M365 Coverage
What AuditKit reports for Microsoft 365 via ScubaGear import.
What AuditKit scans in Microsoft 365 via ScubaGear integration.
Overview
Coverage: 100+ rules via CISA ScubaGear integration
Supported in: Free and Pro versions
Method: Import ScubaGear scan results into AuditKit
Supported frameworks: - SOC2 Type II - PCI-DSS v4.0.1
Imported M365 findings currently carry SOC2 and PCI-DSS mappings only. CMMC, HIPAA and NIST 800-53 mappings for ScubaGear rules are not yet implemented.
Why ScubaGear? - Official CISA tool for M365 security - Free and open-source - Comprehensive security baseline - Regular updates from CISA
How It Works
1. Run ScubaGear (Windows PowerShell)
↓
2. Generate ScubaResults_<uuid>.json
↓
3. Import to AuditKit
↓
4. Get compliance-mapped report
Covered Domains
134 ScubaGear rules, each mapped to SOC 2 criteria and PCI DSS requirements, read from the
mapping files the scanner ships. Identifiers are ScubaGear's own; the parser matches them with
or without the version suffix (MS.AAD.1.1 and MS.AAD.1.1v1 are the same rule).
Entra ID - 30 rules
- MS.AAD.1.1 - Legacy authentication blocked
- MS.AAD.2.1 - Block high-risk users
- MS.AAD.2.2 - Notify admins on high-risk users
- MS.AAD.2.3 - Block high-risk sign-ins
- MS.AAD.3.1 - Phishing-resistant MFA for all users
- MS.AAD.3.2 - Enforce MFA (any approved method) for all users
- MS.AAD.3.3 - Authenticator shows app/location context
- MS.AAD.3.4 - Authentication methods migration completed/managed
- MS.AAD.3.5 - Disable SMS/Voice/Email OTP
- MS.AAD.3.6 - Phishing-resistant MFA for privileged roles
- MS.AAD.3.7 - Require managed devices for authentication
- MS.AAD.3.8 - Require managed device to register MFA
- MS.AAD.3.9 - Block device-code authentication flow
- MS.AAD.4.1 - Send security logs to SIEM/SOC
- MS.AAD.5.1 - Only admins may register applications
- MS.AAD.5.2 - Only admins may consent to applications
- MS.AAD.5.3 - Admin consent workflow configured
- MS.AAD.6.1 - User passwords do not expire (policy-based)
- MS.AAD.7.1 - Limit Global Admins (2–8)
- MS.AAD.7.2 - Use finer-grained roles instead of Global Admin
- MS.AAD.7.3 - Privileged users use cloud-only accounts
- MS.AAD.7.4 - No permanent active privileged assignments
- MS.AAD.7.5 - Provision privileged roles via PIM/PAM
- MS.AAD.7.6 - Global Administrator activation requires approval
- MS.AAD.7.7 - Alert on eligible or active privileged role assignment
- MS.AAD.7.8 - Alert on Global Administrator activation
- MS.AAD.7.9 - Alert on other privileged role activations
- MS.AAD.8.1 - Limit guest access to directory objects
- MS.AAD.8.2 - Only Guest Inviter role can invite guests
- MS.AAD.8.3 - Restrict guest invitations to approved domains
Exchange Online - 40 rules
- MS.EXO.1.1 - Disable automatic email forwarding to external domains
- MS.EXO.2.2 - Publish an SPF record for all domains and enforce hard fail for non-approved senders
- MS.EXO.3.1 - Enable DKIM for all custom domains
- MS.EXO.4.1 - Publish a DMARC policy for all second-level domains
- MS.EXO.4.2 - Set DMARC policy enforcement to p=reject
- MS.EXO.4.3 - Include reports@dmarc.cyber.dhs.gov in DMARC aggregate reports
- MS.EXO.4.4 - Include agency-specific contact addresses in DMARC aggregate and failure reports
- MS.EXO.5.1 - Disable SMTP AUTH for the organization
- MS.EXO.6.1 - Restrict contact folder sharing with all domains
- MS.EXO.6.2 - Restrict calendar detail sharing with all domains
- MS.EXO.7.1 - Implement external sender warnings in Exchange Online
- MS.EXO.8.1 - Implement a Data Loss Prevention (DLP) solution for Exchange Online
