DHS OIG-26-30 Finds 86% of Agencies Missed BOD 25-01's Microsoft 365 Deadline
The DHS Office of Inspector General lists the report as CISA Enhanced Cloud Security for Federal Information, but Lacks Authority to Require All Necessary Protective Actions, with an issue date of September 21, 2026. Federal News Network and CyberScoop both reported on it. They agree on the main figure: 88 of the 102 Federal Civilian Executive Branch (FCEB) agencies did not implement all mandatory policies from CISA's Secure Cloud Business Applications (SCuBA) project by the deadline.
The figure needs careful reading. Eighty-six percent failed to implement all the required policies. That does not mean 86% did nothing. The audit also shows little catch-up after the deadline. CyberScoop quotes the report as saying that by February of this year compliance "had not improved," and that 78 of 102 agencies (76%) were still not in compliance with all mandatory SCuBA policies. Nexsight Cyber Wire, a Japanese security outlet, puts that snapshot at February 12, 2026.
Nexsight also reports compliance at each earlier deadline. It says 40 agencies (39%) did not submit their cloud tenant inventory to CISA on time, 53 (52%) did not fully deploy the assessment tools to their in-scope tenants, and only 14 (14%) completed everything on schedule. Nexsight adds that CISA notified the Office of Management and Budget and every noncompliant agency. No other outlet has reported the per-deadline breakdown, so treat it as secondary reporting of the audit.
The IG's risk finding is stated in general terms. Federal News Network quotes the report as warning that agencies which missed the deadlines "face heighted security risks" that weaken the national cloud security posture and raise the likelihood of preventable attacks and data loss. The audit does not link any specific breach to a specific agency's missing settings.
BOD 25-01 Turned SCuBA Baselines Into Three Microsoft 365 Deadlines
A binding operational directive is a mandatory cybersecurity order that CISA, acting under DHS authority, issues to federal civilian agencies. CISA issued BOD 25-01 in December 2024. BleepingComputer reported at the time that it ordered federal civilian agencies to secure their Microsoft 365 cloud environments by implementing a list of required configuration baselines. The directive covered only federal civilian agencies, but CISA strongly advises all organizations to adopt this directive and prioritize securing their cloud environments to significantly reduce their attack surface and breach risks.
SCuBA is the CISA program behind those baselines. Federal News Network says CISA set it up to close cloud security gaps like those exploited in the 2020 SolarWinds compromise, which the U.S. government attributed to Russian hackers. Nexsight reports that the project launched in 2022. According to Tenable, the SCuBA project currently provides secure configuration baselines for Microsoft 365 and Google Workspace. The Microsoft 365 assessment tool is ScubaGear, an assessment tool that verifies that a Microsoft 365 (M365) tenant's configuration conforms to the policies described in the Secure Cloud Business Applications (SCuBA) Secure Configuration Baseline documents.
The directive set three deadlines, all in 2025:
| Deadline | Required action under BOD 25-01 |
|---|---|
| February 21, 2025 | Submit an inventory of every in-scope cloud tenant, including tenant name and owning agency or component, and update it annually in the first quarter |
| April 25, 2025 | Deploy the SCuBA assessment tools and begin continuous reporting to CISA |
| June 20, 2025 | Implement every mandatory SCuBA policy listed on CISA's BOD 25-01 Required Configurations site |
Tenable's summary of the directive lists these dates and actions. CISA's own implementation guidance confirms that agencies had to implement all mandatory SCuBA policies as set forth in the CISA-managed BOD 25-01 Required Configurations website no later than ?? Friday, June 20, 2025.
Compliance was meant to be measured automatically. BleepingComputer reported that the directive requires agencies to deploy CISA-developed automated configuration assessment tools (ScubaGear for Microsoft 365 audits), integrate with the cybersecurity agency's continuous monitoring infrastructure, and remediate any deviations from the secure configuration baselines within predefined timeframes. Because of that setup, CISA could see which agencies were failing. The IG's point is that seeing a failure did not give CISA any way to fix it.
The Settings Agencies Skipped Were Basic Microsoft 365 Controls: MFA, Legacy Authentication, DLP
The report names examples of what went unimplemented. CyberScoop quotes it: "Some examples of baselines that FCEB agencies did not implement included blocking outdated authentication procedures, enforcing multifactor authentication, and implementing a policy to protect sensitive and personally identifiable information." Nexsight's account of the audit lists the same three.
