allowed to send data to streaming and PUSH datasets using the API with a resource key. The recommended state is `Enabled`. Rationale Resource keys are a form of authentication that allows users to access Power BI resources (such as reports, dashboards, and datasets) without requiring individual user accounts. While convenient, this method bypasses the organization's centralized identity and access management controls. Enabling ensures that access to Power BI resources is tied to the organization's authentication mechanisms, providing a more secure and controlled environment. Impact Developers will need to request a special exception in order to use this feature. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Fabric` https://app.powerbi.com/admin-portal 2. Select `Tenant settings`. 3. Scroll to `Developer settings`. 4. Set `Block ResourceKey Authentication` to `Enabled` Associated Items Affected Objects |
| 9.1.10 | Ensure access to APIs by Service Principals is restricted | Manual Check | NONE | Disabled for the entire organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure access to APIs by Service Principals is restricted Description Web apps registered in Microsoft Entra ID use an assigned service principal to access Power BI APIs without a signed-in user. This setting allows an app to use service principal authentication. The recommended state is `Enabled for a subset of the organization` or `Disabled`. Rationale Leaving API access unrestricted increases the attack surface in the event an adversary gains access to a Service Principal. APIs are a feature-rich method for programmatic access to many areas of Power Bi and should be guarded closely. Impact Disabled is the default behavior. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Fabric` https://app.powerbi.com/admin-portal 2. Select `Tenant settings`. 3. Scroll to `Developer settings`. 4. Set `Service principals can use Fabric APIs` to one of these states: - State 1: `Disabled` - State 2: `Enabled` with `Specific security groups` selected and defined. **Important:** If the organization doesn't actively use this feature it is recommended to keep it `Disabled`. Associated Items Affected Objects More Information TEST ID
|
| 9.1.11 | Ensure Service Principals cannot create and use profiles | Manual Check | NONE | Disabled for the entire organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
X TEST NAME Ensure Service Principals cannot create and use profiles Description Service principal profiles provide a flexible solution for apps used in a multitenancy deployment. The profiles enable customer data isolation and tighter security boundaries between customers that are utilizing the app. The recommended state is `Enabled for a subset of the organization` or `Disabled`. Rationale Service Principals should be restricted to a security group to limit which Service Principals can interact with profiles. This supports the principle of least privilege. Impact Disabled is the default behavior. Recommendation and Steps **To remediate using the UI:** 1. Navigate to `Microsoft Fabric` https://app.powerbi.com/admin-portal 2. Select `Tenant settings`. 3. Scroll to `Developer settings`. 4. Set `Allow service principals to create and use profiles` to one of these states: - State 1: `Disabled` - State 2: `Enabled` with `Specific security groups` selected and defined. **Important:** If the organization doesn't actively use this feature it is recommended to keep it `Disabled`. Associated Items Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Not Available | Ensure Guest Users are reviewed and disabled | Medium | Guest Accounts:15 | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Guest Users are reviewed and disabled Description Rationale Impact Auditing Process needs to be created and followed. There is no impact if the auditing process is created and followed. Recommendation and Steps Guest users can be set up for those users not in your tenant to still be granted access to resources. It is important to maintain visibility for what guest users are established in the tenant. Periodic review of guest users ensures proper access to resources in your tenant. To verify the report is being reviewed at least biweekly, confirm that the necessary procedures are in place and being followed. Associated Items
Affected Objects
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Not Available | Ensure Microsoft 365 Exchange Online Privileged Access Management is Used | High | Status:Not Enabled | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Microsoft 365 Exchange Online Privileged Access Management is Used Description Rationale Impact Role-Based Access Control (RBAC): PAM enables organizations to define and control which users can access certain privileged roles and resources. By using a least-privilege model, it helps reduce the surface area for potential attacks. Time-Limited Access: With PAM, you can ensure that privileged roles are only granted for a limited amount of time. This just-in-time (JIT) access prevents users from holding unnecessary privileges for extended periods. Approval Workflow: Privileged access can be controlled through an approval process. Access requests can be reviewed and authorized by designated approvers before they are granted. Audit Logs and Monitoring: PAM provides detailed audit logs that track who accessed privileged roles, when, and for what purpose. These logs are essential for compliance, troubleshooting, and auditing. Access Reviews and Recertification: Regular access reviews help ensure that only the necessary people have privileged access to sensitive systems. Recommendation and Steps Before enabling Microsoft 365 PAM, make sure you meet the following requirements: -Azure AD Premium P2 license is required for using Privileged Identity Management (PIM), which is part of PAM. -You need to be a Global Administrator or have the Privileged Role Administrator role to configure PAM settings. -Ensure that Multi-Factor Authentication (MFA) is enabled for your organization for added security. Azure AD PIM is the core component of PAM. To enable PIM: -In the Azure AD pane, navigate to Security. - Under Security, select Privileged Identity Management (PIM). -On the PIM Dashboard page, if it is your first time enabling PIM, you will see a Get started option. Click on Start to begin configuring PAM. -Enable PIM for your directory: Click on Enable to activate PIM (if it isn't already enabled). 4. Configure Just-in-Time (JIT) Access for Privileged Roles Once PIM is enabled, you can configure just-in-time (JIT) access to grant time-limited access to privileged roles. Here's how you do it: -In the PIM dashboard, select Azure AD roles. -Click on Roles under Manage and choose the role that you want to configure for JIT access (such as Global Administrator, Security Administrator, etc.). -Click Settings on the role, and under Role Settings, you will find options to enable JIT and set the duration for access (e.g., 1 hour, 8 hours, etc.). -Enable the JIT access toggle and configure additional settings, such as approval workflows and MFA requirements. 5. Configure Approval Workflow for Role Assignments You can configure approval workflows to require that an admin or another designated approver confirms privileged access requests. To enable this: -Under Role Settings for the role, locate the Approval section. -Toggle the approval option to Require approval to activate the role. -Select who should be the approver (e.g., another administrator or a group of users). -Configure additional settings like whether to require MFA before access is granted. 6. Set Up Access Reviews To periodically review who has access to privileged roles and ensure they still need access, you can enable Access Reviews: -In the PIM dashboard, select Azure AD roles > Access reviews. -Click + New review to start a new access review. -Select the role to review, define the review schedule (e.g., quarterly or annually), and assign reviewers (e.g., the role's managers or group owners). -Configure notifications and set up how access will be reviewed (whether to automatically remove or notify users). Associated Items
Affected Objects |
| Not Available | Ensure Microsoft 365 User Roles have less than 10 Admins | Passed | Total Number of Roles having more than 10 Admins:0 | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Microsoft 365 User Roles have less than 10 Admins Description Rationale Impact Refer issue details. Recommendation and Steps Associated Items
Affected Objects
|
| Not Available | Ensure Microsoft 365 Users Have Strong Password Requirements Configured | Passed | Users With Weak Password Requirements:0 | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Microsoft 365 Users Have Strong Password Requirements Configured Description Rationale Impact Users can use Weak passwords which is a security risk. Recommendation and Steps Associated Items
Affected Objects
|
| Not Available | Ensure self-service password reset is enabled | Passed | Status:Enabled | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure self-service password reset is enabled Description Rationale Impact The impact associated with this setting is that users will be required to provide additional contact information to enroll in self-service password reset. Additionally, minor user education may be required for users that are used to calling a help desk for assistance with password resets. As of August of 2020 combined registration is automatic for new tenants therefore users will not need to register for password reset separately from multi-factor authentication. Recommendation and Steps Associated Items
Affected Objects |
| Not Available | Ensure Microsoft 365 Exchange Online Modern Authentication is Used | Passed | Status:Enabled | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Microsoft 365 Exchange Online Modern Authentication is Used Description Rationale Impact Newer clients will not be able to use Modern Authentication feature of Microsoft 365 causing multiple logon prompts. Recommendation and Steps Associated Items
Affected Objects |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Not Available | Ensure Microsoft 365 Users Have Changed Passwords | High | Passwords unchanged since 90 days:17849 | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Microsoft 365 Users Have Changed Passwords Description Rationale Impact It is a security risk. Every user in Microsoft 365 Users must change their passwords within 90 days. Recommendation and Steps Please identify these users and make sure they change their passwords. Associated Items
Affected Objects |
| Not Available | Ensure All Microsoft 365 Users are licensed | Medium | Users Not Licensed:17835 | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure All Microsoft 365 Users are licensed Description Rationale Impact Unlicensed users will not be able to use Microsoft 365 Services. Recommendation and Steps It is recommended to assign Licenses to users. Associated Items
Affected Objects |
| Not Available | Ensure Microsoft 365 Users Password Expires | Medium | Password Never Expires Set:0 | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Microsoft 365 Users Password Expires Description Rationale Impact These users can remain with a single password and if the password is compromised anyone can access Microsoft 365 Services. Recommendation and Steps Every user in Microsoft 365 must change their password according to Password Policies. Associated Items
Affected Objects |
| Not Available | Ensure Microsoft 365 Groups Without Members are Identified | Low | Groups Without Members:118 | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Microsoft 365 Groups Without Members are Identified Description Rationale Impact If these Groups were created for some reason, then they should have members in it. Recommendation and Steps Please review the list of Groups provided by the test and add users or remove these groups. Associated Items
Affected Objects
|
| Not Available | Ensure Deleted Microsoft 365 Users are Identified | Passed | Deleted Users:0 | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Deleted Microsoft 365 Users are Identified Description Rationale Impact These user accounts get deleted from Microsoft 365 Recycle Bin after some time. Recommendation and Steps Associated Items
Affected Objects
|
| Not Available | Ensure Disabled Microsoft 365 Users are Identified | Passed | Disabled Users:3031 | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Disabled Microsoft 365 Users are Identified Description Rationale Impact Disabled users cannot use Microsoft 365 Services. Recommendation and Steps Associated Items
Affected Objects |
| Not Available | Ensure Microsoft 365 Blocked Users are Identified | Passed | Microsoft 365 Users Blocked:0 | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Microsoft 365 Blocked Users are Identified Description Rationale Impact Blocked Users will not be able to sign in to use Microsoft 365 Services. Recommendation and Steps Associated Items
Affected Objects
|
| Not Available | Ensure Microsoft 365 Company Administrators have less than 5 Admins | Passed | More Than 5 Company Administrators Status:0 | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Microsoft 365 Company Administrators have less than 5 Admins Description Rationale Impact More users can have full control over Microsoft 365 Services. Recommendation and Steps Associated Items
Affected Objects |
| Not Available | Ensure Microsoft 365 Deleted and Licensed Users are Identified | Passed | Deleted Users Licensed:0 | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Microsoft 365 Deleted and Licensed Users are Identified Description Rationale Impact Increase in licenses cost. Recommendation and Steps Associated Items
Affected Objects
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Not Available | Ensure Users can create security groups is disabled | High | Status:Enabled-Not Ok | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Users can create security groups is disabled Description Rationale Impact Disabling the Ensure Users can create security groups setting prevents non-admin users from creating security groups in Azure AD, which enhances security by reducing the risk of unauthorized or improperly configured groups. It may impact user flexibility if certain departments or teams require the ability to create and manage their own groups. The administrative overhead increases, as admins will need to create groups on behalf of users. This can also help maintain a more organized and controlled directory structure. Recommendation and Steps Assess whether non-admin users truly need the ability to create security groups and consider enabling it only for specific roles. Use role-based access control (RBAC) to grant permissions to trusted users or groups to create security groups. Implement clear processes for users to request group creation. Ensure admins are adequately equipped to handle group requests in a timely manner and monitor for any potential gaps in access control. Associated Items Affected Objects More Information TEST ID
|
| Not Available | Ensure Users with a verified mail domain can join the tenant is disabled | High | Permission Status:Enabled-Not Ok | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Users with a verified mail domain can join the tenant is disabled Description Rationale Impact It prevents users with email addresses from unapproved or unverified domains from joining the Azure AD tenant. This enhances security by ensuring that only trusted, verified email domains can be used for account creation. However, it may limit the ability for external collaborators or users from certain organizations to join the tenant. This setting helps maintain tighter control over who can access organizational resources. Recommendation and Steps Ensure that only trusted and necessary email domains are verified for user access. Consider enabling this setting for specific external partners if collaboration with them is needed. Regularly review and update the list of verified domains to ensure compliance with organizational policies. Communicate the policy to users to avoid confusion for those attempting to join with unverified email domains. Associated Items Affected Objects More Information TEST ID
|
| Not Available | Ensure Guests can invite other guests into the tenant is disabled | High | Permission Status:Enabled-Not Ok | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Guests can invite other guests into the tenant is disabled Description Rationale Impact Dangerous default configuration settings were found in the Tenant. By default, Azure tenants allow all users to access the Azure Active Directory blade, to read all other users' accounts, create groups, and invite guests. These default settings extend to guest accounts as well, allowing guests to perform these same actions. Other default configurations allow for Self-Service creation of accounts from accepted mail domains. Recommendation and Steps The excessive user permissions can be mitigated by running the listed PowerShell commands as a Global Admin. User access to the Azure AD blade can be restricted by navigating to the Azure Active Directory blade; User Settings and toggling the 'Restrict access to Azure AD administration portal' to Yes. Guest invites may be restricted by navigating to the Azure Active Directory blade; External Identities; External Collaboration Settings, or by going to the Azure Active Directory blade; User Settings; Manage external collaboration settings and toggling 'Members can invite' and 'Guests can invite' to No. Associated Items Affected Objects More Information TEST ID
|
| Not Available | Ensure Users are allowed to create new Azure Active Directory Tenants is disabled | High | Permission Status:Enabled-Not Ok | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Users are allowed to create new Azure Active Directory Tenants is disabled Description Rationale Impact Dangerous default configuration settings were found in the Tenant. By default, Azure tenants allow all users to access the Azure Active Directory blade, to read all other users' accounts, create groups, and invite guests. These default settings extend to guest accounts as well, allowing guests to perform these same actions. Other default configurations allow for Self-Service creation of accounts from accepted mail domains. Recommendation and Steps The excessive user permissions can be mitigated by running the listed PowerShell commands as a Global Admin. User access to the Azure AD blade can be restricted by navigating to the Azure Active Directory blade; User Settings and toggling the 'Restrict access to Azure AD administration portal' to Yes. Guest invites may be restricted by navigating to the Azure Active Directory blade; External Identities; External Collaboration Settings, or by going to the Azure Active Directory blade; User Settings; Manage external collaboration settings and toggling 'Members can invite' and 'Guests can invite' to No. Associated Items Affected Objects More Information TEST ID
|
| Not Available | Ensure Policy exists to restrict non-administrator access to Azure Active Directory or Entra | High | Permission Status:No Policy Found | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Policy exists to restrict non-administrator access to Azure Active Directory or Entra Description Rationale Impact Restrict non-privileged users from signing into the Azure Active Directory portal. Note: This recommendation only affects access to the Azure AD web portal. It does not prevent privileged users from using other methods such as Rest API or PowerShell to obtain information. Those channels are addressed elsewhere in this document. The Azure AD administrative (AAD) portal contains sensitive data and permission settings, which are still enforced based on the users role. However, an end user may inadvertently change properties or account settings that could result in increased administrative overhead. Additionally, a compromised end user account could be used by a malicious attacker as a means to gather additional information and escalate an attack. Note: Users will still be able to sign into Azure Active directory admin center but will be unable to see directory information. Recommendation and Steps Ensure access to the Azure AD portal is restricted: 1. Navigate to Microsoft Entra admin center https://entra.microsoft.com/ 2. Click to expand Identity> Users > User settings. 3. Set Restrict access to Microsoft Entra ID administration portal to Yes then Save. Associated Items Affected Objects More Information TEST ID
|
| Not Available | Ensure Users can read all attributes in Azure AD is disabled | Medium | Permission Status:Enabled-Not Ok | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Users can read all attributes in Azure AD is disabled Description Rationale Impact Disabling this setting restricts users' access to certain directory attributes, enhancing security by limiting exposure to sensitive information. It may affect user experience if essential attributes are inaccessible. This setting can improve compliance with data protection regulations by minimizing access to personal data. Admins have more control over which attributes are visible to users. Recommendation and Steps Evaluate the necessity of user access to specific attributes before disabling this setting. Apply granular access controls to ensure only authorized users can view sensitive data. Test the changes with a small user group and gather feedback. Ensure clear communication about the policy and monitor access logs for potential issues. Associated Items Affected Objects More Information TEST ID
|
| Not Available | Ensure Users are allowed to create and register applications is disabled | Passed | Permission Status:Disabled-Ok | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Users are allowed to create and register applications is disabled Description Rationale Impact The test when implemented restricts non-admin users from registering and managing applications in Azure AD, improving security by preventing unauthorized app registrations. It can impact developers or teams who require the ability to create and test their own applications. This setting helps maintain centralized control over the applications integrated with Azure AD, ensuring that only trusted users can register and manage apps. Recommendation and Steps Associated Items Affected Objects More Information TEST ID
|
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Not Available | Ensure Microsoft 365 Licenses are consumed in SKUs | High | SKUs Not In Use:1 | N/A | N/A | SP v1.0 | NO |
X TEST NAME Ensure Microsoft 365 Licenses are consumed in SKUs Description Rationale Impact Microsoft 365 Services are being charged for SKUs which are not in use. Recommendation and Steps Please review the SKU list and make sure users are licensed from unused SKUs. Associated Items
Affected Objects
|
| Not Available | Ensure All Microsoft 365 Domains Have been verified | Passed | Domains Verification Pending:0 | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure All Microsoft 365 Domains Have been verified Description Rationale Impact Unverified domains will not be able to participate in Microsoft 365 Services. Recommendation and Steps Associated Items
Affected Objects |
| Not Available | Ensure Microsoft 365 Domain Services Have Services Assigned | Passed | Domains Without Services:0 | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Microsoft 365 Domain Services Have Services Assigned Description Rationale Impact Refer issue details. Recommendation and Steps Associated Items
Affected Objects |
| Not Available | Ensure Microsoft 365 Notification Email is configured | Passed | Notifications Email: | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Microsoft 365 Notification Email is configured Description Rationale Impact You will not receive any technical email notification from Microsoft. Recommendation and Steps Associated Items
Affected Objects |
| Not Available | Ensure Microsoft 365 Organization Level Mailbox Auditing is configured | Passed | Status:Enabled | N/A | N/A | SP v1.0 | YES |
X TEST NAME Ensure Microsoft 365 Organization Level Mailbox Auditing is configured Description Rationale Impact Refer issue details. Recommendation and Steps Associated Items
Affected Objects |
#TABLE_Microsoft-365-admin-center-Users1#TABLE_Microsoft-365-admin-center-Teams-groups2#TABLE_Microsoft-365-admin-center-Settings3#TABLE_Microsoft-365-Defender-Email-collaboration4#TABLE_Microsoft-365-Defender-Cloud-Apps5#TABLE_Microsoft-365-Defender-Audit6#TABLE_Microsoft-Purview-Audit7#TABLE_Microsoft-Purview-Data-Loss-Protection8#TABLE_Microsoft-Purview-Information-Protection9#TABLE_Microsoft-Entra-admin-center-Identity-Overview10#TABLE_Microsoft-Entra-admin-center-Identity-Users11#TABLE_Microsoft-Entra-admin-center-Identity-Groups12#TABLE_Microsoft-Entra-admin-center-Identity-Applications13#TABLE_Microsoft-Entra-admin-center-Identity-External-Identities14#TABLE_Microsoft-Entra-admin-center-Identity-Hybrid-Management15#TABLE_Microsoft-Entra-admin-center-Protection-Conditional-Access16#TABLE_Microsoft-Entra-admin-center-Protection-Authentication-Methods17#TABLE_Microsoft-Entra-admin-center-Protection-Password-Reset18#TABLE_Microsoft-Entra-admin-center-Protection-Risk-Activities19#TABLE_Microsoft-Entra-admin-center-Identity-Governance20#TABLE_Microsoft-Exchange-admin-center-Audit21#TABLE_Microsoft-Exchange-admin-center-Mailflow22#TABLE_Microsoft-Exchange-admin-center-Roles23#TABLE_Microsoft-Exchange-admin-center-Settings24#TABLE_Microsoft-Exchange-admin-center-Reports25#TABLE_Microsoft-SharePoint-Admin-Center-Policies26#TABLE_Microsoft-SharePoint-Admin-Center-Settings27#TABLE_Microsoft-Teams-Admin-Center-Teams28#TABLE_Microsoft-Teams-Admin-Center-Users29#TABLE_Microsoft-Teams-Admin-Center-Teams-Apps30#TABLE_Microsoft-Teams-Admin-Center-Meetings31#TABLE_Microsoft-Teams-Admin-Center-Messaging32#TABLE_Microsoft-Teams-Admin-Center-Policies33#TABLE_Microsoft-Fabric-Tenant-Settings34#TABLE_M365-Admin-Center-Users35#TABLE_M365-Admin-Center-Accounts-and-Authentication36#TABLE_M365-Admin-Center-Auditing37#TABLE_Microsoft-M365-Users-Users38#TABLE_Microsoft-M365-Dangerous-Defaults39#TABLE_Microsoft-M365-Configuration40
All Tests Table
Assessment Table satus contains status for both CIS Benchmark and Internal Tests.
