CMMC Level 2 Safe Links and Safe Attachments Baseline
A single email click can undo months of compliance work. When I review Microsoft 365 tenants for CMMC Level 2, I often find email protection half-set, poorly scoped, or hard…
A single email click can undo months of compliance work. When I review Microsoft 365 tenants for CMMC Level 2, I often find email protection half-set, poorly scoped, or hard…
Secure Score can pull a team into point chasing when what it needs is proof. I’ve seen Microsoft 365 admins raise the number, feel better for a week, and still…
External collaboration is often the quietest hole in a CMMC boundary. A tenant-to-tenant trust that looks harmless can let weak identity assumptions cross into your environment. When I review Microsoft…
A generic tabletop won’t help me in a CMMC assessment or during a real Microsoft 365 incident. It also won’t help when an Entra ID admin starts approving MFA prompts…
Access control usually breaks in ordinary moments, new hires, rushed admin requests, outside contractors, and projects that never get cleaned up. When I review CMMC Level 2 gaps, those are…
A Power App can go from harmless helper to audit problem in a week. I see it happen when a team builds a quick form, connects it to live business…
One open federation setting can weaken an otherwise solid CMMC boundary. I’ve seen Microsoft Teams become an untracked side door because nobody wrote down who could talk to whom, under…
One weak sync server can open a path through an otherwise solid CMMC Level 2 program. When I review hybrid identity in regulated environments, I treat Microsoft Entra Connect as…
When I review a Microsoft 365 tenant before a CMMC readiness effort, stale devices jump out fast. They fill reports with ghosts, blur asset counts, and make old access paths…
When I assess Microsoft 365 for CMMC Level 2 OAuth risk, OAuth apps are one of the first places I look. A tenant can have strong MFA, good mail hygiene,…