Skip to content
Spectra Core

Microsoft 365 Security

Identity threat detection and response, conditional access, and tenant hardening

Microsoft 365 is where most small and mid-sized organisations actually keep their business, and its security posture is decided by a few dozen settings spread across several admin centres that change names every eighteen months.

This library pins those settings to a standard so that tenant drift becomes visible instead of gradual.

What this library checks

Evidence you will be asked for

Every check in Spectra Core carries its own evidence. These are the artefacts an auditor, insurer or board most often wants to see for this area.

Where this usually goes wrong

Tenant settings drift because every new licence, integration and pilot quietly changes the defaults. The tenant you hardened at onboarding is not the tenant you have today.

Run this library against your environment

Every check comes with a risk level, a review frequency, an assignee and a plain-language rationale, so the output reads for leadership as well as for engineers.

Other libraries