Security Policies Reference
Comprehensive security configuration guide for Microsoft 365 tenants covering Conditional Access, MFA, DLP, and security baselines.
Table of Contents
Conditional Access Policies
Policy Architecture
| Policy Type |
Target Users |
Applications |
Grant Control |
| Admin MFA |
Admin roles |
All apps |
Require MFA |
| User MFA |
All users |
All apps |
Require MFA |
| Device Compliance |
All users |
Office 365 |
Compliant device |
| Location-Based |
All users |
All apps |
Block non-trusted |
| Legacy Auth Block |
All users |
All apps |
Block |
Recommended Policies
1. Require MFA for Administrators
Scope: Global Admin, Security Admin, Exchange Admin, SharePoint Admin, User Admin
Settings:
- Include: Directory roles (admin roles)
- Exclude: Emergency access accounts
- Grant: Require MFA
- Session: Sign-in frequency 4 hours
2. Require MFA for All Users
Scope: All users
Settings:
- Include: All users
- Exclude: Emergency access accounts, service accounts
- Conditions: All cloud apps
- Grant: Require MFA
- Session: Persistent browser session disabled
3. Block Legacy Authentication
Scope: All users
Settings:
- Include: All users
- Conditions: Exchange ActiveSync, Other clients
- Grant: Block access
Why: Legacy protocols (POP, IMAP, SMTP AUTH) cannot enforce MFA.
4. Require Compliant Devices
Scope: All users accessing sensitive data
Settings:
- Include: All users
- Applications: Office 365, SharePoint, Exchange
- Grant: Require device compliance OR Hybrid Azure AD joined
- Platforms: Windows, macOS, iOS, Android
5. Block Access from Untrusted Locations
Scope: High-risk operations
Settings:
- Include: All users
- Applications: Azure Management, Microsoft Graph
- Conditions: Exclude named locations (corporate IPs)
- Grant: Block access
Named Locations Configuration
| Location Name |
Type |
IP Ranges |
| Corporate HQ |
IP ranges |
203.0.113.0/24 |
| VPN Exit Points |
IP ranges |
198.51.100.0/24 |
| Trusted Countries |
Countries |
US, CA, GB |
| Blocked Countries |
Countries |
(high-risk regions) |
Policy Deployment Strategy
Report-Only Mode (Week 1-2)
- Enable policies in report-only
- Monitor sign-in logs for impact
- Identify false positives
Pilot Group (Week 3-4)
- Enable for IT staff first
- Address issues before broad rollout
- Document exceptions needed
Gradual Rollout (Week 5-8)
- Enable by department
- Provide user communication
- Monitor help desk tickets
Full Enforcement
- Enable for all users
- Maintain exception process
- Quarterly policy review
Multi-Factor Authentication
MFA Methods (Strength Ranking)
| Method |
Security Level |
User Experience |
| FIDO2 Security Keys |
Highest |
Excellent |
| Windows Hello |
Highest |
Excellent |
| Microsoft Authenticator (Passwordless) |
High |
Good |
| Microsoft Authenticator (Push) |
High |
Good |
| OATH Hardware Token |
High |
Fair |
| SMS/Voice |
Medium |
Good |
| Email OTP |
Low |
Fair |
Recommended Configuration
For Administrators:
- Require phishing-resistant MFA (FIDO2, Windows Hello)
- Disable SMS/Voice as backup
- Enforce re-authentication every 4 hours
For Standard Users:
- Require Microsoft Authenticator
- Allow SMS as backup (temporary)
- Session lifetime: 90 days with risk-based re-auth
For External/Guest Users:
- Require MFA from home tenant
- Fall back to email OTP if needed
MFA Registration Campaign
Phase 1: Communication (Week 1)
- Announce MFA requirement
- Provide registration instructions
- Set deadline for registration
Phase 2: Registration (Week 2-3)
- Open registration portal
- IT support available
- Track registration progress
Phase 3: Enforcement (Week 4)
- Enable MFA requirement
- Grace period for stragglers
- Block unregistered after deadline
Data Loss Prevention
Sensitive Information Types
| Category |
Examples |
Action |
| Financial |
Credit card, Bank account |
Block external sharing |
| PII |
SSN, Passport, Driver's license |
Require justification |
| Health |
Medical records, Insurance |
Block and notify |
| Credentials |
Passwords, API keys |
Block all sharing |
DLP Policy Templates
Financial Data Protection
Scope: Exchange, SharePoint, OneDrive, Teams
