Skip to content

Insights

CIS Microsoft 365 Foundations Benchmark: profiles, levels and Implementation Groups explained

QG Professional Services

  • Cybersecurity
  • Microsoft & Cloud

Microsoft Secure Score tells you Microsoft's opinion of your tenant. The CIS Microsoft 365 Foundations Benchmark tells you something an auditor, a board or a customer will accept: an independent, versioned, evidence-based measure of how your tenant compares against a consensus hardening standard. The two are complementary, and mature security programmes run both — Secure Score for day-to-day tracking, CIS for assurance you can defend.

The benchmark's strength is also its intimidation factor: well over a hundred recommendations across identity, application, data, device and governance settings. Two different structures exist to make that tractable, and they are constantly confused with one another. Getting them straight is the difference between a coherent assessment and an unreadable spreadsheet.

What the benchmark actually is

The Center for Internet Security publishes consensus-developed configuration benchmarks for widely used platforms; the Microsoft 365 Foundations Benchmark is the one for M365 tenants. Each recommendation specifies the exact setting, the rationale, the security impact, the licence required, and — critically — how to audit it and how to remediate it, usually with both portal and PowerShell steps.

It is prescriptive in the way BRCGS is prescriptive for food safety: not "secure your identity" but "this specific setting, at this specific value, verified this specific way." That prescriptiveness is what makes it auditable, and what makes the resulting evidence binder meaningful to third parties.

The two axes, and why they get confused

The CIS Microsoft 365 Foundations Benchmark is structured by E3 and E5 licence profiles at Level 1 and Level 2, while Implementation Groups IG1 to IG3 come from the CIS Critical Security Controls and are cross-mapped to it.
Two structures doing different jobs. Profiles and levels are the benchmark's own organisation; Implementation Groups belong to the CIS Critical Security Controls and are mapped onto benchmark recommendations.

The benchmark's own structure is profiles and levels. Recommendations are organised into four profiles, each scoped to a licence tier and a rigour level:

  • E3 Level 1 — the prudent baseline for an E3 tenant. Clear security benefit, minimal impact on the utility of the technology.
  • E3 Level 2 — defence in depth for environments where security is paramount, accepting that some controls may inhibit utility or performance.
  • E5 Level 1 — extends E3 Level 1 with recommendations that require E5-licensed capability.
  • E5 Level 2 — the highest assurance profile across the full E5 estate.

Every recommendation also states which licence provides the underlying capability (E3, E5, F1, F3), which is why the benchmark doubles as a licensing lens — more on that below.

Implementation Groups are a different framework entirely. IG1, IG2 and IG3 come from the CIS Critical Security Controls, CIS's cross-platform prioritisation model, and are cross-mapped onto benchmark recommendations rather than being the benchmark's own structure. They answer a different question: not "how rigorous is this control?" but "what maturity of organisation should be doing it?"

  • IG1 — essential cyber hygiene. The must-do baseline for every organisation: MFA, Conditional Access fundamentals, audit logging, secure email configuration, administrative account hygiene. IG1 counters the commodity attacks that make up the overwhelming majority of real-world compromises. A fully implemented IG1 defeats most of what actually comes through the door.
  • IG2 — intermediate. For organisations handling sensitive data or facing adversaries more capable than commodity crime: advanced monitoring and alerting, granular data-loss prevention, stronger device management, structured incident response. The right target for most mid-market and regulated organisations.
  • IG3 — advanced. For regulated, high-value or high-threat organisations assuming a sophisticated, persistent adversary: mature SOC operations, extensive logging and retention, penetration-test readiness.

The groups are cumulative — IG2 contains IG1, IG3 contains both — and the point of them is proportionality. A thirty-person distributor implementing IG3 controls is spending effort it should have put into completing IG1; a bank stopping at IG1 is under-protected for its threat model.

Why the distinction matters in practice

Because they answer different questions, using only one of them produces a worse assessment.

Assessing purely by profile tells you how far your tenant is from the benchmark at your licence tier, but says nothing about which gaps are urgent. A Level 1 recommendation about a niche setting and a Level 1 recommendation about MFA carry the same weight in a raw conformance percentage, which is how organisations end up closing forty easy findings and leaving the four that matter.

Assessing purely by Implementation Group tells you what a mature organisation of your type should be doing, but not whether your licences can deliver it, nor how to audit and evidence each control.

Used together they produce the two outputs a decision-maker actually needs: "at our licence profile we are 84% conformant" and "of the sixteen open gaps, nine are IG1." The second sentence is the one that gets funded.

The licensing lens

Because every recommendation names the licence that provides the capability, mapping your target maturity against your current entitlements shows precisely where a capability gap forces either a licence decision or a documented accepted risk. Many IG1 controls are achievable at Business Premium and even at the free tier — MFA, Conditional Access basics, audit logging. IG2 and especially IG3 increasingly rely on E5-tier capability: advanced DLP, longer log retention, Defender XDR, Sentinel-based monitoring.

Note that this map moved in 2026. The July 2026 packaging update pushed Defender for Office 365 P1, Intune Plan 2 and (in E5) Endpoint Privilege Management down into suites that did not previously carry them, so some recommendations that were previously out of reach at E3 are now in scope at no extra cost. Re-run the licence mapping after the rollout reaches your tenant rather than relying on an assessment from 2025.

Running an assessment without drowning

  • Assess against the full benchmark at your profile, but report by Implementation Group. A hundred-row spreadsheet is noise; "IG1: 84% conformant, these nine gaps" is a decision.
  • Fix IG1 gaps first, always, regardless of your eventual target. They are the highest-value, usually lowest-cost controls, and leaving them open while pursuing IG2 controls is common and backwards.
  • Record a rationale for every Level 2 recommendation you decline. Level 2 controls are explicitly allowed to affect utility; declining one is a legitimate risk decision, but an undocumented decline is indistinguishable from an oversight when an auditor reads it.
  • Produce the evidence binder as you go. The reason to use CIS over ad-hoc hardening is defensible evidence: each recommendation, its status, the configuration proving it, dated. This is the artefact that satisfies auditors and customers, and it mirrors the audit-ready discipline QG applies across every practice.
  • Re-assess on a cycle. Tenants drift, CIS versions the benchmark as Microsoft ships features, and last year's conformance is not this year's. Confirm you are working from the current benchmark version before you start — assessing against a superseded version is a finding waiting to happen.

Practical steps

Decide your target Implementation Group from your data sensitivity and threat model: most organisations land at IG1-complete moving toward IG2. Confirm which benchmark profile applies to your licences. Assess against the full benchmark, then sort the gaps by IG and close IG1 entirely before anything else. QG runs end-to-end CIS Microsoft 365 assessment and remediation against 100+ controls, reported by both profile and Implementation Group, producing the audit-ready evidence binder and a Secure Score uplift measured at each stage.

Have a question we can answer?

Book a short discovery call to talk through your current systems, sector and target standards. We'll come back with clear, practical next steps.