Back
🔒
Office 365 ProPlus STIG Implementation Checklist (Ver 3, Rel 7)
Hard
16 items
·
4 hours
testuser
Published 3 months ago
This checklist helps IT and security teams implement the Microsoft Office 365 ProPlus STIG (Ver 3, Rel 7). Use it to gather DISA resources, apply GPO and Intune controls, run automated scans, remediate findings, and document changes for ongoing compliance. It’s designed for administrators managing Office 365 ProPlus on endpoints in a managed environment.
Progress
0 / 16
- Gather STIG resources from DISA — Collect STIG document, SCAP/XCCDF files, GPO packages, and Intune policies.
- Download SCAP 1.3 content — Grab the SCAP benchmark content for automated assessments.
- Download Standalone XCCDF 1.1.4 — Obtain the XCCDF checklist for manual or tool-based checks.
- Download Intune policies (latest) — Retrieve the published Intune policy package for Office 365 ProPlus.
- Download GPO package for Office 365 ProPlus — Save the Group Policy Objects distributed by DISA for deployment.
- Review the STIG document and checklist details — Read requirements, scope, exceptions, and change history before implementing.
- Identify target systems running Office 365 ProPlus — List endpoints, user groups, and managed device types in scope.
- Inventory current Office configurations and versions — Record build numbers, update channels, and installed Office components.
- Map STIG requirements to existing controls — Determine which controls are already implemented and identify gaps.
- Import SCAP/XCCDF content into assessment tools — Load benchmark content into your scanner or compliance tool.
- Run automated STIG scan and review results — Execute scans, export findings, and prioritize by risk level.
- Apply GPOs to managed devices — Import and link DISA GPOs to appropriate OUs in your AD environment.
- Deploy Intune policies to managed endpoints — Publish and assign Intune configurations to device groups.
- Remediate high-risk findings — Apply fixes, config changes, or compensating controls for critical items.
- Document configuration changes and approvals — Record what changed, why, and who approved it for audit purposes.
- Schedule recurring reviews and update STIG resources — Plan periodic reassessments and refresh DISA resources as they update.
Your Stats
🏆
0
Completed
📅
—
Last Done
⏱️
—
Last Time
Completion Rate
Items checked per run
⚡
—
Fastest Run
🔥
0
Streak
🚫
—
Most Skipped Step
🔄
0
Resets
📝 My Notes