Skip to main content

Appendix A: Compliance Controls

CMMC Level 2 Controls

Completeness and how to read this matrix

This matrix lists all 110 CMMC Level 2 practices (NIST SP 800-171 Rev. 2, requirements 3.1.1 through 3.14.7). The Microsoft Technology column names the specific Microsoft 365 / Azure capability that implements each practice. Entries marked Policy/process control are satisfied administratively (policy, training, physical security, or contractual flow-down) and have no single Microsoft technology; they are listed here so that no practice number appears to be missing. Where a Microsoft capability supports the evidence for an otherwise administrative control, it is named.

This matrix is a technical input to your System Security Plan: not the SSP itself. Controls marked Policy/process control or Microsoft-managed still require an SSP narrative; for inherited (Microsoft-managed) controls, that narrative belongs in a Customer Responsibility Matrix (CRM) and must cite Microsoft's underlying authorization (e.g., the Azure Government FedRAMP High provisional authorization). See Relationship to the System Security Plan and External Service Provider Management.

Author's Note on NIST Versions

You may notice that NIST has labeled SP 800-171 Rev 2 as "Withdrawn" in favor of Rev 3. For CMMC Level 2 compliance, Revision 2 remains the mandatory standard. The DoD's CMMC Final Rule (32 CFR Part 170) specifically mandates Rev 2. All technical configurations in this book, including Entra ID Conditional Access and Intune Device Compliance, are designed to meet the Rev 2 assessment objectives.

