Appendix A: Compliance Controls
- GCC High
- Commercial
CMMC Level 2 Controls
This matrix lists all 110 CMMC Level 2 practices (NIST SP 800-171 Rev. 2, requirements 3.1.1 through 3.14.7). The Microsoft Technology column names the specific Microsoft 365 / Azure capability that implements each practice. Entries marked Policy/process control are satisfied administratively (policy, training, physical security, or contractual flow-down) and have no single Microsoft technology; they are listed here so that no practice number appears to be missing. Where a Microsoft capability supports the evidence for an otherwise administrative control, it is named.
This matrix is a technical input to your System Security Plan: not the SSP itself. Controls marked Policy/process control or Microsoft-managed still require an SSP narrative; for inherited (Microsoft-managed) controls, that narrative belongs in a Customer Responsibility Matrix (CRM) and must cite Microsoft's underlying authorization (e.g., the Azure Government FedRAMP High provisional authorization). See Relationship to the System Security Plan and External Service Provider Management.
You may notice that NIST has labeled SP 800-171 Rev 2 as "Withdrawn" in favor of Rev 3. For CMMC Level 2 compliance, Revision 2 remains the mandatory standard. The DoD's CMMC Final Rule (32 CFR Part 170) specifically mandates Rev 2. All technical configurations in this book, including Entra ID Conditional Access and Intune Device Compliance, are designed to meet the Rev 2 assessment objectives.
| CMMC Practice | Microsoft Technology | Book Reference |
|---|---|---|
| ACCESS CONTROL (AC) | ||
| AC.L2-3.1.1 (Authorized Access) | Entra ID (Conditional Access) | Conditional Access Policies |
| AC.L2-3.1.2 (Access Enforcement) | Entra ID Conditional Access enforcing approved access authorizations | Conditional Access Policies |
| AC.L2-3.1.3 (CUI Flow Control) | Teams (Private Channels), Exchange Online; Purview DLP (including DLP for Copilot) | Secure Collaboration, Copilot Data Readiness |
| AC.L2-3.1.4 (Separation of Duties) | Entra ID Entitlement Management separation-of-duties checks (incompatible access packages / groups; requires Entra ID P2 or ID Governance); broader duty separation is an administrative control | Access Governance |
| AC.L2-3.1.5 (Least Privilege) | Entra ID PIM (Just-in-Time Access); Intune Local Administrators policy (Local Group Membership) restricts local-admin membership on the endpoint | Access Governance, OIB Deployment |
| AC.L2-3.1.6 (Non-Privileged Account Use) | Entra ID PIM with separate administrative accounts, privileged roles used only for security functions; Intune Local Administrators policy keeps the break-glass admin off daily-use accounts | Access Governance, OIB Deployment |
| AC.L2-3.1.7 (Privileged Functions) | Entra ID RBAC restricts privileged functions; Microsoft Sentinel and audit logs capture privileged-function execution; Intune Local Security Policies enforce UAC elevation on the endpoint | Access Governance, SIEM Strategy, OIB Deployment |
| AC.L2-3.1.8 (Unsuccessful Logon Attempts) | Entra ID (Smart Lockout); Microsoft Sentinel failed-sign-in detection | Identity Foundation, SIEM Strategy |
| AC.L2-3.1.9 (Privacy and Security Notices) | Intune (Local Security Policies: interactive logon banner) | OIB Deployment |
| AC.L2-3.1.10 (Session Lock) | Intune (Login and Lock Screen / Power and Device Lock: Max Inactivity Device Lock ≤ 15 minutes) | OIB Deployment |
| AC.L2-3.1.11 (Session Termination) | Intune device inactivity lock; Entra ID Conditional Access sign-in frequency and session controls; AVD idle and disconnect session limits | OIB Deployment, Scenario: Azure Virtual Desktop |
| AC.L2-3.1.12 (Monitor and Control Remote Access) | Azure Virtual Desktop: all remote access via the managed AVD Gateway, fully logged | Scenario: Azure Virtual Desktop |
| AC.L2-3.1.13 (Remote Access Confidentiality) | Azure Virtual Desktop Gateway (TLS-encrypted RDP); no direct RDP or VPN to session hosts | Scenario: Azure Virtual Desktop |
| AC.L2-3.1.14 (Managed Access Control Points) | Azure Virtual Desktop (AVD Gateway as the single managed remote access point, no direct RDP, no VPN required for CUI access) | Scenario: Azure Virtual Desktop |
| AC.L2-3.1.15 (Privileged Remote Access) | Azure Virtual Desktop (Virtual Machine Administrator Login role, restricts privileged console access to named admin accounts, logged in Entra sign-in logs) | Scenario: Azure Virtual Desktop |
| AC.L2-3.1.16 (Wireless Access) | Intune (Wi-Fi Config Profiles) | OIB Deployment: Wi-Fi Configuration |
