Microsoft 365 security field notes for UK SMEs. Practical checks for real work.
Source-backed notes for Cyber Essentials Plus evidence, Entra ID MFA, Conditional Access, Intune, Defender, external sharing, mail security and audit cleanup.
Field notes
Start with a practical route, then scan the newest checks when the detail matters.
Start here
Four paths through the most common Microsoft 365 security decisions.
Cyber Essentials Plus Readiness Guide
This is the readiness guide I would want before booking a Cyber Essentials Plus assessment for a Microsoft 365-heavy environment: scope first, MFA proof, device evidence, patch records, mail controls and a dry run before assessment week.
Microsoft 365 Security Cleanup Checklist for UK SMEs
Most Microsoft 365 tenants do not need a new product first. They need old admin access removed, MFA gaps closed, risky mail routes checked, sharing defaults tightened and evidence collected before an audit or incident forces the issue.
Microsoft 365 Security Review for UK SMEs: The First 10 Checks
A decent first Microsoft 365 security review does not need to be dramatic. It needs to show which controls are weak, who owns them, what evidence exists and which fixes reduce tenant risk first.
Intune and Defender Endpoint Control
Endpoint control is not proved by a busy Intune portal. It is proved by managed device coverage, Defender onboarding, compliance enforcement, patch evidence, local admin control and a remediation path for exceptions.
Latest field notes
Newest notes first, with the full archive still available below.
Cyber Essentials Plus BYOD and Mobile MAM Policy
Personal smartphones accessing Microsoft 365 fall in scope for Cyber Essentials Plus. Intune MAM app protection protects corporate data without full MDM enrollment.
Defender for Business Web Content Filtering
Microsoft 365 Business Premium includes native web content filtering. Protect remote laptops and block malicious web categories without third-party agents.
Entra ID Mandatory MFA Phase 2 Scripts Fix
Microsoft's mandatory MFA rollout affects PowerShell and Azure CLI. Learn how to migrate legacy credentials to certificate-based service principals.
Windows LAPS with Entra ID Cloud Setup Guide
Shared local admin passwords are an instant Cyber Essentials Plus failure. Windows LAPS with Entra ID automatically rotates unique passwords per device.
Conditional Access Resource Exclusions: 2026
A narrow Conditional Access enforcement change started rolling out in June 2026. Most tenants need no action, but affected custom apps can now receive challenges they did not receive before.
Entra Connect Sync: September 2026 Deadline
Microsoft says Entra Connect Sync services below version 2.5.79.0 will stop on 30 September 2026. Check the live server, then choose upgrade or migration deliberately.
Exchange Online EWS Retirement: October 2026
Exchange Web Services starts its phased retirement in October 2026. The useful work now is finding every dependency, assigning an owner, and testing a replacement.
July 2026 Intune Changes for M365 E3 and E5
Microsoft has changed which advanced Intune capabilities sit inside Microsoft 365 E3 and E5. Check the tenant and contract before buying, renewing or cancelling an add-on.
SMTP AUTH Basic Auth: December 2026 Plan
Microsoft changed the SMTP AUTH Basic authentication timeline. The extra runway should be used to identify devices and applications, not to preserve shared mailbox passwords.
UK Cyber Resilience Pledge: M365 Evidence
The UK Cyber Resilience Pledge is voluntary, but its board, Early Warning and supply-chain commitments are specific. Treat it as operating work, not website copy.
Security policies vs helpdesk reality
Former IT Manager here. I have seen perfectly theoretical security policies crumble on day one. Here is why external consulting usually misses the mark, and how to fix it.
Microsoft 365 Security Backlog 2026
A backlog is useful when it reflects operational reality, not product marketing. This one is built around the problems smaller Microsoft 365 tenants keep tripping over.
Cyber Essentials Plus Endpoint Samples
The assessor does not care about your best three laptops. They care whether an ordinary sample of business devices reflects the controls you say are in place.
Cyber Breaches Survey Lessons for M365
The latest UK breaches survey is not a reason to panic. It is a reason to tighten the day-to-day Microsoft 365 controls that often get treated as background admin.
Cyber Essentials Patch Evidence
The new patching conversation is not just about whether you patch. It is about proving supported software, timely updates, and controlled exceptions across the endpoint estate.
Cyber Essentials MFA Cloud Auto-Fail
Cyber Essentials v3.3 is blunt on MFA. In-scope cloud service access must use it, and Microsoft 365 teams need to prove policy enforcement across users, admins, guests, exclusions and emergency accounts.
Cyber Essentials v3.3: Cloud Services Scope for Microsoft 365 Teams
Cyber Essentials v3.3 removes a lot of wiggle room around cloud scope. For Microsoft 365 teams, that matters more than most people first think.
Endpoint DLP Only Works When the Endpoint Is Actually Managed
What Endpoint DLP really needs before it becomes useful, and why unmanaged or poorly managed devices make the whole story weaker.
