{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/turn-cisa-scubagear-into-a-governed-microsoft-365-drift-assessment/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/turn-cisa-scubagear-into-a-governed-microsoft-365-drift-assessment/",
        "slug": "turn-cisa-scubagear-into-a-governed-microsoft-365-drift-assessment",
        "url": "https://update.dsesecurity.com/updates/turn-cisa-scubagear-into-a-governed-microsoft-365-drift-assessment/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/turn-cisa-scubagear-into-a-governed-microsoft-365-drift-assessment.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/turn-cisa-scubagear-into-a-governed-microsoft-365-drift-assessment/"
        },
        "title": "Turn CISA ScubaGear into a governed Microsoft 365 drift assessment",
        "summary": "ScubaGear can compare Microsoft 365 configuration with CISA's SCuBA baselines. A defensible program also controls permissions, versions, configuration, exceptions, evidence, remediation, reruns, and drift interpretation.",
        "format": {
            "slug": "playbook",
            "name": "Playbook"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "A cloud security baseline assessment moving from scan evidence through governed remediation.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/posts/turn-cisa-scubagear-into-a-governed-microsoft-365-drift-assessment-card.webp?v=1.8.2",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/posts/turn-cisa-scubagear-into-a-governed-microsoft-365-drift-assessment-hero.webp?v=1.8.2",
            "social_url": "https://update.dsesecurity.com/assets/editorial/posts/turn-cisa-scubagear-into-a-governed-microsoft-365-drift-assessment-social.jpg?v=1.8.2",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-04T22:53:02+00:00",
        "modified_at": "2026-08-04T22:53:02+00:00",
        "reviewed_on": "2026-08-04",
        "reading_minutes": 3,
        "word_count": 660,
        "potentially_affected": "Microsoft 365 tenants and the administrators, security teams, auditors, risk owners, and service providers that assess Entra ID, Exchange Online, Teams, SharePoint, Power Platform, Power BI, or Microsoft security settings.",
        "dse_recommendation": "Authorize a controlled assessment, preserve the tool and baseline version with its configuration and raw outputs, assign every material finding, and rerun after approved remediation.",
        "primary_source": {
            "name": "CISA Secure Cloud Business Applications project and ScubaGear",
            "url": "https://github.com/cisagov/ScubaGear",
            "published_on": "2022-10-20",
            "authority": "github.com"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source fact: ScubaGear assesses configuration</h2>\r\n<p>CISA&#8217;s <a href=\"https://github.com/cisagov/ScubaGear\" target=\"_blank\" rel=\"noopener noreferrer\">ScubaGear repository</a> describes a three-step process: PowerShell queries Microsoft 365 APIs, Open Policy Agent compares returned settings with policies derived from CISA&#8217;s Secure Cloud Business Applications baselines, and the tool produces HTML, JSON, and CSV reports. Current coverage includes Microsoft Entra ID, the Microsoft security suite, Exchange Online, Power BI, Power Platform, SharePoint, and Teams.</p>\r\n<p>CISA developed SCuBA principally for federal cloud security, while also recommending that other organizations review the baselines and apply practices where appropriate. A result is therefore not, by itself, a private-sector certification, a complete Microsoft 365 security assessment, or proof that every control is appropriate to a particular tenant.</p>\r\n<h2>Source fact: assessment context changes the result</h2>\r\n<p>The official <a href=\"https://github.com/cisagov/ScubaGear/blob/main/docs/configuration/configuration.md\" target=\"_blank\" rel=\"noopener noreferrer\">configuration documentation</a> supports a YAML or JSON file for product selection, environment details, exclusions, annotations, and policy omissions. It warns that exclusions and omissions can introduce blind spots and says omissions should be approved through the organization&#8217;s risk-management process. Rationales and expiration dates can be recorded. The repository also advises users to review prerequisites, permissions, updates, and product-specific limitations.</p>\r\n<p>These facts matter when comparing two reports. A changed result might reflect tenant drift, a new ScubaGear release, a revised SCuBA baseline, different permissions, a changed configuration file, an API response difference, or a corrected policy implementation. Calling every difference tenant drift would overstate what the evidence proves.</p>\r\n<h2>DSE recommendation: authorize and freeze the assessment context</h2>\r\n<p>Give each run an owner, approved scope, tenant identifier, purpose, and protected execution location. Use only the documented permissions needed for the selected products. Separate interactive testing from any unattended identity, protect its certificate or other authentication material, and remove unnecessary access when scheduled collection is not required. Treat the reports as sensitive because they can expose security configuration and exceptions.</p>\r\n<p>Preserve a run manifest with UTC time, ScubaGear version, baseline or policy version, dependency versions, selected products, environment, invoking identity, configuration-file hash, command parameters, completion status, and output hashes. Store the original HTML, JSON, CSV, console log, and configuration together under access control. This creates reproducibility without claiming the tool captured every relevant setting.