PD Geek

The Technology Blueprint

A complete guide to building enterprise-grade technology operations. Everything you need to do it yourself - or realize you'd rather have us do it.

How to Build Enterprise Technology - The Right Way

This guide walks through everything you need to build a secure, compliant, well-managed technology environment. We're sharing exactly how we do it for every organization we partner with.

Fair warning: this is comprehensive. There's a reason organizations hire professionals to do this. But if you want to understand what "doing IT right" actually means, keep reading.

Guide Contents

  1. Identity & Access
  2. Device Management
  3. Security Stack
  4. Compliance & Governance
  5. Enterprise Controls
  6. People & Process
  7. Network & Infrastructure
  8. Compliance Frameworks

01 · Identity & Access Management

Identity is the foundation of modern security. Before you secure anything else, you need to control who can access your systems and how. In a Zero Trust model, identity is the new perimeter - every access decision starts here.

Prerequisites

Before starting identity configuration, ensure you have:

  1. Global Administrator access to your Microsoft 365 tenant
  2. Access to your domain registrar's DNS management panel
  3. A list of all users who need accounts
  4. Organizational chart or department structure defined
  5. Microsoft 365 Business Premium, E3, or E5 licenses purchased
  6. A test user account that isn't your admin account

Step 1: Initial Tenant Configuration

Your Microsoft 365 tenant is the container for your entire cloud identity. Configure it correctly from day one.

1.1 Basic Tenant Setup:

  1. Sign up for Microsoft 365 at admin.microsoft.com
  2. Choose your tenant name carefully - this becomes yourorg.onmicrosoft.com and cannot be changed
  3. Set your organization's physical address (required for licensing)
  4. Configure tenant-level settings: timezone, language, release preferences
  5. Enable targeted release for IT admins (get features early for testing)

1.2 Add Your Custom Domain:

  1. Navigate to Settings → Domains → Add domain
  2. Enter your domain (e.g., yourcompany.com)
  3. Add the TXT record to your DNS: MS=ms12345678 (value provided)
  4. Wait for DNS propagation (can take 15 minutes to 48 hours)
  5. Verify the domain in Microsoft 365
  6. Add MX, CNAME, and SPF records for email
  7. Configure DKIM signing for email authentication
  8. Add DMARC record for email security: v=DMARC1; p=quarantine; rua=mailto:dmarc@yourcompany.com

Critical: SPF, DKIM, and DMARC are essential for email deliverability and preventing spoofing. Skip these and your emails may go to spam - or attackers can send email pretending to be you.

1.3 DNS Records Required:

  1. MX Record: yourcompany-com.mail.protection.outlook.com (Priority 0)
  2. SPF (TXT): v=spf1 include:spf.protection.outlook.com -all
  3. DKIM (CNAME): selector1._domainkey → selector1-yourcompany-com._domainkey.yourcompany.onmicrosoft.com
  4. DKIM (CNAME): selector2._domainkey → selector2-yourcompany-com._domainkey.yourcompany.onmicrosoft.com
  5. Autodiscover (CNAME): autodiscover → autodiscover.outlook.com
  6. DMARC (TXT): _dmarc → v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc-reports@yourcompany.com

Estimated time: 2-4 hours + DNS propagation wait

Step 2: Entra ID Foundation Setup

Entra ID (formerly Azure Active Directory) is your cloud identity provider. Every user, app, and device ties back here.

2.1 Navigate to Entra Admin Center:

  1. Go to entra.microsoft.com
  2. Sign in with your Global Administrator account
  3. Familiarize yourself with the navigation: Identity, Protection, Identity Governance

2.2 Configure Tenant Settings:

  1. Identity → Overview → Properties
  2. Set tenant name and technical contact
  3. Configure privacy statement URL (required for compliance)
  4. Enable LinkedIn account connections: OFF (security best practice)
  5. Configure external collaboration settings (restrict by default)

2.3 Create Group Structure:

Groups control access to everything. Plan your structure before creating users.

  1. Department Groups: HR, Finance, Operations, IT, etc.
  2. Role Groups: Executives, Managers, Staff
  3. Access Groups: App-Salesforce-Users, App-EHR-Users, etc.
  4. License Groups: License-M365-E3, License-M365-E5
  5. Security Groups: MFA-Excluded (emergency only), CA-Pilot-Users

Best Practice: Use dynamic groups where possible. They automatically add/remove users based on attributes like department or job title. This eliminates manual group management.

2.4 Configure User Settings:

  1. Identity → Users → User settings
  2. Users can register applications: No
  3. Restrict non-admin users from creating tenants: Yes
  4. Users can create security groups: No
  5. Guest user access restrictions: Most restrictive
  6. Administration center: Restrict access to Azure AD admin portal: Yes

Estimated time: 4-6 hours for complete setup

Step 3: Create Break-Glass Accounts

Before enforcing any security policies, create emergency access accounts. These save you when everything else fails.

3.1 Create Two Break-Glass Accounts:

  1. Create BreakGlass1@yourcompany.onmicrosoft.com (use .onmicrosoft.com, not custom domain)
  2. Create BreakGlass2@yourcompany.onmicrosoft.com
  3. Assign Global Administrator role to both
  4. Generate 128+ character random passwords for each
  5. Do NOT enable MFA on these accounts (they're your backup when MFA fails)
  6. Store credentials in a physical safe and/or secure offline location
  7. Split the password: half with CEO, half with IT director (for accountability)

3.2 Configure Monitoring for Break-Glass:

  1. Create an alert rule in Entra ID for any sign-in to these accounts
  2. Go to Protection → Identity Protection → Alerts
  3. Configure email and SMS notifications to multiple admins
  4. Any use of these accounts should trigger immediate investigation
  5. Test the accounts quarterly (document the test)

Critical: Never use break-glass accounts for daily work. They exist only for emergencies. If you see a sign-in you didn't authorize, assume compromise and rotate credentials immediately.

Estimated time: 1-2 hours

Step 4: Configure Password Policies

Modern password guidance has changed. Length matters more than complexity. Ban common passwords.

4.1 Password Policy Settings:

  1. Go to Protection → Authentication methods → Password protection
  2. Enable custom banned password list
  3. Add company-specific terms: company name, product names, local sports teams
  4. Enable password protection for Windows Server AD (if hybrid)
  5. Set mode to Enforced (not Audit)

4.2 Recommended Password Requirements:

  1. Minimum length: 14 characters (12 absolute minimum)
  2. Complexity: Not required if length is 14+ (NIST guidance)
  3. Expiration: Do not expire passwords (NIST guidance) - rely on MFA instead
  4. History: Remember 24 previous passwords
  5. Lockout: 10 failed attempts, 30-minute lockout

Why No Password Expiration?

NIST SP 800-63B recommends against periodic password changes. Users create predictable patterns (Password1!, Password2!, Password3!). With MFA enforced, password theft alone doesn't grant access. Focus on length and banning common passwords instead.

4.3 Self-Service Password Reset (SSPR):

  1. Go to Protection → Password reset
  2. Enable SSPR for All users (not Selected)
  3. Require 2 authentication methods for reset
  4. Methods: Mobile app notification, Mobile app code, Email, Mobile phone
  5. Disable: Office phone, Security questions (too easily guessed)
  6. Require users to re-confirm authentication info every 180 days
  7. Enable writeback if hybrid (syncs reset passwords to on-prem AD)

Estimated time: 2-3 hours

Step 5: Enforce Multi-Factor Authentication (MFA)

MFA is non-negotiable. It blocks 99.9% of account compromise attacks. Every user, every time.

5.1 Configure Authentication Methods:

  1. Go to Protection → Authentication methods → Policies
  2. Enable Microsoft Authenticator for All users
  3. Configure: Push notifications, Passwordless, Number matching (all enabled)
  4. Enable FIDO2 Security Keys for admins (hardware keys like YubiKey)
  5. Enable Temporary Access Pass for onboarding new users
  6. Enable SMS as backup only (it's vulnerable to SIM swapping)
  7. Disable Voice call (easily intercepted)
  8. Disable Email OTP for primary use (use for guests only)

Security Note: SMS-based MFA is better than no MFA, but it's vulnerable to SIM swapping attacks. Use app-based authentication (Microsoft Authenticator) as the primary method. For privileged accounts, require hardware security keys (FIDO2).

5.2 Enable Number Matching and Additional Context:

  1. Go to Authentication methods → Microsoft Authenticator
  2. Enable number matching: Enabled for all users
  3. Show application name: Enabled
  4. Show geographic location: Enabled

Number matching prevents MFA fatigue attacks where attackers spam push notifications hoping users approve one by accident.

5.3 Plan Your MFA Rollout:

  1. Week 1: IT team and early adopters register for MFA
  2. Week 2: Announce to all users, provide documentation
  3. Week 3: Mandatory registration deadline - enable registration campaign
  4. Week 4: Enforce MFA via Conditional Access (report-only first)
  5. Week 5: Switch Conditional Access to Enabled
  6. Provide helpdesk support during rollout for locked-out users

5.4 Troubleshooting Common MFA Issues:

  1. "I don't get push notifications" - Check phone has internet, app is updated, notifications enabled
  2. "My code doesn't work" - Phone time must be accurate (enable automatic time)
  3. "I got a new phone" - Use Temporary Access Pass or backup methods to re-register
  4. "I'm traveling and can't use my phone" - Provide backup codes before travel
  5. "The app keeps asking me to sign in" - May need to remove and re-add account

Estimated time: 4-8 hours for configuration + 2-4 weeks for full rollout

Step 6: Configure Conditional Access Policies

Conditional Access is the policy engine for Zero Trust. Every access request is evaluated against your policies.

6.1 Understand Policy Structure:

Every Conditional Access policy has three parts:

  1. Assignments (WHO): Which users/groups does this apply to?
  2. Conditions (WHEN): Under what circumstances? (device, location, risk, app)
  3. Access Controls (WHAT): Grant access, block, or require additional verification

6.2 Essential Policies (Minimum Required):

  1. CA001: Require MFA for All UsersUsers: All users (exclude break-glass accounts)
  2. Cloud apps: All cloud apps
  3. Grant: Require MFA
  4. CA002: Block Legacy AuthenticationUsers: All users
  5. Cloud apps: All cloud apps
  6. Conditions: Client apps → Legacy authentication clients
  7. Grant: Block access
  8. CA003: Require MFA for AdminsUsers: Directory roles (all admin roles)
  9. Cloud apps: All cloud apps
  10. Grant: Require MFA + Require phishing-resistant MFA (if E5)
  11. CA004: Block High-Risk Sign-insUsers: All users
  12. Cloud apps: All cloud apps
  13. Conditions: Sign-in risk → High
  14. Grant: Block access
  15. CA005: Require Password Change for High-Risk UsersUsers: All users
  16. Cloud apps: All cloud apps
  17. Conditions: User risk → High
  18. Grant: Require password change + Require MFA

6.3 Advanced Policies (Recommended):

  1. CA006: Require Compliant Device for Desktop AppsUsers: All users
  2. Cloud apps: Office 365
  3. Conditions: Device platforms → Windows, macOS
  4. Grant: Require device to be marked as compliant
  5. CA007: Require Approved App for MobileUsers: All users
  6. Cloud apps: Office 365
  7. Conditions: Device platforms → iOS, Android
  8. Grant: Require approved client app OR Require app protection policy
  9. CA008: Block Access from Untrusted LocationsUsers: All users (exclude travelers if needed)
  10. Cloud apps: All cloud apps
  11. Conditions: Locations → Exclude trusted (US, known offices)
  12. Grant: Block access
  13. CA009: Session Timeout for Sensitive AppsUsers: All users
  14. Cloud apps: Sensitive apps (finance, HR systems)
  15. Session: Sign-in frequency → 4 hours
  16. Session: Persistent browser session → Never persistent
  17. CA010: Require Terms of UseUsers: All users
  18. Cloud apps: All cloud apps
  19. Grant: Require Terms of Use acceptance
  20. Re-accept: Every 365 days

Critical: Always start policies in Report-only mode. Run for 1-2 weeks and review the "What If" tool and sign-in logs before switching to Enabled. A misconfigured policy can lock out your entire organization.

6.4 Named Locations Configuration:

  1. Go to Protection → Conditional Access → Named locations
  2. Create "Trusted Office Locations" with your office IP ranges
  3. Create "Blocked Countries" for high-risk regions you don't do business with
  4. Mark your trusted locations as "Mark as trusted location"
  5. Use these in Conditional Access policies for location-based controls

Estimated time: 12-24 hours to design, configure, test, and deploy all policies

Step 7: Configure Single Sign-On (SSO)

Connect all your applications to Entra ID. One identity, one login, centralized control.

7.1 Application Inventory:

  1. List every application your organization uses
  2. Categorize: SaaS apps, on-premises apps, custom apps
  3. Identify authentication method each app supports: SAML, OIDC, password-based
  4. Prioritize by user count and sensitivity

7.2 Add Gallery Applications:

  1. Go to Identity → Applications → Enterprise applications
  2. Click New application → Browse Azure AD Gallery
  3. Search for your app (Salesforce, Zoom, Slack, etc.)
  4. Click the app → Create
  5. Configure SSO: Single sign-on → SAML
  6. Download Federation Metadata XML or copy URLs
  7. Configure the app vendor side with Entra ID details
  8. Test SSO with a pilot user before rolling out

7.3 Configure SCIM Provisioning:

SCIM automatically creates, updates, and disables user accounts in connected apps.

  1. In the Enterprise app, go to Provisioning
  2. Set Provisioning Mode to Automatic
  3. Enter the app's SCIM endpoint URL and authentication token
  4. Configure attribute mappings (which Entra ID fields map to app fields)
  5. Set provisioning scope (all users, or assigned users only)
  6. Start provisioning and monitor the provisioning logs

Why SCIM Matters

Without SCIM, when an employee leaves, you must manually disable their account in every application. With SCIM, disable in Entra ID → automatically disabled everywhere. This is critical for security and compliance.

7.4 Common SSO Applications to Configure:

  1. Productivity: Zoom, Slack, Asana, Monday.com, Notion
  2. Finance: QuickBooks Online, Expensify, Bill.com
  3. HR: BambooHR, Gusto, ADP, Workday
  4. Healthcare: SimplePractice, TherapyNotes, Dentrix (if cloud)
  5. CRM: Salesforce, HubSpot, Zoho
  6. IT: GitHub, Jira, Confluence, AWS, Azure
  7. Security: LastPass, 1Password, KnowBe4

Estimated time: 2-6 hours per application depending on complexity

Step 8: Guest Access and External Collaboration

Control how external users access your environment. Too loose = security risk. Too tight = business friction.