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Not Available | SharePoint External Sharing is not Enabled at Global Level | Critical | Status:Enabled - : Sharing capability is ExternalUserAndGuestSharing (Anyone). | N/A | N/A | OP 1.0 | NO |
| Not Available | SharePoint External User Resharing is not Permitted | Critical | Status:Permitted | N/A | N/A | OP 1.0 | NO |
| Not Available | SharePoint Legacy Authentication is not Enabled | Critical | Status:Enabled | N/A | N/A | OP 1.0 | NO |
| 1.3.2 | Ensure Idle session timeout is set to 3 hours (or less) for unmanaged devices | High | Idle Timeout Status:1 | Not configured. (Idle sessions will not timeout.) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 1.3.3 | Ensure External sharing of calendars is not available | High | Status:Enabled | Enabled (True) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 1.3.7 | Ensure third-party storage services are restricted in Microsoft 365 on the web | High | Status:Not Restricted | Enabled - Users are able to open files stored in third-party storage services | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 2.1.1 | Ensure Safe Links for Office Applications is Enabled | High | Status:Not Enabled | N/A | E5 Level 2 | CIS v6.0 | NO |
| 2.1.2 | Ensure the Common Attachment Types Filter is enabled | High | Status:Not Enabled | Always on | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 2.1.3 | Ensure notifications for internal users sending malware is Enabled | High | Status:Not Enabled | ``` EnableInternalSenderAdminNotifications : False InternalSenderAdminAddress : $null ``` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 2.1.6 | Ensure Exchange Online Spam Policies are set correctly | High | Status:Not Enabled | ``` BccSuspiciousOutboundAdditionalRecipients : {} BccSuspiciousOutboundMail : False NotifyOutboundSpamRecipients : {} NotifyOutboundSpam : False ``` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 2.1.9 | Ensure that DKIM is enabled for all Exchange Online Domains | High | Domains Missing DKIM:3 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 2.1.10 | Ensure DMARC Records for all Exchange Online domains are published | High | Missing Domains for DMARC Records:5 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 2.1.11 | Ensure comprehensive attachment filtering is applied | High | Status:Not Configured Correctly | The following extensions are blocked by default: ace, ani, apk, app, appx, arj, bat, cab, cmd, com, deb, dex, dll, docm, elf, exe, hta, img, iso, jar, jnlp, kext, lha, lib, library, lnk, lzh, macho, msc, msi, msix, msp, mst, pif, ppa, ppam, reg, rev, scf, scr, sct, sys, uif, vb, vbe, vbs, vxd, wsc, wsf, wsh, xll, xz, z | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 2.4.1 | Ensure Priority account protection is enabled and configured | High | Priority Account Status:Not Enabled-Not Implemented | By default, priority accounts are undefined. | E5 Level 1 | CIS v6.0 | NO |
| Not Available | Ensure user role group changes are reviewed and actioned | High | Status:There are user role group changes found in past 7 days | N/A | N/A | OP 1.0 | NO |
| 3.2.1 | Ensure DLP policies are enabled | High | Status:The DLP Policy is NOT Enabled | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 3.2.2 | Ensure DLP policies are enabled for Microsoft Teams | High | Status:No DLP Policy Found | Enabled (On) | E5 Level 1 | CIS v6.0 | NO |
| Not Available | Ensure DLP Policy is enabled for OneDrive | High | Status:Not Enabled | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure DLP Policy is configured for SharePoint | High | Status:Not Enabled | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Custom Anti-Malware Policy is Present | High | Status:Not Defined | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Custom Anti-Phishing Policy is Present | High | Status:Not Defined | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Custom DLP Policies are Present | High | Status:Not Defined-Not Implemented | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Custom DLP Sensitive Information Types are Defined | High | Status:Not Defined-Not Implemented | N/A | N/A | OP 1.0 | NO |
| 4.1 | Ensure devices without a compliance policy are marked not compliant | High | Compliance Policy Default Behavior:1 | UI: Compliant Graph: secureByDefault = $false | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 5.1.2.3 | Ensure Restrict non-admin users from creating tenants is set to Yes | High | Permission Status:Enabled-Not Ok | No - Non-administrators can create tenants. `AllowedToCreateTenants` is `True` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.1.3.1 | Ensure a dynamic group for guest users is created | High | Status:Dynamic Groups for Guest users not found | Undefined | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.1.6.3 | Ensure guest user invitations are limited to the Guest Inviter role | High | Status:Mot Restricted | '- UI: `Anyone in the organization can invite guest users including guests and non-admins (most inclusive)` - PowerShell: `everyone` | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 5.2.2.1 | Ensure multifactor authentication is enabled for all users in administrative roles | High | Admins Without MFA:You have 7 out of 7 users with administrative roles that aren?t registered and protected with MFA. | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.2.2 | Ensure multifactor authentication is enabled for all users | High | Status:Multifactor Authentication is not enabled for all users | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.2.3 | Enable Conditional Access policies to block legacy authentication | High | Block Legacy Authentication Status:You have 14822 of 14822 users that don't have legacy authentication blocked. | Basic authentication is disabled by default as of January 2023. | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.2.4 | Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative users | High | Status:Policy Not Enabled | The default configuration for user sign-in frequency is a rolling window of 90 days. | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.2.5 | Ensure Phishing-resistant MFA strength is required for Administrators | High | Status:Phishing-resistant MFA policy is not configured for administrators | N/A | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| Not Available | Ensure Microsoft Azure Management is limited to administrative roles | High | Permission Status:No Policy Found | No - Non-administrators can access the Azure AD administration portal. | N/A | OP 1.0 | NO |
| 5.2.3.1 | Ensure Microsoft Authenticator is configured to protect against MFA fatigue | High | Status:Microsoft Authenticator is disabled. | Microsoft-managed | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.3.2 | Ensure custom banned passwords lists are used | High | Status:Custom banned passwords setting is disabled. | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.3.4 | Ensure all member users are MFA capable | High | Total Users not MFA Capable:1 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.3.5 | Ensure weak authentication methods are disabled | High | Weak Authentication Methods Disabled:1 | '- SMS : Disabled - Voice Call : Disabled - Email OTP : Enabled | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.4.1 | Ensure Self service password reset enabled is set to All | High | Self-Service Password Status:You have 143 of 14822 users who don't have self-service password reset enabled. | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 6.1.3 | Ensure AuditBypassEnabled is not enabled on mailboxes | High | Status:AuditBypass is enabled on some mailboxes | AuditBypassEnabled `False` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 6.1.3 | Ensure AuditBypassEnabled is not enabled on mailboxes | High | Status:AuditBypass is enabled on some mailboxes | AuditBypassEnabled False | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 6.2.3 | Ensure email from external senders is identified | High | Status:Not Configured Correctly | Disabled (False) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| Not Available | Ensure Safe Attachments is Enabled | High | Status:Not Configured - No ATP License | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Safe Links is Enabled | High | Status:Not Configured - No ATP License | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Safe Links Click-Through is Not Allowed | High | Status:Not Configured - No ATP License | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Safe Links Flags Links in Real Time | High | Status:Not Configured - No ATP License | N/A | N/A | OP 1.0 | NO |
| 6.5.4 | Ensure SMTP Authentication is disabled Globally | High | Status:Not Disabled | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| Not Available | Ensure automatic forwarding options are disabled | High | Status:Not Disabled | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure the Client Rules Forwarding Block is enabled | High | Status:Disabled | N/A | N/A | OP 1.0 | NO |
| 6.3.1 | Ensure users installing Outlook add-ins is not allowed | High | Status:Allowed to Install Outlook Add-in | UI - `My Custom Apps`, `My Marketplace Apps`, and `My ReadWriteMailboxApps` are checked PowerShell - `My Custom Apps` `My Marketplace Apps` and `My ReadWriteMailboxApps` are assigned | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 6.5.4 | Ensure SMTP Authentication is disabled Globally | High | Status:Not Disabled | SmtpClientAuthenticationDisabled : True | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| Not Available | Ensure Email Security Checks are Bypassed Based on Sender Domain are not configured | High | Status:Configured | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Email Security Checks are Bypassed Based on Sender IP are not configured | High | Status:Configured | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure No Exchange Mailboxes with FullAccess Delegates are present | High | Number of Mailboxes with FullAccess Delegates:0 | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure No Exchange Mailboxes with SendAs Delegates are present | High | Number of Mailboxes with SendAs Delegates: | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure No Exchange Mailboxes with SendOnBehalfOf Delegates are present | High | Number of Mailboxes with SendOnBehalfOf Delegates:0 | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Mailboxes External Address Forwarding is not configured | High | Mailboxes Forwarding To External Domains:1 | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Exchange Online Mailboxes on Litigation Hold | High | Mailboxes On Litigation Hold:1 | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Exchange Online SPAM Domains are identified | High | Inbound and Outbound SPAM Items:3 | N/A | N/A | OP 1.0 | NO |
| 7.2.1 | Ensure modern authentication for SharePoint applications is required | High | Status:Disabled | True (Apps that don't use modern authentication are allowed) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 7.2.3 | Ensure external content sharing is restricted | High | Status:Not Configured Correctly | Anyone (ExternalUserAndGuestSharing) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 7.2.4 | Ensure OneDrive content sharing is restricted | High | Status:Not Disabled | Anyone (ExternalUserAndGuestSharing) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 7.2.5 | Ensure that SharePoint guest users cannot share items they dont own | High | Status:Not Enabled | Checked (False) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 7.2.6 | Ensure document sharing is being controlled by domains with whitelist or blacklist | High | Status:Not Controlled | Limit external sharing by domain is unchecked
SharingDomainRestrictionMode: `None`
SharingDomainRestrictionMode: |
E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 7.2.7 | Ensure link sharing is restricted in SharePoint and OneDrive | High | Status:Not Restricted-AnonymousAccess | Only people in your organization (Internal) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 7.2.9 | Ensure guest access to a site or OneDrive will expire automatically | High | Status:Do not expire Automatically | ExternalUserExpirationRequired `$false` ExternalUserExpireInDays `60` days | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 7.2.10 | Ensure reauthentication with verification code is restricted | High | Status:Not Restricted-False | EmailAttestationRequired : `False` EmailAttestationReAuthDays : `30` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 7.2.11 | Ensure the SharePoint default sharing link permission is set | High | Status:Not Restricted | DefaultLinkPermission : Edit | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 7.2.6 | Ensure document sharing is being controlled by domains with whitelist or blacklist | High | Status:Not Controlled | Limit external sharing by domain is unchecked
SharingDomainRestrictionMode: None
SharingDomainRestrictionMode: |
E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 7.3.1 | Ensure Microsoft 365 SharePoint infected files are disallowed for download | High | Status:WARNING:Allowed | FALSE | E5 Level 2 | CIS v6.0 | NO |
| 7.2.4 | Ensure OneDrive content sharing is restricted | High | Status:Not Disabled | By default there are no restrictions applied to the syncing of OneDrive. TenantRestrictionEnabled : `False` AllowedDomainList : `{}` | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| Not Available | Ensure custom script execution is restricted on personal sites | High | Total Sites allowing custom script execution:55 | Selected `Prevent users from running custom script on self-service created sites` | N/A | OP 1.0 | NO |
| Not Available | Ensure SharePoint sites are not enabled for both External and User Sharing | High | Status:Enabled | N/A | N/A | OP 1.0 | NO |
| Not Available | External user sharing-share by email-and guest link sharing are both disabled | High | Status:Not Disabled | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure that external users cannot share files folders and sites they do not own | High | Status:Not Enabled | N/A | N/A | OP 1.0 | NO |
| Not Available | SharePoint Anyone Shared Links Never Expire is not configured | High | Status:Never Expires | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Sign out inactive users in SharePoint Online is Configured | High | Sign-out Inactive Users Status:The setting is not compliant. | N/A | N/A | OP 1.0 | NO |
| 8.1.1 | Ensure external file sharing in Teams is enabled for only approved cloud storage services | High | Status:Not Controlled | AllowDropBox : `True` AllowBox : `True` AllowGoogleDrive : `True` AllowShareFile : `True` AllowEgnyte : `True` | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 8.1.2 | Ensure users cant send emails to a channel email address | High | Status:Can Send Emails | On (True) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| Not Available | Ensure End-to-end encryption for Microsoft Teams is enabled | High | Status:Disabled | N/A | N/A | OP 1.0 | NO |
| 8.2.1 | Ensure external domains are not allowed in Teams | High | Status:Allowed All Domains | N/A | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 8.2.1 | Ensure external domains are not allowed in Teams | High | Status:Allowed All Domains | EnableFederationAccess - $True | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 8.2.2 | Ensure communication with unmanaged Teams users is disabled | High | Status:Not Restricted | '- EnableTeamsConsumerAccess : `True` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 8.2.3 | Ensure external Teams users cannot initiate conversations | High | Status:Not Restricted | '- EnableTeamsConsumerInbound : `True` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 8.4.1 | Ensure app permission policies are configured | High | Status:Either some or all settings are Not compliant | Microsoft apps: On Third-party apps: On Custom apps: On | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 8.5.1 | Ensure anonymous users cant join a meeting | High | Status:Not Restricted | On (True) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 8.5.3 | Ensure only people in my org can bypass the lobby | High | Status:Not Restricted: EveryoneInCompany | People in my org and guests (EveryoneInCompany) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 8.5.4 | Ensure users dialing in cant bypass the lobby | High | Status:Not Restricted | Off (False) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 8.5.5 | Ensure meeting chat does not allow anonymous users | High | Status:Not Restricted | On for everyone (Enabled) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 8.5.6 | Ensure only organizers and co-organizers can present | High | Status:Not Restricted | Everyone (EveryoneUserOverride) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 8.5.7 | Ensure external participants cant give or request control | High | Status:Not Restricted | Off (False) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 8.5.8 | Ensure external meeting chat is off | High | Status:Not Restricted | On(True) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 8.5.9 | Ensure meeting recording is off by default | High | Status:Not Restricted | On (True) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 8.6.1 | Ensure users can report security concerns in Teams | High | Status:Cannot Report | On (`True`) Report message destination: `Microsoft Only` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| Not Available | Ensure Microsoft Teams Users Allowed to Invite Anonymous Users is disabled | High | Status:Enabled | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Microsoft Teams Policies Allow Anonymous Members is disabled | High | Status:Enabled | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Microsoft Teams Consumer Communication Policies are configured | High | Status:Not Configured | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Microsoft Teams Users Allowed to Preview Links in Messages is disabled | High | AllowUrlPreviews Configured in Total Teams Policies:4 | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Safe Links for Teams is Enabled | High | Status:Not Configured - No ATP License | N/A | N/A | OP 1.0 | NO |
| 9.1.1 | Ensure guest user access is restricted | High | Status:Not Restricted: 10dae51f-b6af-4016-8d66-8c2a99b929b3 | Enabled for Entire Organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.2 | Ensure external user invitations are restricted | High | Status:Not Restricted: everyone | Enabled for the entire organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.6 | Ensure Allow users to apply sensitivity labels for content is Enabled | High | Status:Allow users to apply sensitivity labels for content is disabled. | Disabled | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| Not Available | Ensure Microsoft 365 Exchange Online Privileged Access Management is Used | High | Status:Not Enabled | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Microsoft 365 Users Have Changed Passwords | High | Passwords unchanged since 90 days:17849 | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Users can create security groups is disabled | High | Status:Enabled-Not Ok | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Users with a verified mail domain can join the tenant is disabled | High | Permission Status:Enabled-Not Ok | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Guests can invite other guests into the tenant is disabled | High | Permission Status:Enabled-Not Ok | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Users are allowed to create new Azure Active Directory Tenants is disabled | High | Permission Status:Enabled-Not Ok | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Policy exists to restrict non-administrator access to Azure Active Directory or Entra | High | Permission Status:No Policy Found | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Microsoft 365 Licenses are consumed in SKUs | High | SKUs Not In Use:1 | N/A | N/A | OP 1.0 | NO |
| 1.2.1 | Ensure that only organizationally managed-approved public groups exist | Medium | Public Groups:1 | Public when created from the Administration portal; private otherwise. | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 1.3.6 | Ensure the customer lockbox feature is enabled | Medium | Status:Disabled | `Require approval for all data access requests` - `Unchecked` `CustomerLockboxEnabled` - `False` | E5 Level 2 | CIS v6.0 | NO |
| 2.1.8 | Ensure that SPF records are published for all Exchange Domains | Medium | Domains Missing SPF Records:5 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.1.5.1 | Ensure user consent to apps accessing company data on their behalf is not allowed | Medium | Status: Not Configured | UI - `Allow user consent for apps` | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 5.3.1 | Ensure Privileged Identity Management is used to manage roles | Medium | Status:No permanent active role assignments found. | N/A | E5 Level 2 | CIS v6.0 | NO |
