Security 101

How Do You Check Microsoft 365 Against the CIS Benchmark?

The CIS Microsoft 365 Foundations Benchmark is a consensus set of secure configuration recommendations. Here is what it covers, how teams check against it, and how to keep the result current.

You check Microsoft 365 against the CIS benchmark by comparing your tenant’s settings with the recommendations in the CIS Microsoft 365 Foundations Benchmark, then recording which pass, which fail, and which you accept as exceptions. The check can be manual, scripted or run by a platform.

The harder part comes later: keeping the result current as settings change.

Quick answer

  • The benchmark comes from CIS. The Center for Internet Security produces it through a community consensus process.
  • Recommendations come in two levels. Level 1 is a base set; Level 2 adds defense in depth.
  • There are several ways to check. Manual review, scripts, CIS-CAT Pro and validation platforms all produce a result.
  • A pass today can drift tomorrow. Keep a history of results, along with the exceptions you approved.

What is the CIS Microsoft 365 Foundations Benchmark?

The Center for Internet Security publishes configuration benchmarks for many technologies. The Microsoft 365 Foundations Benchmark gives secure configuration guidance for a Microsoft 365 tenant, and CIS describes it as the product of a community consensus process.

7.0.0

The current version of the Microsoft 365 Foundations Benchmark listed by CIS at the time of writing. Versions change, so confirm the latest before an audit.

CIS states that its benchmarks are freely available in PDF format for non-commercial use. CIS SecureSuite members get additional resources, including CIS-CAT Pro, which scans systems against a benchmark.

What is the difference between Level 1 and Level 2?

Level 1

A base set of recommendations that CIS says can be implemented fairly promptly. It aims to reduce attack surface without getting in the way of the business.

Level 2

Defense in depth for environments where security is a top priority. CIS cautions that these can cause problems if applied without care, so test before you enforce.

A practical approach is to measure against Level 1 first, decide which Level 2 items fit your risk, and document the reason for any recommendation you choose not to adopt.

What are the ways to check Microsoft 365 against CIS?

ApproachWhat you getWhat to plan for
Manual review against the PDFA close read of each recommendation and how it applies to youTime for each review, repeated when the tenant or the benchmark changes
Scripts and community toolsFast, repeatable checks you can run on demandSomeone to maintain the scripts and keep results and exceptions on record
CIS-CAT ProA CIS scanner that reports conformance to the benchmarkCIS SecureSuite membership
Validation platformScheduled checks mapped to CIS and other frameworks, with history and ownershipOnboarding, and agreement on an approved baseline
Each approach can work. The right one depends on how often you need proof and who acts on the results.

How do you run a CIS check on Microsoft 365?

  1. Pick the version and level. Record which benchmark version and profile level you are measuring against, so later results compare like with like.
  2. Confirm read access. Checks need to read tenant settings. Use the least access that covers the settings in scope, and document it.
  3. Run the check. Compare each recommendation with your tenant’s current configuration and keep the evidence for each pass and fail.
  4. Decide on each failure. Fix it, schedule it, or record an accepted exception with an owner and a reason.
  5. Repeat and compare. Run the same check again on a schedule and compare it with the last result to catch settings that changed.

Why does a CIS result go out of date?

A benchmark check describes one moment. An administrator edits a Conditional Access policy or a new license assignment alters defaults, and a setting that passed no longer matches the baseline your team agreed on.

Auditors ask for proof that controls stayed in their approved state between assessments. A history of results, with changes recorded as before and after values, answers that question. For more on drift, read how to manage Microsoft 365 security and prove it works and what continuous control validation means for Microsoft security.

What tools check Microsoft 365 against CIS benchmarks?

Any of the approaches above can produce a CIS result. When you compare tools, look at what happens after the check runs.

  • Version tracking. Does the tool say which benchmark version and level it measured?
  • Exceptions. Can you record an accepted risk with an owner and a reason, so it does not return as a new failure?
  • History. Can you see when a setting changed and what it changed from?
  • Other frameworks. If you also report against NIST CSF 2.0, ISO 27001 or CISA SCuBA, can one finding map to all of them?
  • Scope beyond Microsoft 365. CIS also publishes benchmarks for Azure, AWS and GCP that may belong in the same audit.

The Accelerynt Security Platform maps findings to CIS Microsoft 365 and 14 other frameworks, including CISA SCuBA, NIST CSF 2.0, ISO 27001:2022 and the CIS Foundations benchmarks for Azure, AWS, GCP, Google Workspace, GitHub and DevOps. Scans run on a schedule your team configures and on demand, and drift detection watches critical controls between scans. Findings, drift history and compliance mappings export as audit evidence.

Several CIS recommendations concern identity. For two common areas, see how Conditional Access policies combine in Entra ID and how to find risky app registrations and service principals.

Where to go next

To see how your tenant measures up today, start with a Microsoft Control Validation Assessment. For a view framed for executives, see the Executive Risk Assurance Assessment. When findings need turning into a plan, read how to turn assessment findings into a remediation roadmap.

Frequently asked questions

What tools check Microsoft 365 against CIS benchmarks?

Options include a manual review against the CIS benchmark PDF, scripts and community tools, CIS-CAT Pro for CIS SecureSuite members, and validation platforms such as the Accelerynt Security Platform, which maps findings to CIS Microsoft 365 and 14 other frameworks and tracks drift between scheduled scans.

Is the CIS Microsoft 365 benchmark free?

CIS says its benchmarks are freely available in PDF format for non-commercial use. CIS-CAT Pro and some additional resources come with CIS SecureSuite membership. Check the CIS site for the terms that apply to the current version.

What is the difference between CIS Level 1 and Level 2?

CIS describes Level 1 as a base recommendation that can be implemented fairly promptly. Level 2 adds defense in depth for environments where security is a top priority, and CIS cautions that those recommendations can cause problems if applied without care.

How is the CIS benchmark different from Microsoft Secure Score?

Secure Score measures your tenant against Microsoft’s own recommendations, which are the same for every organization. The CIS benchmark is a set of recommendations produced through the CIS community consensus process. Both are shared yardsticks, so to see whether your tenant matches the state your team approved, validate it against your own baseline. The Accelerynt Security Platform maps findings to CIS Microsoft 365 and measures against your approved baseline.

Talk to a Microsoft security engineer

We work inside your Microsoft environment, with your team, and show you where to focus first.