| AC.L2-3.1.17 (Wireless Protection) | Intune Wi-Fi profiles enforcing WPA2/WPA3-Enterprise authentication and encryption | OIB Deployment: Wi-Fi Configuration |
| AC.L2-3.1.18 (Mobile Devices) | Intune (MAM/MDM) | Mobile Device Management & App Protection |
| AC.L2-3.1.19 (Encrypt CUI on Mobile Devices) | Intune App Protection Policies (app-level encryption) and BitLocker; Purview encryption labels | Mobile Device Management & App Protection, Sensitivity Labels |
| AC.L2-3.1.20 (Use of External Systems) | Entra ID Conditional Access (compliant / managed-device requirement); Microsoft Defender for Cloud Apps governs unmanaged and external systems | Conditional Access Policies |
| AC.L2-3.1.21 (Portable Storage on External Systems) | Defender for Endpoint Device Control; Intune removable-storage restrictions | Threat Defense |
| AC.L2-3.1.22 (Publicly Accessible Content) | Microsoft Purview DLP on public-facing SharePoint; primarily an administrative review control | Secure Collaboration |
| AWARENESS & TRAINING (AT) | ||
| AT.L2-3.2.1 (Security Awareness Training) | Defender for Office 365 (Attack Simulation Training) | Threat Defense |
| AT.L2-3.2.2 (Role-Based Training) | Policy/process control: role-based training for staff with security duties; no specific Microsoft 365 technology | — |
| AT.L2-3.2.3 (Insider Threat Awareness) | Policy/process control: no specific Microsoft 365 technology | — |
| AUDIT & ACCOUNTABILITY (AU) | ||
| AU.L2-3.3.1 (System Auditing) | Microsoft Sentinel and Purview Audit (log generation); Azure Storage / Log Analytics retention and archive (create and retain) | SIEM Strategy, Audit Readiness |
| AU.L2-3.3.2 (User Accountability) | Entra ID (Sign-in Logs) | Identity Foundation |
| AU.L2-3.3.3 (Review Logged Events) | Intune (OIB Audit and Event Logging policy: defines which event subcategories endpoints audit); periodic review of the audit-event scope documented in the SSP | Audit Readiness, OIB Deployment |
| AU.L2-3.3.4 (Audit Logging Failure Alert) | Microsoft Sentinel health monitoring (SentinelHealth table) with Azure Monitor alert rules on data-connector failure | Audit Readiness, SIEM Strategy |
| AU.L2-3.3.5 (Audit Analysis) | Microsoft Sentinel (Analytics Rules) | SIEM Strategy |
| AU.L2-3.3.6 (Audit Reduction & Reporting) | Microsoft Sentinel (Workbooks, exportable reports) | SIEM Strategy, Audit Readiness |
| AU.L2-3.3.7 (Time Stamps) | Windows Time service (NTP) synchronized to an authoritative source (Azure host time for AVD session hosts), producing consistent UTC time stamps in audit records | OIB Deployment, Audit Readiness |
| AU.L2-3.3.8 (Protect Audit Information) | Azure RBAC on the Log Analytics workspace; immutability policy on archived storage exports | SIEM Strategy, Audit Readiness |
| AU.L2-3.3.9 (Limit Audit Management) | Entra PIM + Azure RBAC (Log Analytics Contributor / Security Administrator scoped to authorized admins) | SIEM Strategy, Audit Readiness |
| CONFIGURATION MANAGEMENT (CM) | ||
| CM.L2-3.4.1 (Baseline Config) | Intune (Device Compliance Policies); Entra ID device object hygiene (accurate inventory of managed endpoints) | OIB Deployment, Entra Device Hygiene |
| CM.L2-3.4.2 (Configuration Settings) | Intune (configuration profiles and security baselines enforcing required settings) | OIB Deployment |
| CM.L2-3.4.3 (Change Control) | Intune and Entra ID audit logs track configuration changes; change approval is an administrative process | OIB Deployment |
| CM.L2-3.4.4 (Security Impact Analysis) | Policy/process control: security-impact analysis of changes; no specific Microsoft 365 technology | — |
| CM.L2-3.4.5 (Access Restrictions for Change) | Entra ID RBAC + PIM and Intune RBAC restrict who may change configurations | Access Governance |
| CM.L2-3.4.6 (Least Functionality) | MDE Attack Surface Reduction (ASR) Rules: blocks execution of unnecessary system features and living-off-the-land binaries | Defender for Endpoint |
| CM.L2-3.4.7 (Unauthorized Software) | Defender for Endpoint (Software Inventory) | Threat Defense |
| CM.L2-3.4.8 (Authorized Software: Deny by Exception) | Intune (App Control for Business / WDAC with Managed Installer: allow apps deployed by Intune, block the rest; audit mode first) | OIB Deployment: Application Control |
| CM.L2-3.4.9 (User-Installed Software) | Least privilege (Local Administrators + LAPS) blocks machine installs; Intune Discovered apps (software inventory) monitors; App Control for Business enforces allow-listing | OIB Deployment, Application Control |
| IDENTIFICATION & AUTHENTICATION (IA) | ||