8.1 Configure External Collaboration Settings:

  1. Go to Identity → External Identities → External collaboration settings
  2. Guest user access: Limited access (can't enumerate users/groups)
  3. Guest invite restrictions: Only admins and users in guest inviter role
  4. Enable guest self-service sign-up: No
  5. Collaboration restrictions: Allow invitations only to specified domains
  6. Add trusted partner domains to the allow list

8.2 Guest Access Reviews:

  1. Go to Identity Governance → Access reviews
  2. Create a review for all guests in the tenant
  3. Reviewers: Group owners or specific managers
  4. Frequency: Quarterly
  5. Auto-apply results: Remove access if not approved
  6. Require justification for continued access

Estimated time: 2-4 hours

Step 9: Identity Monitoring and Alerting

You can't protect what you can't see. Configure comprehensive monitoring for identity events.

9.1 Configure Sign-in Log Retention:

  1. Default retention is 30 days - not enough for compliance
  2. Configure Log Analytics workspace integration (requires Azure subscription)
  3. Stream logs to long-term storage (90 days minimum, 1 year recommended)
  4. Set up automated exports if using third-party SIEM

9.2 Critical Alerts to Configure:

  1. Any sign-in to break-glass accounts
  2. Global Administrator role assigned
  3. New Conditional Access policy created or modified
  4. High-risk user detected
  5. Bulk user creation or deletion
  6. Consent granted to high-privilege applications
  7. Sign-ins from impossible travel locations
  8. Multiple failed sign-in attempts (brute force)

9.3 Review These Reports Weekly:

  1. Risky sign-ins report
  2. Risky users report
  3. Sign-in logs filtered by failures
  4. Audit logs for admin activities
  5. Conditional Access insights and reporting

Estimated time: 4-8 hours for initial setup + ongoing weekly reviews

Identity Checklist

  1. Tenant configured with custom domain
  2. SPF, DKIM, and DMARC records configured
  3. Break-glass accounts created and documented
  4. Password policies configured (14+ characters, banned list)
  5. Self-service password reset enabled
  6. MFA enforced for all users via Conditional Access
  7. Number matching enabled in Authenticator
  8. All essential Conditional Access policies deployed
  9. Legacy authentication blocked
  10. High-risk sign-ins blocked automatically
  11. SSO configured for all major applications
  12. SCIM provisioning enabled where supported
  13. Guest access restricted and reviewed quarterly
  14. Sign-in logs retained for 1+ year
  15. Critical alerts configured and tested


02 · Device Management

If a device touches your data, you need to manage it. That means enrollment, configuration, patching, and the ability to wipe it when needed. In Zero Trust, device health is a critical signal - unmanaged or non-compliant devices don't get access.

Prerequisites

Before starting device management configuration, ensure you have:

  1. Microsoft 365 Business Premium, E3, or E5 licenses (includes Intune)
  2. Entra ID configured with Conditional Access policies ready
  3. At least one test Windows device and one test Mac (if applicable)
  4. Global Administrator or Intune Administrator role
  5. Apple Business Manager account (for Mac management)
  6. Hardware inventory of all company devices
  7. Decision on BYOD policy (allow personal devices or not)

Step 1: Configure Microsoft Intune Foundation

Intune is your unified endpoint management platform. It handles Windows, Mac, iOS, and Android - but we'll focus on Windows here and Mac in the next section.

1.1 Initial Intune Configuration:

  1. Navigate to intune.microsoft.com (or endpoint.microsoft.com)
  2. Go to Tenant administration → Tenant status
  3. Verify MDM authority is set to Intune (not co-management with SCCM unless intended)
  4. Set tenant name and support information
  5. Configure tenant-wide enrollment settings

1.2 Configure Enrollment Restrictions:

  1. Go to Devices → Enrollment → Device platform restrictions
  2. Edit the default policy (or create custom ones)
  3. Recommended settings:Windows (MDM): Allow - Version minimum 10.0.19044 (Win 10 21H2) or 10.0.22000 (Win 11)
  4. macOS: Allow - Version minimum 13.0 (Ventura) or higher
  5. iOS/iPadOS: Allow - Version minimum 16.0 or higher
  6. Android: Block personally-owned, Allow corporate-owned only (or vice versa based on policy)
  7. Set device limit per user (recommended: 5 devices max)

Decision Point: Will you allow personally-owned devices (BYOD)? This affects enrollment restrictions, compliance policies, and app protection policies. Make this decision before proceeding.

1.3 Create Device Categories and Groups:

  1. Go to Devices → Device categories
  2. Create categories: Corporate-Windows, Corporate-Mac, Corporate-Mobile, BYOD
  3. Go to Groups → New group
  4. Create these dynamic device groups:Devices-Windows-All - Rule: (device.deviceOSType -eq "Windows")
  5. Devices-Mac-All - Rule: (device.deviceOSType -eq "MacMDM")
  6. Devices-iOS-All - Rule: (device.deviceOSType -eq "iOS")
  7. Devices-Corporate - Rule: (device.deviceOwnership -eq "Company")
  8. Devices-BYOD - Rule: (device.deviceOwnership -eq "Personal")
  9. Devices-Autopilot - Rule: (device.enrollmentProfileName -ne null)

1.4 Configure Windows Enrollment:

  1. Go to Devices → Windows → Windows enrollment
  2. Configure Automatic enrollment:
  3. MDM user scope: All (or specific groups)
  4. MAM user scope: None (use MDM for Windows, MAM for mobile)
  5. Enable CNAME validation if using custom domain
  6. Configure Enrollment Status Page (ESP) - see Step 4

1.5 Configure Device Configuration Profiles:

Create configuration profiles to standardize settings across all devices.

  1. Go to Devices → Configuration profiles → Create profile
  2. Essential Windows profiles to create:Security Baseline - Use Microsoft's security baseline template
  3. BitLocker Encryption - Require TPM, save recovery key to Entra ID
  4. Windows Firewall - Enable for all profiles (Domain, Private, Public)
  5. Defender Antivirus - Real-time protection, cloud protection, automatic sample submission
  6. Device Restrictions - Camera, Bluetooth, USB storage policies
  7. Wi-Fi - Corporate Wi-Fi profile with certificate or credentials
  8. VPN - If using always-on VPN or per-app VPN
  9. Assign profiles to appropriate device groups
  10. Use Scope tags if managing multiple organizations

Profile Conflict Resolution

When multiple profiles configure the same setting, Intune uses "last write wins" for some settings and "most restrictive wins" for others. Test thoroughly in a pilot group and use the Device configuration report to identify conflicts.

1.6 Configure Windows Update Rings:

  1. Go to Devices → Windows → Update rings for Windows 10 and later
  2. Create update ring: Production-Standard
  3. Recommended settings:Quality update deferral: 7 days
  4. Feature update deferral: 30 days
  5. Automatic update behavior: Auto install and reboot at scheduled time
  6. Active hours: 8 AM - 6 PM (adjust for your business)
  7. Restart checks: All enabled
  8. Deadline: 7 days for quality, 14 days for feature updates
  9. Create separate ring IT-Pilot with 0-day deferrals for testing
  10. Assign rings to appropriate groups

Critical: Never set 0-day deferrals for production users. Always test updates on pilot devices first. A bad update can disable an entire fleet.

1.7 Configure Application Deployment:

  1. Go to Apps → All apps → Add
  2. Required apps for all Windows devices:Microsoft 365 Apps (configure apps to include, update channel)
  3. Company Portal (for user self-service)
  4. Microsoft Defender for Endpoint (if not using Defender for Business)
  5. Microsoft Edge (enterprise managed)
  6. Any LOB applications your organization requires
  7. Set assignment: Required (auto-install) vs. Available (user choice)
  8. Configure install behavior: System context vs. User context
  9. Set up app dependencies if needed
  10. Configure supersedence for app updates

Estimated time: 16-24 hours for comprehensive Windows Intune setup

Step 2: Configure Jamf Pro for Mac Management

While Intune can manage Macs, Jamf Pro provides deeper macOS-native management capabilities. For organizations with more than a few Macs, Jamf is the industry standard.

2.1 Apple Business Manager Setup:

  1. Go to business.apple.com and sign in (or create account)
  2. Verify your organization with D-U-N-S number
  3. Create Managed Apple IDs for administrators
  4. Configure MDM server connection (will link to Jamf)
  5. Enable Automated Device Enrollment
  6. Configure Apps and Books for volume purchasing
  7. Assign devices to your MDM server

Important: New Macs must be purchased through Apple Business Manager-linked resellers to automatically appear in ABM. Existing Macs require Apple Configurator to add to ABM.

2.2 Jamf Pro Initial Configuration:

  1. Deploy Jamf Pro (Jamf Cloud recommended for simplicity)
  2. Configure Push Certificate:
  3. Go to Settings → Global → Push Certificates
  4. Generate CSR, upload to Apple Push Certificates Portal, download and upload certificate
  5. Configure LDAP/Entra ID integration for user authentication
  6. Set up Jamf Pro user accounts with appropriate permissions

2.3 Link Apple Business Manager to Jamf:

  1. In Jamf Pro, go to Settings → Global → Automated Device Enrollment
  2. Upload the MDM server token from Apple Business Manager
  3. Configure default PreStage Enrollment (see Step 4)
  4. Sync devices - all ABM devices will appear in Jamf
  5. Configure Volume Purchasing integration for app deployment

2.4 Create macOS Configuration Profiles:

  1. Go to Computers → Configuration Profiles → New
  2. Essential macOS profiles:FileVault - Enable encryption, escrow recovery key to Jamf
  3. Firewall - Enable firewall, enable stealth mode
  4. Password Policy - Require password after sleep, minimum length
  5. Security & Privacy - Require admin password for system preferences
  6. Gatekeeper - Allow apps from App Store and identified developers
  7. Software Update - Automatic download and install
  8. Wi-Fi - Corporate Wi-Fi configuration
  9. Login Window - Display login window, disable guest
  10. Restrictions - Disable AirDrop, restrict App Store if needed
  11. Scope profiles to appropriate Smart Groups

2.5 Create Smart Groups:

  1. Go to Computers → Smart Groups → New
  2. Essential Smart Groups:All Managed Macs - All computers
  3. macOS Version Outdated - OS Version less than minimum
  4. FileVault Not Enabled - FileVault Status is Not Encrypted
  5. Missing Critical Apps - Application Title is not Microsoft Defender
  6. Autopilot Enrolled - Enrollment Method is PreStage enrollment
  7. Stale Devices - Last Check-in more than 30 days ago
  8. Use Smart Groups for profile scoping and reporting

2.6 Configure Patch Management:

  1. Go to Computers → Patch Management
  2. Enable software titles you want to manage
  3. Create patch policies:
  4. macOS Updates - Defer 7 days, auto-install, deadline 14 days
  5. Third-party Apps - Auto-update Chrome, Zoom, Slack, etc.
  6. Configure maintenance windows to avoid disruption
  7. Set up notifications before forced restarts

2.7 Deploy Applications:

  1. For App Store apps (via VPP):Purchase licenses in Apple Business Manager
  2. Sync in Jamf → Settings → Volume Purchasing
  3. Deploy via policy, assign to devices or users
  4. For PKG/DMG apps:Upload package to Jamf Pro (or Jamf Cloud Distribution Point)
  5. Create policy with trigger (recurring check-in, enrollment, self-service)
  6. Scope to appropriate groups
  7. Configure Self Service for user-installable apps

2.8 Integrate with Entra ID for Compliance:

  1. If using both Jamf and Intune, configure Jamf-Intune integration
  2. Go to Settings → Global → Conditional Access
  3. Configure Entra ID application registration
  4. Jamf sends compliance status to Entra ID
  5. Conditional Access can require compliant Mac for access

Why Jamf + Intune Integration?

This allows you to use Conditional Access policies that require device compliance across both Windows (managed by Intune) and Mac (managed by Jamf). Without integration, you can't enforce "require compliant device" for Macs in Entra ID.

Estimated time: 16-32 hours for comprehensive Jamf Pro setup

Step 3: Define and Enforce Compliance Policies

Compliance policies define the minimum security requirements a device must meet to access corporate resources. Non-compliant devices get blocked by Conditional Access.

3.1 Windows Compliance Policy:

  1. Go to Devices → Compliance policies → Create policy → Windows 10 and later
  2. Name: Windows-Compliance-Standard
  3. Device Health:Require BitLocker: Yes
  4. Require Secure Boot: Yes
  5. Require code integrity: Yes
  6. Device Properties:Minimum OS version: 10.0.19044.0 (21H2) or 10.0.22000.0 (Win 11)
  7. Maximum OS version: (leave blank unless blocking preview builds)
  8. System Security:Require password: Yes
  9. Minimum password length: 8 (MFA handles stronger auth)
  10. Required password type: Alphanumeric
  11. Firewall: Require
  12. Antivirus: Require
  13. Antispyware: Require
  14. Microsoft Defender Antimalware: Require
  15. Microsoft Defender Antimalware minimum version: Current
  16. Real-time protection: Require
  17. Microsoft Defender for Endpoint:Require device to be at or under machine risk score: Medium (or Low for high security)

3.2 macOS Compliance Policy:

  1. Go to Devices → Compliance policies → Create policy → macOS
  2. Name: macOS-Compliance-Standard
  3. Device Health:Require system integrity protection: Yes
  4. Device Properties:Minimum OS version: 13.0 (Ventura) or higher
  5. System Security:Require password: Yes
  6. Minimum password length: 8
  7. Encryption: Require FileVault
  8. Firewall: Enable
  9. Gatekeeper: Require

3.3 iOS/iPadOS Compliance Policy:

  1. Go to Devices → Compliance policies → Create policy → iOS/iPadOS
  2. Name: iOS-Compliance-Standard
  3. Device Health:Jailbroken devices: Block
  4. Device Properties:Minimum OS version: 16.0
  5. System Security:Require password: Yes
  6. Simple passwords: Block
  7. Minimum password length: 6
  8. Required password type: Numeric

3.4 Configure Non-Compliance Actions:

  1. In each compliance policy, go to Actions for noncompliance
  2. Recommended action schedule:Day 0: Mark device noncompliant (triggers Conditional Access block)
  3. Day 1: Send email notification to user
  4. Day 3: Send push notification to device
  5. Day 7: Send email to user's manager (optional)
  6. Day 14: Remotely lock device (corporate-owned only)
  7. Day 30: Retire device (removes corporate data)

Testing Critical: Test compliance policies in Report-only mode first. A misconfigured policy can mark all devices non-compliant and lock everyone out. Use "What If" tool in Conditional Access to verify behavior.

3.5 Link Compliance to Conditional Access:

  1. In Entra ID, create or edit Conditional Access policy
  2. Grant → Require device to be marked as compliant
  3. This ensures only devices meeting your compliance policies can access resources
  4. Combine with other controls: Require MFA AND require compliant device

Compliance + Conditional Access = Zero Trust

The combination of device compliance policies and Conditional Access is core to Zero Trust. Every access request is evaluated: Is the user identity verified (MFA)? Is the device compliant? Is the sign-in risk acceptable? Only if all conditions pass does access get granted.

Estimated time: 8-12 hours to design, test, and deploy compliance policies

Step 4: Configure Zero-Touch Deployment

Zero-touch deployment means new devices configure themselves automatically. User opens box, connects to internet, signs in - device is fully configured without IT touching it.

