Microsoft 365 hardening security baselines

Preparation

Configuration

  • Navigate to the Microsoft 365 admin center.
  • Go to 'Users' and select 'Active users'.
  • Click on 'Multi-factor authentication' and enable it for all users.
  • Go to 'Azure Active Directory' in the Microsoft 365 admin center.
  • Navigate to 'Security' and then 'Authentication methods'.
  • Set password policies such as length, complexity, and expiration.
  • Access the 'Security & Compliance Center' in Microsoft 365 admin center.
  • Go to 'Audit log search' and enable auditing for relevant activities.
  • Set up alerts for suspicious activities.
  • Access 'Azure Active Directory' in the Microsoft 365 admin center.
  • Navigate to 'Security' and then 'Authentication methods'.
  • Disable legacy protocols such as POP, IMAP, and SMTP.
  • Go to the 'Security & Compliance Center' in Microsoft 365 admin center.
  • Navigate to 'Data loss prevention' and create policies to protect sensitive information.
  • Apply these policies to relevant users and data.
  • Access 'Microsoft 365 admin center' and go to 'Settings'.
  • Navigate to 'Services & add-ins' and select 'Data encryption'.
  • Enable encryption for data at rest and in transit.

Endpoint Protection

Email Security

Access Control

Incident Response

Related Checklists