| IA.L2-3.5.1 (Identification) | Entra ID (User Accounts) | Identity Foundation |
| IA.L2-3.5.2 (Authenticate Users and Devices) | Entra ID authentication; Entra device identity and Intune device certificates (SCEP/PKCS) authenticate devices | Identity Foundation, Entra Device Hygiene |
| IA.L2-3.5.3 (MFA) | Entra ID (Conditional Access) | Conditional Access Policies |
| IA.L2-3.5.4 (Replay-Resistant Authentication) | Entra ID phishing-resistant methods (FIDO2, Windows Hello for Business), replay-resistant by design | Phishing-Resistant Authentication |
| IA.L2-3.5.5 (Identifier Management) | Entra ID identifier / UPN management; Lifecycle Workflows prevent identifier reuse | Identity Foundation |
| IA.L2-3.5.6 (Disable Inactive Identifiers) | Entra ID Access Reviews and Lifecycle Workflows disable accounts after a defined period of inactivity | Access Governance |
| IA.L2-3.5.7 (Password Complexity) | Entra ID (Password Protection, banned-password list); Windows LAPS rotates a unique, complex password for the local Administrator account that Entra Password Protection does not reach | Identity Foundation, OIB Deployment |
| IA.L2-3.5.8 (Prohibit Password Reuse) | Entra ID / Active Directory password history policy | Identity Foundation |
| IA.L2-3.5.9 (Temporary Password) | Entra ID Temporary Access Pass with forced change at next sign-in | Identity Foundation |
| IA.L2-3.5.10 (Cryptographically-Protected Passwords) | Entra ID stores password hashes and enforces TLS in transit (Microsoft-managed) | Identity Foundation |
| IA.L2-3.5.11 (Obscure Authentication Feedback) | Windows and Entra ID default: masked credential entry | Identity Foundation |
| INCIDENT RESPONSE (IR) | ||
| IR.L2-3.6.1 (Incident Handling) | Microsoft Sentinel (Incident Management); MDE Incidents and automated investigation provide the response workflow | SIEM Strategy, Defender for Endpoint |
| IR.L2-3.6.2 (Incident Reporting) | Defender XDR (Alerts); MDE incident timeline and audit log satisfy documentation requirements | Threat Defense, Defender for Endpoint |
| IR.L2-3.6.3 (Test Incident Response) | Administrative control: IR tests and tabletops; Attack Simulation Training and Microsoft Sentinel exercises support the test | Threat Defense |
| MAINTENANCE (MA) | ||
| MA.L2-3.7.1 (Perform Maintenance) | Policy/process control: no specific Microsoft 365 technology | — |
| MA.L2-3.7.2 (Maintenance Tools and Personnel) | Administrative control; privileged maintenance access is governed by Entra PIM | Access Governance |
| MA.L2-3.7.3 (Sanitize Off-Site Equipment) | Policy/process control: media sanitization; no specific Microsoft 365 technology | — |
| MA.L2-3.7.4 (Check Media for Malicious Code) | Defender Antivirus scans diagnostic and removable media before use | Threat Defense |
| MA.L2-3.7.5 (Remote Maintenance) | Azure Virtual Desktop (Secure Admin Workstations, Virtual Machine Administrator Login gated by phishing-resistant CA) | Virtual Desktop Strategy, Scenario: Azure Virtual Desktop |
| MA.L2-3.7.6 (Supervise Maintenance Personnel) | Policy/process control: no specific Microsoft 365 technology | — |
| MEDIA PROTECTION (MP) | ||
| MP.L2-3.8.1 (Media Protection) | BitLocker (Intune Policy) | OIB Deployment |
| MP.L2-3.8.2 (Limit Access to Media) | BitLocker plus access controls; Purview sensitivity labels restrict access to CUI on media | OIB Deployment, Sensitivity Labels |
| MP.L2-3.8.3 (Media Sanitization) | Intune (remote wipe / device retire); physical media destruction is an administrative process | OIB Deployment |
| MP.L2-3.8.4 (Media Marking) | Purview Information Protection (labels apply visual markings, headers, and footers) | Sensitivity Labels |
| MP.L2-3.8.5 (Media Transport Accountability) | Policy/process control: media transport chain-of-custody; no specific Microsoft 365 technology | — |
| MP.L2-3.8.6 (Media Encryption in Transit) | Intune (BitLocker To Go for removable media) | OIB Deployment |
| MP.L2-3.8.7 (Portable Storage) | Defender for Endpoint (Device Control) | Threat Defense |
| MP.L2-3.8.8 (Prohibit Unidentified Storage) | Defender for Endpoint Device Control (block removable devices with no identifiable owner) | Threat Defense |
| MP.L2-3.8.9 (Protect Backup CUI) | Azure Backup (encryption at rest) and BitLocker | — |
| PERSONNEL SECURITY (PS) | ||
| PS.L2-3.9.1 (Personnel Screening) | Policy/process control: personnel screening; no specific Microsoft 365 technology | — |
| PS.L2-3.9.2 (Personnel Termination) | Entra ID (Account Disable / Revocation) | Identity Foundation |
| PHYSICAL PROTECTION (PE) | ||
