Harbour ITMenu

Powered by Office Sentry 2.2.0

You're in the demo. Three fictional clients with made-up people. Look around freely: nothing can be changed, and it all resets every night.Get Office Sentry
Clients/Northwind Traders

CIS Microsoft 365 Foundations Benchmark

Northwind Traders · northwindtraders.onmicrosoft.com

The benchmark's recommendations that Office Sentry reads, judged setting by setting, with the fix for each. Use it as the evidence for a CIS-aligned audit or a client's hardening baseline.

Gaps to close

Northwind Traders has 10 controls not in place.

Judged from Microsoft 365 data collected .

Pick a point in time to see which controls passed then and not now, or the other way round: useful before a renewal.

Gaps to close

21 controls
  1. 1 guest with admin roles. For example g#EXT#@northwindtraders.example: Guest holding Exchange Administrator.

    Fix: Remove admin roles from guest accounts. See the rows →

  2. 1 admin not covered by MFA. For example breakglass@northwindtraders.example: Global Administrator: excluded from Require MFA for all users.

    Fix: Have each listed admin register a strong method. See the rows →

  3. Legacy authentication is allowed. No enabled policy blocks legacy authentication for all users.

    Fix: Block legacy authentication. See the rows →

  4. Users can consent to any app. Any user can grant any app access to their mail and files.

    Fix: Set user consent to "Allow user consent for apps from verified publishers, for selected permissions" or turn it off and use the admin consent workflow. See the rows →

  5. Any user can register an app. Users can register apps that nobody reviews.

    Fix: Set "Users can register applications" to No. See the rows →

  6. 1 suspicious inbox rule. For example ann.patel@northwindtraders.example: ".": Moves to RSS Feeds mail mentioning invoice, payment; Rule name '.' looks deliberately blank.

    Fix: Check each rule with the mailbox owner. See the rows →

  7. SMTP AUTH is on for the organisation. SMTP AUTH is allowed.

    Fix: Turn off SMTP AUTH for the organisation and enable it only on the mailboxes of devices or apps that still need it. See the rows →

  8. 3 files and folders shared with anyone. For example Campaign video.mp4 (Marketing / Documents): Anyone can edit.

    Fix: Remove anyone links that are no longer needed, and set the rest to view-only with an expiry date. See the rows →

  9. 4 of 36 computers not encrypted. For example DESK-WRIGHT18 (leo.wright@northwindtraders.example): Windows disk isn't encrypted.

    Fix: Turn on BitLocker. See the rows →

  10. 5 of 36 Windows computers past end of support. For example LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.

    Fix: Upgrade computers on Windows 10 or an old Windows 11 release to the current Windows 11 release. See the rows →

  11. Enforced by Require MFA for all users, with 1 exclusion to review. For example breakglass@northwindtraders.example: Excluded from "Require MFA for all users".

    Fix: Create a Conditional Access policy requiring MFA for all users and all cloud apps, or turn on Security Defaults if the tenant has no Entra ID P1. See the rows →

  12. 2 admins without a phishing-resistant method. For example ann.patel@northwindtraders.example: Global Administrator; signs in with Authenticator app.

    Fix: Have each listed admin register a passkey. See the rows →

  13. 3 people can only use a text or call as a second factor. For example arthur.evans@northwindtraders.example: Second factor is only Mobile phone (SMS or call).

    Fix: Ask these people to set up the Microsoft Authenticator app. See the rows →

  14. Anyone, including guests, can invite guests. Guests can invite other guests.

    Fix: Restrict guest invitations to admins and the Guest Inviter role, or at least to members, under External collaboration settings. See the rows →

  15. 4 external forwards. For example ann.patel@northwindtraders.example: Mailbox forwarding to ann.patel@homemail.example (keeps a copy).

    Fix: Remove forwarding to outside addresses unless the client has a documented business reason. See the rows →

  16. 1 domain with SPF problems. For example parked.example: Doesn't receive mail but has no "v=spf1 -all" record to stop spoofing.

