Microsoft 365 checks¶
Trimtab runs these 19 read-only checks against each connected Microsoft 365 tenant. Checks that need Microsoft Entra ID P1 or Exchange Online access show as not evaluated when that isn't available. See Connect Microsoft 365.
| ID | Check | Severity | Standards |
|---|---|---|---|
M365-001 |
MFA is enforced for all users | High | CMMC, HIPAA |
M365-002 |
MFA is enforced for administrators | High | CMMC, HIPAA |
M365-003 |
Legacy authentication is blocked | High | CMMC, HIPAA |
M365-004 |
Users are registered for MFA | Medium | CMMC, HIPAA |
M365-005 |
Global Administrator count is controlled | High | CMMC, HIPAA |
M365-006 |
Users cannot consent to risky apps | Medium | CMMC, HIPAA |
M365-007 |
Users cannot register applications | Low | CMMC |
M365-008 |
Guest access and invitations are restricted | Medium | CMMC, HIPAA |
M365-009 |
SharePoint and OneDrive do not allow anonymous links | High | CMMC, HIPAA |
M365-010 |
No stale enabled accounts | Medium | CMMC, HIPAA |
M365-011 |
Microsoft Secure Score meets target | Low | CMMC, HIPAA |
EXO-001 |
Mailbox auditing is on for the organization | High | CMMC, HIPAA |
EXO-002 |
Unified audit log is on | High | CMMC, HIPAA |
EXO-003 |
Automatic forwarding to external addresses is blocked | High | CMMC, HIPAA |
EXO-004 |
No mailboxes forward to external addresses | Medium | CMMC, HIPAA |
EXO-005 |
Modern authentication is on for Exchange | Medium | CMMC, HIPAA |
EXO-006 |
SMTP AUTH is turned off | Medium | CMMC, HIPAA |
EXO-007 |
DKIM signing is on for custom domains | Medium | CMMC, HIPAA |
EXO-008 |
DMARC is enforced for custom domains | Medium | CMMC, HIPAA |
Identity¶
M365-001 · MFA is enforced for all users¶
Fix: Turn on security defaults, or create a Conditional Access policy that requires MFA for all users and all cloud apps.
Take the helm: step-by-step
- Without Entra ID P1: Entra admin center → Identity → Overview → Properties → Manage security defaults → Enabled.
- With P1: Protection → Conditional Access → New policy. Users = All users (exclude two emergency access accounts), Target resources = All cloud apps, Grant = Require multifactor authentication.
- Run it in Report-only for a few days, then switch it On.
- Ask users to register an authenticator app beforehand so nobody gets locked out.
Maps to:
IA.L2-3.5.3Use multifactor authentication164.312(d)Person or entity authentication
M365-002 · MFA is enforced for administrators¶
Fix: Require MFA for all directory roles with a Conditional Access policy, or turn on security defaults.
Take the helm: step-by-step
- Security defaults already require MFA for admins.
- With P1: Conditional Access → New policy. Users → Directory roles = Global Administrator and the other admin roles, Target resources = All cloud apps, Grant = Require multifactor authentication (or phishing-resistant MFA). Turn it On.
Maps to:
IA.L2-3.5.3Use multifactor authenticationAC.L2-3.1.5Employ the principle of least privilege164.312(d)Person or entity authentication
M365-003 · Legacy authentication is blocked¶
Fix: Block legacy authentication (Exchange ActiveSync and other clients) with Conditional Access, or turn on security defaults.
Take the helm: step-by-step
- Security defaults already block legacy authentication.
- With P1, first check Sign-in logs (filter Client app = the legacy clients) for anything still using it.
- Conditional Access → New policy. Users = All users, Target resources = All cloud apps, Conditions → Client apps = Exchange ActiveSync clients and Other clients, Grant = Block access.
- Run it in Report-only first, then switch it On.
Maps to:
IA.L2-3.5.3Use multifactor authenticationCM.L2-3.4.7Restrict nonessential programs, functions, ports, protocols, and services164.312(d)Person or entity authentication
M365-004 · Users are registered for MFA¶
Fix: Have remaining users register an authentication method, for example with a registration campaign.
Default thresholds: Target percentage = 95
Take the helm: step-by-step
- See who isn't registered: Entra admin center → Protection → Authentication methods → User registration details.
- Turn on a registration campaign: Authentication methods → Registration campaign → Enabled for all users.
- Follow up individually with anyone still not registered.
Maps to:
IA.L2-3.5.3Use multifactor authentication164.312(d)Person or entity authentication
M365-010 · No stale enabled accounts¶
Fix: Disable or remove accounts that have not signed in within the inactivity period.