| PE.L2-3.10.1 (Physical Access) | Azure Virtual Desktop (CUI never touches end-user hardware: users see only a rendered screen; data remains in Azure Government FedRAMP High datacenters) | Virtual Desktop Strategy, Scenario: Azure Virtual Desktop |
| PE.L2-3.10.2 (Monitor Physical Facility) | Microsoft Azure datacenter physical controls (cloud-hosted CUI); on-prem facility monitoring is an administrative process | Virtual Desktop Strategy |
| PE.L2-3.10.3 (Escort Visitors) | Policy/process control: no specific Microsoft 365 technology | — |
| PE.L2-3.10.4 (Physical Access Logs) | Microsoft Azure datacenter controls (cloud-side); on-prem physical-access logging is an administrative process | Virtual Desktop Strategy |
| PE.L2-3.10.5 (Manage Physical Access Devices) | Policy/process control: no specific Microsoft 365 technology | — |
| PE.L2-3.10.6 (Alternate Work Sites) | Azure Virtual Desktop (CUI stays in the datacenter regardless of work site); Intune compliance | Scenario: Azure Virtual Desktop |
| RISK ASSESSMENT (RA) | ||
| RA.L2-3.11.1 (Risk Assessment) | Administrative control: risk assessment process; Microsoft Secure Score and Defender inform risk posture | Audit Readiness |
| RA.L2-3.11.2 (Vulnerability Scan) | Defender Vulnerability Management | Threat Defense |
| RA.L2-3.11.3 (Remediate Vulnerabilities) | Defender Vulnerability Management (remediation tracking) with Intune deployment | Threat Defense |
| SECURITY ASSESSMENT (CA) | ||
| CA.L2-3.12.1 (Security Controls) | Compliance Manager / Secure Score | Audit Readiness |
| CA.L2-3.12.2 (Plan of Action and Milestones) | Microsoft Purview Compliance Manager improvement actions track Plan of Action and Milestones items; the plan and remediation decisions are an administrative process | Audit Readiness |
| CA.L2-3.12.3 (Continuous Monitoring) | Microsoft Sentinel; MDE Secure Score, device health reports, and alert pipeline provide continuous monitoring evidence | SIEM Strategy, Defender for Endpoint |
| CA.L2-3.12.4 (System Security Plan) | Administrative control: SSP authoring; Microsoft Purview Compliance Manager supports evidence collection | Audit Readiness |
| SYSTEM & COMMUNICATIONS (SC) | ||
| SC.L2-3.13.1 (Network Boundary Monitoring) | Azure Firewall (deny-all with explicit allow rules, FQDN-based egress control for AVD session hosts) | AVD Firewall Reference, Scenario: Azure Virtual Desktop |
| SC.L2-3.13.2 (Secure Architecture and Engineering) | Policy/process control: secure architecture and engineering; no specific Microsoft 365 technology | — |
| SC.L2-3.13.3 (Separate User and Management Functionality) | Azure RBAC and AVD admin-plane separation; Entra ID privileged roles | Scenario: Azure Virtual Desktop |
| SC.L2-3.13.4 (Shared Resource Isolation) | Azure tenant and resource isolation (Microsoft-managed) | — |
| SC.L2-3.13.5 (Subnetworks / No Public Exposure) | Azure Virtual Desktop (session hosts have no public IPs; inbound via AVD Gateway service tag only; outbound via Azure Firewall UDR) | Scenario: Azure Virtual Desktop |
| SC.L2-3.13.6 (Deny by Default) | Azure Firewall (deny-all default, explicit allow rules) | AVD Firewall Reference |
| SC.L2-3.13.7 (Prevent Split Tunneling) | Azure Virtual Desktop with forced tunneling via UDR (no split tunnel); Entra ID Conditional Access | Scenario: Azure Virtual Desktop |
| SC.L2-3.13.8 (Data in Transit) | TLS 1.2+ (Office 365 Defaults); AVD Gateway enforces TLS on all RDP sessions | Secure Collaboration, Scenario: Azure Virtual Desktop |
| SC.L2-3.13.9 (Network Disconnect) | AVD session time limits (idle / disconnect); Entra ID Conditional Access sign-in frequency | Scenario: Azure Virtual Desktop |
| SC.L2-3.13.10 (Cryptographic Key Management) | Azure Key Vault (FIPS-validated key management) | — |
| SC.L2-3.13.11 (FIPS Encryption) | Intune (BitLocker FIPS Policy) | OIB Deployment |
| SC.L2-3.13.12 (Collaborative Computing Devices) | Intune device restrictions (camera and microphone); Microsoft Teams meeting policies | OIB Deployment |
| SC.L2-3.13.13 (Mobile Code) | MDE Attack Surface Reduction and App Control for Business restrict scripts and mobile code | Defender for Endpoint |
| SC.L2-3.13.14 (VoIP) | Microsoft Teams (managed VoIP) governed by Teams policies | Secure Collaboration |
| SC.L2-3.13.15 (Session Authenticity) | TLS 1.2+ and Entra ID token integrity protect session authenticity; Intune Local Security Policies enforce SMB signing / NTLM hardening on the endpoint | Secure Collaboration, OIB Deployment |
| SC.L2-3.13.16 (Data at Rest) | Purview Information Protection (Encryption) | Sensitivity Labels |
| SYSTEM & INFORMATION INTEGRITY (SI) | ||