4.1 Windows Autopilot - Register Devices:

  1. For new purchases:Work with your hardware vendor (Dell, HP, Lenovo) to register devices at purchase
  2. Provide your tenant ID to the vendor
  3. Devices appear in Intune automatically before they're even shipped
  4. For existing devices:Run PowerShell script to extract hardware hash: Get-WindowsAutopilotInfo.ps1
  5. Export to CSV file
  6. Import CSV in Intune → Devices → Windows enrollment → Devices
  7. Wait for sync (can take 15 minutes)

4.2 Create Autopilot Deployment Profile:

  1. Go to Devices → Windows enrollment → Deployment profiles
  2. Create profile → Windows PC
  3. Name: Autopilot-UserDriven-Standard
  4. Out-of-box experience (OOBE):Deployment mode: User-Driven
  5. Join to Entra ID: Entra ID joined (cloud-only) or Hybrid (if on-prem AD)
  6. Microsoft Software License Terms: Hide
  7. Privacy settings: Hide
  8. Hide change account options: Yes
  9. User account type: Standard (not admin)
  10. Allow pre-provisioned deployment: Yes (for IT pre-staging)
  11. Language (Region): Operating system default
  12. Automatically configure keyboard: Yes
  13. Apply device name template: Yes - WS-%SERIAL% or %RAND:4%-%SERIAL%
  14. Assign to device group (e.g., Devices-Autopilot)

4.3 Configure Enrollment Status Page (ESP):

  1. Go to Devices → Windows enrollment → Enrollment Status Page
  2. Edit default profile or create custom
  3. Settings:Show app and profile configuration progress: Yes
  4. Show error when installation exceeds: 60 minutes
  5. Show custom message when error occurs: Yes
  6. Custom message: "Setup is taking longer than expected. Please contact IT at [number]"
  7. Allow users to collect logs: Yes
  8. Only show page to devices provisioned by OOBE: Yes
  9. Block device use until all apps and profiles are installed: Yes (for required apps)
  10. Allow users to reset device if installation error occurs: Yes
  11. Allow users to use device if installation error occurs: No
  12. Block device use until these required apps are installed:Microsoft 365 Apps
  13. Microsoft Defender for Endpoint
  14. Company Portal
  15. Any critical LOB apps

Caution: Too many required apps in ESP will make deployment slow. Only include apps that are truly required before user can be productive. Everything else can install in the background.

4.4 Mac Automated Device Enrollment:

  1. In Jamf Pro, go to Computers → PreStage Enrollments → New
  2. Name: Mac-AutoEnroll-Standard
  3. General settings:Make MDM profile mandatory: Yes
  4. MDM profile removal requires authorization: Yes
  5. Require user authentication: Yes
  6. Authentication type: Cloud Identity Provider (Entra ID)
  7. Account settings:Create local administrator account: Yes (for IT support)
  8. Account username: localadmin
  9. Hide account: Yes
  10. Allow user to become admin: No
  11. Skip Setup Assistant items:Skip: Location Services, Apple ID, Terms of Service, Siri, Analytics, Screen Time
  12. Don't skip: FileVault (let user enable), Touch ID (user setup)
  13. Assign to devices in Scope

4.5 Test Zero-Touch Deployment:

  1. Windows:Reset a test device: Settings → System → Recovery → Reset this PC → Remove everything
  2. On reboot, connect to internet
  3. Device should recognize Autopilot profile and show company branding
  4. Sign in with test user credentials
  5. Observe ESP - apps should install
  6. Verify device appears in Intune and is compliant
  7. Mac:Erase a test Mac: Recovery Mode → Erase Mac
  8. On Setup Assistant, connect to internet
  9. Device should prompt for Remote Management enrollment
  10. Complete enrollment with Entra ID credentials
  11. Verify device appears in Jamf and policies apply
  12. Document the process with screenshots for user handoff documentation

4.6 User Experience Documentation:

Create end-user documentation that covers:

  1. What to expect when opening a new device
  2. How long setup typically takes (Windows: 30-60 min, Mac: 20-40 min)
  3. What apps will be installed automatically vs. available in Company Portal
  4. Who to contact if setup fails
  5. How to enroll a personal device (if BYOD allowed)

Estimated time: 8-16 hours per platform for zero-touch setup and testing

Device Management Checklist

  1. Intune tenant configured with enrollment restrictions
  2. Device categories and dynamic groups created
  3. Windows security baselines and configuration profiles deployed
  4. Windows Update rings configured with appropriate deferrals
  5. Required applications deployed via Intune
  6. Jamf Pro configured with ABM integration (if Macs)
  7. macOS configuration profiles deployed
  8. Patch management configured for macOS and third-party apps
  9. Windows compliance policy created and assigned
  10. macOS compliance policy created and assigned
  11. iOS/Android compliance policies created (if mobile)
  12. Non-compliance actions configured with escalation
  13. Conditional Access policy requires compliant device
  14. Windows Autopilot devices registered
  15. Autopilot deployment profile configured
  16. Enrollment Status Page configured with required apps
  17. Mac PreStage Enrollment configured
  18. Zero-touch deployment tested on both platforms
  19. End-user documentation created


03 · Security Stack

Defense in depth. Multiple security layers working together to detect and stop threats across endpoints, email, identity, and cloud. In Zero Trust, we assume breach and design controls to detect, contain, and remediate threats at every layer.

Prerequisites

Before configuring your security stack, ensure you have:

  1. Microsoft 365 Business Premium, E3, or E5 licenses (E5 for full Defender suite)
  2. Intune device enrollment completed (for endpoint onboarding)
  3. Global Administrator or Security Administrator role
  4. Test devices enrolled and compliant
  5. Understanding of your organization's risk tolerance
  6. Incident response contact list (who gets alerts)
  7. Baseline understanding of normal network/user behavior

Step 1: Deploy Microsoft Defender for Endpoint

Defender for Endpoint is enterprise-grade EDR (Endpoint Detection and Response). It goes far beyond traditional antivirus - it detects behavioral anomalies, provides threat intelligence, and can automatically remediate attacks.

1.1 Initial Configuration:

  1. Navigate to security.microsoft.com
  2. Go to Settings → Endpoints → Onboarding
  3. Configure tenant settings:Data retention: 180 days (maximum for investigation history)
  4. Preview features: Enable (for IT pilot group only initially)
  5. Geographic location: Select your primary region
  6. Advanced features to enable:Automated investigation: On
  7. Auto-resolve remediated alerts: On
  8. Allow or block file: On
  9. Custom network indicators: On
  10. Tamper protection: On (prevents disabling Defender)
  11. Show user details: On
  12. Skype for Business integration: On
  13. Microsoft Defender for Cloud Apps: On
  14. Web content filtering: On
  15. Device discovery: On

1.2 Onboard Devices via Intune:

  1. In Microsoft Defender portal, go to Settings → Endpoints → Onboarding
  2. Select deployment method: Microsoft Intune
  3. Download the onboarding package (configuration file)
  4. In Intune, go to Endpoint security → Endpoint detection and response
  5. Create profile → Windows 10 and later → Endpoint detection and response
  6. Settings:Microsoft Defender for Endpoint client configuration package type: Auto from connector
  7. Sample sharing: All (or None if privacy concerns)
  8. Telemetry Reporting Frequency: Expedited
  9. Assign to All Devices group
  10. Verify devices appear in Defender portal within 24 hours

Licensing Note: Defender for Endpoint P1 is included with M365 Business Premium. P2 (full EDR with automated investigation) requires M365 E5 or E5 Security add-on. Know which license you have before expecting features.

1.3 Configure Attack Surface Reduction (ASR) Rules:

ASR rules block common attack techniques before they execute.

  1. In Intune, go to Endpoint security → Attack surface reduction
  2. Create policy → Windows 10 and later → Attack surface reduction rules
  3. Essential ASR rules to enable (Block mode):Block executable content from email and webmail
  4. Block all Office applications from creating child processes
  5. Block Office applications from creating executable content
  6. Block Office applications from injecting code
  7. Block JavaScript or VBScript from launching downloaded content
  8. Block execution of potentially obfuscated scripts
  9. Block Win32 API calls from Office macros
  10. Block credential stealing from Windows LSASS
  11. Block process creations from PsExec and WMI commands
  12. Block untrusted and unsigned processes from USB
  13. Use advanced protection against ransomware
  14. Block Adobe Reader from creating child processes
  15. Start in Audit mode for 2 weeks, then switch to Block
  16. Add exclusions for legitimate business applications that trigger false positives

ASR Testing Process

1. Deploy rules in Audit mode to pilot group. 2. Monitor attack surface reduction events in Defender portal for 2 weeks. 3. Review false positives and add exclusions. 4. Switch to Block mode for pilot. 5. Monitor for 1 week. 6. Deploy to all users.

1.4 Configure Automated Investigation and Remediation:

  1. Go to Settings → Endpoints → Advanced features
  2. Ensure Automated investigation is enabled
  3. Go to Settings → Endpoints → Device groups
  4. For each device group, set automation level:
  5. Automation levels:Full - remediate threats automatically: Recommended for most environments
  6. Semi - require approval for core folders: For sensitive servers
  7. Semi - require approval for any: High-oversight environments
  8. No automated response: Only for testing, not recommended

1.5 Configure Web Content Filtering:

  1. Go to Settings → Endpoints → Web content filtering
  2. Create policy for your organization
  3. Categories to block (minimum):Adult content
  4. High bandwidth (streaming sites - optional)
  5. Legal liability (torrents, hacking sites)
  6. Gambling
  7. Malware
  8. Phishing
  9. Newly registered domains (high risk)
  10. Parked domains
  11. Add exceptions for legitimate business sites if needed
  12. Assign to device groups

1.6 Configure Alert Notifications:

  1. Go to Settings → Endpoints → Email notifications
  2. Create notification rule:
  3. Name: Security Team Alerts
  4. Include organization name: Yes
  5. Include device information: Yes
  6. Alert severity: High and Medium (Critical goes to all)
  7. Recipients: security team distribution list
  8. Create separate rule for Critical only → goes to IT leadership
  9. Test by generating a test alert (EICAR test file)

1.7 Onboard macOS Devices:

  1. In Defender portal, go to Settings → Endpoints → Onboarding
  2. Select macOS and download onboarding package
  3. For Jamf-managed Macs:Create configuration profiles for system extensions, network filter, full disk access
  4. Deploy Microsoft Defender app via Jamf Self Service or policy
  5. Deploy the onboarding package via script policy
  6. Required macOS permissions (deploy via MDM):Full Disk Access for Microsoft Defender
  7. System Extension approval
  8. Network Filter (Content Filter) approval
  9. Notifications
  10. Background Services
  11. Verify Macs appear in Defender portal device inventory

Estimated time: 12-20 hours for full endpoint deployment across platforms

Step 2: Configure Defender for Office 365 (Email Security)

Email is the #1 attack vector. Defender for Office 365 provides multi-layered protection against phishing, malware, business email compromise, and other email-borne threats.

2.1 Configure Safe Attachments:

  1. Go to security.microsoft.com → Email & collaboration → Policies → Safe Attachments
  2. Edit the default policy or create custom policy:
  3. Settings:Safe Attachments unknown malware response: Dynamic Delivery (recommended) or Block
  4. Redirect attachment on detection: Enable, send to security mailbox
  5. Apply Safe Attachments detection response if scanning can't complete: On
  6. Apply to all users

Dynamic Delivery vs. Block

Dynamic Delivery: Delivers email immediately, replaces attachment with placeholder while scanning. User can read email while waiting. Best for productivity.

Block: Holds entire email until scan completes. More secure but delays delivery.

2.2 Configure Safe Links:

  1. Go to Policies → Safe Links
  2. Edit default policy or create custom:
  3. Settings:On: Safe Links checks a list of known malicious links when users click links in email
  4. Apply Safe Links to email messages sent within the organization: On
  5. Apply real-time URL scanning for suspicious links: On
  6. Wait for URL scanning to complete before delivering: On
  7. Do not rewrite URLs, do checks via Safe Links API only: Off (keep URL rewriting on)
  8. Do not rewrite the following URLs: Add trusted internal URLs if needed
  9. Apply to: Teams, Office 365 apps
  10. Track user clicks: On (for reporting)
  11. Let users click through to original URL: Off (block malicious, no override)
  12. Display organization branding on warning pages: On

2.3 Configure Anti-Phishing Policies:

  1. Go to Policies → Anti-phishing
  2. Edit default policy or create custom:
  3. Impersonation protection (critical):Enable users to protect: Add executives, finance team, HR (up to 350 users)
  4. Enable domains to protect: Your domain + key partner domains
  5. Add trusted senders and domains: Legitimate partners that might trigger false positives
  6. Enable mailbox intelligence: On
  7. Enable intelligence for impersonation protection: On
  8. Actions for impersonation:If email impersonates protected user: Quarantine the message
  9. If email impersonates protected domain: Quarantine the message
  10. If mailbox intelligence detects impersonated user: Move to Junk folder or Quarantine
  11. Spoof protection:Enable spoof intelligence: On
  12. If email is from spoofed sender: Quarantine
  13. Show first contact safety tip: On
  14. Show user impersonation safety tip: On
  15. Show domain impersonation safety tip: On
  16. Show unusual characters safety tip: On

Critical: Add your CEO, CFO, and anyone who can authorize payments or sensitive data to the protected users list. These are prime targets for BEC (Business Email Compromise).

2.4 Configure Anti-Spam Policies:

  1. Go to Policies → Anti-spam
  2. Edit inbound policy:
  3. Bulk email threshold:Set to 5 or 6 (lower = more aggressive, higher = more permissive)
  4. Most organizations work well at 6
  5. Spam action:High confidence spam: Quarantine message
  6. Spam: Move to Junk folder
  7. Bulk: Move to Junk folder
  8. Phishing: Quarantine message
  9. High confidence phishing: Quarantine message
  10. Retain spam in quarantine: 30 days
  11. Enable safety tips: All on
  12. Enable zero-hour auto purge (ZAP): On for spam, phishing, and malware

2.5 Configure Quarantine Policies:

  1. Go to Email & collaboration → Review → Quarantine
  2. Configure quarantine policies:
  3. Default settings:Spam: Users can release + request release
  4. Phishing: Admin release only
  5. Malware: Admin release only
  6. High confidence phishing: Admin release only
  7. Configure quarantine notifications: Daily digest to users
  8. Set up quarantine admin review process

2.6 Configure User Reporting:

  1. Go to Settings → Email & collaboration → User reported settings
  2. Enable Microsoft reporting experience
  3. Configure:Monitor reported messages in Outlook: On
  4. Send reported messages to: Microsoft and your security mailbox
  5. Custom mailbox: security-phish@yourcompany.com
  6. Customize before/after reporting messages
  7. Deploy Report Message add-in to all users via Intune or centralized deployment
  8. Train users on how and when to report suspicious emails

Why User Reporting Matters

Users are your first line of defense. When they report phishing, Microsoft uses that data to improve filters for everyone. You also get visibility into what's getting through your filters and can investigate potential compromises faster.

