Microsoft 365 Security

Microsoft 365 Security Baseline Review

Altitude reviews your Microsoft 365 tenant against a practical security baseline — authentication, privileged access, external sharing, devices, logging and configuration drift — then gives you a prioritised action plan.

How Securely Is Your Microsoft 365 Tenant Actually Configured?

Microsoft 365 contains powerful security controls, but licensing them does not mean they are configured correctly. Buying Microsoft security tools does not automatically mean the security controls have been implemented. Microsoft 365 security is a configuration discipline — not a licensing decision.

Most Microsoft 365 Security Gaps Are Not Missing Products

Businesses with Microsoft 365 Business Premium, Defender, Intune and Entra may still have: weak or inconsistent MFA methods; excessive administrator privilege; former IT supplier accounts still active; unmanaged guest access; uncontrolled external sharing; unmanaged devices; Conditional Access exclusions; incomplete logging; applications with excessive permissions; configuration drift; Secure Score recommendations never reviewed.

Who This Review Is For

Suitable for businesses that use Microsoft 365 — particularly those that have never had a tenant security review, have changed IT provider, are preparing for Cyber Essentials, have experienced a security incident, use guest access heavily, have deployed Intune or have not reviewed security configuration for 12 months or more.

Seven Review Areas

1 — Authentication

MFA coverage, authentication methods, passkeys and FIDO2, Microsoft Authenticator, legacy authentication, Conditional Access, authentication strengths, administrator account authentication, emergency-access accounts. Outcome: identify weak or inconsistent authentication controls. MFA is the starting point. The quality of the authentication method matters too.

2 — Privileged Access

Global Administrators, privileged roles, former IT suppliers, external administrators, shared accounts, day-to-day use of administrator accounts, standing privilege, PIM where licensed, GDAP where applicable. Outcome: identify excessive or unnecessary administrative access. Every privileged account should have a current owner and a current reason for existing.

3 — External Sharing

SharePoint and OneDrive sharing defaults, Teams guest and external access, anonymous link configuration and expiry, guest user accounts and lifecycle, external domain controls, sensitivity controls where licensed. Outcome: identify unnecessary external exposure without breaking legitimate collaboration. External sharing is useful. Uncontrolled external sharing is a security problem.

4 — Devices

Microsoft Intune enrolment and compliance, encryption, Microsoft Defender antivirus and firewall, supported operating systems, Windows update status, mobile device access, unmanaged devices, Conditional Access device compliance integration. Outcome: establish whether trusted identities are connecting from trusted devices. A valid password and MFA challenge do not automatically make the device trustworthy.

5 — Logging and Visibility

Microsoft Purview Audit status and retention, Microsoft Entra sign-in activity, administrator change logging, risky users and sign-ins, suspicious downloads, Defender alerts and alert ownership. Outcome: identify whether important activity can actually be investigated. Logging matters only if the business can use it when something goes wrong.

6 — Security Baseline

Identity, Conditional Access and roles; Exchange Online anti-phishing, anti-spam, malware, external forwarding and mailbox settings; SharePoint and OneDrive sharing and external access; Teams guest and external access and application controls; device compliance, encryption, Defender and updates; data loss prevention, sensitivity and retention where licensed. Outcome: structured comparison of current configuration against a practical security baseline.

7 — Security Monitoring and Drift

Microsoft Secure Score and outstanding improvement actions, configuration drift, Conditional Access changes, administrator changes, guest growth, risky users, risky sign-ins, application consent, supplier access, device compliance trends. Outcome: establish what should be monitored after the initial review. A secure configuration today can become an insecure configuration gradually without anybody deliberately changing the security strategy.

From the Blog

Practical Microsoft 365 security insight from the Altitude team.

What Does CIS Have to Do With This?

The Center for Internet Security publishes the Microsoft 365 Foundations Benchmark — an independent set of evidence-based secure-configuration recommendations. The current version is CIS Microsoft 365 Foundations Benchmark v7.0.0. Altitude uses it as one reference framework. The benchmark informs the review. It does not replace judgement.

Secure Score Is Useful — But It Is Not the Whole Answer

Microsoft Secure Score helps identify improvement actions, show current posture and track progress. Microsoft itself states that Secure Score is not a guarantee against breach and that not every recommendation suits every organisation. The objective is not to chase 100%. The objective is to understand every important security decision.

What the Review Produces

Executive summary; seven-control traffic-light scorecard; prioritised action plan (Critical / High / Medium / Low / Informational); Secure Score review; CIS alignment observations; privileged access review; external sharing review; device security summary where in scope; remediation plan; management discussion in plain English.

What the Review Does Not Include

The review does not automatically include implementation of every recommendation, Microsoft licence upgrades, Cyber Essentials certification, penetration testing, vulnerability scanning, ISO 27001, SOC services, incident response, full Intune deployment, full Purview implementation or full Defender deployment. The review tells you what should change. Remediation can then be agreed rather than silently included in an undefined project.

Security Configuration Does Not Stay Fixed

Microsoft 365 changes continuously — users join and leave, guest accounts accumulate, applications gain consent, administrators make changes, licensing changes, new recommendations appear. Microsoft 365 needs an Operational Heartbeat: authentication, privilege, sharing, devices, logging, risk and configuration drift should be reviewed rather than assumed to remain secure.

How the Review Works

1. Discover — confirm tenant size, licences, users, devices and requirements. 2. Review — assess current configuration, Secure Score and relevant CIS controls. 3. Prioritise — identify immediate risk, quick wins and licence dependencies. 4. Report — executive summary, scorecard, findings and action plan. 5. Improve — scope agreed remediation separately. 6. Maintain — optionally add recurring review to the Operational Heartbeat.