
Tests authored
- CIS.M365.7.2.2Ensure SharePoint and OneDrive integration with Azure AD B2B is enabled
- CIS.M365.7.2.5Ensure that SharePoint guest users cannot share items they don
- CIS.M365.7.2.7Ensure link sharing is restricted in SharePoint and OneDrive
- CIS.M365.7.2.9Ensure guest access to a site or OneDrive will expire automatically
- CIS.M365.7.2.11Ensure the SharePoint default sharing link permission is set
- CIS.M365.7.3.1Ensure Office 365 SharePoint infected files are disallowed for download
- CIS.M365.8.2.3Ensure external Teams users cannot initiate conversations
- CISA.MS.SHAREPOINT.1.2External sharing for OneDrive SHALL be limited to Existing guests or Only People in your organization.
- CISA.MS.SHAREPOINT.2.1File and folder default sharing scope SHALL be set to Specific People.
- CISA.MS.SHAREPOINT.2.2File and folder default sharing permissions SHALL be set to View only.
- CISA.MS.SHAREPOINT.3.1Expiration days for Anyone links SHALL be set to 30 days or less.
- CISA.MS.SHAREPOINT.3.2Allowable file and folder permissions for Anyone links SHALL be set to View only.
- CISA.MS.SHAREPOINT.3.3Reauthentication days for people who use a verification code SHALL be set to 30 days or less.
Also contributed to
- CIS.M365.1.1.1(L1) Ensure Administrative accounts are cloud-only
- CIS.M365.1.1.3(L1) Ensure that between two and four global admins are designated
- CIS.M365.1.2.1(L2) Ensure that only organizationally managed/approved public groups exist
- CIS.M365.1.2.2(L1) Ensure sign-in to shared mailboxes is blocked
- CIS.M365.1.3.1(L1) Ensure the 'Password expiration policy' is set to 'Set passwords to never expire (recommended)'
- CIS.M365.1.3.3(L2) Ensure 'External sharing' of calendars is not available
- CIS.M365.1.3.4Ensure
- CIS.M365.1.3.5Ensure internal phishing protection for Forms is enabled
- CIS.M365.1.3.6(L2) Ensure the customer lockbox feature is enabled
- CIS.M365.1.3.7Ensure
- CIS.M365.2.1.1(L2) Ensure Safe Links for Office Applications is Enabled (Only Checks Default Policy)
- CIS.M365.2.1.2(L1) Ensure the Common Attachment Types Filter is enabled (Only Checks Default Policy)
- CIS.M365.2.1.3(L1) Ensure notifications for internal users sending malware is Enabled (Only Checks Default Policy)
- CIS.M365.2.1.4(L2) Ensure Safe Attachments policy is enabled (Only Checks Default Policy)
- CIS.M365.2.1.5(L2) Ensure Safe Attachments for SharePoint, OneDrive, and Microsoft Teams is Enabled
- CIS.M365.2.1.6(L1) Ensure Exchange Online Spam Policies are set to notify administrators (Only Checks Default Policy)
- CIS.M365.2.1.7(L1) Ensure that an anti-phishing policy has been created (Only Checks Default Policy)
- CIS.M365.2.1.9(L1) Ensure that DKIM is enabled for all Exchange Online Domains
- CIS.M365.2.1.11(L2) Ensure comprehensive attachment filtering is applied
- CIS.M365.2.1.12(L1) Ensure the connection filter IP allow list is not used (Only Checks Default Policy)
- CIS.M365.2.1.13(L1) Ensure the connection filter safe list is off (Only Checks Default Policy)
- CIS.M365.2.4.4(L1) Ensure Zero-hour auto purge for Microsoft Teams is on (Only Checks ZAP is enabled)
- CIS.M365.3.1.1(L1) Ensure Microsoft 365 audit log search is Enabled
- CIS.M365.4.1Ensure devices without a compliance policy are marked
- CIS.M365.5.1.2.2Ensure third party integrated applications are not allowed
- CIS.M365.5.1.2.3Ensure
- CIS.M365.5.1.3.1Ensure a dynamic group for guest users is created
- CIS.M365.5.1.5.1Ensure user consent to apps accessing company data on their behalf is not allowed
- CIS.M365.5.1.5.2Ensure the admin consent workflow is enabled
- CIS.M365.5.1.6.2Ensure that guest user access is restricted
- CIS.M365.5.2.3.5Ensure weak authentication methods are disabled
- CIS.M365.6.5.3Ensure additional storage providers are restricted in Outlook on the web
- CIS.M365.8.1.1(L2) Ensure external file sharing in Teams is enabled for only approved cloud storage services
- CIS.M365.8.2.2(L1) Ensure communication with unmanaged Teams users is disabled
- CIS.M365.8.4.1(L1) Ensure all or a majority of third-party and custom apps are blocked
- CIS.M365.8.5.3(L1) Ensure only people in my org can bypass the lobby
- CIS.M365.8.6.1(L1) Ensure users can report security concerns in Teams to internal destination
- CISA.MS.SHAREPOINT.1.1External sharing for SharePoint SHALL be limited to Existing guests or Only People in your organization.
- CISA.MS.SHAREPOINT.1.3External sharing SHALL be restricted to approved external domains and/or users in approved security groups per interagency collaboration needs.
- MT.1020All Conditional Access policies are configured to exclude directory synchronization accounts or do not scope them.
- MT.1021Security Defaults are enabled.
- MT.1042Restrict dial-in users from bypassing a meeting lobby
- MT.1045Only invited users should be automatically admitted to Teams meetings
- MT.1046Restrict anonymous users from joining meetings
- MT.1047Restrict anonymous users from starting Teams meetings
- MT.1048Limit external participants from having control in a Teams meeting
- MT.1098Mobile Threat Defense Connectors should be healthy