CIS Microsoft 365 Foundations Benchmark 3.0.0 Checklist Details (Checklist Revisions)
Supporting Resources:
-
Download Prose - CIS Microsoft 365 Foundations Benchmark v3.0.0
- Center for Internet Security (CIS)
Target:
Target | CPE Name |
---|---|
Microsoft Office 365 ProPlus | cpe:/a:microsoft:office_365_proplus:- (View CVEs) |
Checklist Highlights
- Checklist Name:
- CIS Microsoft 365 Foundations Benchmark
- Checklist ID:
- 1140
- Version:
- 3.0.0
- Type:
- Compliance
- Review Status:
- Final
- Authority:
- Third Party: Center for Internet Security (CIS)
- Original Publication Date:
- 09/28/2023
Checklist Summary:
This document, Security Configuration Benchmark for Microsoft 365, provides prescriptive guidance for establishing a secure configuration posture for Microsoft 365 Cloud offerings running on any OS. This guide was tested against Microsoft 365, and includes recommendations for Exchange Online, SharePoint Online, OneDrive for Business, Teams, Power BI (Fabric) and Azure Active Directory. To ensure all PowerShell related cmdlets work in your tenant please download the latest versions of the PowerShell modules. Scripts and commands referenced in this benchmark were tested using the following modules: ExchangeOnlineManagement 3.3.0 Microsoft.Graph 2.4.0 MicrosoftTeams 5.5.0 Microsoft.Online.SharePoint.PowerShell 16.0.24009.12000 AzureAD 2.0.2.182 To obtain the latest version of this guide, please visit http://cisecurity.org. If you have questions, comments, or have identified ways to improve this guide, please write us at feedback@cisecurity.org.
Checklist Role:
- Business Productivity Application
Known Issues:
This benchmark is intended for system and application administrators, security specialists, auditors, help desk, and platform deployment personnel who plan to develop, deploy, assess, or secure solutions that incorporate Microsoft 365. Where possible audit and remediation guidance is provided using both PowerShell and relevant Admin Centers, using either method is acceptable when attempting to determine a Pass or Fail for a particular recommendation.
Target Audience:
Not provided.
Target Operational Environment:
- Managed
- Specialized Security-Limited Functionality (SSLF)
Testing Information:
Not provided.
Regulatory Compliance:
Not provided.
Comments/Warnings/Miscellaneous:
Not provided.
Disclaimer:
Not provided.
Product Support:
Not provided.
Point of Contact:
feedback@cisecurity.org
Sponsor:
Not provided.
Licensing:
Not provided.
Change History:
new checklist - 2/28/24 updated status to FINAL - 3/28/24
Dependency/Requirements:
URL | Description |
---|
References:
Reference URL | Description |
---|