Aligned with CISA & CIS Benchmarks

12 Security Controls. Deployed and Documented.

Each control closes a specific gap that attackers exploit and insurance carriers ask about.

The M365Shield Security Baseline

MFA Enforcement via Conditional Access

Not just turned on — enforced. Every user, every login, no exceptions.

Legacy Authentication Blocked

IMAP, POP3, SMTP Auth shut down. The #1 way attackers bypass MFA.

External Email Forwarding Disabled

Forwarding rules are the most common sign of active compromise.

Admin Account Protection

Dedicated admin accounts with phishing-resistant MFA. No personal device access.

Malware & Phishing Protection

Safe Attachments, Safe Links, anti-phishing policies in Defender for Office 365.

Data Loss Prevention Baseline

DLP policies for credit card numbers, SSNs, and sensitive data in email and SharePoint.

Audit Logging Enabled

Unified Audit Log configured. Know who did what, when, and from where.

Guest Access Restricted

External guest access scoped to specific teams and sites. No open-door policies.

SharePoint & OneDrive Sharing Controls

External sharing locked to specific domains. No anonymous sharing links.

Mobile Device Security

Device compliance policies requiring PIN, encryption, and OS version minimums.

Alert Policies

Alerts for impossible travel, mass downloads, forwarding rules, and admin changes.

Compliance Score Optimization

Secure Score actions mapped and implemented. Your score becomes auditable proof.

Before and After M365Shield

Before

  • ✕MFA optional
  • ✕Legacy auth open
  • ✕No forwarding controls
  • ✕No audit log
  • ✕Default sharing settings
  • ✕Insurance questionnaire = guesswork

After

  • ✓MFA enforced via Conditional Access
  • ✓Legacy auth blocked
  • ✓External forwarding disabled
  • ✓Full audit logging
  • ✓Sharing locked to approved domains
  • ✓Deployment report = compliance evidence

Want to See Which Controls Your Tenant Is Missing?

Check My Risk