Secure Score, MFA, Conditional Access, Intune policies, and a practical map to the ASD Essential Eight.
A Microsoft 365 security baseline is a documented set of identity, device, email and cloud settings you apply and keep current—so staff can work, and attackers have fewer easy paths in.
For Australian companies, the practical path is: measure the tenant, enforce MFA and Conditional Access, manage devices with Intune, then map those controls to the ASD Essential Eight as your local risk language.
You do not need an enterprise security team to start. You do need a clear sequence and authoritative how-to sources. Microsoft Learn and the Australian Cyber Security Centre (ACSC) publish the primary guidance; the steps below are the SMB-friendly order we recommend leaders follow.
Open the Microsoft 365 Defender / Microsoft Secure Score experience in your tenant admin context. Secure Score ranks recommended actions for identity, devices, apps and data. Treat it as a prioritised backlog, not a vanity number. Work the high-impact identity and email items first (MFA coverage, legacy authentication, admin accounts), then device and app hardening.
Microsoft’s own ransomware-oriented guidance starts from assessing posture and applying published baselines—see Configure security baselines (Microsoft Learn).
Multi-factor authentication is the single highest-leverage control for cloud email and collaboration. Prefer phishing-resistant methods where your licences and devices allow (for example authenticator app with number matching, or stronger options as you mature). Turn off legacy authentication that bypasses MFA. Confirm break-glass emergency accounts are documented, monitored and rarely used.
MFA also maps directly to Essential Eight strategy “multi-factor authentication.”
Conditional Access policies decide who can sign in, from which device or location, under what conditions. Typical SMB starting policies:
Start with report-only or a pilot group if you fear locking people out, then enforce. Conditional Access is where “we turned MFA on” becomes “we control access every day.”
Endpoints that hold mail and files need patching, encryption, endpoint protection and a path to remote wipe. Microsoft Intune (often with Autopilot for new devices) is the usual cloud path for Australian Microsoft 365 customers:
Microsoft publishes the security baseline for Microsoft 365 Apps for enterprise and related Intune baseline references. Use those as the settings source; customise only where your business has a documented exception.
Baselines and Defender for Office 365 settings reduce the success of phishing and malware:
Australian boards, insurers and many clients ask about Essential Eight. Use it as your directional framework, not as a claim that a default Microsoft 365 tenant is “done.”
| Essential Eight theme | Typical Microsoft 365 / Intune levers |
|---|---|
| Multi-factor authentication | Entra MFA + Conditional Access |
| Patch applications & operating systems | Intune update rings, Autopatch where used, App deployment |
| Restrict administrative privileges | Privileged roles, PIM if licensed, separate admin accounts |
| Restrict Microsoft Office macros / user application hardening | M365 Apps security baseline, Attack surface reduction |
| Application control | WDAC / AppLocker or equivalent (often a later maturity step) |
| Regular backups | Third-party or native M365 backup with tested restores—Microsoft's recycle bins are not a full backup strategy |
Authoritative overview: ACSC Essential Eight and the Essential Eight maturity model. Progress maturity level by level; do not skip foundations to chase a higher label on paper.
If you have internal IT capacity, follow the vendors’ docs rather than blog shortcuts:
DIY works best when one named owner has admin time every week, a change window, and permission to inconvenience users briefly for MFA and device enrolment. If that owner does not exist, baseline work tends to stall after the first password prompt complaint.
Most Australian SMBs “have Microsoft 365” but still run close to out-of-box defaults. Common gaps we see in assessments:
None of this means Microsoft 365 is insecure. It means defaults favour quick setup, and security baselines are an ongoing operations job.
Internacious is Dale Harper’s Australian MSP (Sydney, Canberra and remote), focused on teams of roughly 5–75 staff. On Microsoft 365 security we:
Related pages: Cybersecurity Services Sydney, Managed IT Services Sydney, Our Services and internacious.com.
If you want a clear picture of your tenant without a long discovery project:
You will leave with prioritised risks and practical next steps—whether you implement them in-house with Microsoft Learn and ACSC guidance, or ask us to operate the baseline for you.
Ready to Talk About Your IT?Book a call