CMMC PracticeMicrosoft TechnologyBook Reference
ACCESS CONTROL (AC)
AC.L2-3.1.1 (Authorized Access)Entra ID (Conditional Access)Conditional Access Policies
AC.L2-3.1.2 (Access Enforcement)Entra ID Conditional Access enforcing approved access authorizationsConditional Access Policies
AC.L2-3.1.3 (CUI Flow Control)Teams (Private Channels), Exchange Online; Purview DLP (including DLP for Copilot)Secure Collaboration, Copilot Data Readiness
AC.L2-3.1.4 (Separation of Duties)Entra ID Entitlement Management separation-of-duties checks (incompatible access packages / groups; requires Entra ID P2 or ID Governance); broader duty separation is an administrative controlAccess Governance
AC.L2-3.1.5 (Least Privilege)Entra ID PIM (Just-in-Time Access); Intune Local Administrators policy (Local Group Membership) restricts local-admin membership on the endpointAccess Governance, OIB Deployment
AC.L2-3.1.6 (Non-Privileged Account Use)Entra ID PIM with separate administrative accounts, privileged roles used only for security functions; Intune Local Administrators policy keeps the break-glass admin off daily-use accountsAccess Governance, OIB Deployment
AC.L2-3.1.7 (Privileged Functions)Entra ID RBAC restricts privileged functions; Microsoft Sentinel and audit logs capture privileged-function execution; Intune Local Security Policies enforce UAC elevation on the endpointAccess Governance, SIEM Strategy, OIB Deployment
AC.L2-3.1.8 (Unsuccessful Logon Attempts)Entra ID (Smart Lockout); Microsoft Sentinel failed-sign-in detectionIdentity Foundation, SIEM Strategy
AC.L2-3.1.9 (Privacy and Security Notices)Intune (Local Security Policies: interactive logon banner)OIB Deployment
AC.L2-3.1.10 (Session Lock)Intune (Login and Lock Screen / Power and Device Lock: Max Inactivity Device Lock ≤ 15 minutes)OIB Deployment
AC.L2-3.1.11 (Session Termination)Intune device inactivity lock; Entra ID Conditional Access sign-in frequency and session controls; AVD idle and disconnect session limitsOIB Deployment, Scenario: Azure Virtual Desktop
AC.L2-3.1.12 (Monitor and Control Remote Access)Azure Virtual Desktop: all remote access via the managed AVD Gateway, fully loggedScenario: Azure Virtual Desktop
AC.L2-3.1.13 (Remote Access Confidentiality)Azure Virtual Desktop Gateway (TLS-encrypted RDP); no direct RDP or VPN to session hostsScenario: Azure Virtual Desktop
AC.L2-3.1.14 (Managed Access Control Points)Azure Virtual Desktop (AVD Gateway as the single managed remote access point, no direct RDP, no VPN required for CUI access)Scenario: Azure Virtual Desktop
AC.L2-3.1.15 (Privileged Remote Access)Azure Virtual Desktop (Virtual Machine Administrator Login role, restricts privileged console access to named admin accounts, logged in Entra sign-in logs)Scenario: Azure Virtual Desktop
AC.L2-3.1.16 (Wireless Access)Intune (Wi-Fi Config Profiles)OIB Deployment: Wi-Fi Configuration
AC.L2-3.1.17 (Wireless Protection)Intune Wi-Fi profiles enforcing WPA2/WPA3-Enterprise authentication and encryptionOIB Deployment: Wi-Fi Configuration
AC.L2-3.1.18 (Mobile Devices)Intune (MAM/MDM)Mobile Device Management & App Protection
AC.L2-3.1.19 (Encrypt CUI on Mobile Devices)Intune App Protection Policies (app-level encryption) and BitLocker; Purview encryption labelsMobile Device Management & App Protection, Sensitivity Labels
AC.L2-3.1.20 (Use of External Systems)Entra ID Conditional Access (compliant / managed-device requirement); Microsoft Defender for Cloud Apps governs unmanaged and external systemsConditional Access Policies
AC.L2-3.1.21 (Portable Storage on External Systems)Defender for Endpoint Device Control; Intune removable-storage restrictionsThreat Defense
AC.L2-3.1.22 (Publicly Accessible Content)Microsoft Purview DLP on public-facing SharePoint; primarily an administrative review controlSecure Collaboration
AWARENESS & TRAINING (AT)
AT.L2-3.2.1 (Security Awareness Training)Defender for Office 365 (Attack Simulation Training)Threat Defense
AT.L2-3.2.2 (Role-Based Training)Policy/process control: role-based training for staff with security duties; no specific Microsoft 365 technology
AT.L2-3.2.3 (Insider Threat Awareness)Policy/process control: no specific Microsoft 365 technology
