Skip to content
Tenant Excellence

Applies toEvery tenant · every package

M365 Best Practices Check

A CIS-inspired configuration baseline for Microsoft 365, scored control by control with a manual-verification guide where Graph cannot answer. Advisory; not a CIS certification.

All packages

Scope as evaluated

  • Identity: MFA, Conditional Access, legacy authentication, admin hygiene
  • Email: SPF, DKIM, DMARC and anti-phishing settings
  • Collaboration: sharing, guest access and retention

Read from the tenant

  • Entra ID and Exchange Online settings through Graph
  • DNS records for every domain
  • SharePoint and Teams sharing configuration

Sample controls

  • 1.1.1 MFA for administrative roles
  • 2.1.9 DMARC records
  • 7.2.3 External sharing
Results are configuration indications drawn from your tenant. They are not an audit opinion or a certification.

In depth

Give the auditor a link, not a folder

Every covered control shows the data Microsoft Graph returned and the endpoint it came from. One click creates a read-only snapshot for one framework; it needs no account and expires after 24 hours.

  • Structured proof per control, with its Graph or ARM source
  • Scoped to one framework, read-only, no sign-in for the auditor
  • Expires after 24 hours; creation is written to the audit log
Learn more

Questions

Questions about M365 Best Practices Check

Is this a CIS Benchmark certification?

No. The catalogue is inspired by CIS guidance and is advisory. It is not a CIS product or certification.

Is it in Essential?

Yes. The M365 Best Practices Check is in every package.

What is the manual-verification guide?

For controls Graph cannot read, the guide gives the admin-centre path or PowerShell command to check, and you record the result.

Request a demo

Which frameworks do you report against?

Tell us in the demo request and we will show the matching controls on a demo tenant.

0 / 2,000