Block legacy authentication protocols CIS-1.1.2 | Entra ID | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Configure sign-in risk Conditional Access policy CIS-1.2.1 | Entra ID | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Block legacy auth endpoints at the authentication methods policy EIDSCA-AP03 | Entra ID | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by EIDSCA. See runbook for step-by-step remediation. | |
Require MFA for Global Administrator sign-ins CIS-1.1.10 | Entra ID | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enforce Conditional Access for unmanaged devices CIS-1.1.16 | Entra ID | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enforce guest user access review cadence CIS-1.3.1 | Entra ID | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Block legacy POP3 authentication to mailboxes CIS-1.3.7 | Entra ID | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by EIDSCA. See runbook for step-by-step remediation. | |
Disable voice call as a primary authentication method CIS-1.3.13 | Entra ID | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enforce authenticator app lockout policy CIS-1.4.5 | Entra ID | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enforce persistent browser sessions off for unmanaged devices CIS-1.4.11 | Entra ID | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enforce maximum eligible assignment duration for privileged roles EIDSCA-CR13 | Entra ID | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require MFA for Exchange Administrator sign-ins EIDSCA-CR19 | Entra ID | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by EIDSCA. See runbook for step-by-step remediation. | |
Block authentication from anonymous IP ranges EIDSCA-CR25 | Entra ID | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Restrict guest user invitation to specific admin roles NIST-IA-3 | Entra ID | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Block legacy IMAP authentication to mailboxes NIST-IA-9 | Entra ID | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enforce firewall policy on Windows endpoints VT-INTUNE-044 | Intune | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by EIDSCA. See runbook for step-by-step remediation. | |
Require biometric authentication for mobile devices VT-INTUNE-APP-MACOS-MAIL | Intune | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enable spoofing prevention for hybrid deployments CIS-3.6.14 | Exchange | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Configure mailbox audit actions to log admin and delegate activity CISA-EXO.1.1 | Exchange | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Configure SPF hard-fail for all accepted domains CISA-EXO.3.1 | Exchange | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Disable EWS (Exchange Web Services) legacy auth NIST-AU-2 | Exchange | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by EIDSCA. See runbook for step-by-step remediation. | |
Configure Safe Attachments policy for all recipients NIST-AU-8 | Exchange | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Disable PowerShell remote connections for non-admin mailboxes NIST-SI-4 | Exchange | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Restrict external direct-send relay via receive connectors NIST-SI-10 | Exchange | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Disable anonymous calendar sharing ISO-A.8.39 | Exchange | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Disable Basic Auth for POP3 at mailbox level SOC2-CC7.1 | Exchange | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by EIDSCA. See runbook for step-by-step remediation. | |
Enable communication compliance policy for Teams ISO-A.5.31 | Teams | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by EIDSCA. See runbook for step-by-step remediation. | |
Configure spam confidence level thresholds CIS-2.4.11 | Defender | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enable automated investigation for URL compromises CIS-2.5.4 | Defender | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enable standard preset security policy for all users CIS-2.5.10 | Defender | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enable external-sender tagging in Outlook NIST-IR-11 | Defender | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require expiration dates on anonymous share links CIS-5.6.9 | SharePoint | critical | medium | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Configure user-risk Conditional Access policy CIS-1.2.2 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Block external mail auto-forwarding org-wide CIS-3.3.1 | Exchange | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enable Conditional Access for SharePoint access by unmanaged devices CIS-5.4.1 | SharePoint | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require MFA for Exchange Administrator sign-ins CIS-1.1.11 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require MFA for SharePoint Administrator sign-ins CIS-1.1.12 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Block authentication from anonymous IP ranges CIS-1.1.17 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Require compliant device for privileged role activation CIS-1.1.18 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by EIDSCA. See runbook for step-by-step remediation. | |
Restrict guest user invitation to specific admin roles CIS-1.3.2 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Block legacy IMAP authentication to mailboxes CIS-1.3.8 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Block legacy SMTP AUTH authentication CIS-1.3.9 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enforce Authenticator app for passwordless sign-in CIS-1.3.14 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enforce FIDO2 security keys for privileged users CIS-1.3.15 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Configure privileged access workstations for tier-0 admins CIS-1.4.6 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require compliant device for admin access to Microsoft 365 admin center CIS-1.4.7 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Configure Identity Protection weekly digest to Security Operations CIS-1.4.12 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Investigate every flagged-for-review sign-in within 24 hours CIS-1.4.13 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by EIDSCA. See runbook for step-by-step remediation. | |
