Microsoft 365 security topics. Start with the control family.
Pillar notes for Cyber Essentials Plus, identity, endpoint management and tenant security. Use the cluster to name the problem before changing a setting.
Browse the clusters
Each route names the control owner, the evidence to collect and the practical decision that follows.
Cyber Essentials Plus
Most CE Plus failures are evidence gaps, not exotic findings. Start here when scope, device samples or MFA evidence ownership is unclear.
Identity & access
Identity controls govern most Microsoft 365 access decisions. Start here when Conditional Access, admin roles or MFA exceptions are owned by memory rather than documentation.
Endpoint management
Intune is easy to half-deploy. Start here when device compliance results exist but the team cannot explain why enrolled devices fail or which policies actually apply.
Tenant & Defender
Licensed controls only matter when someone owns them. Start here when Defender, DLP, external sharing or audit evidence is configured but not actively reviewed.
Read the field notes
Use the latest practical checks when the cluster points to a specific configuration or evidence question.
Questions teams ask first
Which topic should I start with?
Choose the area where ownership or evidence is least clear: access, devices, tenant sharing and mail, or assessment readiness.
Do the notes replace a tenant review?
No. They help frame the first review question. A scoped review is still needed before changing controls in a live tenant.
Related routes
Need help naming the problem?
Send the control area, the deadline and who currently owns the evidence.