- MS.EXO.8.2 - Ensure DLP policies protect personally identifiable and sensitive information
- MS.EXO.8.3 - If using third-party DLP, ensure feature parity with Microsoft native capabilities
- MS.EXO.8.4 - Restrict sharing of PII including credit card numbers, SSNs, and ITINs via email
- MS.EXO.9.1 - Enable attachment file type filtering in Exchange Online
- MS.EXO.9.2 - Ensure the attachment filter verifies true file type and file extension consistency
- MS.EXO.9.3 - Determine and enforce list of disallowed email attachment file types
- MS.EXO.9.4 - Ensure third-party attachment filtering matches Microsoft Defender baseline
- MS.EXO.9.5 - Block common click-to-run file types (e.g., .exe, .cmd, .vbe)
- MS.EXO.10.1 - Enable malware scanning for all inbound and outbound emails
- MS.EXO.10.2 - Quarantine or drop emails detected as containing malware
- MS.EXO.10.3 - Enable post-delivery scanning to detect and remove malware from delivered messages
- MS.EXO.11.1 - Enable impersonation protection checks in Exchange Online
- MS.EXO.11.2 - Display user warnings and safety tips for suspected phishing emails
- MS.EXO.11.3 - Enable AI-based phishing detection using Mailbox Intelligence
- MS.EXO.12.1 - Avoid use of IP allow lists that bypass spam and authentication checks
- MS.EXO.12.2 - Disable global safe lists to prevent bypassing security mechanisms
- MS.EXO.13.1 - Enable mailbox auditing for all Exchange Online users
- MS.EXO.14.1 - Enable spam filtering for inbound email in Exchange Online
- MS.EXO.14.2 - Quarantine or move spam and high-confidence spam to junk folders
- MS.EXO.14.3 - Prohibit adding entire domains to inbound allow lists in spam policies
- MS.EXO.14.4 - Validate third-party spam filtering is equivalent to Microsoft Defender baseline
- MS.EXO.15.1 - Enable Safe Links URL scanning and block-list comparison for incoming email
- MS.EXO.15.2 - Enable real-time malware scanning for direct download links in emails
- MS.EXO.15.3 - Enable user click tracking for Safe Links-protected emails
- MS.EXO.16.1 - Enable alert policies for suspicious and service-impacting activities in Exchange Online
- MS.EXO.16.2 - Send alerts to monitored mailbox or integrate with SIEM for central review
- MS.EXO.17.1 - Enable Unified Audit Logging in Microsoft 365 for Exchange Online
- MS.EXO.17.3 - Retain Unified Audit Logs for minimum 12 months active and 18 months cold storage
SharePoint Online - 8 rules
- MS.SHAREPOINT.1.1 - Limit external sharing for SharePoint to existing guests or internal users only
- MS.SHAREPOINT.1.2 - Limit external sharing for OneDrive to existing guests or internal users only
- MS.SHAREPOINT.1.3 - Restrict external sharing to approved domains or security groups
- MS.SHAREPOINT.2.1 - Set default file and folder sharing scope to Specific people
- MS.SHAREPOINT.2.2 - Set default file and folder sharing permission to View only
- MS.SHAREPOINT.3.1 - Set expiration for Anyone links to 30 days or less
- MS.SHAREPOINT.3.2 - Set permissions for Anyone links to View only
- MS.SHAREPOINT.3.3 - Require reauthentication for verification code users every 30 days or less
Teams - 21 rules
- MS.TEAMS.1.1 - Disable external participants from requesting control of shared screens in Teams meetings
- MS.TEAMS.1.2 - Prevent anonymous users from starting Microsoft Teams meetings
- MS.TEAMS.1.3 - Require lobby admission for anonymous and dial-in users in Teams meetings
- MS.TEAMS.1.4 - Allow internal users to bypass the lobby automatically in Teams meetings
- MS.TEAMS.1.5 - Require dial-in users to wait in the lobby before joining Teams meetings