Require approval workflow for privileged role activation EIDSCA-AF14 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Notify role administrators on privileged role assignment changes EIDSCA-PS15 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require MFA for SharePoint Administrator sign-ins EIDSCA-AF20 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require MFA for Teams Administrator sign-ins EIDSCA-PS21 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require compliant device for privileged role activation EIDSCA-AF26 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enforce maximum sign-in frequency for privileged sessions EIDSCA-PS27 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Prohibit user consent to unverified publisher apps NIST-IA-4 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require admin approval for app consent requests NIST-IA-5 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Block legacy SMTP AUTH authentication NIST-IA-10 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Disable self-service sign-up for guest users CISA-AAD.12.3 | Entra ID | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require device lock password policy on Android CIS-6.8.1 | Intune | high | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Require BitLocker encryption on Windows endpoints VT-INTUNE-APP-ANDROID-MAIL | Intune | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require FileVault encryption on macOS endpoints VT-INTUNE-APP-MACOS-BROWSER | Intune | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Block personal OneDrive sync on corporate Windows VT-INTUNE-APP-WINDOWS-BROWSER | Intune | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require Windows Update for Business ring assignment VT-INTUNE-APP-ANDROID-OFFICE | Intune | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Block external USB storage on corporate devices VT-INTUNE-COMP-010 | Intune | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Configure app configuration policy for Edge (managed) VT-INTUNE-CFG-112 | Intune | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require device lock password policy on Android NIST-CM-11 | Intune | high | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Enforce Microsoft Defender for Endpoint on macOS devices ISO-A.8.25 | Intune | high | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Deploy Microsoft Edge baseline security profile HIPAA-164.310.1.A | Intune | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enable mailbox audit logging on all mailboxes CIS-3.2.2 | Exchange | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Configure mailbox audit actions to log admin and delegate activity CIS-3.2.3 | Exchange | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Configure SPF hard-fail for all accepted domains CIS-3.4.3 | Exchange | high | low | Control evaluates to fail. The tenant is missing the configuration required by EIDSCA. See runbook for step-by-step remediation. | |
Disable EWS (Exchange Web Services) legacy auth CIS-3.6.4 | Exchange | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require quarantine on detected malware attachments CIS-3.6.9 | Exchange | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Configure Safe Attachments policy for all recipients CIS-3.6.10 | Exchange | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Configure mail flow rule to append external-sender banner CIS-3.7.11 | Exchange | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Restrict external direct-send relay via receive connectors CIS-3.7.12 | Exchange | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require MFA for Exchange administrators CISA-EXO.1.2 | Exchange | high | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Configure DMARC with p=reject for all accepted domains CISA-EXO.3.2 | Exchange | high | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Disable Basic Auth for POP3 at mailbox level CISA-EXO.3.3 | Exchange | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Restrict mailbox delegation to approved roles NIST-SI-5 | Exchange | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enable Unified Audit Log tenant-wide ISO-A.8.35 | Exchange | high | low | Control evaluates to fail. The tenant is missing the configuration required by EIDSCA. See runbook for step-by-step remediation. | |
Disable Basic Auth for SMTP AUTH at mailbox level SOC2-CC7.3 | Exchange | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Restrict anti-malware bypass list to approved senders SOC2-CC7.9 | Exchange | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require lobby admission for external meeting participants CIS-4.1.3 | Teams | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enable Safe Links scanning in Teams messages CIS-4.3.3 | Teams | high | low | Control evaluates to fail. The tenant is missing the configuration required by EIDSCA. See runbook for step-by-step remediation. | |
Disable Teams guest access tenant-wide when not needed CIS-4.5.2 | Teams | high | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Block screen sharing from anonymous meeting participants CIS-4.5.3 | Teams | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Disable recording for anonymous meeting participants CIS-4.6.10 | Teams | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Restrict recording transcription to organizers and presenters CISA-TEAMS.1.1 | Teams | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enable DLP policy for Teams chats and channels ISO-A.5.32 | Teams | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enable automatic investigation and remediation (AIR) CIS-2.3.3 | Defender | high | low | Control evaluates to fail. The tenant is missing the configuration required by EIDSCA. See runbook for step-by-step remediation. | |
