A meeting in a bright meeting room

Hardening a Microsoft 365 tenant including MacOS device management

Secure an M365 tenant to the CIS benchmark and manage MacOS devices under control.

A training company wanted to secure its Microsoft 365 tenant to recognized benchmarks and manage its MacOS devices under control. ODCUS implemented the hardening and the device management.

Starting point

The tenant was not hardened against a benchmark, and the MacOS devices ran without consistent policies.

Approach

  • Secured the Microsoft 365 tenant to the CIS benchmark
  • Implemented Zero-Trust measures via Conditional Access
  • Configured the Microsoft Defender suite (Endpoint, O365, Cloud Apps)
  • Set up Intune for MacOS: device configuration and compliance policies
  • Established onboarding policies for new devices

Result

  • A tenant hardened to the CIS benchmark
  • Conditional Access along Zero-Trust principles
  • Consistently managed, compliant MacOS devices
  • A repeatable onboarding process for new devices

Frameworks and tools used

Microsoft 365CIS BenchmarkIntuneConditional AccessDefender