M365Audit

Benchmark · Industry Standard

CIS Microsoft 365 Foundations Benchmark logo

CIS Microsoft 365 Foundations Benchmark.
Automated. One report.

The Center for Internet Security's Microsoft 365 Foundations Benchmark is a consensus-based configuration baseline developed and reviewed by a global community of cybersecurity experts and vendors.

About the baseline

What is CIS M365?

CIS Benchmarks codify secure configuration for a platform into a numbered set of controls with two profiles — Level 1 (broadly applicable, minimal impact) and Level 2 (defense-in-depth for high-security environments). The Microsoft 365 Foundations Benchmark covers Entra ID, Exchange Online, SharePoint Online, Microsoft Teams, and Microsoft Defender. Each control ships with an audit procedure and a remediation procedure, which is exactly what an M365Audit report maps back to.

Maintainer
Center for Internet Security
Coverage
150+ controls (L1 + L2)
License
CIS Benchmarks (free registration)

Capabilities

What CIS M365 covers

The baseline's scope — we run these checks against your tenant and report the results.

Consensus-built controls

Every control is drafted, balloted, and reviewed by a global community of security practitioners — not written by a single vendor.

Level 1 & Level 2 profiles

Level 1 covers baseline hardening suitable for any organization. Level 2 adds defense-in-depth for regulated and high-security environments.

Per-control remediation

Each finding maps to a numbered CIS control with the audit and remediation procedure, so you know exactly what to change and where.

Cross-surface coverage

Identity, email, collaboration, and endpoint configuration are all covered under one benchmark, so a single audit covers the whole tenant.

Surface area

Where it looks

Entra IDExchange OnlineSharePointMicrosoft TeamsDefender

Use cases

When it earns its keep

Baseline tenant hardening

Take a fresh or inherited M365 tenant and close the gap between its current configuration and the CIS Foundation baseline.

Auditor evidence

CIS is a recognized benchmark. Attach the report to a SOC 2, ISO 27001, or cyber-insurance evidence package to show continuous configuration monitoring.

Client reporting for MSPs

Hand a client a numbered, severity-ranked CIS gap report — the same structure auditors and security teams already understand.

Other benchmarks

Add another framework

One credit. One tenant. One report.

Run CIS M365 against a Microsoft 365 tenant and get a severity-ranked PDF. Credits never expire.