2.7 Configure Attack Simulation Training:

  1. Go to Email & collaboration → Attack simulation training
  2. Enable the service
  3. Create simulation:
  4. Select technique: Credential Harvest, Link in Attachment, etc.
  5. Select payload (or create custom matching your brand)
  6. Target all users or specific departments
  7. Schedule: Monthly recommended
  8. Configure landing page for users who click
  9. Assign training for users who fail
  10. Set up recurring simulations with varied techniques
  11. Review reports and track improvement over time

Estimated time: 8-12 hours for complete email security configuration

Step 3: Apply CIS Level 1 Security Baseline

The Center for Internet Security (CIS) publishes industry-standard security benchmarks. Level 1 is the baseline that every organization should meet - it's designed to be practical without breaking functionality.

3.1 Understand CIS Levels:

  1. Level 1: Basic security configurations that should be implemented everywhere. Minimal impact on functionality.
  2. Level 2: Enhanced security for high-security environments. May impact usability or require additional configuration.

We implement Level 1 as the non-negotiable baseline for all organizations.

3.2 Windows 11 CIS Baseline via Intune:

  1. In Intune, go to Endpoint security → Security baselines
  2. Select "Security Baseline for Windows 10 and later" (also applies to 11)
  3. Create profile
  4. Key settings to verify are enabled:BitLocker: Require encryption, TPM required, save to Entra ID
  5. Firewall: Enable for all profiles (Domain, Private, Public)
  6. Windows Hello: Configure or disable based on your MFA strategy
  7. Screen lock: Maximum inactivity 15 minutes, require password
  8. Password: Minimum length 14, no expiration (with MFA)
  9. Local admin: Rename built-in admin account, disable guest
  10. UAC: Always prompt, secure desktop
  11. SMB signing: Required for servers, enabled for clients
  12. Audit policy: Enable success and failure for key events
  13. Deploy to pilot group first
  14. Monitor for conflicts with other profiles
  15. Deploy to all Windows devices after pilot

Important: Security baselines can conflict with other Intune configuration profiles. Use Intune's conflict resolution tools to identify and resolve overlapping settings. The baseline should generally win for security settings.

3.3 Microsoft 365 CIS Baseline:

  1. Go to security.microsoft.com → Secure Score
  2. Review recommended actions - many align with CIS benchmarks
  3. Key M365 security settings:Block legacy authentication (Conditional Access)
  4. Require MFA for all users (Conditional Access)
  5. Enable audit logging (Purview)
  6. Disable anonymous calendar sharing
  7. Block external forwarding (mail flow rules)
  8. Enable mailbox auditing (on by default since 2019)
  9. Configure data loss prevention policies
  10. Restrict who can create groups and Teams
  11. Disable OneDrive/SharePoint sharing with "Anyone"
  12. Require managed devices for desktop apps
  13. Document which Secure Score recommendations you've implemented and why not for others

3.4 macOS CIS Baseline:

  1. In Jamf Pro, create or import CIS benchmark profiles
  2. Key macOS CIS settings:FileVault: Require encryption
  3. Firewall: Enable, enable stealth mode
  4. Gatekeeper: App Store and identified developers only
  5. SIP: Ensure System Integrity Protection is enabled
  6. Automatic updates: Enable for macOS and apps
  7. Screen lock: Require after 5 minutes of inactivity
  8. Password: Require alphanumeric, 14+ characters
  9. Remote access: Disable SSH, Screen Sharing unless needed
  10. Bluetooth: Disable discoverability
  11. AirDrop: Disable or contacts only
  12. Guest account: Disable
  13. Deploy to test group, verify no functionality issues
  14. Deploy to all Macs

3.5 Browser Security (Edge/Chrome):

  1. Create Intune configuration profile for Microsoft Edge
  2. Key browser settings:Block password manager (use enterprise password manager)
  3. SmartScreen: Enabled
  4. Safe Browsing: Enhanced protection
  5. Block dangerous downloads
  6. Block malicious sites
  7. Disable developer tools (optional, may break web apps)
  8. Sync disabled for enterprise
  9. Block third-party cookies (may break some sites)
  10. Block pop-ups except for trusted sites
  11. Extension allow/block list
  12. For Chrome, use ADMX templates or Chrome Browser Cloud Management

3.6 Ongoing Compliance Monitoring:

  1. Use Secure Score as ongoing benchmark (target: 80%+)
  2. Run CIS-CAT assessments quarterly (if you have the tool)
  3. Review Intune compliance reports weekly
  4. Address non-compliant devices immediately
  5. Document exceptions with business justification

Estimated time: 16-24 hours for baseline implementation across platforms

Step 4: Configure Defender for Identity and Cloud Apps

Defender for Identity detects identity-based attacks (credential theft, lateral movement). Defender for Cloud Apps provides visibility and control over SaaS applications.

4.1 Configure Defender for Identity:

  1. Go to security.microsoft.com → Settings → Identities
  2. For hybrid environments (on-prem AD):Download and install sensors on all domain controllers
  3. Configure Directory Services account (read access to AD)
  4. Configure VPN integration if using Always On VPN
  5. Configure SIEM notifications if applicable
  6. For cloud-only environments:Defender for Identity integrates automatically with Entra ID
  7. Ensure Entra ID P2 is licensed for full Identity Protection
  8. Configure entity tags:Mark sensitive accounts (executives, IT admins, service accounts)
  9. Create honeytoken accounts (fake accounts to detect reconnaissance)
  10. Tag sensitive groups (Domain Admins, Enterprise Admins)

4.2 Configure Identity Threat Detections:

  1. Go to Settings → Identities → Detections
  2. Review and tune these detections:Reconnaissance: LDAP reconnaissance, Account enumeration, Network mapping
  3. Compromised credentials: Brute force, Password spray, Kerberoasting
  4. Lateral movement: Pass-the-hash, Pass-the-ticket, Remote code execution
  5. Domain dominance: DCSync, DCShadow, Golden ticket, Skeleton key
  6. Exfiltration: Suspicious data collection, DNS tunneling
  7. Configure exclusions for known legitimate activities (e.g., vulnerability scanners)
  8. Set up alert notifications to security team

4.3 Configure Defender for Cloud Apps:

  1. Go to security.microsoft.com → Cloud apps
  2. Connect apps for visibility:Microsoft 365 (automatic)
  3. Salesforce, Box, Dropbox, Google Workspace (if used)
  4. AWS, Azure, GCP (for cloud posture)
  5. Any SaaS apps with API connectors available
  6. Configure discovery:Enable Cloud Discovery to find shadow IT
  7. Upload firewall/proxy logs or use Defender for Endpoint integration
  8. Review discovered apps weekly
  9. Sanction approved apps, unsanction risky ones

4.4 Create Cloud App Security Policies:

  1. Go to Cloud apps → Policies → Policy management
  2. Create these essential policies:Mass download alert: Alert when user downloads excessive files
  3. Risky sign-in: Alert on sign-ins from new locations or devices
  4. Activity from infrequent country: Detect compromised accounts
  5. Ransomware activity: Detect rapid file changes (encryption)
  6. External sharing: Alert when sensitive files shared externally
  7. Malware detection: Block or quarantine malicious files
  8. Stale external sharing: Review old external shares

4.5 Configure Session Controls:

  1. For high-risk scenarios, use Conditional Access App Control:In Conditional Access, select "Use Conditional Access App Control"
  2. Session policy: Monitor, Block downloads, or Block cut/copy/paste
  3. Example: Allow access from unmanaged device, but block file downloads
  4. Example: Monitor all activity from high-risk sign-ins
  5. Deploy for sensitive applications first (financial systems, HR systems)

Session Control Use Cases

Scenario 1: User signs in from personal device. Allow access to read email, but block downloading attachments.

Scenario 2: High-risk sign-in detected. Allow access but monitor all actions and alert on sensitive operations.

Scenario 3: Contractor accessing HR system. Block copy/paste to prevent data exfiltration.

4.6 Review and Respond to Alerts:

  1. Establish alert review process (daily for high severity, weekly for medium)
  2. Configure alert notification rules to on-call security
  3. Create investigation playbooks for common alerts
  4. For each alert, document:Was it a true positive or false positive?
  5. What investigation steps were taken?
  6. What remediation was performed?
  7. Should detection tuning be adjusted?
  8. Review Microsoft Secure Score weekly and address new recommendations

Estimated time: 8-16 hours for identity and cloud app security configuration

Security Stack Checklist

  1. Defender for Endpoint deployed to all Windows devices
  2. Defender for Endpoint deployed to all Macs
  3. Attack Surface Reduction rules enabled (Block mode)
  4. Automated investigation and remediation enabled
  5. Web content filtering configured
  6. Security alert notifications configured
  7. Safe Attachments policy configured
  8. Safe Links policy configured
  9. Anti-phishing policy with impersonation protection
  10. Anti-spam policies tuned
  11. User reporting enabled and add-in deployed
  12. Attack simulation training scheduled monthly
  13. CIS Level 1 baseline applied to Windows
  14. CIS baseline applied to macOS
  15. Microsoft 365 Secure Score reviewed and optimized
  16. Browser security policies deployed
  17. Defender for Identity configured (sensors deployed if hybrid)
  18. Defender for Cloud Apps connected to key SaaS apps
  19. Cloud discovery enabled for shadow IT
  20. Cloud app security policies created
  21. Alert review process established
  22. Weekly security review scheduled


04 · Compliance & Governance

Build compliance in from day one. When auditors come calling, you want evidence ready - not a scramble to document what you should have been doing. Microsoft Purview provides the tools to classify, protect, retain, and audit your organization's data across all Microsoft 365 workloads.

Prerequisites

Before configuring compliance and governance, ensure you have:

  1. Microsoft 365 E3/E5 or Business Premium (DLP, retention, audit)
  2. Microsoft 365 E5 Compliance add-on for advanced features (or E5 license)
  3. Compliance Administrator or Global Administrator role
  4. Understanding of regulatory requirements (HIPAA, PCI-DSS, SOC 2, etc.)
  5. Data classification scheme approved by stakeholders
  6. Legal review of retention and deletion policies
  7. HR involvement for employee monitoring features

Step 1: Configure Data Loss Prevention (DLP)

DLP policies automatically detect sensitive information (SSNs, credit cards, health records, etc.) and can warn users, block sharing, or notify administrators when data is at risk of exposure.

1.1 Identify Sensitive Data Types:

  1. Go to compliance.microsoft.com → Data classification → Sensitive info types
  2. Review built-in sensitive information types relevant to your organization
  3. Common types by regulation:HIPAA: U.S. Social Security Number, Drug Enforcement Agency (DEA) Number, ICD codes
  4. PCI-DSS: Credit Card Number, Credit Card Expiration Date
  5. GDPR: EU National Identification Numbers, EU Passport Numbers
  6. General: Bank Account Numbers, Driver's License Numbers
  7. Create custom sensitive info types if needed:Patient ID numbers (specific format)
  8. Internal project codes
  9. Employee ID numbers
  10. Custom account numbers

1.2 Create DLP Policies:

  1. Go to Data loss prevention → Policies → Create policy
  2. Choose template or create custom policy
  3. Recommended policies to create:Financial Data Protection: Credit cards, bank accounts
  4. PII Protection: SSN, driver's license, passport
  5. Health Information: If HIPAA applies
  6. Confidential Documents: Based on sensitivity labels
  7. For each policy, configure:Locations: Exchange, SharePoint, OneDrive, Teams, Endpoints (Windows/Mac)
  8. Content conditions: Which sensitive info types, how many instances
  9. Actions: User notifications, admin alerts, block sharing

1.3 Configure Policy Rules:

  1. Low volume rule (1-9 instances):Show policy tip to user
  2. Send incident report to compliance team
  3. Allow override with business justification
  4. High volume rule (10+ instances):Block sharing outside organization
  5. Require encryption if sharing internally
  6. Send high-priority alert to compliance team
  7. No override allowed (or manager approval required)
  8. Context matters:Content shared with external recipients: More restrictive
  9. Content shared internally: Less restrictive (warn, allow override)
  10. Content on endpoints: Block copy to USB, cloud storage

1.4 Configure User Notifications:

  1. In policy settings, enable user notifications
  2. Customize policy tip text:Explain why the action was blocked or flagged
  3. Link to your data handling policy
  4. Provide contact for questions
  5. Email notifications:Notify user who triggered the policy
  6. Notify content owner (for SharePoint/OneDrive)
  7. Notify compliance team for high-severity incidents

1.5 Test in Simulation Mode:

  1. Create policies in "Test it out first" mode
  2. Let policies run for 2-4 weeks without enforcement
  3. Review DLP reports: Data loss prevention → Activity explorer
  4. Identify and address:False positives (legitimate content flagged)
  5. False negatives (sensitive content not detected)
  6. User workflows that will be disrupted
  7. Exclusions needed for specific sites/users
  8. Tune rules based on findings
  9. Switch to enforcement mode

Critical: Never skip simulation mode. A poorly tuned DLP policy will either block legitimate business activities or fail to protect sensitive data. Both outcomes are unacceptable.

1.6 Endpoint DLP (Windows/Mac):

  1. Requires Microsoft 365 E5 or E5 Compliance
  2. Devices must be onboarded to Defender for Endpoint
  3. Endpoint DLP can block:Copy to USB storage devices
  4. Copy to network shares
  5. Upload to cloud storage (Dropbox, Google Drive)
  6. Copy to clipboard for use in other apps
  7. Print sensitive documents
  8. Access via unallowed apps
  9. Configure allowed apps, printers, USB devices
  10. Test thoroughly before enforcement

Estimated time: 12-20 hours for comprehensive DLP implementation

Step 2: Set Up Retention Policies

Retention policies automatically keep data for required periods and delete it when no longer needed. This is essential for compliance (proving you kept records) and risk management (not keeping data longer than necessary).

