
Tests authored
- CIS.M365.1.1.3(L1) Ensure that between two and four global admins are designated
- CIS.M365.1.2.1(L2) Ensure that only organizationally managed/approved public groups exist
- CIS.M365.1.2.2(L1) Ensure sign-in to shared mailboxes is blocked
- CIS.M365.1.3.1(L1) Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)'
- CIS.M365.1.3.6(L2) Ensure the customer lockbox feature is enabled
- CIS.M365.2.1.1(L2) Ensure Safe Links for Office Applications is Enabled (Only Checks Default Policy)
- CIS.M365.2.1.2(L1) Ensure the Common Attachment Types Filter is enabled (Only Checks Default Policy)
- CIS.M365.2.1.3(L1) Ensure notifications for internal users sending malware is Enabled (Only Checks Default Policy)
- CIS.M365.2.1.4(L2) Ensure Safe Attachments policy is enabled (Only Checks Default Policy)
- CIS.M365.2.1.5(L2) Ensure Safe Attachments for SharePoint, OneDrive, and Microsoft Teams is Enabled
- CIS.M365.2.1.6(L1) Ensure Exchange Online Spam Policies are set to notify administrators (Only Checks Default Policy)
- CIS.M365.2.1.7(L1) Ensure that an anti-phishing policy has been created (Only Checks Default Policy)
- CIS.M365.2.1.9(L1) Ensure that DKIM is enabled for all Exchange Online Domains
- CIS.M365.2.1.11(L2) Ensure comprehensive attachment filtering is applied
- CIS.M365.2.1.12(L1) Ensure the connection filter IP allow list is not used (Only Checks Default Policy)
- CIS.M365.2.1.13(L1) Ensure the connection filter safe list is off (Only Checks Default Policy)
- CIS.M365.2.4.4(L1) Ensure Zero-hour auto purge for Microsoft Teams is on (Only Checks ZAP is enabled)
- CIS.M365.3.1.1(L1) Ensure Microsoft 365 audit log search is Enabled
Also contributed to
- CIS.M365.1.1.1(L1) Ensure Administrative accounts are cloud-only
- CIS.M365.1.3.3(L2) Ensure 'External sharing' of calendars is not available
- CIS.M365.8.1.1(L2) Ensure external file sharing in Teams is enabled for only approved cloud storage services
- CIS.M365.8.2.2(L1) Ensure communication with unmanaged Teams users is disabled
- CIS.M365.8.4.1(L1) Ensure all or a majority of third-party and custom apps are blocked
- CIS.M365.8.5.3(L1) Ensure only people in my org can bypass the lobby
- CIS.M365.8.6.1(L1) Ensure users can report security concerns in Teams to internal destination
- CISA.MS.AAD.6.1User passwords SHALL NOT expire.
- CISA.MS.EXO.6.1Contact folders SHALL NOT be shared with all domains.
- CISA.MS.EXO.6.2Calendar details SHALL NOT be shared with all domains.
- MT.1053Ensure intune device clean-up rule is configured
- MT.1054Ensure built-in Device Compliance Policy marks devices with no compliance policy assigned as 'Not compliant'
- MT.1058Ensure Microsoft 365 Group (and Team) expiration is configured to auto-expire groups.