S6E14 - Securing M365 with ScubaGear: A Deep Dive into CISA’s Assessment Tool
Let's Talk Azure!30 Touko 2025

S6E14 - Securing M365 with ScubaGear: A Deep Dive into CISA’s Assessment Tool

In this episode, we dive deep into ScubaGear, an open-source tool developed by the Cybersecurity and Infrastructure Security Agency (CISA) as part of the Secure Cloud Business Applications (SCuBA) project. Designed to assess Microsoft 365 (M365) tenant configurations, ScubaGear helps organizations align with CISA’s Secure Configuration Baselines (SCBs) to prevent costly misconfigurations. From setup to real-world applications, we unpack how ScubaGear strengthens M365 security and share practical tips for IT admins and security teams. What You’ll Learn:

  • Why ScubaGear Matters: Learn how ScubaGear addresses the growing threat of cloud misconfigurations, which accounted for 30% of cloud attacks in early 2024. We discuss its origins in CISA’s SCuBA project, and its value for US federal agencies, private organizations, and critical infrastructure.
  • How ScubaGear Works: A technical breakdown of ScubaGear’s PowerShell-based workflow, using Microsoft Graph APIs and Open Policy Agent (OPA) to compare tenant settings against SCBs. We cover setup requirements.
  • Common Misconfigurations: Examples like disabled MFA or weak DLP policies, and how ScubaGear’s HTML, JSON, and CSV reports provide actionable remediation steps.
  • Best Practices: Tips for integrating ScubaGear into security workflows, including regular scans, policy customization, and combining with tools like Microsoft Secure Score.
  • Real-World Insights: Sam shares experiences from consulting.

What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.

Read transcript

Jaksot(156)

S5E39 - Navigating DevOps Security Challenges with Microsoft Defender for Cloud

S5E39 - Navigating DevOps Security Challenges with Microsoft Defender for Cloud

In this episode, we tackle the critical challenges of securing DevOps environments in today’s fast-paced, cloud-centric landscape. With cyber threats evolving at an unprecedented rate, safeguarding yo...

15 Marras 202441min

S5E38 - Microsoft updates October - new products and features released

S5E38 - Microsoft updates October - new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

8 Marras 202434min

S5E37 - Monitor and secure OAuth applications using App Governance

S5E37 - Monitor and secure OAuth applications using App Governance

This week Alan and Sam discuss OAuth applications and their potential risks. Alan goes into how App Governance can give you the visibility of OAuth app and their usage. Here are a few things we covere...

25 Loka 202436min

S5E36 - Mastering Azure Web Jobs: Automating Tasks in the Cloud

S5E36 - Mastering Azure Web Jobs: Automating Tasks in the Cloud

This week Alan and Sam discuss Azure Web Jobs which is a feature of Azure App Service that allows developers to run background tasks, scripts, and long-running processes alongside their web applicatio...

11 Loka 202436min

S5E35 - Microsoft updates September - new products and features released

S5E35 - Microsoft updates September - new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

4 Loka 202439min

S5E34 - Secure Your Tokens: Defend Against Theft and Replay Attacks

S5E34 - Secure Your Tokens: Defend Against Theft and Replay Attacks

In this episode, Sam and Alan dive deep into the world of token theft and token replay attacks. They explore what these threats are and discuss effective countermeasures to reduce the risk of token th...

20 Syys 202437min

S5E33 - Azure VM Image Builder - A managed Azure service to handle VM image building

S5E33 - Azure VM Image Builder - A managed Azure service to handle VM image building

This week Alan and Sam discuss Azure VM Image Builder which is a service that simplifies the creation, customisation, and management of virtual machine images in Azure, automating tasks like software ...

13 Syys 202441min

S5E32 - Microsoft updates August- new products and features released

S5E32 - Microsoft updates August- new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

6 Syys 202438min