Practical guide · Baseline security
An alert nobody looks at protects nobody.
Microsoft Defender produces useful signals based on the licences already in place - but a signal with no owner and no reading cadence improves nothing. This guide separates routine maintenance from a genuine security review.
The decision to make
This guide helps decide which Defender checks belong in a reasonable monthly cadence, and at what point a signal becomes specialist work.
An alert nobody looks at protects nobody
A Defender alert only has value if a named person reviews it on a known cadence and knows what to do with it. The first task is assigning that responsibility, not adding more tools.
Mail remains the most common entry point
A baseline review confirms that everyday protections against phishing and malicious attachments are active and consistent with the licences held - without pretending to replace a complete security policy.
- Baseline settings are checked every cycle, not once a year
- Exceptions have a documented reason
- An unusual spike in alerts triggers a question, not silence
Devices flag problems before the user does
A regular look at device status - protection active, updates overdue - can catch a problem before it becomes an incident, without requiring a full security-operations-style watch.
What stays specialist work
Threat hunting, incident response, fine-tuning advanced policies, or a complete compliance review go beyond routine maintenance. An in-depth security review is a separate specialist engagement, for example with Secure M365, not an implicit part of monthly management.
A simple matrix for assigning the work.
| Situation | Owner | Cadence | Useful evidence |
|---|---|---|---|
| Routine alert triage | M365 owner | Agreed cadence | Logged entry per alert |
| Baseline setting check | M365 owner | Every review | Setting confirmed or corrected |
| Threat hunting or incident | Security specialist | Separate scope | Engagement report |
Decision checklist
What should be true before considering this area under control.
- A named person triages routine alerts
- Baseline mail protections are checked every cycle
- Device status is reviewed on a regular basis
- Exceptions to baseline settings are documented
- The boundary with an in-depth security review is clear to the team
Next step
See where secure defaults fit inside the monthly scope.
The service scope spells out what is maintained every month. Then use the assessment to see whether your current baseline has a clear owner.