TENOVIA
Book a demo

Configuration audit · CIS Benchmarks

Audit Microsoft 365 and Google Workspace without running a single script.

Tenovia compares the actual configuration of your environments with the CIS Benchmarks, read-only, through direct calls to the administration APIs. You get a time-stamped finding, traceable evidence and a prioritised remediation plan.

Read-only collection No script to run SaaS or dedicated instance

Coverage

Every CIS recommendation, and how it is verified

Two public frameworks, 249 recommendations, 821 pages of recommendations. Here is what Tenovia verifies on each platform, and by what means.

Microsoft 365

Benchmark v7.0.0

160 recommendations · 580 pages read for you

160 of 160 covered

143 verified automatically
17 declared manual by CIS

CIS itself declares 17 of its recommendations non-automatable. No tool covers them programmatically. Tenovia puts them as precise questions and folds them into the same report: you get all 160, not 143 and a gap.

See Microsoft 365 coverage

Google Workspace

Benchmark v1.3.0

89 recommendations · 241 pages read for you

89 of 89 covered

79 verified automatically
10 not exposed by any API

CIS declares all 89 of its recommendations manual, without exception: the official framework holds that auditing Google Workspace is done by hand, screen by screen. Tenovia collects 79 of them automatically through the Cloud Identity Policy API, read-only. The remaining 10 are exposed by no interface; they are put as precise questions and folded into the same report: you get all 89, not 79 and a gap.

See Google Workspace coverage
160
Microsoft 365 recommendations
580
pages read for you
89
Google Workspace recommendations
241
pages read for you

Platform

A configuration audit, not a self-assessment questionnaire

Data is read at source, assessed by written rules, and reported together with its evidence. Nothing is declared, everything is observed.

Collection

Direct API reads

Microsoft Graph and the Exchange and Teams administration APIs are queried read-only from an application registered in the tenant. No action on endpoints.

Assessment

Explicit rule engine

Every collected line is matched against a readable, versioned and replayable rule. The verdict is reproducible from one audit to the next.

Evidence

End-to-end traceability

Object, property, value, collection date: every finding retains the raw data behind it. An external auditor can retrace the path.

Reporting

Report and remediation plan

Gaps ranked by severity, effort and gain, with the original wording of the CIS control and the expected correction.

Follow-up

Comparison between two runs

The second audit reads as a difference: what has been fixed, what has regressed, what has not moved.

Deployment

Shared or dedicated instance

Shared console, or deployment on your own infrastructure where your policy forbids configuration data leaving your estate.

Method

Four steps, from permissions to report

Your technical teams are only involved in the first step.

01

Permissions

Registration of a read-only application in the tenant and admin consent.

02

Collection

Automated API queries. Raw data is normalised into a single format and time-stamped.

03

Assessment

Compliance rules are applied, domain scores computed and gaps identified.

04

Reporting

Audit report, supporting evidence and prioritised remediation plan, presented in session.

Audited scopes

Microsoft 365 and Google Workspace, one core

Two environments, one console, one evidence format.

Available

CIS Microsoft 365 audit

Based on the CIS Microsoft 365 Foundations Benchmark v7.0.0 of 20 May 2026.

  • Identity and access: privileged accounts, roles, authentication methods, conditional access
  • Exchange Online: transport rules, anti-phishing protection, logging
  • SharePoint and OneDrive: external sharing, anonymous links, retention
  • Teams: meeting policies, guest access, federation
  • Defender and Purview: security policies, unified audit log, data loss prevention

See Microsoft 365 coverage

Available

CIS Google Workspace audit

Based on the CIS Google Workspace Foundations Benchmark v1.3.0, which contains 89 recommendations, 73 at level 1 and 16 at level 2. CIS declares every one of them manual: Tenovia collects them through the Cloud Identity Policy API, read-only.

  • Accounts and authentication: two-step verification, security keys, sessions
  • Gmail: sender authentication, attachments, phishing
  • Drive and Docs: external sharing, link visibility, ownership transfer
  • Third-party applications: OAuth access, control of unverified apps
  • Logging: retention and export of audit logs

See Google Workspace coverage

Regulatory mapping

Your configuration gaps feed your obligations

A technical finding is only worth something if it maps to a requirement. Every gap is tied back to the framework that demands it, together with the original wording of the control.

NIS2

NIS2 Directive

The baseline measures expected under article 21 cover access management, security policy and configuration control. A CIS audit documents the actual state of those measures across messaging and collaboration, with a defensible finding date.

DORA

DORA Regulation

For financial entities and their providers, ICT risk management requires knowing and controlling system configuration. The report provides the time-stamped technical evidence that supervisors expect.

ISO 27001

ISO/IEC 27001

Annex A covers privileged access, logging and cloud service security among others. CIS findings feed directly into the evidence presented to your certification auditor.

GDPR

GDPR, article 32

Security of processing requires appropriate technical measures. External sharing, anonymous links, retention and guest access are configuration points that directly condition that compliance.

ANSSI hygiene guidance and sector frameworks are handled on the same principle. Tenovia produces technical evidence: compliance remains yours to steer, and the report is not an attestation.

Frequently asked questions

CIS audit for Microsoft 365 and Google Workspace

What is a CIS Microsoft 365 audit?

It is the comparison of the actual configuration of a Microsoft 365 tenant with the recommendations of the CIS Microsoft 365 Foundations Benchmark, a public hardening framework published by the Center for Internet Security. The audit does not judge usage, it observes settings.

Do you need to run a PowerShell script on the tenant?

No. Tenovia queries the Microsoft APIs directly in read-only mode from an application registered in the tenant. No script is sent, run or maintained by your teams, which removes the main source of friction and risk in conventional audits.

What permissions are required?

Read permissions only, on Microsoft Graph and on the relevant administration APIs. No write permission is requested. The exact list is provided before onboarding and can be reviewed by your security team.

Does a CIS audit help with NIS2 or ISO 27001 compliance?

Yes. CIS hardening measures provide technical evidence that can be used directly to demonstrate control of the baseline hygiene expected by NIS2 and by Annex A of ISO/IEC 27001. The report indicates the mapping for each finding.

Is Google Workspace covered?

Yes, on the same footing as Microsoft 365. The CIS Google Workspace Foundations Benchmark v1.3.0 contains 89 recommendations, every one of which the Center for Internet Security declares manual. Tenovia collects them automatically through the Cloud Identity Policy API, read-only, and reports them in the same document as Microsoft 365.

See what your configuration actually says.

A demo on a test environment, or a pilot audit on your own tenant. Judge on the report, not on the promise.