What AuditKit scans in Microsoft 365 via ScubaGear integration.

Overview

Coverage: 100+ rules via CISA ScubaGear integration
Supported in: Free and Pro versions
Method: Import ScubaGear scan results into AuditKit

Supported frameworks: - SOC2 Type II - PCI-DSS v4.0.1

Imported M365 findings currently carry SOC2 and PCI-DSS mappings only. CMMC, HIPAA and NIST 800-53 mappings for ScubaGear rules are not yet implemented.

Why ScubaGear? - Official CISA tool for M365 security - Free and open-source - Comprehensive security baseline - Regular updates from CISA

How It Works

1. Run ScubaGear (Windows PowerShell)
   ↓
2. Generate ScubaResults_<uuid>.json
   ↓
3. Import to AuditKit
   ↓
4. Get compliance-mapped report

Setup guide →

Covered Domains

134 ScubaGear rules, each mapped to SOC 2 criteria and PCI DSS requirements, read from the mapping files the scanner ships. Identifiers are ScubaGear's own; the parser matches them with or without the version suffix (MS.AAD.1.1 and MS.AAD.1.1v1 are the same rule).

Entra ID - 30 rules

  • MS.AAD.1.1 - Legacy authentication blocked
  • MS.AAD.2.1 - Block high-risk users
  • MS.AAD.2.2 - Notify admins on high-risk users
  • MS.AAD.2.3 - Block high-risk sign-ins
  • MS.AAD.3.1 - Phishing-resistant MFA for all users
  • MS.AAD.3.2 - Enforce MFA (any approved method) for all users
  • MS.AAD.3.3 - Authenticator shows app/location context
  • MS.AAD.3.4 - Authentication methods migration completed/managed
  • MS.AAD.3.5 - Disable SMS/Voice/Email OTP
  • MS.AAD.3.6 - Phishing-resistant MFA for privileged roles
  • MS.AAD.3.7 - Require managed devices for authentication
  • MS.AAD.3.8 - Require managed device to register MFA
  • MS.AAD.3.9 - Block device-code authentication flow
  • MS.AAD.4.1 - Send security logs to SIEM/SOC
  • MS.AAD.5.1 - Only admins may register applications
  • MS.AAD.5.2 - Only admins may consent to applications
  • MS.AAD.5.3 - Admin consent workflow configured
  • MS.AAD.6.1 - User passwords do not expire (policy-based)
  • MS.AAD.7.1 - Limit Global Admins (2–8)
  • MS.AAD.7.2 - Use finer-grained roles instead of Global Admin
  • MS.AAD.7.3 - Privileged users use cloud-only accounts
  • MS.AAD.7.4 - No permanent active privileged assignments
  • MS.AAD.7.5 - Provision privileged roles via PIM/PAM
  • MS.AAD.7.6 - Global Administrator activation requires approval
  • MS.AAD.7.7 - Alert on eligible or active privileged role assignment
  • MS.AAD.7.8 - Alert on Global Administrator activation
  • MS.AAD.7.9 - Alert on other privileged role activations
  • MS.AAD.8.1 - Limit guest access to directory objects
  • MS.AAD.8.2 - Only Guest Inviter role can invite guests
  • MS.AAD.8.3 - Restrict guest invitations to approved domains

