Multifactor authentication for everyone
Enforce MFA for all users and admins via Conditional Access. New tenants leave most accounts protected by a password alone.
Secure baseline configuration of your Microsoft 365 tenant, aligned with Microsoft best practices and the CIS Microsoft 365 Foundations Benchmark — so your environment is not left in insecure defaults.
Aligned with Microsoft best practices and the CIS Microsoft 365 Foundations Benchmark.
Enforce MFA for all users and admins via Conditional Access. New tenants leave most accounts protected by a password alone.
Disable legacy/basic auth protocols (POP, IMAP, SMTP AUTH and older clients) that bypass MFA and are allowed by default.
Policies that require MFA, block legacy auth and react to sign-in and user risk (Identity Protection), plus device-based access controls.
Roll out Microsoft Authenticator with number matching and passkeys (FIDO2); remove weak SMS and voice methods.
Keep only a few Global Admins, assign least-privilege roles, and enable PIM for just-in-time, zero-standing admin access.
Two cloud-only emergency admin accounts, excluded from Conditional Access and monitored, so you are never locked out of the tenant.
Enable SSPR with strong methods, banned-password protection and smart lockout against password-spray attacks.
Block users from registering apps, creating tenants and consenting to third-party apps; require admin or verified-publisher consent (auto-block unconfigured OAuth).
Tighten SharePoint/OneDrive sharing (default allows “Anyone” links) and Teams external/guest access to authenticated guests only.
Enable DKIM (off by default) and publish a DMARC quarantine/reject policy to stop spoofing of your domain.
Block external auto-forwarding, disable legacy mail protocols per mailbox, and confirm mailbox audit logging is on.
Apply the preset Standard/Strict security policies: anti-phishing and impersonation protection, Safe Links and Safe Attachments.
Onboard Defender for Business, set Intune compliance and mobile app protection policies, and require compliant devices via Conditional Access (Business Premium).
Sensitivity labels and Data Loss Prevention (DLP) policies for sensitive data — a new tenant ships with none.
Review oversharing and apply labels and DLP before enabling Copilot, so AI cannot surface data users should not see.
Confirm the unified audit log and retention, configure alert policies for risky activity, and track Microsoft Secure Score over time.