Cyber Security

Microsoft 365 Security Baselines

Your Microsoft 365 hardened to best-practice security standards — and kept that way. We configure, standardise and continuously maintain your M365 security across identity, devices, email and collaboration, powered by the Inforcer platform.

Get a quote

Quick answer

Microsoft 365 security baselines are a set of best-practice security policies applied consistently across your Microsoft 365 environment — identity, devices, email and collaboration — to protect against common attacks. Foresight configures and continuously maintains these baselines for organisations across Greater Manchester and the UK using the Inforcer platform, keeping your settings aligned to CIS, NIST and Cyber Essentials best practice even as Microsoft changes.

Overview

Microsoft 365 is only as secure as it’s configured

Out of the box, Microsoft 365 is built for access and productivity — not locked down. Misconfiguration is one of the leading causes of cloud breaches, and the target keeps moving: Microsoft ships changes constantly, so even a well-configured tenant “drifts” away from best practice over time. We deploy a best-practice security baseline across your Microsoft 365, keep it current as Microsoft changes, and continuously monitor for drift — so your settings are right not just on day one, but every day. We deliver this using Inforcer, a specialist platform whose expert-curated baselines are informed by CIS, NIST and Microsoft’s own guidance.

What’s included

Best practice, applied and maintained

Best-practice baseline aligned to CIS, NIST and Microsoft security guidance
Full coverage — identity (Entra ID), devices (Intune), email (Exchange Online & Defender), collaboration (Teams, SharePoint & OneDrive) and data (Purview)
Continuous drift monitoring — settings stay correct over time, not just at go-live
Kept current as Microsoft ships new features and changes
Modular, phased rollout matched to your licences and maturity
Policy backup & restore so your configuration is protected and recoverable
Standardised and documented — consistent across every user and site
Supports Cyber Essentials and wider compliance
Fully managed by Foresight on the Inforcer platform

How it works

Three steps to a hardened Microsoft 365

1 · AssessWe review your current M365 configuration against best practice
2 · DeployWe roll out the right baseline — all of it, or modular — with minimal disruption
3 · MaintainWe monitor for drift and keep everything current as Microsoft changes

Pricing

Simple managed pricing

From £125 / month

Available as a managed add-on, or included as part of our Advanced Cyber Security plan. Build a quote to see it in context.

Prices are a guide, correct at the time of publication (July 2026), exclude VAT and depend on your Microsoft 365 licences and number of users. Ask us for a tailored quote.

Better together

Part of a complete cyber programme

Hardening Microsoft 365 is one of the highest-impact things you can do — and it works best alongside the rest of your defences.

Baselines set your cloud up securely; 24/7 monitoring watches for threats, vulnerability management finds weaknesses across the wider estate, and awareness training strengthens your people. Together they turn Microsoft 365 from a soft target into a well-defended core.

FAQs

Microsoft 365 security baseline questions, answered.

A security baseline is a set of best-practice configuration policies applied across your Microsoft 365 tenant — covering identity, devices, email and collaboration — so your environment is hardened against common attacks in a consistent, documented way.
Not fully. Microsoft 365 ships configured for easy access and productivity, with many protective settings switched off or set permissively. Achieving a genuinely secure tenant takes deliberate hardening — and keeping it there as Microsoft changes things.
Inforcer is the specialist platform we use to deploy and maintain Microsoft 365 security baselines. Its expert-curated baselines are informed by CIS, NIST and Microsoft guidance, and are kept up to date as Microsoft evolves the platform — giving us a trusted, low-risk foundation to build your security on.
Identity and access (Entra ID), device management (Intune), threat protection (Microsoft Defender), email (Exchange Online), and collaboration and data (Teams, SharePoint, OneDrive and Purview) — the whole Microsoft 365 estate.
Drift is when a tenant’s settings gradually move away from best practice — through manual changes, new features, or Microsoft updates. We continuously monitor for drift and put settings back to your agreed baseline, so security doesn’t quietly degrade over time.
Yes. Many Cyber Essentials controls map directly to Microsoft 365 configuration — MFA, access control, secure defaults and device settings — so a good baseline makes certification far easier to achieve and maintain.
No — we roll baselines out in a planned, phased way and test as we go. Most changes are invisible to users; where a change affects how people work (such as MFA), we communicate it clearly in advance.
Baselines work across common plans such as Microsoft 365 Business Premium, and we tailor what we deploy to the licences you hold so you get the most from what you’re already paying for.
As a managed service from £125 per month, or included as part of our Advanced Cyber Security plan. Final pricing depends on your licences and number of users — ask us for a tailored quote.
Yes. The shared best-practice baseline is the foundation; where you have specific needs we layer tailored (custom) policies on top, so you get both a proven standard and the flexibility your organisation requires.

Lock down your Microsoft 365

Get a scoped Microsoft 365 security baseline for your organisation — no obligation.

Get a quote