Exchange Online - 40 rules

  • MS.EXO.1.1 - Disable automatic email forwarding to external domains
  • MS.EXO.2.2 - Publish an SPF record for all domains and enforce hard fail for non-approved senders
  • MS.EXO.3.1 - Enable DKIM for all custom domains
  • MS.EXO.4.1 - Publish a DMARC policy for all second-level domains
  • MS.EXO.4.2 - Set DMARC policy enforcement to p=reject
  • MS.EXO.4.3 - Include reports@dmarc.cyber.dhs.gov in DMARC aggregate reports
  • MS.EXO.4.4 - Include agency-specific contact addresses in DMARC aggregate and failure reports
  • MS.EXO.5.1 - Disable SMTP AUTH for the organization
  • MS.EXO.6.1 - Restrict contact folder sharing with all domains
  • MS.EXO.6.2 - Restrict calendar detail sharing with all domains
  • MS.EXO.7.1 - Implement external sender warnings in Exchange Online
  • MS.EXO.8.1 - Implement a Data Loss Prevention (DLP) solution for Exchange Online
  • MS.EXO.8.2 - Ensure DLP policies protect personally identifiable and sensitive information
  • MS.EXO.8.3 - If using third-party DLP, ensure feature parity with Microsoft native capabilities
  • MS.EXO.8.4 - Restrict sharing of PII including credit card numbers, SSNs, and ITINs via email
  • MS.EXO.9.1 - Enable attachment file type filtering in Exchange Online
  • MS.EXO.9.2 - Ensure the attachment filter verifies true file type and file extension consistency
  • MS.EXO.9.3 - Determine and enforce list of disallowed email attachment file types
  • MS.EXO.9.4 - Ensure third-party attachment filtering matches Microsoft Defender baseline
  • MS.EXO.9.5 - Block common click-to-run file types (e.g., .exe, .cmd, .vbe)
  • MS.EXO.10.1 - Enable malware scanning for all inbound and outbound emails
  • MS.EXO.10.2 - Quarantine or drop emails detected as containing malware
  • MS.EXO.10.3 - Enable post-delivery scanning to detect and remove malware from delivered messages
  • MS.EXO.11.1 - Enable impersonation protection checks in Exchange Online
  • MS.EXO.11.2 - Display user warnings and safety tips for suspected phishing emails
  • MS.EXO.11.3 - Enable AI-based phishing detection using Mailbox Intelligence
  • MS.EXO.12.1 - Avoid use of IP allow lists that bypass spam and authentication checks
  • MS.EXO.12.2 - Disable global safe lists to prevent bypassing security mechanisms
  • MS.EXO.13.1 - Enable mailbox auditing for all Exchange Online users
  • MS.EXO.14.1 - Enable spam filtering for inbound email in Exchange Online
  • MS.EXO.14.2 - Quarantine or move spam and high-confidence spam to junk folders
  • MS.EXO.14.3 - Prohibit adding entire domains to inbound allow lists in spam policies
  • MS.EXO.14.4 - Validate third-party spam filtering is equivalent to Microsoft Defender baseline
  • MS.EXO.15.1 - Enable Safe Links URL scanning and block-list comparison for incoming email
  • MS.EXO.15.2 - Enable real-time malware scanning for direct download links in emails
  • MS.EXO.15.3 - Enable user click tracking for Safe Links-protected emails
  • MS.EXO.16.1 - Enable alert policies for suspicious and service-impacting activities in Exchange Online
  • MS.EXO.16.2 - Send alerts to monitored mailbox or integrate with SIEM for central review
  • MS.EXO.17.1 - Enable Unified Audit Logging in Microsoft 365 for Exchange Online
  • MS.EXO.17.3 - Retain Unified Audit Logs for minimum 12 months active and 18 months cold storage

SharePoint Online - 8 rules

  • MS.SHAREPOINT.1.1 - Limit external sharing for SharePoint to existing guests or internal users only
  • MS.SHAREPOINT.1.2 - Limit external sharing for OneDrive to existing guests or internal users only
  • MS.SHAREPOINT.1.3 - Restrict external sharing to approved domains or security groups
  • MS.SHAREPOINT.2.1 - Set default file and folder sharing scope to Specific people
  • MS.SHAREPOINT.2.2 - Set default file and folder sharing permission to View only
  • MS.SHAREPOINT.3.1 - Set expiration for Anyone links to 30 days or less
  • MS.SHAREPOINT.3.2 - Set permissions for Anyone links to View only
  • MS.SHAREPOINT.3.3 - Require reauthentication for verification code users every 30 days or less