| SI.L2-3.14.1 (Flaw Remediation) | Intune (Windows Autopatch / Updates) | OIB Deployment |
| SI.L2-3.14.2 (Malicious Code) | Defender Antivirus | Threat Defense |
| SI.L2-3.14.3 (Monitor Security Alerts and Advisories) | Microsoft Defender for Endpoint / Defender XDR (security alerts, threat analytics, and advisories) | Defender for Endpoint, Threat Defense |
| SI.L2-3.14.4 (Malicious Code Protection Updates) | MDE platform and signature updates managed by Microsoft, no separate update infrastructure required | Defender for Endpoint |
| SI.L2-3.14.5 (Periodic and Real-Time Scans) | Defender Antivirus (scheduled and real-time scanning) | Threat Defense |
| SI.L2-3.14.6 (System Monitoring) | MDE behavioral analytics and anomaly detection; Microsoft Sentinel analytics rules and UEBA | Defender for Endpoint, SIEM Strategy |
| SI.L2-3.14.7 (Identify Unauthorized Use) | MDE behavioral analytics and anomaly detection: surfaces unexpected process execution, lateral movement, and data exfiltration patterns | Defender for Endpoint |
NIST SP 800-171 Rev. 3 Controls
This matrix lists all 97 active NIST SP 800-171 Rev. 3 requirements across the 17 families. The Microsoft 365 Technology column names the capability that implements each requirement; entries marked Policy/process control are satisfied administratively and have no single Microsoft technology. Requirements that NIST withdrew in Rev 3 (consolidated into other requirements) are shown in a compact line at the end of each family so that no number appears unexplained. Control identifiers and titles follow Rev 3 numbering; verify against NIST SP 800-171 Rev. 3 for the authoritative text.
| NIST SP 800-171 Rev. 3 Requirement | Microsoft 365 Technology | Book Reference |
|---|---|---|
| ACCESS CONTROL (AC) | ||
| 3.1.1 (Account Management) | Entra ID (Conditional Access); user account lifecycle management | Conditional Access Policies |
| 3.1.2 (Access Enforcement) | Entra ID Conditional Access enforcing approved access authorizations at sign-in; Microsoft 365 role-based access control | Conditional Access Policies |
| 3.1.3 (Information Flow Enforcement) | Teams (Private Channels), Exchange Online; Purview DLP (including DLP for Copilot) | Secure Collaboration, Copilot Data Readiness |
| 3.1.4 (Separation of Duties) | Entra ID Entitlement Management separation-of-duties checks (incompatible access packages / groups; requires Entra ID P2 or ID Governance); broader duty separation is an administrative control | Access Governance |
| 3.1.5 (Least Privilege) | Entra ID PIM (Just-in-Time Access); Intune Local Administrators policy (Local Group Membership) restricts local-admin membership on the endpoint | Access Governance, OIB Deployment |
| 3.1.6 (Least Privilege – Privileged Accounts) | Entra ID PIM with separate administrative accounts, privileged roles used only for privileged functions; Intune Local Administrators policy keeps the break-glass admin off daily-use accounts | Access Governance, OIB Deployment |
| 3.1.7 (Least Privilege – Privileged Functions) | Entra ID RBAC; Microsoft Sentinel and audit logs capture privileged-function execution; Intune Local Security Policies enforce UAC elevation on the endpoint | Access Governance, SIEM Strategy, OIB Deployment |
| 3.1.8 (Unsuccessful Logon Attempts) | Entra ID (Smart Lockout); Microsoft Sentinel failed-sign-in detection | Identity Foundation, SIEM Strategy |
| 3.1.9 (System Use Notification) | Intune (Local Security Policies: interactive logon banner) | OIB Deployment |
| 3.1.10 (Device Lock) | Intune (Login and Lock Screen / Power and Device Lock: Max Inactivity Device Lock ≤ 15 minutes) | OIB Deployment |
| 3.1.11 (Session Termination) | Entra ID Conditional Access sign-in frequency and session controls; AVD idle and disconnect session limits | Scenario: Azure Virtual Desktop |
| 3.1.12 (Remote Access) | Azure Virtual Desktop or Conditional Access with compliant-device requirement; Entra PIM with phishing-resistant MFA and Azure Bastion / AVD Virtual Machine Administrator Login for privileged sessions | Scenario: Azure Virtual Desktop |
| 3.1.16 (Wireless Access) | Intune (Wi-Fi Configuration Profiles) | OIB Deployment: Wi-Fi Configuration |
| 3.1.18 (Access Control for Mobile Devices) | Intune (MAM/MDM) | Mobile Device Management & App Protection |
| 3.1.20 (Use of External Systems) | Entra ID Conditional Access (compliant / managed-device requirement); Microsoft Defender for Cloud Apps | Conditional Access Policies |
| 3.1.22 (Publicly Accessible Content) | Microsoft Purview DLP on public-facing SharePoint; primarily an administrative review control | Secure Collaboration |