- MS.TEAMS.1.6 - Disable default meeting recording in Teams to prevent unauthorized data exposure
- MS.TEAMS.1.7 - Disable 'Always record' for Teams Live Events and restrict to organizer discretion
- MS.TEAMS.2.1 - Restrict external access in Teams to specific approved domains only
- MS.TEAMS.2.2 - Block unmanaged Teams users from initiating contact with internal users
- MS.TEAMS.2.3 - Prevent internal users from initiating chats with unmanaged Teams users
- MS.TEAMS.4.1 - Disable Teams channel email integration to prevent external message routing
- MS.TEAMS.5.1 - Restrict Teams integration to approved Microsoft apps only
- MS.TEAMS.5.2 - Restrict installation of third-party apps to approved selections only
- MS.TEAMS.5.3 - Restrict Teams custom app installation to approved and verified apps only
- MS.TEAMS.6.1 - Enable a Data Loss Prevention (DLP) solution to monitor and prevent data leakage in Teams
- MS.TEAMS.6.1 - Enable a Data Loss Prevention (DLP) solution to monitor and prevent data leakage in Teams
- MS.TEAMS.6.2 - Configure DLP to detect and protect PII and sensitive information shared in Teams
- MS.TEAMS.7.1 - Enable malware scanning for Teams file attachments
- MS.TEAMS.7.2 - Prevent users from opening or downloading malware-detected files in Teams
- MS.TEAMS.8.1 - Enable Safe Links protection for URLs shared in Teams messages
- MS.TEAMS.8.2 - Enable user click tracking for Safe Links in Teams messages
Power Platform - 8 rules
- MS.POWERPLATFORM.1.1 - Restrict creation of production and sandbox environments to admins
- MS.POWERPLATFORM.1.2 - Restrict creation of trial environments to admins
- MS.POWERPLATFORM.2.1 - Create DLP policy to restrict connector access in the default environment
- MS.POWERPLATFORM.2.2 - Apply DLP policies to all non-default environments
- MS.POWERPLATFORM.3.1 - Enable Power Platform tenant isolation
- MS.POWERPLATFORM.3.2 - Configure inbound/outbound connection allowlist
- MS.POWERPLATFORM.4.1 - Enforce Content Security Policy for model-driven and canvas Power Apps
- MS.POWERPLATFORM.5.1 - Restrict Power Pages creation to admins
Power BI - 8 rules
- MS.POWERBI.1.1 - Disable Publish to Web feature unless business-justified
- MS.POWERBI.2.1 - Restrict or disable Power BI guest access
- MS.POWERBI.3.1 - Disable external invitations unless required by mission need
- MS.POWERBI.4.1 - Restrict Power BI service principal API access to approved groups
- MS.POWERBI.4.2 - Restrict service principals creating or using profiles to approved groups
- MS.POWERBI.5.1 - Block ResourceKey-based authentication unless justified by design
- MS.POWERBI.6.1 - Disable Python and R visual sharing to reduce script-based risk
- MS.POWERBI.7.1 - Enable and enforce sensitivity labels for Power BI content
Defender for Office 365 - 19 rules
- MS.DEFENDER.1.1 - Enable Standard and Strict preset security policies in Microsoft Defender
- MS.DEFENDER.1.2 - Assign all users to Exchange Online Protection (EOP) via Standard or Strict preset policies
- MS.DEFENDER.1.3 - Assign all users to Defender for Office 365 protection via preset policies
- MS.DEFENDER.1.4 - Add sensitive accounts to Exchange Online Protection (EOP) strict policy
- MS.DEFENDER.1.5 - Add sensitive accounts to Defender for Office 365 strict policy
- MS.DEFENDER.2.1 - Enable user impersonation protection for sensitive accounts in Standard and Strict policies
- MS.DEFENDER.2.2 - Enable domain impersonation protection for all agency-owned domains
- MS.DEFENDER.2.3 - Enable domain impersonation protection for trusted partner domains
