Skip to main content
This lesson reviews how Microsoft 365 secures access to core services—Exchange Online, Microsoft Teams, SharePoint Online, and OneDrive—and how administrators manage these controls through the Microsoft 365 admin center. The focus here is on the security, identity, and compliance capabilities that protect users, devices, and corporate data.

Device management

Devices must be trusted before they access Microsoft 365 services. Device management covers how users connect from laptops, phones, tablets, and other endpoints and how organizations enforce security posture on those devices. Using Microsoft Intune with Microsoft Entra (formerly Azure AD), administrators can require device compliance before granting access. Typical compliance requirements include device encryption, current OS/security patches, and approved antivirus. Conditional Access can then grant different access levels based on device health and management state: compliant corporate devices receive full access, while unmanaged or risky devices are restricted or blocked. Protection of corporate data on personally owned devices is another key capability. Administrators can prevent business data from being copied to personal apps or cloud storage while preserving modern, mobile work scenarios.
A slide titled "Establishing Security, Identity, and Compliance Foundations" showing a diagram of approved devices and client apps connecting to Microsoft 365 services (Teams, Exchange, SharePoint, OneDrive). It also lists Device Access Management steps like enforcing device compliance, applying conditional access based on device health, and protecting corporate data on personal devices.
For example, employees may access Teams or Outlook from personal phones; device and app policies can block copying business data into personal apps or storage locations, enabling flexibility while maintaining corporate control.

Conditional Access: signal-based decisions

Conditional Access is Microsoft’s policy engine for making risk-based access decisions. Rather than relying solely on username and password, Conditional Access evaluates multiple real-time signals and enforces controls accordingly. Administrators target policies to users or groups and evaluate signals such as user identity, device compliance state, location, application being accessed, and sign-in risk. Actions include granting access, blocking access, requiring multi-factor authentication (MFA), or enforcing additional controls (for example, requiring a compliant device, an approved client app, or applying session restrictions). Common scenarios and examples:
  • Geo-fencing: make an internal app accessible only from a specific region.
  • Network restrictions: allow access only from specified corporate IP ranges.
  • Platform restrictions: permit Windows and macOS but block unsupported platforms.
  • Device-based access: require managed or compliant devices for full access.
Signals and policy actions at a glance:
A presentation slide titled "Establishing Security, Identity, and Compliance Foundations" showing a Signal → Decision → Enforcement diagram. The right side lists three conditional access controls: target policies to users/groups, evaluate sign‑in risk in real time, and control or monitor user sessions.
Microsoft collects telemetry—device attributes, IP addresses, locations, browsers, and sign-in patterns—to build a risk profile for each user. Deviations raise sign-in risk; Conditional Access evaluates that risk and applies the configured response (block, require MFA, or conditionally grant access). This approach balances security and productivity through intelligent, signal-based decisions.

Data protection and governance

Protecting and governing information across its lifecycle is a core part of Microsoft 365 compliance. Start with discovery and classification. Sensitivity labels categorize content (for example: Public, Internal, Confidential, Highly Sensitive). Labels can trigger protections automatically—such as encryption, watermarking, or external sharing restrictions. Data Loss Prevention (DLP) policies detect and prevent accidental or intentional leaks of sensitive information (credit card numbers, financial records, personal identifiers). DLP operates across Exchange, Teams, SharePoint, and OneDrive to stop risky sharing or to warn users in real time. Retention and information lifecycle policies let organizations retain data for regulatory or business needs and then dispose of it when appropriate. Key capabilities:
  • Discover and classify data with sensitivity labels.
  • Protect content automatically (encryption, sharing restrictions).
  • Prevent leaks with DLP across collaboration surfaces.
  • Apply retention and disposal policies to meet compliance requirements.
A presentation slide titled "Establishing Security, Identity, and Compliance Foundations" showing four green circles labeled "Know Your Data," "Prevent Data Loss," "Protect Your Data," and "Govern Your Data." To the right is a "Content Protection Strategies" list with three items: classify and protect data with sensitivity labels; prevent data leaks using DLP policies; and manage data retention and lifecycle policies.
Combining classification, protection, DLP, and retention enables organizations to identify, secure, and govern information while supporting legal and regulatory obligations.

Administration portals and Zero Trust

Microsoft exposes security and compliance features across several integrated admin portals that together implement the Zero Trust model—continual verification of every user, device, and request. Primary admin portals:
  • Microsoft Purview: compliance, data classification, DLP, retention, and compliance investigations.
  • Microsoft Entra admin center: identity platform—manage users, authentication, Conditional Access, and identity security.
  • Microsoft Intune: device and application lifecycle management—compliance policies, configuration, and monitoring.
Summary table: These portals collaborate under a Zero Trust approach: validate identity (Entra), verify device health (Intune), and protect data (Purview) for every access request.
A presentation slide titled "Establishing Security, Identity, and Compliance Foundations" with a diagram linking Identity (Microsoft Entra), Devices & Apps (Microsoft Intune), and Data (Microsoft Purview) unified by Zero Trust. The right side lists deployment and monitoring interfaces: manage compliance with Purview, manage identities via the Entra admin center, and monitor devices with Intune dashboards.

Best practices for deployment and ongoing management

Successful implementations require planning, testing, and continuous operations. Recommended approach:
  • Start with a pilot group to validate policies and collect feedback.
  • Use Microsoft’s recommended templates and configurations to accelerate deployment.
  • Phase rollout by workload and user group to minimize disruption.
  • Monitor audit logs, sign-in activity, compliance reports, and alerts continuously.
  • Periodically review and update policies to adapt to threats and business changes.
Begin with a small pilot group, validate policies, and iterate before broad deployment. Use Microsoft’s recommended templates to speed implementation while following best practices.
Be careful when creating Conditional Access rules: a misconfiguration can cause administrative lockout. Always test policies in scoped pilots and maintain emergency access accounts.
Avoid locking out administrators: exclude at least one emergency (break‑glass) account from restrictive Conditional Access policies and validate changes on a small scope first.
Ongoing monitoring and scheduled reviews are essential—security and compliance are continuous processes, not one-time projects.

Summary

Identity protection, device management, and data protection form the foundation of a secure, compliant Microsoft 365 environment. When implemented with careful testing, standardized deployment, and ongoing monitoring, these capabilities help organizations reduce risk while enabling productive work. For implementation details and step-by-step guidance, see the official documentation for Microsoft Entra, Microsoft Intune, and Microsoft Purview.

Watch Video