Skip to the main content.

Modernize & Transform

Built to help you reimagine IT operations, empower your workforce, and leverage AI-powered tools to stay ahead of the curve.

Untitled design (3)

Empower My Team

We bring together the best of Microsoft’s cloud ecosystem and productivity tools to help your people thrive.

Untitled design (3)

Build My Infrastructure

We offer a comprehensive suite of infrastructure services tailored to support your business goals today and scale for the future

Untitled design (3)

IT Services

Our managed and co-managed IT service plans deliver a responsive and innovative engagement to support your IT needs, improve employee experience, and drive growth for your business. 

Untitled design (3)

Cybersecurity Services

Sourcepass offers innovative solutions, including SOC, GRC, Security Assessments, and more to protect your business.

Untitled design (3)

Professional Services

Grow your business with cloud migrations, infrastructure refreshes, M&A integrations, staff augmentation, technical assessments, and more.

Untitled design (3)

Industries

We understand what most managed service providers don’t – when it comes to industry-specific technology, one-size-fits-all solutions don’t exist.

Untitled design (3)

Public Sector

Sourcepass GOV, a division of Sourcepass, is dedicated to providing specialized IT solutions for the public sector.

Untitled design (3)

Locations

We have coverage across the United States, with phyiscal locations across 8 states. Wherever you are, Sourcepass has your back.

Untitled design (3)

Resource Library

Stay ahead, stay connected, and discover the future of IT with Sourcepass.

Untitled design (3)

Events & Webinars

Dive into a dynamic calendar of webinars and in-person gatherings designed to illuminate the latest in managed IT services, cybersecurity, and automation.

Untitled design (3)

Resources by Role

Explore key resources, eBooks, video trainings, and more curated for CEOs, CFOs, CIOs, CISOs, and technology leaders!

Untitled design (3)

The Sourcepass Story

Sourcepass aims to be different. It is owned and operated by technology, security, and managed services experts who are passionate about delivering an IT experience that clients love.

Untitled design (3)

The Sourcepass Experience

At Sourcepass, we’re rewriting the IT and cybersecurity experience by helping businesses focus on what they do best, while we deliver the infrastructure, insights, and innovation to help them thrive.

Untitled design (3)

 

Microsoft 365 Hardening Checklist: 10 Steps to a Secure Tenant

 
Microsoft 365 Hardening Checklist: 10 Steps to a Secure Tenant

Why M365 Hardening Matters

 

Microsoft 365 is the backbone of modern business productivity and a prime target for cyber threats. Out of the box, M365 ships with reasonable defaults. Hardening a tenant takes focused, ongoing work. It spans identity, endpoints, email, data, and monitoring.

Every organizations should take these steps to reduce its attack surface, help meet compliance requirements, and build a strong security posture in Microsoft ecosystem.

 

Step 1: How to Choose the Right Microsoft 365 Licensing

 

Effective security hardening starts with the right foundation. For most small and midsized organizations, the minimum recommended licenses are Microsoft 365 Business Premium or E3. These licenses give you the core security toolset needed to harden your tenant. Without the right licensing, critical controls simply are not available.

Business Premium and Microsoft 365 E3 include, among other capabilities:

  • Entra ID P1 for Conditional Access, identity protection, and hybrid identity management
  • Microsoft Intune for cloud-based device management and policy enforcement
  • Defender for Office 365 P1 for advanced email and collaboration threat protection
  • Defender for Endpoint P1 / Defender for Business for advanced endpoint EDR and threat protection

 

Step 2: Run a Security Assessment First

 

Before making changes, understand where you stand. A security assessment identifies gaps across your identity, email, endpoint, and data layers. It gives you a ranked plan rather than a random checklist. Focus on changes that drive real security improvements. Start with these three actions:

  • Run Microsoft Secure Score as a great starting point for measuring your current posture
  • Get a hands-on review from an experienced partner for deeper context
  • Clean up stale accounts and devices by removing or disabling inactive users and devices in Entra ID and Intune

Stale accounts are active attack vectors. They also create noise in reporting, making it harder to tune policies accurately.

 

Step 3: Enable MFA for Every User

 

Enabling multi-factor authentication (MFA) for every user is the single highest-impact security step you can take. Studies consistently show that MFA blocks over 99% of automated credential attacks. Prioritize phishing-resistant methods like the Microsoft Authenticator app and FIDO2 security passkeys. Avoid SMS-based codes when possible.

 

Pair MFA with Conditional Access

 

Pair MFA deployment with a solid Conditional Access policy framework. For a deeper dive, see our article on the Top 10 Conditional Access Policies Every Tenant Should Have. That guide includes blocking legacy authentication protocols, a common attacker bypass for MFA controls.

 

 

Step 4: Configure SPF, DKIM, and DMARC

 

Email authentication records (SPF, DKIM, and DMARC) are the foundation of phishing and spoofing protection.