    Fix: Publish one SPF record per domain ending in -all. See the rows →

  17. 1 mail domain without DKIM. For example northwindtraders.example: Microsoft 365 DKIM isn't set up (selector2 CNAME missing).

    Fix: Turn on DKIM for each domain in the Defender portal. See the rows →

  18. 2 domains without DMARC enforcement. For example northwindtraders.example: DMARC is monitor-only (p=none); spoofed mail is still delivered.

    Fix: Publish a DMARC record with a rua= reporting address, start at p=none to see who sends as the domain, then move to p=quarantine and p=reject. See the rows →

  19. Anyone, including anonymous links. For example SharePoint and OneDrive: Anyone links are allowed.

    Fix: Change SharePoint external sharing to "New and existing guests". See the rows →

  20. 4 teams and groups without an owner. For example Project Phoenix: Team, only owner is disabled (Robert Hughes).

    Fix: Make an active person, ideally two, an owner of each listed team or group. See the rows →

  21. 1 of 37 joined computers not in Intune. For example DESK-RECEPTION: Hybrid joined, not managed by Intune.

    Fix: Enrol Entra-joined and hybrid-joined computers in Intune. See the rows →

Microsoft 365 admin centre

Fail

Few, cloud-only Global Administrators, no shared mailboxes anyone can sign in to, and a way to get apps approved.

Pass
Two to four Global Administrators

Between two and four accounts hold the Global Administrator role.

  • 2 Global Administrators.
Accounts holding privileged roles
4
Admins with no MFA policy
1
Admins with no MFA method registered
2

2 Global Administrators.

What Microsoft 365 can't show: Judged from Entra ID role assignments, including through groups.

Pass
Administrative accounts are cloud-only

Accounts with admin roles aren't synchronised from on-premises Active Directory.

  • Cloud-only tenant: no accounts are synced from on-premises AD.

Cloud-only tenant: no accounts are synced from on-premises AD.

What Microsoft 365 can't show: Judged from Entra ID admin role holders.

Pass
Sign-in to shared mailboxes is blocked

The accounts behind shared mailboxes can't be signed in to.

  • All 3 shared mailboxes block sign-in.

All 3 shared mailboxes block sign-in.

What Microsoft 365 can't show: Judged from Exchange Online and Entra ID.

Fail
No guests or apps with admin roles

Admin roles are held by internal people, not guests, and apps holding roles are reviewed.

Gaps
  • 1 guest with admin roles.
  • g#EXT#@northwindtraders.example: Guest holding Exchange Administrator
  • 1 app with privileged roles.
  • Some app: App holding Exchange Administrator

Fix: Remove admin roles from guest accounts. If an external partner needs access, use GDAP or a member account in this tenant protected by MFA. See the rows →

1 guest with admin roles. 1 app with privileged roles.

What Microsoft 365 can't show: Judged from Entra ID role assignments.

Microsoft Entra ID

Fail

MFA for everyone with Conditional Access, phishing-resistant MFA for admins, legacy authentication blocked, no user consent to apps, and users can't register apps, create tenants or join by email.

Partly
MFA required for all users

A Conditional Access policy requires multi-factor authentication for every user.

  • But: 14 users without MFA.
Users with an MFA method registered
62.2% of 37
Accounts covered by an enforced MFA policy
36 of 36
Gaps
  • Enforced by Require MFA for all users, with 1 exclusion to review.
  • breakglass@northwindtraders.example: Excluded from "Require MFA for all users"

Fix: Create a Conditional Access policy requiring MFA for all users and all cloud apps, or turn on Security Defaults if the tenant has no Entra ID P1. Keep exclusions to break-glass accounts. See the rows →

Enforced by Require MFA for all users, with 1 exclusion to review.

What Microsoft 365 can't show: Judged from Conditional Access and Security Defaults.

Fail
MFA required for administrative roles

A Conditional Access policy requires multi-factor authentication for every admin role.