| 3.1.13–3.1.15, 3.1.17, 3.1.19, 3.1.21 | Withdrawn in Rev 3 (consolidated into other requirements) | — |
| AWARENESS & TRAINING (AT) | ||
| 3.2.1 (Literacy Training and Awareness) | Defender for Office 365 (Attack Simulation Training) | Threat Defense |
| 3.2.2 (Role-Based Training) | Policy/process control: role-based training for staff with security duties; no specific Microsoft 365 technology | — |
| 3.2.3 | Withdrawn in Rev 3 | — |
| AUDIT & ACCOUNTABILITY (AU) | ||
| 3.3.1 (Event Logging) | Microsoft Sentinel and Purview Audit (log generation); Azure Storage / Log Analytics retention and archive (create and retain) | SIEM Strategy, Audit Readiness |
| 3.3.2 (Audit Record Content) | Entra ID (Sign-in Logs) | Identity Foundation |
| 3.3.3 (Audit Record Generation) | Intune (endpoint audit-policy config) generating records at the selected event types, ingested by Microsoft Sentinel / Purview Audit | SIEM Strategy, Audit Readiness |
| 3.3.4 (Response to Audit Logging Process Failures) | Microsoft Sentinel health monitoring (SentinelHealth table) with Azure Monitor alert rules on data-connector failure | Audit Readiness, SIEM Strategy |
| 3.3.5 (Audit Record Review, Analysis, and Reporting) | Microsoft Sentinel (Analytics Rules) | SIEM Strategy |
| 3.3.6 (Audit Record Reduction and Report Generation) | Microsoft Sentinel (Workbooks, exportable reports) | SIEM Strategy, Audit Readiness |
| 3.3.7 (Time Stamps) | Windows Time service (NTP) synchronized to an authoritative source, producing consistent UTC time stamps in audit records | Audit Readiness |
| 3.3.8 (Protection of Audit Information) | Azure RBAC on the Log Analytics workspace; immutability policy on archived storage exports; audit management limited to authorized admins via Entra PIM | SIEM Strategy, Audit Readiness |
| 3.3.9 | Withdrawn in Rev 3 (folded into 3.3.8) | — |
| CONFIGURATION MANAGEMENT (CM) | ||
| 3.4.1 (Baseline Configuration) | Intune (Device Compliance Policies) | OIB Deployment |
| 3.4.2 (Configuration Settings) | Intune (configuration profiles and security baselines enforcing required settings) | OIB Deployment |
| 3.4.3 (Configuration Change Control) | Intune and Entra ID audit logs track configuration changes; change approval is an administrative process | OIB Deployment |
| 3.4.4 (Impact Analyses) | Policy/process control: security-impact analysis of changes; no specific Microsoft 365 technology | — |
| 3.4.5 (Access Restrictions for Change) | Entra ID RBAC + PIM and Intune RBAC restrict who may change configurations | Access Governance |
| 3.4.6 (Least Functionality) | MDE Attack Surface Reduction (ASR) Rules: blocks execution of unnecessary system features and living-off-the-land binaries | Defender for Endpoint |
| 3.4.8 (Authorized Software – Allow by Exception) | Intune (App Control for Business / WDAC with Managed Installer: allow apps deployed by Intune, block the rest; audit mode first) | OIB Deployment: Application Control |
| 3.4.10 (System Component Inventory) | Intune device inventory and Entra ID device objects; Defender device inventory | Entra Device Hygiene |
| 3.4.11 (Information Location) | Microsoft Purview (Content Explorer / Data Map locates where CUI resides) | Sensitivity Labels |
| 3.4.12 (System and Component Config for High-Risk Areas) | Intune configuration profiles for travel / high-risk scenarios; Conditional Access location policies | Conditional Access Policies |
| 3.4.7, 3.4.9 | Withdrawn in Rev 3 (consolidated into 3.4.8) | — |
| IDENTIFICATION & AUTHENTICATION (IA) | ||
| 3.5.1 (User Identification and Authentication) | Entra ID (User Accounts) | Identity Foundation |
| 3.5.2 (Device Identification and Authentication) | Entra ID device identity and Intune device certificates (SCEP / PKCS) authenticate devices | Entra Device Hygiene |
| 3.5.3 (Multi-Factor Authentication) | Entra ID (Conditional Access) | Conditional Access Policies |
| 3.5.4 (Replay-Resistant Authentication) | Entra ID phishing-resistant methods (FIDO2, Windows Hello for Business), replay-resistant by design | Phishing-Resistant Authentication |
| 3.5.5 (Identifier Management) | Entra ID identifier / UPN management; Lifecycle Workflows | Identity Foundation |
| 3.5.7 (Password Management) | Entra ID (Password Protection, banned-password list); Windows LAPS rotates a unique, complex password for the local Administrator account that Entra Password Protection does not reach | Identity Foundation, OIB Deployment |
| 3.5.11 (Authentication Feedback) | Windows and Entra ID default: masked credential entry | Identity Foundation |
