> For the complete documentation index, see [llms.txt](https://helpdesk.augmentt.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://helpdesk.augmentt.com/modules/secure/security-posture/posture-templates/default-posture-templates.md).

# Default Posture Templates

This is the follow-up promised on the [Posture Templates](/modules/secure/security-posture/posture-templates.md) page: the full list of Augmentt's built-in **Default templates**, what each one bundles, and which compliance framework or assessment it lines up with.

{% hint style="warning" %}
**Correction to the original overview.** The first-pass page said Default templates include "one aligned to the Augmentt Quick Baseline assessment," which reads as if Quick Baseline were the only one. It isn't. Augmentt ships **12 default templates** — four general-purpose templates that predate the framework-aligned line, the Quick Baseline template, and seven templates aligned to named security frameworks (CIS Microsoft 365 v6 and v7, at both Level 1 and Level 2, NIST CSF 2.0, HIPAA Security Rule, and CMMC Level 1).
{% endhint %}

## How to read this page

For each template below:

* **Framework/assessment alignment** — the Compliance Audit assessment (if any) the template's settings correspond to.
* **Bundled settings** — the checks and target values the template writes when applied. Where a template carries a small, stable number of settings, every one is listed with its exact target value. Where a template has accumulated many settings over time (notably the two CIS M365 V6 templates, which several dozen follow-up changes have added to since launch), it's summarized by category with representative examples rather than reproduced check-by-check — call support or open the template in-product for the authoritative current list.

{% hint style="info" %}
Target values are written exactly as they appear in the underlying settings data, which is why some read as UI labels ("Enabled" / "Never expires") rather than plain English.
{% endhint %}

## Quick Baseline

**Template name:** Augmentt Quick Baseline **Aligned to:** the **Augmentt Quick Baseline** assessment (a lightweight assessment Augmentt defines and maintains, not a third-party framework)

Quick Baseline is positioned as the on-ramp: a small set of high-impact, low-friction controls for customers who aren't ready to commit to a full compliance standard. Every check in it is available on Microsoft 365 Business Basic/Standard licensing.

{% hint style="info" %}
Quick Baseline is also available as a dedicated one-click "Apply Baseline" action in Protect, separate from picking a template off the template list — but it applies the same settings as the Augmentt Quick Baseline template described here.
{% endhint %}

Bundled settings (15):

| Check                                       | Setting                                    | Target value                                                                                                  |
| ------------------------------------------- | ------------------------------------------ | ------------------------------------------------------------------------------------------------------------- |
| Microsoft Authenticator MFA                 | Microsoft Authenticator                    | Enabled                                                                                                       |
| Microsoft Authenticator MFA                 | Number Matching                            | Enabled                                                                                                       |
| MFA push context (EIDSCA.AM06)              | Show Application Name                      | Enabled                                                                                                       |
| MFA push context (EIDSCA.AM09)              | Show Geographic Location                   | Enabled                                                                                                       |
| Temporary Access Pass                       | Temporary Access Pass                      | Enabled                                                                                                       |
| Exchange calendar sharing (CISA.MS.EXO.6.2) | Default Sharing Policy                     | Disabled                                                                                                      |
| Exchange/Outlook modern auth                | Modern Authentication for Exchange/Outlook | Enabled                                                                                                       |
| Password expiration (CISA.MS.AAD.6.1)       | Passwords should not expire                | Never expires                                                                                                 |
| Direct Send                                 | Block Direct Send in Exchange Online       | Blocked                                                                                                       |
| SMTP AUTH (CISA.MS.EXO.5.1)                 | SMTP AUTH                                  | Disabled                                                                                                      |
| Unified Audit Log                           | Unified Audit Log                          | On                                                                                                            |
| Mailbox auditing                            | Mailbox Auditing (organization level)      | Enabled                                                                                                       |
| App consent                                 | Disable User Application Consent           | On                                                                                                            |
| Guest user access                           | Guest user access                          | Guests can't see membership of any groups                                                                     |
| Guest invite settings                       | Guest user invite settings                 | Allow members of Global Administrators, User Administrators, and Guest Inviter roles to invite external users |

The matching **Augmentt Quick Baseline assessment** (what Compliance Audit measures against) covers 19 checks — the 15 above plus four read-only/reporting checks that aren't deployable from the template: inactive accounts, blocked sign-in for shared mailboxes, non-admin PowerShell access, and legacy authentication blocking.

