🎁 Free onboarding credit for Sydney SMBs (new customers).
Internacious • Microsoft 365 Security

How to get a Microsoft 365 security baseline for your Australian company

Secure Score, MFA, Conditional Access, Intune policies, and a practical map to the ASD Essential Eight.

A Microsoft 365 security baseline is a documented set of identity, device, email and cloud settings you apply and keep current—so staff can work, and attackers have fewer easy paths in.

For Australian companies, the practical path is: measure the tenant, enforce MFA and Conditional Access, manage devices with Intune, then map those controls to the ASD Essential Eight as your local risk language.

Based on Microsoft Learn and ACSC published guidance
DIY-friendly sequence, or hand it to us
Essential Eight mapped to real Microsoft 365 controls
The sequence in short
1–2. Measure & enforce MFA
Secure Score as a prioritised backlog, then MFA for every user—especially admins.
3–4. Conditional Access & Intune
Control who signs in from where, then bring devices under management.
5–6. Harden & map
Email and app hardening, then map the whole stack to Essential Eight.
Reality check: Most Australian SMBs “have Microsoft 365” but still run close to out-of-box defaults.

You do not need an enterprise security team to start. You do need a clear sequence and authoritative how-to sources. Microsoft Learn and the Australian Cyber Security Centre (ACSC) publish the primary guidance; the steps below are the SMB-friendly order we recommend leaders follow.

The how: a practical sequence for Australian SMBs

1. Measure with Microsoft Secure Score

Open the Microsoft 365 Defender / Microsoft Secure Score experience in your tenant admin context. Secure Score ranks recommended actions for identity, devices, apps and data. Treat it as a prioritised backlog, not a vanity number. Work the high-impact identity and email items first (MFA coverage, legacy authentication, admin accounts), then device and app hardening.

Microsoft’s own ransomware-oriented guidance starts from assessing posture and applying published baselines—see Configure security baselines (Microsoft Learn).

2. Enforce MFA for every user (and especially every admin)

Multi-factor authentication is the single highest-leverage control for cloud email and collaboration. Prefer phishing-resistant methods where your licences and devices allow (for example authenticator app with number matching, or stronger options as you mature). Turn off legacy authentication that bypasses MFA. Confirm break-glass emergency accounts are documented, monitored and rarely used.

MFA also maps directly to Essential Eight strategy “multi-factor authentication.”

3. Put Conditional Access in front of sign-in

Conditional Access policies decide who can sign in, from which device or location, under what conditions. Typical SMB starting policies:

  • •Require MFA for all users
  • •Block legacy authentication
  • •Require compliant or hybrid-joined devices for sensitive apps (once Intune is live)
  • •Restrict or tightly control guest and admin access

Start with report-only or a pilot group if you fear locking people out, then enforce. Conditional Access is where “we turned MFA on” becomes “we control access every day.”

4. Manage devices with Intune (or cloud policy)

Endpoints that hold mail and files need patching, encryption, endpoint protection and a path to remote wipe. Microsoft Intune (often with Autopilot for new devices) is the usual cloud path for Australian Microsoft 365 customers:

  • •Enrol Windows (and other platforms you support)
  • •Apply compliance policies (BitLocker, OS version, Defender health)
  • •Deploy configuration and security baselines for Windows and Microsoft 365 Apps
  • •Tie compliance to Conditional Access so only healthy devices reach company data

Microsoft publishes the security baseline for Microsoft 365 Apps for enterprise and related Intune baseline references. Use those as the settings source; customise only where your business has a documented exception.

5. Harden email and Microsoft 365 apps

Baselines and Defender for Office 365 settings reduce the success of phishing and malware:

  • •SPF, DKIM and DMARC for your domains
  • •Safe attachment / safe links where licensed
  • •Macro and Office application hardening aligned to Microsoft's baseline recommendations
  • •Least-privilege admin roles (no standing Global Admin for daily work)

6. Map the work to ASD Essential Eight (SMB-practical)

Australian boards, insurers and many clients ask about Essential Eight. Use it as your directional framework, not as a claim that a default Microsoft 365 tenant is “done.”

Essential Eight themeTypical Microsoft 365 / Intune levers
Multi-factor authenticationEntra MFA + Conditional Access
Patch applications & operating systemsIntune update rings, Autopatch where used, App deployment
Restrict administrative privilegesPrivileged roles, PIM if licensed, separate admin accounts
Restrict Microsoft Office macros / user application hardeningM365 Apps security baseline, Attack surface reduction
Application controlWDAC / AppLocker or equivalent (often a later maturity step)
Regular backupsThird-party or native M365 backup with tested restores—Microsoft's recycle bins are not a full backup strategy

Authoritative overview: ACSC Essential Eight and the Essential Eight maturity model. Progress maturity level by level; do not skip foundations to chase a higher label on paper.

DIY pointers (authoritative sources)

If you have internal IT capacity, follow the vendors’ docs rather than blog shortcuts:

DIY works best when one named owner has admin time every week, a change window, and permission to inconvenience users briefly for MFA and device enrolment. If that owner does not exist, baseline work tends to stall after the first password prompt complaint.

What goes wrong on default Microsoft 365 tenants

Most Australian SMBs “have Microsoft 365” but still run close to out-of-box defaults. Common gaps we see in assessments:

  • •MFA optional or missing for some users; legacy protocols still allowed
  • •Many Global Admins, shared admin passwords, no separation of duties
  • •Devices unmanaged—no encryption guarantee, no remote wipe, patching left to users
  • •External sharing wide open on SharePoint and OneDrive
  • •No Conditional Access beyond a single basic MFA policy—or none at all
  • •Backups assumed because "it's in the cloud"; restore never tested
  • •Secure Score ignored or cherry-picked for easy points that do not reduce real risk
  • •Essential Eight discussed in a policy PDF but not reflected in Entra, Intune or backup evidence

None of this means Microsoft 365 is insecure. It means defaults favour quick setup, and security baselines are an ongoing operations job.

What Internacious implements

Internacious is Dale Harper’s Australian MSP (Sydney, Canberra and remote), focused on teams of roughly 5–75 staff. On Microsoft 365 security we:

  • •Run identity and device controls as part of managed operations—MFA essentials, Conditional Access, Intune policy, patching and endpoint protection
  • •Use ASD Essential Eight as a directional baseline and monitoring frame, with progress tracked over time—not a claim that we complete Essential Eight out of the box
  • •Include backup for Microsoft 365 and endpoints within managed packages, with restore drills
  • •Quote deeper remediation and maturity-lift projects separately and transparently
  • •Price managed IT typically at $150–$225 per user per month, with no lock-in after onboarding
  • •Offer a free Microsoft 365 assessment so leaders see score, top gaps and next steps before committing

Related pages: Cybersecurity Services Sydney, Managed IT Services Sydney, Our Services and internacious.com.

Free Microsoft 365 assessment — start here

If you want a clear picture of your tenant without a long discovery project:

  1. 1Take the free Microsoft 365 assessment on internacious.com (short questionnaire; designed for non-technical leaders).
  2. 2Or book a 15-minute fit call / call (02) 8313 0464 to walk through Secure Score priorities and whether managed baseline operations fit your team.

You will leave with prioritised risks and practical next steps—whether you implement them in-house with Microsoft Learn and ACSC guidance, or ask us to operate the baseline for you.

Ready to Talk About Your IT?