Rules:
- Credit card numbers (Luhn validated)
- Bank account numbers
- SWIFT codes
Actions:
- Block external sharing
- Encrypt email to external recipients
- Notify compliance team
PII Protection
Scope: All Microsoft 365 locations
Rules:
- Social Security Numbers
- Passport numbers
- Driver's license numbers
Actions:
- Warn user before sharing
- Require business justification
- Log all incidents
Healthcare (HIPAA)
Scope: Exchange, SharePoint, Teams
Rules:
- Medical record numbers
- Health insurance IDs
- Drug names with patient info
Actions:
- Block external sharing
- Apply encryption
- Retain for 7 years
DLP Deployment
Audit Mode First
- Enable policies in test mode
- Review matched content
- Tune false positives
User Tips
- Enable policy tips in apps
- Educate before enforcing
- Provide override option with justification
Enforcement
- Block high-risk content
- Warn for medium-risk
- Log everything
Security Baselines
Microsoft Secure Score Targets
| Category |
Target Score |
Key Actions |
| Identity |
80%+ |
MFA, Conditional Access, PIM |
| Data |
70%+ |
DLP, Sensitivity labels, Encryption |
| Device |
75%+ |
Compliance policies, Defender |
| Apps |
70%+ |
OAuth app review, Admin consent |
Priority Security Settings
Identity (Do First)
Data Protection
Device Security
Application Security
Admin Role Security
Privileged Identity Management (PIM)
Configuration:
- Require approval for Global Admin activation
- Maximum activation: 8 hours
- Require MFA at activation
- Require justification
- Send notification to security team
Role Assignment Best Practices
| Role |
Assignment Type |
Approval Required |
| Global Admin |
Eligible only |
Yes |
| Security Admin |
Eligible only |
Yes |
| User Admin |
Eligible |
No |
| Help Desk Admin |
Permanent (limited) |
No |
Emergency Access Accounts
Configuration:
- 2 cloud-only accounts
- Excluded from ALL Conditional Access
- No MFA (break-glass scenario)
- Monitored via alerts
- Passwords in secure vault
- Test quarterly
Naming: emergency-access-01@tenant.onmicrosoft.com
Guest Access Controls
Guest Invitation Settings
| Setting |
Recommended Value |
| Guest invite restrictions |
Admins and users in guest inviter role |
| Enable guest self-service sign-up |
No |
| Enable email one-time passcode |
Yes |
| Collaboration restrictions |
Allow invitations only to specified domains |
Guest Access Review
Frequency: Quarterly
Scope:
- All guest users
- Group memberships
- Application access
Actions:
- Remove inactive guests (90+ days)
- Revoke unnecessary permissions
- Require re-certification
B2B Collaboration Settings
Allowed Domains:
- Partners:
partner1.com, partner2.com
- Block all others for sensitive resources
Guest Permissions:
- Limited directory browsing
- Cannot enumerate users
- Cannot invite other guests
1---2name: security-policies-reference3description: Comprehensive security configuration guide for Microsoft 365 tenants covering Conditional Access, MFA, DLP, and security baselines.4---5# Security Policies Reference67Comprehensive security configuration guide for Microsoft 365 tenants covering Conditional Access, MFA, DLP, and security baselines.89---1011## Table of Contents1213- [Conditional Access Policies](#conditional-access-policies)14- [Multi-Factor Authentication](#multi-factor-authentication)15- [Data Loss Prevention](#data-loss-prevention)16- [Security Baselines](#security-baselines)17- [Admin Role Security](#admin-role-security)18- [Guest Access Controls](#guest-access-controls)1920---2122## Conditional Access Policies2324### Policy Architecture2526| Policy Type | Target Users | Applications | Grant Control |27|-------------|-------------|--------------|---------------|28| Admin MFA | Admin roles | All apps | Require MFA |29| User MFA | All users | All apps | Require MFA |30| Device Compliance | All users | Office 365 | Compliant device |31| Location-Based | All users | All apps | Block non-trusted |32| Legacy Auth Block | All users | All apps | Block |3334### Recommended Policies3536#### 1. Require MFA for Administrators3738**Scope:** Global Admin, Security Admin, Exchange Admin, SharePoint