Multifactor authentication for everyone
Enforce MFA for all users and admins with Conditional Access policies, replacing the basic security defaults a new tenant starts with so you get granular, risk-aware control.
Secure baseline configuration of your Microsoft 365 tenant, aligned with Microsoft best practices and the CIS Microsoft 365 Foundations Benchmark, so your environment is not left in insecure defaults.
Aligned with Microsoft best practices and the CIS Microsoft 365 Foundations Benchmark.
Enforce MFA for all users and admins with Conditional Access policies, replacing the basic security defaults a new tenant starts with so you get granular, risk-aware control.
Turn off legacy/basic auth protocols (POP, IMAP, SMTP AUTH and older clients) that bypass MFA. Microsoft has retired most basic auth in Exchange Online, and we confirm remaining paths such as SMTP AUTH stay disabled.
Policies that require MFA, block legacy auth and react to sign-in and user risk (Identity Protection), plus device-based access controls.
Roll out Microsoft Authenticator with number matching and passkeys (FIDO2); remove weak SMS and voice methods.
Keep only a few Global Admins, assign least-privilege roles, and enable PIM for just-in-time, zero-standing admin access.
Two cloud-only emergency admin accounts, excluded from Conditional Access and monitored, so you are never locked out of the tenant.
Enable SSPR with strong methods, banned-password protection and smart lockout against password-spray attacks.
Block users from registering apps, creating tenants and consenting to third-party apps; require admin or verified-publisher consent (auto-block unconfigured OAuth).
Tighten SharePoint/OneDrive external sharing and Teams external and guest access so only authenticated guests can be invited, with anonymous “Anyone” links restricted or turned off.
Enable DKIM for your custom domains and publish a DMARC quarantine/reject policy, so attackers cannot spoof your domain.
Block external auto-forwarding, disable legacy mail protocols per mailbox, and confirm mailbox audit logging is on.
Apply the preset Standard/Strict security policies: anti-phishing and impersonation protection, Safe Links and Safe Attachments.
Onboard Defender for Business, set Intune compliance and mobile app protection policies, and require compliant devices via Conditional Access (Business Premium).
Sensitivity labels and Data Loss Prevention (DLP) policies tailored to your sensitive data, so classification and protection match how your organization actually works.
Review oversharing and apply labels and DLP before enabling Copilot, so AI cannot surface data users should not see.
Confirm the unified audit log and retention, configure alert policies for risky activity, and track Microsoft Secure Score over time.