Accounts holding privileged roles
4
Admins with no MFA policy
1
Admins with no MFA method registered
2
Gaps
  • 1 admin not covered by MFA.
  • breakglass@northwindtraders.example: Global Administrator: excluded from Require MFA for all users
  • 1 admin without MFA, and 1 whose registration isn't known.
  • breakglass@northwindtraders.example: Global Administrator with no MFA method registered
  • g#EXT#@northwindtraders.example: Exchange Administrator: MFA registration unknown

Fix: Have each listed admin register a strong method (Authenticator or a FIDO2 key), or remove the role. Break-glass accounts should use FIDO2 keys kept offline. See the rows →

1 admin not covered by MFA. 1 admin without MFA, and 1 whose registration isn't known.

What Microsoft 365 can't show: Judged from Conditional Access and Entra ID admin roles.

Partly
Phishing-resistant MFA for administrators

Administrators sign in with a phishing-resistant method (passkey, FIDO2 key or Windows Hello for Business).

Gaps
  • 2 admins without a phishing-resistant method.
  • ann.patel@northwindtraders.example: Global Administrator; signs in with Authenticator app
  • breakglass@northwindtraders.example: Global Administrator; signs in with no MFA method at all

Fix: Have each listed admin register a passkey (in Microsoft Authenticator or on a security key) or Windows Hello for Business, then require the Phishing-resistant MFA authentication strength for admin roles in Conditional Access. Codes and push approvals can be relayed by a fake sign-in page; these can't. See the rows →

2 admins without a phishing-resistant method.

What Microsoft 365 can't show: Judged from the methods each admin has registered.

Partly
Weak authentication methods not relied on

Text messages and voice calls aren't anyone's only second factor.

Gaps
  • 3 people can only use a text or call as a second factor.
  • arthur.evans@northwindtraders.example: Second factor is only Mobile phone (SMS or call)
  • mia.hughes@northwindtraders.example: Second factor is only Mobile phone (SMS or call)
  • zara.jackson@northwindtraders.example: Second factor is only Mobile phone (SMS or call)

Fix: Ask these people to set up the Microsoft Authenticator app (the registration campaign in the authentication methods policy prompts them at sign-in), then turn off text message and voice call sign-in, or keep them only as a backup. Texts and calls can be intercepted or moved to an attacker's SIM. See the rows →

3 people can only use a text or call as a second factor.

What Microsoft 365 can't show: Judged from Entra ID authentication methods.

Fail
Legacy authentication blocked

A Conditional Access policy blocks legacy authentication.

Gaps
  • Legacy authentication is allowed.
  • No enabled policy blocks legacy authentication for all users

Fix: Block legacy authentication (Exchange ActiveSync and other clients) with a Conditional Access policy for all users. Legacy protocols can't do MFA and are the most common password-spray target. See the rows →

Legacy authentication is allowed.

What Microsoft 365 can't show: Judged from Conditional Access.

Fail
Users can't register applications

Only admins can register applications.

Gaps
  • Any user can register an app.
  • Users can register apps that nobody reviews

Fix: Set "Users can register applications" to No (Entra admin center > Users > User settings) and give the Application Developer role to the people who need it. See the rows →

Any user can register an app.

What Microsoft 365 can't show: Judged from Entra ID user settings.

Not collected
Non-admins can't create tenants

Users who aren't admins can't create new tenants.

  • Not checked: users can't create new tenants (Microsoft didn't return this setting).

Microsoft didn't return this setting.

Not checked: users can't create new tenants (Microsoft didn't return this setting).

What Microsoft 365 can't show: Judged from Entra ID user settings.

Partly
Guest access to the directory restricted

Guests have limited access to directory objects, and only admins and the Guest Inviter role can invite.

  • Guests have limited access to directory objects (the default).
Gaps
  • Anyone, including guests, can invite guests.
  • Guests can invite other guests

Fix: Restrict guest invitations to admins and the Guest Inviter role, or at least to members, under External collaboration settings. See the rows →

Guests have limited access to directory objects (the default). Anyone, including guests, can invite guests.

