m365expertise MICROSOFT SECURITY EXPERTISE

EntraGUARD controls

EntraGUARD does not invent its own rules. Every one of its 318 controls is drawn from a recognised public framework, and carries the mapping in its own record — which is what allows a report to answer a compliance requirement without retyping anything.

318controls
13built-in packs
8audited sources
165 / 153level 1 / level 2

The frameworks the controls draw on

Each line shows how many controls of the catalog are mapped to that framework. A control usually answers several at once — that is the point of the mapping.

CIS Microsoft 365 Foundations Benchmark267 / 318

The reference benchmark for Microsoft 365 hardening, published by the Center for Internet Security. It is the backbone of this catalog, level 1 and level 2 alike.

CISA SCuBA98 / 318

Secure Cloud Business Applications: the configuration baselines published by the US cybersecurity agency for Microsoft 365, including the full Exchange Online baseline.

ISO/IEC 27001:2022318 / 318

Annex A clauses, split between organizational (A.5) and technological (A.8) controls.

NIST SP 800-53318 / 318

The US federal control catalog, by family: access control, identification, audit, configuration management.

Microsoft Cloud Security Benchmark318 / 318

Microsoft's own cloud security benchmark, organised by domain — identity management, privileged access, data protection.

NIS2318 / 318

The risk-management measures of article 21 of the European directive, applicable since January 2025.

DORA318 / 318

The articles on ICT risk management, for the financial sector.

ANSSI85 / 318

The recommendations of the French national cybersecurity agency that apply to a Microsoft 365 tenant.

What is checked, domain by domain

Representative controls, not the full list: the complete catalog ships with the tool and is available to network members.

Identity and authentication132

  • Require MFA for every administrative role
  • Enable number matching in Microsoft Authenticator
  • Deploy phishing-resistant methods
  • Block legacy authentication

Privileged access and PIM

  • Disallow guests in administrative roles
  • Require justification when activating a PIM role
  • Limit the maximum PIM role activation duration
  • Audit privileged roles assigned to service principals

Guests and external collaboration

  • Restrict guest user permissions
  • Limit who can invite guest users
  • Govern cross-tenant access (B2B) settings
  • Restrict B2B invitations to administrators

Exchange Online68

  • Block external automatic email forwarding
  • Disable legacy mail protocols (POP, IMAP)
  • Disable SMTP authentication at the tenant level
  • Inventory mailboxes with forwarding configured

SharePoint, OneDrive, Teams56

  • Restrict SharePoint external sharing
  • Set the default sharing link type to internal
  • Govern the team lifecycle and guest access
  • Control third-party applications in Teams

Defender, Purview, Intune62

  • Review the Defender XDR posture and Secure Score
  • Enable at least one data loss prevention policy
  • Review device compliance policies
  • Govern retention and sensitivity labels

What a control looks like

Every control carries the same fields, in the interface and in every export — which is what makes a finding traceable months later.

ControlRequire MFA for every administrative role
LevelL1
FindingThe named objects at fault, read from the estate itself.
RemediationThe correction path, plus a PowerShell command to verify it.
FrameworksCIS Microsoft 365 · NIST IA-2 · ISO 27001 A.8.5 · ANSSI MFA · DORA Art. 9 · NIS2 21.2(j) · MCSB IM-6
Want to see it run?
Every screen of the tool, in the order of a real engagement.
See the features →