Showing all 49 failing findings.
IAM-001
Require MFA for all users
Critical
Expert-assisted — not auto-applied
EvidenceNo CA policy requires MFA; 120 accounts can sign in with a password only.
FixCreate a Conditional Access policy requiring MFA for all users / all apps.
SCuBA MS.AAD.3.2v1Secure ScoreCIS 1.1.1NIST PR.AC-7
IAM-002
Block legacy authentication
Critical
Expert-assisted — not auto-applied
EvidenceNo Conditional Access policy blocks legacy authentication.
FixCreate a CA policy blocking legacy authentication protocols.
SCuBA MS.AAD.1.1v1Secure ScoreCIS 1.2.1NIST PR.AC-7
EXO-001
External mailbox auto-forwarding blocked
Critical
Expert-assisted — not auto-applied
Evidence1 mailbox(es) forward mail to an external address; the outbound spam policy permits it tenant-wide.
Affected‹CONTOSO_USER_09›
FixSet AutoForwardingMode to Off in the outbound anti-spam policy and remove forwarding rules.
SCuBA MS.EXO.1.1v2Secure ScoreCIS 4.2.1NIST PR.DS-5
IAM-003
MFA registered for all active users
High
Expert-assisted — not auto-applied
EvidenceStrong MFA registered for 82% of users — 22 accounts have no second factor.
FixDrive registration via the Authentication Methods policy + a registration campaign.
Secure ScoreNIST PR.AC-1
ADM-004
Admins require phishing-resistant MFA
High
Expert-assisted — not auto-applied
EvidenceNo Conditional Access policy requires phishing-resistant MFA for administrative roles.
FixCA policy scoping admin roles to phishing-resistant authentication strength.
SCuBA MS.AAD.3.6v1Secure ScoreCIS 1.1.2NIST PR.AC-7
APP-001
User consent to apps restricted
High
Expert-assisted — not auto-applied
EvidenceAny user may grant third-party OAuth apps access to organizational data.
FixRestrict user consent + enable the admin consent request workflow.
SCuBA MS.AAD.5.2v1Secure ScoreCIS 5.1.5NIST PR.AC-4
EXO-006
SMTP AUTH disabled tenant-wide
High
Expert-assisted — not auto-applied
EvidenceSMTP AUTH is enabled tenant-wide (legacy protocol that bypasses MFA).
FixDisable SMTP AUTH tenant-wide; enable per-mailbox only for legacy line-of-business needs.
SCuBA MS.EXO.5.1v1NIST PR.AC-7
DEF-001
Microsoft Secure Score baseline
High
Expert-assisted — not auto-applied
EvidenceMicrosoft Secure Score is 47% (282/600).
FixWork the top Secure Score improvement actions by impact.
Secure ScoreNIST ID.RA-1
DEF-002
Preset security policies (Standard or Strict) enabled
High
Expert-assisted — not auto-applied
EvidenceNo preset security policy (Standard/Strict) is enabled.
FixEnable the Standard (or Strict) preset security policy for all users.
SCuBA MS.DEFENDER.1.1v1NIST PR.IP-1
DEF-003
Safe Attachments enabled
High
Expert-assisted — not auto-applied
EvidenceSafe Attachments is not enabled.
FixEnable Safe Attachments (Block action) and Safe Docs for O365.
SCuBA MS.DEFENDER.3.1v1NIST DE.CM-4
DEF-004
Safe Links enabled
High
Expert-assisted — not auto-applied
EvidenceSafe Links is not enabled.
FixEnable Safe Links for email/Teams/Office with URL rewrite + click tracking.
NIST DE.CM-4
DEF-005
Anti-phishing impersonation protection configured
High
Expert-assisted — not auto-applied
EvidenceAnti-phishing impersonation/mailbox-intelligence protection is incomplete.
FixConfigure user/domain impersonation protection and mailbox intelligence in the anti-phish policy.
SCuBA MS.DEFENDER.2.1v1NIST DE.CM-4
SHR-001
External sharing not set to "Anyone"
High
Expert-assisted — not auto-applied
EvidenceOrganization sharing is set to 'Anyone' — anonymous links are permitted across all sites.
FixSet org sharing to 'New and existing guests' or stricter.