</p>\r\n<h2>DSE recommendation: turn findings into governed decisions</h2>\r\n<ol><li><strong>Validate:</strong> confirm collection succeeded and required permissions were available. Review unsupported, error, warning, omitted, and indeterminate results before counting pass or fail.</li><li><strong>Contextualize:</strong> map each material result to the exact SCuBA policy and current tenant design. Confirm whether a third-party control, licensing boundary, emergency account, or service dependency changes the interpretation.</li><li><strong>Decide:</strong> assign a technical owner and risk owner. Record remediate, accept temporarily, not applicable, or tool result incorrect, with evidence and approval. Time-bound exceptions and name their review trigger.</li><li><strong>Change safely:</strong> test Microsoft 365 changes with representative users and dependent applications. Use normal change approval and rollback planning; ScubaGear is an assessment tool, not permission to change production automatically.</li><li><strong>Prove closure:</strong> rerun the affected products, preserve the new evidence, and link the result to the approved change and original finding.</li></ol>\r\n<p>Before remediation, DSE recommends comparing each finding with current official Microsoft documentation for the tenant&#8217;s licensed services and recording the setting&#8217;s actual enforcement scope. Controls can interact across products or depend on licensing. Capture those dependencies so a passing point result is not mistaken for end-to-end enforcement.</p>\r\n<h2>Measure drift without losing the baseline</h2>\r\n<p>Run again on an organization-defined schedule and after material tenant, licensing, identity, or baseline changes. Compare normalized policy identifiers and results, but retain both manifests. Distinguish a tenant change from a tool or policy change in the review record. New checks should enter triage rather than being silently treated as old failures; removed checks should not disappear from the risk register until their disposition is understood.</p>\r\n<p>This operating model differs from DSE&#8217;s Microsoft Secure Score article. Secure Score is a Microsoft-maintained improvement work queue. ScubaGear compares observed settings with CISA policy logic. Neither substitutes for threat modeling, application testing, licensing review, or accountable risk acceptance.</p>\r\n<h2>Official sources</h2>\r\n<ul><li><a href=\"https://www.cisa.gov/resources-tools/services/secure-cloud-business-applications-scuba-project\" target=\"_blank\" rel=\"noopener noreferrer\">CISA Secure Cloud Business Applications project</a></li><li><a href=\"https://github.com/cisagov/ScubaGear\" target=\"_blank\" rel=\"noopener noreferrer\">CISA ScubaGear official repository</a></li><li><a href=\"https://github.com/cisagov/ScubaGear/blob/main/docs/configuration/configuration.md\" target=\"_blank\" rel=\"noopener noreferrer\">ScubaGear configuration-file documentation</a></li><li><a href=\"https://www.cisa.gov/news-events/news/scuba-dives-deeper-help-federal-agencies-secure-their-cloud-environments-publishes-security\" target=\"_blank\" rel=\"noopener noreferrer\">CISA announcement of Microsoft 365 SCuBA baselines</a></li></ul>",
        "content_text": "Source fact: ScubaGear assesses configuration\r\nCISA’s ScubaGear repository describes a three-step process: PowerShell queries Microsoft 365 APIs, Open Policy Agent compares returned settings with policies derived from CISA’s Secure Cloud Business Applications baselines, and the tool produces HTML, JSON, and CSV reports. Current coverage includes Microsoft Entra ID, the Microsoft security suite, Exchange Online, Power BI, Power Platform, SharePoint, and Teams.\r\nCISA developed SCuBA principally for federal cloud security, while also recommending that other organizations review the baselines and apply practices where appropriate. A result is therefore not, by itself, a private-sector certification, a complete Microsoft 365 security assessment, or proof that every control is appropriate to a particular tenant.\r\nSource fact: assessment context changes the result\r\nThe official configuration documentation supports a YAML or JSON file for product selection, environment details, exclusions, annotations, and policy omissions. It warns that exclusions and omissions can introduce blind spots and says omissions should be approved through the organization’s risk-management process. Rationales and expiration dates can be recorded. The repository also advises users to review prerequisites, permissions, updates, and product-specific limitations.\r\nThese facts matter when comparing two reports. A changed result might reflect tenant drift, a new ScubaGear release, a revised SCuBA baseline, different permissions, a changed configuration file, an API response difference, or a corrected policy implementation. Calling every difference tenant drift would overstate what the evidence proves.\r\nDSE recommendation: authorize and freeze the assessment context\r\nGive each run an owner, approved scope, tenant identifier, purpose, and protected execution location. Use only the documented permissions needed for the selected products. Separate interactive testing from any unattended identity, protect its certificate or other authentication material, and remove unnecessary access when scheduled collection is not required. Treat the reports as sensitive because they can expose security configuration and exceptions.