What Microsoft 365 can't show: Judged from Entra ID external collaboration settings.

Not collected
No joining the tenant by email verification

People can't join the tenant just by verifying an email address.

  • Not checked: people can't join the tenant just by verifying an email address (Microsoft didn't return this setting).

Microsoft didn't return this setting.

Not checked: people can't join the tenant just by verifying an email address (Microsoft didn't return this setting).

What Microsoft 365 can't show: Judged from Entra ID authorisation settings.

Pass
Group creation limited

Only chosen people can create Microsoft 365 groups and teams.

  • Only admins and members of Group creators can create teams and groups.

Only admins and members of Group creators can create teams and groups.

What Microsoft 365 can't show: Judged from Entra ID group settings.

Not collected
Risky users and sign-ins dealt with

Entra ID Protection risk is acted on: no account left at risk, no risky sign-in left open.

  • Not checked: no accounts are at risk in Entra ID Protection (Risky users need Entra ID P2).
  • Not checked: no risky sign-ins succeeded (Sign-in risk needs Entra ID P2).

Risky users need Entra ID P2.

Not checked: no accounts are at risk in Entra ID Protection (Risky users need Entra ID P2). Not checked: no risky sign-ins succeeded (Sign-in risk needs Entra ID P2).

What Microsoft 365 can't show: Judged from Entra ID Protection (Entra ID P2 for the full detections).

Not collected
Password hash sync on (hybrid)

Where accounts sync from Active Directory, password hash sync is on so leaked credentials are detected.

  • Not checked: password hash sync is on (Cloud-only tenant: directory sync isn't turned on).

Cloud-only tenant: directory sync isn't turned on.

Not checked: password hash sync is on (Cloud-only tenant: directory sync isn't turned on).

What Microsoft 365 can't show: Judged from Entra Connect; not applicable to cloud-only tenants.

Exchange Online

Fail

Auditing on, no forwarding outside, SMTP AUTH off, and every domain with SPF, DKIM and DMARC.

Pass
Mailbox auditing on

Mailbox auditing is on for every user mailbox.

  • Mailbox auditing is on for the organisation.

Mailbox auditing is on for the organisation.

What Microsoft 365 can't show: Judged from Exchange Online.

Partly
All forms of mail forwarding blocked

Automatic forwarding to outside addresses is blocked by policy, and no mailbox or rule forwards out.

  • The default outbound policy blocks automatic external forwarding.
Gaps
  • 4 external forwards.
  • ann.patel@northwindtraders.example: Mailbox forwarding to ann.patel@homemail.example (keeps a copy)
  • ann.patel@northwindtraders.example: Inbox rule "Copy to home" forwards to ann.patel.home@homemail.example
  • grace.taylor@northwindtraders.example: Mailbox forwarding to grace.taylor@homemail.example (doesn't keep a copy)
  • olivia.smith@northwindtraders.example: Inbox rule "Invoices to bookkeeper" forwards to bookkeeping@ledgerline.example

Fix: Remove forwarding to outside addresses unless the client has a documented business reason. Forwarding is the most common way attackers keep reading a mailbox after a password reset. See the rows →

The default outbound policy blocks automatic external forwarding. 4 external forwards.

What Microsoft 365 can't show: Judged from the outbound spam policy, mailbox forwarding and inbox rules.

Fail
No inbox rules hiding mail

Inbox rules that delete, hide or redirect mail are found and reviewed.

Gaps
  • 1 suspicious inbox rule.
  • ann.patel@northwindtraders.example: ".": Moves to RSS Feeds mail mentioning invoice, payment; Rule name '.' looks deliberately blank

Fix: Check each rule with the mailbox owner. Rules that delete or bury messages about payments or security alerts are a sign of a compromised account: reset the password, revoke sessions and review sign-ins. See the rows →

1 suspicious inbox rule.

What Microsoft 365 can't show: Judged from Exchange Online inbox rules.

Fail
SMTP AUTH disabled

Authenticated SMTP is turned off for the organisation.