SCuBA MS.SHAREPOINT.1.1v1Secure ScoreCIS 7.2.xNIST PR.DS-5
ADM-011
Privileged users use finer-grained roles instead of Global Administrator
High
Expert-assisted — not auto-applied
Evidence7 Global Administrator(s) exceed the 2 member(s) in finer-grained roles — over-provisioned on GA.
FixReassign day-to-day admins from Global Administrator to least-privilege roles (User/Exchange/SharePoint/Security Administrator, etc.).
SCuBA MS.AAD.7.2v1NIST PR.AC-4
IAM-008
Phishing-resistant MFA available/enforced for all users
Medium
Expert-assisted — not auto-applied
EvidenceNo phishing-resistant authentication method is enabled.
FixEnable phishing-resistant methods; pilot an auth-strength CA policy before enforcing tenant-wide.
SCuBA MS.AAD.3.1v1Secure ScoreNIST PR.AC-7
IAM-009
SMS/Voice is not an allowed primary MFA method
Medium
Expert-assisted — not auto-applied
EvidenceSMS or Voice is still enabled as an MFA method.
FixDisable SMS/Voice as a primary method in the Authentication Methods policy after migrating users to Authenticator/FIDO2.
SCuBA MS.AAD.3.5v1NIST PR.AC-7
IAM-010
Microsoft Authenticator shows login context (number matching)
Medium
Expert-assisted — not auto-applied
EvidenceAuthenticator number matching is not enabled.
FixEnable number matching + app/geo context in the Authenticator method configuration.
SCuBA MS.AAD.3.3v2NIST PR.AC-7
IAM-013
Guest sign-ins require MFA
Medium
Expert-assisted — not auto-applied
EvidenceNo Conditional Access policy requires MFA for guest / external users.
FixAdd a CA policy requiring MFA for guest and external users.
NIST PR.AC-7
ADM-005
Privileged users are cloud-only accounts
Medium
Expert-assisted — not auto-applied
Evidence1 privileged account(s) are synced from on-premises, not cloud-only.
Affected‹CONTOSO_USER_03›
FixMove privileged assignments to dedicated cloud-only admin identities.
SCuBA MS.AAD.7.3v1NIST PR.AC-4
APP-003
Admin consent request workflow enabled
Medium
Expert-assisted — not auto-applied
EvidenceThe admin consent request workflow is disabled.
FixEnable the admin consent request workflow and assign reviewers.
SCuBA MS.AAD.5.3v1NIST PR.AC-4
APP-005
App registration restricted to admins
Medium
Expert-assisted — not auto-applied
EvidenceAny user can register applications.
FixDisable users' ability to register applications.
SCuBA MS.AAD.5.1v1CIS 5.1.2NIST PR.AC-4
APP-006
No stale or long-lived app credentials
Medium
Expert-assisted — not auto-applied
Evidence1 app credential(s) are expired-but-present or valid > 12 months.
Affected‹CONTOSO_USER_08›
FixRotate/remove stale secrets; move to certificate credentials with short lifetimes.
NIST PR.AC-1
EXO-005
DMARC policy enforced (p=reject)
Medium
Expert-assisted — not auto-applied
EvidenceDMARC is not at p=reject on 1 domain(s) — failures are reported, not blocked.
FixProgress DMARC p=none -> p=quarantine -> p=reject after monitoring aggregate reports.
SCuBA MS.EXO.4.2v1CIS 2.1.xNIST PR.DS-2
DEF-006
Common attachment / malware filter configured
Medium
Expert-assisted — not auto-applied
EvidenceThe common attachment types filter is not enabled.
FixEnable the common attachment types filter and malware ZAP.
NIST DE.CM-4
SHR-002
Guest access restrictions configured
Medium
Expert-assisted — not auto-applied
EvidenceGuest users inherit broad (member-equivalent) directory access.
FixSet guest user access to the most restrictive role.
SCuBA MS.AAD.8.1v1Secure ScoreCIS 1.xNIST PR.AC-4
TMS-001
External access (federation) restricted
Medium
Expert-assisted — not auto-applied
EvidenceTeams external federation is open to all domains.
FixRestrict federation to an allow-list of partner domains.