Admin, User Admin3940**Settings:**41- Include: Directory roles (admin roles)42- Exclude: Emergency access accounts43- Grant: Require MFA44- Session: Sign-in frequency 4 hours4546#### 2. Require MFA for All Users4748**Scope:** All users4950**Settings:**51- Include: All users52- Exclude: Emergency access accounts, service accounts53- Conditions: All cloud apps54- Grant: Require MFA55- Session: Persistent browser session disabled5657#### 3. Block Legacy Authentication5859**Scope:** All users6061**Settings:**62- Include: All users63- Conditions: Exchange ActiveSync, Other clients64- Grant: Block access6566**Why:** Legacy protocols (POP, IMAP, SMTP AUTH) cannot enforce MFA.6768#### 4. Require Compliant Devices6970**Scope:** All users accessing sensitive data7172**Settings:**73- Include: All users74- Applications: Office 365, SharePoint, Exchange75- Grant: Require device compliance OR Hybrid Azure AD joined76- Platforms: Windows, macOS, iOS, Android7778#### 5. Block Access from Untrusted Locations7980**Scope:** High-risk operations8182**Settings:**83- Include: All users84- Applications: Azure Management, Microsoft Graph85- Conditions: Exclude named locations (corporate IPs)86- Grant: Block access8788### Named Locations Configuration8990| Location Name | Type | IP Ranges |91|--------------|------|-----------|92| Corporate HQ | IP ranges | 203.0.113.0/24 |93| VPN Exit Points | IP ranges | 198.51.100.0/24 |94| Trusted Countries | Countries | US, CA, GB |95| Blocked Countries | Countries | (high-risk regions) |9697### Policy Deployment Strategy98991. **Report-Only Mode (Week 1-2)**100 - Enable policies in report-only101 - Monitor sign-in logs for impact102 - Identify false positives1031042. **Pilot Group (Week 3-4)**105 - Enable for IT staff first106 - Address issues before broad rollout107 - Document exceptions needed1081093. **Gradual Rollout (Week 5-8)**110 - Enable by department111 - Provide user communication112 - Monitor help desk tickets1131144. **Full Enforcement**115 - Enable for all users116 - Maintain exception process117 - Quarterly policy review118119---120121## Multi-Factor Authentication122123### MFA Methods (Strength Ranking)124125| Method | Security Level | User Experience |126|--------|---------------|-----------------|127| FIDO2 Security Keys | Highest | Excellent |128| Windows Hello | Highest | Excellent |129| Microsoft Authenticator (Passwordless) | High | Good |130| Microsoft Authenticator (Push) | High | Good |131| OATH Hardware Token | High | Fair |132| SMS/Voice | Medium | Good |133| Email OTP | Low | Fair |134135### Recommended Configuration136137**For Administrators:**138- Require phishing-resistant MFA (FIDO2, Windows Hello)139- Disable SMS/Voice as backup140- Enforce re-authentication every 4 hours141142**For Standard Users:**143- Require Microsoft Authenticator144- Allow SMS as backup (temporary)145- Session lifetime: 90 days with risk-based re-auth146147**For External/Guest Users:**148- Require MFA from home tenant149- Fall back to email OTP if needed150151### MFA Registration Campaign152153```154Phase 1: Communication (Week 1)155- Announce MFA requirement156- Provide registration instructions157- Set deadline for registration158159Phase 2: Registration (Week 2-3)160- Open registration portal161- IT support available162- Track registration progress163164Phase 3: Enforcement (Week 4)165- Enable MFA requirement166- Grace period for stragglers167- Block unregistered after deadline168```169170---171172## Data Loss Prevention173174### Sensitive Information Types175176| Category | Examples | Action |177|----------|----------|--------|178| Financial | Credit card, Bank account | Block external sharing |179| PII | SSN, Passport, Driver's license | Require justification |180| Health | Medical records, Insurance | Block and notify |181| Credentials | Passwords, API keys | Block all sharing |182183### DLP Policy Templates184185#### Financial Data Protection186187**Scope:** Exchange, SharePoint, OneDrive, Teams188189**Rules:**1901. Credit card numbers (Luhn validated)1912. Bank account numbers1923. SWIFT codes193194**Actions:**195- Block