Gaps
  • SMTP AUTH is on for the organisation.
  • SMTP AUTH is allowed

Fix: Turn off SMTP AUTH for the organisation and enable it only on the mailboxes of devices or apps that still need it, such as scanners. It accepts passwords without MFA. See the rows →

SMTP AUTH is on for the organisation.

What Microsoft 365 can't show: Judged from Exchange Online transport settings.

Partly
SPF records published

Every mail domain publishes an SPF record.

Gaps
  • 1 domain with SPF problems.
  • parked.example: Doesn't receive mail but has no "v=spf1 -all" record to stop spoofing

Fix: Publish one SPF record per domain ending in -all (or ~all while testing), e.g. "v=spf1 include:spf.protection.outlook.com -all". Domains that never send mail should publish "v=spf1 -all". See the rows →

1 domain with SPF problems.

What Microsoft 365 can't show: Judged from public DNS.

Partly
DKIM enabled

DKIM signing is on for every mail domain.

Gaps
  • 1 mail domain without DKIM.
  • northwindtraders.example: Microsoft 365 DKIM isn't set up (selector2 CNAME missing)

Fix: Turn on DKIM for each domain in the Defender portal (Email authentication settings > DKIM), publishing the two selector CNAME records it shows. This applies to domains behind a mail gateway too when Microsoft 365 still sends for them (their SPF includes spf.protection.outlook.com); a gateway signs only the mail that goes out through it. See the rows →

1 mail domain without DKIM.

What Microsoft 365 can't show: Judged from Exchange Online and public DNS.

Partly
DMARC published and enforced

Every domain publishes a DMARC record with a quarantine or reject policy.

Gaps
  • 2 domains without DMARC enforcement.
  • northwindtraders.example: DMARC is monitor-only (p=none); spoofed mail is still delivered
  • parked.example: Doesn't receive mail but has no DMARC p=reject record

Fix: Publish a DMARC record with a rua= reporting address, start at p=none to see who sends as the domain, then move to p=quarantine and p=reject. Without enforcement, spoofed mail from the domain is delivered. See the rows →

2 domains without DMARC enforcement.

What Microsoft 365 can't show: Judged from public DNS.

SharePoint, OneDrive and Teams

Fail

External sharing is limited, there are no open anyone links, and groups and teams have owners.

Partly
External sharing restricted

SharePoint and OneDrive sharing doesn't allow anyone links.

Gaps
  • Anyone, including anonymous links.
  • SharePoint and OneDrive: Anyone links are allowed

Fix: Change SharePoint external sharing to "New and existing guests" so every external person signs in. If the client relies on Anyone links, set them to expire and to view-only. See the rows →

Anyone, including anonymous links.

What Microsoft 365 can't show: Judged from SharePoint tenant settings.

Pass
Guest users reviewed

Guest accounts are reviewed, and invitations nobody accepted are removed.

  • No stale guest invitations.

Guest and external user accounts are not reviewed regularly. 1 guest account: 1 guest inactive for 90+ days or never signed in (g#EXT#@northwindtraders.example).

What Microsoft 365 can't show: Judged from Entra ID guests and their invitation state.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Partly
Every group and team has an owner

Microsoft 365 groups and teams have owners who answer for their membership and content.

  • Unused teams and groups expire after 365 days.
Gaps
  • 4 teams and groups without an owner.
  • Project Phoenix: Team, only owner is disabled (Robert Hughes)
  • Marketing: Microsoft 365 group, only owner is disabled (Robert Hughes)
  • Marketing: Microsoft 365 group, no owner
  • Provisioned: Microsoft 365 group, owned only by an app (Provisioning app)

Fix: Make an active person, ideally two, an owner of each listed team or group (Teams admin center or Microsoft 365 admin center > Teams & groups). Owners approve members and guests and renew the group; without one, nobody looks after its files and conversations. The ownerless group policy (Microsoft 365 admin center > Settings > Org settings > Microsoft 365 Groups) asks members to take over when the last owner leaves. See the rows →

Unused teams and groups expire after 365 days. 4 teams and groups without an owner.

