De4sec
De4sec Technology
de4sec.technology
๐ŸŒ AU + KE

Microsoft 365 Security Guide

A comprehensive guide to securing your Microsoft 365 tenant โ€” identity, email, devices, data, and compliance โ€” using built-in security features.

Prepared by
De4sec Technology
Contact
support@de4sec.technology
Edition
2026 ยท March
CONFIDENTIAL ยท FOR CLIENT USE ONLY
Contents
  1. Microsoft 365 Security: What You Already Have
  2. Identity Security
  3. Email Security
  4. Device and Endpoint Security
  5. Data Protection and Compliance
  6. De4sec Microsoft 365 Security Service
01

Microsoft 365 Security: What You Already Have

If your business uses Microsoft 365, you already have access to a significant security capability โ€” most of which is not enabled by default. The gap between what Microsoft provides and what most organisations actually have configured is the primary cause of Microsoft 365-related incidents.

FeatureRequired ActionWhere to Configure
MFA for all usersEnable and enforceEntra ID > Security > Conditional Access
Safe Links and AttachmentsConfigure policySecurity.microsoft.com > Email & collab
Unified audit logEnableCompliance.microsoft.com > Audit
Microsoft Secure ScoreReview and actSecurity.microsoft.com > Secure Score
Device complianceDeploy IntuneIntune.microsoft.com
DLP policiesCreate policiesCompliance.microsoft.com > DLP

Microsoft's default configuration is designed for broad compatibility, not security. Securing your tenant requires deliberate configuration changes beyond the defaults.

02

Identity Security

Conditional Access Policies

โœ“Require MFA for all users โ€” no exceptions
โœ“Block legacy authentication protocols โ€” these bypass MFA
โœ“Require compliant device for sensitive apps (when Intune is deployed)
โœ“Block access from high-risk sign-ins โ€” Entra ID Identity Protection integration
โœ“Restrict admin portal access to managed devices only

Admin Role Security

โœ“Global Admin accounts separate from daily-use accounts โ€” no mailbox on GA accounts
โœ“Use role-specific admin roles โ€” not Global Admin for everything (Exchange Admin, Teams Admin, etc.)
โœ“Enable Privileged Identity Management โ€” Just-in-Time admin role activation
โœ“Require MFA for all admin role activation

User Account Security

โœ“Self-Service Password Reset with MFA verification โ€” reduce helpdesk burden
โœ“Entra ID Identity Protection โ€” risk policies for users and sign-ins
โœ“Named locations โ€” flag sign-ins from countries you don't operate in
โœ“Passwordless authentication for supported users
03

Email Security

Exchange Online Protection (included in all licences)

โœ“Anti-spam policies โ€” tune confidence thresholds
โœ“Anti-malware policy โ€” block common malicious file types
โœ“Spoofing protection โ€” built-in for your tenant domains

Defender for Office 365 (Business Premium / E3+addon)

โœ“Safe Links โ€” time-of-click URL detonation
โœ“Safe Attachments โ€” sandbox file detonation
โœ“Anti-phishing โ€” impersonation protection for key users and domains
โœ“Spoof intelligence โ€” cross-domain spoofing detection

Email Authentication

โœ“SPF record: publish and test
โœ“DKIM: enable for all sending domains, include marketing/automation tools
โœ“DMARC: start at p=none, monitor, move to p=quarantine, then p=reject
โœ“DMARC reporting: configure external reporting to review spoofing attempts
04

Device and Endpoint Security

Microsoft Intune

โœ“Enrol all company-owned devices โ€” Windows, macOS, iOS, Android
โœ“Configure device compliance policies โ€” encryption, OS version, screen lock, antivirus
โœ“Apply Conditional Access requiring compliant device for corporate data access
โœ“Deploy Intune Configuration Profiles โ€” browser policies, Wi-Fi, VPN settings

Defender for Endpoint

โœ“Onboard all enrolled devices to MDE via Intune
โœ“Configure security baseline via Endpoint Security policies
โœ“Enable Tamper Protection โ€” prevent attackers from disabling security
โœ“Attack Surface Reduction rules โ€” at minimum enable in audit mode, then block mode after review

Application Management

โœ“Intune Application Protection Policies โ€” protect corporate data in mobile apps without full MDM
โœ“Block copy/paste from corporate apps to personal apps
โœ“Remote wipe of corporate data from personal devices (MAM wipe)
05

Data Protection and Compliance

Microsoft Purview (Compliance portal)

โœ“Enable Unified Audit Log โ€” required for any security investigation
โœ“Sensitivity labels โ€” classify documents: Public, Internal, Confidential, Highly Confidential
โœ“DLP policies โ€” prevent sensitive data leaving via email, Teams, or SharePoint sharing
โœ“Retention policies โ€” define data lifecycle: how long to keep, what to delete
โœ“Communication compliance โ€” optional, for regulated industries requiring message monitoring

Secure Score

Microsoft Secure Score (security.microsoft.com > Secure Score) is the single most actionable starting point for Microsoft 365 security improvement. It scores your current configuration, shows what's missing, and provides direct implementation guidance.

โœ“Target: 60%+ for SMB baseline
โœ“Each recommendation includes effort estimate and security impact
โœ“Prioritise: identity recommendations highest impact, email second, device third
06

De4sec Microsoft 365 Security Service

Tenant Audit
Review current configuration against security best practices. Identify gaps in identity, email, device, and data protection.
Secure Baseline
Implement Conditional Access, email security, Intune, DLP, sensitivity labels, and audit logging.
Secure Score Optimisation
Work through prioritised Secure Score recommendations. Target 65%+ within 90 days of engagement.
Ongoing Management
Monthly Secure Score review, alert monitoring, quarterly policy review, patch compliance reporting.
// NEXT STEP

Ready to implement this?

De4sec provides hands-on implementation. Book a free discovery call โ€” we assess your environment at no cost.

Book a Free Discovery Call โ†’de4sec.technology
De4sec
ยฉ 2026 DE4SEC TECHNOLOGY. ALL RIGHTS RESERVED.