Exchange CIS Audit Crate
What does the Exchange CIS Audit Crate do?
This Crate automates the process of validating certain Center for Internet Security (CIS) controls such as audit logs and mailbox configurations, and logs a ticket in your PSA for record-keeping and potential remediation actions.
How the Crate works
The workflow validates if audit logs are configured correctly per CIS controls.
It confirms if mailbox settings align with specific CIS controls.
A ticket is created in your integrated PSA, detailing the compliance status of each control validated.
The ticket contains a detailed summary of all the controls checked, making it easier for remediation if necessary.
Crate prerequisites
The Microsoft Cloud Integration Bundle must be set up before unpacking this Crate.
Your PSA must successfully be integrated with Rewst.
Unpack the Exchange CIS Audit Crate
Navigate to Marketplace > Crates in the Rewst platform.
Search for
Exchange CIS Audit.
Click on the Crate tile to begin unpacking.
Click Unpack Crate.
Click Continue.
Note that you have the option under the Cron Job accordion menu to activate the Crate for all future organizations in addition to the current one. You may also set activation to certain tags, trigger criteria, or for integration overrides.
Click Unpack.
Update the cron trigger
After unpacking, the default schedule for this Crate is once monthly, on the first day of each month.
Navigate to Automations > Workflows.
Search for
[ROC] EXO: CIS Audit.Click on the workflow to open it in the Workflow Builder.
Click on the trigger in the workflow to open its settings in the right side menu.
Update the timing of the cron trigger as desired in the fields under Trigger Parameters. Note that when entering the time into the Cron Schedule field, the correct format is minutes followed by hour. For example, 18 3, not 3 18.
Click Save Trigger.
Last updated
Was this helpful?