| 6.5.2 | Ensure MailTips are enabled for end users | Medium | Status:Not All MailTips Enabled | MailTipsAllTipsEnabled: True MailTipsExternalRecipientsTipsEnabled: False MailTipsGroupMetricsEnabled: True MailTipsLargeAudienceThreshold: 25 | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 6.5.3 | Ensure external storage providers available in Outlook on the Web are restricted | Medium | Status:Not Restricted | `Additional Storage Providers` - `True` | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| Not Available | Ensure Microsoft 365 Hidden Mailboxes are Identified | Medium | Hidden Mailboxes:1 | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure expiration time for external sharing links is set | Medium | Status:Expiration Time for Links NOT Set | ExternalUserExpirationRequired $false ExternalUserExpireInDays 60 days | N/A | OP 1.0 | NO |
| Not Available | Ensure Microsoft Teams External Domain Communication Policies are configured | Medium | Domains Allowed Status:All Domains Allowed | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Guest Users are reviewed and disabled | Medium | Guest Accounts:15 | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure All Microsoft 365 Users are licensed | Medium | Users Not Licensed:17835 | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Microsoft 365 Users Password Expires | Medium | Password Never Expires Set:0 | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Users can read all attributes in Azure AD is disabled | Medium | Permission Status:Enabled-Not Ok | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Microsoft Teams External Access Policies are configured | Low | Status:Not Configured:EnableFederationAccess is set to True | N/A | N/A | OP 1.0 | NO |
| Not Available | Ensure Microsoft 365 Groups Without Members are Identified | Low | Groups Without Members:118 | N/A | N/A | OP 1.0 | NO |
| 1.1.1 | Ensure Administrative accounts are separate and cloud-only | Passed | Sync-In Admins:0 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 1.1.3 | Ensure that between two and four global admins are designated | Passed | Total Global Admins:3 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 1.1.4 | Ensure administrative accounts use licenses with a reduced application footprint | Passed | Status:Please check licenses assigned | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 1.2.2 | Ensure sign-in to shared mailboxes is blocked | Passed | Sign-In Allowed for Total SharedMailbox:0 | AccountEnabled: `True` | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 1.3.1 | Ensure the Password expiration policy is set to Set passwords to never expire (recommended) | Passed | Missing Password Policies Domains:0 | If the property is not set, a default value of 90 days will be used | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 1.3.4 | Ensure User owned apps and services is restricted | Passed | Status:Restricted | `Let users access the Office Store` is `Checked` `Let users start trials on behalf of your organization` is `Checked` | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 1.3.5 | Ensure internal phishing protection for Forms is enabled | Passed | Forms Phishing Protection:0 | Internal Phishing Protection is enabled. | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 2.1.4 | Ensure Safe Attachments policy is enabled | Passed | Status:Not Enabled-Not Implemented | ``` Identity : Built-In Protection Policy Enable : True Action : Block QuarantineTag : AdminOnlyAccessPolicy Priority : (lowest) ``` | E5 Level 2 | CIS v6.0 | YES |
| 2.1.7 | Ensure that an anti-phishing policy has been created | Passed | Status:Created | N/A | E5 Level 2 | CIS v6.0 | YES |
| 2.1.12 | Ensure the connection filter IP allow list is not used | Passed | Status:Not Used | IPAllowList : {} | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 2.1.13 | Ensure the connection filter safe list is off | Passed | Status:Turned Off | EnableSafeList : False | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 2.1.14 | Ensure inbound anti-spam policies do not contain allowed domains | Passed | Status:Not Allowed | AllowedSenderDomains : {} | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 2.4.4 | Ensure Zero-hour auto purge for Microsoft Teams is on | Passed | Status:License Not Available - Control Not Applicable | On (Default) | E5 Level 1 | CIS v6.0 | YES |
| Not Available | Ensure the Account Provisioning Activity report is reviewed and actioned | Passed | Account Provisioning Items:0 | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure non-global administrator role group assignments are reviewed and actioned | Passed | Status:Found non-admin Global Role assignments found in past 7 days | N/A | N/A | OP 1.0 | YES |
| 3.1.1 | Ensure Microsoft 365 audit log search is Enabled | Passed | Status:Enabled | 180 days | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| Not Available | Ensure Security Defaults is disabled on Azure Active Directory | Passed | Status:Security Defaults are disabled. | Enabled. | N/A | OP 1.0 | YES |
| 5.1.2.1 | Ensure Per-user MFA is disabled | Passed | Total Users Not Enabled with Per MFA:0 | Disabled | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 5.1.2.2 | Ensure third party integrated applications are not allowed | Passed | Status:Not Allowed | Yes (Users can register applications.) | E3 Level 2-E5 Level 2 | CIS v6.0 | YES |
| 5.1.5.2 | Ensure the admin consent workflow is enabled | Passed | Status:Enabled | '- `Users can request admin consent to apps they are unable to consent to`: `No` - `Selected users to review admin consent requests`: `None` - `Selected users will receive email notifications for requests`: `Yes` - `Selected users will receive request expiration reminders`: `Yes` - `Consent request expires after (days)`: `30` | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 5.1.6.2 | Ensure that guest user access is restricted | Passed | Status:Restricted | '- UI: `Guest users have limited access to properties and memberships of directory objects` - PowerShell: `10dae51f-b6af-4016-8d66-8c2a99b929b3` | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 5.1.8.1 | Ensure that password hash sync is enabled for hybrid deployments | Passed | Status:Password Hash Sync is enabled. | '- Microsoft Entra Connect sync `disabled` by default - Password Hash Sync is Microsoft's recommended setting for new deployments | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 5.2.2.6 | Enable Identity Protection user risk policies | Passed | Status: Configured Correctly | N/A | E5 Level 1 | CIS v6.0 | YES |
| 5.2.2.7 | Enable Identity Protection sign-in risk policies | Passed | Status: Configured Correctly | N/A | E5 Level 1 | CIS v6.0 | YES |
| 5.2.2.8 | Ensure sign-in risk is blocked for medium and high risk | Passed | Status: Configured Correctly | N/A | E5 Level 2 | CIS v6.0 | YES |
| Not Available | Ensure the self-service password reset activity report is reviewed and actioned | Passed | Status:Changed Password Found via SSPR | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure the Azure AD Risky sign-ins report is reviewed at least weekly | Passed | Status:No Risky user found | N/A | N/A | OP 1.0 | YES |
| 5.3.2 | Ensure Access reviews for Guest Users are configured | Passed | Status:Access Reviews were found | By default access reviews are not configured. | E5 Level 1 | CIS v6.0 | YES |
| 5.3.3 | Ensure Access reviews for high privileged Azure AD roles are configured | Passed | Status:Access Reviews were found | By default access reviews are not configured. | E5 Level 1 | CIS v6.0 | YES |
| 6.1.1 | Ensure AuditDisabled organizationally is set to False | Passed | Status:Enabled | FALSE | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 6.1.2 | Ensure mailbox audit actions are configured | Passed | Mailbox Audit Config Issues:26106 | `AuditEnabled`: `True` for all mailboxes except below: - Resource Mailboxes - Public Folder Mailboxes - DiscoverySearch Mailbox **AuditAdmin:** ApplyRecord, Create, HardDelete, MailItemsAccessed, MoveToDeletedItems, Send, SendAs, SendOnBehalf, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules **AuditDelegate:** ApplyRecord, Create, HardDelete, MailItemsAccessed, MoveToDeletedItems, SendAs, SendOnBehalf, SoftDelete, Update, UpdateFolderPermissions, UpdateInboxRules **AuditOwner:** ApplyRecord, HardDelete, MailItemsAccessed, MoveToDeletedItems, Send, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| Not Available | Ensure mailbox auditing for E3 users is Enabled | Passed | Missing Mailbox Auditing:0 | AuditEnabled: True for all mailboxes except below: - Resource Mailboxes - Public Folder Mailboxes - DiscoverySearch Mailbox **AuditAdmin:** ApplyRecord, Create, HardDelete, MoveToDeletedItems, SendAs, SendOnBehalf, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules **AuditDelegate:** ApplyRecord, Create, HardDelete, MoveToDeletedItems, SendAs, SendOnBehalf, SoftDelete, Update, UpdateFolderPermissions, UpdateInboxRules **AuditOwner:** ApplyRecord, HardDelete, MoveToDeletedItems, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules | N/A | OP 1.0 | YES |
| Not Available | Ensure mailbox auditing for E5 users is Enabled | Passed | Missing Mailbox Auditing:0 | AuditEnabled: True for all mailboxes except below: - Resource Mailboxes - Public Folder Mailboxes - DiscoverySearch Mailbox **AuditAdmin:** ApplyRecord, Create, HardDelete, MailItemsAccessed, MoveToDeletedItems, Send, SendAs, SendOnBehalf, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules **AuditDelegate:** ApplyRecord, Create, HardDelete, MailItemsAccessed, MoveToDeletedItems, SendAs, SendOnBehalf, SoftDelete, Update, UpdateFolderPermissions, UpdateInboxRules **AuditOwner:** ApplyRecord, HardDelete, MailItemsAccessed, MoveToDeletedItems, Send, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules | N/A | OP 1.0 | YES |
| 6.2.1 | Ensure all forms of mail forwarding are blocked and-or disabled | Passed | Mails Forwarding Rules Enabled:0 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 6.2.2 | Ensure mail transport rules do not whitelist specific domains | Passed | Whitelist Domains:0 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| Not Available | Ensure Transport Rules to Block Exchange Auto-Forwarding is configured | Passed | Status:Configured | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure Do Not Bypass the Safe Attachments Filter is not configured | Passed | Status:Not Configured | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure Do Not Bypass the Safe Links Feature is not configured | Passed | Status:Not Configured | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure Exchange Modern Authentication is Enabled | Passed | Status:Enabled | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure Transport Rules to Block Executable Attachments are configured | Passed | Status:Configured | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure Malware Filter Policies Alert for Internal Users Sending Malware is configured | Passed | Status:Configured | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure Mailbox Auditing is Enabled at Tenant Level | Passed | Status:Enabled | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure Mailboxes without Mailbox Auditing are not present | Passed | Mailboxes Without Auditing:0 | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure mail transport rules do not forward email to external domains | Passed | Mails Forwarding Rules Enabled:0 | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure the Advanced Threat Protection Safe Links policy is enabled | Passed | Status:Not Enabled-Not Implemented | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure the Advanced Threat Protection SafeAttachments policy is enabled | Passed | Status:Not Enabled-Not Implemented | N/A | N/A | OP 1.0 | YES |
| 2.1.7 | Ensure that an anti-phishing policy has been created | Passed | Status:Created | N/A | E5 Level 2 | CIS v6.0 | YES |
| Not Available | Ensure mailbox auditing for all users is Enabled | Passed | Missing Mailbox Auditing:0 | N/A | N/A | OP 1.0 | YES |
| 6.5.1 | Ensure modern authentication for Exchange Online is enabled | Passed | Status:Enabled | TRUE | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| Not Available | Ensure mail forwarding rules are reviewed and actioned | Passed | Forwarding Rules To External Domains:0 | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure the Malware Detections report is reviewed at least weekly | Passed | Malware Report Items:0 | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure Microsoft 365 Deleted Mailboxes are identified and Verified | Passed | Deleted Mailboxes:0 | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure Exchange Online Mailbox Auditing is enabled | Passed | Mailboxes Without Auditing:0 | N/A | N/A | OP 1.0 | YES |
| Not Available | Microsoft 365 Exchange Online Admin Success and Failure Attempts | Passed | Failures for Online Admins:0 | N/A | N/A | OP 1.0 | YES |
| Not Available | Microsoft 365 Exchange Online External Access Admin Success and Failure Attempts | Passed | Failures for External Admins:0 | N/A | N/A | OP 1.0 | YES |
| 7.2.2 | Ensure SharePoint and OneDrive integration with Azure AD B2B is enabled | Passed | Status:Enabled | FALSE | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| Not Available | Ensure custom script execution is restricted on site collections | Passed | Not Restricted for Sites:0 | DenyAddAndCustomizePages `$true` or `Enabled` | N/A | OP 1.0 | YES |
| Not Available | SharePoint Online Modern Authentication is Enabled | Passed | Status:Enabled | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure communication with Skype users is disabled | Passed | Status:Restricted | '- AllowPublicUsers : `True` | N/A | OP 1.0 | YES |
| 8.5.2 | Ensure anonymous users and dial-in callers cant start a meeting | Passed | Status:Restricted | Off (False) | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| Not Available | Ensure Microsoft 365 User Roles have less than 10 Admins | Passed | Total Number of Roles having more than 10 Admins:0 | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure Microsoft 365 Users Have Strong Password Requirements Configured | Passed | Users With Weak Password Requirements:0 | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure self-service password reset is enabled | Passed | Status:Enabled | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure Microsoft 365 Exchange Online Modern Authentication is Used | Passed | Status:Enabled | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure Deleted Microsoft 365 Users are Identified | Passed | Deleted Users:0 | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure Disabled Microsoft 365 Users are Identified | Passed | Disabled Users:3031 | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure Microsoft 365 Blocked Users are Identified | Passed | Microsoft 365 Users Blocked:0 | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure Microsoft 365 Company Administrators have less than 5 Admins | Passed | More Than 5 Company Administrators Status:0 | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure Microsoft 365 Deleted and Licensed Users are Identified | Passed | Deleted Users Licensed:0 | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure Users are allowed to create and register applications is disabled | Passed | Permission Status:Disabled-Ok | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure All Microsoft 365 Domains Have been verified | Passed | Domains Verification Pending:0 | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure Microsoft 365 Domain Services Have Services Assigned | Passed | Domains Without Services:0 | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure Microsoft 365 Notification Email is configured | Passed | Notifications Email: | N/A | N/A | OP 1.0 | YES |
| Not Available | Ensure Microsoft 365 Organization Level Mailbox Auditing is configured | Passed | Status:Enabled | N/A | N/A | OP 1.0 | YES |
| 1.1.2 | Ensure two emergency access accounts have been defined | Manual Check | NONE | Not defined. | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 1.3.8 | Ensure that Sways cannot be shared with people outside of your organization | Manual Check | NONE | `Let people in your organization share their sways with people outside your organization` - Enabled | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 2.1.5 | Ensure Safe Attachments for SharePoint-OneDrive-Microsoft Teams is Enabled | Manual Check | NONE | N/A | E5 Level 2 | CIS v6.0 | NO |
| 2.2.1 | Ensure emergency access account activity is monitored | Manual Check | NONE | A policy to monitor emergency access accounts does not exist by default. | E5 Level 1 | CIS v6.0 | NO |
| 2.4.3 | Ensure Microsoft Defender for Cloud Apps is Enabled | Manual Check | NONE | Disabled | E5 Level 2 | CIS v6.0 | NO |
| 3.3.1 | Ensure Information Protection sensitivity label policies are published | Manual Check | NONE | The Global sensitivity label policy exists by default. | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.1.2.4 | Ensure access to the Entra admin center is restricted | Manual Check | NONE | No - Non-administrators can access the Microsoft Entra admin center. | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.1.2.5 | Ensure the option to remain signed in is hidden | Manual Check | NONE | Users may select `stay signed in` | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 5.1.2.6 | Ensure LinkedIn account connections is disabled | Manual Check | NONE | LinkedIn integration is enabled by default. | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 5.1.6.1 | Ensure that collaboration invitations are sent to allowed domains only | Manual Check | NONE | Allow invitations to be sent to any domain (most inclusive) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 5.2.2.9 | Ensure a managed device is required for authentication | Manual Check | NONE | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.2.10 | Ensure a managed device is required to register security information | Manual Check | NONE | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.2.11 | Ensure sign-in frequency for Intune Enrollment is set to Every time | Manual Check | NONE | Sign-in frequency defaults to 90 days. | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.2.12 | Ensure the device code sign-in flow is blocked | Manual Check | NONE | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.3.3 | Ensure that password protection is enabled for Active Directory | Manual Check | NONE | Enable - Yes Mode - Audit | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.3.6 | Ensure system-preferred multifactor authentication is enabled | Manual Check | NONE | Microsoft Managed (Enabled) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.3.4 | Ensure approval is required for Global Administrator role activation | Manual Check | NONE | `Require approval to activate` : `No`. | E5 Level 1 | CIS v6.0 | NO |
| 5.3.5 | Ensure approval is required for Privileged Role Administrator activation | Manual Check | NONE | `Require approval to activate` : `No`. | E5 Level 1 | CIS v6.0 | NO |
| Not Available | Use Just In Time privileged access to Microsoft 365 roles | Manual Check | NONE | N/A | N/A | OP 1.0 | NO |
| 7.2.8 | Ensure external sharing is restricted by security group | Manual Check | NONE | Unchecked/Undefined | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 9.1.3 | Ensure guest access to content is restricted | Manual Check | NONE | Disabled | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.4 | Ensure Publish to web is restricted | Manual Check | NONE | Enabled for the entire organization Only allow existing codes | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.5 | Ensure Interact with and share R and Python visuals is Disabled | Manual Check | NONE | Enabled | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 9.1.7 | Ensure shareable links are restricted | Manual Check | NONE | Enabled for Entire Organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.8 | Ensure enabling of external data sharing is restricted | Manual Check | NONE | Enabled for the entire organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.9 | Ensure Block ResourceKey Authentication is Enabled | Manual Check | NONE | Disabled for the entire organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.10 | Ensure access to APIs by Service Principals is restricted | Manual Check | NONE | Disabled for the entire organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.11 | Ensure Service Principals cannot create and use profiles | Manual Check | NONE | Disabled for the entire organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
CIS Assessment Status Table
Assessment Table satus contains status for CIS Benchmark Tests.
