Identify gaps before they become business risks
This security baseline is designed primarily for organizations using Microsoft 365 Business Premium. Some controls appear in more than one section because Microsoft Entra ID, Conditional Access, Intune, Defender, Exchange Online and Microsoft Purview operate as interconnected security components.
Topics covered
1. Tenant Foundation
1.1 Tenant Ownership
Document the Microsoft 365 tenant ID, primary domain, subscription owner, billing contacts, technical contacts and authorised administrators. This information should be securely maintained and regularly updated.
1.2 Administrative Access
Limit Global Administrator access to the minimum number of authorised personnel. Normally, an organisation should maintain between two and four appropriately secured Global Administrator accounts.
1.3 Separate Administrator Accounts
Administrators must use separate accounts for administrative activities and routine work. Privileged accounts should not be used for regular email, internet browsing or day-to-day office activities.
1.4 Emergency Access Accounts
Maintain two cloud-only emergency-access accounts to prevent complete tenant lockout. Protect these accounts with phishing-resistant authentication, securely store their credentials, monitor every login and test them quarterly.
1.5 Custom Domains
Verify all approved business domains configured within Microsoft 365. Remove any unused, expired or unrecognised domains from the tenant.
1.6 Domain and DNS Protection
Protect the domain registrar account using MFA, registrar lock and restricted administrative access. Maintain controlled documentation of Microsoft verification, SPF, DKIM and DMARC DNS records.
1.7 Organisation Contacts
Configure valid security, privacy, compliance, technical-support and service-health notification addresses. These mailboxes should be actively monitored.
1.8 Licensing Governance
Assign Microsoft 365 licences only to authorised users, preferably through controlled groups. Review unused, duplicate and unnecessarily assigned licences every month.
1.9 Release Management
Use Targeted Release only for a selected group of pilot users. Keep production users on the Standard Release channel unless there is a specific operational requirement.
1.10 Group and Site Creation
Restrict the creation of Microsoft 365 Groups, Teams and SharePoint sites to authorised users. Alternatively, implement a documented creation, naming and approval process.
1.11 Naming Standards
Establish consistent naming conventions for users, groups, devices, Conditional Access policies, enterprise applications, Teams and SharePoint sites.
1.12 Baseline Security Configuration
Review the Microsoft 365 Baseline Security Mode settings and enable applicable controls after completing an impact assessment and dependency review.
1.13 Unified Audit Logging
Confirm that Microsoft Purview Audit is enabled. Periodically verify that user activities and administrative changes are being recorded.
1.14 Configuration Register
Maintain an approved configuration register containing tenant settings, security policies, exceptions, responsible owners, approval information and implementation dates.
1.15 Change Control
Test material tenant configuration changes using pilot groups. Record the approval, expected impact, implementation steps and rollback procedure before applying changes to production.
2. Identity and Access Management
2.1 User Account Provisioning
Create user accounts only against approved employee, contractor or third-party onboarding requests. Every account should have a documented owner and business purpose.
2.2 Unique User Identity
Every person must have an individually assigned Microsoft 365 account. Shared user accounts should not be permitted because they prevent accountability and effective auditing.
2.3 Joiner–Mover–Leaver Process
Establish documented procedures for employee onboarding, role changes, department transfers, account suspension and termination.
2.4 Employee Offboarding
Immediately block sign-in, revoke active sessions, reset credentials, remove privileged roles and group memberships, transfer business data and remove unnecessary licences when employment ends.
2.5 Administrative Accounts
Maintain separate standard and privileged accounts for administrators. Dedicated administrative accounts should not have regular mailboxes unless there is a documented requirement.
2.6 Role-Based Access Control
Assign the least-privileged administrative role required for each responsibility. Do not assign Global Administrator when a more limited role can perform the required task.
2.7 Privileged Access Review
Review Global Administrator and other privileged role assignments at least quarterly. Remove unnecessary, duplicate or outdated access promptly.
2.8 Group-Based Access
Grant access through approved security groups wherever possible instead of directly assigning permissions to individual users.
