CIS Microsoft 365 Foundations Benchmark v7.0.0

Measure your Microsoft 365 against a real security standard.

I review your tenant against the 114Level 1 controls of the CIS Microsoft 365 Foundations Benchmark, harden the ones it's safe to, and hand you a clear pass/fail report you can see in your portal — and show to an insurer or auditor. No guesswork, no jargon.

Microsoft Partner
Cyber Essentials aligned
UK-based MSP
Why it matters

A licence isn't a configuration.

Microsoft 365 ships with sensible defaults for getting started — not for staying secure. The settings that actually protect you are scattered across the admin centres, off by default, and easy to miss. A benchmark gives you an objective checklist to hold your tenant against, so "secure" stops being a feeling and becomes something you can measure.

You can't see what's misconfigured

Microsoft 365 has hundreds of security settings spread across six admin centres. Without a structured benchmark to check them against, there's no way to know which ones are leaving you exposed.

Defaults favour convenience, not safety

Out of the box, legacy authentication is allowed, sharing is wide open and auditing is patchy. Each one is a small gap — together they're an open door.

Insurers and clients want evidence

Cyber insurance renewals and larger customers increasingly ask you to prove your cloud is configured to a recognised standard. "We think it's fine" is no longer an answer.

What I check

114Level 1 controls, across every corner of your tenant.

The benchmark spans nine areas of Microsoft 365. I assess each control, mark it pass, fail or not-applicable, and harden the ones that are safe to enable.

9 controls

Microsoft 365 admin center

Admin-center users, groups and tenant-wide settings.

15 controls

Microsoft Defender

Email, collaboration and threat-protection policies.

5 controls

Microsoft Purview

Audit logging, data loss prevention and information protection.

2 controls

Microsoft Intune

Device compliance and enrolment controls.

45 controls

Microsoft Entra ID

Identity, conditional access and privileged roles.

10 controls

Exchange Online

Mailbox auditing, mail flow and Outlook add-ins.

7 controls

SharePoint & OneDrive

External sharing and access controls.

10 controls

Microsoft Teams

External access, meetings and app permissions.

11 controls

Microsoft Fabric

Power BI / Fabric tenant sharing and access.

How it works

Review, tune, and a report you can actually use.

Step 1

Review against the benchmark

I work through every Level 1 recommendation of the CIS Microsoft 365 Foundations Benchmark v7.0.0 against your live tenant — identity, email, sharing, devices and auditing — and record a pass, fail or not-applicable for each.

Step 2

Tune what's safe to tune

Where a control can be enabled without disrupting how your team works, I harden it there and then — with a note of exactly what changed and why. Anything with a trade-off I flag for a quick chat first.

Step 3

See it in your portal

Your results live in your client portal: a score, every control with its status and my notes, plus any evidence attached. You can watch it improve and show it to an insurer or auditor whenever you need to.

One-off engagement
Get a quote

A complete CIS Level 1 review of your tenant, hardening of the controls that are safe to enable, and your results kept in your portal. Final price is confirmed after a quick look at your tenant — no surprises.

  • All 114 CIS Level 1 controls reviewed
  • Safe controls hardened, trade-offs flagged first
  • Pass/fail report visible in your client portal
  • Re-runnable for insurance or audit evidence
Request a review
FAQ

Common questions

What is the CIS Microsoft 365 Foundations Benchmark?+

It's a freely-published, vendor-neutral security standard maintained by the Center for Internet Security. It defines, in precise terms, how a Microsoft 365 tenant should be configured to reduce risk. I review against v7.0.0, Level 1 — the practical baseline that improves security without getting in the way of day-to-day work.

What's the difference between Level 1 and Level 2?+

Level 1 is the essential baseline — sensible, low-friction settings every tenant should have. Level 2 adds stricter, higher-impact controls (things like privileged-access management and token protection) that suit larger or higher-risk organisations. For most small businesses, Level 1 is the right place to focus, and it's what this review covers.

Will hardening these settings break things for my staff?+

That's exactly why this is a review-and-tune, not a blind switch-flip. I only apply changes that are safe for how your team actually works, and anything with a trade-off (a setting that might change someone's workflow) I flag and talk through with you first. Nothing happens to your tenant without you knowing.

Do I need particular Microsoft licences?+

The Level 1 controls are achievable on Microsoft 365 Business Premium, which most small businesses are best on anyway. A handful of items lean on features in higher plans — where that's the case I'll tell you plainly whether it's worth it for you, rather than pushing licences you don't need.

How does this relate to your Microsoft 365 Security & Management service?+

They complement each other. The Security & Management service sets up and actively manages Defender, Intune and Conditional Access. This CIS review is a structured audit of the whole tenant against an external standard — a great one-off health check, and an ideal companion to ongoing management or a Cyber Essentials submission.

Is it a one-off or ongoing?+

It's a one-off engagement with a fixed report at the end. Because your results stay in the portal, it's easy to re-run later — after a big change, an insurance renewal, or when a new benchmark version lands — to confirm you're still where you should be.

Request a review

Let's benchmark your tenant.

Tell me a little about your business and how many users you have. I'll come back within one working day to arrange your CIS Microsoft 365 Benchmark review — clear, practical and in plain English.

I'll only use your details to reply to your enquiry. No newsletters, no sharing.