Supported Microsoft cloud controls

Manage a Microsoft 365 Security Baseline Across Customer Tenants

Define expected values for supported Microsoft 365 and Entra settings, compare configured customer organizations during the scheduled security-compliance workflow, and review mismatches without hiding the customer context.

Coverage depends on the connected services, permissions, tenant configuration, and Microsoft licensing. Automatic correction is limited to the controls identified below.

Direct answer

What Is Microsoft 365 Security Baseline Management?

Microsoft 365 security baseline management is the process of defining expected security settings, comparing each managed customer environment with those expectations, investigating mismatches, and applying approved changes. In MSPControl, this process covers a defined set of Microsoft 365 and Microsoft Entra controls. A global policy can supply the expected values, while an organization can override supported baseline values when the customer needs a different configuration.

Operating workflow

Turn a Baseline into a Repeatable Review

The workflow keeps expected values, customer-specific differences, current match state, and reporting in the same operational context.

  1. 01

    Define expected values

    Configure the global security-compliance baseline for the supported controls your service has approved.

  2. 02

    Apply customer context

    Use an organization override when a supported setting must differ from the global policy for that customer.

  3. 03

    Compare on schedule

    Include baseline synchronization in the scheduled security-compliance report workflow for configured organizations.

  4. 04

    Review and act

    Investigate mismatches, confirm prerequisites and impact, then make the approved change manually or use a supported correction.

Verified product scope

Know What MSPControl Compares and What It Can Correct

The current implementation records the match state for the controls below. Most mismatches are findings for technician review. Automatic correction is available only for the four explicitly identified settings and only when auto-remediation is enabled.

Control Baseline comparison Automatic correction Operational note
Safe Links enabled Compared No Requires the relevant Exchange Online protection service and licensing.
MFA enforced by Conditional Access Compared No Review exclusions, emergency access, license requirements, and lockout risk before changing policy.
Diagnostic settings enabled Compared No Depends on the configured Azure monitoring destination and available tenant data.
Users can register applications Compared Supported attempt MSPControl can attempt to set the expected directory value when auto-remediation is enabled.
Non-admin access to the Entra admin portal Compared Supported attempt MSPControl can attempt to apply the expected directory restriction.
MFA required to join devices Compared No The comparison needs device-registration policy data from the tenant.
Microsoft Entra license Compared No The detected license is compared with the configured expected value; MSPControl does not assign the license here.
Legacy authentication blocked Compared No Plan exclusions and compatibility work before enforcing a tenant change.
Spam filtering enabled Compared No The organization can use global policy values or an organization-specific override.
Unified Audit Log ingestion and minimum retention Compared Ingestion state only MSPControl can attempt to correct the enabled state. It does not automatically raise the retention period.
Microsoft Intune MDM user scope Compared No The comparison depends on available Intune configuration data.
User consent setting Compared Supported attempt MSPControl can attempt to apply the expected authorization-policy value.
Microsoft 365 Standard Protection Compared No Protection targets, domains, exclusions, initialization, and licensing still require deliberate review.
An attempted correction is not a guarantee of success. Permissions, licensing, service availability, tenant topology, policy conflicts, and Microsoft API behavior can prevent or partially apply a change. Verify the resulting tenant state after every write.

Clear product boundary

Use the Baseline as Evidence for a Decision, Not as a Compliance Certificate

MSPControl provides an operational comparison for supported settings. The result still needs technical and customer context.

No universal standards engine

The workflow does not inspect every Microsoft 365, Entra, Exchange, Defender, Intune, Teams, SharePoint, or Azure configuration object.

No automatic repair of every mismatch

Most supported controls are compared and reported. Only the four correction paths described in the control table are implemented.

No approved-exception lifecycle

Customer overrides can hold different supported baseline values, but the current workflow is not presented as a full exception-request, approval, expiry, and audit system.

No security or compliance guarantee

A matching baseline does not prove that a tenant is secure, compliant, breach-free, correctly licensed, or fully observable.

Safe rollout

Confirm the Context Before You Enforce a Setting

A secure default can still interrupt a customer if licensing, exclusions, legacy dependencies, emergency access, or monitoring destinations have not been prepared.

  • Start with visibility: collect the current values and identify missing data before treating a mismatch as confirmed.
  • Check prerequisites: confirm Microsoft licensing, delegated permissions, connected services, and the customer identity topology.
  • Plan access changes: protect emergency accounts, test exclusions, and review legacy authentication or Conditional Access dependencies.
  • Document customer differences: use organization-specific values only when the exception is deliberate and traceable in your operating process.
  • Verify after a write: reopen the tenant state and confirm the intended value rather than relying on the attempted action alone.

Scheduled evidence

Keep the Review in the Security-Compliance Workflow

The scheduled task can include baseline synchronization while it builds security-compliance data for configured organizations. Report delivery can follow the configured schedule and customer settings. Where ConnectWise integration is configured, related security findings can include ticket context; this page does not claim that every baseline mismatch automatically creates or closes a ticket.

For recurring mismatch investigation, correction boundaries and ticket follow-up, use the Microsoft 365 configuration drift workflow.

Configuration and verification

Use the Guide That Matches the Setting

Review the current MSPControl configuration surface and the applicable Microsoft prerequisites before changing a production tenant.

Common questions

Microsoft 365 Security Baseline FAQ

Does MSPControl manage the same baseline for every customer?

MSPControl can use a global baseline for supported settings and can apply supported organization-specific values when a customer needs a different configuration. The operator remains responsible for approving and documenting the customer context.

Does MSPControl automatically remediate every baseline mismatch?

No. Most controls are compared and stored as match or mismatch evidence. The current optional automatic correction paths are limited to user app registration, non-admin Entra portal access, Unified Audit Log ingestion state, and user consent settings. Retention and the other controls in the table require separate review and action.

Is a matching baseline proof that the tenant is secure or compliant?

No. A match covers only the supported settings and available data. It does not assess every threat, configuration object, license, user, device, workload, legal requirement, or compensating control.

Can MSPControl replace Microsoft Secure Score?

No. Secure Score is a Microsoft measurement of recommended-action progress across supported products. MSPControl’s baseline workflow compares its own defined set of settings for configured customer organizations. The two views answer different operational questions.

What should I check before enabling automatic correction?

Confirm delegated permissions, Microsoft licensing, connected services, customer approval, emergency-access arrangements, policy exclusions, expected business impact, and a rollback path. Verify the tenant state after the attempted change.