## Framework-aligned templates

### CIS M365 V6 (L1)

**Aligned to:** CIS Microsoft 365 Benchmark v6, Level 1

Launched with 10 settings (DKIM, Unified Audit Log, Exchange modern auth, mailbox auditing, external mail tagging, Authenticator + number matching MFA, MFA push app-name/geo display, and guest group visibility) and has had roughly 30 more settings added to it since, one or two at a time, as the CIS v6 assessment grew. Confirmed additions include, by category:

* **Identity/MFA:** password non-expiration, banned-password-list enforcement, system-preferred MFA, per-user MFA disabled (in favor of Conditional Access), weak authentication methods disabled, admin-consent workflow (request/notify/expire-after-30-days), managed-device requirement for auth (MT.1001), forced password reset on high user risk (MT.1013), sign-in frequency limits for admin roles, restriction on who can create security groups.
* **SharePoint/OneDrive:** modern auth required, Azure AD B2B integration enabled.
* **Email/anti-spam:** MailTips recommended values, internal phishing protection in Forms, connection filter safe list cleared, connection filter IP allow list cleared, inbound anti-spam allowed domains cleared, outbound anti-spam limits (external recipient limit 500, internal recipient limit 1000, daily recipient limit 1000, threshold action BlockUser).
* **App governance:** Office Store access disabled, org trial sign-up disabled, user-owned apps and services restricted.

{% hint style="warning" %}
The list above is what's confirmed from the seed/migration history, not necessarily the complete current template — CIS M365 V6 (L1) is the most actively maintained template and settings continue to be added as the CIS v6 assessment is refined.
{% endhint %}

### CIS M365 V6 (L2)

**Aligned to:** CIS Microsoft 365 Benchmark v6, Level 2

Builds on the L1 control set with the more disruptive, advanced-tier settings. Confirmed settings (18):

DKIM (Enabled), Unified Audit Log (On), Exchange modern auth (Enabled), mailbox auditing (Enabled), external mail tagging (Enabled), Authenticator + number matching MFA (Enabled), MFA push app-name/geo display (Enabled), guest group visibility ("Guests can't see membership of any groups"), app consent disabled (On), guest invite settings restricted to admin/inviter roles, external resharing disabled, activity-based idle session timeout enabled at 3 hours, Direct Send blocked, Customer Lockbox enabled, and infected-file download disallowed in SharePoint.

{% hint style="info" %}
Two settings passed through the template's history without landing: Application Enforced Restrictions for Unmanaged Devices (MT.1019) and Comprehensive Attachment Filtering were each added in one migration and removed in a later one — neither is part of the current template.
{% endhint %}

### CIS M365 V7 (L1)

**Aligned to:** CIS Microsoft 365 Benchmark v7.0.0, Level 1

A purpose-built template for the v7 assessment (not just a copy of the v6 template), restricted to the checks the v7 Level 1 profile actually measures. All 24 settings, confirmed complete:

DKIM (Enabled) · Unified Audit Log (On) · Exchange/Outlook modern auth (Enabled) · mailbox auditing (Enabled) · external mail tagging (Enabled) · Authenticator MFA (Enabled) · number matching (Enabled) · MFA push app-name display (Enabled) · MFA push geo display (Enabled) · passwords should not expire (Never expires) · admin consent requests (Enabled) · reviewer email notifications (Enabled) · reviewer expiration reminders (Enabled) · consent request expiry (30 days) · managed-device requirement for auth (Enabled) · forced reset on high user risk (Enabled) · admin-role sign-in frequency / non-persistent sessions (Enabled) · banned password list enforced (Enabled) · SMTP AUTH (Disabled) · weak authentication methods (Disabled) · SharePoint modern auth required (Enabled) · system-preferred MFA (Enabled) · restriction on who can create security groups (No) · per-user MFA state (Disabled).

### CIS M365 V7 (L2)

**Aligned to:** CIS Microsoft 365 Benchmark v7.0.0, Level 2

All 15 settings, confirmed complete: DKIM (Enabled) · Unified Audit Log (On) · Exchange/Outlook modern auth (Enabled) · mailbox auditing (Enabled) · external mail tagging (Enabled) · Authenticator MFA (Enabled) · number matching (Enabled) · MFA push app-name display (Enabled) · MFA push geo display (Enabled) · app consent disabled (On) · external resharing disabled · activity-based timeout enabled, idle session timeout 3 hours · Direct Send blocked · Customer Lockbox enabled.

