NetFusion Designs logo
Heart icon
Support
Email
info@nfd.ca
Phone
289 212-3930(Canada)
IT Services
Icon dropdown arrow

Infrastructure Implementation

Project PlanningHardware Voice over IP (VoIP)Application DevelopmentCloud DesktopSecurity Cameras

Managed IT Services

IT Support24/7 HelpDeskCyber Security & AntivirusData Backups & Disaster
Recovery
Co-Managed ITComplianceEmergency Ransomware
Recovery
Penetration & Vulnerability
Assessment

Optimization of Processes

Microsoft 365 OptimizationVirtual CIO ServicesPenetration TestingInventory Lifecycle
Management
Transforming SMEs with AI
Industries
Icon dropdown arrow
Dental Managed IT Services
Construction
Hotels & Hospitality
Franchises
Financial & Insurance Services
Government
Health Care & PharmaceuticalLegal & Professional Services
Local Small & Medium Businesses
Manufacturing
Non-profit
Real Estate
Retail
Transportation & Logistics
Enterprise & Consulting
Publicly Traded Companies
Our Story
Icon dropdown arrow
About UsTestimonials
Partners
Sponsorship
BlogContact Us
Open menuClose menu
Icon chevron up
Browse Blog:
Business
Insight
Advice
Insight

Enable M365 Security Baselines Without Breaking Legacy Apps for Admins

A Microsoft 365 security baseline is a tested set of configuration defaults that Microsoft publishes to close the gaps that most often lead to account compromise. The single most useful action you can take today is to enable Baseline Security Mode in the admin centre or assign an Intune security baseline profile to a pilot group, then track the result through Secure Score.


TL;DR:

  • Enabling Baseline Security Mode or Intune profiles is critical for establishing a strong security foundation and improving your Secure Score quickly.
  • Prioritize identity and authentication controls, especially blocking legacy authentication and enforcing phishing-resistant MFA for privileged accounts, to reduce most breach risks.
  • Deploy baselines gradually starting with a pilot group, monitor settings carefully, and validate no critical applications break before tenant-wide enforcement.
  • Use Intune dashboards, Secure Score, and Zero Trust assessments regularly to track compliance, identify weaknesses, and prevent configuration drift.
  • Be aware that newer baseline formats and updates may require creating new profiles and testing app compatibility to avoid disruptive breakages.

NetFusion Designs Inc
nfd.ca
Strengthen Your Microsoft 365 Security
NetFusion Designs helps businesses manage Microsoft 365, security, monitoring, helpdesk, cloud, and compliance with enterprise-grade tooling.
Explore managed IT services

Table of Contents

  • What a Microsoft 365 security baseline is and where it fits in your security programme
  • Key baseline controls and recommended settings by category
  • How to access and deploy baselines: BSM, Intune profiles, and Security Compliance Toolkit
  • Testing, monitoring and validation: Intune reports, Secure Score and Zero Trust Assessment
  • Versioning and migration considerations: new baseline formats and avoiding breaking changes
  • Operational checklist for rollout and common pitfalls
  • Publisher perspective: how we approach baseline rollouts
  • How NetFusion Designs can help deploy and operate Microsoft 365 security baselines
  • Sources
  • FAQ

What a Microsoft 365 security baseline is and where it fits in your security programme

Microsoft security engineering teams, product groups and partner contributors build these baselines from real incident data, not guesswork. The goal is to give administrators a defensible starting point instead of a blank configuration screen, which is where most misconfigurations begin.

Baselines matter because they compress months of policy research into a package you can review and apply in days. They also standardize settings across tenants of similar size, so your configuration decisions match what Microsoft’s own security teams recommend for organizations facing comparable threats.

You will find baselines published and managed in three places:

  • Microsoft Intune, where baseline profiles are assigned to devices and monitored through a dashboard.
  • The Security Compliance Toolkit, for organizations still managing devices through on-premises Group Policy.
  • The Microsoft 365 admin centre, where Baseline Security Mode applies tenant-wide protective defaults without requiring device enrolment.

Baselines feed directly into a Zero Trust approach: they enforce the “verify explicitly, use least privilege” principle at the configuration layer rather than leaving it to policy documents. Every setting you bring into line with a baseline typically improves your Secure Score, giving you a running number that shows whether your posture is improving or drifting.

