logo

CISA orders federal agencies to secure Microsoft 365 tenants

ID: 6daa9588-53cf-5301-9dca-284dbfc26047

STIX ID: report--6daa9588-53cf-5301-9dca-284dbfc26047

Feed Name: Bleeping Computer

Date Published: 2024-12-17

Date Updated: 2026-03-27

Author: Sergiu Gatlan

...
...

CISA issued Binding Operational Directive 25-01 mandating Federal Civilian Executive Branch agencies to harden cloud environments by identifying in-scope tenants by February 21, 2025, deploying SCuBA assessment tools (e.g., ScubaGear for Microsoft 365) and beginning continuous reporting by April 25, 2025, and implementing mandatory SCuBA policies by June 20, 2025, with ongoing updates and secure configuration baselines required before ATOs. Initial baselines cover Microsoft 365 (Entra ID/Azure AD, Defender, Exchange Online, Power Platform, SharePoint/OneDrive, Teams), with Google Workspace baselines anticipated in FY25 Q2, and CISA encourages all organizations to adopt these practices to reduce cloud attack surface.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.