What It Delivers
Exchange Online Protection Tuning
Anti-phishing, anti-malware, and anti-spam policies reviewed and tightened. DKIM, DMARC, and SPF validated. External sender tagging enabled. Auto-forwarding to external addresses blocked — one of the most reliable business email compromise persistence mechanisms.
Mailbox Auditing and UAL Forwarding
Mailbox auditing enabled tenant-wide for all user and admin actions. Unified Audit Log configured for forwarding to SIEM or PULSAR. Every mailbox access, calendar sharing change, and permission modification becomes a searchable, retained event.
Secure Score Baseline and Improvement Plan
Current Secure Score documented with every open recommendation classified: accept, remediate, or mitigate. A realistic 90-day improvement plan targets the highest-impact items within the existing E3 licence — no new spend required to close most gaps.
Attack Surface Reduction Rules
ASR rules deployed via Intune in audit mode first, then staged to enforcement. Rules targeting Office macro abuse, credential theft from LSASS, and suspicious process creation — covering the most common malware execution paths without blocking legitimate business workflows.
ASTRAL Baseline Capture
ASTRAL deployed to take a Git-tracked snapshot of the post-hardening configuration. Every subsequent change opens a pull request with a diff and an AI-generated narrative. The hardened state becomes the recoverable baseline — if anything drifts, you know immediately and can restore deterministically.
No New Licensing Required
The full scope of this module is deliverable on Microsoft 365 E3. We do not recommend upgrading to E5 as a condition of delivery. If E5 features would materially improve a specific control, we say so and explain the trade-off — but we do not use the engagement as a licence upsell.
Scope and Prerequisites
| Duration | 30–60 days |
| Environment | M365 E3+ |
| Prerequisites | Global Administrator access; Module 2 (Identity Security) completed or in parallel |
| Natural follow-on | Module 4 (Data Governance) for sensitivity labels and DLP |
Extract the security your licence already includes
Most E3 tenants leave the majority of their security value unconfigured. This module closes that gap systematically.