| 3.5.12 (Authenticator Management) | Windows Hello for Business (TPM-bound, phishing-resistant credential lifecycle, control added in Rev. 3) | Phishing-Resistant Authentication |
| 3.5.6, 3.5.8, 3.5.9, 3.5.10 | Withdrawn in Rev 3 | — |
| INCIDENT RESPONSE (IR) | ||
| 3.6.1 (Incident Handling) | Microsoft Sentinel (Incident Management); MDE automated investigation and response | SIEM Strategy, Defender for Endpoint |
| 3.6.2 (Incident Monitoring, Reporting, and Response Assistance) | Defender XDR (Alerts and incident timeline) | Threat Defense, Defender for Endpoint |
| 3.6.3 (Incident Response Testing) | Administrative control: IR tests and tabletops; Attack Simulation Training and Microsoft Sentinel exercises support the test | Threat Defense |
| 3.6.4 (Incident Response Training) | Policy/process control: no specific Microsoft 365 technology | — |
| 3.6.5 (Incident Response Plan) | Policy/process control: no specific Microsoft 365 technology | — |
| MAINTENANCE (MA) | ||
| 3.7.4 (Maintenance Tools) | Defender Antivirus scans maintenance and diagnostic media; Intune governs approved tools | Threat Defense |
| 3.7.5 (Nonlocal Maintenance) | Entra PIM with Conditional Access requiring phishing-resistant MFA for privileged remote sessions | Identity Foundation |
| 3.7.6 (Maintenance Personnel) | Administrative control; privileged maintenance access is governed by Entra PIM | Access Governance |
| 3.7.1–3.7.3 | Withdrawn in Rev 3 | — |
| MEDIA PROTECTION (MP) | ||
| 3.8.1 (Media Storage) | BitLocker (Intune Policy) | OIB Deployment |
| 3.8.2 (Media Access) | BitLocker plus access controls; Purview sensitivity labels restrict access to CUI on media | Sensitivity Labels |
| 3.8.3 (Media Sanitization) | Intune (remote wipe / device retire); physical media destruction is an administrative process | OIB Deployment |
| 3.8.4 (Media Marking) | Purview Information Protection (labels apply visual markings, headers, and footers) | Sensitivity Labels |
| 3.8.5 (Media Transport) | Intune BitLocker To Go (encryption in transit); transport chain-of-custody is an administrative process | OIB Deployment |
| 3.8.7 (Media Use) | Defender for Endpoint (Device Control) | Threat Defense |
| 3.8.9 (System Backup – Cryptographic Protection) | Azure Backup (encryption at rest) and BitLocker | — |
| 3.8.6, 3.8.8 | Withdrawn in Rev 3 | — |
| PERSONNEL SECURITY (PS) | ||
| 3.9.1 (Personnel Screening) | Policy/process control: personnel screening; no specific Microsoft 365 technology | — |
| 3.9.2 (Personnel Termination and Transfer) | Entra ID (Account disable, token revocation, access package removal) | Identity Foundation |
| PHYSICAL PROTECTION (PE) | ||
| 3.10.1 (Physical Access Authorizations) | Microsoft Azure datacenter physical controls (SOC 2 Type II, ISO 27001 certified facilities) | Virtual Desktop Strategy |
| 3.10.2 (Monitoring Physical Access) | Microsoft Azure datacenter physical monitoring (cloud-hosted CUI); on-prem facility monitoring is an administrative process | Virtual Desktop Strategy |
| 3.10.6 (Alternate Work Site) | Azure Virtual Desktop (CUI stays in the datacenter regardless of work site); Intune compliance | Scenario: Azure Virtual Desktop |
| 3.10.7 (Physical Access Control) | Microsoft Azure datacenter physical access controls (cloud); on-prem is an administrative process | Virtual Desktop Strategy |
| 3.10.8 (Access Control for Transmission) | Microsoft Azure datacenter controls protect transmission infrastructure (cloud); on-prem cabling is an administrative process | Virtual Desktop Strategy |
| 3.10.3–3.10.5 | Withdrawn in Rev 3 | — |
| RISK ASSESSMENT (RA) | ||
| 3.11.1 (Risk Assessment) | Administrative control: risk assessment process; Microsoft Secure Score and Defender inform risk posture | Audit Readiness |
| 3.11.2 (Vulnerability Monitoring and Scanning) | Defender Vulnerability Management | Threat Defense |
| 3.11.4 (Risk Response) | Defender Vulnerability Management (remediation tracking) and Microsoft Purview Compliance Manager improvement actions; risk-acceptance decisions are an administrative process | Threat Defense |
| 3.11.3 | Withdrawn in Rev 3 | — |
| SECURITY ASSESSMENT (CA) | ||
| 3.12.1 (Security Assessment) | Compliance Manager / Secure Score | Audit Readiness |
| 3.12.2 (Plan of Action and Milestones) | Microsoft Purview Compliance Manager improvement actions track Plan of Action and Milestones items; the plan and remediation decisions are an administrative process | Audit Readiness |
| 3.12.3 (Continuous Monitoring) | Microsoft Sentinel; MDE Secure Score and device health reports | SIEM Strategy, Defender for Endpoint |
