ScubaGear is a free, open-source assessment tool from CISA that evaluates Microsoft 365 tenant configurations against Secure Cloud Business Applications (SCuBA) baselines. It assesses security settings across Entra ID, Exchange Online, Teams, SharePoint, Power Platform, Power BI and Security Suite, generating compliance reports in HTML, JSON and CSV formats.
There is a free version. Listing updated . Checked by MSP Software .
ScubaGear is a free Microsoft 365 assessment tool from CISA, the Cybersecurity and Infrastructure Security Agency, for evaluating M365 tenant configurations against CISA's Secure Cloud Business Applications (SCuBA) baselines. The tool uses PowerShell to query M365 APIs and Open Policy Agent policies to assess seven major product categories: Microsoft Entra ID, Exchange Online, Teams, SharePoint, Power Platform, Power BI, and Security Suite. It generates compliance reports in HTML, JSON and CSV formats highlighting security configuration gaps and misalignments with government security baselines, making it particularly valuable for organisations subject to federal compliance requirements or those seeking CISA security guidance.
ScubaGear runs as a PowerShell module on Windows, installed from the PowerShell Gallery via a single command. Once initialised, it connects to a Microsoft 365 tenant using provided credentials, queries configuration settings across specified products, evaluates those settings against over 100 individual baseline policies, and produces detailed HTML reports with interactive dashboards alongside machine-readable JSON and CSV outputs. The tool assesses conditional access policies, user provisioning settings, security suite configurations, external sharing restrictions, Teams communication controls, and dozens of other M365 security controls. No client-side installation on user machines is needed; ScubaGear runs entirely as an administrative assessment tool.
Because ScubaGear is free, open-source software distributed under the Creative Commons Zero licence (checked September 2026), organisations can run assessments as often as needed without licensing cost. It suits government agencies, contractors, and any MSP or enterprise evaluating M365 against federal baselines or implementing CISA guidance. The tool integrates with ScubaConnect, CISA's cloud infrastructure for automated scheduled assessments, and because source code is public, shops can extend policies or customise baselines for their own compliance frameworks.
ScubaGear fills a specific niche: free CISA-published M365 baseline assessment for government compliance and MSP security audits. Unlike commercial M365 management platforms such as N-able or Microsoft 365 Lighthouse, ScubaGear is assessment-only and focuses on federal baselines rather than operational management. It suits organisations weighing compliance posture against CISA standards or those subject to federal requirements. MSPs should pair it with an M365 management or configuration tool; ScubaGear identifies gaps but does not execute remediation. Before deploying, confirm appropriate tenant permissions for API queries and PowerShell 5 compatibility.
| Feature | Supported | Note |
|---|---|---|
| Tenant and user provisioning | yes | Assesses tenant configuration and user provisioning settings |
| Licence assignment | unknown | Vendor documentation does not address licence assignment verification |
| Security baseline templates | yes | Core feature: evaluates against 100+ CISA SCuBA baseline policies across 7 M365 products |
| Conditional access management | yes | Evaluates conditional access policies and device trust configurations |
| Multi-tenant console | yes | Supports assessment of multiple M365 tenants in single assessment run |
| Shadow SaaS discovery | no | Assessment tool does not discover unmanaged cloud applications |
| Automated offboarding | no | Assessment-only tool; does not perform offboarding operations |
| Reporting and QBR exports | yes | Generates HTML dashboards, JSON and CSV exports for reporting and QBR |
| Microsoft Graph API integration | yes | Uses Microsoft 365 APIs and Microsoft Graph to query configuration data |
| PSA integration | no | No PSA ticketing or integration for findings |
| Backup integration | no | Assessment tool does not include backup functionality |
| Delegated admin (GDAP) support | unknown | Vendor documentation does not specify delegated admin (GDAP) support |
| Feature | Supported |
|---|---|
| Network vulnerability scanning | unknown |
| Authenticated scanning | unknown |
| Missing patch detection | unknown |
| Compliance framework mapping | unknown |
| Risk scoring | unknown |
| Dark web monitoring | unknown |
| External attack surface scanning | unknown |
| PSA integration for remediation tickets | unknown |
| Scheduled recurring scans | unknown |
| Client-facing reports | unknown |
| Multi-tenant console | unknown |
| Automated evidence collection | unknown |
Yes, ScubaGear is completely free. It is open-source software distributed under the Creative Commons Zero (CC0-1.0) licence, which is a public domain dedication. There are no licensing fees, subscription costs, or per-tenant charges. Organisations can download the tool from CISA's GitHub repository and run assessments as frequently as needed at no cost.
ScubaGear assesses seven major Microsoft 365 product categories: Microsoft Entra ID (identity and access management), Exchange Online (email and compliance), Teams (communication and meetings), SharePoint (collaboration and document sharing), Power Platform (low-code applications), Power BI (data analytics and visualisation), and Security Suite (threat protection and advanced security). The tool evaluates over 100 individual baseline policies across these products.
No, ScubaGear is an assessment and audit tool only. It identifies security configuration gaps and misalignments with CISA baselines but does not automatically remediate or change M365 settings. Users must review findings in ScubaGear's reports and make configuration changes manually or through other M365 management tools. MSPs typically pair ScubaGear with an M365 management platform for execution of remediation.
ScubaGear runs as a PowerShell module on Windows and requires PowerShell 5 or later. Installation is performed via the PowerShell Gallery with the command Install-Module -Name ScubaGear. The tool connects to Microsoft 365 via APIs and requires a M365 tenant with appropriate permissions to query configuration settings. No per-user client installation is needed.
Yes, ScubaGear integrates with ScubaConnect, CISA's cloud infrastructure, which supports automated scheduled execution of assessments. Without ScubaConnect, assessments can also be scheduled via Windows Task Scheduler or other PowerShell automation tools. Automated scheduling allows organisations to run regular compliance baselines against their M365 tenants on a recurring basis.
Reviews are moderated. How reviews work.
Share what it is like to use this product day to day. Your experience helps other MSPs choose with confidence.
Write the first review