2.1 Define Retention Requirements:

  1. Common retention periods by regulation:HIPAA: 6 years from creation or last effective date
  2. SOX (financial): 7 years
  3. Tax records: 7 years (IRS)
  4. Employee records: 7 years after termination
  5. Contracts: 7-10 years after expiration
  6. General business records: 3-7 years
  7. Email (typical): 3-7 years
  8. Document retention schedule with legal counsel approval
  9. Identify exceptions (litigation hold, regulatory investigation)

2.2 Create Retention Labels:

  1. Go to Data lifecycle management → Microsoft 365 → Labels
  2. Create label → Retention label
  3. Example labels:Retain-7-Years: Retain for 7 years, then delete
  4. Retain-3-Years: Retain for 3 years, then delete
  5. Permanent-Record: Retain forever, mark as record
  6. Delete-After-1-Year: Delete after 1 year
  7. Regulatory-Record: Retain 7 years, regulatory record (can't be modified)
  8. For each label, configure:Retention period (days, months, years)
  9. Retention trigger: When created, when labeled, when modified, or event-based
  10. At end of retention: Delete automatically, trigger disposition review, or do nothing
  11. Mark as record: Prevents editing/deletion during retention

2.3 Publish Labels to Users:

  1. Go to Label policies → Publish labels
  2. Select labels to publish
  3. Choose locations: SharePoint, OneDrive, Exchange, Teams
  4. Select users/groups (or all)
  5. Optional settings:Require users to apply a label (mandatory labeling)
  6. Apply default label to new content
  7. Train users on when to apply each label

2.4 Create Auto-Apply Retention Policies:

  1. Go to Policies → Retention policies
  2. Create policy → Adaptive or Static
  3. Static policies (simpler):Apply to all Exchange mailboxes: Retain 7 years
  4. Apply to all SharePoint sites: Retain 5 years
  5. Apply to all Teams: Retain 3 years
  6. Adaptive policies (more flexible):Based on user attributes (department, location)
  7. Based on site properties
  8. Example: HR SharePoint sites retain 10 years

Retention Policy vs. Retention Label

Policies: Apply automatically to locations (all mailboxes, all sites). Users don't see them. Good for baseline retention.

Labels: Can be applied by users or auto-applied based on content. Users can see them. Good for classification and special handling.

2.5 Configure Disposition Review:

  1. For records that need review before deletion, enable disposition review
  2. Configure:Reviewers: Who approves deletion
  3. Notification: Email when items are ready for review
  4. Review stage: Can add multiple approval stages
  5. Reviewers access items at: compliance.microsoft.com → Data lifecycle management → Disposition
  6. Actions: Approve deletion, extend retention, apply different label, release as record

2.6 Configure Litigation Hold:

  1. When litigation is anticipated or ongoing, apply hold to preserve evidence
  2. Go to eDiscovery → Cases → Create case
  3. Add custodians (users whose data must be preserved)
  4. Place on hold: All content or specific content
  5. Hold prevents:Users from permanently deleting content
  6. Retention policies from deleting content
  7. Content from being modified (if immutable hold)
  8. Document hold with legal team
  9. Release hold when litigation concludes

Legal Requirement: Failure to preserve data when litigation is reasonably anticipated can result in severe sanctions (spoliation). Always involve legal counsel when implementing holds.

Estimated time: 12-16 hours for retention strategy + legal review

Step 3: Configure Audit Logging

Audit logs record every action in Microsoft 365 - who accessed what, when, and from where. Essential for security investigations, compliance evidence, and insider threat detection.

3.1 Verify Audit Logging is Enabled:

  1. Go to compliance.microsoft.com → Audit
  2. If you see "Start recording user and admin activity", click it
  3. Note: Audit logging is ON by default for most tenants since January 2019
  4. Verify by searching for recent activity

3.2 Configure Audit Log Retention:

  1. Default retention:E3/Business Premium: 90 days (can extend to 180 days)
  2. E5/E5 Compliance: 1 year by default, up to 10 years
  3. Go to Audit → Audit retention policies
  4. Create retention policies for:All activities: 1 year (baseline)
  5. High-value activities (admin actions, mailbox access): 7 years
  6. Security events (sign-ins, password changes): 7 years
  7. Assign policies to users, groups, or all users

3.3 Enable Mailbox Auditing:

  1. Mailbox auditing is ON by default since January 2019
  2. Actions logged by default:Owner: HardDelete, MailItemsAccessed, SoftDelete, Update, etc.
  3. Delegate: Create, HardDelete, SendAs, SendOnBehalf, etc.
  4. Admin: Copy, HardDelete, MessageBind, etc.
  5. Verify: Get-OrganizationConfig | FL AuditDisabled (should be False)
  6. For specific mailboxes: Get-Mailbox -Identity user@domain.com | FL Audit*

3.4 Configure Entra ID Audit Logs:

  1. Go to entra.microsoft.com → Monitoring → Audit logs
  2. Key events to monitor:User creation/deletion
  3. Password resets
  4. Role assignments
  5. Conditional Access policy changes
  6. Application registrations
  7. Group membership changes
  8. Configure sign-in logs: Same location → Sign-in logs
  9. Default retention:Free/P1: 7 days
  10. P2: 30 days
  11. For longer retention, export to Log Analytics or storage account

3.5 Set Up Audit Log Alerts:

  1. Go to compliance.microsoft.com → Audit → Audit search → New search
  2. Create saved searches for critical events:Admin role assignments
  3. External sharing of sensitive files
  4. Mail forwarding rule creation
  5. eDiscovery searches (who's searching what)
  6. DLP policy matches
  7. Sensitivity label changes
  8. For real-time alerts, use Microsoft Sentinel or Defender XDR alert policies
  9. Go to security.microsoft.com → Policies → Alert policy
  10. Create alerts for high-priority events

3.6 Export Logs for Long-Term Storage:

  1. Option 1: Azure Log AnalyticsCreate Log Analytics workspace in Azure
  2. Configure diagnostic settings in Entra ID
  3. Export: Sign-in logs, Audit logs, Provisioning logs
  4. Query with KQL (Kusto Query Language)
  5. Retention: Up to 2 years (or archive to storage)
  6. Option 2: Azure Storage AccountCreate storage account with immutable blob storage (WORM)
  7. Configure diagnostic settings to stream to storage
  8. Retention: As long as needed
  9. Cost-effective for long-term archival
  10. Option 3: SIEM IntegrationMicrosoft Sentinel (native integration)
  11. Splunk, IBM QRadar, etc. (via Event Hub)

Compliance Tip

Many regulations require 7 years of audit log retention. Default M365 retention is insufficient. Plan for long-term storage from day one - you can't recover logs that were never stored.

Estimated time: 4-8 hours for audit configuration + storage setup

Step 4: Implement Sensitivity Labels

Sensitivity labels classify and protect data based on how sensitive it is. They can apply encryption, watermarks, access restrictions, and travel with the data even outside your organization.

4.1 Design Classification Scheme:

  1. Recommended classification levels:Public: Information intended for public release. No restrictions.
  2. Internal: General business information. Not for external sharing.
  3. Confidential: Sensitive business information. Restricted access.
  4. Highly Confidential: Most sensitive data. Encrypted, strict controls.
  5. Add sub-labels for specific use cases:Confidential \ All Employees
  6. Confidential \ Finance Only
  7. Confidential \ HR Only
  8. Highly Confidential \ Project X
  9. Document classification criteria with examples
  10. Get stakeholder approval before implementation

4.2 Create Sensitivity Labels:

  1. Go to compliance.microsoft.com → Information protection → Labels
  2. Create label for each classification level
  3. Label settings:Name and description (what users see)
  4. Scope: Files, emails, meetings, containers (sites/teams)
  5. Protection settings: See next step
  6. Auto-labeling: See step 4.4
  7. Label priority: Higher priority labels override lower

4.3 Configure Protection Settings:

  1. Public label:No encryption
  2. No content marking
  3. No restrictions
  4. Internal label:No encryption (or encrypt with "Anyone in org" access)
  5. Footer: "Internal Use Only"
  6. Confidential label:Encryption: Assign permissions now
  7. Permissions: All authenticated users can view, org users can edit
  8. Header: "Confidential"
  9. Footer: "Do not share externally"
  10. Watermark: Optional
  11. Highly Confidential label:Encryption: Specific users/groups only
  12. Permissions: View only (no print, copy, forward)
  13. Offline access: Limited to 7 days
  14. Header/Footer: "Highly Confidential - Restricted"
  15. Watermark: User's email address
  16. Prevent forwarding/copy for email

Encryption Considerations: Encrypted documents can't be indexed for search by users who don't have access. Some external recipients may have trouble opening encrypted documents. Test thoroughly with key partners before requiring encryption on shared content.

4.4 Configure Auto-Labeling:

  1. In label settings, enable "Auto-apply this label to content"
  2. Conditions for auto-labeling:Content contains sensitive info types (SSN, credit card)
  3. Content contains specific keywords
  4. Content matches trainable classifiers (requires E5)
  5. Recommended auto-label rules:10+ SSNs → Highly Confidential (auto-apply)
  6. 1-9 SSNs → Confidential (recommend to user)
  7. Credit card numbers → Confidential (auto-apply)
  8. Health information → Highly Confidential (auto-apply)
  9. Choose action:Recommend label: User sees suggestion, can dismiss
  10. Apply label automatically: No user interaction needed

4.5 Create Service-Side Auto-Labeling Policies:

  1. Go to Information protection → Auto-labeling
  2. Create policy for content at rest in SharePoint/OneDrive/Exchange
  3. Different from client-side auto-labeling:Runs on existing content (not just new)
  4. Labels content even when user isn't editing
  5. Requires simulation before deployment
  6. Run in simulation mode for 2+ weeks
  7. Review matched content
  8. Enable auto-labeling after validation

4.6 Publish Labels to Users:

  1. Go to Label policies → Publish labels
  2. Select labels to publish
  3. Choose users/groups (or all users)
  4. Policy settings:Apply default label to: Documents, emails, meetings, sites
  5. Require justification for label removal/downgrade
  6. Require users to apply label (mandatory labeling)
  7. Help link: URL to your classification guide
  8. Deploy labels to pilot group first
  9. Gather feedback, adjust, then deploy to all

4.7 Container Labels (Sites and Teams):

  1. Enable container labels in label settings
  2. Container settings:Privacy: Public, Private, or None (org default)
  3. External sharing: Anyone, Existing guests, Only org, Block
  4. Guest access: Allow or block
  5. Unmanaged device access: Full, limited, or block
  6. Default sharing link: Specific people, org only, or anyone
  7. Users apply container labels when creating Teams or SharePoint sites
  8. Settings enforce automatically for all content in container

4.8 User Training:

  1. Training should cover:What each label means and when to apply it
  2. How to apply labels in Office apps, SharePoint, Teams
  3. What happens when a label is applied (encryption, restrictions)
  4. How to work with encrypted documents
  5. How to share protected content externally
  6. Where to get help
  7. Provide quick reference card with examples
  8. Include in new employee onboarding
  9. Refresh training annually

Estimated time: 16-24 hours for label implementation + user training

Compliance & Governance Checklist

  1. Sensitive info types identified for your organization
  2. DLP policies created for each data type
  3. DLP policies tested in simulation mode
  4. DLP policies deployed with user notifications
  5. Endpoint DLP configured (if applicable)
  6. Retention schedule defined with legal approval
  7. Retention labels created and published
  8. Retention policies applied to all workloads
  9. Litigation hold process documented
  10. Audit logging verified as enabled
  11. Audit log retention extended (7+ years)
  12. Critical event alerts configured
  13. Long-term log storage configured
  14. Classification scheme approved by stakeholders
  15. Sensitivity labels created with appropriate protection
  16. Auto-labeling rules configured and tested
  17. Labels published to all users
  18. Container labels configured for sites/teams
  19. User training delivered
  20. Compliance reports scheduled for review


05 · Enterprise Controls

For larger organizations or those with elevated risk requirements. Advanced controls for deeper visibility and tighter security. These features require Microsoft 365 E5 or equivalent add-on licenses.

Prerequisites

Before implementing enterprise controls, ensure you have:

  1. Microsoft 365 E5 or E5 Security/Compliance add-ons
  2. Entra ID P2 (required for PIM)
  3. Base security controls already in place (Sections 1-4)
  4. HR and Legal approval for monitoring features
  5. Designated security/compliance team members
  6. Executive sponsorship for governance initiatives

Step 1: Privileged Identity Management (PIM)

PIM provides just-in-time, just-enough access for administrative roles. Instead of permanent admin access, users request temporary elevation when they need it. This dramatically reduces the attack surface for privileged accounts.

1.1 Understand PIM Concepts:

  1. Eligible assignment: User can activate the role when needed (requires action)
  2. Active assignment: User has the role permanently (always on)
  3. Activation: Process of temporarily enabling an eligible role
  4. Just-in-time (JIT): Access granted only when needed, for limited time
  5. Just-enough-access (JEA): Minimum permissions required for the task

1.2 Inventory Current Privileged Access:

  1. Go to entra.microsoft.com → Identity governance → Privileged Identity Management
  2. Click on Entra ID roles → Roles
  3. Review each privileged role and its current assignments
  4. High-priority roles to address first:Global Administrator
  5. Privileged Role Administrator
  6. Security Administrator
  7. Exchange Administrator
  8. SharePoint Administrator
  9. User Administrator
  10. Billing Administrator
  11. Document current permanent assignments and who uses them

1.3 Configure Role Settings:

  1. For each role, click Settings
  2. Activation settings:Maximum activation duration: 8 hours (or less for highly sensitive roles)
  3. Require MFA on activation: Yes (always)
  4. Require justification: Yes
  5. Require ticket information: Optional (for change management tracking)
  6. Require approval: Yes for Global Admin, optional for others
  7. Assignment settings:Allow permanent eligible assignment: Yes (for designated admins)
  8. Allow permanent active assignment: No (except break-glass accounts)
  9. Expire eligible assignment after: 1 year (forces annual review)
  10. Expire active assignment after: 8 hours
  11. Notification settings:Send notifications when eligible member activates: Yes
  12. Notify all Privileged Role Administrators
  13. Add security team to notifications

1.4 Convert Permanent Admins to Eligible:

  1. Go to Entra ID roles → Select role (e.g., Global Administrator)
  2. View current active (permanent) assignments
  3. For each user:
  4. Click on the assignment → Edit
  5. Change from Active to Eligible
  6. Set end date (1 year recommended)
  7. Save changes
  8. Notify affected admins before making changes
  9. Provide documentation on how to activate roles

Critical: Keep at least 2 break-glass accounts with permanent Global Admin access (excluded from PIM). These are emergency-only accounts with complex passwords stored securely. Monitor all sign-ins to these accounts.

1.5 Configure Approval Workflows:

  1. For highly sensitive roles, require approval before activation
  2. Go to Role settings → Require approval
  3. Select approvers:Primary: IT Security Manager or Director
  4. Fallback: IT Director or CIO
  5. Never have single approver (vacation, unavailability)
  6. Configure notification to approvers
  7. Set approval timeout (4 hours recommended)

When to Require Approval

Always require: Global Administrator, Privileged Role Administrator

Consider requiring: Exchange Admin, Security Admin, Billing Admin

Usually don't require: Helpdesk Admin, User Admin (for daily operations)

1.6 Set Up Access Reviews:

  1. Go to Identity governance → Access reviews → New access review
  2. Configure review:Review name: "Quarterly Admin Role Review"
  3. Review scope: Directory roles (select privileged roles)
  4. Reviewers: Manager, self-review, or specific reviewers
  5. Recurrence: Quarterly
  6. Duration: 14 days
  7. Auto-apply results: Yes (remove access if not approved)
  8. If reviewer doesn't respond: Remove access
  9. Enable for all privileged roles
  10. Send reminders to reviewers

1.7 Configure PIM Alerts:

  1. Go to PIM → Entra ID roles → Alerts
  2. Enable and configure these alerts:Roles don't require MFA: Should trigger (misconfiguration)
  3. Roles are being activated too frequently: Review threshold
  4. Potential stale accounts: Haven't activated in 90+ days
  5. Roles assigned outside of PIM: Detect shadow assignments
  6. Too many Global Administrators: Limit to 2-4
  7. Roles being assigned without MFA: Critical alert
  8. Configure alert recipients (security team)
  9. Review alerts weekly

1.8 Train Administrators on PIM:

  1. Activation process:Go to Privileged Identity Management → My roles
  2. Find the role you need → Activate
  3. Provide justification (required)
  4. Complete MFA (required)
  5. Wait for approval (if required)
  6. Role is active for configured duration
  7. Role automatically deactivates when time expires
  8. Document common scenarios and which roles to activate
  9. Provide emergency escalation process

Estimated time: 12-20 hours for full PIM implementation

Step 2: Insider Risk Management

Insider Risk Management detects potentially risky user behavior - data theft, security violations, or policy breaches - before they become incidents. It correlates signals across Microsoft 365 to identify concerning patterns.