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 1.3.2 | Ensure Idle session timeout is set to 3 hours (or less) for unmanaged devices | High | Idle Timeout Status:1 | Not configured. (Idle sessions will not timeout.) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 1.3.3 | Ensure External sharing of calendars is not available | High | Status:Enabled | Enabled (True) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 1.3.7 | Ensure third-party storage services are restricted in Microsoft 365 on the web | High | Status:Not Restricted | Enabled - Users are able to open files stored in third-party storage services | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 2.1.1 | Ensure Safe Links for Office Applications is Enabled | High | Status:Not Enabled | N/A | E5 Level 2 | CIS v6.0 | NO |
| 2.1.2 | Ensure the Common Attachment Types Filter is enabled | High | Status:Not Enabled | Always on | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 2.1.3 | Ensure notifications for internal users sending malware is Enabled | High | Status:Not Enabled | ``` EnableInternalSenderAdminNotifications : False InternalSenderAdminAddress : $null ``` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 2.1.6 | Ensure Exchange Online Spam Policies are set correctly | High | Status:Not Enabled | ``` BccSuspiciousOutboundAdditionalRecipients : {} BccSuspiciousOutboundMail : False NotifyOutboundSpamRecipients : {} NotifyOutboundSpam : False ``` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 2.1.9 | Ensure that DKIM is enabled for all Exchange Online Domains | High | Domains Missing DKIM:3 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 2.1.10 | Ensure DMARC Records for all Exchange Online domains are published | High | Missing Domains for DMARC Records:5 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 2.1.11 | Ensure comprehensive attachment filtering is applied | High | Status:Not Configured Correctly | The following extensions are blocked by default: ace, ani, apk, app, appx, arj, bat, cab, cmd, com, deb, dex, dll, docm, elf, exe, hta, img, iso, jar, jnlp, kext, lha, lib, library, lnk, lzh, macho, msc, msi, msix, msp, mst, pif, ppa, ppam, reg, rev, scf, scr, sct, sys, uif, vb, vbe, vbs, vxd, wsc, wsf, wsh, xll, xz, z | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 2.4.1 | Ensure Priority account protection is enabled and configured | High | Priority Account Status:Not Enabled-Not Implemented | By default, priority accounts are undefined. | E5 Level 1 | CIS v6.0 | NO |
| 3.2.1 | Ensure DLP policies are enabled | High | Status:The DLP Policy is NOT Enabled | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 3.2.2 | Ensure DLP policies are enabled for Microsoft Teams | High | Status:No DLP Policy Found | Enabled (On) | E5 Level 1 | CIS v6.0 | NO |
| 4.1 | Ensure devices without a compliance policy are marked not compliant | High | Compliance Policy Default Behavior:1 | UI: Compliant Graph: secureByDefault = $false | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 5.1.2.3 | Ensure Restrict non-admin users from creating tenants is set to Yes | High | Permission Status:Enabled-Not Ok | No - Non-administrators can create tenants. `AllowedToCreateTenants` is `True` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.1.3.1 | Ensure a dynamic group for guest users is created | High | Status:Dynamic Groups for Guest users not found | Undefined | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.1.6.3 | Ensure guest user invitations are limited to the Guest Inviter role | High | Status:Mot Restricted | '- UI: `Anyone in the organization can invite guest users including guests and non-admins (most inclusive)` - PowerShell: `everyone` | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 5.2.2.1 | Ensure multifactor authentication is enabled for all users in administrative roles | High | Admins Without MFA:You have 7 out of 7 users with administrative roles that aren?t registered and protected with MFA. | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.2.2 | Ensure multifactor authentication is enabled for all users | High | Status:Multifactor Authentication is not enabled for all users | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.2.3 | Enable Conditional Access policies to block legacy authentication | High | Block Legacy Authentication Status:You have 14822 of 14822 users that don't have legacy authentication blocked. | Basic authentication is disabled by default as of January 2023. | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.2.4 | Ensure Sign-in frequency is enabled and browser sessions are not persistent for Administrative users | High | Status:Policy Not Enabled | The default configuration for user sign-in frequency is a rolling window of 90 days. | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.2.5 | Ensure Phishing-resistant MFA strength is required for Administrators | High | Status:Phishing-resistant MFA policy is not configured for administrators | N/A | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 5.2.3.1 | Ensure Microsoft Authenticator is configured to protect against MFA fatigue | High | Status:Microsoft Authenticator is disabled. | Microsoft-managed | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.3.2 | Ensure custom banned passwords lists are used | High | Status:Custom banned passwords setting is disabled. | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.3.4 | Ensure all member users are MFA capable | High | Total Users not MFA Capable:1 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.3.5 | Ensure weak authentication methods are disabled | High | Weak Authentication Methods Disabled:1 | '- SMS : Disabled - Voice Call : Disabled - Email OTP : Enabled | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.4.1 | Ensure Self service password reset enabled is set to All | High | Self-Service Password Status:You have 143 of 14822 users who don't have self-service password reset enabled. | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 6.1.3 | Ensure AuditBypassEnabled is not enabled on mailboxes | High | Status:AuditBypass is enabled on some mailboxes | AuditBypassEnabled `False` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 6.1.3 | Ensure AuditBypassEnabled is not enabled on mailboxes | High | Status:AuditBypass is enabled on some mailboxes | AuditBypassEnabled False | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 6.2.3 | Ensure email from external senders is identified | High | Status:Not Configured Correctly | Disabled (False) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 6.5.4 | Ensure SMTP Authentication is disabled Globally | High | Status:Not Disabled | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 6.3.1 | Ensure users installing Outlook add-ins is not allowed | High | Status:Allowed to Install Outlook Add-in | UI - `My Custom Apps`, `My Marketplace Apps`, and `My ReadWriteMailboxApps` are checked PowerShell - `My Custom Apps` `My Marketplace Apps` and `My ReadWriteMailboxApps` are assigned | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 6.5.4 | Ensure SMTP Authentication is disabled Globally | High | Status:Not Disabled | SmtpClientAuthenticationDisabled : True | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 7.2.1 | Ensure modern authentication for SharePoint applications is required | High | Status:Disabled | True (Apps that don't use modern authentication are allowed) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 7.2.3 | Ensure external content sharing is restricted | High | Status:Not Configured Correctly | Anyone (ExternalUserAndGuestSharing) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 7.2.4 | Ensure OneDrive content sharing is restricted | High | Status:Not Disabled | Anyone (ExternalUserAndGuestSharing) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 7.2.5 | Ensure that SharePoint guest users cannot share items they dont own | High | Status:Not Enabled | Checked (False) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 7.2.6 | Ensure document sharing is being controlled by domains with whitelist or blacklist | High | Status:Not Controlled | Limit external sharing by domain is unchecked
SharingDomainRestrictionMode: `None`
SharingDomainRestrictionMode: |
E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 7.2.7 | Ensure link sharing is restricted in SharePoint and OneDrive | High | Status:Not Restricted-AnonymousAccess | Only people in your organization (Internal) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 7.2.9 | Ensure guest access to a site or OneDrive will expire automatically | High | Status:Do not expire Automatically | ExternalUserExpirationRequired `$false` ExternalUserExpireInDays `60` days | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 7.2.10 | Ensure reauthentication with verification code is restricted | High | Status:Not Restricted-False | EmailAttestationRequired : `False` EmailAttestationReAuthDays : `30` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 7.2.11 | Ensure the SharePoint default sharing link permission is set | High | Status:Not Restricted | DefaultLinkPermission : Edit | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 7.2.6 | Ensure document sharing is being controlled by domains with whitelist or blacklist | High | Status:Not Controlled | Limit external sharing by domain is unchecked
SharingDomainRestrictionMode: None
SharingDomainRestrictionMode: |
E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 7.3.1 | Ensure Microsoft 365 SharePoint infected files are disallowed for download | High | Status:WARNING:Allowed | FALSE | E5 Level 2 | CIS v6.0 | NO |
| 7.2.4 | Ensure OneDrive content sharing is restricted | High | Status:Not Disabled | By default there are no restrictions applied to the syncing of OneDrive. TenantRestrictionEnabled : `False` AllowedDomainList : `{}` | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 8.1.1 | Ensure external file sharing in Teams is enabled for only approved cloud storage services | High | Status:Not Controlled | AllowDropBox : `True` AllowBox : `True` AllowGoogleDrive : `True` AllowShareFile : `True` AllowEgnyte : `True` | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 8.1.2 | Ensure users cant send emails to a channel email address | High | Status:Can Send Emails | On (True) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 8.2.1 | Ensure external domains are not allowed in Teams | High | Status:Allowed All Domains | N/A | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 8.2.1 | Ensure external domains are not allowed in Teams | High | Status:Allowed All Domains | EnableFederationAccess - $True | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 8.2.2 | Ensure communication with unmanaged Teams users is disabled | High | Status:Not Restricted | '- EnableTeamsConsumerAccess : `True` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 8.2.3 | Ensure external Teams users cannot initiate conversations | High | Status:Not Restricted | '- EnableTeamsConsumerInbound : `True` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 8.4.1 | Ensure app permission policies are configured | High | Status:Either some or all settings are Not compliant | Microsoft apps: On Third-party apps: On Custom apps: On | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 8.5.1 | Ensure anonymous users cant join a meeting | High | Status:Not Restricted | On (True) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 8.5.3 | Ensure only people in my org can bypass the lobby | High | Status:Not Restricted: EveryoneInCompany | People in my org and guests (EveryoneInCompany) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 8.5.4 | Ensure users dialing in cant bypass the lobby | High | Status:Not Restricted | Off (False) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 8.5.5 | Ensure meeting chat does not allow anonymous users | High | Status:Not Restricted | On for everyone (Enabled) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 8.5.6 | Ensure only organizers and co-organizers can present | High | Status:Not Restricted | Everyone (EveryoneUserOverride) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 8.5.7 | Ensure external participants cant give or request control | High | Status:Not Restricted | Off (False) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 8.5.8 | Ensure external meeting chat is off | High | Status:Not Restricted | On(True) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 8.5.9 | Ensure meeting recording is off by default | High | Status:Not Restricted | On (True) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 8.6.1 | Ensure users can report security concerns in Teams | High | Status:Cannot Report | On (`True`) Report message destination: `Microsoft Only` | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.1 | Ensure guest user access is restricted | High | Status:Not Restricted: 10dae51f-b6af-4016-8d66-8c2a99b929b3 | Enabled for Entire Organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.2 | Ensure external user invitations are restricted | High | Status:Not Restricted: everyone | Enabled for the entire organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.6 | Ensure Allow users to apply sensitivity labels for content is Enabled | High | Status:Allow users to apply sensitivity labels for content is disabled. | Disabled | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 1.2.1 | Ensure that only organizationally managed-approved public groups exist | Medium | Public Groups:1 | Public when created from the Administration portal; private otherwise. | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 1.3.6 | Ensure the customer lockbox feature is enabled | Medium | Status:Disabled | `Require approval for all data access requests` - `Unchecked` `CustomerLockboxEnabled` - `False` | E5 Level 2 | CIS v6.0 | NO |
| 2.1.8 | Ensure that SPF records are published for all Exchange Domains | Medium | Domains Missing SPF Records:5 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.1.5.1 | Ensure user consent to apps accessing company data on their behalf is not allowed | Medium | Status: Not Configured | UI - `Allow user consent for apps` | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 5.3.1 | Ensure Privileged Identity Management is used to manage roles | Medium | Status:No permanent active role assignments found. | N/A | E5 Level 2 | CIS v6.0 | NO |
| 6.5.2 | Ensure MailTips are enabled for end users | Medium | Status:Not All MailTips Enabled | MailTipsAllTipsEnabled: True MailTipsExternalRecipientsTipsEnabled: False MailTipsGroupMetricsEnabled: True MailTipsLargeAudienceThreshold: 25 | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 6.5.3 | Ensure external storage providers available in Outlook on the Web are restricted | Medium | Status:Not Restricted | `Additional Storage Providers` - `True` | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 1.1.1 | Ensure Administrative accounts are separate and cloud-only | Passed | Sync-In Admins:0 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 1.1.3 | Ensure that between two and four global admins are designated | Passed | Total Global Admins:3 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 1.1.4 | Ensure administrative accounts use licenses with a reduced application footprint | Passed | Status:Please check licenses assigned | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 1.2.2 | Ensure sign-in to shared mailboxes is blocked | Passed | Sign-In Allowed for Total SharedMailbox:0 | AccountEnabled: `True` | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 1.3.1 | Ensure the Password expiration policy is set to Set passwords to never expire (recommended) | Passed | Missing Password Policies Domains:0 | If the property is not set, a default value of 90 days will be used | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 1.3.4 | Ensure User owned apps and services is restricted | Passed | Status:Restricted | `Let users access the Office Store` is `Checked` `Let users start trials on behalf of your organization` is `Checked` | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 1.3.5 | Ensure internal phishing protection for Forms is enabled | Passed | Forms Phishing Protection:0 | Internal Phishing Protection is enabled. | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 2.1.4 | Ensure Safe Attachments policy is enabled | Passed | Status:Not Enabled-Not Implemented | ``` Identity : Built-In Protection Policy Enable : True Action : Block QuarantineTag : AdminOnlyAccessPolicy Priority : (lowest) ``` | E5 Level 2 | CIS v6.0 | YES |
| 2.1.7 | Ensure that an anti-phishing policy has been created | Passed | Status:Created | N/A | E5 Level 2 | CIS v6.0 | YES |
| 2.1.12 | Ensure the connection filter IP allow list is not used | Passed | Status:Not Used | IPAllowList : {} | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 2.1.13 | Ensure the connection filter safe list is off | Passed | Status:Turned Off | EnableSafeList : False | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 2.1.14 | Ensure inbound anti-spam policies do not contain allowed domains | Passed | Status:Not Allowed | AllowedSenderDomains : {} | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 2.4.4 | Ensure Zero-hour auto purge for Microsoft Teams is on | Passed | Status:License Not Available - Control Not Applicable | On (Default) | E5 Level 1 | CIS v6.0 | YES |
| 3.1.1 | Ensure Microsoft 365 audit log search is Enabled | Passed | Status:Enabled | 180 days | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 5.1.2.1 | Ensure Per-user MFA is disabled | Passed | Total Users Not Enabled with Per MFA:0 | Disabled | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 5.1.2.2 | Ensure third party integrated applications are not allowed | Passed | Status:Not Allowed | Yes (Users can register applications.) | E3 Level 2-E5 Level 2 | CIS v6.0 | YES |
| 5.1.5.2 | Ensure the admin consent workflow is enabled | Passed | Status:Enabled | '- `Users can request admin consent to apps they are unable to consent to`: `No` - `Selected users to review admin consent requests`: `None` - `Selected users will receive email notifications for requests`: `Yes` - `Selected users will receive request expiration reminders`: `Yes` - `Consent request expires after (days)`: `30` | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 5.1.6.2 | Ensure that guest user access is restricted | Passed | Status:Restricted | '- UI: `Guest users have limited access to properties and memberships of directory objects` - PowerShell: `10dae51f-b6af-4016-8d66-8c2a99b929b3` | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 5.1.8.1 | Ensure that password hash sync is enabled for hybrid deployments | Passed | Status:Password Hash Sync is enabled. | '- Microsoft Entra Connect sync `disabled` by default - Password Hash Sync is Microsoft's recommended setting for new deployments | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 5.2.2.6 | Enable Identity Protection user risk policies | Passed | Status: Configured Correctly | N/A | E5 Level 1 | CIS v6.0 | YES |
| 5.2.2.7 | Enable Identity Protection sign-in risk policies | Passed | Status: Configured Correctly | N/A | E5 Level 1 | CIS v6.0 | YES |
| 5.2.2.8 | Ensure sign-in risk is blocked for medium and high risk | Passed | Status: Configured Correctly | N/A | E5 Level 2 | CIS v6.0 | YES |
| 5.3.2 | Ensure Access reviews for Guest Users are configured | Passed | Status:Access Reviews were found | By default access reviews are not configured. | E5 Level 1 | CIS v6.0 | YES |
| 5.3.3 | Ensure Access reviews for high privileged Azure AD roles are configured | Passed | Status:Access Reviews were found | By default access reviews are not configured. | E5 Level 1 | CIS v6.0 | YES |
| 6.1.1 | Ensure AuditDisabled organizationally is set to False | Passed | Status:Enabled | FALSE | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 6.1.2 | Ensure mailbox audit actions are configured | Passed | Mailbox Audit Config Issues:26106 | `AuditEnabled`: `True` for all mailboxes except below: - Resource Mailboxes - Public Folder Mailboxes - DiscoverySearch Mailbox **AuditAdmin:** ApplyRecord, Create, HardDelete, MailItemsAccessed, MoveToDeletedItems, Send, SendAs, SendOnBehalf, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules **AuditDelegate:** ApplyRecord, Create, HardDelete, MailItemsAccessed, MoveToDeletedItems, SendAs, SendOnBehalf, SoftDelete, Update, UpdateFolderPermissions, UpdateInboxRules **AuditOwner:** ApplyRecord, HardDelete, MailItemsAccessed, MoveToDeletedItems, Send, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 6.2.1 | Ensure all forms of mail forwarding are blocked and-or disabled | Passed | Mails Forwarding Rules Enabled:0 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 6.2.2 | Ensure mail transport rules do not whitelist specific domains | Passed | Whitelist Domains:0 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 2.1.7 | Ensure that an anti-phishing policy has been created | Passed | Status:Created | N/A | E5 Level 2 | CIS v6.0 | YES |