Teams - 21 rules

  • MS.TEAMS.1.1 - Disable external participants from requesting control of shared screens in Teams meetings
  • MS.TEAMS.1.2 - Prevent anonymous users from starting Microsoft Teams meetings
  • MS.TEAMS.1.3 - Require lobby admission for anonymous and dial-in users in Teams meetings
  • MS.TEAMS.1.4 - Allow internal users to bypass the lobby automatically in Teams meetings
  • MS.TEAMS.1.5 - Require dial-in users to wait in the lobby before joining Teams meetings
  • MS.TEAMS.1.6 - Disable default meeting recording in Teams to prevent unauthorized data exposure
  • MS.TEAMS.1.7 - Disable 'Always record' for Teams Live Events and restrict to organizer discretion
  • MS.TEAMS.2.1 - Restrict external access in Teams to specific approved domains only
  • MS.TEAMS.2.2 - Block unmanaged Teams users from initiating contact with internal users
  • MS.TEAMS.2.3 - Prevent internal users from initiating chats with unmanaged Teams users
  • MS.TEAMS.4.1 - Disable Teams channel email integration to prevent external message routing
  • MS.TEAMS.5.1 - Restrict Teams integration to approved Microsoft apps only
  • MS.TEAMS.5.2 - Restrict installation of third-party apps to approved selections only
  • MS.TEAMS.5.3 - Restrict Teams custom app installation to approved and verified apps only
  • MS.TEAMS.6.1 - Enable a Data Loss Prevention (DLP) solution to monitor and prevent data leakage in Teams
  • MS.TEAMS.6.1 - Enable a Data Loss Prevention (DLP) solution to monitor and prevent data leakage in Teams
  • MS.TEAMS.6.2 - Configure DLP to detect and protect PII and sensitive information shared in Teams
  • MS.TEAMS.7.1 - Enable malware scanning for Teams file attachments
  • MS.TEAMS.7.2 - Prevent users from opening or downloading malware-detected files in Teams
  • MS.TEAMS.8.1 - Enable Safe Links protection for URLs shared in Teams messages
  • MS.TEAMS.8.2 - Enable user click tracking for Safe Links in Teams messages

Power Platform - 8 rules

  • MS.POWERPLATFORM.1.1 - Restrict creation of production and sandbox environments to admins
  • MS.POWERPLATFORM.1.2 - Restrict creation of trial environments to admins
  • MS.POWERPLATFORM.2.1 - Create DLP policy to restrict connector access in the default environment
  • MS.POWERPLATFORM.2.2 - Apply DLP policies to all non-default environments
  • MS.POWERPLATFORM.3.1 - Enable Power Platform tenant isolation
  • MS.POWERPLATFORM.3.2 - Configure inbound/outbound connection allowlist
  • MS.POWERPLATFORM.4.1 - Enforce Content Security Policy for model-driven and canvas Power Apps
  • MS.POWERPLATFORM.5.1 - Restrict Power Pages creation to admins

Power BI - 8 rules

  • MS.POWERBI.1.1 - Disable Publish to Web feature unless business-justified
  • MS.POWERBI.2.1 - Restrict or disable Power BI guest access
  • MS.POWERBI.3.1 - Disable external invitations unless required by mission need
  • MS.POWERBI.4.1 - Restrict Power BI service principal API access to approved groups
  • MS.POWERBI.4.2 - Restrict service principals creating or using profiles to approved groups
  • MS.POWERBI.5.1 - Block ResourceKey-based authentication unless justified by design
  • MS.POWERBI.6.1 - Disable Python and R visual sharing to reduce script-based risk
  • MS.POWERBI.7.1 - Enable and enforce sensitivity labels for Power BI content