Default thresholds: Inactivity period (days) = 90
Take the helm: step-by-step
- Review the inactive accounts listed in the evidence.
- Confirm with the manager or HR, then block sign-in (Users → user → Edit properties → Account enabled: off) or delete the account.
- Set up access reviews (Entra ID P2) or a monthly review so inactive accounts get caught.
Maps to:
IA.L2-3.5.6Disable identifiers after a period of inactivity164.312(a)(1)Access control
Privileged access¶
M365-005 · Global Administrator count is controlled¶
Fix: Keep between two and four Global Administrators. Use less privileged roles for day-to-day administration.
Default thresholds: Minimum = 2, Maximum = 4
Take the helm: step-by-step
- Review assignments: Entra admin center → Roles & admins → Global Administrator.
- Move people who only need part of that access to narrower roles, such as User Administrator or Exchange Administrator.
- If there's only one Global Admin, add a second: a cloud-only emergency access account with a long password stored securely.
Maps to:
AC.L2-3.1.5Employ the principle of least privilege164.312(a)(1)Access control
Applications¶
M365-006 · Users cannot consent to risky apps¶
Fix: Set user consent to 'Do not allow' or 'Allow for verified publishers, for selected permissions', and use the admin consent workflow.
Take the helm: step-by-step
- Entra admin center → Enterprise applications → Consent and permissions → User consent settings → 'Do not allow user consent' (or 'Allow user consent for apps from verified publishers, for selected permissions').
- Turn on Admin consent requests (Enterprise applications → Admin consent settings) so users can ask for approval.
Maps to:
CM.L2-3.4.9Control and monitor user-installed software164.312(a)(1)Access control
M365-007 · Users cannot register applications¶
Fix: Set 'Users can register applications' to No in Entra ID user settings.
Take the helm: step-by-step
- Entra admin center → Users → User settings → 'Users can register applications' = No.
- Give people who build apps the Application Developer role instead.
Maps to:
CM.L2-3.4.9Control and monitor user-installed softwareAC.L2-3.1.5Employ the principle of least privilege
External access¶
M365-008 · Guest access and invitations are restricted¶
Fix: Restrict guest user access to their own directory objects, and limit invitations to admins and the Guest Inviter role.
Take the helm: step-by-step
- Entra admin center → External Identities → External collaboration settings.
- Guest user access: 'Guest user access is restricted to properties and memberships of their own directory objects'.
- Guest invite settings: 'Only users assigned to specific admin roles can invite guest users'.
Maps to:
AC.L2-3.1.20Verify and control connections to external systemsAC.L2-3.1.1Limit system access to authorized users164.312(a)(1)Access control
M365-009 · SharePoint and OneDrive do not allow anonymous links¶
Fix: Set SharePoint external sharing to 'New and existing guests' or more restrictive, so 'Anyone' links are not allowed.
Take the helm: step-by-step
- SharePoint admin center → Policies → Sharing.
- Set the SharePoint and OneDrive slider to 'New and existing guests' or more restrictive, so 'Anyone' links aren't allowed.
- Optionally set the default link type to 'Specific people' and limit sharing to approved domains.
Maps to:
AC.L2-3.1.22Control CUI on publicly accessible systemsAC.L2-3.1.20Verify and control connections to external systems164.312(a)(1)Access control164.312(e)(1)Transmission security
Posture¶
M365-011 · Microsoft Secure Score meets target¶
Fix: Work through the improvement actions in Microsoft Secure Score, starting with the highest impact.
Default thresholds: Target percentage = 50
Take the helm: step-by-step
- Open the Microsoft Defender portal → Exposure management → Secure Score → Recommended actions.
- Sort by score impact and work through the top items. Many are covered by other Trimtab checks.
- Mark items handled by third-party tools as resolved that way, so the score reflects reality.
Maps to:
CM.L2-3.4.2Establish and enforce security configuration settings164.308(a)(1)(ii)(B)Risk management
Exchange Online¶
EXO-001 · Mailbox auditing is on for the organization¶
Fix: Run Set-OrganizationConfig -AuditDisabled $false so mailbox actions are logged for every mailbox.
Take the helm: step-by-step
- Connect to Exchange Online PowerShell:
Connect-ExchangeOnline. - Run
Set-OrganizationConfig -AuditDisabled $false. - Confirm with
Get-OrganizationConfig | Format-List AuditDisabled.