AUDIT & ACCOUNTABILITY (AU)
AU.L2-3.3.1 (System Auditing)Microsoft Sentinel and Purview Audit (log generation); Azure Storage / Log Analytics retention and archive (create and retain)SIEM Strategy, Audit Readiness
AU.L2-3.3.2 (User Accountability)Entra ID (Sign-in Logs)Identity Foundation
AU.L2-3.3.3 (Review Logged Events)Intune (OIB Audit and Event Logging policy: defines which event subcategories endpoints audit); periodic review of the audit-event scope documented in the SSPAudit Readiness, OIB Deployment
AU.L2-3.3.4 (Audit Logging Failure Alert)Microsoft Sentinel health monitoring (SentinelHealth table) with Azure Monitor alert rules on data-connector failureAudit Readiness, SIEM Strategy
AU.L2-3.3.5 (Audit Analysis)Microsoft Sentinel (Analytics Rules)SIEM Strategy
AU.L2-3.3.6 (Audit Reduction & Reporting)Microsoft Sentinel (Workbooks, exportable reports)SIEM Strategy, Audit Readiness
AU.L2-3.3.7 (Time Stamps)Windows Time service (NTP) synchronized to an authoritative source (Azure host time for AVD session hosts), producing consistent UTC time stamps in audit recordsOIB Deployment, Audit Readiness
AU.L2-3.3.8 (Protect Audit Information)Azure RBAC on the Log Analytics workspace; immutability policy on archived storage exportsSIEM Strategy, Audit Readiness
AU.L2-3.3.9 (Limit Audit Management)Entra PIM + Azure RBAC (Log Analytics Contributor / Security Administrator scoped to authorized admins)SIEM Strategy, Audit Readiness
CONFIGURATION MANAGEMENT (CM)
CM.L2-3.4.1 (Baseline Config)Intune (Device Compliance Policies); Entra ID device object hygiene (accurate inventory of managed endpoints)OIB Deployment, Entra Device Hygiene
CM.L2-3.4.2 (Configuration Settings)Intune (configuration profiles and security baselines enforcing required settings)OIB Deployment
CM.L2-3.4.3 (Change Control)Intune and Entra ID audit logs track configuration changes; change approval is an administrative processOIB Deployment
CM.L2-3.4.4 (Security Impact Analysis)Policy/process control: security-impact analysis of changes; no specific Microsoft 365 technology
CM.L2-3.4.5 (Access Restrictions for Change)Entra ID RBAC + PIM and Intune RBAC restrict who may change configurationsAccess Governance
CM.L2-3.4.6 (Least Functionality)MDE Attack Surface Reduction (ASR) Rules: blocks execution of unnecessary system features and living-off-the-land binariesDefender for Endpoint
CM.L2-3.4.7 (Unauthorized Software)Defender for Endpoint (Software Inventory)Threat Defense
CM.L2-3.4.8 (Authorized Software: Deny by Exception)Intune (App Control for Business / WDAC with Managed Installer: allow apps deployed by Intune, block the rest; audit mode first)OIB Deployment: Application Control
CM.L2-3.4.9 (User-Installed Software)Least privilege (Local Administrators + LAPS) blocks machine installs; Intune Discovered apps (software inventory) monitors; App Control for Business enforces allow-listingOIB Deployment, Application Control
IDENTIFICATION & AUTHENTICATION (IA)
IA.L2-3.5.1 (Identification)Entra ID (User Accounts)Identity Foundation
IA.L2-3.5.2 (Authenticate Users and Devices)Entra ID authentication; Entra device identity and Intune device certificates (SCEP/PKCS) authenticate devicesIdentity Foundation, Entra Device Hygiene
IA.L2-3.5.3 (MFA)Entra ID (Conditional Access)Conditional Access Policies
IA.L2-3.5.4 (Replay-Resistant Authentication)Entra ID phishing-resistant methods (FIDO2, Windows Hello for Business), replay-resistant by designPhishing-Resistant Authentication
IA.L2-3.5.5 (Identifier Management)Entra ID identifier / UPN management; Lifecycle Workflows prevent identifier reuseIdentity Foundation
IA.L2-3.5.6 (Disable Inactive Identifiers)Entra ID Access Reviews and Lifecycle Workflows disable accounts after a defined period of inactivityAccess Governance
IA.L2-3.5.7 (Password Complexity)Entra ID (Password Protection, banned-password list); Windows LAPS rotates a unique, complex password for the local Administrator account that Entra Password Protection does not reachIdentity Foundation, OIB Deployment
IA.L2-3.5.8 (Prohibit Password Reuse)Entra ID / Active Directory password history policyIdentity Foundation
IA.L2-3.5.9 (Temporary Password)Entra ID Temporary Access Pass with forced change at next sign-inIdentity Foundation
