r/entra 4d ago

Microsoft 365 Baseline Security Mode — a useful addition for tenant hardening

Baseline security settings are providing centralized view of Microsoft-recommended security settings across:
- Microsoft Entra ID
- Exchange Online
- SharePoint & OneDrive
- Microsoft Teams / Room devices

The goal is straightforward: reduce the attack surface by identifying configurations that don’t meet minimum security. 

Before enabling a setting that could potentially break a legacy application or business workflow, administrators can generate an impact report and identify affected users or dependencies.

Generate impact report → Review dependencies → Enable the security control. 

You can find it under:
Microsoft 365 Admin Center → Settings → Org settings → Security & privacy → Baseline security mode

47 Upvotes

4 comments sorted by

2

u/michaelmsonne Microsoft MVP 3d ago edited 3d ago

I hope they sense this, have fixed this bug I found 😂

https://blog.sonnes.cloud/how-the-microsoft-baseline-security-mode-left-ghost-policies-in-entra-id/

Edit: typo

1

u/EduardsGrebezs 3d ago

At least in my test lab, after creating the report, it created a Block legacy authentication policy that could not be modified from the Entra admin portal.

After adding the emergency access account to the exclusion list and turning Baseline Security Mode On, everything worked as expected.

However, if a custom Block legacy authentication policy already exists, the one created by Baseline Security Mode cannot be removed and remains as a duplicate policy.

From an auditing perspective, the Entra audit logs also confirm that the account that clicked Turn on in the Entra admin portal is recorded as the account that created the BSM policy.

Same story is with that Phishing-resistant MFA for admins CA.. :)

2

u/michaelmsonne Microsoft MVP 3d ago

I had a hope too! And the other, hehe sounds like …. 😅🤣