Control catalogue

All 176 checks, searchable.

Every check ConfigCheckup runs on a client tenant, across 8 areas: what it looks at, how to fix it, the 20 frameworks it maps to, and whether it has an approved fix. 111 of the 176 offer one from the finding.

30 days of everything in Automate on up to 3 tenants, from your first connected tenant. No card. Then choose the plan that fits.

The checks

176 shown

Identity & Authentication (34)

Privileged Access (21)

Data Protection (11)

Device & Endpoint (20)

Collaboration & Sharing (36)

Threat Protection (42)

Licensing & Cost (5)

Governance & Operations (7)

criticalIdentity & AuthenticationNL-IDN-001

Multi-factor authentication registration coverage

Measures how many enabled member accounts are MFA capable: registered for a multi-factor method that the authentication methods policy allows.

Recommended fix

Drive registration to 100% of enabled member accounts, then enforce it with Conditional Access.

Approved fix from the finding

Frameworks

NIST CSF 2.0Essential EightCyber EssentialsCIS Controls v8.1NCSC 10 StepsISO 27001:2022NCSC CAFDSPTDORANIS2Microsoft Cloud Security BenchmarkZero TrustSOC 2PCI DSS 4.0.1NIST SP 800-171CMMC Level 2Secure ScoreCyber Essentials PlusCIS M365

A check that could not read its data is reported as not assessed and left out of the score, never counted as a pass. “Fix” marks a check with an approved fix: a dry run, approval and a way back.

See the checks on a real assessment

How the checks become a scored, worst-first assessment of each client, with the evidence behind every finding.

The Microsoft 365 security assessment How an approved fix is made

Run every check on your own tenants.

The findings come from your client’s own tenant, with the evidence behind each.

30 days of everything in Automate on up to 3 tenants, from your first connected tenant. No card. Then choose the plan that fits.