IA.L2-3.5.10 (Cryptographically-Protected Passwords)Entra ID stores password hashes and enforces TLS in transit (Microsoft-managed)Identity Foundation
IA.L2-3.5.11 (Obscure Authentication Feedback)Windows and Entra ID default: masked credential entryIdentity Foundation
INCIDENT RESPONSE (IR)
IR.L2-3.6.1 (Incident Handling)Microsoft Sentinel (Incident Management); MDE Incidents and automated investigation provide the response workflowSIEM Strategy, Defender for Endpoint
IR.L2-3.6.2 (Incident Reporting)Defender XDR (Alerts); MDE incident timeline and audit log satisfy documentation requirementsThreat Defense, Defender for Endpoint
IR.L2-3.6.3 (Test Incident Response)Administrative control: IR tests and tabletops; Attack Simulation Training and Microsoft Sentinel exercises support the testThreat Defense
MAINTENANCE (MA)
MA.L2-3.7.1 (Perform Maintenance)Policy/process control: no specific Microsoft 365 technology
MA.L2-3.7.2 (Maintenance Tools and Personnel)Administrative control; privileged maintenance access is governed by Entra PIMAccess Governance
MA.L2-3.7.3 (Sanitize Off-Site Equipment)Policy/process control: media sanitization; no specific Microsoft 365 technology
MA.L2-3.7.4 (Check Media for Malicious Code)Defender Antivirus scans diagnostic and removable media before useThreat Defense
MA.L2-3.7.5 (Remote Maintenance)Azure Virtual Desktop (Secure Admin Workstations, Virtual Machine Administrator Login gated by phishing-resistant CA)Virtual Desktop Strategy, Scenario: Azure Virtual Desktop
MA.L2-3.7.6 (Supervise Maintenance Personnel)Policy/process control: no specific Microsoft 365 technology
MEDIA PROTECTION (MP)
MP.L2-3.8.1 (Media Protection)BitLocker (Intune Policy)OIB Deployment
MP.L2-3.8.2 (Limit Access to Media)BitLocker plus access controls; Purview sensitivity labels restrict access to CUI on mediaOIB Deployment, Sensitivity Labels
MP.L2-3.8.3 (Media Sanitization)Intune (remote wipe / device retire); physical media destruction is an administrative processOIB Deployment
MP.L2-3.8.4 (Media Marking)Purview Information Protection (labels apply visual markings, headers, and footers)Sensitivity Labels
MP.L2-3.8.5 (Media Transport Accountability)Policy/process control: media transport chain-of-custody; no specific Microsoft 365 technology
MP.L2-3.8.6 (Media Encryption in Transit)Intune (BitLocker To Go for removable media)OIB Deployment
MP.L2-3.8.7 (Portable Storage)Defender for Endpoint (Device Control)Threat Defense
MP.L2-3.8.8 (Prohibit Unidentified Storage)Defender for Endpoint Device Control (block removable devices with no identifiable owner)Threat Defense
MP.L2-3.8.9 (Protect Backup CUI)Azure Backup (encryption at rest) and BitLocker
PERSONNEL SECURITY (PS)
PS.L2-3.9.1 (Personnel Screening)Policy/process control: personnel screening; no specific Microsoft 365 technology
PS.L2-3.9.2 (Personnel Termination)Entra ID (Account Disable / Revocation)Identity Foundation
PHYSICAL PROTECTION (PE)
PE.L2-3.10.1 (Physical Access)Azure Virtual Desktop (CUI never touches end-user hardware: users see only a rendered screen; data remains in Azure Government FedRAMP High datacenters)Virtual Desktop Strategy, Scenario: Azure Virtual Desktop
PE.L2-3.10.2 (Monitor Physical Facility)Microsoft Azure datacenter physical controls (cloud-hosted CUI); on-prem facility monitoring is an administrative processVirtual Desktop Strategy
PE.L2-3.10.3 (Escort Visitors)Policy/process control: no specific Microsoft 365 technology
PE.L2-3.10.4 (Physical Access Logs)Microsoft Azure datacenter controls (cloud-side); on-prem physical-access logging is an administrative processVirtual Desktop Strategy
PE.L2-3.10.5 (Manage Physical Access Devices)Policy/process control: no specific Microsoft 365 technology
PE.L2-3.10.6 (Alternate Work Sites)Azure Virtual Desktop (CUI stays in the datacenter regardless of work site); Intune complianceScenario: Azure Virtual Desktop
RISK ASSESSMENT (RA)
RA.L2-3.11.1 (Risk Assessment)Administrative control: risk assessment process; Microsoft Secure Score and Defender inform risk postureAudit Readiness
RA.L2-3.11.2 (Vulnerability Scan)Defender Vulnerability ManagementThreat Defense