\r\nPreserve a run manifest with UTC time, ScubaGear version, baseline or policy version, dependency versions, selected products, environment, invoking identity, configuration-file hash, command parameters, completion status, and output hashes. Store the original HTML, JSON, CSV, console log, and configuration together under access control. This creates reproducibility without claiming the tool captured every relevant setting.\r\nDSE recommendation: turn findings into governed decisions\r\nValidate: confirm collection succeeded and required permissions were available. Review unsupported, error, warning, omitted, and indeterminate results before counting pass or fail.Contextualize: map each material result to the exact SCuBA policy and current tenant design. Confirm whether a third-party control, licensing boundary, emergency account, or service dependency changes the interpretation.Decide: assign a technical owner and risk owner. Record remediate, accept temporarily, not applicable, or tool result incorrect, with evidence and approval. Time-bound exceptions and name their review trigger.Change safely: test Microsoft 365 changes with representative users and dependent applications. Use normal change approval and rollback planning; ScubaGear is an assessment tool, not permission to change production automatically.Prove closure: rerun the affected products, preserve the new evidence, and link the result to the approved change and original finding.\r\nBefore remediation, DSE recommends comparing each finding with current official Microsoft documentation for the tenant’s licensed services and recording the setting’s actual enforcement scope. Controls can interact across products or depend on licensing. Capture those dependencies so a passing point result is not mistaken for end-to-end enforcement.\r\nMeasure drift without losing the baseline\r\nRun again on an organization-defined schedule and after material tenant, licensing, identity, or baseline changes. Compare normalized policy identifiers and results, but retain both manifests. Distinguish a tenant change from a tool or policy change in the review record. New checks should enter triage rather than being silently treated as old failures; removed checks should not disappear from the risk register until their disposition is understood.\r\nThis operating model differs from DSE’s Microsoft Secure Score article. Secure Score is a Microsoft-maintained improvement work queue. ScubaGear compares observed settings with CISA policy logic. Neither substitutes for threat modeling, application testing, licensing review, or accountable risk acceptance.\r\nOfficial sources\r\nCISA Secure Cloud Business Applications projectCISA ScubaGear official repositoryScubaGear configuration-file documentationCISA announcement of Microsoft 365 SCuBA baselines",
        "content_markdown": "## Source fact: ScubaGear assesses configuration\n\nCISA’s [ScubaGear repository](https://github.com/cisagov/ScubaGear) describes a three-step process: PowerShell queries Microsoft 365 APIs, Open Policy Agent compares returned settings with policies derived from CISA’s Secure Cloud Business Applications baselines, and the tool produces HTML, JSON, and CSV reports. Current coverage includes Microsoft Entra ID, the Microsoft security suite, Exchange Online, Power BI, Power Platform, SharePoint, and Teams.\n\nCISA developed SCuBA principally for federal cloud security, while also recommending that other organizations review the baselines and apply practices where appropriate. A result is therefore not, by itself, a private-sector certification, a complete Microsoft 365 security assessment, or proof that every control is appropriate to a particular tenant.\n\n## Source fact: assessment context changes the result\n\nThe official [configuration documentation](https://github.com/cisagov/ScubaGear/blob/main/docs/configuration/configuration.md) supports a YAML or JSON file for product selection, environment details, exclusions, annotations, and policy omissions. It warns that exclusions and omissions can introduce blind spots and says omissions should be approved through the organization’s risk-management process. Rationales and expiration dates can be recorded. The repository also advises users to review prerequisites, permissions, updates, and product-specific limitations.\n\nThese facts matter when comparing two reports. A changed result might reflect tenant drift, a new ScubaGear release, a revised SCuBA baseline, different permissions, a changed configuration file, an API response difference, or a corrected policy implementation. Calling every difference tenant drift would overstate what the evidence proves.\n\n## DSE recommendation: authorize and freeze the assessment context\n\nGive each run an owner, approved scope, tenant identifier, purpose, and protected execution location. Use only the documented permissions needed for the selected products. Separate interactive testing from any unattended identity, protect its certificate or other authentication material, and remove unnecessary access when scheduled collection is not required. Treat the reports as sensitive because they can expose security configuration and exceptions.\n\nPreserve a run manifest with UTC time, ScubaGear version, baseline or policy version, dependency versions, selected products, environment, invoking identity, configuration-file hash, command parameters, completion status, and output hashes. Store the original HTML, JSON, CSV, console log, and configuration together under access control. This creates reproducibility without claiming the tool captured every relevant setting.