A default Microsoft 365 tenant leaves dozens of doors unlocked. This checklist walks through 80 CIS-based controls across 13 security domains — from MFA and Conditional Access to email security, SharePoint, Teams, and Secure Score — each prioritized so you fix the highest-impact gaps first.
One-time purchase · instant download · 80 controls with verification & remediation steps
What's inside
Every control is plain-language, prioritized by severity, and paired with how to verify it and how to fix it. Organized into 13 sections.
Real sample controls
These are taken directly from the checklist — no paraphrasing.
Require multi-factor authentication for every user, not just admins.
Enforce MFA on all Global Administrator accounts.
Block legacy (Basic) authentication protocols with Conditional Access.
Run an active Conditional Access policy that requires MFA for all users.
By purchasing you agree to our Terms. Digital products are non-refundable once accessed.
Free
Download a free one-page preview of this checklist — the highest-impact controls, no email gate. Want the curated top-10 by email instead? Use the form on the homepage.
Why teams use Strondex
Built by security professionals
Controls drawn from CIS benchmarks, framework requirements, and real-world assessment findings.
Self-serve, no consultant
Plain-language steps you can action yourself — without the $300/hr engagement.
Honest scope
Exactly 80 controls. No inflated counts, no fabricated reviews — see the samples above.
Yes. The 80 controls are built on CIS Microsoft 365 benchmark guidance and organized into 13 practical security domains so you can work through them tenant by tenant.
Most controls apply to standard Business and E3 tenants. A handful of advanced controls (such as certain Defender and compliance features) call out the licensing they require so you know what is in scope.
Each control includes verification and remediation guidance so you can roll changes out safely. The checklist flags severity so you can sequence high-impact, low-disruption changes first.
Cyber Insurance Prep Checklist
47 controls underwriters actually check — know exactly where you stand before renewal.
View $47 ›AWS Hardening Checklist
95 CIS L1/L2 controls for AWS — IAM, logging, networking, storage, and more.
View $147 ›Azure Hardening Checklist
88 CIS-based controls for Microsoft Azure — identity to networking to Defender.
View $147 ›SOC 2 Readiness Workbook
85 controls mapped to AICPA Trust Services Criteria — know your audit readiness score.
View $197 ›PCI DSS Compliance Checklist
78 PCI DSS v4.0 controls with SAQ-A and SAQ-D annotations.
View $147 ›