2.9 Group Ownership
Assign at least two accountable owners to important security groups and Microsoft 365 Groups. This prevents groups from becoming unmanaged when an owner leaves the organisation.
2.10 Inactive Accounts
Identify and disable inactive, duplicate, test and orphaned accounts. Account inactivity should be reviewed at least monthly.
2.11 Guest Account Lifecycle
Assign a business owner, purpose and expected duration to every guest account. Review guest accounts quarterly and remove access that is no longer required.
2.12 Service Accounts
Document the owner and purpose of every service account. Block interactive sign-in where possible and use certificates, managed identities or other secure authentication methods instead of permanent passwords.
2.13 Password Management
Use Microsoft Entra Password Protection to block known weak passwords and organisation-specific terms. Passwords should be changed after suspected compromise rather than routinely changed without a security or regulatory reason.
2.14 Self-Service Password Reset
Enable Self-Service Password Reset for authorised users and require combined MFA and SSPR security-information registration.
2.15 Licence Removal
Remove unnecessary licences promptly. Before licence removal, preserve or transfer required mailbox, OneDrive and business information according to the organisation’s retention requirements.
3. Microsoft Entra ID Security
3.1 Multifactor Authentication
Require multifactor authentication for all users through Microsoft Entra Conditional Access.
3.2 Administrator Authentication
Require phishing-resistant MFA for administrator roles. Preferred authentication methods include Windows Hello for Business, passkeys or FIDO2 security keys, and certificate-based authentication.
3.3 Conditional Access Framework
Maintain documented Conditional Access policies with clear naming, scope, ownership, exclusions, dependencies and emergency-access arrangements.
3.4 Legacy Authentication
Block legacy authentication protocols that cannot support MFA, Conditional Access or device-compliance controls.
3.5 Authentication Methods
Centrally manage the authentication methods users are allowed to register. Prefer Windows Hello, passkeys and Microsoft Authenticator. Avoid SMS and voice authentication for administrators.
3.6 Security Defaults
Do not use Microsoft Security Defaults and Conditional Access together. Organisations with Microsoft 365 Business Premium should generally use Conditional Access for more granular control.
3.7 Emergency Account Exclusions
Exclude emergency accounts only from organisation-created Conditional Access policies that could cause complete tenant lockout. These accounts must still comply with applicable Microsoft platform MFA requirements.
3.8 Device Registration
Require MFA for Microsoft Entra device registration and restrict which users are allowed to join devices to the organisation’s directory.
3.9 Compliant Device Access
Require Intune-enrolled and compliant devices for access to Microsoft 365 and sensitive business applications wherever operationally possible.
3.10 Geographic Access Restrictions
Block sign-ins from countries where the organisation does not operate. Maintain documented exceptions for approved travel and legitimate business requirements.
3.11 Named Locations
Configure trusted office public IP addresses where required. Trusted network location must not be treated as a substitute for MFA and device compliance.
3.12 Application Consent
Allow users to provide consent only to verified applications requesting approved low-impact permissions. Route all other application-consent requests through an administrator approval process.
3.13 Enterprise Applications
Regularly review enterprise application owners, permissions, user assignments, certificates, secrets and usage information. Remove unused applications and excessive permissions.
3.14 Guest Access Restrictions
Apply the most restrictive practical guest-directory visibility and limit which users or administrative roles can invite external users.
3.15 Sign-In Monitoring
Monitor failed sign-ins, unusual locations, legacy authentication attempts, administrator logins, MFA failures and emergency-account activity.
3.16 Audit Monitoring
Monitor changes to administrative roles, Conditional Access, authentication methods, enterprise applications, credentials and guest access settings.
3.17 Entra Log Retention
Export Microsoft Entra sign-in and audit logs to Log Analytics, Azure Storage or a SIEM platform when retention beyond the native period is required.
3.18 Identity Secure Score
Review identity-related Microsoft Secure Score recommendations every month. Document completed actions, accepted risks and approved exceptions.
3.19 Conditional Access Deployment
Deploy new Conditional Access policies initially in Report-only mode. Review the impact and then enable them through phased pilot and production groups.
