Skip to content
ControlVerdict

Starter kit: Microsoft 365 + Intune + Entra

ControlVerdict Editorial · Aug 2, 2026A practical control-mapping checklist for small OSCs on Microsoft 365, Intune, and Entra ID — licensing gotchas, inheritance limits, and gaps that still need compensating controls.

Microsoft 365 plus Intune plus Entra ID is one of the most common stacks a small OSC actually runs. This checklist maps native capabilities to practices they tend to touch, flags licensing dependencies, and names gaps the stack does not close by itself.

If you handle CUI in Microsoft cloud, you are usually in GCC or GCC High territory depending on data and contract constraints — confirm with counsel and your shared-responsibility documentation. Buying a government SKU does not configure Conditional Access for you.

Shared responsibility in one paragraph

Microsoft’s FedRAMP authorization and Customer Responsibility Matrix describe what you may inherit (for example, aspects of physical datacenter protection) versus what you must configure and operate (identity policies, logging review, training, incident response in your tenant). An MSP performing work in your tenant is almost always shared, not inherited: you still need evidence it is happening in your environment. Your authorizing official still owns the affirmation.

Capability → controls → example patterns

Capability Practices often touched Platform example
Conditional Access + MFA IA.L2-3.5.3 (network paths), IA.L2-3.5.2, AC.L2-3.1.1 Device-claim VDI/SaaS, Enclave allow-list
Phishing-resistant / replay-resistant auth IA.L2-3.5.3, IA.L2-3.5.4 FIDO2 / certificate network access
Entra PIM / eligible admin AC.L2-3.1.5, AC.L2-3.1.6, AC.L2-3.1.7 JIT admin roles
Intune compliance + config baselines CM.L2-3.4.1 / 3.4.2, AC device objectives Intune baseline example
Purview labels + DLP AC.L2-3.1.3 (CUI flow) Labeled libraries + DLP
Unified audit → Sentinel / Log Analytics AU.L2-3.3.1 and review objectives AU create/retain, Event catalog review
Mobile App Protection / enrollment AC mobile objectives MDM-enrolled mobiles

Licensing notes (do not silently assume P2 / G5)

  • Privileged Identity Management and several Identity Governance features need Entra ID P2 (included in many G5 / E5 paths, not in bare G3/E3).
  • Audit retention claims in the SSP must match what your SKU actually retains. Premium audit / longer retention is often a G5 or add-on story; otherwise plan export to Sentinel or immutable storage.
  • Defender / Purview bundles differ between commercial and GCC High — map features before you write “we auto-label CUI” into the SSP.
  • Role-based licensing (CUI handlers on premium SKUs, others elsewhere) only works if the enclave boundary enforces it.

Gaps this stack still needs help with

  1. Local privileged MFA — Conditional Access does not cover the rack. Plan PAWs, smart cards, Windows Hello for Business, or equivalent.
  2. FIPS-validated cryptography where the objective requires it — verify modules and configurations; do not assume “TLS in M365” closes every SC cryptographic objective on every component.
  3. Print / plotter / lab appliances — classic enclave leaks; isolate and document. See accepted-gap patterns in the AC examples.
  4. Vendor remote maintenance — brokered access, MFA, supervision, teardown. See Vendor remote sessions….
  5. Operational IR testing and risk assessment — tools do not attend tabletops for you (IR testing example).
  6. Security Protection Assets — the Entra tenant, Intune, SIEM, and ticketing system are usually in scope as SPAs even when they do not store CUI.

First-pass checklist for a small OSC

  • Confirm cloud offering (GCC vs GCC High) and document CRM inheritance vs customer config in the SSP.
  • Enforce phishing-resistant MFA for privileged and CUI network paths; close local privileged separately.
  • Block legacy authentication; require compliant devices for enclave apps.
  • Turn standing Global Admin into eligible PIM (or equivalent) with ticketed activation.
  • Intune baseline + compliance grant wired into Conditional Access.
  • CUI labels + DLP + sync/disabled download paths for enclave libraries.
  • Audit pipeline with review tickets and retention that matches the SSP.
  • SRM with MSP: who configures, who reviews, who speaks in the assessment.
  • Tabletop dates on the calendar with after-action owners.

Disclaimer

Licensing and inheritance change; verify against current Microsoft CRM documentation and your contract. This starter kit is editorial guidance, not a certification guarantee.

Discussion(0)

No discussion on this article yet

Ask clarifying questions or share related assessment scenarios.

Sign in to start a thread.