Configure email authentication alert rule to SOC CIS-2.5.2 | Defender | high | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Enable Attack Simulation Training user outcome tracking CIS-2.4.6 | Defender | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Configure incident response playbook for mailbox takeover CIS-2.5.5 | Defender | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Configure incident response playbook for BEC attempts CIS-2.5.6 | Defender | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enable anti-phishing impersonation protection for VIPs CIS-2.5.11 | Defender | high | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Configure DKIM alignment enforcement CIS-2.5.12 | Defender | high | low | Control evaluates to fail. The tenant is missing the configuration required by EIDSCA. See runbook for step-by-step remediation. | |
Enable Defender for Cloud Apps integration with Defender CISA-DEFENDER.2.2 | Defender | high | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Enable Defender for Identity integration with Entra ID CISA-DEFENDER.2.3 | Defender | high | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Disable SharePoint App Catalog self-service CIS-5.5.3 | SharePoint | high | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Extend Unified Audit Log retention to 12 months CIS-3.1.2 | Exchange | medium | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Block iCloud keychain sync on corporate iOS devices VT-INTUNE-831 | Intune | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Review access privileges via Access Reviews NIST-AC-2.5 | Entra ID | medium | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Require MFA for Teams Administrator sign-ins CIS-1.1.13 | Entra ID | medium | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Require MFA for Compliance Administrator sign-ins CIS-1.1.14 | Entra ID | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enforce maximum sign-in frequency for privileged sessions CIS-1.1.19 | Entra ID | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require password change on high user risk CIS-1.1.20 | Entra ID | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require admin approval for app consent requests CIS-1.3.4 | Entra ID | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Block unmanaged browser access to SharePoint and OneDrive CIS-1.3.5 | Entra ID | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Block authentication attempts from countries not on allowlist CIS-1.3.10 | Entra ID | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require number matching for Microsoft Authenticator push CIS-1.3.11 | Entra ID | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require temporary access passes to expire within 24 hours CIS-1.4.2 | Entra ID | medium | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Configure password protection banned-password list CIS-1.4.3 | Entra ID | medium | low | Control evaluates to fail. The tenant is missing the configuration required by EIDSCA. See runbook for step-by-step remediation. | |
Configure named locations for trusted IP ranges CIS-1.4.8 | Entra ID | medium | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Require MFA for external partner tenant access (B2B) CIS-1.4.9 | Entra ID | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Route Identity Protection alerts to the SIEM EIDSCA-AG10 | Entra ID | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enforce just-in-time access for Exchange Administrator role EIDSCA-AP11 | Entra ID | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require justification for privileged role activation EIDSCA-AG16 | Entra ID | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Configure activation notification recipients for all privileged roles EIDSCA-AP17 | Entra ID | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require MFA for Compliance Administrator sign-ins EIDSCA-AG22 | Entra ID | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require MFA for Security Administrator sign-ins EIDSCA-AP23 | Entra ID | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Disable self-service sign-up for guest users EIDSCA-AP29 | Entra ID | medium | low | Control evaluates to fail. The tenant is missing the configuration required by EIDSCA. See runbook for step-by-step remediation. | |
Block unmanaged browser access to SharePoint and OneDrive NIST-IA-6 | Entra ID | medium | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Restrict local administrator accounts on Windows VT-INTUNE-048 | Intune | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Block personal OneDrive sync on corporate Windows ISO-A.8.22 | Intune | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Deploy Office 365 app baseline security profile HIPAA-164.310.2.B | Intune | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Restrict local administrator accounts on Windows HIPAA-164.310.3.C | Intune | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Configure DMARC with p=reject for all accepted domains CIS-3.5.1 | Exchange | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Disable Basic Auth for POP3 at mailbox level CIS-3.5.2 | Exchange | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Block mail forwarding to external domains by transport rule CIS-3.6.6 | Exchange | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Configure Safe Links policy with click-time protection CIS-3.6.11 | Exchange | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enable anti-phishing policy with impersonation protection CIS-3.6.12 | Exchange | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enforce litigation hold retention for 365 days minimum CIS-3.7.8 | Exchange | medium | low | Control evaluates to fail. The tenant is missing the configuration required by EIDSCA. See runbook for step-by-step remediation. | |
