The 283 controls explained: CIS, ANSSI, NIST and ISO 27001
A security control only means something when it is tied to a recognised framework. EntraGUARD runs 283 automated controls across nine Microsoft referentials, each mapped to established standards. Here is what that coverage looks like and why it matters.
Why framework alignment matters
Anyone can invent a checklist. What makes an audit defensible — in front of a board, a cyber insurer, or an ISO assessor — is that every control traces back to an authoritative source. EntraGUARD aligns its controls with four widely recognised frameworks so that each finding carries a reference you can justify.
The four frameworks
CIS Microsoft 365 & Azure Benchmarks
The Center for Internet Security publishes consensus-based hardening benchmarks for Microsoft 365 and Azure. They are prescriptive and practical — exact settings, recommended values, level 1 (essential) and level 2 (defence-in-depth) tiers. They form the backbone of EntraGUARD's control set.
ANSSI recommendations
The French national cybersecurity agency publishes hardening guides for Active Directory and Microsoft environments that are especially strong on on-premises and hybrid identity. They inform many of the AD-focused controls.
NIST
NIST's cybersecurity guidance (including SP 800-53 and the Cybersecurity Framework) provides the control-family structure that helps map technical findings to governance categories — useful when reporting to risk and compliance functions.
ISO/IEC 27001
The international standard for information security management. Mapping controls to ISO 27001 annex A helps organisations pursuing or maintaining certification show concrete technical evidence behind their ISMS.
Coverage across nine referentials
The 283 controls are distributed across nine Microsoft referentials:
| Referential | Example controls |
|---|---|
| Entra ID | Conditional access, MFA, legacy auth, privileged roles |
| Active Directory | Privileged groups, delegation, password policy, Kerberos |
| Azure | RBAC, network exposure, Defender for Cloud, key vaults |
| Exchange Online | Mail flow, external forwarding, authentication |
| SharePoint | External sharing, access controls |
| Teams | Guest access, meeting and messaging policy |
| OneDrive | Sharing, sync restrictions |
| Defender | Threat policies, safe attachments/links |
| Purview | Retention, audit, data governance |
More than three times Secure Score depth
Microsoft Secure Score covers roughly eighty checks. At 283 controls across nine referentials, EntraGUARD goes more than three times deeper — and crucially, it covers on-premises Active Directory, which Secure Score does not touch at all.
Every finding is traceable
Each control in a report cites its framework reference and, where relevant, a link to Microsoft documentation. That traceability is what turns a scan into an audit: you can explain, line by line, why a setting matters and where the recommendation comes from.
Takeaway. Framework alignment is not a marketing checkbox — it is what lets you defend a compliance score to an auditor, an insurer or your executive committee.
Audit your Microsoft environment
Put this into practice. EntraGUARD runs 283 automated controls across Entra ID, Active Directory and Azure — try the free demo.
Download the free demo