4. Exchange Online Security
4.1 Preset Security Policies
Apply the Standard preset security policy to all users. Apply the Strict preset security policy to administrators, directors, finance staff and other high-risk users.
4.2 Anti-Phishing Protection
Enable spoof protection, mailbox intelligence, user and domain impersonation protection, phishing thresholds and relevant safety tips.
4.3 Anti-Malware Protection
Enable malware filtering, Zero-hour Auto Purge and common attachment-type filtering to prevent malicious files from reaching users.
4.4 Inbound Anti-Spam Protection
Apply Microsoft-recommended actions for spam, high-confidence spam, phishing and high-confidence phishing messages.
4.5 Outbound Anti-Spam Protection
Configure outbound sending limits and alerts to identify compromised accounts, unusual sending patterns and restricted users.
4.6 Safe Links
Enable Safe Links for email and supported Microsoft 365 applications. Apply time-of-click URL scanning to protect users against malicious links.
4.7 Safe Attachments
Enable Safe Attachments for all users, with stronger protection for administrators, finance staff and other high-risk users.
4.8 SPF Configuration
Publish one accurate SPF record for every sending domain. The record should include only approved Microsoft and third-party email services.
4.9 DKIM Configuration
Enable DKIM signing for every custom domain used to send email through Microsoft 365 or another approved email platform.
4.10 DMARC Configuration
Implement DMARC after validating SPF and DKIM. Progress from monitoring to quarantine and then rejection after confirming all legitimate email sources.
4.11 External Sender Identification
Enable Microsoft 365 external sender identification or an approved external-email banner to help users recognise messages originating outside the organisation.
4.12 External Auto-Forwarding
Block automatic email forwarding to external domains by default. Permit forwarding only through formally approved and documented exceptions.
4.13 Authenticated SMTP
Disable SMTP AUTH across the organisation unless required by an approved application. Prefer OAuth and restrict exceptions to dedicated application accounts.
4.14 Mail Flow Rules and Connectors
Review transport rules, mail connectors, approved domains, IP allowlists and filtering bypass rules quarterly. Avoid broad rules that bypass spam, phishing or malware protection.
4.15 Mailbox Permissions
Regularly review Full Access, Send As, Send on Behalf, delegate access and forwarding permissions assigned to user mailboxes.
4.16 Shared Mailboxes
Provide shared-mailbox access only to approved named users or groups. Block direct sign-in and review shared-mailbox membership quarterly.
4.17 User Reporting
Enable the Report Message or Report Phishing capability. Establish a process for reviewing, investigating and responding to user-reported messages.
4.18 Quarantine Management
Configure quarantine policies and notifications appropriate to each threat category. Restrict the release of malware and high-confidence phishing messages to authorised administrators.
4.19 Mailbox Auditing
Confirm that mailbox auditing is enabled. Monitor mailbox-rule creation, forwarding changes, permission changes and unusual mailbox access.
4.20 Email Security Monitoring
Regularly review threat-protection, mail-flow, auto-forwarding, restricted-user, phishing and malware reports.
5. Device Management – Microsoft Intune
5.1 Intune Management Authority
Confirm that Microsoft Intune is the approved Mobile Device Management authority and that all required Microsoft service connectors are properly configured and healthy.
5.2 Automatic Enrolment
Enable automatic Intune enrolment for licensed users who access business information from organisation-managed devices.
5.3 Enrolment Restrictions
Block unsupported platforms, obsolete operating-system versions and unauthorised device manufacturers where applicable.
5.4 Personally Owned Devices
Block personally owned device enrolment when only corporate devices are permitted. Use Mobile Application Management and App Protection Policies where approved BYOD access is required.
5.5 Device Enrolment Limits
Set a reasonable maximum number of devices that each user can enrol in Microsoft Intune.
5.6 Windows Autopilot
Use Windows Autopilot for consistent corporate-device provisioning, Microsoft Entra joining, Intune enrolment and security-policy deployment.
5.7 Intune Administration
Apply Intune Role-Based Access Control, least privilege and scope tags. Do not use Global Administrator accounts for routine device-management activities.
