The CIS Benchmark for Microsoft 365 — Level 1, Level 2 and what it actually requires
The CIS Microsoft 365 Foundations Benchmark v3.0 is the minimum-defensible configuration standard published by the Center for Internet Security. Not a marketing recommendation — specific controls in two levels (L1 practical, L2 robust), grouped into seven sections. What each level contains, where it differs from SCuBA and Secure Score, and why many "Microsoft 365 audit" PDFs cite it incorrectly.
What the CIS Benchmark is
The Center for Internet Security is a non-profit founded in 2000 that publishes reference configurations for systems — Windows, Linux, Kubernetes, AWS, Azure, Microsoft 365. The Microsoft 365 baseline is called the CIS Microsoft 365 Foundations Benchmark; the current version is v3.0 (released 2024). It's free as a PDF for internal and consultative use, downloadable from cisecurity.org/benchmark/microsoft_365.
Unlike SCuBA (federal publisher, ScubaGear as bundled evaluation tool), CIS publishes the document — implementation is up to the consumer. Vendors like Tenable, Rapid7, or Microsoft Compliance Manager ship evaluators that map against CIS, but they're not from CIS directly.
The two levels
The benchmark splits each control into two levels:
- Level 1 (L1) — controls considered operational baseline. Reduce material risk without significantly impacting day-to-day product utility. Designed to be applicable by any tenant without an extensive change-management process.
- Level 2 (L2) — robust-security controls for sensitive environments. May require trade-offs (productivity, cost, operational complexity) and apply selectively.
A tenant at 100% L1 is not "fully secure" — it's a tenant that cleared the floor. L2 is the defensible ceiling. Any mid-market organisation with regulated data (finance, health, government) should target L2 on the sections that apply.
The seven sections
v3.0 organises ~140 controls into seven main sections:
1. Account / Authentication — password policy, MFA, conditional access, federation. The densest section.
2. Application Permissions — OAuth consents, app registration, service principal permissions.
3. Data Management — DLP, sensitivity labels, retention policies, BYOD restrictions.
4. Email Security / Exchange Online — SPF, DKIM, DMARC, anti-phish, auto-forwarding, mailbox auditing.
5. Auditing — Unified Audit Log, retention, alerting.
6. Storage — SharePoint / OneDrive sharing, external access, version history.
7. Mobile Device Management — Intune, compliance policies, app protection.
Each control has a stable number (e.g. `1.1.1` for "Ensure Security Defaults is disabled on Azure Active Directory" — where "disabled" makes sense only if you have more granular Conditional Access configured).
How it differs from SCuBA and Secure Score
| | CIS Microsoft 365 v3.0 | CISA SCuBA | Microsoft Secure Score |
|---|---|---|---|
| Publisher | CIS (industry) | CISA (US federal) | Microsoft |
| Scope | Microsoft 365 + operational recommendations | Microsoft 365 strictly technical | Microsoft 365 + Defender + Azure AD |
| Output form | PDF with controls + levels | Policy with stable ID | Relative 0–100% score |
| Evaluation mechanism | Manual or via third-party evaluator | ScubaGear (bundled) | Native portal |
| Granularity | L1 / L2 | Single baseline | Per individual feature |
CIS is broader than SCuBA but less auditable (no stable ID like `MS.AAD.3.1v1` — controls have numbers but versions evolve). Secure Score is more visible but less defensible to an auditor — it goes up and down with Microsoft's feature catalogue.
How simiriki treats it
simiriki explicitly cites CIS Microsoft 365 v3.0 on Posture Brief Page 3 as one of the primary framework references. The 201 rules in `packages/scan-core/src/registry.ts` map to CIS controls in JSDoc comments with the v3.0 control number. Coverage: L1 at 95%+, L2 at ~70% (some L2 — custom complex-password policies, app-registry review in Microsoft AppSource — can't be evaluated via Graph API and require manual validation).
Honest gap worth naming: CIS L2 includes operational controls (user training, quarterly documentation review) no tool can evaluate automatically. Any "CIS L2 audit" promising 100% automated coverage is misrepresenting framework scope.
Why many PDFs cite it wrong
Common errors in "Microsoft 365 audit" PDFs that reference CIS:
1. Conflating L1 and L2. Reporting "tenant 92% CIS compliant" without specifying the level — because L1 and L2 are distinct control universes.
2. Citing v2.0 when v3.0 is current. v3.0 changed several controls, removed obsolete ones, added controls for Teams + Power Platform. v2.x is no longer maintained.
3. Mixing CIS with Secure Score. "Your Secure Score went up, that means your CIS compliance also did" — false. Different metrics. Microsoft can raise your Secure Score by enabling a feature CIS doesn't consider baseline.
Bottom line
CIS Microsoft 365 Foundations Benchmark v3.0 is the most-cited standard and, used properly, the most useful for technical Microsoft 365 audit in regulated environments. The right question to ask your MSP is: "what version of the benchmark, what level did you evaluate, and where are the L2 gaps documented?" If the answer is "92% CIS compliant" without that specificity, you're not getting an audit — you're getting a metric.
Related reading:
Is your business protected?
A free Microsoft 365 audit—the automated scan delivers a preview in 90 seconds. Find risks before they become incidents.