Microsoft 365 security guides
What you already own, how to switch it on, and how to check it works
63 guides on securing Microsoft 365 in an Australian business. Each one states the licence a control needs, the steps to configure it, and the check that proves it is working. Complete on the page, with no email gate and no request for your tenant data.
How to read any of this
A licence is not a control.
Most arguments about Microsoft 365 security are really arguments about which of four states something is in. A licence audit only answers the first.
Included
It is in the subscription you pay for.
Enabled
Somebody switched it on in the tenant.
Configured
The settings match how the business actually operates.
Monitored
Somebody reads the alerts it produces.
When an insurer or a tender questionnaire asks whether you have multifactor authentication or endpoint detection and response, they are asking about the third and fourth states. Answering from the licence sheet is how businesses end up making a claim that does not hold.
Start here
The four guides that answer the questions Australian businesses ask first: what does my licence include, what do I do this week, how do I stop phishing, and what happens when an account is taken over.
- What Security Is Included in Microsoft 365 Business Premium (And What You Still Have to Switch On)The full entitlement list for Business Premium, checked against Microsoft's own documentation, plus the four-state test that separates a licence you pay for from a control that actually works. Checked September 2026.Last reviewed 12 September 2026 · 11 min read
- Microsoft 365 Security Checklist for Small Business: 12 Controls in Priority OrderThe first-week sequence Frontrow runs on an Australian SMB tenant, with the licence each control needs, who has to do it, and the exact check that proves it is working. Free, complete, no email gate. Checked September 2026.Last reviewed 12 September 2026 · 13 min read
- The Microsoft 365 health check Frontrow runs every quarter (full checklist)A quarterly M365 health check is the single most valuable managed service deliverable most clients never ask for. This is the exact checklist Frontrow works through.2 May 2026 · 12 min read
Identity and access
Identity is the perimeter. Multifactor authentication, Conditional Access, the Entra ID licence boundary, and the privileged accounts that decide how bad a bad day gets.
- Phishing-resistant MFA migration plan — the 90-day Australian rolloutASD Essential Eight ML2 expects phishing-resistant MFA on internet-facing systems and privileged accounts. We walk through the 90-day rollout we run for Australian midmarket — FIDO2 keys, Windows Hello for Business, Authenticator passkeys.Last reviewed 10 May 2026 · 8 min read
- Conditional Access policies every Australian Microsoft 365 tenant should runMost Australian Microsoft 365 tenants run two or three Conditional Access policies. The recommended baseline is closer to ten. We walk through the ten policies Frontrow deploys for AU midmarket — what each does, why it matters, and the order to deploy them in.Last reviewed 10 May 2026 · 10 min read
- Conditional Access: the five misconfigurations we see in every Australian tenantFrontrow's identity engagements consistently surface the same five Conditional Access failure patterns. Report-only purgatory, weak break-glass, untrusted device-compliance, location bypass, legacy auth. The board thinks the policies are enforcing. They aren't.7 May 2026 · 10 min read
- Conditional Access patterns that don't break for travelling execsThe Conditional Access policy set we actually deploy for Australian businesses. Block legacy auth, require MFA, require compliant device — without locking out execs in airport lounges.22 April 2026 · 8 min read
- Entra ID P1 vs P2: the seven-feature gap and when P2 pays back (AU 2026)Entra ID P1 vs P2 for Australian buyers: standalone P1 is $9 AUD per user per month, P2 is $13.50. The seven P2-only features (PIM, Identity Protection, access reviews) and the five scenarios where the $4.50 upgrade pays back.Last reviewed 3 July 2026 · 7 min read
- Entra ID P2: the 10 things to turn on in your first 90 days — an Australian tenant checklistMost tenants that pay for Entra ID P2 have configured none of it. Ten configuration steps in order — sign-in and user risk policies in report-only first, the self-remediation path, risk levels, alert routing, rehearsal with simulated detections, PIM for roles, groups and Azure resources, the privileged role access review, and the score baseline — plus what P2 does not include so you do not plan on it.29 July 2026 · 12 min read
- Setting up Privileged Identity Management, step by step — with the 7 traps that break a PIM rolloutTen stages for turning standing administrative privilege into just-in-time access in Microsoft Entra: licensing, the standing-privilege inventory, protecting emergency access accounts, role settings before assignments, converting permanent to eligible, the pilot, Azure resource roles and PIM for Groups, alerts and access reviews. Plus the seven traps that produce a rollout everyone quietly works around.29 July 2026 · 13 min read
- A PIM rollout that actually sticksEntra ID PIM is the Essential Eight's biggest lever on Strategy 5. Here's how to roll it out without breaking your IT ops team on day one.22 April 2026 · 8 min read
- Locked out of multifactor authentication: the recovery runbookWhat to do when a user is locked out of MFA in Microsoft 365: verifying who they are, resetting authentication methods safely, and the Temporary Access Pass.19 August 2026 · 9 min read
- Workload identities: the CISO's blind spot in Microsoft 365Service principals, app registrations and OAuth-consented apps are the most exploited and least governed surface in M365. Storm-0558 and Midnight Blizzard both pivoted through workload identities. Here's the AU mid-market field report.7 May 2026 · 11 min read
- Entra cross-tenant access settings — the M&A playbook for AU mid-market (2026)Every Australian M&A transaction in 2026 requires the two Entra tenants to talk before they merge. Cross-tenant access settings, B2B vs Direct Connect, trust settings and the 90-day plan Frontrow runs on AU acquisitions.Last reviewed 18 May 2026 · 8 min read
Email, phishing and payment fraud
Where the money actually goes missing. Email authentication for your own domain, the tenant lockdown for business email compromise, and the Australian loss figures behind both.