5.8 Pilot and Production Groups
Maintain separate pilot and production assignment groups for applications, configuration profiles, security baselines and operating-system updates.
5.9 Intune Security Baselines
Deploy the current Microsoft Intune Windows security baseline after compatibility testing. Review and test new baseline versions before migration.
5.10 Configuration Profiles
Centrally manage Windows, browser, OneDrive, Microsoft 365 Apps, firewall, encryption and device-restriction settings through Intune configuration profiles.
5.11 Application Management
Deploy approved business applications through Microsoft Intune or Company Portal. Restrict unapproved and obsolete software where possible.
5.12 Mobile Application Protection
Apply App Protection Policies to Outlook, Teams, OneDrive and Microsoft 365 mobile applications, particularly when users access corporate data from personal devices.
5.13 Windows Update Management
Configure pilot and production Windows update rings with installation deadlines, restart controls and expedited security-update procedures.
5.14 Feature Update Management
Control approved Windows feature versions and prevent devices from remaining on unsupported or end-of-life releases.
5.15 Device Inventory
Review enrolled, inactive, duplicated, unmanaged and noncompliant devices every month.
5.16 Device Retirement and Wipe
Use Retire for removing organisational data from approved personal devices. Use Wipe or Autopilot Reset for lost, compromised or reassigned corporate devices.
5.17 Policy Monitoring
Regularly review configuration conflicts, policy deployment failures and devices that have stopped communicating with Microsoft Intune.
6. Endpoint Protection – Microsoft Defender
6.1 Endpoint Onboarding
Onboard all supported corporate Windows and macOS devices to Microsoft Defender for Business.
6.2 Sensor Health
Monitor endpoints that are inactive, misconfigured, not reporting or unsuccessfully onboarded to Microsoft Defender.
6.3 Real-Time Protection
Keep Microsoft Defender Antivirus real-time protection enabled on all supported endpoints.
6.4 Behaviour Monitoring
Enable behaviour monitoring and script scanning to detect suspicious actions that may not be identified through traditional file scanning.
6.5 Cloud-Delivered Protection
Enable cloud-delivered protection and automatic security-intelligence updates for faster detection of emerging threats.
6.6 Automatic Sample Submission
Enable safe automatic sample submission according to the organisation’s privacy and security requirements.
6.7 Tamper Protection
Enable Tamper Protection to prevent users, malware and unauthorised processes from modifying important Defender security settings.
6.8 Potentially Unwanted Applications
Configure Potentially Unwanted Application protection in Block mode.
6.9 Network Protection
Enable Microsoft Defender Network Protection to block malicious and suspicious domains, URLs and internet content.
6.10 Attack Surface Reduction
Deploy Microsoft-recommended Attack Surface Reduction rules in Audit mode. Validate business applications and progressively move compatible rules into Block mode.
6.11 Controlled Folder Access
Test Controlled Folder Access in Audit mode and enable it for systems handling important data where application compatibility allows.
6.12 Microsoft Defender Firewall
Keep Microsoft Defender Firewall enabled for Domain, Private and Public network profiles.
6.13 Web Content Filtering
Configure web-content filtering categories according to the organisation’s security, compliance and acceptable-use requirements.
6.14 Removable Media
Audit removable-storage activity and restrict USB write or execute access according to business requirements. Maintain controlled exceptions for approved devices.
6.15 Vulnerability Management
Regularly review exposed software, known vulnerabilities, missing updates and Microsoft Defender security recommendations.
6.16 Antivirus Exclusions
Keep antivirus exclusions to the minimum required. Document the owner, justification, scope and expiry or review date for every exclusion.
6.17 Incident Handling
Review Microsoft Defender incidents and alerts daily. Assign an owner and record investigation, containment and remediation actions.
6.18 Action Centre
Review automated remediation actions and pending approvals. Verify that affected endpoints return to a healthy and protected state.
7. Device Security and Compliance
7.1 Platform Compliance Policies
Create separate compliance policies for Windows, macOS, Android and iOS where those device platforms are permitted.
7.2 Devices Without Compliance Policies
Configure devices without an assigned compliance policy to be treated as noncompliant.
