Scope of M365 Hardening and Security Optimization Project
Included as part of the service contract, this project encompasses some or all of the following measures (but is not limited to):
Protect against phishing, malware, and other threats with Safe Links and Safe Attachments policies.
Configure custom policies to block spoofed domains and impersonation attempts.
Use Office Message Encryption (OME) to secure sensitive communications.
Prevent unauthorized auto-forwarding of emails to external domains.
Classify and protect files with encryption and access restrictions based on sensitivity.
Prevent sharing of sensitive information through email, SharePoint, and OneDrive.
Automate classification and protection of sensitive data.
Monitor and control actions within apps, such as blocking downloads or enforcing read-only access for sensitive files.
Prevent unauthorized changes to security settings.
Restrict external storage usage or enforce monitoring.
Use real-time threat intelligence to stop emerging threats.
Use Microsoft Defender for Cloud Apps to monitor app permissions and detect risky behaviors.
Regularly review and revoke unnecessary or high-risk permissions granted to third-party apps.
Use Conditional Access App Control to enforce policies for third-party applications that access Microsoft 365.
Limit API calls to approved applications and monitor API usage for unusual activity.
Block or restrict access for high-risk users identified by Azure AD Identity Protection.
Enforce read-only access or block downloads for users accessing from unmanaged devices.
Restrict access for external users to specific apps or resources.
Implement Zero Trust Network Access (ZTNA) to replace traditional VPNs with ZTNA to ensure secure access to internal applications.
Use Microsoft Entra Verified ID to strengthen user authentication by issuing and verifying digital credentials.
Leverage Microsoft Secure Access Service Edge (SASE) to integrate with Azure AD and Microsoft Defender to provide secure, scalable access to corporate resources.
Enable Microsoft 365 Global Secure Access to enforce granular access controls for internet use and SaaS apps based on user roles and device compliance.
Deploy Endpoint Detection and Response (EDR) to monitor and protect against advanced threats.
Enforce encryption, password complexity, and security baselines for all devices accessing Microsoft 365.
Protect app data on personal devices without requiring full device management.
Streamline provisioning of new devices with pre-configured security policies and applications. Automate device enrollment into Intune for ongoing management.
Enable Unified Audit Logs to track and monitor activity across all Microsoft 365 services.
Use Microsoft Secure Score to regularly review your Secure Score and implement recommended improvements.
Enable Threat Analytics to gain insights into active threats and vulnerabilities across the environment.
Retain or delete data based on regulatory requirements.
Preserve data for legal or compliance purposes.
Use built-in assessments to improve compliance posture.
Microsoft 365 Security Project