- MS.DEFENDER.3.1 - Enable Safe Attachments for SharePoint, OneDrive, and Microsoft Teams
- MS.DEFENDER.4.1 - Configure a custom Data Loss Prevention (DLP) policy to protect PII and sensitive data
- MS.DEFENDER.4.2 - Apply DLP policies to Exchange, SharePoint, OneDrive, Teams, and Devices
- MS.DEFENDER.4.3 - Configure DLP actions to block sharing sensitive information with all users
- MS.DEFENDER.4.4 - Enable DLP user notifications and policy tips for education and awareness
- MS.DEFENDER.4.5 - Define a list of restricted applications under Endpoint DLP settings
- MS.DEFENDER.4.6 - Block access to sensitive information from restricted or unallowed Bluetooth applications
- MS.DEFENDER.5.1 - Enable mandatory alert policies to detect suspicious or malicious activities across M365 services
- MS.DEFENDER.5.2 - Route security alerts to a monitored mailbox or integrated SIEM for continuous monitoring
- MS.DEFENDER.6.1 - Enable Unified Audit Logging to capture user and administrative activity across Microsoft 365
- MS.DEFENDER.6.3 - Retain Microsoft 365 audit logs for at least 12 months active and 18 months cold storage per OMB M-21-31
Running M365 Scans
Step 1: Run ScubaGear (Windows PowerShell)
# Install ScubaGear
Install-Module -Name ScubaGear
# Run scan (all domains)
Invoke-SCuBA -ProductNames aad,exo,sharepoint,teams,powerplatform,defender -OutPath ./ScubaResults
# Run scan (specific domains)
Invoke-SCuBA -ProductNames aad,exo -OutPath ./ScubaResults
Step 2: Import to AuditKit
# Import results. The rule mappings ship inside the binary, so this runs from
# any directory.
./auditkit integrate -source scubagear -file ScubaResults/ScubaResults_*.json
# Generate PDF report
./auditkit integrate -source scubagear -file ScubaResults/ScubaResults_*.json -format pdf -output m365-report.pdf
M365 License Requirements
Free M365 Features
- Basic Entra ID (formerly Azure AD Free)
- Exchange Online (Plan 1)
- SharePoint Online (Plan 1)
- Teams (basic)
Limitations: Many security features require premium licenses
Premium Features Required
Azure AD Premium P1 ($6/user/month) - Conditional Access - Self-service password reset - Dynamic groups
Azure AD Premium P2 ($9/user/month) - Identity Protection - Privileged Identity Management - Risk-based policies
Microsoft 365 E3 ($36/user/month) - Advanced DLP - Information Rights Management - Advanced auditing
Microsoft 365 E5 ($57/user/month) - Defender for Office 365 Plan 2 - Advanced threat protection - Cloud App Security
AuditKit reports which features require premium licenses
Comparison with Native Azure
| Domain | AuditKit M365 (ScubaGear) | AuditKit Azure |
|---|---|---|
| Entra ID | Via ScubaGear (30 rules) | Via Azure scan (12 checks) |
| Exchange Online | Via ScubaGear (40 rules) | Not covered |
| SharePoint | Via ScubaGear (8 rules) | Not covered |
| Teams | Via ScubaGear (21 rules) | Not covered |
| Power Platform | Via ScubaGear (8 rules) | Not covered |
| Azure Infrastructure | Not covered | Via Azure scan (277 controls) |
Recommendation: Run both for complete coverage
# Scan Azure infrastructure
./auditkit scan -provider azure -framework soc2
# Scan M365 applications
Invoke-SCuBA -ProductNames aad,exo,sharepoint,teams -OutPath ./ScubaResults
./auditkit integrate -source scubagear -file ScubaResults/ScubaResults_*.json
Next Steps
Start scanning
Full results in about thirty minutes, with a remediation command and a console link on every finding.
Start 14-Day Free Trial$297/month after the trial. Cancel any time. The Community Edition is free and open source.