SCuBA MS.TEAMS.2.1v2NIST PR.AC-3
TMS-005
Third-party and custom app usage governed
Medium
Expert-assisted — not auto-applied
EvidenceThird-party and custom Teams apps are globally allowed by default.
FixRestrict third-party and custom app permission policies.
SCuBA MS.TEAMS.5.2v2NIST PR.IP-1
DEV-002
Conditional Access requires a compliant / hybrid-joined device
Medium
Expert-assisted — not auto-applied
EvidenceNo Conditional Access policy requires a compliant or hybrid-joined device.
FixAdd a device-based Conditional Access grant control.
SCuBA MS.AAD.3.7v1NIST PR.AC-3
DEF-008
Security alerts routed to a monitored address / SIEM
Medium
Expert-assisted — not auto-applied
EvidenceSecurity alerts are not routed to a monitored address or SIEM.
FixSet alert notification recipients and/or forward to the SIEM.
SCuBA MS.DEFENDER.5.2v1NIST DE.CM-1
IAM-011
Migrated off legacy per-user MFA to the Authentication Methods policy
Low
Expert-assisted — not auto-applied
EvidenceStill managing MFA via the legacy per-user portal (migration incomplete).
FixComplete the Authentication Methods policy migration.
SCuBA MS.AAD.3.4v1NIST PR.AC-7
IAM-012
Cloud account password expiration disabled
Low
Expert-assisted — not auto-applied
Evidence1 domain(s) still expire passwords (NIST advises never-expire + MFA).
FixSet password policy to never expire for cloud accounts (pair with MFA + risk-based detection).
SCuBA MS.AAD.6.1v1Secure ScoreNIST PR.AC-1
IAM-014
Self-service password reset with strong verification
Low
Expert-assisted — not auto-applied
EvidenceSSPR is enabled but weak (security questions on, or <2 strong methods).
FixEnable SSPR with two strong methods; disable security questions.
Secure ScoreNIST PR.AC-1
IAM-015
Device registration/join requires MFA
Low
Expert-assisted — not auto-applied
EvidenceDevice join/registration does not require MFA.
FixRequire MFA to join or register devices.
NIST PR.AC-7
EXO-008
External sender identification enabled
Low
Expert-assisted — not auto-applied
EvidenceExternal-sender identification (the [External] tag) is not enabled.
FixEnable native external sender identification.
SCuBA MS.EXO.7.1v1NIST PR.AT-1
EXO-010
Additional storage providers disabled in Outlook on the web
Low
Expert-assisted — not auto-applied
EvidenceThird-party storage providers (Box/Dropbox/…) are available in OWA.
FixDisable additional storage providers in the OWA mailbox policy.
NIST PR.DS-5
TMS-002
Contact with unmanaged / Skype consumer users blocked
Low
Expert-assisted — not auto-applied
EvidenceContact with Teams consumer / unmanaged accounts is allowed.
FixDisable federation with consumer/unmanaged accounts.
SCuBA MS.TEAMS.2.2v2NIST PR.AC-3
TMS-004
Meeting lobby admits authenticated users only
Low
Expert-assisted — not auto-applied
EvidenceThe meeting lobby auto-admits everyone (external/anonymous included).
FixSet the lobby to admit organization/trusted users automatically only.
SCuBA MS.TEAMS.1.3v1NIST PR.AC-3
TMS-006
Teams email integration disabled
Low
Expert-assisted — not auto-applied
EvidenceEmail-into-channel is enabled.
FixDisable email-into-channel.
SCuBA MS.TEAMS.4.1v1NIST PR.DS-5
LOG-003
Audit log retention adequate
Low
Expert-assisted — not auto-applied
EvidenceAudit log retention is only 90 days (< 1 year).
FixCreate an audit-log retention policy for the required window.
SCuBA MS.DEFENDER.6.3v1NIST PR.PT-1
DEV-004
Mobile app protection (MAM) policies configured
Low
Expert-assisted — not auto-applied
EvidenceNo mobile app protection (MAM) policies exist.
FixCreate MAM app protection policies for mobile platforms.
NIST PR.DS-5
EXO-011
Contact folders not shared with all domains
Low
Expert-assisted — not auto-applied
EvidenceA sharing policy shares contact folders with all domains.
FixRestrict contact-folder sharing to specific domains.
