SECURITYSQUAD

Microsoft 365 can be configured securely – out of the box it is not

Security assessment and hardening to CIS Benchmarks: first know where you stand, then close the gaps that matter.

The starting point

Microsoft secures the platform, you secure the configuration

Cloud services arrive with defaults optimised for collaboration, not for containment. That is not an oversight on the provider's part but a deliberate choice: a tool that forbids everything by default does not get used. Securing it is therefore not a state you buy along with the licence but a task that stays with you.

In practice that means permissions granted once and never reviewed. Shares that reach further than anyone intended. Logs nobody keeps. Sign-in methods left over from the days before the cloud. None of it is spectacular – and that is exactly where incidents come from.

The misconfigurations we encounter most often are set out separately.

Assessment

What we look at

The basis is the CIS Benchmarks from the Center for Internet Security – a vendor-neutral catalogue of concrete hardening requirements that also exists for Microsoft 365. Rather than assessing by instinct, we compare your tenant against a recognised target state.

  • Identities and permissions: who may do what, who holds global administrator, which accounts have been forgotten.
  • Conditional access and multi-factor sign-in: do the rules apply everywhere, or only where they inconvenience nobody.
  • External sharing and guest access: what leaves your organisation, deliberately and otherwise.
  • Logging and retention: is what gets recorded enough to reconstruct an incident later.
  • Legacy authentication and leftovers from the migration.
Hardening

Not just a report – the implementation

A list of findings has never changed a setting on its own. We prioritise the findings by impact and effort and work through them with your IT team, starting with what can be implemented without noticeably constraining operations.

The CIS Benchmarks distinguish two levels for this. Level 1 covers measures with reasonable effort and low risk to day-to-day operations – that is the starting point. Level 2 goes further and is intended for environments with elevated protection requirements; what makes sense there we decide together rather than across the board.

How system hardening with CIS Benchmarks works in principle is explained in the knowledge hub.

The outcome

What you hold afterwards

  • A prioritised list of findings referenced to the relevant CIS requirement – traceable rather than “somebody should look at this”.
  • A judgement on which of it genuinely matters for your protection requirements and what you can leave with a clear conscience.
  • An implementation plan with a sequence, and the implementation itself if you want it.
  • Evidence that fits into an ISMS to ISO 27001 or IT-Grundschutz rather than sitting beside it.
Afterwards

Getting it right once is not enough

Configurations drift. New features arrive with their own defaults, updates change settings, and in day-to-day work an exception gets made that nobody reverses. Six months later the tenant looks different from the closing report.

A recurring review is therefore more useful than a one-off project. How often depends on how much moves in your environment – we agree that with you rather than prescribing it.

Scope

Not only Microsoft 365

We apply the same approach to Azure and AWS, and on request to servers and workstations. Where your focus lies is decided by your environment.

We deliberately do not offer fixed packages here. The scope depends on the size of your tenant, the number of connected services and how much you want to implement yourselves. What we do promise: the scope is settled before the quote, not after.

We work remotely or on site, as agreed with you – a configuration assessment usually runs remotely.

Questions

Frequently asked questions about securing Microsoft 365

Do we have to grant access to our environment?

Read access with the necessary permissions is enough for the assessment. We make no changes without agreement, and what we do change we record traceably. Scope and permissions are settled in writing beforehand.

How is this different from Secure Score?

The Microsoft Secure Score is a useful indicator, but it assesses from the vendor's perspective and does not weight by your protection requirements. The CIS Benchmarks are vendor-neutral and considerably more concrete. We use both, but we do not rely on a single number.

Do we have to implement every recommendation?

No. A hardening catalogue is not a list of obligations. Some requirements do not fit your workflows, and a measure that makes work impossible gets circumvented anyway. We tell you what each measure achieves and what it costs – the decision stays with you.

How long does an assessment take?

That depends on the size of the environment and how many services are connected. After a short preliminary conversation we can estimate the effort reliably – before that, any figure would be a guess.

Does this help with NIS2 or a certification?

Yes. The results and the measures derived from them can serve as evidence within an ISMS. Anyone heading for ISO 27001 or IT-Grundschutz anyway should not treat cloud configuration as a separate topic.

Do you know how your tenant is configured today?

A short preliminary conversation establishes how large the scope realistically is for you.

Arrange a first conversation