Skip to content

Microsoft 365 checks

Trimtab runs these 19 read-only checks against each connected Microsoft 365 tenant. Checks that need Microsoft Entra ID P1 or Exchange Online access show as not evaluated when that isn't available. See Connect Microsoft 365.

ID Check Severity Standards
M365-001 MFA is enforced for all users High CMMC, HIPAA
M365-002 MFA is enforced for administrators High CMMC, HIPAA
M365-003 Legacy authentication is blocked High CMMC, HIPAA
M365-004 Users are registered for MFA Medium CMMC, HIPAA
M365-005 Global Administrator count is controlled High CMMC, HIPAA
M365-006 Users cannot consent to risky apps Medium CMMC, HIPAA
M365-007 Users cannot register applications Low CMMC
M365-008 Guest access and invitations are restricted Medium CMMC, HIPAA
M365-009 SharePoint and OneDrive do not allow anonymous links High CMMC, HIPAA
M365-010 No stale enabled accounts Medium CMMC, HIPAA
M365-011 Microsoft Secure Score meets target Low CMMC, HIPAA
EXO-001 Mailbox auditing is on for the organization High CMMC, HIPAA
EXO-002 Unified audit log is on High CMMC, HIPAA
EXO-003 Automatic forwarding to external addresses is blocked High CMMC, HIPAA
EXO-004 No mailboxes forward to external addresses Medium CMMC, HIPAA
EXO-005 Modern authentication is on for Exchange Medium CMMC, HIPAA
EXO-006 SMTP AUTH is turned off Medium CMMC, HIPAA
EXO-007 DKIM signing is on for custom domains Medium CMMC, HIPAA
EXO-008 DMARC is enforced for custom domains Medium CMMC, HIPAA

Identity

M365-001 · MFA is enforced for all users

High Identity

Fix: Turn on security defaults, or create a Conditional Access policy that requires MFA for all users and all cloud apps.

Take the helm: step-by-step
  1. Without Entra ID P1: Entra admin center → Identity → Overview → Properties → Manage security defaults → Enabled.
  2. With P1: Protection → Conditional Access → New policy. Users = All users (exclude two emergency access accounts), Target resources = All cloud apps, Grant = Require multifactor authentication.
  3. Run it in Report-only for a few days, then switch it On.
  4. Ask users to register an authenticator app beforehand so nobody gets locked out.

Maps to:

M365-002 · MFA is enforced for administrators

High Identity

Fix: Require MFA for all directory roles with a Conditional Access policy, or turn on security defaults.

Take the helm: step-by-step
  1. Security defaults already require MFA for admins.
  2. With P1: Conditional Access → New policy. Users → Directory roles = Global Administrator and the other admin roles, Target resources = All cloud apps, Grant = Require multifactor authentication (or phishing-resistant MFA). Turn it On.

Maps to:

M365-003 · Legacy authentication is blocked

High Identity

Fix: Block legacy authentication (Exchange ActiveSync and other clients) with Conditional Access, or turn on security defaults.

Take the helm: step-by-step
  1. Security defaults already block legacy authentication.
  2. With P1, first check Sign-in logs (filter Client app = the legacy clients) for anything still using it.
  3. Conditional Access → New policy. Users = All users, Target resources = All cloud apps, Conditions → Client apps = Exchange ActiveSync clients and Other clients, Grant = Block access.
  4. Run it in Report-only first, then switch it On.

Maps to:

  • IA.L2-3.5.3 Use multifactor authentication
  • CM.L2-3.4.7 Restrict nonessential programs, functions, ports, protocols, and services
  • 164.312(d) Person or entity authentication

M365-004 · Users are registered for MFA

Medium Identity

Fix: Have remaining users register an authentication method, for example with a registration campaign.

Default thresholds: Target percentage = 95

Take the helm: step-by-step
  1. See who isn't registered: Entra admin center → Protection → Authentication methods → User registration details.
  2. Turn on a registration campaign: Authentication methods → Registration campaign → Enabled for all users.
  3. Follow up individually with anyone still not registered.

