Independent Microsoft 365 security assessment.Atlant Security
365/AuditBY ATLANT SECURITY
Build your scope Audit brief builder

MICROSOFT 365 AUDIT

Microsoft 365 security baselines: CIS and CISA SCuBA

Use Microsoft recommendations, CIS guidance and CISA SCuBA as defined audit criteria with explicit scope, versions and exceptions.

Discuss your requirements

Record the reference before interpreting the result

A baseline review needs a named version, workload scope and assessment date. Microsoft guidance, CIS configuration recommendations and CISA SCuBA have different purposes and coverage. Select the applicable criteria in the proposal and retain the mapping used during assessment.

Automation helps collect consistent observations

CISA ScubaGear evaluates Microsoft 365 configuration against SCuBA baselines. Its output can identify review questions efficiently. The assessor still needs to understand licensing, approved exceptions, unsupported areas and the business consequences of a proposed change.

Separate result types

ResultTreatment
Observed gapRecord the setting, population, evidence and risk rationale.
Approved exceptionInspect approval, expiry, rationale and alternative controls.
Not applicableExplain why the criterion does not fit the scoped environment.
Not assessed or missing evidenceState the coverage limit; do not convert an unknown into a pass.

A benchmark is not a certificate

A baseline-aligned configuration review is not CIS certification, Microsoft endorsement, statutory assurance or proof of compliance with every obligation. Proprietary benchmark content is obtained under its applicable terms; this site does not reproduce a control library.

Prepare your audit request

Use the Microsoft 365 Audit Planner for a licence-aware starting scope, or the detailed scoping assistant. Review the brief and send it with your enquiry. You can attach your NDA or RFP in the contact form.

Sources & further reading

Reviewed 6 October 2026. Product names, licence entitlements and guidance can change. Confirm applicability to your tenant and agreed assessment date.

LET’S START A CONVERSATION

Define the scope.
Take the next step.

Your audit objectives, control boundaries and evidence period. A useful starting point for your assessment.

Discuss your requirements