7.3 BitLocker Encryption
Require BitLocker encryption on corporate Windows devices. Securely store recovery keys in Microsoft Entra ID.
7.4 Secure Boot and TPM
Require Secure Boot and supported Trusted Platform Module capabilities for managed Windows devices.
7.5 Code Integrity
Require operating-system code integrity where supported by the device hardware and Windows version.
7.6 Antivirus Status
Require an active and up-to-date antivirus and antispyware solution on managed devices.
7.7 Firewall Status
Require the host-based firewall to remain enabled on managed endpoints.
7.8 Supported Operating Systems
Define minimum supported operating-system versions. Mark unsupported or end-of-life devices as noncompliant.
7.9 Device Threat Level
Integrate Microsoft Defender device risk with Intune compliance. Mark devices above the organisation’s accepted threat level as noncompliant.
7.10 Windows Hello for Business
Deploy Windows Hello for Business using a secure PIN or biometric authentication backed by the enrolled device.
7.11 Password and PIN Security
Apply appropriate password or PIN length, complexity, retry and lockout requirements to managed devices.
7.12 Screen Lock
Automatically lock devices after an approved period of inactivity and require authentication before access resumes.
7.13 Local Administrator Access
Remove unnecessary local-administrator access. Maintain separate privileged accounts for approved device administrators.
7.14 Windows LAPS
Use Windows Local Administrator Password Solution to generate, rotate and securely store unique local-administrator passwords.
7.15 Rooted or Jailbroken Devices
Mark rooted or jailbroken mobile devices as noncompliant and block them from accessing corporate applications and information.
7.16 Conditional Access Enforcement
Use Conditional Access to prevent noncompliant devices from accessing Microsoft 365, subject to formally approved exceptions.
7.17 Noncompliance Grace Period
Configure an appropriate remediation grace period. Use a shorter period for critical security failures and a reasonable period for routine compliance issues.
7.18 Compliance Exceptions
Place approved exceptions in controlled groups. Document the justification, responsible owner, compensating controls and expiration date.
7.19 Compliance Review
Review noncompliant devices, policy failures and overdue remediation actions at least weekly.
8. Collaboration Security – Teams, SharePoint and OneDrive
8.1 External Sharing
Allow external sharing only where there is a valid business requirement. Prefer authenticated guest access instead of anonymous Anyone links.
8.2 Default Sharing Link
Configure Specific People as the default link type when users share information externally.
8.3 Anonymous Links
Disable Anyone links by default. Where anonymous links are permitted, restrict them to view-only access and apply a short expiration period.
8.4 Domain Restrictions
Use allowed-domain or blocked-domain lists for regular business partners and prohibited external organisations.
8.5 Guest Access Expiration
Configure guest-access expiration where supported. Periodically require reauthentication or access renewal for continuing collaboration.
8.6 Unmanaged Devices
Apply limited web-only access or prevent downloads from unmanaged devices when users access sensitive SharePoint and OneDrive content.
8.7 Teams External Access
Permit external Teams chat only with approved organisations where practical. Block inbound contact from unmanaged Teams accounts unless required.
8.8 Teams Guest Access
Enable only the guest capabilities required for business collaboration. Restrict guest calling, meetings, messaging and content access appropriately.
8.9 Meeting Lobby
Require anonymous and untrusted participants to wait in the meeting lobby. Prevent anonymous users from starting meetings.
8.10 Presenter Rights
Configure external meeting participants as attendees by default. Grant presenter permissions only when approved by the meeting organiser.
8.11 Recording and Transcription
Restrict meeting recording and transcription to approved users. Inform participants and apply retention requirements to recordings and transcripts.
8.12 Teams Applications
Allow only approved Microsoft, third-party and custom Teams applications. Review application permissions and data access before approval.
8.13 Team and Site Creation
Restrict Team and SharePoint site creation or implement an approved creation and naming process. Important Teams and sites should have at least two owners.
8.14 Permission Reviews
Review SharePoint site owners, members, visitors, sharing links and guests quarterly. Remove direct and inherited access that is no longer required.