| 6.5.1 | Ensure modern authentication for Exchange Online is enabled | Passed | Status:Enabled | TRUE | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 7.2.2 | Ensure SharePoint and OneDrive integration with Azure AD B2B is enabled | Passed | Status:Enabled | FALSE | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 8.5.2 | Ensure anonymous users and dial-in callers cant start a meeting | Passed | Status:Restricted | Off (False) | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 1.1.2 | Ensure two emergency access accounts have been defined | Manual Check | NONE | Not defined. | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 1.3.8 | Ensure that Sways cannot be shared with people outside of your organization | Manual Check | NONE | `Let people in your organization share their sways with people outside your organization` - Enabled | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 2.1.5 | Ensure Safe Attachments for SharePoint-OneDrive-Microsoft Teams is Enabled | Manual Check | NONE | N/A | E5 Level 2 | CIS v6.0 | NO |
| 2.2.1 | Ensure emergency access account activity is monitored | Manual Check | NONE | A policy to monitor emergency access accounts does not exist by default. | E5 Level 1 | CIS v6.0 | NO |
| 2.4.3 | Ensure Microsoft Defender for Cloud Apps is Enabled | Manual Check | NONE | Disabled | E5 Level 2 | CIS v6.0 | NO |
| 3.3.1 | Ensure Information Protection sensitivity label policies are published | Manual Check | NONE | The Global sensitivity label policy exists by default. | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.1.2.4 | Ensure access to the Entra admin center is restricted | Manual Check | NONE | No - Non-administrators can access the Microsoft Entra admin center. | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.1.2.5 | Ensure the option to remain signed in is hidden | Manual Check | NONE | Users may select `stay signed in` | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 5.1.2.6 | Ensure LinkedIn account connections is disabled | Manual Check | NONE | LinkedIn integration is enabled by default. | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 5.1.6.1 | Ensure that collaboration invitations are sent to allowed domains only | Manual Check | NONE | Allow invitations to be sent to any domain (most inclusive) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 5.2.2.9 | Ensure a managed device is required for authentication | Manual Check | NONE | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.2.10 | Ensure a managed device is required to register security information | Manual Check | NONE | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.2.11 | Ensure sign-in frequency for Intune Enrollment is set to Every time | Manual Check | NONE | Sign-in frequency defaults to 90 days. | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.2.12 | Ensure the device code sign-in flow is blocked | Manual Check | NONE | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.3.3 | Ensure that password protection is enabled for Active Directory | Manual Check | NONE | Enable - Yes Mode - Audit | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.3.6 | Ensure system-preferred multifactor authentication is enabled | Manual Check | NONE | Microsoft Managed (Enabled) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.3.4 | Ensure approval is required for Global Administrator role activation | Manual Check | NONE | `Require approval to activate` : `No`. | E5 Level 1 | CIS v6.0 | NO |
| 5.3.5 | Ensure approval is required for Privileged Role Administrator activation | Manual Check | NONE | `Require approval to activate` : `No`. | E5 Level 1 | CIS v6.0 | NO |
| 7.2.8 | Ensure external sharing is restricted by security group | Manual Check | NONE | Unchecked/Undefined | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 9.1.3 | Ensure guest access to content is restricted | Manual Check | NONE | Disabled | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.4 | Ensure Publish to web is restricted | Manual Check | NONE | Enabled for the entire organization Only allow existing codes | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.5 | Ensure Interact with and share R and Python visuals is Disabled | Manual Check | NONE | Enabled | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 9.1.7 | Ensure shareable links are restricted | Manual Check | NONE | Enabled for Entire Organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.8 | Ensure enabling of external data sharing is restricted | Manual Check | NONE | Enabled for the entire organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.9 | Ensure Block ResourceKey Authentication is Enabled | Manual Check | NONE | Disabled for the entire organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.10 | Ensure access to APIs by Service Principals is restricted | Manual Check | NONE | Disabled for the entire organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.11 | Ensure Service Principals cannot create and use profiles | Manual Check | NONE | Disabled for the entire organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
SmartProfiler Assessment Tests Status Table
Assessment Table satus contains status for SmartProfiler Tests.
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| Not Available | SharePoint External Sharing is not Enabled at Global Level | Critical | Status:Enabled - : Sharing capability is ExternalUserAndGuestSharing (Anyone). | N/A | N/A | SP v1.0 | NO |
| Not Available | SharePoint External User Resharing is not Permitted | Critical | Status:Permitted | N/A | N/A | SP v1.0 | NO |
| Not Available | SharePoint Legacy Authentication is not Enabled | Critical | Status:Enabled | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure user role group changes are reviewed and actioned | High | Status:There are user role group changes found in past 7 days | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure DLP Policy is enabled for OneDrive | High | Status:Not Enabled | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure DLP Policy is configured for SharePoint | High | Status:Not Enabled | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Custom Anti-Malware Policy is Present | High | Status:Not Defined | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Custom Anti-Phishing Policy is Present | High | Status:Not Defined | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Custom DLP Policies are Present | High | Status:Not Defined-Not Implemented | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Custom DLP Sensitive Information Types are Defined | High | Status:Not Defined-Not Implemented | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Microsoft Azure Management is limited to administrative roles | High | Permission Status:No Policy Found | No - Non-administrators can access the Azure AD administration portal. | N/A | SP v1.0 | NO |
| Not Available | Ensure Safe Attachments is Enabled | High | Status:Not Configured - No ATP License | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Safe Links is Enabled | High | Status:Not Configured - No ATP License | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Safe Links Click-Through is Not Allowed | High | Status:Not Configured - No ATP License | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Safe Links Flags Links in Real Time | High | Status:Not Configured - No ATP License | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure automatic forwarding options are disabled | High | Status:Not Disabled | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure the Client Rules Forwarding Block is enabled | High | Status:Disabled | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Email Security Checks are Bypassed Based on Sender Domain are not configured | High | Status:Configured | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Email Security Checks are Bypassed Based on Sender IP are not configured | High | Status:Configured | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure No Exchange Mailboxes with FullAccess Delegates are present | High | Number of Mailboxes with FullAccess Delegates:0 | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure No Exchange Mailboxes with SendAs Delegates are present | High | Number of Mailboxes with SendAs Delegates: | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure No Exchange Mailboxes with SendOnBehalfOf Delegates are present | High | Number of Mailboxes with SendOnBehalfOf Delegates:0 | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Mailboxes External Address Forwarding is not configured | High | Mailboxes Forwarding To External Domains:1 | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Exchange Online Mailboxes on Litigation Hold | High | Mailboxes On Litigation Hold:1 | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Exchange Online SPAM Domains are identified | High | Inbound and Outbound SPAM Items:3 | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure custom script execution is restricted on personal sites | High | Total Sites allowing custom script execution:55 | Selected `Prevent users from running custom script on self-service created sites` | N/A | SP v1.0 | NO |
| Not Available | Ensure SharePoint sites are not enabled for both External and User Sharing | High | Status:Enabled | N/A | N/A | SP v1.0 | NO |
| Not Available | External user sharing-share by email-and guest link sharing are both disabled | High | Status:Not Disabled | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure that external users cannot share files folders and sites they do not own | High | Status:Not Enabled | N/A | N/A | SP v1.0 | NO |
| Not Available | SharePoint Anyone Shared Links Never Expire is not configured | High | Status:Never Expires | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Sign out inactive users in SharePoint Online is Configured | High | Sign-out Inactive Users Status:The setting is not compliant. | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure End-to-end encryption for Microsoft Teams is enabled | High | Status:Disabled | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Microsoft Teams Users Allowed to Invite Anonymous Users is disabled | High | Status:Enabled | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Microsoft Teams Policies Allow Anonymous Members is disabled | High | Status:Enabled | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Microsoft Teams Consumer Communication Policies are configured | High | Status:Not Configured | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Microsoft Teams Users Allowed to Preview Links in Messages is disabled | High | AllowUrlPreviews Configured in Total Teams Policies:4 | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Safe Links for Teams is Enabled | High | Status:Not Configured - No ATP License | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Microsoft 365 Exchange Online Privileged Access Management is Used | High | Status:Not Enabled | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Microsoft 365 Users Have Changed Passwords | High | Passwords unchanged since 90 days:17849 | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Users can create security groups is disabled | High | Status:Enabled-Not Ok | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Users with a verified mail domain can join the tenant is disabled | High | Permission Status:Enabled-Not Ok | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Guests can invite other guests into the tenant is disabled | High | Permission Status:Enabled-Not Ok | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Users are allowed to create new Azure Active Directory Tenants is disabled | High | Permission Status:Enabled-Not Ok | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Policy exists to restrict non-administrator access to Azure Active Directory or Entra | High | Permission Status:No Policy Found | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Microsoft 365 Licenses are consumed in SKUs | High | SKUs Not In Use:1 | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Microsoft 365 Hidden Mailboxes are Identified | Medium | Hidden Mailboxes:1 | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure expiration time for external sharing links is set | Medium | Status:Expiration Time for Links NOT Set | ExternalUserExpirationRequired $false ExternalUserExpireInDays 60 days | N/A | SP v1.0 | NO |
| Not Available | Ensure Microsoft Teams External Domain Communication Policies are configured | Medium | Domains Allowed Status:All Domains Allowed | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Guest Users are reviewed and disabled | Medium | Guest Accounts:15 | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure All Microsoft 365 Users are licensed | Medium | Users Not Licensed:17835 | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Microsoft 365 Users Password Expires | Medium | Password Never Expires Set:0 | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Users can read all attributes in Azure AD is disabled | Medium | Permission Status:Enabled-Not Ok | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Microsoft Teams External Access Policies are configured | Low | Status:Not Configured:EnableFederationAccess is set to True | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Microsoft 365 Groups Without Members are Identified | Low | Groups Without Members:118 | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure the Account Provisioning Activity report is reviewed and actioned | Passed | Account Provisioning Items:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure non-global administrator role group assignments are reviewed and actioned | Passed | Status:Found non-admin Global Role assignments found in past 7 days | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Security Defaults is disabled on Azure Active Directory | Passed | Status:Security Defaults are disabled. | Enabled. | N/A | SP v1.0 | YES |
| Not Available | Ensure the self-service password reset activity report is reviewed and actioned | Passed | Status:Changed Password Found via SSPR | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure the Azure AD Risky sign-ins report is reviewed at least weekly | Passed | Status:No Risky user found | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure mailbox auditing for E3 users is Enabled | Passed | Missing Mailbox Auditing:0 | AuditEnabled: True for all mailboxes except below: - Resource Mailboxes - Public Folder Mailboxes - DiscoverySearch Mailbox **AuditAdmin:** ApplyRecord, Create, HardDelete, MoveToDeletedItems, SendAs, SendOnBehalf, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules **AuditDelegate:** ApplyRecord, Create, HardDelete, MoveToDeletedItems, SendAs, SendOnBehalf, SoftDelete, Update, UpdateFolderPermissions, UpdateInboxRules **AuditOwner:** ApplyRecord, HardDelete, MoveToDeletedItems, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules | N/A | SP v1.0 | YES |
| Not Available | Ensure mailbox auditing for E5 users is Enabled | Passed | Missing Mailbox Auditing:0 | AuditEnabled: True for all mailboxes except below: - Resource Mailboxes - Public Folder Mailboxes - DiscoverySearch Mailbox **AuditAdmin:** ApplyRecord, Create, HardDelete, MailItemsAccessed, MoveToDeletedItems, Send, SendAs, SendOnBehalf, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules **AuditDelegate:** ApplyRecord, Create, HardDelete, MailItemsAccessed, MoveToDeletedItems, SendAs, SendOnBehalf, SoftDelete, Update, UpdateFolderPermissions, UpdateInboxRules **AuditOwner:** ApplyRecord, HardDelete, MailItemsAccessed, MoveToDeletedItems, Send, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules | N/A | SP v1.0 | YES |
| Not Available | Ensure Transport Rules to Block Exchange Auto-Forwarding is configured | Passed | Status:Configured | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Do Not Bypass the Safe Attachments Filter is not configured | Passed | Status:Not Configured | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Do Not Bypass the Safe Links Feature is not configured | Passed | Status:Not Configured | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Exchange Modern Authentication is Enabled | Passed | Status:Enabled | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Transport Rules to Block Executable Attachments are configured | Passed | Status:Configured | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Malware Filter Policies Alert for Internal Users Sending Malware is configured | Passed | Status:Configured | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Mailbox Auditing is Enabled at Tenant Level | Passed | Status:Enabled | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Mailboxes without Mailbox Auditing are not present | Passed | Mailboxes Without Auditing:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure mail transport rules do not forward email to external domains | Passed | Mails Forwarding Rules Enabled:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure the Advanced Threat Protection Safe Links policy is enabled | Passed | Status:Not Enabled-Not Implemented | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure the Advanced Threat Protection SafeAttachments policy is enabled | Passed | Status:Not Enabled-Not Implemented | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure mailbox auditing for all users is Enabled | Passed | Missing Mailbox Auditing:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure mail forwarding rules are reviewed and actioned | Passed | Forwarding Rules To External Domains:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure the Malware Detections report is reviewed at least weekly | Passed | Malware Report Items:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Microsoft 365 Deleted Mailboxes are identified and Verified | Passed | Deleted Mailboxes:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Exchange Online Mailbox Auditing is enabled | Passed | Mailboxes Without Auditing:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Microsoft 365 Exchange Online Admin Success and Failure Attempts | Passed | Failures for Online Admins:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Microsoft 365 Exchange Online External Access Admin Success and Failure Attempts | Passed | Failures for External Admins:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure custom script execution is restricted on site collections | Passed | Not Restricted for Sites:0 | DenyAddAndCustomizePages `$true` or `Enabled` | N/A | SP v1.0 | YES |
| Not Available | SharePoint Online Modern Authentication is Enabled | Passed | Status:Enabled | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure communication with Skype users is disabled | Passed | Status:Restricted | '- AllowPublicUsers : `True` | N/A | SP v1.0 | YES |
| Not Available | Ensure Microsoft 365 User Roles have less than 10 Admins | Passed | Total Number of Roles having more than 10 Admins:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Microsoft 365 Users Have Strong Password Requirements Configured | Passed | Users With Weak Password Requirements:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure self-service password reset is enabled | Passed | Status:Enabled | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Microsoft 365 Exchange Online Modern Authentication is Used | Passed | Status:Enabled | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Deleted Microsoft 365 Users are Identified | Passed | Deleted Users:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Disabled Microsoft 365 Users are Identified | Passed | Disabled Users:3031 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Microsoft 365 Blocked Users are Identified | Passed | Microsoft 365 Users Blocked:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Microsoft 365 Company Administrators have less than 5 Admins | Passed | More Than 5 Company Administrators Status:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Microsoft 365 Deleted and Licensed Users are Identified | Passed | Deleted Users Licensed:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Users are allowed to create and register applications is disabled | Passed | Permission Status:Disabled-Ok | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure All Microsoft 365 Domains Have been verified | Passed | Domains Verification Pending:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Microsoft 365 Domain Services Have Services Assigned | Passed | Domains Without Services:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Microsoft 365 Notification Email is configured | Passed | Notifications Email: | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Microsoft 365 Organization Level Mailbox Auditing is configured | Passed | Status:Enabled | N/A | N/A | SP v1.0 | YES |
| Not Available | Use Just In Time privileged access to Microsoft 365 roles | Manual Check | NONE | N/A | N/A | SP v1.0 | NO |
All Passed Checks Table
Contains Passed Checks for both CIS Benchmark and SmartProfiler Tests.
