Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
BRILLIANT AT THE BASICS · CLOUD SETUPMicrosoft 365
Productivity Suite

Key Settings One-Pager

The essential goal, the features that carry it, the mistake to avoid, and the proof to keep — for each of the ten Brilliant at the Basics requirements. A quick reference to pin up, not a substitute for the full step-by-step guide. Confirm every setting against Microsoft 365’s own documentation.

Where you work
Microsoft 365 admin center + Microsoft Entra admin center
Content reviewed
2026-07-21
Before you store CUI here

Commercial Microsoft 365 is generally NOT authorized to store CUI. Most ITAR / CUI contractors need Microsoft 365 GCC High.

01

Phishing-Resistant Multi-Factor Authentication

IT-013.5.3IA.L2-3.5.3

Make a stolen password useless on its own.

Configure in
Microsoft Entra IDConditional AccessAuthentication strengthsFIDO2 security keysWindows Hello for Business
Don’t miss

Always exclude two break-glass accounts before you enforce, or a bad policy can lock every admin out of the tenant.

Evidence to keep

Conditional Access policy export (JSON) · Authentication methods registration report · Sign-in logs showing phishing-resistant sign-ins

02

Least-Privilege Access Control

3.1.5AC.L2-3.1.5

Give each person only the access their job needs — and no more.

Configure in
Microsoft Entra IDPrivileged Identity Management (PIM)Entra role-based access control (RBAC)Access reviews
Don’t miss

Keep your two break-glass accounts as permanent (not PIM-eligible) admins so you can still get in if PIM or MFA ever breaks.

Evidence to keep

PIM role settings export · List of eligible vs. permanent role assignments · Completed access review report

03

Asset & Account Inventory

IT-023.4.1CM.L2-3.4.1

Keep a live list of every device, identity, and app you defend.

Configure in
Microsoft IntuneMicrosoft Entra IDEnterprise applicationsMicrosoft Defender for Endpoint
Don’t miss

Set a monthly reminder to re-export the inventory; a one-time list is stale within weeks as people and devices come and go.

Evidence to keep

Intune All devices export (CSV) · Entra Users and Devices export · Enterprise applications list

04

Logging, Monitoring & Audit

3.3.1AU.L2-3.3.1

Record important events and watch for trouble.

Configure in
Microsoft Purview AuditMicrosoft Defender portalMicrosoft Entra sign-in logsMicrosoft Sentinel
Don’t miss

Standard audit logs only keep 180 days by default; if a rule requires one year, set a retention policy now, not after an incident.

Evidence to keep

Screenshot of UnifiedAuditLogIngestionEnabled = True · Sample audit log search export · Audit retention policy configuration

05

Network Segmentation & Boundary Protection

IT-053.13.5SC.L2-3.13.5

Keep one compromised thing from reaching everything else.

Configure in
Conditional AccessNamed locationsMicrosoft Entra Global Secure AccessMicrosoft Entra Private Access
Don’t miss

Exclude the Microsoft Intune and Intune Enrollment apps from compliant-device policies, or you create a chicken-and-egg loop where devices can't enroll.

Evidence to keep

Named locations configuration export · Conditional Access policy set export · Global Secure Access / Private Access app list

06

Vulnerability & Patch Management

IT-063.11.2RA.L2-3.11.2

Find weak spots and fix the risky ones first.

Configure in
Microsoft Defender Vulnerability ManagementMicrosoft Defender for EndpointMicrosoft IntuneWindows Autopatch
Don’t miss

Never push updates to every device at once; a pilot ring first lets you catch a bad patch before it breaks your whole fleet.

Evidence to keep

Defender Vulnerability Management recommendations export · Intune Update rings configuration · Windows Autopatch / update compliance report

07

Data Protection & Encryption

3.13.11SC.L2-3.13.11

Scramble sensitive data so only the right people can read it.

Configure in
Microsoft Purview Information ProtectionSensitivity labelsMicrosoft IntuneBitLocker
Don’t miss

Turn on silent BitLocker so device disks encrypt automatically at enrollment, and always escrow the recovery keys to Entra ID or you may permanently lose data.

Evidence to keep

Sensitivity label and policy export · Intune BitLocker (Disk encryption) policy · Entra-escrowed BitLocker recovery keys report

08

Backup & Recovery

IT-093.8.9MP.L2-3.8.9

Be able to restore your data after an attack or outage.

Configure in
Microsoft 365 BackupSharePoint OnlineOneDrive for BusinessExchange Online
Don’t miss

Retention and backup frequency are fixed and can't be changed, so read the RPO/RTO limits before you rely on it as your only recovery plan.

Evidence to keep

Microsoft 365 Backup policy configuration · Screenshot of available restore points · Successful test-restore record

09

Secure Configuration Baseline

3.4.2CM.L2-3.4.2

Start every service from a known-good, hardened setting.

Configure in
Microsoft Secure ScoreMicrosoft Intune security baselinesMicrosoft Defender portalSecurity Defaults / Conditional Access
Don’t miss

Don't turn on Security Defaults and custom Conditional Access at the same time; pick one, because running both causes confusing conflicts.

Evidence to keep

Secure Score history export · Intune security baseline assignment and compliance report · Conditional Access or Security Defaults configuration

10

Secure AI Adoption & Data Loss Prevention

IT-083.1.3AC.L2-3.1.3

Use AI and share files without leaking sensitive information.

Configure in
Microsoft Purview Data Loss PreventionMicrosoft 365 CopilotSensitivity labelsEndpoint DLP
Don’t miss

Run DLP in simulation mode first; a blocking rule that's too broad will frustrate users and get switched off, defeating the whole purpose.

Evidence to keep

Purview DLP policy export (Copilot location) · Endpoint DLP rule for generative AI sites · DLP simulation / alert report

This one-pager is independent education from the Brilliant at the Basics Resource Center, published by inDirectIT. It is a condensed reference — the full guide has the click-by-click steps. It does not by itself establish compliance, satisfy a contract clause, or confer CMMC certification. Cloud consoles change often — verify each setting against the provider’s documentation. The official DoW campaign remains authoritative: https://dowcio.war.gov/BrilliantBasics/