Key baseline controls and recommended settings by category

Not every setting in a baseline carries equal weight. A handful of categories account for most of the risk reduction, so prioritize these first if your rollout window is short.

Identity and authentication sits at the top of the list. Baseline Security Mode settings push administrators toward phishing-resistant MFA for privileged roles, block legacy and basic authentication protocols outright, and require Conditional Access policies for high-risk sign-ins. Legacy auth remains one of the easiest paths into a tenant because it bypasses modern MFA checks entirely, so blocking it is rarely optional once you understand the exposure.

Application consent and app credentials come next. Restricting user consent to third-party applications closes a path attackers use to gain persistent access without ever touching a password, and blocking password-based app credentials in favour of certificates removes another quiet backdoor.

Exchange and EWS controls deserve specific attention because Exchange Web Services is a common target for token theft and mailbox exfiltration tools. Baseline guidance points administrators toward disabling or tightly scoping EWS access where it is not actively needed by a line-of-business integration.

File and protocol controls block insecure legacy protocols such as HTTP and FTP for file access, along with outdated browser and client authentication mechanisms like RPS and IDCRL that predate modern token-based sign-in.

Office application protections round out the list: blocking Flash content, restricting JScript execution, requiring signed macros, and applying attack-surface reduction rules that stop Office apps from spawning child processes commonly used in malware delivery.

  • Enforce phishing-resistant MFA for all privileged and administrative accounts.
  • Block legacy authentication protocols tenant-wide through Conditional Access.
  • Restrict third-party application consent to admin-approved apps only.
  • Disable or scope EWS access where no integration depends on it.
  • Require signed macros and enable attack-surface reduction rules in Office apps.

Most security breaches trace back to missing foundational controls like these, and applying baselines alongside Zero Trust Assessment and Conditional Access delivers the most measurable short-term risk reduction. That is a strong argument for starting with identity and legacy auth before moving to the rest of the list.

Expect some user friction. Blocking legacy auth can break older line-of-business applications that authenticate with basic credentials, and macro-signing requirements will surface unsigned internal tools that nobody has touched in years. Budget time to find these before you enforce anything tenant-wide.

How to access and deploy baselines: BSM, Intune profiles, and Security Compliance Toolkit

You have three practical deployment paths, and most enterprise tenants will end up using more than one.

  1. Enable Baseline Security Mode from the Microsoft 365 admin centre’s security settings, where you can review each recommended control before turning it on tenant-wide.
  2. Create and assign an Intune security baseline profile to a device group, then use the Intune monitoring dashboard to check assignment status and per-setting compliance as devices report in.
  3. Download the current baseline package from the Security Compliance Toolkit if part of your estate is still managed through on-premises Active Directory, then import the GPOs and run Policy Analyzer to compare them against your existing policies before deployment.

Our Intune device management setup guide walks through the profile creation steps in more detail if you are configuring this for the first time.

Do not enforce any baseline tenant-wide on day one. Assign it to a small, representative pilot group first, watch the per-setting status for a week or two, and confirm no critical application breaks before expanding the assignment. If something goes wrong, removing the assignment from the pilot group rolls the devices back to their prior state without a manual undo of every setting.

Pilot rollout path with rollback option

Pro Tip: Keep one test device on the old baseline version during a migration so you have a working comparison point if the new profile causes unexpected behaviour.

Testing, monitoring and validation: Intune reports, Secure Score and Zero Trust Assessment

Deployment is only half the job. Validating that a baseline is actually doing what it should requires three separate views into your tenant.

  • The Intune baseline dashboard shows per-setting status and device assignment status, letting you drill into a specific device to see which settings failed to apply and why.
  • Secure Score tracks the cumulative effect of your changes over time, so you can map a specific baseline rollout to a measurable score improvement rather than guessing at impact.
  • The Zero Trust Assessment produces a scored gap list across identity, devices, data and network, which is useful for finding weaknesses a device-level baseline alone will not catch.