SCuBA MS.EXO.6.1v1NIST PR.DS-5
EXO-012
Calendar details not shared with all domains
Low
Expert-assisted — not auto-applied
EvidenceA sharing policy shares calendar details with all domains.
FixRestrict calendar sharing to specific domains / free-busy only.
SCuBA MS.EXO.6.2v1NIST PR.DS-5
SHR-012
Guest invitations restricted to inviters
Low
Expert-assisted — not auto-applied
EvidenceAny user can invite guests (allowInvitesFrom=everyone).
FixSet guest-invite permission to admins and Guest Inviter role holders.
SCuBA MS.AAD.8.2v1NIST PR.AC-4
TMS-007
External participants cannot request control of shared desktop
Low
Expert-assisted — not auto-applied
EvidenceExternal participants can request control of a shared desktop.
FixDisable external participant give/request control.
SCuBA MS.TEAMS.1.1v1NIST PR.AC-3
TMS-008
Internal users cannot initiate contact with unmanaged users
Low
Expert-assisted — not auto-applied
EvidenceInternal users can start chats with unmanaged users.
FixDisable internal-to-unmanaged outbound contact.
SCuBA MS.TEAMS.2.3v2NIST PR.AC-3
TMS-009
Only agency-approved Microsoft apps installable
Low
Expert-assisted — not auto-applied
EvidenceAll Microsoft Teams apps are installable by default.
FixRestrict the Microsoft-app permission policy to approved apps.
SCuBA MS.TEAMS.5.1v2NIST PR.IP-1
TMS-010
Meeting recording restricted
Low
Expert-assisted — not auto-applied
EvidenceMeeting cloud recording is enabled.
FixDisable or scope cloud recording in the meeting policy.
SCuBA MS.TEAMS.1.6v1NIST PR.DS-5
TMS-011
Dial-in (PSTN) users cannot bypass the meeting lobby
Low
Expert-assisted — not auto-applied
EvidenceDial-in (PSTN) users can bypass the meeting lobby.
FixSet AllowPSTNUsersToBypassLobby to false in the meeting policy.
SCuBA MS.TEAMS.1.5v1NIST PR.AC-3
TMS-012
Live events are not forced to always record
Low
Expert-assisted — not auto-applied
EvidenceLive events are forced to always record (BroadcastRecordingMode=AlwaysEnabled).
FixChange the live-event broadcast recording mode away from Always record (use organizer choice).
SCuBA MS.TEAMS.1.7v2NIST PR.DS-5
IAM-004Security Defaults OR Conditional Access in forcePassed
EXO-002SPF record publishedPassed
EXO-003DKIM signing enabled for all domainsPassed
EXO-004DMARC record publishedPassed
LOG-001Unified audit log enabledPassed
EXO-007Mailbox auditing enabledPassed
EXO-009Connector/IP allow-list not used to bypass filteringPassed
DEF-007Security alerts enabledPassed
DEV-001Intune compliance policies existPassed
DEV-003Disk encryption (BitLocker/FileVault) enforcedPassed
TMS-003Anonymous users cannot start meetingsPassed
These controls were evaluated, but their framework mapping / check is not yet reconciled against the pinned baseline, so their result is shown as Not verified rather than a pass or fail, and is not counted in the headline grade. They are verified during the live calibration pass.
