Microsoft 365 Security
Identity threat detection and response, conditional access, and tenant hardening
Microsoft 365 is where most small and mid-sized organisations actually keep their business, and its security posture is decided by a few dozen settings spread across several admin centres that change names every eighteen months.
This library pins those settings to a standard so that tenant drift becomes visible instead of gradual.
What this library checks
- Conditional access policy inventory, what each policy targets and what it excludes
- Legacy authentication status and any protocol still permitted
- Global Administrator count, break-glass account configuration and privileged role assignment
- External sharing posture across SharePoint, OneDrive and Teams
- Mailbox forwarding rules, especially external forwarding
- Anti-phishing, safe links and safe attachment policy coverage
- Audit log retention and whether it is actually switched on
- Guest access, application consent policy and registered enterprise applications
Evidence you will be asked for
Every check in Spectra Core carries its own evidence. These are the artefacts an auditor, insurer or board most often wants to see for this area.
- Conditional access policy export with exclusions itemised
- Global Administrator list with justification per account
- External forwarding rule report
Where this usually goes wrong
Tenant settings drift because every new licence, integration and pilot quietly changes the defaults. The tenant you hardened at onboarding is not the tenant you have today.
Run this library against your environment
Every check comes with a risk level, a review frequency, an assignee and a plain-language rationale, so the output reads for leadership as well as for engineers.
Other libraries
Remote Monitoring & Management
Alerting, patching, agent health, and endpoint visibility standards
Network Environment
Switching, routing, Wi-Fi, DNS, and network segmentation checks
Active Directory Configuration
GPOs, OU structure, password policies, and domain hygiene
Network Security
Identity, access management, and endpoint protection / EDR standards
Backup & Disaster Recovery
On-premise DR systems and Microsoft 365 backup configuration checks
Server Rooms
Physical environment, cooling, fire suppression, and monitoring standards