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 1.1.1 | Ensure Administrative accounts are separate and cloud-only | Passed | Sync-In Admins:0 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 1.1.3 | Ensure that between two and four global admins are designated | Passed | Total Global Admins:3 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 1.1.4 | Ensure administrative accounts use licenses with a reduced application footprint | Passed | Status:Please check licenses assigned | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 1.2.2 | Ensure sign-in to shared mailboxes is blocked | Passed | Sign-In Allowed for Total SharedMailbox:0 | AccountEnabled: `True` | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 1.3.1 | Ensure the Password expiration policy is set to Set passwords to never expire (recommended) | Passed | Missing Password Policies Domains:0 | If the property is not set, a default value of 90 days will be used | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 1.3.4 | Ensure User owned apps and services is restricted | Passed | Status:Restricted | `Let users access the Office Store` is `Checked` `Let users start trials on behalf of your organization` is `Checked` | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 1.3.5 | Ensure internal phishing protection for Forms is enabled | Passed | Forms Phishing Protection:0 | Internal Phishing Protection is enabled. | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 2.1.4 | Ensure Safe Attachments policy is enabled | Passed | Status:Not Enabled-Not Implemented | ``` Identity : Built-In Protection Policy Enable : True Action : Block QuarantineTag : AdminOnlyAccessPolicy Priority : (lowest) ``` | E5 Level 2 | CIS v6.0 | YES |
| 2.1.7 | Ensure that an anti-phishing policy has been created | Passed | Status:Created | N/A | E5 Level 2 | CIS v6.0 | YES |
| 2.1.12 | Ensure the connection filter IP allow list is not used | Passed | Status:Not Used | IPAllowList : {} | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 2.1.13 | Ensure the connection filter safe list is off | Passed | Status:Turned Off | EnableSafeList : False | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 2.1.14 | Ensure inbound anti-spam policies do not contain allowed domains | Passed | Status:Not Allowed | AllowedSenderDomains : {} | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 2.4.4 | Ensure Zero-hour auto purge for Microsoft Teams is on | Passed | Status:License Not Available - Control Not Applicable | On (Default) | E5 Level 1 | CIS v6.0 | YES |
| Not Available | Ensure the Account Provisioning Activity report is reviewed and actioned | Passed | Account Provisioning Items:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure non-global administrator role group assignments are reviewed and actioned | Passed | Status:Found non-admin Global Role assignments found in past 7 days | N/A | N/A | SP v1.0 | YES |
| 3.1.1 | Ensure Microsoft 365 audit log search is Enabled | Passed | Status:Enabled | 180 days | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| Not Available | Ensure Security Defaults is disabled on Azure Active Directory | Passed | Status:Security Defaults are disabled. | Enabled. | N/A | SP v1.0 | YES |
| 5.1.2.1 | Ensure Per-user MFA is disabled | Passed | Total Users Not Enabled with Per MFA:0 | Disabled | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 5.1.2.2 | Ensure third party integrated applications are not allowed | Passed | Status:Not Allowed | Yes (Users can register applications.) | E3 Level 2-E5 Level 2 | CIS v6.0 | YES |
| 5.1.5.2 | Ensure the admin consent workflow is enabled | Passed | Status:Enabled | '- `Users can request admin consent to apps they are unable to consent to`: `No` - `Selected users to review admin consent requests`: `None` - `Selected users will receive email notifications for requests`: `Yes` - `Selected users will receive request expiration reminders`: `Yes` - `Consent request expires after (days)`: `30` | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 5.1.6.2 | Ensure that guest user access is restricted | Passed | Status:Restricted | '- UI: `Guest users have limited access to properties and memberships of directory objects` - PowerShell: `10dae51f-b6af-4016-8d66-8c2a99b929b3` | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 5.1.8.1 | Ensure that password hash sync is enabled for hybrid deployments | Passed | Status:Password Hash Sync is enabled. | '- Microsoft Entra Connect sync `disabled` by default - Password Hash Sync is Microsoft's recommended setting for new deployments | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 5.2.2.6 | Enable Identity Protection user risk policies | Passed | Status: Configured Correctly | N/A | E5 Level 1 | CIS v6.0 | YES |
| 5.2.2.7 | Enable Identity Protection sign-in risk policies | Passed | Status: Configured Correctly | N/A | E5 Level 1 | CIS v6.0 | YES |
| 5.2.2.8 | Ensure sign-in risk is blocked for medium and high risk | Passed | Status: Configured Correctly | N/A | E5 Level 2 | CIS v6.0 | YES |
| Not Available | Ensure the self-service password reset activity report is reviewed and actioned | Passed | Status:Changed Password Found via SSPR | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure the Azure AD Risky sign-ins report is reviewed at least weekly | Passed | Status:No Risky user found | N/A | N/A | SP v1.0 | YES |
| 5.3.2 | Ensure Access reviews for Guest Users are configured | Passed | Status:Access Reviews were found | By default access reviews are not configured. | E5 Level 1 | CIS v6.0 | YES |
| 5.3.3 | Ensure Access reviews for high privileged Azure AD roles are configured | Passed | Status:Access Reviews were found | By default access reviews are not configured. | E5 Level 1 | CIS v6.0 | YES |
| 6.1.1 | Ensure AuditDisabled organizationally is set to False | Passed | Status:Enabled | FALSE | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 6.1.2 | Ensure mailbox audit actions are configured | Passed | Mailbox Audit Config Issues:26106 | `AuditEnabled`: `True` for all mailboxes except below: - Resource Mailboxes - Public Folder Mailboxes - DiscoverySearch Mailbox **AuditAdmin:** ApplyRecord, Create, HardDelete, MailItemsAccessed, MoveToDeletedItems, Send, SendAs, SendOnBehalf, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules **AuditDelegate:** ApplyRecord, Create, HardDelete, MailItemsAccessed, MoveToDeletedItems, SendAs, SendOnBehalf, SoftDelete, Update, UpdateFolderPermissions, UpdateInboxRules **AuditOwner:** ApplyRecord, HardDelete, MailItemsAccessed, MoveToDeletedItems, Send, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| Not Available | Ensure mailbox auditing for E3 users is Enabled | Passed | Missing Mailbox Auditing:0 | AuditEnabled: True for all mailboxes except below: - Resource Mailboxes - Public Folder Mailboxes - DiscoverySearch Mailbox **AuditAdmin:** ApplyRecord, Create, HardDelete, MoveToDeletedItems, SendAs, SendOnBehalf, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules **AuditDelegate:** ApplyRecord, Create, HardDelete, MoveToDeletedItems, SendAs, SendOnBehalf, SoftDelete, Update, UpdateFolderPermissions, UpdateInboxRules **AuditOwner:** ApplyRecord, HardDelete, MoveToDeletedItems, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules | N/A | SP v1.0 | YES |
| Not Available | Ensure mailbox auditing for E5 users is Enabled | Passed | Missing Mailbox Auditing:0 | AuditEnabled: True for all mailboxes except below: - Resource Mailboxes - Public Folder Mailboxes - DiscoverySearch Mailbox **AuditAdmin:** ApplyRecord, Create, HardDelete, MailItemsAccessed, MoveToDeletedItems, Send, SendAs, SendOnBehalf, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules **AuditDelegate:** ApplyRecord, Create, HardDelete, MailItemsAccessed, MoveToDeletedItems, SendAs, SendOnBehalf, SoftDelete, Update, UpdateFolderPermissions, UpdateInboxRules **AuditOwner:** ApplyRecord, HardDelete, MailItemsAccessed, MoveToDeletedItems, Send, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules | N/A | SP v1.0 | YES |
| 6.2.1 | Ensure all forms of mail forwarding are blocked and-or disabled | Passed | Mails Forwarding Rules Enabled:0 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 6.2.2 | Ensure mail transport rules do not whitelist specific domains | Passed | Whitelist Domains:0 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| Not Available | Ensure Transport Rules to Block Exchange Auto-Forwarding is configured | Passed | Status:Configured | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Do Not Bypass the Safe Attachments Filter is not configured | Passed | Status:Not Configured | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Do Not Bypass the Safe Links Feature is not configured | Passed | Status:Not Configured | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Exchange Modern Authentication is Enabled | Passed | Status:Enabled | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Transport Rules to Block Executable Attachments are configured | Passed | Status:Configured | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Malware Filter Policies Alert for Internal Users Sending Malware is configured | Passed | Status:Configured | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Mailbox Auditing is Enabled at Tenant Level | Passed | Status:Enabled | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Mailboxes without Mailbox Auditing are not present | Passed | Mailboxes Without Auditing:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure mail transport rules do not forward email to external domains | Passed | Mails Forwarding Rules Enabled:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure the Advanced Threat Protection Safe Links policy is enabled | Passed | Status:Not Enabled-Not Implemented | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure the Advanced Threat Protection SafeAttachments policy is enabled | Passed | Status:Not Enabled-Not Implemented | N/A | N/A | SP v1.0 | YES |
| 2.1.7 | Ensure that an anti-phishing policy has been created | Passed | Status:Created | N/A | E5 Level 2 | CIS v6.0 | YES |
| Not Available | Ensure mailbox auditing for all users is Enabled | Passed | Missing Mailbox Auditing:0 | N/A | N/A | SP v1.0 | YES |
| 6.5.1 | Ensure modern authentication for Exchange Online is enabled | Passed | Status:Enabled | TRUE | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| Not Available | Ensure mail forwarding rules are reviewed and actioned | Passed | Forwarding Rules To External Domains:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure the Malware Detections report is reviewed at least weekly | Passed | Malware Report Items:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Microsoft 365 Deleted Mailboxes are identified and Verified | Passed | Deleted Mailboxes:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Exchange Online Mailbox Auditing is enabled | Passed | Mailboxes Without Auditing:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Microsoft 365 Exchange Online Admin Success and Failure Attempts | Passed | Failures for Online Admins:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Microsoft 365 Exchange Online External Access Admin Success and Failure Attempts | Passed | Failures for External Admins:0 | N/A | N/A | SP v1.0 | YES |
| 7.2.2 | Ensure SharePoint and OneDrive integration with Azure AD B2B is enabled | Passed | Status:Enabled | FALSE | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| Not Available | Ensure custom script execution is restricted on site collections | Passed | Not Restricted for Sites:0 | DenyAddAndCustomizePages `$true` or `Enabled` | N/A | SP v1.0 | YES |
| Not Available | SharePoint Online Modern Authentication is Enabled | Passed | Status:Enabled | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure communication with Skype users is disabled | Passed | Status:Restricted | '- AllowPublicUsers : `True` | N/A | SP v1.0 | YES |
| 8.5.2 | Ensure anonymous users and dial-in callers cant start a meeting | Passed | Status:Restricted | Off (False) | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| Not Available | Ensure Microsoft 365 User Roles have less than 10 Admins | Passed | Total Number of Roles having more than 10 Admins:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Microsoft 365 Users Have Strong Password Requirements Configured | Passed | Users With Weak Password Requirements:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure self-service password reset is enabled | Passed | Status:Enabled | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Microsoft 365 Exchange Online Modern Authentication is Used | Passed | Status:Enabled | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Deleted Microsoft 365 Users are Identified | Passed | Deleted Users:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Disabled Microsoft 365 Users are Identified | Passed | Disabled Users:3031 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Microsoft 365 Blocked Users are Identified | Passed | Microsoft 365 Users Blocked:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Microsoft 365 Company Administrators have less than 5 Admins | Passed | More Than 5 Company Administrators Status:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Microsoft 365 Deleted and Licensed Users are Identified | Passed | Deleted Users Licensed:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Users are allowed to create and register applications is disabled | Passed | Permission Status:Disabled-Ok | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure All Microsoft 365 Domains Have been verified | Passed | Domains Verification Pending:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Microsoft 365 Domain Services Have Services Assigned | Passed | Domains Without Services:0 | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Microsoft 365 Notification Email is configured | Passed | Notifications Email: | N/A | N/A | SP v1.0 | YES |
| Not Available | Ensure Microsoft 365 Organization Level Mailbox Auditing is configured | Passed | Status:Enabled | N/A | N/A | SP v1.0 | YES |
All Affected Objects Table
Contains Affected Objects Items for both CIS Benchmark and SmartProfiler Tests. You can find tests that have affected objects.
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 1.3.2 | Ensure Idle session timeout is set to 3 hours (or less) for unmanaged devices | High | 1 | Not configured. (Idle sessions will not timeout.) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 2.1.9 | Ensure that DKIM is enabled for all Exchange Online Domains | High | 3 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 2.1.10 | Ensure DMARC Records for all Exchange Online domains are published | High | 5 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 4.1 | Ensure devices without a compliance policy are marked not compliant | High | 1 | UI: Compliant Graph: secureByDefault = $false | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 5.2.3.4 | Ensure all member users are MFA capable | High | 1 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.3.5 | Ensure weak authentication methods are disabled | High | 1 | '- SMS : Disabled - Voice Call : Disabled - Email OTP : Enabled | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| Not Available | Ensure Mailboxes External Address Forwarding is not configured | High | 1 | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Exchange Online Mailboxes on Litigation Hold | High | 1 | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Exchange Online SPAM Domains are identified | High | 3 | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure custom script execution is restricted on personal sites | High | 55 | Selected `Prevent users from running custom script on self-service created sites` | N/A | SP v1.0 | NO |
| Not Available | Ensure Microsoft Teams Users Allowed to Preview Links in Messages is disabled | High | 4 | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Microsoft 365 Users Have Changed Passwords | High | 17849 | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Microsoft 365 Licenses are consumed in SKUs | High | 1 | N/A | N/A | SP v1.0 | NO |
| 1.2.1 | Ensure that only organizationally managed-approved public groups exist | Medium | 1 | Public when created from the Administration portal; private otherwise. | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 2.1.8 | Ensure that SPF records are published for all Exchange Domains | Medium | 5 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| Not Available | Ensure Microsoft 365 Hidden Mailboxes are Identified | Medium | 1 | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Guest Users are reviewed and disabled | Medium | 15 | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure All Microsoft 365 Users are licensed | Medium | 17835 | N/A | N/A | SP v1.0 | NO |
| Not Available | Ensure Microsoft 365 Groups Without Members are Identified | Low | 118 | N/A | N/A | SP v1.0 | NO |
| 1.1.3 | Ensure that between two and four global admins are designated | Passed | 3 | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| 6.1.2 | Ensure mailbox audit actions are configured | Passed | 26106 | `AuditEnabled`: `True` for all mailboxes except below: - Resource Mailboxes - Public Folder Mailboxes - DiscoverySearch Mailbox **AuditAdmin:** ApplyRecord, Create, HardDelete, MailItemsAccessed, MoveToDeletedItems, Send, SendAs, SendOnBehalf, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules **AuditDelegate:** ApplyRecord, Create, HardDelete, MailItemsAccessed, MoveToDeletedItems, SendAs, SendOnBehalf, SoftDelete, Update, UpdateFolderPermissions, UpdateInboxRules **AuditOwner:** ApplyRecord, HardDelete, MailItemsAccessed, MoveToDeletedItems, Send, SoftDelete, Update, UpdateCalendarDelegation, UpdateFolderPermissions, UpdateInboxRules | E3 Level 1-E5 Level 1 | CIS v6.0 | YES |
| Not Available | Ensure Disabled Microsoft 365 Users are Identified | Passed | 3031 | N/A | N/A | SP v1.0 | YES |
All Manual Checks Table
Contains Manual Checks for both CIS Benchmark and SmartProfiler Tests.