2.1 Prerequisites and Privacy Considerations:

  1. Required licenses:Microsoft 365 E5
  2. Or M365 E3 + E5 Insider Risk Management add-on
  3. Or M365 E3 + E5 Compliance add-on
  4. Before implementation, involve:Legal: Review privacy laws, employee monitoring regulations
  5. HR: Align with employee policies, union considerations
  6. Works council: If applicable in your jurisdiction
  7. Privacy officer: Data protection impact assessment
  8. Document business justification for monitoring
  9. Update employee handbook/policies to disclose monitoring

Privacy Alert: Insider Risk Management monitors user behavior. Many jurisdictions require employee notification and consent. Some prohibit certain types of monitoring entirely. Always get legal approval first.

2.2 Configure Prerequisites:

  1. Go to compliance.microsoft.com → Insider risk management
  2. Enable audit logging:Required for activity correlation
  3. Should already be enabled from Section 4
  4. Configure HR connector (optional but powerful):Go to Settings → Data connectors → HR
  5. Connect to your HR system (Workday, SAP, custom CSV)
  6. Import: Resignation date, termination date, performance status
  7. This enables "departing employee" triggering events
  8. Define priority users (optional):Go to Settings → Priority user groups
  9. Add users with access to sensitive data
  10. Add users in high-risk roles (finance, IT, executives)
  11. These users get enhanced monitoring

2.3 Create Insider Risk Policies:

  1. Go to Policies → Create policy
  2. Policy templates available:Data theft by departing users: Detects data exfiltration before/after resignation
  3. General data leaks: Detects accidental or intentional data exposure
  4. Data leaks by priority users: Enhanced monitoring for high-risk users
  5. Data leaks by disgruntled users: Correlates with HR performance data
  6. Security policy violations: Detects circumventing security controls
  7. Patient data misuse: Healthcare-specific (requires healthcare data)
  8. Start with "Data theft by departing users" - highest ROI

2.4 Configure Policy Settings:

  1. Triggering events (what starts monitoring):User submits resignation (from HR connector)
  2. User is terminated (from HR connector)
  3. User removed from group (e.g., removed from project team)
  4. User on performance improvement plan (from HR)
  5. Manual: Add user to policy scope
  6. Indicators to detect (what behavior to monitor):Downloading large amounts of files from SharePoint/OneDrive
  7. Copying files to USB devices (Endpoint DLP signals)
  8. Uploading to personal cloud storage
  9. Sending emails with attachments to personal accounts
  10. Printing unusual volumes
  11. Accessing files outside normal working hours
  12. Accessing files not normally accessed by this role
  13. Thresholds:Set what's "unusual" - e.g., downloading 100+ files when normal is 10
  14. Start with default thresholds, tune based on alerts

2.5 Configure Privacy Settings:

  1. Go to Settings → Privacy
  2. Anonymization:Enable pseudonymization: User names shown as "User-1234"
  3. Investigators can't see real names until escalation
  4. Requires approval to de-anonymize
  5. Data handling:Set data retention period for alerts (default 120 days)
  6. Configure who can view case data
  7. Enable audit logging of investigator actions

2.6 Set Up Alert and Case Management:

  1. Alert workflow:Alert generated → Triage (is this real?) → Case (investigate)
  2. Cases can have multiple alerts
  3. Configure alert severity thresholds:Low: Informational, review weekly
  4. Medium: Review within 48 hours
  5. High: Review within 24 hours
  6. Case actions:Dismiss: False positive, document why
  7. Escalate: Send to HR, Legal, or management
  8. Send notice: Automated warning to user
  9. Create eDiscovery case: Preserve evidence for investigation

2.7 Train Investigation Team:

  1. Role assignments:Insider Risk Management Analysts: Triage alerts
  2. Insider Risk Management Investigators: Full case access
  3. Insider Risk Management Admins: Configure policies
  4. Training should cover:How to review and triage alerts
  5. What constitutes actionable vs. false positive
  6. Proper documentation of investigation steps
  7. When to escalate to HR/Legal
  8. Evidence preservation requirements
  9. Privacy and confidentiality obligations
  10. Document escalation procedures

Estimated time: 20-32 hours for implementation + legal/HR coordination

Step 3: Viva Insights (Organizational Analytics)

Viva Insights provides data-driven insights into how your organization works - meeting culture, focus time, work-life balance, and collaboration patterns. Not a security control, but valuable for organizational health.

3.1 Understand Viva Insights Tiers:

  1. Personal insights: Individual productivity data (free with M365)
  2. Manager insights: Team-level aggregated data (requires Viva license)
  3. Leader insights: Organization-wide trends (requires Viva license)
  4. Advanced insights: Custom queries, research-grade data (requires premium)

3.2 Configure Privacy Settings:

  1. Go to Microsoft 365 admin center → Settings → Org settings → Viva Insights
  2. Privacy controls:Minimum aggregation threshold: 10 people (can't see groups smaller than this)
  3. Opt-out: Allow users to opt out of personal insights
  4. Manager access: Control what managers can see about their teams
  5. Excluded groups: Exclude sensitive groups (executives, HR)

Privacy by Design

Viva Insights is designed with privacy in mind. Individual data is never shown to managers or leaders. All insights are aggregated and anonymized. The minimum threshold prevents identification of individuals in small teams.

3.3 Enable and Configure:

  1. Assign Viva Insights licenses to users
  2. Personal insights (automatic):Digest email: Weekly summary of work patterns
  3. Focus time: Schedule blocks for deep work
  4. Meeting effectiveness: Track meeting habits
  5. Collaboration hours: Monitor work-life balance
  6. Manager insights:Managers see aggregated team data
  7. After-hours work trends
  8. Meeting load analysis
  9. 1:1 meeting frequency
  10. Organizational data upload (optional):Upload HR data: Department, location, level, function
  11. Enables insights by org segment
  12. E.g., "Engineering spends 30% more time in meetings than Sales"

3.4 Use Insights for Organizational Health:

  1. Key metrics to track:After-hours collaboration: Burnout indicator
  2. Meeting-free time: Availability for focus work
  3. Manager 1:1 frequency: Employee engagement indicator
  4. Network size: Collaboration breadth
  5. Double-booked meetings: Calendar hygiene
  6. Set up quarterly reviews with leadership
  7. Use data to inform policy changes (e.g., "meeting-free Fridays")

Estimated time: 4-8 hours for setup and configuration

Step 4: eDiscovery (Premium)

eDiscovery finds, preserves, and exports content for legal and compliance investigations. Premium adds advanced analytics, review workflows, and custodian management.

4.1 eDiscovery Tiers:

  1. Content search: Basic search across M365 (included with E3)
  2. eDiscovery Standard: Case management, holds, export (E3)
  3. eDiscovery Premium: Custodians, review sets, analytics, predictive coding (E5)

4.2 Assign eDiscovery Permissions:

  1. Go to compliance.microsoft.com → Permissions
  2. Role groups:eDiscovery Manager: Create cases, run searches, manage holds
  3. eDiscovery Administrator: Full access to all cases
  4. Reviewer: View and tag content (no search/export)
  5. Assign minimal necessary permissions
  6. Log who has eDiscovery access

Security Note: eDiscovery provides access to potentially all organizational content. Limit access strictly. Audit all eDiscovery activity. Consider requiring manager approval for case creation.

4.3 Create and Manage Cases:

  1. Go to eDiscovery → Cases → Create case
  2. Case structure:Case name: Use consistent naming (e.g., "Legal-2024-001-SmithVCompany")
  3. Description: Matter number, legal counsel, purpose
  4. Members: Who can access this case
  5. Premium cases include:Custodians: People whose data is being collected
  6. Data sources: Specific mailboxes, sites, Teams
  7. Holds: Preserve data from deletion
  8. Review sets: Collected content for analysis
  9. Jobs: Processing and export tasks

4.4 Implement Legal Holds:

  1. When to place holds:Litigation is filed or reasonably anticipated
  2. Regulatory investigation
  3. Internal investigation
  4. Audit requirement
  5. Hold types:In-place hold: Preserves all content for custodian
  6. Query-based hold: Preserves content matching criteria
  7. Retention hold: Uses retention policy (Section 4)
  8. Hold process:Document hold requirement from Legal
  9. Identify custodians and data sources
  10. Create hold in eDiscovery case
  11. Verify hold is applied
  12. Track hold status
  13. Release hold only with Legal approval

4.5 Search and Collect Content:

  1. Build search queries:Date range: sent:2023-01-01..2023-12-31
  2. Keywords: "project alpha" OR "project beta"
  3. Sender/recipient: from:john@company.com
  4. File types: filetype:xlsx OR filetype:pdf
  5. Locations: Specific mailboxes, SharePoint sites
  6. Preview results before collection
  7. Add results to review set for analysis

4.6 Review and Analyze (Premium):

  1. Review set features:Near-duplicate detection: Group similar documents
  2. Email threading: View conversations together
  3. Themes: AI-identified topics in content
  4. Relevance tagging: Train model to prioritize relevant content
  5. Tagging:Create tag structure (Responsive, Non-Responsive, Privileged)
  6. Assign reviewers to tag content
  7. Track review progress
  8. Use analytics to reduce review volume

4.7 Export for Production:

  1. Export options:Native format: Original file types
  2. PDF: All content converted to PDF
  3. PST: Email exported as Outlook archive
  4. Include metadata in load file
  5. Download export package
  6. Transfer to external counsel or review platform
  7. Document chain of custody

Estimated time: Varies by case (hours to hundreds of hours)

Enterprise Controls Checklist

  1. PIM enabled for Entra ID roles
  2. All privileged roles converted to eligible assignments
  3. Break-glass accounts documented and monitored
  4. Approval workflows configured for high-sensitivity roles
  5. Access reviews scheduled for all admin roles
  6. PIM alerts configured and monitored
  7. Administrators trained on activation process
  8. Insider Risk Management approved by Legal/HR
  9. HR connector configured (if applicable)
  10. Initial insider risk policies created
  11. Investigation team trained
  12. Privacy settings configured appropriately
  13. Viva Insights enabled with privacy controls
  14. eDiscovery permissions assigned appropriately
  15. Legal hold process documented
  16. eDiscovery audit logging enabled


06 · People & Process

Technology without documentation and training is just expensive equipment. This is where most organizations fail - and where we differentiate. The best security tools in the world can't protect you from an employee who clicks on a phishing link or shares their password.

Prerequisites for People & Process

  1. Leadership buy-in for security culture
  2. Designated policy owner (HR, Legal, or IT)
  3. Microsoft 365 or equivalent for document management
  4. Budget for training platform (optional but recommended)
  5. Understanding of regulatory requirements (HIPAA, PCI-DSS, etc.)

Required Policies

Written policies are not optional - they're legally required for most compliance frameworks. Every employee must acknowledge these annually, and they must be reviewed and updated regularly. Insurance companies and auditors will ask for these first.

Core Security Policies (Required)

  1. Acceptable Use Policy (AUP) - Defines permitted use of company technology, email, internet access, and data handling. Typically 5-10 pages covering prohibited activities, monitoring disclosure, and consequences.
  2. Information Security Policy - High-level security framework covering data classification, access controls, incident response, and security responsibilities. Often serves as the master policy that other policies reference.
  3. Password & Authentication Policy - Minimum length (14+ characters), complexity requirements, MFA mandates, password manager requirements, sharing prohibitions, and service account management.
  4. Data Classification Policy - Categories (Public, Internal, Confidential, Restricted), handling requirements for each level, labeling requirements, and destruction procedures.
  5. Incident Response Policy - What constitutes an incident, reporting requirements, escalation procedures, communication protocols, and post-incident review requirements.
  6. Data Retention & Destruction Policy - What data to keep, how long to keep it, legal hold procedures, and secure destruction methods.

Additional Policies by Scenario

  1. Remote Work Policy - VPN requirements, approved home network configurations, physical security (screen locks, visitor policies), prohibited locations (coffee shops, co-working spaces for sensitive work).
  2. BYOD Policy - If personal devices are allowed: MDM requirements, minimum OS versions, remote wipe consent, company data containerization, prohibited device types.
  3. Vendor Management Policy - Due diligence requirements, security assessments, contractual requirements (SOC 2, BAA for healthcare), access provisioning and revocation, ongoing monitoring.
  4. Change Management Policy - Change classification (standard, emergency), approval requirements, testing mandates, rollback procedures, documentation requirements.
  5. Physical Security Policy - Badge access, visitor procedures, clean desk policy, device lock requirements, sensitive area restrictions.

Policy Management in Microsoft 365

Use SharePoint + Power Automate for policy lifecycle management:

  1. Store policies in a dedicated SharePoint site with version control
  2. Use metadata columns for: Version, Effective Date, Review Date, Owner
  3. Set up Power Automate flows for annual review reminders
  4. Track acknowledgments in a SharePoint list or use Forms for signatures
  5. Apply sensitivity labels to policy documents to prevent unauthorized sharing
  6. Configure retention labels to maintain policy versions for audit purposes

Important: Policies without enforcement are meaningless. Every policy must have corresponding technical controls or audit procedures. If your Password Policy says "14 characters minimum" but Entra ID allows 8, you have a compliance gap.

Annual Policy Review Process

  1. Schedule annual review dates for each policy (stagger throughout the year)
  2. Review against current regulatory requirements and industry standards
  3. Update for new technologies, threats, or business changes
  4. Obtain legal review for significant changes
  5. Communicate changes to all employees with re-acknowledgment requirement
  6. Maintain review logs for audit purposes

Estimated time: 40-80 hours initial creation, 20-30 hours annual review cycle

Standard Operating Procedures

If it's not documented, it's not repeatable - and it's definitely not auditable. SOPs ensure consistent execution regardless of who performs the task. They're also critical for business continuity when key personnel are unavailable.

