North Ark
← All articles

Microsoft 365 · 5 July 2026 · 8 min read

M365 Conditional Access baseline: what insurers and clients actually check

Business Premium with defaults is not a security baseline. Before cyber insurance renewal or enterprise client diligence, fix MFA enforcement, admin separation, legacy auth, and logging — in that order.

Assessors and enterprise clients do not care that you bought Microsoft 365 Business Premium. They ask for enforced MFA, blocked legacy authentication, separated admin accounts, audit logging retention, and evidence backups restore — often with screenshots or policy exports.

FC-04 M365 Security Baseline delivers an email break-in risk review: identity, admin roles, MFA, Conditional Access gaps, and prioritised remediation order in five business days.

Conditional Access policies that matter first

Require MFA for all users — with exceptions documented and time-bound, not permanent.

Block legacy auth protocols. Require compliant or hybrid-joined devices for admin roles where feasible.

Geo and risky sign-in policies are secondary until MFA and legacy auth are solid.

Admin tiering and break-glass

Separate admin accounts from daily email. Fewer Global Admins. Privileged Identity Management for just-in-time elevation where licensing allows.

Document break-glass accounts, store credentials securely, and test recovery — insurers ask about this after incidents, not before.

Logging and backup evidence

Unified audit log retention, mailbox auditing, and SharePoint audit — know where logs go and who can read them.

Backup: know what is protected, restore tested in the last 12 months, and who owns recovery drills.

Before Copilot and before insurance renewal

Fix baseline before Copilot seats — FC-27 bundles FC-19 and FC-04 for teams buying AI and insurance at once.

See the M365 security Brisbane guide and book FC-04 from Microsoft packages.

Frequently asked questions

Is Business Premium enough for insurance?
Licence tier enables features — it does not configure them. Insurers want proof of enforcement: MFA coverage metrics, CA policies, backup restore tests, and incident contacts.
Can our MSP do the baseline review?
Many MSPs can — if they scope it as a project with deliverables, not a checkbox during onboarding. FC-04 is fixed price and independent when you need a second pair of eyes before renewal.
How does this relate to Essential Eight?
M365 baseline covers identity and email — ML1 ML2 overlap for MFA, patching on endpoints, and macro settings still need endpoint and application work. See Essential Eight Brisbane SMB guide for the full picture.

Next step

M365 Conditional Access baseline — ready to act?

M365 baseline — $2,490

Or book a free fit call