For many businesses Microsoft 365 is the central identity and communications platform. Access controls should therefore go beyond passwords.
Start with a clear baseline
Define a small, understandable security baseline before creating many individual policies.
- MFA for users and administrators
- block legacy authentication
- special handling for privileged roles
- planned emergency access
Use device and location context carefully
Managed devices and known contexts can be treated differently from unknown clients or risky sign-ins.
- consider device state
- differentiate by risk
- minimize exceptions
- do not blindly trust locations
Exceptions are part of the architecture
Service accounts and special applications often require exceptions. They should be documented, justified and reviewed.
- assign an owner
- document technical necessity
- define review dates
- consider compensating controls
Policies should be testable and auditable
Purpose, scope and effect should be documented so technical controls can be reviewed and evidenced.
- document policy purpose and scope
- use report-only before enforcement
- review sign-in logs
- retain evidence for important controls