User Lifecycle SOPs

  1. User Onboarding SOP - HR notification triggers, account creation checklist (Entra ID, email, Teams, applications), device assignment process, security training enrollment, manager approval steps, Day 1 orientation checklist.
  2. User Offboarding SOP - Immediate termination procedure (within 15 minutes of notification), standard termination procedure (planned departure), account disabling sequence, email forwarding/delegation, data preservation for legal hold, device return and wipe, access revocation checklist.
  3. Role Change SOP - Access review for previous role, new access provisioning, manager approval requirements, audit trail documentation.
  4. Contractor/Vendor Onboarding - Guest account creation, limited access provisioning, NDA confirmation, expiration date setting, sponsor assignment.

Security Operations SOPs

  1. Security Incident Response SOP - Detection and triage procedures, severity classification, containment actions by incident type, evidence preservation, escalation matrix, communication templates, recovery procedures, post-incident review.
  2. Password Reset SOP - Identity verification requirements (knowledge questions, manager callback, video verification for high-risk accounts), reset methods by account type, temporary password handling, audit logging.
  3. Phishing Response SOP - User reporting procedures, initial triage, mailbox search for additional recipients, quarantine actions, sender blocking, user communication, remediation if credentials compromised.
  4. Vulnerability Management SOP - Scanning schedule, risk rating criteria, remediation timelines by severity (critical: 48hrs, high: 7 days, medium: 30 days), exception request process, verification procedures.

IT Operations SOPs

  1. Change Management SOP - Change request submission, categorization (standard, normal, emergency), CAB review requirements, testing requirements, implementation windows, rollback triggers, post-implementation review.
  2. Backup Verification SOP - Daily backup status review, weekly restore testing, monthly full recovery drill, quarterly disaster recovery test, documentation of all test results.
  3. Patch Management SOP - Patch Tuesday procedures, testing requirements, deployment rings (pilot → early adopters → broad deployment), emergency patch procedures, rollback criteria.
  4. Access Review SOP - Quarterly review triggers, manager certification requirements, privileged access monthly review, orphaned account identification, remediation timelines.

SOP Documentation Standards

Every SOP should include:

  1. Purpose - Why this procedure exists
  2. Scope - When it applies and to whom
  3. Roles & Responsibilities - Who does what
  4. Prerequisites - What must be in place first
  5. Procedure Steps - Numbered, detailed actions
  6. Decision Points - Flowcharts for complex decisions
  7. Escalation Paths - When and how to escalate
  8. Documentation Requirements - What to log/record
  9. Revision History - Version control and changes

SOP Automation Opportunities

  1. User onboarding/offboarding via Identity Governance lifecycle workflows
  2. Access reviews via Entra ID Access Reviews (automated reminders, escalation)
  3. Patch deployment via Intune Update Rings (automated, policy-driven)
  4. Backup verification via automated alerts and reports
  5. Incident creation via Defender XDR integration with ticketing system

Estimated time: 20-40 hours for core SOPs, 8-16 hours for automation setup

Security Awareness Training

Your employees are either your strongest defense or your biggest vulnerability. 94% of malware is delivered via email, and social engineering is the leading attack vector. Training isn't optional - it's essential.

Training Program Structure

  1. New Hire Security Orientation - Required within first week. Cover: password requirements, phishing recognition, data handling, incident reporting, acceptable use overview. Duration: 30-60 minutes.
  2. Annual Security Awareness Training - Required for all employees. Cover: current threat landscape, social engineering tactics, data protection, physical security, incident reporting, policy review. Duration: 45-90 minutes.
  3. Role-Based Training - Additional training for specific roles: developers (secure coding), finance (BEC prevention), HR (data privacy), IT admins (privileged access security). Duration: 30-60 minutes per topic.
  4. Just-In-Time Training - Triggered by specific actions: clicking simulated phishing, violating DLP policy, failing password requirements. Brief, targeted reinforcement.

Phishing Simulation Program

Regular simulations train employees to recognize threats in real-world conditions:

  1. Frequency - Monthly simulations minimum, varied timing to prevent pattern recognition.
  2. Difficulty Progression - Start with obvious phishing, gradually increase sophistication. Include: credential harvesting, malware attachments, business email compromise, QR code phishing.
  3. Immediate Feedback - Users who click receive instant training explaining what they missed. No public shaming.
  4. Reporting Mechanism - Easy "Report Phishing" button in Outlook. Track report rates, not just click rates.
  5. Metrics Tracking - Click rate, report rate, time to report, improvement trends, repeat offenders.

Attack Simulation Training in Microsoft 365

Microsoft 365 E5 or Defender for Office 365 P2 includes Attack Simulation Training:

  1. Navigate to: security.microsoft.com → Email & collaboration → Attack simulation training
  2. Use payload automations for continuous, randomized campaigns
  3. Target specific groups based on risk (executives, finance, new hires)
  4. Assign training automatically based on simulation results
  5. Review training completion reports and simulation metrics
  6. Configure repeat offender policies for additional intervention

Note: Inform your email security vendor before running simulations. Allowlist simulation domains to prevent blocking. Never use simulations as punishment.

Training Topics by Threat Type

  1. Phishing & Social Engineering - URL inspection, sender verification, urgency/fear tactics, callback phishing, vishing (voice phishing), smishing (SMS phishing).
  2. Business Email Compromise (BEC) - Executive impersonation, vendor payment fraud, gift card scams, invoice manipulation. Key for finance and executives.
  3. Password Security - Password manager usage, recognizing fake login pages, MFA importance, not sharing credentials, reporting compromised passwords.
  4. Data Handling - Classification levels, sharing restrictions, external collaboration rules, removable media policies, disposal procedures.
  5. Physical Security - Tailgating prevention, visitor procedures, clean desk policy, screen locking, device security in public.
  6. Remote Work Security - Home network security, VPN usage, public Wi-Fi dangers, physical workspace security, video call security.

Measuring Training Effectiveness

  1. Phishing Click Rate - Industry average: 15-20%. Target: under 5%. Track trend over time, not just point-in-time.
  2. Phishing Report Rate - Target: over 70% of users report suspicious emails. More important than click rate.
  3. Time to Report - How quickly do users report? Faster is better for incident response.
  4. Training Completion Rate - Target: 100%. Track overdue assignments.
  5. Knowledge Retention - Pre/post training assessments, periodic quizzes.
  6. Real Incident Metrics - User-reported phishing that was actually malicious, security incidents with human factor.

Building a Security Culture

  1. Make reporting easy and rewarding - recognize users who report threats
  2. No blame culture - people who click are victims, not villains
  3. Executive participation - leadership must complete training publicly
  4. Regular communication - security newsletter, tips of the week
  5. Gamification - leaderboards, badges, team competitions
  6. Real examples - share (anonymized) actual incidents from your organization

Estimated time: 4-8 hours initial setup, 2-4 hours/month ongoing management

People & Process Checklist

  1. All core security policies written and approved by leadership
  2. Policies reviewed against regulatory requirements (HIPAA, PCI-DSS, etc.)
  3. All employees acknowledged policies (documented signatures)
  4. Policy repository set up in SharePoint with version control
  5. Annual policy review calendar established
  6. User onboarding SOP documented and automated where possible
  7. User offboarding SOP documented with immediate termination procedure
  8. Incident response SOP documented with escalation matrix
  9. Change management process defined and enforced
  10. Security awareness training program launched
  11. New hire security orientation in place
  12. Phishing simulation program running monthly
  13. Training completion tracking active with overdue notifications
  14. Report phishing button deployed in Outlook
  15. Training metrics dashboard configured
  16. Role-based training assigned for privileged users


07 · Network & Infrastructure

The foundation everything else runs on. Business-class equipment, proper segmentation, and enterprise-grade monitoring. A poorly designed network undermines every other security control you implement.

Prerequisites for Network & Infrastructure

  1. Budget for business-class equipment (Ubiquiti, Meraki, or equivalent)
  2. Internet service with static IP or DDNS for remote management
  3. Physical access to network closet/equipment room
  4. Current inventory of all network-connected devices
  5. Understanding of bandwidth requirements

Network Architecture

Segment, monitor, and control traffic flow. A flat network where everything can talk to everything is a ransomware attacker's dream. Proper segmentation contains breaches and limits lateral movement.

Network Segmentation Strategy

Create separate VLANs for different security zones:

  1. Corporate VLAN (10) - Managed workstations, company-owned devices. Full access to internal resources, subject to firewall inspection.
  2. Server VLAN (20) - On-premises servers, NAS devices, critical infrastructure. Restricted access, only necessary ports open.
  3. IoT/OT VLAN (30) - Printers, cameras, HVAC systems, medical devices. No internet access unless required, isolated from corporate network.
  4. Guest VLAN (40) - Visitors, personal devices if allowed. Internet only, no access to internal resources, bandwidth throttled.
  5. BYOD VLAN (50) - Personal devices that need limited internal access. Captive portal authentication, restricted to specific resources.
  6. Management VLAN (99) - Network equipment management interfaces. Highly restricted, only IT admin access.

Business-Class Equipment Requirements

  1. Firewall/Router - Next-gen firewall with IDS/IPS, content filtering, VPN capability. Sophos XGS, Fortinet, or Ubiquiti Dream Machine Pro for smaller environments.
  2. Managed Switches - VLAN support, PoE for access points and cameras, port security, SNMP monitoring. Ubiquiti Pro or Enterprise series.
  3. Wireless Access Points - Enterprise-grade with multiple SSID support, WPA3, RADIUS authentication capability, centralized management.
  4. UPS (Uninterruptible Power Supply) - Protect network equipment from power fluctuations. Minimum 15-minute runtime for graceful shutdown.

No Consumer Equipment: Consumer routers (Netgear, Linksys, TP-Link consumer lines) lack security features, receive infrequent updates, and don't support proper segmentation. They're never appropriate for business use.

Firewall Configuration

  1. Default Deny - Block all traffic by default, explicitly allow required traffic. Document every rule.
  2. IDS/IPS Enabled - Intrusion detection and prevention for all traffic. Keep signatures updated.
  3. SSL/TLS Inspection - Decrypt and inspect HTTPS traffic (with appropriate privacy considerations and certificate deployment).
  4. Geo-blocking - Block traffic from countries you don't do business with. Common blocks: Russia, China, North Korea, Iran.
  5. Application Control - Block known malicious applications, control cloud app usage (shadow IT).
  6. DNS Filtering - Block malicious domains at the DNS level before connections are established.

Wireless Network Security

  1. WPA3-Enterprise - Preferred. Uses RADIUS for authentication, individual credentials per user, certificate-based authentication option.
  2. WPA3-Personal - Acceptable for guest networks with strong passphrase (20+ characters), rotated regularly.
  3. Separate SSIDs - Different networks for corporate (RADIUS), guest (captive portal), IoT (isolated), BYOD (certificate or credentials).
  4. 802.1X Authentication - Machine certificates from Intune for managed devices, RADIUS authentication for all.
  5. Client Isolation - Enable on guest and BYOD networks to prevent device-to-device communication.

Network Monitoring & Alerting

  1. SNMP Monitoring - Monitor bandwidth, CPU, memory on all network devices. Alert on thresholds.
  2. NetFlow/sFlow - Traffic analysis for anomaly detection, capacity planning, security investigation.
  3. Syslog Collection - Centralize logs from all network devices for SIEM integration.
  4. Uptime Monitoring - Monitor critical devices, alert on outages. External monitoring for internet connectivity.
  5. Automated Alerts - New device connected, rogue DHCP server, port flapping, high bandwidth consumption.

Network Documentation Requirements

  1. Network diagram (logical and physical) - updated with every change
  2. IP addressing scheme with VLAN assignments
  3. Firewall rule documentation with business justification
  4. Equipment inventory (model, serial, location, warranty)
  5. ISP contact information and circuit details
  6. Change log for all network modifications

Estimated time: 16-40 hours for design and implementation

Backup & Recovery

When (not if) something fails, how fast can you recover? Ransomware attacks, hardware failures, and human error will happen. Your backup strategy determines whether it's an inconvenience or a catastrophe.

Critical Misconception: Microsoft 365 retention is NOT backup. Retention policies protect against accidental deletion for a limited time. After retention expires, data is permanently gone. Malicious deletion by a compromised account can bypass retention. You need true backup.

The 3-2-1 Backup Rule

  1. 3 Copies - Original data plus two backup copies
  2. 2 Different Media - Cloud and local, or different cloud providers
  3. 1 Offsite - At least one copy in a different physical location

Modern enhancement: 3-2-1-1-0: Add one immutable copy (can't be modified or deleted) and zero errors (verified backup integrity).

Microsoft 365 Backup

Third-party backup solutions for Microsoft 365 (Veeam, Datto, Acronis, etc.):

  1. Exchange Online - Mailboxes, calendars, contacts. Point-in-time recovery for individual items or full mailbox restore.
  2. SharePoint Online - Sites, document libraries, lists. Version history beyond native 500 versions, site-level restore.
  3. OneDrive for Business - User file storage. Individual file recovery, full account restore for departed users.
  4. Teams - Channels, conversations, files. Team-level and channel-level recovery.
  5. Entra ID - User objects, group memberships, configurations. Often overlooked but critical for disaster recovery.

New: Microsoft 365 Backup

Microsoft now offers native M365 Backup (pay-per-use, via Azure). Covers Exchange, SharePoint, OneDrive. Consider for organizations standardizing on Microsoft, but evaluate against established third-party solutions.

On-Premises/Hybrid Backup

  1. Servers - Full image backup for bare-metal recovery. Application-aware backup for databases (SQL, Exchange on-prem).
  2. File Shares - Incremental backup with versioning. Fast recovery for individual files.
  3. Databases - Transaction log backup for point-in-time recovery. Test restoration regularly.
  4. Virtual Machines - Snapshot-based backup with application quiescing. Instant recovery capability.
  5. Configuration Backup - Network device configs, firewall rules, system settings. Often forgotten until needed.

RPO and RTO Definitions

  1. RPO (Recovery Point Objective) - Maximum acceptable data loss measured in time. "We can lose up to 4 hours of work." Determines backup frequency.
  2. RTO (Recovery Time Objective) - Maximum acceptable downtime. "We need to be operational within 2 hours." Determines recovery method.

Example targets by system criticality:

  1. Critical (Email, ERP) - RPO: 1 hour, RTO: 4 hours
  2. Important (File shares) - RPO: 4 hours, RTO: 8 hours
  3. Standard (Archive) - RPO: 24 hours, RTO: 24 hours

Immutable Backup (Ransomware Protection)

Ransomware specifically targets backup systems. Immutable backups cannot be modified or deleted, even by administrators, for a set retention period.

  1. Cloud Immutability - AWS S3 Object Lock, Azure Immutable Blob Storage, Wasabi Object Lock. Backup vendor must support.
  2. Air-Gapped Backup - Physically disconnected backup that ransomware cannot reach. Tape, offline disk, or isolated cloud.
  3. Retention Lock - Backup software feature preventing deletion before retention expires.
  4. Separate Credentials - Backup system uses different credentials than production. Compromise of domain admin doesn't give backup access.