- Business email compromise: a tenant lockdown planSeven Microsoft 365 controls that stop BEC: phishing-resistant MFA, Conditional Access, forwarding blocks, DMARC and payment verification. Checked August 2026.12 August 2026 · 10 min read
- SPF, DKIM and DMARC for Microsoft 365: the complete email authentication setup guideThe exact DNS records, portal steps and staged rollout Frontrow uses to configure SPF, DKIM and DMARC on a Microsoft 365 domain, and the mistakes that silently break legitimate mail.6 July 2026 · 12 min read
- BEC scam statistics Australia 2026: the $2.18B pictureCombined scam losses hit $2.18B in 2025; payment redirection cost $166.8M. NASC, ASD ReportCyber and FBI IC3 figures reconciled. Checked July 2026.19 August 2026 · 10 min read
Devices and endpoints
Which Defender you have, whether it is genuinely an EDR, how to deploy it, and what to do with the alerts once it starts producing them.
- Is Microsoft Defender an EDR? It Depends Which Defender You Mean (2026)The built-in Defender Antivirus is not an EDR, but Defender for Endpoint Plan 2 and Defender for Business are. Which licence includes which, capability by capability, with AUD prices. Checked September 2026.Last reviewed 12 September 2026 · 9 min read
- Deploying Microsoft Defender for Endpoint: a 12-step rollout for an Australian mid-market tenantBuying the licence is not the deployment. Twelve steps in the order they have to happen — data storage geolocation, onboarding method, the antivirus handover, device groups before devices, pilot ring, sensor health verification, automation level, the protections that are off until you turn them on, servers, alert routing, live response, and the review cadence — with the five traps that stall Australian rollouts.29 July 2026 · 13 min read
- Microsoft Defender for Endpoint alert triage: a first-hour runbook for Australian IT teamsWhat to do in the sixty minutes after a high-severity Defender alert. The five questions to answer before touching anything, a nine-step triage sequence, containment actions ranked by how reversible they are, the six alert types never to auto-resolve, and what to preserve so the Notifiable Data Breach assessment can be narrow rather than precautionary.29 July 2026 · 12 min read
- Microsoft Defender ASR rules — the 16 you actually need, ranked for AU mid-market (2026)Attack Surface Reduction rules in Microsoft Defender for Endpoint stop the dominant attacker techniques in Australian breaches. Sixteen rules, ranked by impact, with the audit-vs-enforce posture Frontrow recommends and the exception patterns that actually surface in production.Last reviewed 14 May 2026 · 9 min read
- Defender Vulnerability Management Australia 2026 — what the standalone SKU adds, the dollar cost, when it pays backMicrosoft Defender Vulnerability Management is a paid SKU that extends Defender for Endpoint with security baselines, browser extension assessment, certificate inventory and authenticated network scanning. AUD pricing, what it actually adds and the break-even for AU mid-market.Last reviewed 18 May 2026 · 8 min read
- Microsoft Defender for Identity — what it catches that nothing else does, Australia 2026Defender for Identity (formerly Azure ATP) detects on-premises Active Directory attacks invisible to Defender for Endpoint and Defender XDR. AU 2026 deployment guide, the attacks it actually catches, and licensing.Last reviewed 18 May 2026 · 8 min read
Data protection, labels and backup
Retention is not backup, a recycle bin is not a restore, and a sensitivity label is the control that makes Copilot safe to switch on.