  • SPF defines which mail servers are authorized to send on behalf of your domain
  • DKIM digitally signs outbound messages
  • DMARC ties them together with an enforcement policy. It tells receiving mail servers how to handle messages that fail authentication

We recommend using a solution such as EasyDMARC for visibility and reporting. DMARC reporting shows real-time legitimate and fraudulent sending on your domain. That visibility lets you move from a "monitor" policy to a "reject" policy with confidence. That shift stops domain spoofing in its tracks.

 

Step 5: Configure Defender for Office 365

 

Defender for Office 365 Plan 1 (included in Business Premium and M365 E3) provides layered protection for email and collaboration tools. Tuned anti-phishing, anti-spam, and anti-malware policies cover the most common attack organizations face today. Safe Links and Safe Attachments scan URLs and sandbox suspicious files in real time. Both go well beyond basic spam filtering.

 

Baseline with Preset Security Policies

 

Apply Microsoft's "Strict" or "Standard" preset security policies as a baseline. Then customize based on your assessment findings and operational needs. Review quarantine activity and false positive/negative logs regularly to keep policies tuned.

 

 

Step 6: Enable Mailbox Auditing and Audit Logging

 

You cannot investigate what you cannot see. Unified audit logging and mailbox auditing ensure that critical actions are recorded and available for investigation. This includes:

  • Sign-ins
  • Mail access
  • Permission changes
  • File access

These logs are essential for incident response and are often required for regulatory compliance. Audit log retention policies should align with your compliance needs. Retain logs for a minimum of 90 days, and longer for regulated industries. Review them regularly or ingest them into a SIEM or MDR platform.

 

Step 7: Deploy Microsoft Defender for Business

 

Microsoft Defender for Business is included in Microsoft 365 Business Premium, Microsoft Defender for Endpoint, or Microsoft 365 E3. It is one of the most capable Endpoint Detection and Response (EDR) solutions available. Independent analysts consistently recognize it as a top performer. It provides:

  • Continuous endpoint monitoring
  • Automated attack disruption
  • Vulnerability management
  • Threat analytics across Windows, macOS, iOS, and Android devices

 

Onboard Devices and Review Threat Data

 

Onboard all devices to Defender for Endpoint and review the threat and vulnerability management dashboard regularly. Automated fixes can cut response times for common threats without manual action.

 

 

Step 8: Build Out Intune Configurations and Deploy Autopilot

 

Microsoft Intune gives you centralized control over device configuration, updates, and security policy enforcement. This applies across your entire device fleet, whether on-premises or remote. Security baselines in Intune provide a Microsoft-recommended starting configuration that can be deployed in minutes.

Windows Autopilot makes device setup easy. It ensures every new device is enrolled, configured, and secured automatically. This removes manual setup and reduces the risk of misconfigured endpoints entering your environment.

 

Step 9: Require Compliant Device Access

 

Compliant device access is one of the most powerful controls you can enforce. It means only Intune-managed, compliant devices can reach your Microsoft 365 resources. Entra ID Conditional Access works with Intune compliance policies to enforce this. Even authenticated users cannot reach corporate data from unmanaged or non-compliant devices. Define compliance baselines that include:

  • OS version requirements
  • Encryption enforcement
  • Antivirus status
  • Screen lock policies

Roll out access requirements in stages, starting with high-sensitivity workloads. This minimizes user disruption while steadily raising the security bar.

 

Step 10: Deploy DLP Policies and Sensitivity Labels

 

Data Loss Prevention (DLP) policies and Microsoft Purview Sensitivity Labels work together to protect your most sensitive information. DLP policies detect and block unauthorized sharing of sensitive data across:

  • Email
  • Teams
  • SharePoint
  • Endpoints

Protected data types include:

  • Financial records
  • PII
  • Health information

Sensitivity labels classify and protect documents and emails. They apply encryption and access controls that persist wherever the content travels.

 

Start with SharePoint and Label Structure

 

Start by locking down SharePoint external sharing settings. Then define a label structure that aligns with your data classification requirements before broad deployment.

 

 

Extra Credit: Advanced Security Capabilities

 

Organizations that have completed the core hardening steps above can take their security posture further with these additional investments.

 

Defender Suite and Microsoft Purview (Advanced Add-ons)

 

Adding Defender for Office 365 P2, Defender for Identity, and the full Microsoft Purview suite unlocks enterprise-grade capabilities such as:

  • Privileged Identity Management (PIM)
  • Risky sign-in and risky user policies
  • Advanced data governance
  • Copilot data protection controls
  • Compliance and inside-risk management tools

 

24/7 Managed Detection and Response (MDR)

 

Even the best-configured tenant benefits from around-the-clock human monitoring. A 24/7 MDR solution provides:

  • After-hours threat investigation and containment
  • Reduced dwell time
  • Smaller impact from any incident

 

Ready to Get Started?

 

The Sourcepass Center of Excellence for Microsoft specializes in M365 security assessments, hardening engagements, and ongoing managed security services. Reach out to your account team to schedule a complimentary discovery call.

 

 

Learn More about Our Security Assessment