| 3.12.5 (Information Exchange) | Policy/process control: interconnection and information-exchange agreements; no specific Microsoft 365 technology | — |
| 3.12.4 | Withdrawn in Rev 3 | — |
| SYSTEM & COMMUNICATIONS PROTECTION (SC) | ||
| 3.13.1 (Boundary Protection) | Azure Firewall or NSG with deny-all default; FQDN-based egress filtering; Azure Virtual Network with private endpoints and no public IP exposure for internal workloads | Threat Defense, Scenario: Azure Virtual Desktop |
| 3.13.4 (Information in Shared System Resources) | Azure tenant and resource isolation (Microsoft-managed) | — |
| 3.13.6 (Network Communications – Deny by Default) | Azure Firewall (deny-all default, explicit allow rules); NSGs | Scenario: Azure Virtual Desktop |
| 3.13.8 (Transmission and Storage Confidentiality) | TLS 1.2+ enforced by Microsoft 365 defaults and Conditional Access blocking legacy authentication (in transit); Purview Information Protection sensitivity label-based encryption (at rest) | Secure Collaboration, Sensitivity Labels |
| 3.13.9 (Network Disconnect) | AVD session time limits (idle / disconnect); Entra ID Conditional Access sign-in frequency | Scenario: Azure Virtual Desktop |
| 3.13.10 (Cryptographic Key Establishment and Management) | Azure Key Vault (FIPS-validated key management) | — |
| 3.13.11 (Cryptographic Protection) | Intune (BitLocker AES-256, FIPS-validated cryptographic module policy) | OIB Deployment |
| 3.13.12 (Collaborative Computing Devices and Applications) | Intune device restrictions (camera and microphone); Microsoft Teams meeting policies | OIB Deployment |
| 3.13.13 (Mobile Code) | MDE Attack Surface Reduction and App Control for Business restrict scripts and mobile code | Defender for Endpoint |
| 3.13.15 (Session Authenticity) | TLS 1.2+ and Entra ID token integrity protect session authenticity; Intune Local Security Policies enforce SMB signing / NTLM hardening on the endpoint | Secure Collaboration, OIB Deployment |
| 3.13.2, 3.13.3, 3.13.5, 3.13.7, 3.13.14, 3.13.16 | Withdrawn in Rev 3 | — |
| SYSTEM & INFORMATION INTEGRITY (SI) | ||
| 3.14.1 (Flaw Remediation) | Intune (Windows Update / Autopatch rings) | OIB Deployment |
| 3.14.2 (Malicious Code Protection) | Microsoft Defender Antivirus, protection mechanisms plus Microsoft-managed platform and signature updates | Threat Defense, Defender for Endpoint |
| 3.14.3 (Security Alerts, Advisories, and Directives) | Microsoft Defender for Endpoint / Defender XDR (security alerts, threat analytics, and advisories) | Defender for Endpoint, Threat Defense |
| 3.14.6 (System Monitoring) | MDE behavioral analytics and anomaly detection: surfaces unexpected process execution, lateral movement, and data exfiltration patterns | Defender for Endpoint |
| 3.14.8 (Information Management and Retention) | Microsoft Purview Data Lifecycle Management (retention policies and labels governing how CUI is retained and disposed) | Data Lifecycle & Retention |
| 3.14.4, 3.14.5, 3.14.7 | Withdrawn in Rev 3 | — |
| PLANNING (PL) | ||
| 3.15.1 (Policy and Procedures) | Policy/process control: security policies and procedures; no specific Microsoft 365 technology | — |
| 3.15.2 (System Security Plan) | Administrative control: SSP authoring; Microsoft Purview Compliance Manager supports evidence collection | Audit Readiness |
| 3.15.3 (Rules of Behavior) | Administrative control: rules of behavior / acceptable use; Intune can deploy the acknowledgement, but acceptance is a process | — |
| SYSTEM & SERVICES ACQUISITION (SA) | ||
| 3.16.1 (Security Engineering Principles) | Policy/process control: secure systems-engineering principles; no specific Microsoft 365 technology | — |
| 3.16.2 (Unsupported System Components) | Defender Vulnerability Management flags end-of-life and unsupported software; Intune update rings retire unsupported OS versions | Threat Defense |
| 3.16.3 (External System Services) | Microsoft Purview Compliance Manager (assess external service providers); contractual flow-down is an administrative process | Audit Readiness |
| SUPPLY CHAIN RISK MANAGEMENT (SR) | ||
| 3.17.1 (Supply Chain Risk Management Plan) | Policy/process control: no specific Microsoft 365 technology | — |
| 3.17.2 (Acquisition Strategies, Tools, and Methods) | Policy/process control: no specific Microsoft 365 technology | — |
| 3.17.3 (Supply Chain Requirements and Processes) | Policy/process control: flow-down of supply-chain requirements; no specific Microsoft 365 technology | — |
📩 Don't Miss the Next Solution
Join the list to see the real-time solutions I'm delivering to my GCC High clients.