| CIS Section | Test | Severity | Items | Default Value | CIS Profile | Control Type | Configured Correctly? |
| 1.1.2 | Ensure two emergency access accounts have been defined | Manual Check | NONE | Not defined. | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 1.3.8 | Ensure that Sways cannot be shared with people outside of your organization | Manual Check | NONE | `Let people in your organization share their sways with people outside your organization` - Enabled | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 2.1.5 | Ensure Safe Attachments for SharePoint-OneDrive-Microsoft Teams is Enabled | Manual Check | NONE | N/A | E5 Level 2 | CIS v6.0 | NO |
| 2.2.1 | Ensure emergency access account activity is monitored | Manual Check | NONE | A policy to monitor emergency access accounts does not exist by default. | E5 Level 1 | CIS v6.0 | NO |
| 2.4.3 | Ensure Microsoft Defender for Cloud Apps is Enabled | Manual Check | NONE | Disabled | E5 Level 2 | CIS v6.0 | NO |
| 3.3.1 | Ensure Information Protection sensitivity label policies are published | Manual Check | NONE | The Global sensitivity label policy exists by default. | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.1.2.4 | Ensure access to the Entra admin center is restricted | Manual Check | NONE | No - Non-administrators can access the Microsoft Entra admin center. | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.1.2.5 | Ensure the option to remain signed in is hidden | Manual Check | NONE | Users may select `stay signed in` | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 5.1.2.6 | Ensure LinkedIn account connections is disabled | Manual Check | NONE | LinkedIn integration is enabled by default. | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 5.1.6.1 | Ensure that collaboration invitations are sent to allowed domains only | Manual Check | NONE | Allow invitations to be sent to any domain (most inclusive) | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 5.2.2.9 | Ensure a managed device is required for authentication | Manual Check | NONE | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.2.10 | Ensure a managed device is required to register security information | Manual Check | NONE | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.2.11 | Ensure sign-in frequency for Intune Enrollment is set to Every time | Manual Check | NONE | Sign-in frequency defaults to 90 days. | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.2.12 | Ensure the device code sign-in flow is blocked | Manual Check | NONE | N/A | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.3.3 | Ensure that password protection is enabled for Active Directory | Manual Check | NONE | Enable - Yes Mode - Audit | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.2.3.6 | Ensure system-preferred multifactor authentication is enabled | Manual Check | NONE | Microsoft Managed (Enabled) | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 5.3.4 | Ensure approval is required for Global Administrator role activation | Manual Check | NONE | `Require approval to activate` : `No`. | E5 Level 1 | CIS v6.0 | NO |
| 5.3.5 | Ensure approval is required for Privileged Role Administrator activation | Manual Check | NONE | `Require approval to activate` : `No`. | E5 Level 1 | CIS v6.0 | NO |
| Not Available | Use Just In Time privileged access to Microsoft 365 roles | Manual Check | NONE | N/A | SP v1.0 | NO |
|
| 7.2.8 | Ensure external sharing is restricted by security group | Manual Check | NONE | Unchecked/Undefined | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 9.1.3 | Ensure guest access to content is restricted | Manual Check | NONE | Disabled | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.4 | Ensure Publish to web is restricted | Manual Check | NONE | Enabled for the entire organization Only allow existing codes | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.5 | Ensure Interact with and share R and Python visuals is Disabled | Manual Check | NONE | Enabled | E3 Level 2-E5 Level 2 | CIS v6.0 | NO |
| 9.1.7 | Ensure shareable links are restricted | Manual Check | NONE | Enabled for Entire Organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.8 | Ensure enabling of external data sharing is restricted | Manual Check | NONE | Enabled for the entire organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.9 | Ensure Block ResourceKey Authentication is Enabled | Manual Check | NONE | Disabled for the entire organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.10 | Ensure access to APIs by Service Principals is restricted | Manual Check | NONE | Disabled for the entire organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
| 9.1.11 | Ensure Service Principals cannot create and use profiles | Manual Check | NONE | Disabled for the entire organization | E3 Level 1-E5 Level 1 | CIS v6.0 | NO |
Microsoft 365 Security & Compliance Table
Lists Controls status from Microsoft 365 Security & Compliance panel. Some of the controls belong to CIS Benchmark. You can see status of all controls here.
| Actual Control | MG Control | Score | Mapped to CIS | Remark | Configured Correctly? |
| SelfServicePasswordReset | Ensure 'Self service password reset enabled' is set to 'All' You have 143 of 14822 users who don't have self-service password reset enabled. |
99% |
Ensure Self service password reset enabled is set to All | With self-service password reset in Microsoft Entra ID, users no longer need to engage help desk to reset passwords. This feature works well with Microsoft Entra ID dynamically banned passwords, which prevents easily guessable passwords from being used. |
YES |
| meeting_autoadmitusers_v1 | Only invited users should be automatically admitted to Teams meetings Description not available |
50% |
N/A | Users who aren?t invited to a meeting shouldn?t be let in automatically, because it increases the risk of data leaks, inappropriate content being shared, or malicious actors joining. If only invited users are automatically admitted, then users who weren?t invited will be sent to a meeting lobby. The host can then decide whether or not to let them in. |
YES |
| mdo_recipientlimitperday | Set a daily message limit 100% of users are affected by policies that are configured securely
|
100% |
N/A | Configure the maximum number of recipients that a user can send to within a day. After an account is compromised, attackers commonly use the account to generate spam and phish. Configuring recommended values can reduce the amount of spam and phishing emails |
YES |
| exo_oauth2clientprofileenabled | Ensure modern authentication for Exchange Online is enabled Modern authentication for Exchange Online is enabled |
100% |
Ensure modern authentication for Exchange Online is enabled | Modern authentication in Microsoft 365 enables authentication features like multifactor authentication (MFA) using smart cards, certificate-based authentication (CBA), and third-party SAML identity providers. When you enable modern authentication in Exchange Online, Outlook 2016 and Outlook 2013 use modern authentication to log in 'to Microsoft 365 mailboxes. When you disable modern authentication in Exchange Online, Outlook 2016 and Outlook 2013 use basic authentication to log in to Microsoft 365 mailboxes. When users initially configure certain email clients, like Outlook 2013 and Outlook 2016, they may be required to authenticate using enhanced authentication mechanisms, such as multifactor authentication. Other Outlook clients that are available in Microsoft 365 (for example, Outlook Mobile and Outlook for Mac 2016) always use modern uthentication to log in to Microsoft 365 mailboxes |
YES |
| exo_mailboxaudit | Ensure mailbox auditing for all users is Enabled Mailbox auditing for all users is enabled |
100% |
Ensure mailbox auditing for E3 users is Enabled | By turning on mailbox auditing, Microsoft 365 back office teams can track logons to a mailbox as well as what actions are taken while the user is logged on. After you turn on mailbox audit logging for a mailbox, you can search the audit log for mailbox activity. Additionally, when mailbox audit logging is turned on, some actions performed by administrators, delegates, and owners are logged by default. Rationale:Starting in January 2019, Microsoft is turning on mailbox audit logging by default for all organizations. This means that certain actions performed by mailbox owners, delegates, and admins are automatically logged, and the corresponding mailbox audit records will be available when you search for them in the mailbox audit log. When mailbox auditing on by default is turned on for the organization, the AuditEnabled property for affected mailboxes won't be changed from False to True. In other words, mailbox auditing on by default ignores the AuditEnabled property on mailboxes. However, only certain mailbox types support default auditing setting 'On': User Mailboxes, Shared Mailboxes, and Microsoft 365 Group Mailboxes. The remaining mailbox types require auditing to be turned on at the mailbox level: Resource Mailboxes, Public Folder Mailboxes, and DiscoverySearch Mailbox. Whether it is for regulatory compliance or for tracking unauthorized configuration changes in Microsoft 365, enabling mailbox auditing allows for Microsoft 365 back office teams to run security operations, forensics or general investigations on mailbox activities. NOTE: Without advanced auditing (E5 function) the logs are limited to 90 days. |
YES |
| mdo_zapmalware | Create zero-hour auto purge policies for malware 100% of users are affected by policies that are configured securely
|
100% |
N/A | Zero-hour auto purge (ZAP) quarantines the message that contains malware attachment for both read, as well as unread, messages that are found to contain malware after delivery. Only admins can view and manage messages that have been quarantined. For additional information, see Zero-hour auto purge (ZAP) in Exchange Online. " |
YES |
| RoleOverlap | Use least privileged administrative roles You have 141 users with least privileged administrative roles. |
100% |
N/A | Ensure that your administrators can accomplish their work with the least amount of privilege assigned to their account. Assigning users roles like Password Administrator or Exchange Online Administrator, instead of Global Administrator, reduces the likelihood of a global administrative privileged account being breached. |
YES |
| mip_search_auditlog | Ensure Microsoft 365 audit log search is Enabled Microsoft 365 audit log search is enabled |
100% |
Ensure Microsoft 365 audit log search is Enabled | When audit log search in the Microsoft Purview compliance portal is enabled, user and admin activity from your organization is recorded in the audit log and retained for 90 days. However, your organization might be using a third-party security information and event management (SIEM) application to access your auditing data. In that case, a global admin can turn off audit log search in Microsoft 365. |
YES |
| mdo_recipientinternallimitperhour | Set maximum number of internal recipients that a user can send to within an hour 100% of users are affected by policies that are configured securely
|
100% |
N/A | Configure the maximum number of recipients that a user can send to per hour for internal recipients. After an account is compromised, attackers commonly use the account to generate spam and phish. Configuring recommended values can reduce the amount of spam and phishing emails |
YES |
| mdo_spamaction | Set action to take on spam detection 100% of users are affected by policies that are configured securely
|
100% |
N/A | Set the action that will be taken on spam detection. |
YES |
| mdo_autoforwardingmode | Set automatic email forwarding rules to be system controlled 100% of users are affected by policies that are configured securely
|
100% |
N/A | YES |
|
| mdo_highconfidencephishaction | Set action to take on high confidence phishing detection 100% of users are affected by policies that are configured securely
|
100% |
N/A | Set the action that will be taken on high confidence phishing detection. |
YES |
| mdo_bulkspamaction | Set action to take on bulk spam detection 100% of users are affected by policies that are configured securely
|
100% |
N/A | Set the action that will be taken on bulk spam detection. |
YES |
| exo_transportrulesallowlistdomains | Ensure Spam confidence level (SCL) is configured in mail transport rules with specific domains Spam confidence level (SCL) is not configured in mail transport rules with specific domain |
100% |
N/A | You should set Spam confidence level (SCL) in your Exchange Online mail transport rules with specific domains. Allow-listing domains in transport rules bypasses regular malware and phishing scanning, which can enable an attacker to launch attacks against your users from a safe haven domain.
Note: In order to get a score for this security control, all the active transport rule that applies to specific domains must have a Spam Confidence Level (SCL) of 0 or higher. " |
YES |
| mdo_recipientexternallimitperhour | Set maximum number of external recipients that a user can email per hour 100% of users are affected by policies that are configured securely
|
100% |
N/A | Configure the maximum number of external recipients that a user can email per hour. After an account is compromised, attackers commonly use the account to generate spam and phish. Configuring recommended values can reduce the amount of spam and phishing emails |
YES |
| meeting_anonymousstartmeeting_v1 | Restrict anonymous users from starting Teams meetings Description not available |
100% |
N/A | If anonymous users are allowed to start meetings, they can admit any users from the lobbies, authenticated or otherwise. Anonymous users haven?t been authenticated, which can increase the risk of data leakage. |
YES |
| mdo_zapphish | Create zero-hour auto purge policies for phishing messages 100% of users are affected by policies that are configured securely
|
100% |
N/A | For read or unread messages that are identified as phishing after delivery, the ZAP outcome depends on the action that's configured for a Phishing email filtering verdict in the applicable anti-phishing policy. For additional information, see Zero-hour auto purge (ZAP) in Exchange Online. " |
YES |
| PWAgePolicyNew | Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)' Your current policy is set to never let passwords expire. |
100% |
Ensure the Password expiration policy is set to Set passwords to never expire (recommended) | Research has found that when periodic password resets are enforced, passwords become less secure. Users tend to pick a weaker password and vary it slightly for each reset. If a user creates a strong password (long, complex and without any pragmatic words present) it should remain just as strong in the future as it is today. It is Microsoft's official security position to not expire passwords periodically without a specific reason, and recommends that cloud-only tenants set the password policy to never expire. |
YES |
| OneAdmin | Designate more than one global admin You currently have 3 global admins. |
100% |
Ensure that between two and four global admins are designated | Having more than one global administrator helps if you are unable to fulfill the needs or obligations of your organization. It's important to have a delegate or an emergency account someone from your team can access if necessary. It also allows admins the ability to monitor each other for signs of a breach. Note: According to CIS O365 Benchmark 2.0.0, the suggestion is to have between two to four global admins. Currently, the condition to comply is to have more than one global administrator - This security recommendation will be updated accordingly to CIS benchmark in the future. Rationale:If there is only one global tenant administrator, he or she can perform malicious activity without the possibility of being discovered by another admin. If there are numerous global tenant administrators, the more likely it is that one of their accounts will be successfully breached by an external attacker. |
YES |
| mdo_zapspam | Create zero-hour auto purge policies for spam messages 100% of users are affected by policies that are configured securely
|
100% |
Ensure Zero-hour auto purge for Microsoft Teams is on | For unread messages that are identified as spam after delivery, the ZAP outcome depends on the action that's configured for the Spam filtering verdict in the applicable anti-spam policy. For additional information, see Zero-hour auto purge (ZAP) in Exchange Online. " |
YES |
| mdo_enablemailboxintelligence | Ensure that mailbox intelligence is enabled 100% of users are affected by policies that are configured securely
|
100% |
N/A |
Turns on artificial intelligence (AI) that identifies users? email patterns with their frequent contacts to spot potential phishing attempts.
|
YES |
| mdo_connectionfilter | Don't add allowed IP addresses in the connection filter policy The allowed IP addresses list in the connection filter policy is empty |
100% |
Ensure the connection filter IP allow list is not used | If you're a Microsoft 365 customer with mailboxes in Exchange Online or a standalone Exchange Online Protection (EOP) customer without Exchange Online mailboxes, EOP offers multiple ways of ensuring that users will receive email from trusted senders. These options include Exchange mail flow rules (also known as transport rules), Outlook Safe Senders, the IP Allow List (connection filtering), and allowed sender lists or allowed domain lists in anti-spam policies. Collectively, you can think of these options as safe sender lists. Without additional verification like mail flow rules, email from sources in the IP Allow List skips spam filtering and sender authentication (SPF, DKIM, DMARC) checks. Since the IP Allow List doesn't prevent malware or high confidence phishing messages from being filtered, this creates a high risk of attackers successfully delivering email to an inbox that would otherwise be filtered. |
YES |
| IntegratedApps | Ensure user consent to apps accessing company data on their behalf is not allowed You have no user consent policy in place. |
0% |
Ensure user consent to apps accessing company data on their behalf is not allowed | To reduce the risk of malicious applications attempting to trick users into granting them access to your organization's data, we recommend that you allow user consent only for applications that have been published by a verified publisher. |
NO |
| PasswordHashSync | Ensure that password hash sync is enabled for hybrid deployments You have disabled password hash sync. |
0% |
Ensure that password hash sync is enabled for hybrid deployments | Password hash synchronization is one of the sign-in methods used to accomplish hybrid identity. Microsoft Entra ID Connect synchronizes a hash of the hash of a user's password from an on-premises Active Directory instance to a cloud-based Microsoft Entra ID instance. Password hash synchronization helps by reducing the number of passwords your users need to maintain to just one. Enabling password hash synchronization also allows for leaked credential reporting. |
NO |
| SigninRiskPolicy | Enable Microsoft Entra ID Identity Protection sign-in risk policies You have 14822 of 14822 users that don't have the sign-in risky policy turned on. |
0% |
N/A | Turning on the sign-in risk policy ensures that suspicious sign-ins are challenged for multifactor authentication (MFA). |
NO |
| UserRiskPolicy | Enable Microsoft Entra ID Identity Protection user risk policies You have 14822 users out of 14822 that do not have user risk policy enabled. |
0% |
N/A | With the user risk policy turned on, Microsoft Entra ID detects the probability that a user account has been compromised. As an administrator, you can configure a user risk Conditional Access policy to automatically respond to a specific user risk level. For example, you can block access to your resources or require a password change to get a user account back into a clean state. |
NO |
| AdminMFAV2 | Ensure multifactor authentication is enabled for all users in administrative roles You have 7 out of 7 users with administrative roles that aren?t registered and protected with MFA. |
0% |
Ensure multifactor authentication is enabled for all users in administrative roles | Requiring multifactor authentication (MFA) for administrative roles makes it harder for attackers to access accounts. Administrative roles have higher permissions than typical users. If any of those accounts are compromised, your entire organization is exposed. At a minimum, protect the following roles:
|
NO |
| BlockLegacyAuthentication | Enable Conditional Access policies to block legacy authentication You have 14822 of 14822 users that don't have legacy authentication blocked. |
0% |
Enable Conditional Access policies to block legacy authentication | Today, most compromising sign-in attempts come from legacy authentication. Older office clients such as Office 2010 don?t support modern authentication and use legacy protocols such as IMAP, SMTP, and POP3. Legacy authentication does not support multifactor authentication (MFA). Even if an MFA policy is configured in your environment, bad actors can bypass these enforcements through legacy protocols. |
NO |
| MFARegistrationV2 | Ensure multifactor authentication is enabled for all users You have 14822 out of 14822 users that aren?t registered with MFA. |
0% |
Ensure multifactor authentication is enabled for all users | Multifactor authentication (MFA) helps protect devices and data that are accessible to these users. Adding more authentication methods, such as the Microsoft Authenticator app or a phone number, increases the level of protection if one factor is compromised. |
NO |
| mip_purviewlabelconsent | Extend M365 sensitivity labeling to assets in Microsoft Purview data map The setting was not enabled. |
0% |
N/A |
To get work done, people in your organization collaborate with others both inside and outside the organization. Data doesn't always stay in your cloud, and often roams everywhere?across devices, apps, and services. When your data roams, you still want it to be secure in a way that meets your organization's business and compliance policies.
Applying sensitivity labels to your content helps you keep your data secure by stating how sensitive certain data is in your organization. It also abstracts the data itself, letting you track the type of data without exposing sensitive data on other platforms. For example, applying the sensitivity label ?highly confidential? to a document that contains social security numbers and credit card numbers helps you identify the sensitivity of the document without knowing the actual data in the document. The sensitivity labels created in Microsoft Purview Information Protection can also be extended to the Microsoft Purview data map. When you apply a label on an office document and then scan it into the Microsoft Purview data map, the label will be applied to the data asset. |
NO |
| mdo_blockmailforward | Ensure all forms of mail forwarding are blocked and/or disabled 100% of users are affected by policies that are configured less securely than is recommended
|
0% |
Ensure all forms of mail forwarding are blocked and-or disabled | Exchange Online offers several methods of managing the flow of email messages.