ADM-001Global Administrator count right-sizedNot verified
BasisdirectoryRole members; ScubaGear v1.8.0 MS.AAD.7.1 (fetched)
ADM-002Break-glass emergency account exists and is CA-excludedNot verified
BasisBreak-glass is an operational concept, not a Graph property
SHR-009OneDrive external sharing limitedNot verified
BasisGraph v1.0 sharepointSettings (fetched); MS.SHAREPOINT.1.2v1
SHR-003"Anyone" link expiration and permission limitedNot verified
BasisGraph v1.0 sharepointSettings (fetched); MS.SHAREPOINT.3.1v1
SHR-006SharePoint custom scripts disabledNot verified
BasisGraph v1.0 sharepointSettings (fetched)
LOG-002Sign-in and audit logs exported to durable storage / SIEMNot verified
BasisAzure Monitor diagnostic settings (Lighthouse), not a tenant M365 Graph read; MS.AAD.4.1v1
IAM-016Device code authentication flow blockedNot verified
BasisCA conditions.authenticationFlows.transferMethods (deviceCodeFlow); MS.AAD.3.9v1
APP-004Group owner consent restrictedNot verified
BasisGraph v1.0 authorizationPolicy (fetched)
SHR-004Default sharing link scope is specific peopleNot verified
BasisGraph v1.0 sharepointSettings (fetched); MS.SHAREPOINT.2.1v1
SHR-005Reauthentication required for external usersNot verified
BasisGraph v1.0 sharepointSettings (fetched); MS.SHAREPOINT.3.3v2
APP-007Application password (secret) credential addition blockedNot verified
BasisGraph BETA appManagementPolicy / defaultAppManagementPolicy (not re-fetched); MS.AAD.5.5v1
SHR-010Default file/folder sharing permission is view-onlyNot verified
BasisGraph v1.0 sharepointSettings (fetched); MS.SHAREPOINT.2.2v1
SHR-011"Anyone" link permission is view-onlyNot verified
BasisGraph v1.0 sharepointSettings (fetched); MS.SHAREPOINT.3.2v1
APP-002No over-privileged / illicit OAuth grantsNot verified
BasisGraph v1.0 oauth2PermissionGrants + servicePrincipals (not re-fetched)
IAM-007High-risk users are blocked or remediatedNot assessedrequires EntraP2, not licensed on this tenant
IAM-005Sign-in risk policy enabledNot assessedrequires EntraP2, not licensed on this tenant
IAM-006User risk policy enabledNot assessedrequires EntraP2, not licensed on this tenant
ADM-003Privileged roles are PIM-eligible, not permanently activeNot assessedrequires EntraP2, not licensed on this tenant
ADM-006Privileged role activation requires approvalNot assessedrequires EntraP2, not licensed on this tenant
ADM-007Privileged role activation/assignment alertingNot assessedrequires EntraP2, not licensed on this tenant
PWR-001Environment creation restricted to adminsNot assessedrequires PowerPlatform, not licensed on this tenant
PWR-003DLP policy on the default environmentNot assessedrequires PowerPlatform, not licensed on this tenant
PWR-004Power Platform tenant isolation enabledNot assessedrequires PowerPlatform, not licensed on this tenant
DLP-001DLP policies protect sensitive informationNot assessedrequires Purview, not licensed on this tenant
ADM-009Privileged role provisioning restricted to PIM/PAMNot assessedrequires EntraP2, not licensed on this tenant
PWR-005Non-default environments covered by a DLP policyNot assessedrequires PowerPlatform, not licensed on this tenant
DLP-004Custom DLP policy scoped to Exchange, OneDrive, SharePoint, Teams, and DevicesNot assessedrequires Purview, not licensed on this tenant
DLP-005DLP policy blocks sharing sensitive information with everyoneNot assessedrequires Purview, not licensed on this tenant
PWR-007Content Security Policy enforced for Power AppsNot assessedrequires PowerPlatform, not licensed on this tenant
PWR-009Share with Everyone disabled in Power AppsNot assessedrequires PowerPlatform, not licensed on this tenant
ADM-008Access reviews for privileged roles and guestsNot assessedrequires EntraP2, not licensed on this tenant
PWR-002Trial environment creation restrictedNot assessedrequires PowerPlatform, not licensed on this tenant
DLP-002Sensitivity labels publishedNot assessedrequires Purview, not licensed on this tenant
DLP-003Retention policy configuredNot assessedrequires Purview, not licensed on this tenant
IAM-017Admin notification on high-risk usersNot assessedrequires EntraP2, not licensed on this tenant
ADM-010Alert on Global Administrator activationNot assessedrequires EntraP2, not licensed on this tenant
PWR-006Power Platform connection allow-list configuredNot assessedrequires PowerPlatform, not licensed on this tenant
DLP-006DLP policy notifies and educates usersNot assessedrequires Purview, not licensed on this tenant
DLP-007Restricted-apps list defined for endpoint DLPNot assessedrequires Purview, not licensed on this tenant
DLP-008Endpoint DLP blocks restricted apps and unwanted Bluetooth transfersNot assessedrequires Purview, not licensed on this tenant
PWR-008Power Pages site creation restricted to adminsNot assessedrequires PowerPlatform, not licensed on this tenant