Key Settings One-Pager
The essential goal, the features that carry it, the mistake to avoid, and the proof to keep — for each of the ten Brilliant at the Basics requirements. A quick reference to pin up, not a substitute for the full step-by-step guide. Confirm every setting against Microsoft 365’s own documentation.
Commercial Microsoft 365 is generally NOT authorized to store CUI. Most ITAR / CUI contractors need Microsoft 365 GCC High.
Phishing-Resistant Multi-Factor Authentication
Make a stolen password useless on its own.
Always exclude two break-glass accounts before you enforce, or a bad policy can lock every admin out of the tenant.
Conditional Access policy export (JSON) · Authentication methods registration report · Sign-in logs showing phishing-resistant sign-ins
Least-Privilege Access Control
Give each person only the access their job needs — and no more.
Keep your two break-glass accounts as permanent (not PIM-eligible) admins so you can still get in if PIM or MFA ever breaks.
PIM role settings export · List of eligible vs. permanent role assignments · Completed access review report
Asset & Account Inventory
Keep a live list of every device, identity, and app you defend.
Set a monthly reminder to re-export the inventory; a one-time list is stale within weeks as people and devices come and go.
Intune All devices export (CSV) · Entra Users and Devices export · Enterprise applications list
Logging, Monitoring & Audit
Record important events and watch for trouble.
Standard audit logs only keep 180 days by default; if a rule requires one year, set a retention policy now, not after an incident.
Screenshot of UnifiedAuditLogIngestionEnabled = True · Sample audit log search export · Audit retention policy configuration
Network Segmentation & Boundary Protection
Keep one compromised thing from reaching everything else.
Exclude the Microsoft Intune and Intune Enrollment apps from compliant-device policies, or you create a chicken-and-egg loop where devices can't enroll.
Named locations configuration export · Conditional Access policy set export · Global Secure Access / Private Access app list
Vulnerability & Patch Management
Find weak spots and fix the risky ones first.
Never push updates to every device at once; a pilot ring first lets you catch a bad patch before it breaks your whole fleet.
Defender Vulnerability Management recommendations export · Intune Update rings configuration · Windows Autopatch / update compliance report
Data Protection & Encryption
Scramble sensitive data so only the right people can read it.
Turn on silent BitLocker so device disks encrypt automatically at enrollment, and always escrow the recovery keys to Entra ID or you may permanently lose data.
Sensitivity label and policy export · Intune BitLocker (Disk encryption) policy · Entra-escrowed BitLocker recovery keys report
Backup & Recovery
Be able to restore your data after an attack or outage.
Retention and backup frequency are fixed and can't be changed, so read the RPO/RTO limits before you rely on it as your only recovery plan.
Microsoft 365 Backup policy configuration · Screenshot of available restore points · Successful test-restore record
Secure Configuration Baseline
Start every service from a known-good, hardened setting.
Don't turn on Security Defaults and custom Conditional Access at the same time; pick one, because running both causes confusing conflicts.
Secure Score history export · Intune security baseline assignment and compliance report · Conditional Access or Security Defaults configuration
Secure AI Adoption & Data Loss Prevention
Use AI and share files without leaking sensitive information.
Run DLP in simulation mode first; a blocking rule that's too broad will frustrate users and get switched off, defeating the whole purpose.
Purview DLP policy export (Copilot location) · Endpoint DLP rule for generative AI sites · DLP simulation / alert report