What should a Microsoft 365 security baseline include?

Short answer

A Microsoft 365 security baseline is the documented minimum set of security settings every tenant should meet. At its core: multifactor authentication for all users, stronger protection for administrators, legacy authentication blocked, and email, sharing and device settings hardened. Use Microsoft security defaults or Conditional Access to enforce it, Microsoft Secure Score to track it, and CISA's SCuBA baselines as a detailed reference.

Start with identity: MFA and legacy authentication

Most Microsoft 365 compromises begin with a stolen or guessed password. Microsoft's security defaults for Entra ID enforce a basic identity baseline at no extra cost: all users register for multifactor authentication, administrators must use MFA, users are prompted for MFA when necessary, legacy authentication protocols are blocked, device code flow is blocked, and access to Azure management tools requires MFA.

Microsoft states that legacy authentication does not support MFA, which is why an attacker can use an older protocol such as IMAP or POP3 to bypass an MFA policy. Blocking it is not optional in a serious baseline.

Security defaults or Conditional Access?

Security defaults are on or off with no customization. Microsoft positions them for organizations that are getting started or that use the free tier of Entra ID. Conditional Access requires at least Microsoft Entra ID P1 licensing and lets you build specific policies, for example requiring compliant devices, blocking risky locations or excluding emergency access accounts.

You cannot run both. Microsoft notes that organizations replacing security defaults with Conditional Access must disable security defaults, and should immediately enable policies that keep the same protections: MFA for all users, MFA for admins, MFA for Azure management and blocking legacy authentication. Microsoft also recommends two cloud-only emergency access accounts.

Beyond identity: what else belongs in the baseline

  • Admin hygiene: separate admin accounts, least-privilege roles, a minimal number of Global Administrators
  • Email protection: anti-phishing, safe links and attachment scanning in Microsoft Defender for Office 365 where licensed
  • Sharing controls in SharePoint, OneDrive and Teams, especially for external and anonymous links
  • Device management and compliance requirements for laptops and phones
  • Audit logging enabled and reviewed
  • A documented exception process, so deviations are deliberate and recorded

Measure it: Secure Score and CISA SCuBA

Microsoft Secure Score, in the Microsoft Defender portal, measures your security posture, with a higher number indicating more recommended actions taken. It covers Entra ID, Exchange Online, SharePoint Online, Teams, Defender products and others. Microsoft is clear that it is not an absolute measure of breach likelihood or a guarantee.

For a more prescriptive reference, CISA's Secure Cloud Business Applications (SCuBA) project publishes secure configuration baselines for Microsoft 365. CISA finalized baselines for seven products in December 2023, including Entra ID (then Azure Active Directory), Exchange Online, Defender for Office 365, SharePoint Online and OneDrive, Teams, Power Platform and Power BI. Its no-cost ScubaGear tool checks a tenant against those policies.

Common follow-up questions

Are Microsoft security defaults enough for a small business?

They are a strong starting point and far better than nothing, because they enforce MFA and block legacy authentication at no extra cost. Companies with Entra ID P1 licensing, compliance obligations or a need for exceptions and device-based rules should move to Conditional Access.

What is a good Microsoft Secure Score?

There is no universal passing number. Use Secure Score to track progress and prioritize recommended actions, and compare against similar organizations in the portal. Microsoft notes that not every recommendation fits every environment, and that a high score does not guarantee you will not be breached.

Do CISA SCuBA baselines apply to private companies?

They were built for federal agencies, but CISA makes the baselines and the ScubaGear assessment tool publicly available, and private organizations can use them as a detailed, vendor-neutral reference. Treat them as guidance and adapt them to your licensing and business needs.

Need help with this?

LAN Service Group administers and secures Microsoft 365 for small and mid-size businesses, including GCC High migration and administration for companies with defense-related compliance requirements.

Talk to LAN Service Group (888) 281-7243

Sources