CIS Microsoft 365 Foundations Benchmarks
Industry-consensus security configuration benchmarks from the Center for Internet Security.
Official documentation154
Controls
111
Auto-Remediable
7
Domains
Entra ID(63)
CIS-1.1.2Limit Global Administrator role assignments to 5 or fewer
CIS-1.1.23Security defaults disabled when Conditional Access is used
CIS-1.1.3Require MFA for guest access
CIS-1.1.4Admin accounts are cloud-only (not synced from on-premises)
CIS-1.1.5Privileged Identity Management enabled for Global Administrator role
CIS-1.1.6Access review configured for Global Administrator role
CIS-1.1.7Terms of use acceptance required
CIS-1.2.1Require MFA for risky sign-ins
CIS-1.2.2Require MFA for Azure management
CIS-1.2.3Require password change for high-risk users
CIS-1.3.1Require compliant or managed device for all users
CIS-1.3.2Require compliant device for admins
CIS-1.3.3Require MDM-enrolled compliant device for cloud apps
CIS-1.3.4Block access from unsupported device platforms
CIS-1.3.5Use app enforced restrictions for O365
CIS-1.3.6Sign-in frequency configured for session management
CIS-1.4Password expiration set to never expire (with MFA enforced)
CIS-2.1.1Microsoft 365 group expiration policy configured
CIS-2.1.2M365 group creation restricted to admins
CIS-5.2.3Token lifetime policy configured
CIS-6.1.1Enable FIDO2 security keys as authentication method
CIS-M365.1.1.1Administrative accounts are cloud-only
CIS-M365.1.1.3Global Administrator role assigned to 2-4 designated accounts
CIS-M365.1.2.1Public groups restricted to organizationally approved
CIS-M365.1.2.2Sign-in to shared mailboxes blocked
CIS-M365.1.3.1Password expiration policy set to 'never expire'
CIS-M365.1.3.3External calendar sharing unavailable
CIS-M365.1.3.6Customer Lockbox feature enabled
CIS-M365.1.3.8External sharing of Sways blocked
CIS-M365.5.1.1.1Security defaults disabled in Azure Active Directory
CIS-M365.5.1.2.1Per-user MFA disabled (legacy method)
CIS-M365.5.1.2.2Third-party integrated applications blocked
CIS-M365.5.1.2.3Non-admin users restricted from creating tenants
CIS-M365.5.1.2.4Azure AD administration portal restricted to admins
CIS-M365.5.1.2.5Remain-signed-in option hidden at sign-in
CIS-M365.5.1.2.6LinkedIn account connections disabled
CIS-M365.5.1.3.1Dynamic group for guest users exists
CIS-M365.5.1.5.1Application Usage report reviewed weekly
CIS-M365.5.1.5.2User consent to apps accessing company data blocked
CIS-M365.5.1.5.3Admin consent workflow enabled
CIS-M365.5.1.6.1Collaboration invitations restricted to allowed domains
CIS-M365.5.1.8.1Password hash sync enabled for hybrid deployments
CIS-M365.5.2.2.4Admin sign-in frequency enabled with non-persistent browser sessions
CIS-M365.5.2.2.5Phishing-resistant MFA strength required for administrators
CIS-M365.5.2.2.6Azure AD Identity Protection user-risk policies enabled
CIS-M365.5.2.2.7Azure AD Identity Protection sign-in-risk policies enabled
CIS-M365.5.2.2.8Admin center access limited to administrative roles
CIS-M365.5.2.3.1Microsoft Authenticator hardened against MFA fatigue
CIS-M365.5.2.3.2Custom banned password list in use
CIS-M365.5.2.3.3Password protection enabled for on-prem Active Directory
CIS-M365.5.2.3.4All member users MFA-capable
CIS-M365.5.2.4.1Self-service password reset enabled for all users
CIS-M365.5.2.4.2Self-service password reset activity report reviewed weekly
CIS-M365.5.2.6.1Azure AD Risky sign-ins report reviewed weekly
CIS-M365.9.1.1Guest user access restricted
CIS-M365.9.1.2External user invitations restricted
CIS-M365.9.1.3Guest access to content restricted
CIS-M365.9.1.4Publish to web restricted
CIS-M365.9.1.5R and Python visuals interaction/sharing disabled
CIS-M365.9.1.6Users can apply sensitivity labels to content
CIS-M365.9.1.7Shareable links restricted
CIS-M365.9.1.8External data sharing enablement restricted
CIS-M365.9.1.9ResourceKey authentication blocked
Intune(29)
CIS-5.1.1Deploy Microsoft Defender Antivirus baseline
CIS-5.1.2Configure Defender Update Controls
CIS-5.1.3Configure Windows Security Experience
CIS-5.1.4Deploy Windows LAPS
CIS-5.1.5Deploy MacOS Endpoint Security Antivirus
CIS-5.2.10Configure Endpoint Privilege Management
CIS-5.2.2.1Require BitLocker drive encryption
CIS-5.2.2.2Deploy Personal Data Encryption
CIS-5.2.5Configure Exploit Protection
CIS-5.2.6Deploy Edge Security Baseline
CIS-5.2.7Deploy M365 Apps Security Baseline
CIS-5.2.8Configure Device Control
CIS-5.2.9Configure App and Browser Isolation
CIS-5.3.1Deploy Windows Security Baseline
