Why start with a baseline
Most Microsoft 365 incidents come from a handful of gaps: weak sign-in, over-shared data and unmanaged devices. A baseline closes those first, before you spend on anything advanced.
1. Lock down sign-in
Enforce multi-factor authentication for every user, block legacy authentication, and use conditional access to require a compliant device or trusted location for sensitive apps.
2. Protect email
Turn on anti-phishing and safe links, and publish SPF, DKIM and DMARC records so attackers cannot easily impersonate your domain.
3. Manage devices
Enrol laptops and phones in Intune, require encryption and screen locks, and make sure Defender is active and reporting.
4. Control sharing and retention
Set sensible external sharing limits in SharePoint and OneDrive, and apply retention so deleted data can be recovered.
5. Reduce admin risk
Use separate admin accounts, keep the number of global admins small and review privileged access regularly.
What to do next
Pick the first two items this month. If you want a plain-English review of your tenant, we can run a Microsoft 365 baseline check.