Sign in with your Microsoft Entra account to audit your tenant against
the CIS Microsoft 365 Foundations Benchmark v7.0.0 — live from your browser, read-only,
with HTML and Word report downloads.
⚠ Sign in only after onboarding by Limon-IT.
This tool requires that Limon-IT has completed the onboarding of your Microsoft 365
tenant. Signing in before onboarding will fail or produce incomplete, misleading
results. Contact Limon-IT if you are unsure whether your tenant has been onboarded.
The audit runs in your browser and your tenant data is never stored. Sign-in uses Microsoft
Entra with PKCE; tokens are session-only and requests go to graph.microsoft.com (plus
dns.google for SPF/DKIM/DMARC record checks and, optionally, api.fabric.microsoft.com for the
Power BI controls). Controls that Microsoft exposes only to Exchange, Purview, Teams or
SharePoint PowerShell are graded from PowerShell evidence — collected on demand by the
optional read-only evidence service, or imported from the offline collector script — and are
otherwise reported as Manual with the exact audit command and portal path.
What do you want to audit?
Audit scope
CIS Microsoft 365 Foundations Benchmark v7.0.0 · 160 controls
PowerShell evidence
Runs read-only Graph checks; nothing is changed in your tenant.
Report
Load from GitHub
Loads scheduled audit results published to the private audits repository
(results/<tenant>/…). Requires a fine-grained personal access token with
read-only Contents permission on that repository. The token is stored only in this
browser.