The Center for Internet Security (CIS) Microsoft 365 Foundations Benchmark is one of the most widely adopted security frameworks for M365 environments. This guide breaks down what it covers, how to implement it, and where automated tooling like TenantVigil can help.
What Is the CIS M365 Benchmark?
The CIS Benchmark is a set of configuration guidelines developed by consensus among cybersecurity practitioners, technology vendors, and subject matter experts. For Microsoft 365, it covers:
- Entra ID (Azure AD) — Authentication policies, MFA, Conditional Access, role management
- Exchange Online — Mail transport rules, anti-phishing, anti-malware, forwarding controls
- SharePoint Online — External sharing, access controls, guest policies
- Microsoft Teams — Guest access, external communication, meeting policies
- Microsoft Defender — Safe Attachments, Safe Links, anti-spam configuration
- Intune — Device compliance, enrollment restrictions, configuration profiles
Benchmark Levels
The CIS Benchmark defines two implementation levels:
Level 1 (L1) — Essential
Practical security settings that can be implemented in most organizations with minimal impact on usability. Examples:
- Enable MFA for all users
- Block legacy authentication
- Enable audit logging
Level 2 (L2) — Defense in Depth
More restrictive controls for environments with higher security requirements. Examples:
- Block all external sharing in SharePoint
- Disable Teams guest access
- Require hardware security keys for admin accounts
How TenantVigil Maps to CIS Controls
TenantVigil's security controls are mapped to specific CIS Benchmark recommendations. When you run a scan, each finding references:
- The CIS control ID (e.g., CIS 1.1.1 — Ensure MFA is enabled for all users)
- The benchmark level (L1 or L2)
- The current configuration state in your tenant
- Remediation steps aligned with CIS guidance
Example Mapping
| CIS Control | TenantVigil Check | Status |
|---|---|---|
| 1.1.1 — Enable MFA for all users | MFA-001 |
✅ Pass / ❌ Fail |
| 1.1.3 — Block legacy authentication | LEGACY-AUTH-001 |
✅ Pass / ❌ Fail |
| 2.1.1 — Configure anti-phishing policy | EXO-ANTIPHISH-001 |
✅ Pass / ❌ Fail |
| 5.1.1 — Enable audit logging | AUDIT-001 |
✅ Pass / ❌ Fail |
Getting Started
- Run a free assessment at tenantvigil.com/assess to see your current CIS compliance posture
- Focus on Level 1 controls first — these provide the highest security impact with the least friction
- Use the remediation guidance in your TenantVigil report to address each failing control
- Schedule recurring scans to ensure ongoing compliance as your environment evolves
The CIS Benchmark is updated regularly as Microsoft introduces new features and security capabilities. TenantVigil tracks these updates and adds new controls to keep your assessments current.