RA.L2-3.11.3 (Remediate Vulnerabilities)Defender Vulnerability Management (remediation tracking) with Intune deploymentThreat Defense
SECURITY ASSESSMENT (CA)
CA.L2-3.12.1 (Security Controls)Compliance Manager / Secure ScoreAudit Readiness
CA.L2-3.12.2 (Plan of Action and Milestones)Microsoft Purview Compliance Manager improvement actions track Plan of Action and Milestones items; the plan and remediation decisions are an administrative processAudit Readiness
CA.L2-3.12.3 (Continuous Monitoring)Microsoft Sentinel; MDE Secure Score, device health reports, and alert pipeline provide continuous monitoring evidenceSIEM Strategy, Defender for Endpoint
CA.L2-3.12.4 (System Security Plan)Administrative control: SSP authoring; Microsoft Purview Compliance Manager supports evidence collectionAudit Readiness
SYSTEM & COMMUNICATIONS (SC)
SC.L2-3.13.1 (Network Boundary Monitoring)Azure Firewall (deny-all with explicit allow rules, FQDN-based egress control for AVD session hosts)AVD Firewall Reference, Scenario: Azure Virtual Desktop
SC.L2-3.13.2 (Secure Architecture and Engineering)Policy/process control: secure architecture and engineering; no specific Microsoft 365 technology
SC.L2-3.13.3 (Separate User and Management Functionality)Azure RBAC and AVD admin-plane separation; Entra ID privileged rolesScenario: Azure Virtual Desktop
SC.L2-3.13.4 (Shared Resource Isolation)Azure tenant and resource isolation (Microsoft-managed)
SC.L2-3.13.5 (Subnetworks / No Public Exposure)Azure Virtual Desktop (session hosts have no public IPs; inbound via AVD Gateway service tag only; outbound via Azure Firewall UDR)Scenario: Azure Virtual Desktop
SC.L2-3.13.6 (Deny by Default)Azure Firewall (deny-all default, explicit allow rules)AVD Firewall Reference
SC.L2-3.13.7 (Prevent Split Tunneling)Azure Virtual Desktop with forced tunneling via UDR (no split tunnel); Entra ID Conditional AccessScenario: Azure Virtual Desktop
SC.L2-3.13.8 (Data in Transit)TLS 1.2+ (Office 365 Defaults); AVD Gateway enforces TLS on all RDP sessionsSecure Collaboration, Scenario: Azure Virtual Desktop
SC.L2-3.13.9 (Network Disconnect)AVD session time limits (idle / disconnect); Entra ID Conditional Access sign-in frequencyScenario: Azure Virtual Desktop
SC.L2-3.13.10 (Cryptographic Key Management)Azure Key Vault (FIPS-validated key management)
SC.L2-3.13.11 (FIPS Encryption)Intune (BitLocker FIPS Policy)OIB Deployment
SC.L2-3.13.12 (Collaborative Computing Devices)Intune device restrictions (camera and microphone); Microsoft Teams meeting policiesOIB Deployment
SC.L2-3.13.13 (Mobile Code)MDE Attack Surface Reduction and App Control for Business restrict scripts and mobile codeDefender for Endpoint
SC.L2-3.13.14 (VoIP)Microsoft Teams (managed VoIP) governed by Teams policiesSecure Collaboration
SC.L2-3.13.15 (Session Authenticity)TLS 1.2+ and Entra ID token integrity protect session authenticity; Intune Local Security Policies enforce SMB signing / NTLM hardening on the endpointSecure Collaboration, OIB Deployment
SC.L2-3.13.16 (Data at Rest)Purview Information Protection (Encryption)Sensitivity Labels
SYSTEM & INFORMATION INTEGRITY (SI)
SI.L2-3.14.1 (Flaw Remediation)Intune (Windows Autopatch / Updates)OIB Deployment
SI.L2-3.14.2 (Malicious Code)Defender AntivirusThreat Defense
SI.L2-3.14.3 (Monitor Security Alerts and Advisories)Microsoft Defender for Endpoint / Defender XDR (security alerts, threat analytics, and advisories)Defender for Endpoint, Threat Defense
SI.L2-3.14.4 (Malicious Code Protection Updates)MDE platform and signature updates managed by Microsoft, no separate update infrastructure requiredDefender for Endpoint
SI.L2-3.14.5 (Periodic and Real-Time Scans)Defender Antivirus (scheduled and real-time scanning)Threat Defense
SI.L2-3.14.6 (System Monitoring)MDE behavioral analytics and anomaly detection; Microsoft Sentinel analytics rules and UEBADefender for Endpoint, SIEM Strategy
SI.L2-3.14.7 (Identify Unauthorized Use)MDE behavioral analytics and anomaly detection: surfaces unexpected process execution, lateral movement, and data exfiltration patternsDefender for Endpoint

📩 Don't Miss the Next Solution

Join the list to see the real-time solutions I'm delivering to my GCC High clients.