Back to all posts
    Microsoft 365
    Compliance
    MSP

    CISA Just Gave MSPs a Microsoft 365 Blueprint

    ThreatMate Team
    Sep 25, 2024
    5 min read
    CISA Just Gave MSPs a Microsoft 365 Blueprint

    What is ScubaGear?

    The Cybersecurity and Infrastructure Security Agency (CISA) has published a hardening baseline for Microsoft 365 called ScubaGear.

    It's not a whitepaper or a conceptual checklist. ScubaGear is a tactical set of configuration checks designed to help organizations secure Microsoft 365 tenants against real threats.

    Why CISA's Voice Matters

    CISA is the U.S. federal agency tasked with protecting national infrastructure from cyber threats. They created Shields Up, KEV alerts, and other trusted frameworks.

    CISA does not sell licenses or products. Their guidance is threat-informed and purpose-built to reduce risk. For MSPs, this makes ScubaGear a rare tool — one that provides external validation and a defensible baseline.

    Why Secure Score Isn't Enough

    Microsoft's Secure Score is widely known but inherently limited. It attempts to balance security with usability, licensing tiers, and product promotion.

    ScubaGear flips that lens. It assumes the tenant is a target and applies a security-first posture. Its assessments are pass or fail — not partial credit.

    How to Use ScubaGear

    1. Read the Baseline. Explore the ScubaGear GitHub repository to view the full list of configuration controls.
    2. Run the Assessment. Use CISA's official PowerShell script to assess a tenant.
    3. Review the Score and Findings. Focus on the failed controls — these are real, actionable risks.
    4. Educate Clients. Use the results as part of onboarding, QBRs, or monthly service reporting.

    Next Steps

    That's where solutions like ThreatMate step in. We help MSPs automate ScubaGear assessments, monitor configuration changes over time, and provide a centralized view across all clients.

    Ready to secure your attack surface?

    See how ThreatMate helps MSPs identify and remediate vulnerabilities across their client base.