### NIST CSF 2.0

**Aligned to:** NIST Cybersecurity Framework 2.0

Covers the deployable subset of the NIST CSF 2.0 assessment — outcomes that depend on process, policy, or per-user/Conditional Access configuration are tracked by the assessment but not written by this template. All 16 settings, confirmed complete:

Authenticator MFA (Enabled) · number matching (Enabled) · Temporary Access Pass (Enabled) · Exchange/Outlook modern auth (Enabled) · SharePoint modern auth required (Enabled) · app consent disabled (On) · guest group visibility restricted · guest invite settings restricted to admin/inviter roles · external resharing disabled · activity-based timeout enabled, idle session timeout 3 hours · DKIM (Enabled) · external mail tagging (Enabled) · Direct Send blocked · Unified Audit Log (On) · mailbox auditing (Enabled) · deleted user's OneDrive retained for 1 year.

### HIPAA Security Rule

**Aligned to:** the HIPAA Security Rule assessment (technical and administrative safeguards)

Same "deployable subset" scoping as NIST CSF 2.0 above. All 15 settings, confirmed complete:

Authenticator MFA (Enabled) · number matching (Enabled) · Temporary Access Pass (Enabled) · activity-based timeout enabled, idle session timeout 3 hours · Unified Audit Log (On) · mailbox auditing (Enabled) · app consent disabled (On) · guest group visibility restricted · guest invite settings restricted to admin/inviter roles · external resharing disabled · Exchange/Outlook modern auth (Enabled) · SharePoint modern auth required (Enabled) · DKIM (Enabled) · Direct Send blocked.

### CMMC Level 1

**Aligned to:** CMMC 2.0 Level 1 practices (FAR 52.204-21)

All 10 settings, confirmed complete: Authenticator MFA (Enabled) · number matching (Enabled) · app consent disabled (On) · SharePoint site creation restricted to admins (Enabled) · guest group visibility restricted · guest invite settings restricted to admin/inviter roles · external resharing disabled · DKIM (Enabled) · external mail tagging (Enabled) · Direct Send blocked.

{% hint style="info" %}
There's a CMMC Level 2 assessment in Compliance Audit, but no CMMC Level 2 posture template exists yet — Level 2 has more practices that depend on process/policy rather than a deployable M365 setting, which is likely why a template hasn't been built for it.
{% endhint %}

## The four original templates

These predate the framework-aligned templates above and aren't tied to any named compliance framework or assessment — they're still shipped and still maintained (new checks that get added to the CIS/Enable-All settings pool get backfilled into these too), so they remain valid choices, just framework-agnostic ones:

* **Enable All Settings** — the union of every check in the two categories below (external mail forwarding control, external mail tagging, DKIM, deleted-user OneDrive retention, Authenticator + number matching MFA, MFA push app-name/geo display, Safe Attachments, Temporary Access Pass, activity-based session timeout, Unified Audit Log, mailbox auditing, app consent, external resharing, SharePoint site creation restriction, Exchange modern auth, and guest access/invite settings).
* **Enable Logging** — just the two logging checks: Unified Audit Log and mailbox auditing.
* **Access Management** — just the access-control checks: app consent, external resharing, SharePoint site creation restriction, Exchange modern auth, and guest access/invite settings.
* **Logging & Access Management** — the union of the two templates above.

{% hint style="warning" %}
Unlike the newer templates, the guest-access target value in these four original templates is the *permissive* default ("Guests can see membership of all non-hidden groups") rather than the locked-down value the CIS/NIST/HIPAA/CMMC templates use ("Guests can't see membership of any groups"). Applying "Enable All Settings" is not equivalent to applying a framework template — check the target value before assuming it tightens a setting.
{% endhint %}

## What's still not covered here

This page documents what each default template *sets*. It doesn't yet cover:

* The full, current check list for CIS M365 V6 (L1) and (L2) — those templates keep growing; treat the categorized summary above as directional, not exhaustive.
* The Compliance Audit assessments themselves in full (CIS M365 v6/v7, NIST CSF 2.0, HIPAA, CMMC L1/L2 also include checks that are reporting-only and never written by any template).
* Walkthroughs for building or customizing a template — see the main [Posture Templates](/modules/secure/security-posture/posture-templates.md) page for that.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://helpdesk.augmentt.com/modules/secure/security-posture/posture-templates/default-posture-templates.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