These map directly onto the Microsoft 365 services the directive covers. A Red-Team News analysis of BOD 25-01 says the directive covers six core Microsoft 365 services: Entra ID (formerly Azure AD), Defender, Exchange Online, Power Platform, SharePoint/OneDrive, and Teams. In its examples, Entra ID mandates phishing-resistant MFA for all users and blocking of legacy authentication protocols, while Exchange Online requires disabling SMTP AUTH and implementing DMARC with p=reject policies. On the Defender side, the same analysis says the baselines require enabling Microsoft Purview Audit logging for all users and implementing data loss prevention policies to block sharing of sensitive information like SSNs and credit card numbers.
None of these are new ideas. Blocking legacy authentication, enforcing MFA, and running data loss prevention (DLP) policies are standard hardening steps for Microsoft 365. A large share of federal agencies had not fully applied them months after a mandatory deadline. The baselines' own documentation hints at why some agencies stalled. ScubaGear's published baselines mark each policy as a BOD 25-01 Requirement, but some policies need extra configuration before the tool can check them, and others require manual verification of configuration settings.
The report's conclusion on these controls is direct. CyberScoop quotes the IG as saying that "implementation of these baselines could mitigate vulnerabilities and threats from affecting the cloud business applications."
FISMA 2014 Lets CISA Issue Binding Operational Directives but Not Enforce Them
The audit's main institutional finding comes from the Federal Information Security Modernization Act of 2014 (FISMA). According to Federal News Network's account, the IG found that FISMA gives DHS authority to issue cyber directives to other agencies but does not give CISA, through DHS, authority to enforce compliance. The IG wrote that CISA's role is limited to "developing policies, assisting [FCEB agencies] to implement policies, and reporting on how well FCEB agencies follow the policies." In its own words, "CISA lacks the authority necessary to require full and timely implementation of Binding Operational Directives."
That finding shaped the report. The IG made no recommendations to CISA, reasoning that the agency cannot be told to fix something the law does not let it control. Nexsight reports that the IG described the enforcement gap as a statutory limitation. CISA declined to comment on the report, and CyberScoop said the agency did not immediately respond to its own request for comment.
The IG did find that CISA made a real effort. It documented one-on-one outreach to agencies and meetings between CISA's Federal Enterprise Improvement Team (FEIT) and agency chief information security officers to review compliance with mandatory directives. CISA had the data, the relationships, and the meetings. What it lacked was any consequence it could impose on an agency that stayed out of compliance.
Congress has already considered changing this. In 2023, the Senate Homeland Security and Governmental Affairs Committee passed a FISMA reform bill that would have strengthened CISA's authority to oversee federal network security, but the bill went no further after committee. Federal News Network's reporting does not give the bill number or its enforcement provisions. The practical position today is that a BOD is mandatory in name, and nothing in the law penalizes an agency that misses its deadlines.
CyberScoop notes that questions about whether CISA's directives can be enforced have come up before. That matters beyond BOD 25-01, because CISA is now overseeing several newer directives. Federal News Network describes one of them as a key artificial intelligence-driven directive on prioritizing software vulnerabilities. The IG's finding applies to every BOD, since all of them depend on the same FISMA authority.
Why SCuBA's 130,000 ScubaGear Downloads Didn't Produce Compliant Tenants
The SCuBA program was widely used, and the IG credits it. Federal News Network reports that the audit found CISA held more than 80 engagements with over 1,000 participants, and that more than 130,000 requesters downloaded the SCuBA assessment tools. Nexsight adds that CISA helped 17 agencies trial the tools and improve them. Those numbers measure outreach and interest. They do not measure how many tenants were remediated, and many of the downloads presumably came from outside the 102 covered agencies.
Two former federal technology officials quoted by Federal News Network explain the gap in different ways. Bob Costello, CISA's former CIO and now chief digital and information officer at Merlin Group, called SCuBA "excellent" but said the work is heavy: "It can be a lot of work to implement those settings within your Microsoft tenant." He said CISA applied the baselines to its own tenant with good results, and suggested some agencies "felt a little overwhelmed." He also noted that agencies often lack the resources to implement new directives, and that there are few consequences for those that don't comply.
