Skip to content

Secure Cloud Business Applications (SCuBA) Microsoft 365 Secure Configuration Baselines

In effectCISA · CISA guidance · December 21, 2023

Summary

Sets secure configuration settings for Microsoft 365 services such as Exchange Online, Teams, and SharePoint, with a free tool (ScubaGear) to check them; Binding Operational Directive 25-01 requires agencies to apply the mandatory settings.

Read it on www.cisa.gov

What FedXchange has recorded

No changes recorded. The watch records a new document and any change in its status.

Issuer
Cybersecurity and Infrastructure Security Agency (CISA)
Type
CISA guidance
Issued
December 21, 2023
Status
In effect

Still in force, possibly with amendments.

BOD 25-01 made the mandatory settings in these baselines binding for agency Microsoft 365 tenants, with a June 20, 2025 deadline.

Get new governance by email

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.