CIS-5.3.2Deploy Windows 365 Security Baseline
CIS-5.3.3Deploy HoloLens 2 Security Baseline
CIS-5.4.1Deploy Defender for Endpoint security baseline
CIS-5.5.1Windows device compliance policy configured
CIS-5.5.2iOS device compliance policy configured
CIS-5.5.3Android device compliance policy configured
CIS-5.5.4macOS device compliance policy configured
CIS-5.5.5Deploy macOS FileVault disk encryption
CIS-5.7.1Enrollment Status Page configured
CIS-5.7.2Device enrollment limit configured
CIS-5.8.1Windows Autopilot deployment profile configured
CIS-6.2.1iOS app protection policy configured
CIS-6.2.2Android app protection policy configured
CIS-6.2.3iOS app protection requires data encryption
CIS-6.2.4Android app protection requires data encryption
SharePoint(21)
CIS-3.1SharePoint idle session sign-out enabled
CIS-3.2Default sharing link type set to Specific People
CIS-3.3External resharing disabled for SharePoint
CIS-3.4Guest access expiration configured for SharePoint
CIS-3.5Default link permission set to View
CIS-3.6Sharing domain restriction configured for SharePoint
CIS-3.7Unmanaged device sync restricted for SharePoint
CIS-3.8SharePoint site creation restricted to admins
CIS-M365.7.2.1Modern authentication required for SharePoint apps
CIS-M365.7.2.10Reauthentication with verification code restricted
CIS-M365.7.2.2SharePoint/OneDrive Azure AD B2B integration enabled
CIS-M365.7.2.3External content sharing restricted
CIS-M365.7.2.4OneDrive content sharing restricted
CIS-M365.7.2.5SharePoint guest users blocked from sharing items they don't own
CIS-M365.7.2.6SharePoint external sharing managed via domain allow/block list
CIS-M365.7.2.7Link sharing restricted in SharePoint and OneDrive
CIS-M365.7.2.8External sharing restricted by security group
CIS-M365.7.2.9Guest access to sites/OneDrive auto-expires
CIS-M365.7.3.1Infected SharePoint files blocked from download
CIS-M365.7.3.2OneDrive sync restricted on unmanaged devices
CIS-M365.7.3.3Custom script execution restricted on personal sites
Exchange(15)
CIS-6.1.1aModern authentication enabled for Exchange Online
CIS-6.1.2MailTips enabled for external recipients
CIS-M365.2.1.1Safe Links enabled for Office applications
CIS-M365.2.1.11Comprehensive attachment filtering applied
CIS-M365.2.1.12Connection filter IP allow list disabled
CIS-M365.2.1.13Connection filter safe list off
CIS-M365.2.1.2Common Attachment Types filter enabled
CIS-M365.2.1.3Notifications enabled when internal users send malware
CIS-M365.2.1.4Safe Attachments policy enabled
CIS-M365.2.1.5Safe Attachments enabled for SharePoint, OneDrive, and Teams
CIS-M365.2.1.6Exchange Online spam policies notify administrators
CIS-M365.2.1.7At least one anti-phishing policy exists
CIS-M365.2.1.9DKIM enabled for all Exchange Online domains
CIS-M365.2.4.4Zero-hour auto purge enabled for Teams
CIS-M365.6.1.4AuditDisabled set to False organizationally
Teams(14)
CIS-M365.8.1.1Teams external file sharing limited to approved cloud storage providers
CIS-M365.8.1.2Channel email addresses blocked from receiving user email
CIS-M365.8.2.2Communication with unmanaged Teams users disabled
CIS-M365.8.2.4Communication with Skype users disabled
CIS-M365.8.4.1Most third-party and custom apps blocked
CIS-M365.8.5.1Anonymous users blocked from joining meetings
CIS-M365.8.5.2Anonymous and dial-in users blocked from starting meetings
CIS-M365.8.5.3Lobby bypass restricted to org users
CIS-M365.8.5.4Dial-in users blocked from bypassing meeting lobby
CIS-M365.8.5.5Meeting chat blocks anonymous users
CIS-M365.8.5.6Only organizers and co-organizers can present
CIS-M365.8.5.7External participants blocked from give/request control
CIS-M365.8.5.8External meeting chat disabled
CIS-M365.8.6.1Users can report Teams security concerns to internal destination
Defender(8)
CIS-M365.2.1.10DMARC records published for all Exchange Online domains
CIS-M365.2.1.14Comprehensive attachment filtering applied
CIS-M365.2.1.8SPF records published for all Exchange domains
CIS-M365.2.3.1Account Provisioning Activity report reviewed weekly
CIS-M365.2.3.2Non-global-admin role assignments reviewed weekly
CIS-M365.2.4.1Priority Account protection enabled and configured
CIS-M365.2.4.2Priority Accounts covered by Strict protection preset
CIS-M365.2.4.3Microsoft Defender for Cloud Apps enabled and configured
Purview(4)
CIS-M365.3.1.1Microsoft 365 unified audit log search enabled
CIS-M365.3.2.1DLP policies enabled
CIS-M365.3.2.2DLP policies enabled for Teams
CIS-M365.3.3.1SharePoint Online Information Protection policies in use