Beyond these dashboards, enable diagnostic settings for Microsoft Entra and Intune and ship the logs to a queryable workspace. Conflicts between baseline settings and existing Conditional Access policies rarely show up cleanly in the summary dashboards. They surface in sign-in logs as failed authentication attempts or unexpected blocks, so having a searchable log history saves hours during troubleshooting.

Run this combination on a schedule rather than once. A baseline that passed validation in January can drift out of compliance by June as new devices enrol, apps get updated, or someone reverts a setting manually during a support call.

Versioning and migration considerations: new baseline formats and avoiding breaking changes

Microsoft moved Intune baselines to a new format starting in May 2023, mapping settings directly to Configuration Service Providers (CSPs) rather than the older policy structure. If you built baseline profiles before that change, understand what shifts before you touch them.

  • Older profile instances can become read-only once Microsoft retires the format they were built on, meaning you will need to create a new profile rather than edit the existing one.
  • The Microsoft 365 Apps security baseline is published twice a year under explicit version numbers such as 2412 or 2512, and each release ships as a downloadable package containing GPOs, documentation and the MS Security Guide administrative template.
  • Some legacy Office behaviours break when a newer baseline is applied without a pilot phase, so test with a representative app compatibility group before rolling a new version tenant-wide.
  • Use Policy Analyzer from the Security Compliance Toolkit to detect GPO conflicts and configuration drift whenever you move between baseline versions, particularly in hybrid environments running both Intune and on-premises Group Policy.

Pro Tip: Subscribe to the baseline release notes for both Intune and Microsoft 365 Apps so a new version never catches your team off guard mid-quarter.

Our post on the tools that replaced the Microsoft Baseline Security Analyzer covers how the Security Compliance Toolkit fits into this versioning picture for teams still running mixed environments.

Operational checklist for rollout and common pitfalls

A baseline rollout succeeds or fails based on the groundwork you do before enforcement, not the settings themselves.

  1. Inventory your device types, operating system versions and the applications that authenticate in ways a baseline might block.
  2. Pilot the profile on a small, representative group and watch per-setting status closely for at least a week.
  3. Roll out in stages, monitoring reports at each stage and remediating conflicts before expanding further.
  4. Validate with a Zero Trust Assessment once the rollout stabilizes, then schedule recurring reviews to catch drift.

Common pitfalls are consistent across most rollouts:

  • Skipping the pilot phase and enforcing a baseline tenant-wide on day one.
  • Mixing Security Defaults with Conditional Access policies without checking for overlap or conflict.
  • Never enabling diagnostic logging, which leaves you troubleshooting blind when something breaks.

Our guide on strengthening business data security posture covers how these steps fit into a broader annual security review cycle.

Publisher perspective: how we approach baseline rollouts

We run every baseline deployment pilot first. A small, representative group tells you more about real-world impact in a week than any documentation review will, and it catches the legacy application that nobody remembered still uses basic authentication.

Staged rollout and continuous monitoring follow the pilot, with baseline drift checked against Secure Score and folded into our MDR monitoring so a configuration change never sits unnoticed for months. Organizations with limited internal IT capacity, a hybrid estate spanning cloud and on-premises systems, or specific compliance obligations tend to benefit most from handing this work to a team that does it daily. As a SOC 2 Type II certified provider running a 24/7 NOC with dedicated Microsoft 365 optimization expertise, this is the kind of work we do for clients across their full environment, not just at rollout.

— Geeshan

How NetFusion Designs can help deploy and operate Microsoft 365 security baselines

Getting a baseline configured correctly is one project. Keeping it correctly configured through every Intune update, every new device enrolment and every application change is an ongoing operational commitment, and that is where most internal IT teams run out of bandwidth.

NetFusion Designs Inc

NetFusion Designs handles baseline deployment, monitoring and remediation as part of our Managed IT Services, backed by a SOC 2 Type II certified team and a 24/7 NOC watching for drift after rollout. Our Microsoft 365 optimization work covers everything from initial baseline assessment through staged deployment and ongoing Secure Score tracking, so your configuration stays current as Microsoft ships new versions. If you want a clear picture of where your tenant stands before committing to a rollout timeline, our free cybersecurity assessment gives you a starting score in a few minutes.