- Does Microsoft 365 back up your data? The shared-responsibility truth for Australian businessesThe short answer is no, not in the way most businesses assume. Here is exactly what Microsoft protects, how long deleted data survives natively, what the paid Microsoft 365 Backup service covers, and where third-party backup still earns its keep.Last reviewed 12 September 2026 · 9 min read
- Microsoft 365 backup strategy for AU businesses: what Microsoft does, what you still need to addMicrosoft provides redundancy and short-term recoverability, not backup. Here's what Australian businesses are actually missing, and what a complete M365 backup strategy looks like.2 May 2026 · 7 min read
- Sensitivity labels in 2026: what Privacy Act reform means for your Microsoft 365 tenantPrivacy Act reforms have hardened the 'reasonable steps' standard. Tribunals now point at sensitivity labelling and DLP as baseline expectations. Most AU mid-market tenants have labels deployed at 4% adoption. That's the gap.7 May 2026 · 10 min read
- Container labels versus file labels: the 90% of Australian tenants doing it wrongMost Microsoft 365 tenants apply file labels and never apply container labels — leaving sensitive SharePoint sites fully shareable even when individual files are correctly classified. Here's the field report on why that gap matters and how to close it.7 May 2026 · 8 min read
- What to fix in SharePoint and OneDrive permissions before you switch Copilot on: a pre-flight checklistCopilot grants nobody new access. It removes the friction from access that already existed, which is why oversharing is the classic Australian mid-market Copilot failure. This is the eight-step pre-flight checklist: the reports to run, broad internal sharing, Anyone links, the OneDrive blind spot, sensitivity labels and the encryption trap, restricting discovery on sites still under review, ownership, and the agents users are already creating.29 July 2026 · 13 min read
Essential Eight and Australian frameworks
The ASD maturity model mapped onto Microsoft 365, what Maturity Level Two costs, and where the frameworks are heading.
- How the Essential Eight maps to Microsoft 365For each of the ACSC's eight strategies, the exact Microsoft 365 control that does the work. No vendor bingo. No abstraction. Just the tools you already licence.22 April 2026 · 11 min read
- Essential Eight Maturity Level 2 — the Microsoft 365 implementation mapEach Essential Eight strategy at Maturity Level 2 mapped to the Microsoft 365 service that delivers it. Frontrow's working blueprint for Australian tenants closing the gap to ML2 with the licensing already in place.25 April 2026 · 9 min read
- Reaching Essential Eight Maturity Level 2 without killing productivityA practical, 90-day roadmap for Australian businesses moving from ML0/ML1 to ML2 on Microsoft 365 — with the change-management gotchas that usually derail it.22 April 2026 · 9 min read
- Essential Eight Maturity Level 2 is the new Australian baseline. A 90-day plan from ML1.ASD expects ML2 as the default in 2026, ML3 for critical infrastructure. A pragmatic 90-day sprint if a Microsoft 365 tenant is still at ML1 or ML0.25 April 2026 · 9 min read
- Is the Essential Eight Being Replaced? ASD's Essentials Series, Explained (2026)ASD is consulting on replacing the Essential Eight with an Essentials series. The Essential Eight stays in force today. What changes. Checked July 2026.26 July 2026 · 9 min read
- What Essential Eight Compliance Costs in Australia (2026)Essential Eight cost drivers: what Microsoft 365 licensing already covers, published assessment fees from $8,500, and the hidden costs. Checked July 2026.30 July 2026 · 9 min read
- Essential Eight Compliance Statistics: How Many Australian Organisations Actually Get There? (2026)Verified Essential Eight compliance statistics for Australia: only 22% of federal government entities reached Maturity Level 2 in 2025, per-strategy pass rates, ANAO audit findings, and why no reliable private-sector numbers exist.11 July 2026 · 7 min read
Incidents, breaches and obligations
What the first 72 hours look like, what the Notifiable Data Breaches scheme requires, and what an Australian cyber insurer will ask before it pays.
- Data breach response plan Australia — the first 72 hours, step by stepWhat an Australian business must do in the first 72 hours of a data breach: containment, evidence, the Privacy Act serious-harm assessment, OAIC and ACSC reporting, and the ransomware payment reporting rule, hour by hour.Last reviewed 3 July 2026 · 10 min read
- Privacy Act 2026: the seven Microsoft 365 controls regulators expectOAIC determinations and tribunal decisions through 2025-2026 have hardened the 'reasonable steps' standard. These are the seven Microsoft 365 controls that now define the contemporary baseline — and what to do if you don't have them.7 May 2026 · 11 min read
- What Australian cyber insurers actually require in 2026 (and why claims get denied)The controls Australian cyber insurers expect at renewal in 2026 (MFA everywhere, EDR, tested backups, patching, restricted admin rights), why claims get denied, and how the questionnaire maps to the Essential Eight and Microsoft 365.11 July 2026 · 7 min read
- Australian data breach statistics 2026: what the OAIC numbers show1,205 data breaches were notified to the OAIC in 2025, the highest annual total since mandatory reporting began. Here are the verified numbers on causes, sectors, credentials, ransomware and costs, with every figure sourced to its OAIC reporting period.11 July 2026 · 7 min read
- Australian ransomware statistics: 138 incidents, 64% pay138 ransomware incidents, 64% of attacked businesses paying, a $711,000 average ransom, and the mandatory payment-reporting numbers. Checked July 2026.12 August 2026 · 10 min read
- Australian cyber insurance statistics 2026: the APRA numbersCyber GWP was AUD $32m in the March 2026 quarter, under 0.2% of industry premium, and uptake fell in 2025. APRA and AIC figures. Checked July 2026.8 August 2026 · 8 min read
- Australian cyber security statistics 2026: what the official numbers actually sayOver 84,700 cybercrime reports to ASD in FY2024-25, an average small-business loss of $56,600 per report, and 1,205 data breaches notified to the OAIC in 2025. The verified Australian cyber security statistics, with sources, compiled July 2026.11 July 2026 · 8 min read
Securing Copilot and AI
Copilot inherits whatever permissions and labels are already in place. These cover the work that has to happen before it is switched on, and the governance that follows.