external sharing196- Encrypt email to external recipients197- Notify compliance team198199#### PII Protection200201**Scope:** All Microsoft 365 locations202203**Rules:**2041. Social Security Numbers2052. Passport numbers2063. Driver's license numbers207208**Actions:**209- Warn user before sharing210- Require business justification211- Log all incidents212213#### Healthcare (HIPAA)214215**Scope:** Exchange, SharePoint, Teams216217**Rules:**2181. Medical record numbers2192. Health insurance IDs2203. Drug names with patient info221222**Actions:**223- Block external sharing224- Apply encryption225- Retain for 7 years226227### DLP Deployment2282291. **Audit Mode First**230 - Enable policies in test mode231 - Review matched content232 - Tune false positives2332342. **User Tips**235 - Enable policy tips in apps236 - Educate before enforcing237 - Provide override option with justification2382393. **Enforcement**240 - Block high-risk content241 - Warn for medium-risk242 - Log everything243244---245246## Security Baselines247248### Microsoft Secure Score Targets249250| Category | Target Score | Key Actions |251|----------|-------------|-------------|252| Identity | 80%+ | MFA, Conditional Access, PIM |253| Data | 70%+ | DLP, Sensitivity labels, Encryption |254| Device | 75%+ | Compliance policies, Defender |255| Apps | 70%+ | OAuth app review, Admin consent |256257### Priority Security Settings258259#### Identity (Do First)260261- [ ] Enable Security Defaults OR Conditional Access262- [ ] Require MFA for all admins263- [ ] Block legacy authentication264- [ ] Enable self-service password reset265- [ ] Configure password protection (banned passwords)266267#### Data Protection268269- [ ] Enable sensitivity labels270- [ ] Configure DLP policies271- [ ] Enable audit logging272- [ ] Set retention policies273- [ ] Configure information barriers (if needed)274275#### Device Security276277- [ ] Require device compliance278- [ ] Enable Microsoft Defender for Endpoint279- [ ] Configure BitLocker requirements280- [ ] Set application protection policies281- [ ] Enable Windows Autopilot282283#### Application Security284285- [ ] Review OAuth app permissions286- [ ] Configure admin consent workflow287- [ ] Block risky OAuth apps288- [ ] Enable app governance289- [ ] Configure MCAS policies290291---292293## Admin Role Security294295### Privileged Identity Management (PIM)296297**Configuration:**298- Require approval for Global Admin activation299- Maximum activation: 8 hours300- Require MFA at activation301- Require justification302- Send notification to security team303304### Role Assignment Best Practices305306| Role | Assignment Type | Approval Required |307|------|-----------------|-------------------|308| Global Admin | Eligible only | Yes |309| Security Admin | Eligible only | Yes |310| User Admin | Eligible | No |311| Help Desk Admin | Permanent (limited) | No |312313### Emergency Access Accounts314315**Configuration:**316- 2 cloud-only accounts317- Excluded from ALL Conditional Access318- No MFA (break-glass scenario)319- Monitored via alerts320- Passwords in secure vault321- Test quarterly322323**Naming:** `emergency-access-01@tenant.onmicrosoft.com`324325---326327## Guest Access Controls328329### Guest Invitation Settings330331| Setting | Recommended Value |332|---------|------------------|333| Guest invite restrictions | Admins and users in guest inviter role |334| Enable guest self-service sign-up | No |335| Enable email one-time passcode | Yes |336| Collaboration restrictions | Allow invitations only to specified domains |337338### Guest Access Review339340**Frequency:** Quarterly341342**Scope:**343- All guest users344- Group memberships345- Application access346347**Actions:**348- Remove inactive guests (90+ days)349- Revoke unnecessary permissions350- Require re-certification351352### B2B Collaboration Settings353354**Allowed Domains:**355- Partners: `partner1.com`, `partner2.com`356- Block all others for sensitive resources357358**Guest Permissions:**359- Limited directory browsing360- Cannot enumerate users361- Cannot invite other guests