Gary Barlet, federal sector CTO at Illumio and former CIO of the U.S. Postal Service Office of Inspector General, said the problem is follow-through, not a shortage of guidance. He argued that the challenge is turning years of cloud security and zero trust planning into operational reality. Both are outside views and neither is an audit finding. Together they describe the same problem: well-documented baselines, limited staff to apply them, and no penalty for delay.
CISA's own guidance shows why this work takes staff time. Before ScubaGear can report a policy as passing, the tool often has to be told about the tenant's exceptions. CISA says that in some cases, ScubaGear may need to be configured with relevant information so that policies successfully pass the evaluation criteria. For example, "break glass" accounts that are exempt from certain policies must be explicitly listed. Every exemption has to be identified, justified, and recorded before a scan can pass. For a large agency with many tenants and components, that is a substantial project.
What This Means for Microsoft 365 Administrators Running SCuBA Baselines
If your organization is a federal civilian agency, the IG report does not change your obligations. BOD 25-01 is still mandatory, and CISA's continuous reporting still shows it which tenants are failing. The audit only confirms that no enforcement mechanism sits behind that reporting. For everyone else, including state and local IT, contractors, and private companies, the directive never applied. The baselines and ScubaGear are still a free, government-maintained checklist for hardening Microsoft 365, and CISA itself recommends them to non-federal organizations.
Running an assessment is fairly simple. The part that takes work is fixing what it finds. According to the ScubaGear project documentation:
- On a Windows computer, open a PowerShell 5 terminal and install the module and its dependencies with
Install-Module -Name ScubaGearfollowed byInstall-ScubaDependencies. - Build a YAML configuration file for your tenant, starting from the included
full_config.yaml. The project warns that without a properly defined YAML file, ScubaGear will assume a default configuration that may not reflect your organization's actual policies or risk posture. List break-glass accounts and other documented exemptions here. - Run the assessment. For BOD 25-01 submissions, the documented form is
Invoke-SCuBA -ConfigFilePath "path/to/your/config.yaml" -Organization 'example.onmicrosoft.com'. Organizations outside the directive can add-SilenceBODWarnings. Per the documentation, if you are running v2.0.0 with interactive login against a non-commercial tenant such as gcc or gcchigh, include the -M365Environment parameter. - Read the report. ScubaGear queries Microsoft 365 APIs for configuration settings, then calls Open Policy Agent (OPA) to compare these settings against Rego security policies written per the baseline documents. Finally, it reports the results of the comparison as HTML, JSON, and CSV.
- Fix the failures, then run it again. CISA's guidance for agencies is to re-run ScubaGear again to confirm that the policy failures have been remediated. Federal agencies then resubmit the results to CISA. Keep the tool current with
Update-ScubaGear.
Plan for side effects before you enforce anything. Blocking legacy authentication or disabling SMTP AUTH will break older clients, scanners, and scripts that still depend on them. Find those dependencies before you switch on the controls the audit says agencies skipped.
- Federal civilian agencies remain bound by BOD 25-01, and the June 20, 2025 deadline for all mandatory SCuBA policies has passed.
- The IG found 88 of 102 agencies missed that deadline, and CyberScoop reports 78 were still noncompliant as of February 2026.
- The skipped controls named in the audit were legacy authentication blocking, MFA enforcement, and a policy protecting sensitive and personally identifiable information. These are good first checks in any Microsoft 365 tenant.
- ScubaGear covers Microsoft 365 through a PowerShell module, but a scan only means something when the YAML config accurately lists your tenant's break-glass accounts and exemptions.
- Non-federal organizations can use the SCuBA baselines voluntarily and should add
-SilenceBODWarningswhen running ScubaGear outside the directive. - Some baseline policies require manual verification, so a clean automated scan does not cover everything the baselines contain.
The IG made no recommendations because it concluded the fix is in the law, not at CISA. Until Congress revisits the FISMA reform that stalled in committee in 2023, compliance with BOD 25-01 and CISA's newer directives, including the AI-driven vulnerability prioritization order, depends on each agency choosing to comply. The February 2026 figures show that 76% of agencies still had not fully done so eight months after the deadline. The baselines and ScubaGear remain freely available, and any Microsoft 365 administrator, federal or not, can use them to check whether their own tenant has the same gaps.