- Prompt injection and Copilot: a rollout risk assessmentEchoLeak and SearchLeak made prompt injection a board question. A ten-question assessment with a proceed-or-pause verdict per row, built from what both cases actually showed.28 August 2026 · 11 min read
- Does the Essential Eight actually cover Microsoft Copilot?The short answer: partly. The Essential Eight was written before Copilot existed, and there are six specific controls it doesn't touch that a Copilot rollout requires. Here's the honest delta.22 April 2026 · 12 min read
- ISO 42001, Voluntary AI Safety Standard and Essential Eight — what Australian organisations actually needThree frameworks Australian boards are being asked about: the international AI management standard ISO 42001, the Department of Industry's Voluntary AI Safety Standard, and the ASD's Essential Eight. Frontrow's plain-English guide to what each one is, where they overlap, and which one to start with.25 April 2026 · 8 min read
- AI misuse at work: the employer response checklistStaff pasting client data into chatbots, AI-drafted grievance campaigns, AI claims at the Fair Work Commission. The detect, policy and response checklist for employers.28 August 2026 · 10 min read
The rest of the security library
Deeper and more specialised material: regulated-industry obligations, Sentinel and SOC work, insider risk, and the Australian threat statistics Frontrow reconciles against primary sources.
- Mining supplier cyber security questionnaire: the checklistCyber Security
- APRA's AI letter mapped to Microsoft 365 controlsCyber Security
- Defender for Office 365 Plan 1 vs Plan 2: what P2 adds, AUD pricing and the July 2026 bundle changeCyber Security
- IRAP Assessments Explained: Process, Cost Drivers and Readiness for Selling to the Australian Government (2026)Compliance
- Entra Suite vs Entra ID P2: the à la carte trap (AU 2026)Identity & Access
- Microsoft Sentinel vs Defender XDR: When You Need Each (Australia 2026)Cyber Security
- Entra ID P2 Explained: Features, Price & Licensing (AU)Identity & Access
- Insider Risk Management: the Australian mid-market starter playbookInsider risk
- Global Secure Access vs traditional VPN: when AU organisations should switch in 2026Network security
- APRA CPS 230 readiness: the operational risk checklist for AU financial services in 2026Regulatory compliance
- Microsoft Sentinel KQL — the 20 queries every Australian SOC analyst should know (2026)Cyber
- Defender for Cloud Apps — shadow IT discovery, the AU rollout playbook (2026)Cyber
- Microsoft Sentinel cost optimisation — five plays that cut AU spend by 30–50%Cyber
- SOCI in Microsoft 365: a plain-English operational guide for Australian mid-marketCompliance
- APRA CPS 234 — the Microsoft 365 implementation map for Australian financial servicesCyber Security
- What a cyber report for the board should actually containCyber Security
- When an Australian mid-market business actually needs Microsoft SentinelCyber Security
Free tools
Check your own position.
Each of these runs in the browser, asks no email address, and never asks you to upload tenant data, sign-in logs or incident evidence.
- Essential Eight scorecardScore the eight strategies against the ASD maturity model.
- Phishing-resistant MFA checkFind which sign-in methods an attacker-in-the-middle kit can relay.
- Conditional Access misconfiguration checkThe policy gaps Frontrow finds most often in Australian tenants.
- Microsoft EDR plan selectorWork out whether your licence actually includes endpoint detection and response.
- Microsoft 365 backup gap checkerWhat your tenant can currently restore, and how far back.
- Defender posture gapHow your Defender configuration compares with a sound SMB baseline.
- SharePoint oversharing checkThe permissions work to do before Copilot is switched on.
- Notifiable Data Breaches readinessWhether you could actually run the 30-day assessment the scheme requires.
Want someone to walk your tenant with you?
A senior Frontrow consultant works through what your licence includes, what is switched on, and what is configured to match how your business actually operates. The output is a gap list in plain English, with the effort against each item.