Microsoft 365 Baseline Security Mode, Secure Score And Tenant Governance

Compare Microsoft 365 Baseline Security Mode, Secure Score and tenant governance. Learn where CIS Controls and NIS2 fit, and which BSM controls need impact review.
Practical Microsoft security, identity and governance insights
Practical Microsoft security, identity and governance insights

Compare Microsoft 365 Baseline Security Mode, Secure Score and tenant governance. Learn where CIS Controls and NIS2 fit, and which BSM controls need impact review.

Microsoft Entra SMS and voice MFA retirement is coming. Learn when to use passkeys, Windows Hello for Business, QR code sign in and Temporary Access Pass.

Microsoft Entra passwordless password change arrives in October 2026. Learn how it differs from SSPR and what hybrid identity teams should test.

Most Microsoft Entra tenants look mature at the policy layer, but far fewer can clearly explain which system is actually authoritative for their groups. This article explores why Group Source of Authority is not just a sync setting, but a governance control question that shapes ownership, lifecycle, access review enforcement and real identity assurance.

On 19 March 2026, Microsoft quietly released one of the most requested enterprise identity features to Public Preview: a native, platform-managed backup and point-in-time recovery capability for Entra ID tenant configuration. No big announcement, no Message Centre notification. Just a…

Entra Tenant Governance extends UTCM into a multi-tenant governance model, adding tenant discovery, governance relationships and policy templates on top of Microsoft’s native monitoring and snapshot engine. This post breaks down how it works mechanically, what each licensing tier unlocks, where the control-plane risks sit, and when native governance makes sense versus third-party tooling.

Every IT professional knows the struggle: an Intune notification pings with a vague error code or cryptic alert about a device compliance issue, failed update, or potential security threat. You're left scratching your head, wondering, "What does this even mean?" These unclear messages can bury critical issues, like non-compliant devices or malware risks, in a flood of noise. Imagine if those alerts came with clear, human-readable explanations and actionable steps.

Microsoft is phasing out One-Time Passcode (OTP) authentication for SharePoint Online and OneDrive external sharing, replacing it with Entra ID B2B Collaboration, effective July 1, 2025 (MC1089315). Legacy OTP links will stop working, requiring users to re-share content to restore access for external collaborators, who must also register for mandatory MFA. Prepare now by notifying users, updating documentation, auditing shared content, and ensuring Entra ID B2B settings are configured. This shift enhances security but demands proactive planning to avoid disruptions.

As Artificial Intelligence (AI) transforms industries with unparalleled innovation, it also brings serious security risks like data leaks and malicious attacks. A staggering 57% of organisations report rising AI-related incidents, yet 60% lack basic controls. This blog explores the top AI threats, including data exfiltration and malicious prompt injection, and outlines a Zero Trust framework to secure your AI initiatives. Discover powerful tools, from data governance to threat protection, to safeguard your data and ensure compliance in 2025. Don’t let AI become a security wild west—learn how to innovate safely today.

Discover how to strengthen your Microsoft 365 auditing strategy in this practical guide. Learn the strengths and limitations of the Unified Audit Log (UAL) and explore actionable steps to go beyond its basics—using Audit (Premium), SIEM integration, PowerShell automation, and more. Perfect for IT professionals aiming to boost security and compliance with advanced auditing techniques. Start building a robust setup today!