8.15 Safe Attachments
Enable Microsoft Defender Safe Attachments protection for SharePoint, OneDrive and Microsoft Teams.
8.16 Infected File Downloads
Prevent users and administrators from downloading files that Microsoft Defender has identified as malicious.
8.17 Sharing Monitoring
Monitor external sharing, anonymous links, unusual downloads, guest access and changes to site permissions.
8.18 Collaboration Lifecycle Management
Identify inactive, ownerless and obsolete Teams and SharePoint sites. Archive or remove them through an approved governance process.
9. Data Protection and Compliance
9.1 Data Classification
Establish an approved data-classification scheme such as Public, Internal, Confidential and Highly Confidential.
9.2 Data Ownership
Assign accountable owners to important data repositories. Data owners should approve access, external sharing, retention and deletion requirements.
9.3 Sensitivity Labels
Publish a simple and understandable set of sensitivity labels for emails and documents. Avoid creating excessive or confusing labels.
9.4 Label-Based Protection
Apply encryption, visual markings and sharing restrictions to Confidential and Highly Confidential information where required.
9.5 Default Labelling
Configure an appropriate default sensitivity label. Where supported, require users to provide business justification when downgrading protected information.
9.6 Data Loss Prevention
Configure Microsoft Purview DLP policies for Exchange, SharePoint and OneDrive to identify and protect personal, financial, employee, client and intellectual-property information.
9.7 DLP User Guidance
Use DLP policy tips to warn users before sensitive information is shared. Permit an override only where appropriate and require business justification.
9.8 DLP Policy Rollout
Deploy DLP policies initially in simulation or test mode. Validate detected matches and progressively enable user notifications and enforcement.
9.9 Sensitive Information Types
Review Microsoft’s built-in sensitive-information types and create organisation-specific types where the available templates do not meet business requirements.
9.10 Retention Schedule
Define retention periods based on legal, contractual, regulatory and operational requirements rather than relying only on technical defaults.
9.11 Retention Policies
Apply Microsoft Purview retention policies to Exchange, SharePoint, OneDrive and relevant Teams content based on the approved retention schedule.
9.12 Deleted File Preservation
Use retention policies to preserve protected OneDrive and SharePoint content even when users delete the active copy.
9.13 Legal Hold and eDiscovery
Maintain a documented legal-hold and eDiscovery process. Confirm that the available Microsoft 365 licence supports the required hold, search or investigation capability.
9.14 Audit Logging
Confirm that Microsoft Purview Audit is enabled. Microsoft Purview Audit Standard generally retains supported audit records for 180 days.
9.15 Encryption
Use Microsoft service encryption for information in transit and at rest. Apply sensitivity-label encryption to highly sensitive information where required.
9.16 Offboarding Data
Transfer required OneDrive, mailbox and business records to an authorised manager or repository before removing the user’s licence and account.
9.17 Data Recovery
Document Microsoft 365 recycle-bin, version-history, retention and restore capabilities. Test important recovery procedures periodically.
9.18 Independent Backup
Microsoft retention provides data preservation but is not a complete independent backup. Consider a third-party Microsoft 365 backup solution where separate copies, extended recovery or protection from configuration failure are required.
9.19 Compliance Review
Regularly review Microsoft Compliance Manager recommendations, DLP incidents, retention exceptions and unresolved compliance actions.
10. Monitoring, Governance and Operational Readiness
10.1 Security Ownership
Define accountable owners for Microsoft Entra ID, Intune, Defender, Exchange Online, Teams, SharePoint, OneDrive and Microsoft Purview.
10.2 Alert Contacts
Configure actively monitored email addresses for security alerts, service incidents, privacy notifications and administrative warnings.
10.3 Defender Incident Monitoring
Review high and critical Microsoft Defender incidents daily. Review lower-severity alerts according to an agreed response time.
10.4 Endpoint Health Monitoring
Monitor device onboarding, antivirus status, exposure, vulnerabilities, sensor health and inactive endpoints.
10.5 Email Security Monitoring
Review phishing, malware, spam, impersonation, restricted-user and automatic-forwarding reports.
