Starter kit: Microsoft 365 + Intune + Entra
Microsoft 365 plus Intune plus Entra ID is one of the most common stacks a small OSC actually runs. This checklist maps native capabilities to practices they tend to touch, flags licensing dependencies, and names gaps the stack does not close by itself.
If you handle CUI in Microsoft cloud, you are usually in GCC or GCC High territory depending on data and contract constraints — confirm with counsel and your shared-responsibility documentation. Buying a government SKU does not configure Conditional Access for you.
Shared responsibility in one paragraph
Microsoft’s FedRAMP authorization and Customer Responsibility Matrix describe what you may inherit (for example, aspects of physical datacenter protection) versus what you must configure and operate (identity policies, logging review, training, incident response in your tenant). An MSP performing work in your tenant is almost always shared, not inherited: you still need evidence it is happening in your environment. Your authorizing official still owns the affirmation.
Capability → controls → example patterns
| Capability | Practices often touched | Platform example |
|---|---|---|
| Conditional Access + MFA | IA.L2-3.5.3 (network paths), IA.L2-3.5.2, AC.L2-3.1.1 | Device-claim VDI/SaaS, Enclave allow-list |
| Phishing-resistant / replay-resistant auth | IA.L2-3.5.3, IA.L2-3.5.4 | FIDO2 / certificate network access |
| Entra PIM / eligible admin | AC.L2-3.1.5, AC.L2-3.1.6, AC.L2-3.1.7 | JIT admin roles |
| Intune compliance + config baselines | CM.L2-3.4.1 / 3.4.2, AC device objectives | Intune baseline example |
| Purview labels + DLP | AC.L2-3.1.3 (CUI flow) | Labeled libraries + DLP |
| Unified audit → Sentinel / Log Analytics | AU.L2-3.3.1 and review objectives | AU create/retain, Event catalog review |
| Mobile App Protection / enrollment | AC mobile objectives | MDM-enrolled mobiles |
Licensing notes (do not silently assume P2 / G5)
- Privileged Identity Management and several Identity Governance features need Entra ID P2 (included in many G5 / E5 paths, not in bare G3/E3).
- Audit retention claims in the SSP must match what your SKU actually retains. Premium audit / longer retention is often a G5 or add-on story; otherwise plan export to Sentinel or immutable storage.
- Defender / Purview bundles differ between commercial and GCC High — map features before you write “we auto-label CUI” into the SSP.
- Role-based licensing (CUI handlers on premium SKUs, others elsewhere) only works if the enclave boundary enforces it.
Gaps this stack still needs help with
- Local privileged MFA — Conditional Access does not cover the rack. Plan PAWs, smart cards, Windows Hello for Business, or equivalent.
- FIPS-validated cryptography where the objective requires it — verify modules and configurations; do not assume “TLS in M365” closes every SC cryptographic objective on every component.
- Print / plotter / lab appliances — classic enclave leaks; isolate and document. See accepted-gap patterns in the AC examples.
- Vendor remote maintenance — brokered access, MFA, supervision, teardown. See Vendor remote sessions….
- Operational IR testing and risk assessment — tools do not attend tabletops for you (IR testing example).
- Security Protection Assets — the Entra tenant, Intune, SIEM, and ticketing system are usually in scope as SPAs even when they do not store CUI.
First-pass checklist for a small OSC
- Confirm cloud offering (GCC vs GCC High) and document CRM inheritance vs customer config in the SSP.
- Enforce phishing-resistant MFA for privileged and CUI network paths; close local privileged separately.
- Block legacy authentication; require compliant devices for enclave apps.
- Turn standing Global Admin into eligible PIM (or equivalent) with ticketed activation.
- Intune baseline + compliance grant wired into Conditional Access.
- CUI labels + DLP + sync/disabled download paths for enclave libraries.
- Audit pipeline with review tickets and retention that matches the SSP.
- SRM with MSP: who configures, who reviews, who speaks in the assessment.
- Tabletop dates on the calendar with after-action owners.
Disclaimer
Licensing and inheritance change; verify against current Microsoft CRM documentation and your contract. This starter kit is editorial guidance, not a certification guarantee.
Discussion(0)
No discussion on this article yet
Ask clarifying questions or share related assessment scenarios.
Sign in to start a thread.