What Microsoft 365 can't show: Judged from Entra ID groups.

Intune and devices

Fail

Devices are enrolled, compliant, encrypted and on supported versions.

Partly
Devices enrolled and compliant

Company computers are managed by Intune, check in, and meet the compliance policies.

Gaps
  • 1 of 37 joined computers not in Intune.
  • DESK-RECEPTION: Hybrid joined, not managed by Intune
  • 6 of 37 managed devices not compliant.
  • DESK-ROBINSON12 (george.robinson@northwindtraders.example): Not compliant
  • DESK-WRIGHT18 (leo.wright@northwindtraders.example): Not compliant
  • LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Not compliant
  • LAPTOP-SCOTT25 (alfie.scott@northwindtraders.example): Not compliant
  • LAPTOP-SCOTT29 (olivia.scott@northwindtraders.example): Not compliant
  • and 1 more
  • 3 devices haven't checked in for 30+ days.
  • DESK-ROBINSON12 (george.robinson@northwindtraders.example): Last check-in 38 days ago
  • LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Last check-in 45 days ago
  • LAPTOP-SCOTT25 (alfie.scott@northwindtraders.example): Last check-in 38 days ago

Fix: Enrol Entra-joined and hybrid-joined computers in Intune (automatic enrolment under Devices > Enrollment > Windows) so compliance, encryption and updates can be enforced on them. See the rows →

1 of 37 joined computers not in Intune. 6 of 37 managed devices not compliant. 3 devices haven't checked in for 30+ days.

What Microsoft 365 can't show: Judged from Intune and Entra ID.

Fail
Disks encrypted

Company computers are encrypted.

Gaps
  • 4 of 36 computers not encrypted.
  • DESK-WRIGHT18 (leo.wright@northwindtraders.example): Windows disk isn't encrypted
  • LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Windows disk isn't encrypted
  • LAPTOP-SCOTT29 (olivia.scott@northwindtraders.example): Windows disk isn't encrypted
  • LAPTOP-SMITH07 (olivia.smith@northwindtraders.example): Windows disk isn't encrypted

Fix: Turn on BitLocker (Windows) and FileVault (macOS) with an Intune disk encryption policy, with recovery keys escrowed to Entra ID, so a lost or stolen laptop doesn't expose the client's data. See the rows →

4 of 36 computers not encrypted.

What Microsoft 365 can't show: Judged from Intune.

Fail
Supported operating systems

Windows computers run a version that still gets security updates.

Gaps
  • 5 of 36 Windows computers past end of support.
  • LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • LAPTOP-MARTIN22 (maya.martin@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • LAPTOP-PATEL13 (hannah.patel@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • LAPTOP-ROBERTS31 (george.roberts@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • LAPTOP-TAYLOR04 (grace.taylor@northwindtraders.example): Windows 10 stopped getting security updates on 14 Oct 2025. Extended Security Updates or LTSC can cover it; otherwise upgrade.
  • and 20 more

Fix: Upgrade computers on Windows 10 or an old Windows 11 release to the current Windows 11 release (Intune: Windows feature updates policy). Replace hardware that can't run Windows 11, or buy Extended Security Updates as a stopgap. See the rows →

5 of 36 Windows computers past end of support.

What Microsoft 365 can't show: Judged from the Windows versions Intune reports.

About this pack

This is a subset of the benchmark: the recommendations Office Sentry can judge from read-only data. A Pass is evidence for that recommendation; the rest of the benchmark still needs checking in the admin centres.

Requirements: CIS Microsoft 365 Foundations Benchmark, recommendations matched by title. Recommendations paraphrased from the CIS Microsoft 365 Foundations Benchmark. CIS renumbers them between versions, so match each one by its title in the version you're auditing against. Defender, Purview and Teams meeting settings Office Sentry doesn't read are left out rather than guessed. Source

Pass and Fail are judged from Microsoft 365 settings and accounts read with read-only access; accepted risks count as documented exceptions. Oldest data used: .