Sources

  • Baseline security mode settings - Microsoft Learn
  • Security baselines in Microsoft Intune - Microsoft Learn
  • Security Compliance Toolkit 10 - Microsoft Learn

FAQ

Is the Microsoft Baseline Security Analyzer still available?

No, the legacy Microsoft Baseline Security Analyzer (MBSA) has been retired. Microsoft replaced it with the Security Compliance Toolkit, which provides baseline downloads, GPO backup files, reports and scripts for managing security configurations.

What is the Microsoft Windows 11 security baseline?

It is a preconfigured set of Windows security settings, built by Microsoft security engineering teams and partners, that administrators can apply through Intune or as Group Policy Objects on-premises. The baseline groups related settings together so admins do not have to configure each one individually from a blank policy.

What is a security baseline document?

A security baseline document describes a tested group of configuration settings, along with the reasoning and guidance behind each one, that an organization can adopt as a starting security posture. For Microsoft products, these are published as downloadable packages containing GPOs, administrative templates and supporting documentation.

What replaced Microsoft Baseline Security Analyzer?

The Security Compliance Toolkit (SCT) replaced MBSA, adding tools like Policy Analyzer for comparing existing Group Policy Objects against Microsoft’s recommended baselines. It gives administrators a clearer way to detect configuration drift than MBSA ever offered.

Recommended

  • Microsoft 365 Optimization
  • Free Cybersecurity Assessment | 8 Questions, Instant Score

Continue Reading

Measure by difficulty: Phishing simulation best practices for SMBs
PIA First, Pilot Next: Bring Your Own Device Policy for IT & Execs
Working Catalog: Power Automate Examples for IT & Business Leaders
Stop 30 Day Purges: Exchange Online Retention Policies for Admins
NetFusion Designs logo
NetFusion Designs is a globally recognized IT service provider and services clients across North America.

We hold a SOC 2 Type 2 report, and maintain internal processes and procedures that keep our clients’ data secure and confidential.
NetFusion Designs IT support team
IT Services Near Me
BurlingtonOakvilleHamiltonMississaugaMiltonBramptonEtobicokeBrantfordGuelphKitchenerWaterlooCambridgeSt CatharinesTorontoMarkhamCaledonNewmarket
Services
Project PlanningHardwareTelephony & VoIPApplication DevelopmentCloud DesktopSecurity CamerasHelpdesk & SupportCyber Security & Anti-VirusData Backups & Disaster RecoveryMicrosoft 365 OptimizationVirtual CIO ServicesPenetration TestingPricingSchedule a MeetingRemote Support
Pricing
Pages
Free Security ScanAbout UsOur Migration ApproachWork CultureOur Core ValuesCode of ConductTestimonialsContactBlogSchedule a MeetingRemote Support
TORONTO
Bank capital office building law
401 Bay St, 16th Floor, Toronto Ontario
Email
info@nfd.ca
Phone
647-476-5259 (Canada)
MARKHAM
Bank capital office building law
141 Main Street N, Markham, ON L3P 1Y2
Email
info@nfd.ca
Phone
647-476-5259 (Canada)
TRI-CITY AREA
(Kitchener / Waterloo / Cambridge)
Bank capital office building law
22 Frederick St, Suite 700, Kitchener Ontario
Email
info@nfd.ca
Phone
647-476-5259 (Canada)
PEEL REGION
Bank capital office building law
6700 Century Ave, 3rd floor, Mississauga, ON L5N 1V8
Email
info@nfd.ca
Phone
647-476-5259 (Canada)
DURHAM REGION
Bank capital office building law
1315 Pickering Parkway, Pickering, ON L1V 7G5
Email
info@nfd.ca
MONTREAL
Bank capital office building law
8815 Av du Parc #402, Montréal, QC H2N 1Y7
Email
info@nfd.ca
Phone
647-476-5259 (Canada)
Special Offers
Pie chart piechart stats analytics
IT-Optimization Session
Icon chevron right
Money safe safebox
800% ROI Consultancy Offer (Video)
Icon chevron right
Radio station signal antena tower
Coming Soon!
Icon chevron right
Terms and ConditionsPrivacy PolicyCookie Policy
© 2026 NetFusion Designs Inc.
LinkedInFacebookAlignable logo