Purview DSPM for Copilot AI
Copilot readiness is usually not an AI settings question first. It is a data posture question with a lot of old permissions and neglected workspaces hiding inside it.
Intune Policy Conflict Map: Baselines, Settings Catalog and Endpoint Security
How to give each Intune control family a proper home, instead of layering settings until nobody trusts the result.
Intune Mobile Passkeys and Credential Provider: Small Change, Useful Control
A practical look at passkeys on mobile, what Intune can protect, and where phone access still weakens Microsoft 365 control.
Microsoft-Managed Conditional Access Policies: Useful, but Still Needs Ownership
What Microsoft-managed Conditional Access policies actually do, where they help, and why they still need local ownership before anyone treats them as finished security work.
Container Labels for Teams, Sites and Groups: Control the Place, Not Just the File
Sometimes the real problem is not one badly handled document. It is the workspace around it being too open, too easy to share, or too loose on unmanaged access.
Sensitivity Labels in SharePoint and OneDrive: A Practical Start
Most label rollouts fail because they are too abstract. People get a list of terms, not a small set of decisions that actually helps them handle data better.
DLP for Copilot and Third-Party AI
AI does not invent a permissions mess. It tends to find it faster, summarise it faster, and make sloppy data controls harder to ignore.
Password Spray Controls for Microsoft 365
The Microsoft 365 controls that do the most to raise the cost of password spray attacks, without pretending the answer is one magic setting.
Passkeys in Entra ID: Practical Rollout for Microsoft 365 Admins
A grounded rollout plan for passkeys in Microsoft Entra ID, including pilot scope, recovery, and the policy choices that matter more than the launch announcement.
Audit Logs and Evidence: What to Capture Before Assessment Week
Good evidence packs are not glamorous. They are dated, easy to navigate, and strong enough that nobody reconstructs the tenant from memory under pressure.
OAuth App Consent Audit: The Microsoft 365 Backdoor People Miss
How to review OAuth app consent in Microsoft 365 properly, including user consent settings, admin workflow, and the apps that quietly end up with far too much access.
Defender Office 365 Operations
Email security does not usually fail because the licence was wrong. It fails because the queue had no owner, exceptions multiplied and the monthly review stopped happening.
Microsoft 365 Incident Response Plan
A good Microsoft 365 incident plan does not need to be huge. It needs to help a small team make clean decisions in the first hour, while evidence is fresh.
Guest Access Reviews in Teams
Guest access is usually not risky because it exists. It becomes risky when nobody can explain who still needs it, what they can see, and when it should end.
Break-Glass Accounts in Microsoft 365
How to design Microsoft 365 emergency access accounts that actually help in a lockout without turning into permanent unmanaged admin shortcuts.
Mail Forwarding and Inbox Rules: The Audit Nobody Should Skip
Password resets are not cleanup. If you have not checked forwarding, inbox rules and transport rules, you may be leaving the quiet part of an email compromise behind.
Windows 10 After End of Support: Microsoft 365 and Cyber Essentials Risk
What Windows 10 end of support really changes for Microsoft 365 teams, and where people overstate or understate the risk.
Device Compliance and Conditional Access
How to make device compliance matter at the access layer, instead of leaving it as a nice-looking dashboard.
AVD Least Privilege with Intune EPM
A practical way to think about least privilege in Azure Virtual Desktop, without pretending virtual desktops remove endpoint risk.
Endpoint Privilege Management
A grounded way to use Endpoint Privilege Management, with tighter exception handling and less wishful thinking.
Intune Baseline Conflict Fixes
Why Intune conflicts usually come from overlapping ownership, and how to simplify the estate without breaking devices.
Microsoft Secure Score Backlog
Secure Score is useful because it points at work. It becomes less useful when people turn it into a trophy number and stop asking which recommendations reduce real risk.
SharePoint External Sharing Cleanup
External sharing in Microsoft 365 is usually not one giant mistake. It is dozens of small permissions that nobody came back to tidy up.
Phishing Still Pays: A Microsoft 365 Action Plan for UK SMEs
Phishing is still cheap, common and effective when basic follow-up controls are weak. A Microsoft 365 action plan that makes sense for UK teams without turning into theatre.
Email Security Baselines: Standard vs Strict
Standard and Strict are not personality types. They are operating choices. A practical way to decide what goes where and stop phishing tuning becoming a weekly argument.
MFA in Microsoft 365: Security Defaults, Conditional Access or Per-User MFA?
A practical comparison of Security Defaults, Conditional Access, and per-user MFA, including when each option still makes sense and when it does not.
Global Admin Cleanup in Microsoft 365
How to clean up Global Administrator sprawl in Microsoft 365 without turning the exercise into guesswork or politics.
Enforcement Rollout Strategy
A practical plan for moving Microsoft Entra Conditional Access policies from report-only to enforced, without pretending the hard parts are somebody else's problem.
Browse by topic
Group the notes by Cyber Essentials Plus, identity, endpoint management or tenant security.
Related routes
Ask about your setup.
Send the user count, deadline and control problem behind the question.