Defender for Office 365 - 19 rules

  • MS.DEFENDER.1.1 - Enable Standard and Strict preset security policies in Microsoft Defender
  • MS.DEFENDER.1.2 - Assign all users to Exchange Online Protection (EOP) via Standard or Strict preset policies
  • MS.DEFENDER.1.3 - Assign all users to Defender for Office 365 protection via preset policies
  • MS.DEFENDER.1.4 - Add sensitive accounts to Exchange Online Protection (EOP) strict policy
  • MS.DEFENDER.1.5 - Add sensitive accounts to Defender for Office 365 strict policy
  • MS.DEFENDER.2.1 - Enable user impersonation protection for sensitive accounts in Standard and Strict policies
  • MS.DEFENDER.2.2 - Enable domain impersonation protection for all agency-owned domains
  • MS.DEFENDER.2.3 - Enable domain impersonation protection for trusted partner domains
  • MS.DEFENDER.3.1 - Enable Safe Attachments for SharePoint, OneDrive, and Microsoft Teams
  • MS.DEFENDER.4.1 - Configure a custom Data Loss Prevention (DLP) policy to protect PII and sensitive data
  • MS.DEFENDER.4.2 - Apply DLP policies to Exchange, SharePoint, OneDrive, Teams, and Devices
  • MS.DEFENDER.4.3 - Configure DLP actions to block sharing sensitive information with all users
  • MS.DEFENDER.4.4 - Enable DLP user notifications and policy tips for education and awareness
  • MS.DEFENDER.4.5 - Define a list of restricted applications under Endpoint DLP settings
  • MS.DEFENDER.4.6 - Block access to sensitive information from restricted or unallowed Bluetooth applications
  • MS.DEFENDER.5.1 - Enable mandatory alert policies to detect suspicious or malicious activities across M365 services
  • MS.DEFENDER.5.2 - Route security alerts to a monitored mailbox or integrated SIEM for continuous monitoring
  • MS.DEFENDER.6.1 - Enable Unified Audit Logging to capture user and administrative activity across Microsoft 365
  • MS.DEFENDER.6.3 - Retain Microsoft 365 audit logs for at least 12 months active and 18 months cold storage per OMB M-21-31

Running M365 Scans

Step 1: Run ScubaGear (Windows PowerShell)

# Install ScubaGear
Install-Module -Name ScubaGear

# Run scan (all domains)
Invoke-SCuBA -ProductNames aad,exo,sharepoint,teams,powerplatform,defender -OutPath ./ScubaResults

# Run scan (specific domains)
Invoke-SCuBA -ProductNames aad,exo -OutPath ./ScubaResults

Step 2: Import to AuditKit

# Import results. The rule mappings ship inside the binary, so this runs from
# any directory.
./auditkit integrate -source scubagear -file ScubaResults/ScubaResults_*.json

# Generate PDF report
./auditkit integrate -source scubagear -file ScubaResults/ScubaResults_*.json -format pdf -output m365-report.pdf

M365 License Requirements

Free M365 Features

  • Basic Entra ID (formerly Azure AD Free)
  • Exchange Online (Plan 1)
  • SharePoint Online (Plan 1)
  • Teams (basic)

Limitations: Many security features require premium licenses

Premium Features Required

Azure AD Premium P1 ($6/user/month) - Conditional Access - Self-service password reset - Dynamic groups

Azure AD Premium P2 ($9/user/month) - Identity Protection - Privileged Identity Management - Risk-based policies

Microsoft 365 E3 ($36/user/month) - Advanced DLP - Information Rights Management - Advanced auditing

Microsoft 365 E5 ($57/user/month) - Defender for Office 365 Plan 2 - Advanced threat protection - Cloud App Security

AuditKit reports which features require premium licenses

Comparison with Native Azure

Domain AuditKit M365 (ScubaGear) AuditKit Azure
Entra ID Via ScubaGear (30 rules) Via Azure scan (12 checks)
Exchange Online Via ScubaGear (40 rules) Not covered
SharePoint Via ScubaGear (8 rules) Not covered
Teams Via ScubaGear (21 rules) Not covered
Power Platform Via ScubaGear (8 rules) Not covered
Azure Infrastructure Not covered Via Azure scan (277 controls)

Recommendation: Run both for complete coverage

# Scan Azure infrastructure
./auditkit scan -provider azure -framework soc2

# Scan M365 applications
Invoke-SCuBA -ProductNames aad,exo,sharepoint,teams -OutPath ./ScubaResults
./auditkit integrate -source scubagear -file ScubaResults/ScubaResults_*.json

Next Steps

Start scanning

Full results in about thirty minutes, with a remediation command and a console link on every finding.

Start 14-Day Free Trial

$297/month after the trial. Cancel any time. The Community Edition is free and open source.