Backup Testing Requirements

  1. Daily - Verify backup job completion, check for errors and warnings, confirm data protected.
  2. Weekly - Restore random file/email to verify recoverability. Document results.
  3. Monthly - Full system restore to isolated environment. Verify application functionality.
  4. Quarterly - Disaster recovery drill. Simulate major outage, execute recovery procedures, measure against RTO.
  5. Annually - Complete DR test with business stakeholder participation. Update procedures based on lessons learned.

Untested backups are not backups. "We think it's working" is not acceptable. Regular, documented testing is the only way to know you can recover.

Disaster Recovery Planning

  1. Business Impact Analysis - Identify critical systems, maximum tolerable downtime, recovery priorities.
  2. Recovery Procedures - Step-by-step instructions for each scenario (hardware failure, ransomware, site loss).
  3. Communication Plan - Who to notify, how to communicate during outage, status update cadence.
  4. Vendor Contacts - Support numbers, account details, escalation paths for critical vendors.
  5. Recovery Site - Where will you operate if primary site is unavailable? Cloud, alternate office, remote work?

Backup Encryption Requirements

  1. Encryption in transit (TLS 1.2+) for all backup traffic
  2. Encryption at rest (AES-256) for stored backup data
  3. Key management separate from backup data (avoid key stored with backup)
  4. Document encryption keys securely (offline copy, break-glass procedure)

Estimated time: 8-16 hours for setup + 2-4 hours/month for testing

Network & Infrastructure Checklist

  1. Network segmented with VLANs for different security zones
  2. Business-class firewall with IDS/IPS enabled
  3. All consumer-grade networking equipment replaced
  4. Wireless networks secured with WPA3 and proper authentication
  5. Guest network isolated from internal resources
  6. Network diagram current and accessible
  7. Firewall rules documented with business justification
  8. Network monitoring and alerting active
  9. Microsoft 365 backed up with third-party solution
  10. On-premises data backed up following 3-2-1 rule
  11. Immutable/air-gapped backup copy exists
  12. RPO and RTO defined for all critical systems
  13. Backup testing performed and documented regularly
  14. Disaster recovery plan documented and tested
  15. Backup encryption configured (transit and rest)
  16. Backup credentials separate from production domain


08 · Compliance Frameworks

Compliance isn't a checkbox - it's a continuous process. Understanding which frameworks apply to your organization and mapping your controls to their requirements is essential for audit readiness, insurance, and legal protection.

Prerequisites for Compliance

  1. Sections 1-7 of this blueprint implemented
  2. Understanding of your regulatory obligations
  3. Legal/compliance officer identified (internal or external)
  4. Executive sponsorship for compliance program
  5. Budget for audits and assessments if required

HIPAA (Health Insurance Portability and Accountability Act)

Required for any organization that handles Protected Health Information (PHI). This includes healthcare providers, health plans, healthcare clearinghouses, and their business associates. HIPAA violations can result in fines up to $1.5 million per violation category per year.

Who Must Comply

  1. Covered Entities - Healthcare providers (doctors, dentists, therapists, hospitals), health plans, healthcare clearinghouses
  2. Business Associates - Any vendor that handles PHI on behalf of a covered entity (IT providers, billing services, cloud vendors)
  3. Subcontractors - Vendors of business associates who access PHI

HIPAA Security Rule - Technical Safeguards

  1. §164.312(a) - Access Control - Unique user IDs, emergency access procedures, automatic logoff, encryption and decryption. → Entra ID, Conditional Access, BitLocker, session timeouts.
  2. §164.312(b) - Audit Controls - Record and examine system activity. → Unified Audit Log, Defender XDR, SIEM integration.
  3. §164.312(c) - Integrity Controls - Protect ePHI from improper alteration or destruction. → Data Loss Prevention, sensitivity labels, access controls.
  4. §164.312(d) - Authentication - Verify identity of persons seeking access. → MFA, passwordless authentication, certificate-based auth.
  5. §164.312(e) - Transmission Security - Guard against unauthorized access during transmission. → TLS encryption, email encryption, VPN.

Administrative Requirements

  1. Security Risk Assessment (annual, documented)
  2. Written policies and procedures
  3. Workforce training (annual, documented)
  4. Business Associate Agreements (BAAs) with all vendors
  5. Incident response and breach notification procedures
  6. Designated Security Officer

Breach Notification: Breaches affecting 500+ individuals must be reported to HHS within 60 days and are publicly posted on the "Wall of Shame." Smaller breaches must be reported annually. Individual notification required for all.

42 CFR Part 2 (Substance Use Disorder Records)

Stricter than HIPAA for substance abuse treatment records. Key differences:

  1. Written patient consent required for almost all disclosures
  2. Cannot be disclosed for legal proceedings without court order
  3. Re-disclosure prohibition must accompany shared records
  4. No treatment-payment-operations exception like HIPAA

Estimated time: 80-160 hours for initial compliance program

PCI-DSS (Payment Card Industry Data Security Standard)

Required for any organization that stores, processes, or transmits credit card data. Compliance level depends on transaction volume. Non-compliance can result in fines up to $100,000/month and loss of card processing privileges.

Compliance Levels

  1. Level 1 - 6+ million transactions/year. Annual on-site audit by QSA, quarterly network scans.
  2. Level 2 - 1-6 million transactions. Annual SAQ, quarterly scans.
  3. Level 3 - 20,000-1 million e-commerce transactions. Annual SAQ, quarterly scans.
  4. Level 4 - Under 20,000 e-commerce or under 1 million other. Annual SAQ, quarterly scans recommended.

Most SMBs are Level 4. If you use a compliant payment processor (Square, Stripe, PayPal) and never see card numbers, compliance burden is significantly reduced.

PCI-DSS 4.0 Key Requirements

  1. Requirement 1 - Install and maintain network security controls (firewalls). → Sophos, Fortinet, network segmentation.
  2. Requirement 2 - Apply secure configurations. → CIS benchmarks, Intune configuration profiles.
  3. Requirement 3 - Protect stored account data. → Encryption, tokenization, minimize data storage.
  4. Requirement 4 - Protect cardholder data with strong cryptography. → TLS 1.2+, encrypted transmissions.
  5. Requirement 5 - Protect against malicious software. → Defender for Endpoint, regular updates.
  6. Requirement 6 - Develop and maintain secure systems. → Patch management, secure development practices.
  7. Requirement 7 - Restrict access to cardholder data. → Least privilege, role-based access control.
  8. Requirement 8 - Identify users and authenticate access. → MFA for all access to cardholder data environment.
  9. Requirement 9 - Restrict physical access. → Physical security controls for systems storing cardholder data.
  10. Requirement 10 - Log and monitor all access. → Audit logging, SIEM, centralized log management.
  11. Requirement 11 - Test security regularly. → Vulnerability scans, penetration testing.
  12. Requirement 12 - Maintain security policies. → Written policies, risk assessments, security awareness training.

Reduce PCI Scope

The best way to achieve PCI compliance is to minimize scope:

  1. Use tokenized/hosted payment forms (Stripe Elements, Square)
  2. Never store card numbers in your systems
  3. Segment payment systems from corporate network
  4. Use P2PE (Point-to-Point Encryption) terminals

Estimated time: 40-80 hours for SAQ completion (Level 4)

SOC 2 (Service Organization Control 2)

A trust-based framework for service organizations. Not legally required, but increasingly demanded by enterprise customers, especially for SaaS, cloud, and managed service providers. Demonstrates controls over customer data.

Trust Service Criteria

  1. Security (Common Criteria) - Required for all SOC 2 reports. Protection against unauthorized access.
  2. Availability - Systems are available for operation as agreed. Uptime commitments, disaster recovery.
  3. Processing Integrity - System processing is complete, accurate, timely, and authorized.
  4. Confidentiality - Information designated as confidential is protected as agreed.
  5. Privacy - Personal information is collected, used, retained, and disclosed in conformity with commitments.

Most organizations start with Security only, then add Availability and Confidentiality as customer requirements dictate.

SOC 2 Report Types

  1. Type I - Point-in-time assessment. Are controls designed appropriately? Faster, less expensive, but less valuable.
  2. Type II - Assessed over 6-12 months. Are controls operating effectively? Industry standard, what customers expect.

Common SOC 2 Controls (Security)

  1. Access control and authentication (CC6.1-6.8)
  2. Logical and physical access restrictions
  3. System operations monitoring (CC7.1-7.5)
  4. Change management (CC8.1)
  5. Risk assessment and mitigation (CC9.1-9.2)
  6. Vendor management
  7. Incident response
  8. Business continuity and disaster recovery

SOC 2 Readiness Approach

  1. Gap assessment against Trust Service Criteria
  2. Remediate gaps (3-6 months typical)
  3. Implement continuous monitoring and evidence collection
  4. Type I audit (optional, as stepping stone)
  5. Type II observation period (6-12 months)
  6. Type II audit and report

Estimated time: 3-6 months readiness + 6-12 months observation

NIST Cybersecurity Framework (CSF)

Voluntary framework developed by NIST. Widely adopted as a common language for cybersecurity. Required for federal contractors, recommended for all organizations. Maps well to other frameworks (HIPAA, PCI-DSS, SOC 2).

NIST CSF 2.0 Core Functions

  1. GOVERN (New in 2.0) - Cybersecurity risk management strategy, expectations, and policy. Executive leadership, risk appetite, roles and responsibilities.
  2. IDENTIFY - Asset management, business environment, governance, risk assessment, risk management strategy, supply chain risk management.
  3. PROTECT - Access control, awareness and training, data security, information protection processes, maintenance, protective technology.
  4. DETECT - Anomalies and events, security continuous monitoring, detection processes.
  5. RESPOND - Response planning, communications, analysis, mitigation, improvements.
  6. RECOVER - Recovery planning, improvements, communications.

NIST Implementation Tiers

  1. Tier 1 - Partial - Ad hoc, reactive, limited awareness. No formal risk management process.
  2. Tier 2 - Risk Informed - Risk management approved but not org-wide. Some awareness, informal processes.
  3. Tier 3 - Repeatable - Formal policies, regular updates, risk-informed decisions at organizational level.
  4. Tier 4 - Adaptive - Continuous improvement, lessons learned integrated, agile response to threats.

Most SMBs should target Tier 2-3. Tier 4 is for mature, well-resourced programs.

NIST CSF for Cross-Framework Mapping

NIST CSF serves as a "Rosetta Stone" for compliance. Map your controls to CSF, then map CSF to specific requirements (HIPAA, PCI-DSS, SOC 2). Reduces duplication and provides unified control framework.

Estimated time: 40-80 hours for initial assessment and profile

CIS Controls

Prescriptive, prioritized security controls developed by the Center for Internet Security. Practical, actionable, and regularly updated. Our baseline for all client environments.

CIS Controls v8 - Implementation Groups

  1. Implementation Group 1 (IG1) - Essential cyber hygiene. 56 safeguards for small organizations with limited IT resources. Minimum baseline.
  2. Implementation Group 2 (IG2) - IG1 + 74 additional safeguards. For organizations with dedicated IT staff, more complex infrastructure.
  3. Implementation Group 3 (IG3) - IG1 + IG2 + 23 additional safeguards. For organizations with security experts, handling sensitive data, advanced threats.

We implement IG1 as minimum for all clients, IG2 for regulated industries (healthcare, finance), IG3 for high-security environments.

CIS Controls v8 - Top 18 Controls

  1. 1. Enterprise Asset Inventory - Know what you have
  2. 2. Software Asset Inventory - Know what's installed
  3. 3. Data Protection - Identify and protect sensitive data
  4. 4. Secure Configuration - Harden systems from defaults
  5. 5. Account Management - Control user access
  6. 6. Access Control Management - Least privilege
  7. 7. Continuous Vulnerability Management - Find and fix vulnerabilities
  8. 8. Audit Log Management - Collect and analyze logs
  9. 9. Email and Web Browser Protections - Secure primary attack vectors
  10. 10. Malware Defenses - Prevent and detect malicious software
  11. 11. Data Recovery - Backup and restore capabilities
  12. 12. Network Infrastructure Management - Secure network devices
  13. 13. Network Monitoring and Defense - Detect threats
  14. 14. Security Awareness Training - Train your people
  15. 15. Service Provider Management - Secure your vendors
  16. 16. Application Software Security - Secure development
  17. 17. Incident Response Management - Be ready to respond
  18. 18. Penetration Testing - Test your defenses

CIS Benchmarks

Configuration guides for hardening specific technologies. Available for:

  1. Operating Systems (Windows 10/11, macOS, Linux)
  2. Cloud Platforms (Azure, AWS, Google Cloud)
  3. Microsoft 365 (Exchange Online, SharePoint, Teams)
  4. Network Devices (Cisco, Palo Alto, Fortinet)
  5. Databases (SQL Server, Oracle, PostgreSQL)
  6. Web Servers (Apache, Nginx, IIS)

Level 1 benchmarks are practical for most organizations. Level 2 for high-security environments (may impact functionality).

Why We Use CIS as Our Baseline

  1. Prescriptive - tells you exactly what to configure
  2. Prioritized - Implementation Groups help focus efforts
  3. Mapped to frameworks - crosswalks to NIST, HIPAA, PCI-DSS
  4. Regularly updated - keeps pace with evolving threats
  5. Free - benchmarks and controls available at no cost
  6. Measurable - clear success criteria for each safeguard

Estimated time: 20-40 hours for IG1 assessment and remediation

Compliance Frameworks Checklist

  1. Identified all applicable compliance frameworks
  2. HIPAA: Security Risk Assessment completed (if applicable)
  3. HIPAA: BAAs in place with all vendors handling PHI
  4. HIPAA: Workforce training documented annually
  5. HIPAA: Breach notification procedures documented
  6. PCI-DSS: Scope minimized (tokenization, hosted payment forms)
  7. PCI-DSS: SAQ completed annually (if applicable)
  8. PCI-DSS: Quarterly vulnerability scans performed
  9. SOC 2: Gap assessment completed (if pursuing)
  10. SOC 2: Evidence collection process established
  11. NIST CSF: Current profile assessed
  12. NIST CSF: Target profile defined
  13. CIS: Implementation Group level determined
  14. CIS: Benchmarks applied to all systems
  15. Cross-framework control mapping documented
  16. Compliance calendar established for recurring requirements


That's a Lot of Work

If you've made it this far, you understand why organizations hire professionals to build and maintain their technology operations. This guide covers the "what" and the "how" - but doing it right requires experience, ongoing attention, and time most organizations don't have.

This is exactly what we do for every organization we partner with. We build it right from day one, maintain it continuously, and handle the complexity so you don't have to.

Free assessment. No pressure. Just honest answers about where you are and what it would take to get you here.

PD Geek is an operating brand of Pleasant Digital, LLC. © 2026 Pleasant Digital, LLC. Contact PD Geek through the Contact page.

Dental Practices · Therapy & Counseling · Churches & Nonprofits · Blog · Privacy Policy · Terms of Service