No universal standards engine
The workflow does not inspect every Microsoft 365, Entra, Exchange, Defender, Intune, Teams, SharePoint, or Azure configuration object.
Platform capabilities
Manage Microsoft cloud services, Windows devices, security, documentation, backup, and support from one self-hosted platform.
Supported Microsoft cloud controls
Define expected values for supported Microsoft 365 and Entra settings, compare configured customer organizations during the scheduled security-compliance workflow, and review mismatches without hiding the customer context.
Coverage depends on the connected services, permissions, tenant configuration, and Microsoft licensing. Automatic correction is limited to the controls identified below.
Direct answer
Microsoft 365 security baseline management is the process of defining expected security settings, comparing each managed customer environment with those expectations, investigating mismatches, and applying approved changes. In MSPControl, this process covers a defined set of Microsoft 365 and Microsoft Entra controls. A global policy can supply the expected values, while an organization can override supported baseline values when the customer needs a different configuration.
Operating workflow
The workflow keeps expected values, customer-specific differences, current match state, and reporting in the same operational context.
Configure the global security-compliance baseline for the supported controls your service has approved.
Use an organization override when a supported setting must differ from the global policy for that customer.
Include baseline synchronization in the scheduled security-compliance report workflow for configured organizations.
Investigate mismatches, confirm prerequisites and impact, then make the approved change manually or use a supported correction.
Verified product scope
The current implementation records the match state for the controls below. Most mismatches are findings for technician review. Automatic correction is available only for the four explicitly identified settings and only when auto-remediation is enabled.
| Control | Baseline comparison | Automatic correction | Operational note |
|---|---|---|---|
| Safe Links enabled | Compared | No | Requires the relevant Exchange Online protection service and licensing. |
| MFA enforced by Conditional Access | Compared | No | Review exclusions, emergency access, license requirements, and lockout risk before changing policy. |
| Diagnostic settings enabled | Compared | No | Depends on the configured Azure monitoring destination and available tenant data. |
| Users can register applications | Compared | Supported attempt | MSPControl can attempt to set the expected directory value when auto-remediation is enabled. |
| Non-admin access to the Entra admin portal | Compared | Supported attempt | MSPControl can attempt to apply the expected directory restriction. |
| MFA required to join devices | Compared | No | The comparison needs device-registration policy data from the tenant. |
| Microsoft Entra license | Compared | No | The detected license is compared with the configured expected value; MSPControl does not assign the license here. |
| Legacy authentication blocked | Compared | No | Plan exclusions and compatibility work before enforcing a tenant change. |
| Spam filtering enabled | Compared | No | The organization can use global policy values or an organization-specific override. |
| Unified Audit Log ingestion and minimum retention | Compared | Ingestion state only | MSPControl can attempt to correct the enabled state. It does not automatically raise the retention period. |
| Microsoft Intune MDM user scope | Compared | No | The comparison depends on available Intune configuration data. |
| User consent setting | Compared | Supported attempt | MSPControl can attempt to apply the expected authorization-policy value. |
| Microsoft 365 Standard Protection | Compared | No | Protection targets, domains, exclusions, initialization, and licensing still require deliberate review. |
Clear product boundary
MSPControl provides an operational comparison for supported settings. The result still needs technical and customer context.
The workflow does not inspect every Microsoft 365, Entra, Exchange, Defender, Intune, Teams, SharePoint, or Azure configuration object.
Most supported controls are compared and reported. Only the four correction paths described in the control table are implemented.
Customer overrides can hold different supported baseline values, but the current workflow is not presented as a full exception-request, approval, expiry, and audit system.
A matching baseline does not prove that a tenant is secure, compliant, breach-free, correctly licensed, or fully observable.
Safe rollout
A secure default can still interrupt a customer if licensing, exclusions, legacy dependencies, emergency access, or monitoring destinations have not been prepared.
Scheduled evidence
The scheduled task can include baseline synchronization while it builds security-compliance data for configured organizations. Report delivery can follow the configured schedule and customer settings. Where ConnectWise integration is configured, related security findings can include ticket context; this page does not claim that every baseline mismatch automatically creates or closes a ticket.
For recurring mismatch investigation, correction boundaries and ticket follow-up, use the Microsoft 365 configuration drift workflow.
Configuration and verification
Review the current MSPControl configuration surface and the applicable Microsoft prerequisites before changing a production tenant.
Common questions
MSPControl can use a global baseline for supported settings and can apply supported organization-specific values when a customer needs a different configuration. The operator remains responsible for approving and documenting the customer context.
No. Most controls are compared and stored as match or mismatch evidence. The current optional automatic correction paths are limited to user app registration, non-admin Entra portal access, Unified Audit Log ingestion state, and user consent settings. Retention and the other controls in the table require separate review and action.
No. A match covers only the supported settings and available data. It does not assess every threat, configuration object, license, user, device, workload, legal requirement, or compensating control.
No. Secure Score is a Microsoft measurement of recommended-action progress across supported products. MSPControl’s baseline workflow compares its own defined set of settings for configured customer organizations. The two views answer different operational questions.
Confirm delegated permissions, Microsoft licensing, connected services, customer approval, emergency-access arrangements, policy exclusions, expected business impact, and a rollback path. Verify the tenant state after the attempted change.
Self-hosted. Free license available. No credit card required.