EntraGUARD controls
EntraGUARD does not invent its own rules. Every one of its 318 controls is drawn from a recognised public framework, and carries the mapping in its own record — which is what allows a report to answer a compliance requirement without retyping anything.
The frameworks the controls draw on
Each line shows how many controls of the catalog are mapped to that framework. A control usually answers several at once — that is the point of the mapping.
The reference benchmark for Microsoft 365 hardening, published by the Center for Internet Security. It is the backbone of this catalog, level 1 and level 2 alike.
Secure Cloud Business Applications: the configuration baselines published by the US cybersecurity agency for Microsoft 365, including the full Exchange Online baseline.
Annex A clauses, split between organizational (A.5) and technological (A.8) controls.
The US federal control catalog, by family: access control, identification, audit, configuration management.
Microsoft's own cloud security benchmark, organised by domain — identity management, privileged access, data protection.
The risk-management measures of article 21 of the European directive, applicable since January 2025.
The articles on ICT risk management, for the financial sector.
The recommendations of the French national cybersecurity agency that apply to a Microsoft 365 tenant.
What is checked, domain by domain
Representative controls, not the full list: the complete catalog ships with the tool and is available to network members.
Identity and authentication132
- Require MFA for every administrative role
- Enable number matching in Microsoft Authenticator
- Deploy phishing-resistant methods
- Block legacy authentication
Privileged access and PIM
- Disallow guests in administrative roles
- Require justification when activating a PIM role
- Limit the maximum PIM role activation duration
- Audit privileged roles assigned to service principals
Guests and external collaboration
- Restrict guest user permissions
- Limit who can invite guest users
- Govern cross-tenant access (B2B) settings
- Restrict B2B invitations to administrators
Exchange Online68
- Block external automatic email forwarding
- Disable legacy mail protocols (POP, IMAP)
- Disable SMTP authentication at the tenant level
- Inventory mailboxes with forwarding configured
SharePoint, OneDrive, Teams56
- Restrict SharePoint external sharing
- Set the default sharing link type to internal
- Govern the team lifecycle and guest access
- Control third-party applications in Teams
Defender, Purview, Intune62
- Review the Defender XDR posture and Secure Score
- Enable at least one data loss prevention policy
- Review device compliance policies
- Govern retention and sensitivity labels
What a control looks like
Every control carries the same fields, in the interface and in every export — which is what makes a finding traceable months later.