← Custodia

CMMC Level 1 Microsoft 365 Checklist for Small Contractors

A practical Microsoft 365 checklist for CMMC Level 1: MFA, users, SharePoint permissions, external sharing, device inventory, Defender, patching, and evidence.

By David Fuentes· Compliance Officer, CustodiaJune 17, 202610 min read

Most small DoD contractors do not need to build a new security stack for Level 1. They need to make the Microsoft 365 stack they already pay for behave like a controlled FCI workspace. This checklist is intentionally practical: what to turn on, what to avoid, and what proof to keep.

The short answer

  • Use named Microsoft 365 accounts for everyone who touches FCI.
  • Enable MFA through Security Defaults or Conditional Access.
  • Put FCI in a controlled SharePoint/OneDrive location, not personal email or random file shares.
  • Restrict public and anonymous links for FCI folders.
  • Keep device, Defender, and patch evidence for endpoints that access FCI.

Which Microsoft 365 plan?

Start with the data type, not the product catalog. CMMC Level 1 is for FCI. It does not automatically require GCC or GCC High. If your contract, prime, or data owner requires a government cloud tenant, follow that requirement. If you handle CUI, this article is no longer your stopping point. You need a Level 2 conversation.

The practical checklist

AreaWhat to do in Microsoft 365Level 1 requirement supported
IdentityUse named user accounts. Disable shared mailboxes or shared logins for FCI work.AC.1, IA.1
MFAEnable Security Defaults or Conditional Access requiring MFA for users/admins.IA.2
AdminsLimit Global Admin and other admin roles to a small number of named users. Use separate admin accounts where practical.AC.2
FCI storageCreate a dedicated SharePoint site or folder for FCI. Restrict access to named users.AC.1, AC.2
External sharingTurn off anonymous/public links for the FCI location. Review guest users.AC.3, AC.4
Email forwardingBlock automatic forwarding to personal/external email for accounts handling FCI.AC.3
DevicesKeep an inventory of laptops/desktops that access FCI. Prefer company-managed devices.IA.1, AC.3
Endpoint protectionConfirm Microsoft Defender Antivirus or another AV/EDR is enabled and current on in-scope Windows devices.SI.2, SI.3, SI.4
PatchingKeep Windows, Office apps, browsers, and firmware updated on in-scope devices.SI.1
Public contentReview company website, LinkedIn, Teams guest access, and shared links so FCI is not posted publicly.AC.4

SharePoint and OneDrive

The cleanest M365 pattern for Level 1 is one controlled FCI workspace: a SharePoint site, Teams-backed document library, or dedicated folder where contract documents live. Keep access small. Use named groups. Avoid "anyone with the link." Review guest users on a schedule.

What you are trying to avoid is sprawl: FCI attachments living in personal OneDrive folders, downloaded to unmanaged laptops, forwarded to personal email, or shared with public links. Sprawl makes the Level 1 boundary expensive because everything that touches FCI comes into scope.

Devices, Defender, and patching

Microsoft Defender Antivirus is built into supported Windows versions, and Microsoft describes it as part of next-generation protection for Windows endpoints. For Level 1, the question is not whether the logo exists in the taskbar. The question is whether protection is enabled, current, and covering the endpoints that touch FCI.

  • Save Defender status for one representative device or your device group.
  • Save update status for Windows and Office apps.
  • Document any Macs or non-Windows devices separately.
  • Do not allow unmanaged personal laptops to become invisible FCI storage.

Evidence to save

  1. Security Defaults enabled or Conditional Access MFA policy screenshots.
  2. User export showing named accounts for FCI users.
  3. Admin role export showing limited privileged accounts.
  4. SharePoint/OneDrive permissions screenshot for the FCI folder or site.
  5. External sharing and guest-user review screenshot.
  6. Device inventory for endpoints that access FCI.
  7. Defender/AV status and update status for in-scope devices.
  8. Short written policy: where FCI lives, who can access it, and how sharing is approved.

Sources

FAQ

Can Microsoft 365 support CMMC Level 1?

Yes. Microsoft 365 can support many CMMC Level 1 requirements when it is configured correctly: named accounts, MFA, controlled SharePoint/OneDrive access, external sharing limits, audit-friendly user lists, endpoint protection, and patching evidence. The subscription itself is not enough; the tenant configuration and operating process matter.

Is Microsoft 365 GCC required for CMMC Level 1?

No. CMMC Level 1 protects FCI, not CUI. GCC or GCC High may be required by contract, by customer policy, or for CUI workloads, but Level 1 itself does not automatically require GCC. Confirm your contract and data type before buying a government cloud tenant.

Is MFA required for CMMC Level 1 in Microsoft 365?

FAR 52.204-21 does not use the word MFA, but it requires authentication before access. For Microsoft 365, MFA is the practical baseline for showing strong authentication, especially for email, admin accounts, and remote access to FCI.

Is Microsoft Defender enough for CMMC Level 1?

Microsoft Defender Antivirus is built into supported Windows versions and can satisfy the Level 1 malicious-code protection requirements when it is enabled, current, and covering the devices that touch FCI. Some contractors choose a managed EDR for visibility, but Level 1 does not require a specific product.

What Microsoft 365 evidence should I save for Level 1?

Save MFA/security defaults or Conditional Access screenshots, user and admin exports, SharePoint/OneDrive FCI-folder permissions, external sharing settings, device inventory, Defender status, update status, and a short policy explaining how FCI is stored and shared.

Keep reading
  1. Level 1 Evidence
    CMMC Level 1 Evidence Examples: What to Keep for Each Requirement

    What counts as evidence for CMMC Level 1? Here are practical examples for all 15 requirements, plus what not to rely on.

    Read →
  2. Subcontractors
    CMMC Level 1 for Subcontractors: What Actually Flows Down

    If you are a DoD sub handling FCI, Level 1 can flow down. Here is what the prime needs, what SPRS shows, and what not to overpromise.

    Read →
  3. Remote Work
    CMMC Level 1 for Remote Work: Home Offices, Laptops, and FCI

    Remote work does not break CMMC Level 1. It changes the evidence you keep: managed devices, MFA, home-office rules, and a clear FCI boundary.

    Read →
Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements — no signup, no card. If you like what you see, the 7-day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

7-day free trial · No credit card required · $249/mo Self Service ($2,496/yr on annual — two months free)