10.6 Identity Monitoring
Review administrator sign-ins, unusual locations, failed MFA, legacy authentication, application consent and emergency-account activity.
10.7 Unified Audit Review
Use Microsoft Purview Audit to review relevant user and administrator activities during investigations and scheduled control reviews.
10.8 SIEM Integration
Forward relevant Microsoft Entra, Microsoft 365 and Defender logs to Microsoft Sentinel, Wazuh or another SIEM platform where centralised monitoring or extended retention is required.
10.9 Log-Retention Management
Document native log-retention periods. Configure export or archival when legal, regulatory or investigation requirements exceed the available retention period.
10.10 Microsoft Secure Score
Review Microsoft Secure Score every month. Assign improvement actions and document rejected recommendations, approved exceptions and accepted risks.
10.11 Microsoft 365 Service Health
Monitor Microsoft 365 Service Health for active incidents and advisories affecting the organisation’s tenant.
10.12 Microsoft 365 Message Centre
Review Microsoft 365 Message Centre at least weekly for security changes, feature retirements, changes to defaults and required administrative actions.
10.13 Security Policy Review
Review Conditional Access, Intune, Defender, Exchange, Teams, SharePoint and Purview security policies at least every six months.
10.14 Access Reviews
Review administrators, guests, enterprise-application permissions, shared mailboxes, forwarding rules and sensitive-site access at least quarterly.
10.15 Incident Response Plan
Maintain documented incident-response procedures for compromised accounts, phishing, malware, lost devices, data leakage and unauthorised administrative changes.
10.16 Incident Response Playbooks
Document specific containment actions such as blocking sign-in, revoking sessions, resetting credentials, isolating devices and removing malicious email.
10.17 Emergency Access Testing
Test emergency-access accounts at least quarterly and immediately after major identity or Conditional Access policy changes.
10.18 Recovery Testing
Periodically test mailbox, OneDrive, SharePoint, endpoint and configuration-recovery procedures.
10.19 Configuration Change Control
Record significant administrative changes, approvals, test results, implementation times and rollback information.
10.20 Security Reporting
Prepare monthly reports covering security incidents, vulnerable devices, patch compliance, noncompliant devices, phishing, DLP events and Microsoft Secure Score.
10.21 Security Awareness
Train users to identify phishing, protect MFA requests, handle sensitive data correctly and report suspicious emails, messages and devices.
10.22 Operational Documentation
Maintain current documentation covering tenant configuration, administrator contacts, vendors, escalation paths, network information and technical runbooks.
11. Microsoft 365 Business Premium Licensing Considerations
11.1 Microsoft Entra ID P2 Capabilities
Risk-based Conditional Access, complete Microsoft Entra ID Protection, Privileged Identity Management and advanced automated access reviews generally require Microsoft Entra ID P2 or another qualifying licence.
11.2 Microsoft Defender for Identity
Microsoft Defender for Identity is not included in the standard Microsoft 365 Business Premium licence and requires an appropriate add-on or upgraded security subscription.
11.3 Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps is not included in the standard Business Premium package and requires additional licensing.
11.4 Defender for Office 365 Plan 2
Advanced email investigation, expanded threat hunting, attack simulation training and other Plan 2 capabilities require Defender for Office 365 Plan 2 or a qualifying security add-on.
11.5 Defender for Endpoint Plan 2
Capabilities such as advanced hunting, live response and extended endpoint data retention may require Defender for Endpoint Plan 2 or an appropriate security add-on.
11.6 Advanced Microsoft Purview Controls
Endpoint DLP, certain Teams message DLP capabilities, automatic sensitivity labelling, advanced records management, Insider Risk Management and Communication Compliance may require additional Microsoft Purview licences.
11.7 Extended Audit Retention
Extended or customised audit retention beyond the standard licence entitlement may require Microsoft Purview Audit Premium or another qualifying subscription.
11.8 Licensing Validation
Validate licensing against the final technical design before committing advanced controls to the implementation scope. Features shown in an administrative portal should not automatically be assumed to be fully licensed for every user.