Disable Basic Auth for SMTP AUTH at mailbox level CISA-EXO.4.2 | Exchange | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Block automatic mail forwarding at mailbox level NIST-AU-5 | Exchange | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enable anti-phishing mailbox intelligence NIST-AU-11 | Exchange | medium | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Enable DLP policy for Teams chats and channels CIS-4.5.10 | Teams | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Restrict Teams federation to allow-listed domains CIS-4.6.7 | Teams | medium | low | Control evaluates to fail. The tenant is missing the configuration required by EIDSCA. See runbook for step-by-step remediation. | |
Block consumer OneDrive access in Teams channels CISA-TEAMS.1.3 | Teams | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Restrict guest access to specific team channels CISA-TEAMS.3.3 | Teams | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Block Teams live events creation to approved producers only ISO-A.5.28 | Teams | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Configure Teams data residency for in-region tenants ISO-A.5.34 | Teams | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enable anti-phishing impersonation protection for VIPs CIS-2.2.2 | Defender | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Configure Explorer search persistent queries for IR CIS-2.4.8 | Defender | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enable Defender for Office 365 Plan 2 AIR investigations CIS-2.4.9 | Defender | medium | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Configure spam confidence level thresholds NIST-IR-8 | Defender | medium | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Enable bulk complaint level (BCL) filtering NIST-IR-9 | Defender | medium | low | Control evaluates to fail. The tenant is missing the configuration required by EIDSCA. See runbook for step-by-step remediation. | |
Require MFA for Security Administrator sign-ins CIS-1.1.15 | Entra ID | low | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Disable self-service sign-up for guest users CIS-1.1.21 | Entra ID | low | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enforce sign-in session lifetime for browser-based access CIS-1.3.6 | Entra ID | low | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Disable SMS as a primary authentication method CIS-1.3.12 | Entra ID | low | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Require on-premises password protection agent CIS-1.4.4 | Entra ID | low | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Disable cross-tenant inbound B2B invitations by default CIS-1.4.10 | Entra ID | low | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enforce just-in-time access for Global Reader role EIDSCA-AM12 | Entra ID | low | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require MFA for Global Administrator sign-ins EIDSCA-AM18 | Entra ID | low | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Enforce Conditional Access for unmanaged devices EIDSCA-AM24 | Entra ID | low | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Enforce guest user access review cadence NIST-IA-2 | Entra ID | low | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Block legacy POP3 authentication to mailboxes NIST-IA-8 | Entra ID | low | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Require MFA for SharePoint Administrator sign-ins CSF-ID.AM-8 | Entra ID | low | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Restrict cut-copy-paste outside managed apps VT-INTUNE-061 | Intune | low | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Deploy Microsoft Edge baseline security profile VT-INTUNE-COMP-013 | Intune | low | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Block personal iCloud drive on corporate iOS NIST-CM-3 | Intune | low | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Block external USB storage on corporate devices ISO-A.8.29 | Intune | low | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Restrict calendar sharing to internal users only CIS-3.3.3 | Exchange | low | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enforce retention policy on Exchange mailboxes CIS-3.7.9 | Exchange | low | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Configure DKIM signing for all accepted domains CISA-EXO.2.3 | Exchange | low | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Disable Exchange ActiveSync legacy authentication CISA-EXO.4.3 | Exchange | low | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Block authentication from high-risk IP ranges NIST-SI-3 | Exchange | low | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Disable OAB (Offline Address Book) legacy auth SOC2-CC7.6 | Exchange | low | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Block Teams live events creation to approved producers only CIS-4.5.6 | Teams | low | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Configure Teams data residency for in-region tenants CIS-4.6.2 | Teams | low | low | Control evaluates to fail. The tenant is missing the configuration required by NIST 800-53 r5. See runbook for step-by-step remediation. | |
Disable Teams guest access tenant-wide when not needed CISA-TEAMS.4.1 | Teams | low | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Configure DKIM alignment enforcement CIS-2.2.3 | Defender | low | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |
Enable intra-organization spoof protection NIST-IR-10 | Defender | low | low | Control evaluates to fail. The tenant is missing the configuration required by CIS Microsoft 365 See runbook for step-by-step remediation. | |