Maps to:

M365-010 · No stale enabled accounts

Medium Identity

Fix: Disable or remove accounts that have not signed in within the inactivity period.

Default thresholds: Inactivity period (days) = 90

Take the helm: step-by-step
  1. Review the inactive accounts listed in the evidence.
  2. Confirm with the manager or HR, then block sign-in (Users → user → Edit properties → Account enabled: off) or delete the account.
  3. Set up access reviews (Entra ID P2) or a monthly review so inactive accounts get caught.

Maps to:

Privileged access

M365-005 · Global Administrator count is controlled

High Privileged access

Fix: Keep between two and four Global Administrators. Use less privileged roles for day-to-day administration.

Default thresholds: Minimum = 2, Maximum = 4

Take the helm: step-by-step
  1. Review assignments: Entra admin center → Roles & admins → Global Administrator.
  2. Move people who only need part of that access to narrower roles, such as User Administrator or Exchange Administrator.
  3. If there's only one Global Admin, add a second: a cloud-only emergency access account with a long password stored securely.

Maps to:

Applications

M365-006 · Users cannot consent to risky apps

Medium Applications

Fix: Set user consent to 'Do not allow' or 'Allow for verified publishers, for selected permissions', and use the admin consent workflow.

Take the helm: step-by-step
  1. Entra admin center → Enterprise applications → Consent and permissions → User consent settings → 'Do not allow user consent' (or 'Allow user consent for apps from verified publishers, for selected permissions').
  2. Turn on Admin consent requests (Enterprise applications → Admin consent settings) so users can ask for approval.

Maps to:

M365-007 · Users cannot register applications

Low Applications

Fix: Set 'Users can register applications' to No in Entra ID user settings.

Take the helm: step-by-step
  1. Entra admin center → Users → User settings → 'Users can register applications' = No.
  2. Give people who build apps the Application Developer role instead.

Maps to:

External access

M365-008 · Guest access and invitations are restricted

Medium External access

Fix: Restrict guest user access to their own directory objects, and limit invitations to admins and the Guest Inviter role.

Take the helm: step-by-step
  1. Entra admin center → External Identities → External collaboration settings.
  2. Guest user access: 'Guest user access is restricted to properties and memberships of their own directory objects'.
  3. Guest invite settings: 'Only users assigned to specific admin roles can invite guest users'.

Maps to:

M365-009 · SharePoint and OneDrive do not allow anonymous links

High External access

Fix: Set SharePoint external sharing to 'New and existing guests' or more restrictive, so 'Anyone' links are not allowed.

Take the helm: step-by-step
  1. SharePoint admin center → Policies → Sharing.
  2. Set the SharePoint and OneDrive slider to 'New and existing guests' or more restrictive, so 'Anyone' links aren't allowed.
  3. Optionally set the default link type to 'Specific people' and limit sharing to approved domains.

Maps to:

Posture

M365-011 · Microsoft Secure Score meets target

Low Posture

Fix: Work through the improvement actions in Microsoft Secure Score, starting with the highest impact.

Default thresholds: Target percentage = 50

Take the helm: step-by-step
  1. Open the Microsoft Defender portal → Exposure management → Secure Score → Recommended actions.
  2. Sort by score impact and work through the top items. Many are covered by other Trimtab checks.
  3. Mark items handled by third-party tools as resolved that way, so the score reflects reality.

Maps to:

Exchange Online

EXO-001 · Mailbox auditing is on for the organization

High Exchange Online

Fix: Run Set-OrganizationConfig -AuditDisabled $false so mailbox actions are logged for every mailbox.

Take the helm: step-by-step
  1. Connect to Exchange Online PowerShell: Connect-ExchangeOnline.
  2. Run Set-OrganizationConfig -AuditDisabled $false.
  3. Confirm with Get-OrganizationConfig | Format-List AuditDisabled.

Maps to:

EXO-002 · Unified audit log is on

High Exchange Online

Fix: Turn on auditing in the Microsoft Purview portal, or run Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $true.