\n\n## DSE recommendation: turn findings into governed decisions\n\n- Validate: confirm collection succeeded and required permissions were available. Review unsupported, error, warning, omitted, and indeterminate results before counting pass or fail.\n- Contextualize: map each material result to the exact SCuBA policy and current tenant design. Confirm whether a third-party control, licensing boundary, emergency account, or service dependency changes the interpretation.\n- Decide: assign a technical owner and risk owner. Record remediate, accept temporarily, not applicable, or tool result incorrect, with evidence and approval. Time-bound exceptions and name their review trigger.\n- Change safely: test Microsoft 365 changes with representative users and dependent applications. Use normal change approval and rollback planning; ScubaGear is an assessment tool, not permission to change production automatically.\n- Prove closure: rerun the affected products, preserve the new evidence, and link the result to the approved change and original finding.\n\nBefore remediation, DSE recommends comparing each finding with current official Microsoft documentation for the tenant’s licensed services and recording the setting’s actual enforcement scope. Controls can interact across products or depend on licensing. Capture those dependencies so a passing point result is not mistaken for end-to-end enforcement.\n\n## Measure drift without losing the baseline\n\nRun again on an organization-defined schedule and after material tenant, licensing, identity, or baseline changes. Compare normalized policy identifiers and results, but retain both manifests. Distinguish a tenant change from a tool or policy change in the review record. New checks should enter triage rather than being silently treated as old failures; removed checks should not disappear from the risk register until their disposition is understood.\n\nThis operating model differs from DSE’s Microsoft Secure Score article. Secure Score is a Microsoft-maintained improvement work queue. ScubaGear compares observed settings with CISA policy logic. Neither substitutes for threat modeling, application testing, licensing review, or accountable risk acceptance.\n\n## Official sources\n\n- [CISA Secure Cloud Business Applications project](https://www.cisa.gov/resources-tools/services/secure-cloud-business-applications-scuba-project)\n- [CISA ScubaGear official repository](https://github.com/cisagov/ScubaGear)\n- [ScubaGear configuration-file documentation](https://github.com/cisagov/ScubaGear/blob/main/docs/configuration/configuration.md)\n- [CISA announcement of Microsoft 365 SCuBA baselines](https://www.cisa.gov/news-events/news/scuba-dives-deeper-help-federal-agencies-secure-their-cloud-environments-publishes-security)"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo.png"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/turn-cisa-scubagear-into-a-governed-microsoft-365-drift-assessment/",
                "url": "https://update.dsesecurity.com/updates/turn-cisa-scubagear-into-a-governed-microsoft-365-drift-assessment/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-04"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/turn-cisa-scubagear-into-a-governed-microsoft-365-drift-assessment/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Turn CISA ScubaGear into a governed Microsoft 365 drift assessment",
                        "item": "https://update.dsesecurity.com/updates/turn-cisa-scubagear-into-a-governed-microsoft-365-drift-assessment/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/turn-cisa-scubagear-into-a-governed-microsoft-365-drift-assessment/#article",
                "identifier": "https://update.dsesecurity.com/updates/turn-cisa-scubagear-into-a-governed-microsoft-365-drift-assessment/",
                "url": "https://update.dsesecurity.com/updates/turn-cisa-scubagear-into-a-governed-microsoft-365-drift-assessment/",
                "headline": "Turn CISA ScubaGear into a governed Microsoft 365 drift assessment",
                "description": "ScubaGear can compare Microsoft 365 configuration with CISA's SCuBA baselines. A defensible program also controls permissions, versions, configuration…",
                "abstract": "ScubaGear can compare Microsoft 365 configuration with CISA's SCuBA baselines. A defensible program also controls permissions, versions, configuration, exceptions, evidence, remediation, reruns, and drift interpretation.",
                "articleBody": "Source fact: ScubaGear assesses configuration\r\nCISA’s ScubaGear repository describes a three-step process: PowerShell queries Microsoft 365 APIs, Open Policy Agent compares returned settings with policies derived from CISA’s Secure Cloud Business Applications baselines, and the tool produces HTML, JSON, and CSV reports. Current coverage includes Microsoft Entra ID, the Microsoft security suite, Exchange Online, Power BI, Power Platform, SharePoint, and Teams.\r\nCISA developed SCuBA principally for federal cloud security, while also recommending that other organizations review the baselines and apply practices where appropriate. A result is therefore not, by itself, a private-sector certification, a complete Microsoft 365 security assessment, or proof that every control is appropriate to a particular tenant.