NOTE:
Rationale:Attackers often create these rules to exfiltrate data from your tenancy, this could be accomplished via access to an end-user account or otherwise. An insider could also use one of these methods as an secondary channel to exfiltrate sensitive data. |
NO |
| mdo_antiphishingpolicies | Ensure that an anti-phishing policy has been created 100% of users are affected by policies that are configured less securely than is recommended
|
0% |
Ensure that an anti-phishing policy has been created | By default, Office 365 includes built-in features that help protect users from phishing attacks. Set up anti-phishing polices to increase this protection, for example by refining settings to better detect and prevent impersonation and spoofing attacks. The default policy applies to all users within the organization, and is a single view to fine-tune anti-phishing protection. Custom policies can be created and configured for specific users, groups or domains within the organization and will take precedence over the default policy for the scoped users. Rationale: Protects users from phishing attacks (like impersonation and spoofing), and uses safety tips to warn users about potentially harmful messages. |
NO |
| exo_outlookaddins | Ensure users installing Outlook add-ins is not allowed Installing Outlook add-ins configuration is disabled |
0% |
Ensure users installing Outlook add-ins is not allowed | Specify the administrators and users who can install and manage add-ins for Outlook in Exchange Online By default, users can install add-ins in their Microsoft Outlook Desktop client, allowing data access within the client application. Rationale:Attackers exploit vulnerable or custom add-ins to access user data. Disabling user installed add-ins in Microsoft Outlook reduces this threat surface. |
NO |
| mip_autosensitivitylabelspolicies | Ensure that Auto-labeling data classification policies are set up and used Policies were published on 0 of the 14806 users |
0% |
N/A |
Create auto-labeling policies to automatically apply sensitivity labels to email messages or OneDrive and SharePoint files that contain sensitive info.
This ability to apply sensitivity labels to content automatically is important because: You don't need to train your users on the appropriate way to use each of your classifications. You don't need to rely on users to classify all content correctly. Users no longer need to know about your policies?they can instead focus on their work. |
NO |
| mip_sensitivitylabelspolicies | Publish M365 sensitivity label data classification policies Policies were published on 1 of the 14806 users |
0% |
N/A | Set up and use data classification policies on data stored in your users' Office apps (like Outlook and Word), SharePoint sites, and Office 365 groups.
The policies will help categorize your most important data so you can effectively protect it from illicit access and will help make it easier to investigate discovered breaches. Creation of data classification policies will not cause a significant impact to an organization. However, ensuring long term adherence with policies can potentially be a significant training and ongoing compliance effort across an organization. Organizations should ensure that training and compliance planning is part of the classification policy creation process. This information was taken from Center for Internet Security (CIS). |
NO |
| mdo_safelinksforOfficeApps | Ensure Safe Links for Office Applications is Enabled 100% of users aren?t affected by policies set from the following domains
|
0% |
Ensure Safe Links for Office Applications is Enabled | Enabling Safe Links policy for Office applications allows URL's that exist inside of Office documents and email applications opened by Office, Office Online and Office mobile to be processed against Defender for Office time-of-click verification and rewritten if required. |
NO |
| exo_mailtipsenabled | Ensure MailTips are enabled for end users MailTips for end users are disabled. |
0% |
Ensure MailTips are enabled for end users | MailTips assist end users with identifying strange patterns to emails they send. |
NO |
| AATP_DefenderForIdentityIsNotInstalled | Start your Defender for Identity deployment, installing Sensors on Domain Controllers and other eligible servers. Description not available |
0% |
N/A | Installing Microsoft Defender for Identity sensors provides you with the ability to detect advanced threats in your entire identity infrastructure. Actionable security alerts are generated through the analysis of network traffic and security events. |
NO |
| spo_legacy_auth | Ensure modern authentication for SharePoint applications is required The setting is not compliant. |
0% |
Ensure modern authentication for SharePoint applications is required |
Modern authentication in Microsoft 365 enables authentication features like multifactor authentication (MFA) using smart cards, certificate-based authentication (CBA), and third-party SAML identity providers.
Strong authentication controls, such as the use of multifactor authentication, may be circumvented if basic authentication is used by SharePoint applications. Requiring modern authentication for SharePoint applications ensures strong authentication mechanisms are used when establishing sessions between these applications, SharePoint, and connecting users. This information was taken from Center for Internet Security (CIS). |
NO |
| mdo_safeattachmentpolicy | Ensure Safe Attachments policy is enabled 100% of users aren?t affected by policies set from the following domains
|
0% |
Ensure Safe Attachments policy is enabled | The Safe Attachments policy helps protect users from malware in email attachments by Rationale:Enabling Safe Attachments policy helps protect against malware threats in email attachments by analyzing suspicious attachments in a secure, cloud-based environment before they are delivered to the user's inbox. This provides an additional layer of security and can prevent new or unseen types of malware from infiltrating the organization's network. |
NO |
| mdo_spam_notifications_only_for_admins | Ensure Exchange Online Spam Policies are set to notify administrators 100% of users are affected by policies that are configured less securely than is recommended
|
0% |
Ensure Exchange Online Spam Policies are set correctly | In Microsoft 365 organizations with mailboxes in Exchange Online or standalone Exchange Online Protection (EOP) organizations without Exchange Online mailboxes, email messages are automatically protected against spam (junk email) by EOP. Configure Exchange Online Spam Policies to copy emails and notify someone when a sender in the organization has been blocked for sending spam emails.
Note: Audit and Remediation guidance may focus on the Default policy however, if a Custom Policy exists in the organization's tenant, then ensure the setting is set as |
NO |
| exo_storageproviderrestricted | Ensure additional storage providers are restricted in Outlook on the web Additional storage providers are restricted in Outlook on the web is not configured correctly. Please follow next steps to correctly configure the control. |
0% |
Ensure external storage providers available in Outlook on the Web are restricted | This setting allows users to open certain external files while working in Outlook on the Ensure AdditionalStorageProvidersAvailable is restricted. Rationale:By default additional storage providers are allowed in Office on the Web (such as Box, |
NO |
| mdo_unusualcharacterssafetytips | Enable the user impersonation unusual characters safety tip? 100% of users are affected by policies that are configured less securely than is recommended
|
0% |
N/A |
This setting specifies whether to enable the safety tip that is shown to recipients for unusual characters in domain and user impersonation detections.
When the ‘Show user impersonation unusual safety tip’ is enabled, the tip is shown to recipients in messages where the sender's name or email address contains characters that are not typically used together, such as a mix of mathematical symbols and plain text or a mix of uppercase and lowercase letters. Example tip: ‘The email address MARY@CoNT?SO.C?M includes unexpected letters or numbers. We recommend you do not interact with this message.’ This setting is available only if the ‘Enable impersonated user protection’ setting is configured properly. |
NO |
| CustomerLockBoxEnabled | Ensure the customer lockbox feature is enabled Feature in place: false. |
0% |
Ensure the customer lockbox feature is enabled | Turning on the customer lockbox feature requires that approval is obtained for datacenter operations that grants a Microsoft employee direct access to your content. Access may be needed by Microsoft support engineers if an issue arises. There's an expiration time on the request and content access is removed after the support engineer has fixed the issue. |
NO |
| mdo_safedocuments | Turn on Safe Documents for Office Clients Description not available |
0% |
N/A | Safe Documents uses Microsoft Defender for Endpoint to scan documents and files for malicious content. To keep you protected, Safe Documents sends files to the Defender for Endpoint cloud for analysis. Files sent by Safe Documents are not retained in Defender for Endpoint beyond the time needed for analysis (typically, less than 24 hours). |
NO |
| exo_individualsharing | Ensure 'External sharing' of calendars is not available Description not available |
0% |
Ensure External sharing of calendars is not available | Users should not be allowed to share the full details of their calendars with external users. |
NO |
| mdo_safeattachments | Turn on Safe Attachments in block mode 100% of users aren?t affected by policies set from the following domains
|
0% |
N/A | Safe Attachments in block mode prevents messages with detected malware attachments from being delivered. These messages are quarantined and only admins (not regular users) can review, release, or delete them. This will also automatically block future malware attachments.
MDO Built-in protection policy provides safe attachments protection for everyone by default. You could also create additional Safe Attachment policies for customized Safe Attachment operations. |
NO |
| mdo_highconfidencespamaction | Set action to take on high confidence spam detection 100% of users are affected by policies that are configured less securely than is recommended
|
0% |
N/A | Set the action that will be taken on high confidence spam detection. |
NO |
| mdo_commonattachmentsfilter | Ensure the Common Attachment Types Filter is enabled 100% of users are affected by policies that are configured less securely than is recommended
|
0% |
Ensure the Common Attachment Types Filter is enabled | There are certain types of files that are risker to send and receive via email due to the likelihood that they contain malware (for example, executable files). To make sure these file types don't get through, enable the common attachment filter. You can use the default list of file types or customize it. The default file types are: .ace, .ani, .app, .docm, .exe, .jar, .reg, .scr, .vbe, .vbs. Messages with the specified attachments types are treated as malware and are automatically quarantined. |
NO |
| mdo_safelinksforemail | Create Safe Links policies for email messages 100% of users aren?t affected by policies set from the following domains
|
0% |
Ensure Safe Links is Enabled | MDO Built-in protection policy will provide base level safe links protection for everyone by default. You could also create additional Safe Links policies for enhanced or customized Safe Links operations. |
NO |
| meeting_externalrequestcontrol_v1 | Limit external participants from having control in a Teams meeting Description not available |
0% |
Ensure external participants cant give or request control | External participants are users that are outside your organization. Limiting their permission to share content, add new users, and more protects your organization?s information from data leaks, inappropriate content being shared, or malicious actors joining the meeting. |
NO |
| meeting_pstnusersbypasslobby_v1 | Restrict dial-in users from bypassing a meeting lobby Description not available |
0% |
Ensure anonymous users and dial-in callers cant start a meeting | Dial-in users aren?t authenticated though the Teams app. Increase the security of your meetings by preventing these unknown users from bypassing the lobby and immediately joining the meeting. |
NO |
| meeting_restrictanonymousjoin_v1 | Restrict anonymous users from joining meetings current status: On |
0% |
Ensure anonymous users cant join a meeting | By restricting anonymous users from joining Microsoft Teams meetings, you have full control over meeting access. Anonymous users may not be from your organization and could have joined for malicious purposes, such as gaining information about your organization through conversations. |
NO |
| meeting_designatedpresenter_v1 | Configure which users are allowed to present in Teams meetings Description not available |
0% |
Ensure only organizers and co-organizers can present | Only allow users with presenter rights to share content during meetings. Restricting who can present limits meeting disruptions and reduces the risk of unwanted or inappropriate content being shared. |
NO |
| dlp_datalossprevention | Ensure DLP policies are enabled Description not available |
0% |
Ensure DLP policies are enabled | Data Loss Prevention (DLP) policies allows content in multiple locations, such as, devices, Exchange online and Teams chats to be scanned for specific types of data like social security numbers, credit card numbers, or passwords. |
NO |
| mdo_atpprotection | Turn on Microsoft Defender for Office 365 in SharePoint, OneDrive, and Microsoft Teams Description not available |
0% |
Ensure Microsoft Defender for Cloud Apps is Enabled | Microsoft Defender for Office 365 for SharePoint, OneDrive, and Microsoft Teams protects your organization from inadvertently sharing malicious files. |
NO |
| spo_idle_session_timeout | Sign out inactive users in SharePoint Online The setting is not compliant. |
0% |
N/A |
Idle session sign-out lets you specify a time at which users are warned and are later signed out of Microsoft 365 after a period of browser inactivity in SharePoint and OneDrive.
This policy is one of several you can use with SharePoint and OneDrive to balance security and user productivity and help keep your data safe, regardless of where users access the data from, what device they're working on, and how secure their network connection is. |
NO |
| mdo_similardomainssafetytips | Enable the domain impersonation safety tip 100% of users are affected by policies that are configured less securely than is recommended
|
0% |
N/A |
This setting specifies whether to enable the safety tip that is shown to recipients for domain impersonation detections.
When the ‘Show domain impersonation safety tip’ is enabled, the tip “This sender might be impersonating a domain that's associated with your organization” is shown to recipients in messages where the sender's email domain is included in domain impersonation protection. This setting is available only if the ‘Enable impersonated domain protection’ setting is configured properly. |
NO |
| mdo_phishthresholdlevel | Set the phishing email level threshold at 2 or higher 100% of users are affected by policies that are configured less securely than is recommended
|
0% |
N/A |
The threshold controls the sensitivity with which machine learning models are applied to email messages to determine whether a phishing attempt has occurred.
A higher value indicates greater sensitivity. The default value is 1, but 2 or 3 are the recommended values. |
NO |
| mdo_enabledomainstoprotect | Enable impersonated domain protection 100% of users are affected by policies that are configured less securely than is recommended
|
0% |
N/A |
Prevents specified domains from being impersonated?by the message sender's domain.
When you add domains to the ‘Enable domains to protect’ list, messages from?senders in those domains?are subject to impersonation protection checks. The message is checked for impersonation?if?it?s sent to a?recipient?that the policy applies to. If impersonation is detected in the sender's domain, the impersonation protection actions for domains are applied to the message. By default, no sender domains are covered by impersonation protection, either in the default policy or in custom policies. |
NO |
| mdo_similaruserssafetytips | Enable the user impersonation safety tip 100% of users are affected by policies that are configured less securely than is recommended
|
0% |
N/A |
This setting specifies whether to enable the safety tip that is shown to recipients for user impersonation detections.
When the ‘Show user impersonation safety tip’ is enabled, the tip “This sender appears to be similar to someone who previously sent you email but may not be that person” is shown to recipients in messages where the sender's email address is included in user impersonation protection. This setting is available only if the ‘Enable impersonated user protection’ setting is configured properly. |
NO |
| mdo_targetedusersprotection | Enable impersonated user protection 100% of users are affected by policies that are configured less securely than is recommended
|
0% |
N/A |
Prevents specified internal or external email addresses from being impersonated as message senders in phishing attempts.
By default, impersonated user protection is disabled, and no sender email addresses are covered by impersonation protection, whether in the default policy or in custom policies. We highly recommend adding users (message senders) in key roles. Internally, protected senders might be your CEO, CFO, and other senior leaders. Externally, protected senders could include council members or your board of directors. |
NO |
| mdo_targeteduserprotectionaction | Quarantine messages that are detected from impersonated users 100% of users are affected by policies that are configured less securely than is recommended
|
0% |
N/A |
This setting specifies the action to take on detected user impersonation messages.
If a message is detected from an impersonated user, no default action will be taken. We recommend quarantining the message. Whenever you select ‘Quarantine the message’, a ‘Select quarantine policy’ box is available. Quarantine policies define who is allowed to do to quarantined messages. This setting is available only if ‘Enable impersonated user protection’ setting is configured properly. |
NO |
| mdo_targeteddomainprotectionaction | Quarantine messages that are detected from impersonated domains 100% of users are affected by policies that are configured less securely than is recommended
|
0% |
N/A |
This setting specifies the action to take on detected domain impersonation messages.
If a message is detected from an impersonated domain, no action is taken by default. We recommend quarantining the message. This setting is available only if ‘Enable impersonated domain protection’ setting is configured properly. |
NO |
| mdo_allowedsenderscombined | Ensure that no sender domains are allowed for anti-spam policies 100% of users are affected by policies that are configured less securely than is recommended
|
0% |
N/A | Never add your own accepted domains or common domains (for example, microsoft.com or office.com) to the allowed domains list. If these domains are allowed to bypass spam filtering, attackers can easily send messages that spoof these trusted domains to your organization. In addition, avoid adding specific senders that can bypass spam filtering. |
NO |
| mdo_quarantineretentionperiod | Retain spam in quarantine for 30 days 100% of users are affected by policies that are configured less securely than is recommended
|
0% |
N/A | Specifies how long to keep the message in quarantine if you selected “Quarantine message” as the action for a spam filtering verdict. After the time period expires, the message is deleted, and is not recoverable. |
NO |
| mdo_phisspamacation | Set action to take on phishing detection 100% of users are affected by policies that are configured less securely than is recommended
|
0% |
N/A | Set the action that will be taken on phishing detection. |
NO |
| mdo_bulkthreshold | Set the email bulk complaint level (BCL) threshold to be 6 or lower 100% of users are affected by policies that are configured less securely than is recommended
|
0% |
N/A | Specifies the bulk complaint level (BCL) of a message that triggers the specified action for the bulk spam filtering verdict that you configure on the next page. A higher value indicates that the message is less desirable (more likely to resemble spam). While the default value is 7, 6 or lower is the recommended value. |
NO |
| mdo_mailboxintelligenceprotectionaction | Move messages that are detected as impersonated users by mailbox intelligence 100% of users are affected by policies that are configured less securely than is recommended
|
0% |
N/A |
This setting specifies what to do with messages for impersonation detections from mailbox intelligence results.
If a message is detected to be an impersonated user by mailbox intelligence, no action will be applied by default. We recommend moving the message to the recipients? junk email folder and strongly recommend quarantining it. This setting is available only if the ‘Ensure that intelligence for impersonation protection is enabled’ setting is properly configured. |
NO |
| mdo_mailboxintelligenceprotection | Ensure that intelligence for impersonation protection is enabled 100% of users are affected by policies that are configured less securely than is recommended
|
0% |
N/A |
Enables enhanced impersonation results based on each user's individual sender map and allows you to define specific actions for impersonated messages.
This setting is available only if?‘Enable mailbox intelligence’?is selected. |
NO |
| mdo_thresholdreachedaction | Block users who reached the message limit 100% of users are affected by policies that are configured less securely than is recommended
|
0% |
N/A | Configure action to take when any of the limits specified in the outbound anti-spam policy are reached. It is common, after an account compromise incident, for an attacker to use the account to generate spam and phish. Configuring the recommended values can reduce the impact." |
NO |