Take the helm: step-by-step
  1. Microsoft Purview portal → Audit → 'Start recording user and admin activity'.
  2. Or in Exchange Online PowerShell: Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $true.
  3. Recording can take up to an hour to start.

Maps to:

EXO-003 · Automatic forwarding to external addresses is blocked

High Exchange Online

Fix: Set automatic forwarding to Off in the outbound spam filter policy, and allow it only for approved users with a separate policy.

Take the helm: step-by-step
  1. Microsoft Defender portal → Email & collaboration → Policies & rules → Threat policies → Anti-spam → Anti-spam outbound policy (Default).
  2. Set Automatic forwarding rules to 'Off - Forwarding is disabled'.
  3. If a few users truly need forwarding, create a separate outbound policy just for them.
  4. PowerShell: Set-HostedOutboundSpamFilterPolicy -Identity Default -AutoForwardingMode Off.

Maps to:

EXO-004 · No mailboxes forward to external addresses

Medium Exchange Online

Fix: Remove external forwarding addresses from mailboxes unless there is a documented business need.

Take the helm: step-by-step
  1. Review each mailbox in the evidence with its owner.
  2. Remove the forward: Exchange admin center → Recipients → Mailboxes → mailbox → Mail flow settings → Email forwarding, or Set-Mailbox <user> -ForwardingSmtpAddress $null -DeliverToMailboxAndForward $false.
  3. Check the user's inbox rules too: Get-InboxRule -Mailbox <user>.

Maps to:

EXO-005 · Modern authentication is on for Exchange

Medium Exchange Online

Fix: Run Set-OrganizationConfig -OAuth2ClientProfileEnabled $true so Outlook uses modern authentication and MFA.

Take the helm: step-by-step
  1. In Exchange Online PowerShell, run Set-OrganizationConfig -OAuth2ClientProfileEnabled $true.
  2. Newer tenants have this on by default; older tenants may need it turned on.

Maps to:

EXO-006 · SMTP AUTH is turned off

Medium Exchange Online

Fix: Run Set-TransportConfig -SmtpClientAuthenticationDisabled $true, and enable it only on mailboxes that need it, such as scanners.

Take the helm: step-by-step
  1. Find what still uses SMTP AUTH, such as scanners or line-of-business apps (sign-in logs or Exchange reports).
  2. Turn it off for the organization: Set-TransportConfig -SmtpClientAuthenticationDisabled $true.
  3. Re-enable it only on mailboxes that need it: Set-CASMailbox <mailbox> -SmtpClientAuthenticationDisabled $false.

Maps to:

  • CM.L2-3.4.7 Restrict nonessential programs, functions, ports, protocols, and services
  • IA.L2-3.5.3 Use multifactor authentication
  • 164.312(d) Person or entity authentication

EXO-007 · DKIM signing is on for custom domains

Medium Exchange Online

Fix: Enable DKIM for each custom domain in the Microsoft Defender portal and publish the two CNAME records.

Take the helm: step-by-step
  1. Microsoft Defender portal → Email & collaboration → Policies & rules → Threat policies → Email authentication settings → DKIM.
  2. Select each domain and copy its two CNAME records (selector1._domainkey and selector2._domainkey).
  3. Add both records at your DNS host, wait for them to publish, then turn on 'Sign messages for this domain with DKIM signatures'.

Maps to:

Email security

EXO-008 · DMARC is enforced for custom domains

Medium Email security

Fix: Publish a DMARC record (_dmarc.yourdomain) with p=quarantine or p=reject after monitoring with p=none.

Take the helm: step-by-step
  1. Make sure SPF and DKIM are set up first.
  2. Add a TXT record at _dmarc.<yourdomain> with v=DMARC1; p=none; rua=mailto:reports@<yourdomain>.
  3. Review the reports for two to four weeks and fix any legitimate senders that fail.
  4. Change the policy to p=quarantine, and later p=reject.

Maps to: