top of page

Office 365 Security - Capabilities & Planning

  1. Employees downloading sensitive corporate data with the intention of taking that data with them when they leave to join a competitor

  2. Malicious administrators accessing data out of policy or data not related to their role, intentionally degrading security settings, or creating dummy accounts for unauthorized third party access

  3. High-risk user behavior such as downloading data from company-sanctioned cloud services and uploading it to high-risk shadow IT services

  4. Third parties logging into cloud service accounts using stolen or guessed login credentials in order to steal sensitive data

  5. Dormant administrator accounts belonging to former employees that can be de-provisioned to eliminate the latent risk of account compromise

  6. Data leakage from users due to improper configurations/permission management The information gathered in this report can help mitigate those types of scenarios, based on Microsoft’s own best-practice foundational security goals:

  7. Simplify and protect access​

  8. Allow collaboration and prevent leaks

  9. Stop external threats​

  10. Stay compliant​

  11. Secure administrative access​

Introduction to Office 365 Security Let's assess risk and implement the most critical security, compliance, and information protection controls to protect your Office 365 tenant. The goal is to prioritize threats, translate threats into technical strategy, and then take a systematic approach to implementing features and controls. At core to Office 365 Security: Data Loss Prevention​

  1. Malware and targeted attacks can cause data breaches; however, user error is a much greater source of data risk​

  2. DLP identifies, monitors and protects sensitive data and helps users understand risks​Auditing and Retention Policies​

  3. Allow logging of events including viewing, editing and deleting content such as email messages, documents and calendars​eDiscovery​

  4. A single experience for searching and preserving email & documents​Data Deletion​

  5. Clear commitments and procedures for end-of-life and data destruction​Data Spillage Management​

  6. Hardware with your data is locked downQuestion: “What are the main differences between security on-premises and security in the public cloud?”​Answer: “You still need to do most of what you’re doing now. Ensuring that the data and its classification is done correctly, and that the solution will be compliant with regulatory obligations is the responsibility of the customer. ​Physical security is the one responsibility that is wholly owned by cloud service providers when using cloud computing. The remaining responsibilities are shared between customers and cloud service providers​.

Responsibility Zones

Security Responsibilities Managed by Office 365

Threats Managed by Office 365

Implications Considering the aforementioned Security Responsibility & Threat patterns, a key conclusion can be drawn as to what your Organizational security focus with Office 365 should be:

  1. Authentication Security is critical

  2. Tenant Security Configuration is critical

Security Capabilites Plan Start with a set of standards that can be applied across your organization. Here is an example of what this can look like.

Set Information Protection Standards Start with a set of standards that can be applied across your organization. Here is an example of what this can look like: GoalDescriptionEstablish information protection prioritiesThe first step of protecting information is identifying what to protect. Develop clear, simple, and well-communicated guidelines to identify, protect, and monitor the most important data assets anywhere they reside.Set organization minimum standardsEstablish minimum standards for devices and accounts accessing any data assets belonging to the organization. This can include device configuration compliance, device wipe, enterprise data protection capabilities, user authentication strength, and user identity.Find and protect sensitive dataIdentify and classify sensitive assets. Define the technologies and processes to automatically apply security controls.Protect high value assets (HVAs)Establish the strongest protection for assets that have a disproportionate impact on the organizations mission or profitability. Perform stringent analysis of HVA lifecycle and security dependencies, establish appropriate security controls and conditions.

Classify Data by Sensitivity Levels Four levels is a good starting point if your organization doesn’t already have defined Data Sensitivity standards: Sensitivity LevelDescriptionConfidentialOnly those who need explicitly need access must be granted it, and only to the least degree in order to do their work (the ‘need to know’ and ‘least privilege’ principles).RestrictedSubject to controls on access, such as only allowing valid logons from a small group of staff. ‘Restricted’ information must be held in such a manner that prevents unauthorised access i.e. on a system that requires a valid and appropriate user to log in before access is grantedInternal UseCan be disclosed or disseminated by its owner to appropriate members of your organization, partners and other individuals, as appropriate by information owners without any restrictions on content or time of publicationPublicCan be disclosed or disseminated without any restrictions on content, audience or time of publication. Disclosure or dissemination of the information must not violate any applicable laws or regulations, such as privacy rules.

Map Service Capabilities to Data Sensitivity Levels This table is an example of how capabilities can be mapped to data sensitivity levels: Service CapabilityDescriptionData is encrypted and available only to authenticated usersProvided by default for data stored in Office 365 services. Data is encrypted while it resides in the service and in transit between the service and client devices.Additional data and identity protection applied broadlyCapabilities such as multi-factor authentication (MFA), mobile device management, and Exchange Online Advanced Threat Protection increase protection and substantially raise the minimum standard for protecting devices, accounts, and data.Sophisticated protection applied to specific data setsCapabilities such as Azure Rights Management (RMS) and Data Loss Protection (DLP) across Office 365 can be used to enforce permissions and other policies that protect sensitive dataStrongest protection and separationCustomer Lockbox for Office 365, eDiscovery features in Office 365, and use of auditing features to ensure compliance to policies and prescribed configurations.

Office 365 Secure Score Secure Score analyzes your Office 365 organization’s security based on your regular activities and security settings and assigns a score. Think of it as a credit score for security. Anyone who has admin permissions (global admin or a custom admin role) for an Office 365 Business Premium or Enterprise subscription can access the Secure Score at Users who aren’t assigned an admin role won't be able to access Secure Score. However, admins can use the tool to share their results with other people in their organization. Secure Score figures out what Office 365 services you’re using (like OneDrive, SharePoint, and Exchange) then looks at your settings and activities and compares them to a baseline established by Microsoft. You’ll get a score based on how aligned you are with best security practices.

Using Secure Score helps increase your organization’s security by encouraging you to use the built-in security features in Office 365 (many of which you already purchased but might not be aware of). Learning more about these features as you use the tool will help give you piece of mind that you’re taking the right steps to protect your organization from threats. If you want to improve your score, review the action queue to see what you can do to help increase security and reduce risks.

Add Secure Store to Office 365 Security and Compliance Center Dashboard Office 365 Secure Score is a great security analytics tool that you can access at However not everyone knows how to access Secure Score. You can make it easier to discover and quickly review your security position by adding a Secure Score widget to the home page of the Office 365 Security and Compliance Center. The widget will show your latest score and the maximum points you can obtain. To get more information about your score you can click the “Go to Secure Score” link and it will take you directly to Secure Score to review the additional details.

ReferencesOfferingsOffice 365 Secure Productive Enterprise Getting StartedNew technologies and services enhance Microsoft’s unique approach to cybersecurityAddress your CXO’s top five cloud security concernsTake control of your security and compliance with Office 365Learn how Office 365 security and compliance leverages intelligence in a cloud first worldSecure Office 365 like a cybersecurity pro—assessing risk and implementing controlsOwn your data with next generation access control technology in Office 365General Data Protection Regulation (GDPR) How Does Microsoft IT Secure Office 365?Keep calm and automate: How we secure the Office 365 service Office 365 Secure ScoreIntroducing the Office 365 Secure ScoreAn introduction to Office 365 Secure score New Office 365 capabilities help you proactively manage security and compliance risk Advanced Threat AnalyticsLearn how Microsoft Advanced Threat Analytics combats persistent threatsPlan and deploy Microsoft Advanced Threat Analytics the right way Advanced Security ManagementOverview of Advanced Security Management in Office 365Get started with Advanced Security ManagementGain visibility and control with Office 365 Advanced Security Management Advanced Threat ProtectionIntroducing Office 365 Advanced Threat ProtectionAdvanced threat protection for safe attachments and safe linksLearn about advancements in Office 365 Advanced Threat Protection Data Loss PreventionProtect your sensitive information with Office 365 Data Loss PreventionCustomize and tune Microsoft Office 365 Data Loss Prevention Customer Lockbox Announcing Customer Lockbox for Office 365Office 365 Customer Lockbox Requests DeveloperBuilding security and compliance solutions with the O365 Activity API – a Microsoft IT case study ExchangeImplement Microsoft Exchange Online ProtectionGet an edge over attackers – what you need to know about email threatsUnderstand how Microsoft protects you against Spoof, Phish, Malware, and Spam emailsLearn about advancements in Office 365 Advanced Threat Protection Advanced eDiscoveryOffice 365 Advanced eDiscoveryVideo: Office 365 Advanced eDiscoveryReduce costs and challenges with Office 365 eDiscovery and Analytics Azure Information ProtectionWhat is Azure Rights Management?Collaborate confidently using Rights ManagementAdopt a comprehensive identity-driven solution for protecting and sharing data securely Mobile DevicesSecure access to Office 365, SaaS, and on-premises apps and files with Azure AD and IntuneDeliver a BYOD program that employees and security teams will love with Microsoft IntuneManage BYOD and corporate-owned devices with MDM solutions EncryptionIntroducing Office 365 Message Encryption: Send encrypted emails to anyone!Encryption in Office 365Challenge cloud encryption myths and learn about Office 365 BYOK plans Advanced Data GovernanceAdvanced Data Governance overview Take control of your data with intelligent data governance in Office 365Applying intelligence to security and compliance in Office 365

3 views0 comments

Recent Posts

See All

M365 Community Content

There is a huge amount of great content available at This repository is here for YOU. The goal is to build an open source set of content to


bottom of page