\r\nSource fact: assessment context changes the result\r\nThe official configuration documentation supports a YAML or JSON file for product selection, environment details, exclusions, annotations, and policy omissions. It warns that exclusions and omissions can introduce blind spots and says omissions should be approved through the organization’s risk-management process. Rationales and expiration dates can be recorded. The repository also advises users to review prerequisites, permissions, updates, and product-specific limitations.\r\nThese facts matter when comparing two reports. A changed result might reflect tenant drift, a new ScubaGear release, a revised SCuBA baseline, different permissions, a changed configuration file, an API response difference, or a corrected policy implementation. Calling every difference tenant drift would overstate what the evidence proves.\r\nDSE recommendation: authorize and freeze the assessment context\r\nGive each run an owner, approved scope, tenant identifier, purpose, and protected execution location. Use only the documented permissions needed for the selected products. Separate interactive testing from any unattended identity, protect its certificate or other authentication material, and remove unnecessary access when scheduled collection is not required. Treat the reports as sensitive because they can expose security configuration and exceptions.\r\nPreserve a run manifest with UTC time, ScubaGear version, baseline or policy version, dependency versions, selected products, environment, invoking identity, configuration-file hash, command parameters, completion status, and output hashes. Store the original HTML, JSON, CSV, console log, and configuration together under access control. This creates reproducibility without claiming the tool captured every relevant setting.\r\nDSE recommendation: turn findings into governed decisions\r\nValidate: confirm collection succeeded and required permissions were available. Review unsupported, error, warning, omitted, and indeterminate results before counting pass or fail.Contextualize: map each material result to the exact SCuBA policy and current tenant design. Confirm whether a third-party control, licensing boundary, emergency account, or service dependency changes the interpretation.Decide: assign a technical owner and risk owner. Record remediate, accept temporarily, not applicable, or tool result incorrect, with evidence and approval. Time-bound exceptions and name their review trigger.Change safely: test Microsoft 365 changes with representative users and dependent applications. Use normal change approval and rollback planning; ScubaGear is an assessment tool, not permission to change production automatically.Prove closure: rerun the affected products, preserve the new evidence, and link the result to the approved change and original finding.\r\nBefore remediation, DSE recommends comparing each finding with current official Microsoft documentation for the tenant’s licensed services and recording the setting’s actual enforcement scope. Controls can interact across products or depend on licensing. Capture those dependencies so a passing point result is not mistaken for end-to-end enforcement.\r\nMeasure drift without losing the baseline\r\nRun again on an organization-defined schedule and after material tenant, licensing, identity, or baseline changes. Compare normalized policy identifiers and results, but retain both manifests. Distinguish a tenant change from a tool or policy change in the review record. New checks should enter triage rather than being silently treated as old failures; removed checks should not disappear from the risk register until their disposition is understood.\r\nThis operating model differs from DSE’s Microsoft Secure Score article. Secure Score is a Microsoft-maintained improvement work queue. ScubaGear compares observed settings with CISA policy logic. Neither substitutes for threat modeling, application testing, licensing review, or accountable risk acceptance.\r\nOfficial sources\r\nCISA Secure Cloud Business Applications projectCISA ScubaGear official repositoryScubaGear configuration-file documentationCISA announcement of Microsoft 365 SCuBA baselines",
                "datePublished": "2026-08-04T22:53:02+00:00",
                "dateModified": "2026-08-04T22:53:02+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/turn-cisa-scubagear-into-a-governed-microsoft-365-drift-assessment/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@id": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/turn-cisa-scubagear-into-a-governed-microsoft-365-drift-assessment/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/posts/turn-cisa-scubagear-into-a-governed-microsoft-365-drift-assessment-social.jpg?v=1.8.2",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/posts/turn-cisa-scubagear-into-a-governed-microsoft-365-drift-assessment-social.jpg?v=1.8.2",
                    "width": 1200,
                    "height": 630,
                    "caption": "Turn CISA ScubaGear into a governed Microsoft 365 drift assessment"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity",
                    "Playbook",
                    "Advisory priority"
                ],
                "genre": "Playbook",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 660,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "CISA Secure Cloud Business Applications project and ScubaGear",
                    "url": "https://github.com/cisagov/ScubaGear",
                    "datePublished": "2022-10-20"
                }
            }
        ]
    }
}