Skip to content

Practical guide · Baseline security

An alert nobody looks at protects nobody.

Microsoft Defender produces useful signals based on the licences already in place - but a signal with no owner and no reading cadence improves nothing. This guide separates routine maintenance from a genuine security review.

The decision to make

This guide helps decide which Defender checks belong in a reasonable monthly cadence, and at what point a signal becomes specialist work.

An alert nobody looks at protects nobody

A Defender alert only has value if a named person reviews it on a known cadence and knows what to do with it. The first task is assigning that responsibility, not adding more tools.

Mail remains the most common entry point

A baseline review confirms that everyday protections against phishing and malicious attachments are active and consistent with the licences held - without pretending to replace a complete security policy.

  • Baseline settings are checked every cycle, not once a year
  • Exceptions have a documented reason
  • An unusual spike in alerts triggers a question, not silence

Devices flag problems before the user does

A regular look at device status - protection active, updates overdue - can catch a problem before it becomes an incident, without requiring a full security-operations-style watch.

What stays specialist work

Threat hunting, incident response, fine-tuning advanced policies, or a complete compliance review go beyond routine maintenance. An in-depth security review is a separate specialist engagement, for example with Secure M365, not an implicit part of monthly management.

A simple matrix for assigning the work.

SituationOwnerCadenceUseful evidence
Routine alert triageM365 ownerAgreed cadenceLogged entry per alert
Baseline setting checkM365 ownerEvery reviewSetting confirmed or corrected
Threat hunting or incidentSecurity specialistSeparate scopeEngagement report

Decision checklist

What should be true before considering this area under control.

  • A named person triages routine alerts
  • Baseline mail protections are checked every cycle
  • Device status is reviewed on a regular basis
  • Exceptions to baseline settings are documented
  • The boundary with an in-depth security review is clear to the team

Next step

See where secure defaults fit inside the monthly scope.

The service scope spells out what is maintained every month. Then use the assessment to see whether your current baseline has a clear owner.

Let’s discuss ownership of your M365 tenant

Describe your team, what currently lacks an owner, and the outcome you need. No tenant access is required for this first conversation.

Direct email remains the simplest way to start. Use the public m365care.ca address with an already attributed subject.