Record the reference before interpreting the result
A baseline review needs a named version, workload scope and assessment date. Microsoft guidance, CIS configuration recommendations and CISA SCuBA have different purposes and coverage. Select the applicable criteria in the proposal and retain the mapping used during assessment.
Automation helps collect consistent observations
CISA ScubaGear evaluates Microsoft 365 configuration against SCuBA baselines. Its output can identify review questions efficiently. The assessor still needs to understand licensing, approved exceptions, unsupported areas and the business consequences of a proposed change.
Separate result types
| Result | Treatment |
|---|---|
| Observed gap | Record the setting, population, evidence and risk rationale. |
| Approved exception | Inspect approval, expiry, rationale and alternative controls. |
| Not applicable | Explain why the criterion does not fit the scoped environment. |
| Not assessed or missing evidence | State the coverage limit; do not convert an unknown into a pass. |
A benchmark is not a certificate
A baseline-aligned configuration review is not CIS certification, Microsoft endorsement, statutory assurance or proof of compliance with every obligation. Proprietary benchmark content is obtained under its applicable terms; this site does not reproduce a control library.
Prepare your audit request
Use the Microsoft 365 Audit Planner for a licence-aware starting scope, or the detailed scoping assistant. Review the brief and send it with your enquiry. You can attach your NDA or RFP in the contact form.
Sources & further reading
Reviewed 6 October 2026. Product names, licence entitlements and guidance can change. Confirm applicability to your tenant and agreed assessment date.

