Consulting Module

Module 3 — M365 Security Hardening

Most M365 E3 tenants are running at a fraction of the security their licence already includes. This module extracts that value systematically — tightening the controls that exist, enabling the logging that should be on, and capturing the baseline so drift is detectable from day one.

What It Delivers

📧

Exchange Online Protection Tuning

Anti-phishing, anti-malware, and anti-spam policies reviewed and tightened. DKIM, DMARC, and SPF validated. External sender tagging enabled. Auto-forwarding to external addresses blocked — one of the most reliable business email compromise persistence mechanisms.

📒

Mailbox Auditing and UAL Forwarding

Mailbox auditing enabled tenant-wide for all user and admin actions. Unified Audit Log configured for forwarding to SIEM or PULSAR. Every mailbox access, calendar sharing change, and permission modification becomes a searchable, retained event.

📊

Secure Score Baseline and Improvement Plan

Current Secure Score documented with every open recommendation classified: accept, remediate, or mitigate. A realistic 90-day improvement plan targets the highest-impact items within the existing E3 licence — no new spend required to close most gaps.

🛡️

Attack Surface Reduction Rules

ASR rules deployed via Intune in audit mode first, then staged to enforcement. Rules targeting Office macro abuse, credential theft from LSASS, and suspicious process creation — covering the most common malware execution paths without blocking legitimate business workflows.

📸

ASTRAL Baseline Capture

ASTRAL deployed to take a Git-tracked snapshot of the post-hardening configuration. Every subsequent change opens a pull request with a diff and an AI-generated narrative. The hardened state becomes the recoverable baseline — if anything drifts, you know immediately and can restore deterministically.

No New Licensing Required

The full scope of this module is deliverable on Microsoft 365 E3. We do not recommend upgrading to E5 as a condition of delivery. If E5 features would materially improve a specific control, we say so and explain the trade-off — but we do not use the engagement as a licence upsell.

Scope and Prerequisites

Duration30–60 days
EnvironmentM365 E3+
PrerequisitesGlobal Administrator access; Module 2 (Identity Security) completed or in parallel
Natural follow-onModule 4 (Data Governance) for sensitivity labels and DLP

Extract the security your licence already includes

Most E3 tenants leave the majority of their security value unconfigured. This module closes that gap systematically.