Maps to:
AU.L2-3.3.1Create and retain system audit logsAU.L2-3.3.2Ensure actions of individual users can be traced164.312(b)Audit controls
EXO-002 · Unified audit log is on¶
Fix: Turn on auditing in the Microsoft Purview portal, or run Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $true.
Take the helm: step-by-step
- Microsoft Purview portal → Audit → 'Start recording user and admin activity'.
- Or in Exchange Online PowerShell:
Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $true. - Recording can take up to an hour to start.
Maps to:
AU.L2-3.3.1Create and retain system audit logsAU.L2-3.3.2Ensure actions of individual users can be traced164.312(b)Audit controls
EXO-003 · Automatic forwarding to external addresses is blocked¶
Fix: Set automatic forwarding to Off in the outbound spam filter policy, and allow it only for approved users with a separate policy.
Take the helm: step-by-step
- Microsoft Defender portal → Email & collaboration → Policies & rules → Threat policies → Anti-spam → Anti-spam outbound policy (Default).
- Set Automatic forwarding rules to 'Off - Forwarding is disabled'.
- If a few users truly need forwarding, create a separate outbound policy just for them.
- PowerShell:
Set-HostedOutboundSpamFilterPolicy -Identity Default -AutoForwardingMode Off.
Maps to:
AC.L2-3.1.3Control the flow of CUI164.312(e)(1)Transmission security
EXO-004 · No mailboxes forward to external addresses¶
Fix: Remove external forwarding addresses from mailboxes unless there is a documented business need.
Take the helm: step-by-step
- Review each mailbox in the evidence with its owner.
- Remove the forward: Exchange admin center → Recipients → Mailboxes → mailbox → Mail flow settings → Email forwarding, or
Set-Mailbox <user> -ForwardingSmtpAddress $null -DeliverToMailboxAndForward $false. - Check the user's inbox rules too:
Get-InboxRule -Mailbox <user>.
Maps to:
AC.L2-3.1.3Control the flow of CUI164.312(e)(1)Transmission security
EXO-005 · Modern authentication is on for Exchange¶
Fix: Run Set-OrganizationConfig -OAuth2ClientProfileEnabled $true so Outlook uses modern authentication and MFA.
Take the helm: step-by-step
- In Exchange Online PowerShell, run
Set-OrganizationConfig -OAuth2ClientProfileEnabled $true. - Newer tenants have this on by default; older tenants may need it turned on.
Maps to:
IA.L2-3.5.3Use multifactor authentication164.312(d)Person or entity authentication
EXO-006 · SMTP AUTH is turned off¶
Fix: Run Set-TransportConfig -SmtpClientAuthenticationDisabled $true, and enable it only on mailboxes that need it, such as scanners.
Take the helm: step-by-step
- Find what still uses SMTP AUTH, such as scanners or line-of-business apps (sign-in logs or Exchange reports).
- Turn it off for the organization:
Set-TransportConfig -SmtpClientAuthenticationDisabled $true. - Re-enable it only on mailboxes that need it:
Set-CASMailbox <mailbox> -SmtpClientAuthenticationDisabled $false.
Maps to:
CM.L2-3.4.7Restrict nonessential programs, functions, ports, protocols, and servicesIA.L2-3.5.3Use multifactor authentication164.312(d)Person or entity authentication
EXO-007 · DKIM signing is on for custom domains¶
Fix: Enable DKIM for each custom domain in the Microsoft Defender portal and publish the two CNAME records.
Take the helm: step-by-step
- Microsoft Defender portal → Email & collaboration → Policies & rules → Threat policies → Email authentication settings → DKIM.
- Select each domain and copy its two CNAME records (selector1._domainkey and selector2._domainkey).
- Add both records at your DNS host, wait for them to publish, then turn on 'Sign messages for this domain with DKIM signatures'.
Maps to:
SC.L2-3.13.1Monitor, control, and protect communications at system boundaries164.312(e)(1)Transmission security
Email security¶
EXO-008 · DMARC is enforced for custom domains¶
Fix: Publish a DMARC record (_dmarc.yourdomain) with p=quarantine or p=reject after monitoring with p=none.
Take the helm: step-by-step
- Make sure SPF and DKIM are set up first.
- Add a TXT record at
_dmarc.<yourdomain>withv=DMARC1; p=none; rua=mailto:reports@<yourdomain>. - Review the reports for two to four weeks and fix any legitimate senders that fail.
- Change the policy to
p=quarantine, and laterp=reject.
Maps to:
SC.L2-3.13.1Monitor, control, and protect communications at system boundaries164.312(e)(1)Transmission security