Augmentt Blogs

Expert analysis and practical guides for navigating Microsoft 365 and the evolving world of cybersecurity. Your go-to hub for staying secure and efficient in the cloud.

Compliance used to be something MSPs worried about only when a healthcare or financial services client asked for it. That’s no longer the case. Cyber insurance carriers are demanding proof of security controls before they’ll issue or renew a policy. State privacy laws are spreading well beyond California. And clients in construction, manufacturing, and professional services are increasingly asking their MSP the same question: “Can you show me we’re secure?”

For MSPs, compliance frameworks aren’t just a checkbox for regulated clients anymore but are becoming the common language for proving security value across your entire book of business. The challenge is that there are a lot of frameworks, they overlap in confusing ways, and most MSPs don’t have a compliance officer on staff to sort it all out.

This post breaks down the compliance frameworks that matter most for MSPs and their clients, explains how they relate to one another, and shows where Augmentt fits into the picture, especially through its Microsoft 365 security posture and CIS benchmark reporting.

Why compliance frameworks matter for MSPs, not just their clients

A compliance framework is a structured set of security controls and best practices; things like requiring multi-factor authentication, encrypting data at rest, logging administrative activity, or restricting who can access sensitive systems. Frameworks exist so that a business (and its customers, regulators, or insurers) can point to a recognized standard and say, “we followed this.”

For an MSP, frameworks show up in three ways:

  1. Client requirements. A healthcare client needs HIPAA. A defense contractor needs CMMC. A software client’s enterprise customers demand SOC 2. If you manage their IT environment, you’re implicated in whether they pass an audit.
  2. Cyber insurance underwriting. Insurers increasingly use frameworks like the NIST Cybersecurity Framework or CIS Controls as the baseline for what they’ll ask about on an application, and what they’ll use to deny a claim if it wasn’t in place.
  3. Your own differentiation. MSPs that can speak fluently about compliance, and back it up with reporting, win more security-conscious deals and justify higher-margin security services.

The good news: most of these frameworks share a large common core of controls. You don’t need to master ten separate rulebooks — you need to understand the handful that come up most often and recognize how they overlap.

The frameworks MSPs run into most often

NIST Cybersecurity Framework (CSF)

The NIST CSF, maintained by the U.S. National Institute of Standards and Technology, is less a checklist than an organizing structure. Version 2.0 groups activities into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It’s voluntary and not industry-specific, which is exactly why it’s so widely adopted. It works as a common vocabulary that other frameworks (and many cyber insurance questionnaires) map back to.

For MSPs, NIST CSF is often the framework you use to structure a client’s overall security program, even if a more specific framework governs a particular compliance obligation.

CIS Controls and CIS Benchmarks

The Center for Internet Security (CIS) publishes two related things MSPs should know apart: the CIS Critical Security Controls, a prioritized list of 18 safeguards (things like inventory and control of assets, access control management, and continuous vulnerability management), and CIS Benchmarks, which are prescriptive, product-specific configuration guides, including one built specifically for Microsoft 365.

CIS Benchmarks are popular with MSPs because they’re actionable in a way broader frameworks aren’t. Instead of “protect access to systems,” a CIS Benchmark tells you the exact tenant setting to change. Because CIS controls are deliberately cross-mapped to NIST CSF, ISO 27001, PCI DSS, CMMC, HIPAA, and GDPR, hardening a client’s environment to the CIS Microsoft 365 Foundations Benchmark also moves the needle on most other frameworks a client might need.

This is where Augmentt is most directly useful. Augmentt’s security posture checks and MFA reporting are mapped to specific controls in the CIS Microsoft 365 Foundations Benchmark v2.0.0; things like identifying admin accounts without MFA, blocking legacy authentication, monitoring Microsoft Purview audit log status, enforcing idle session timeouts, and alerting on risky sign-ins or role changes outside of Privileged Identity Management. The Security Posture Report shows a Posture Score, flags each check as compliant, partially compliant, or not compliant, and lets you export a branded PDF for a client who doesn’t have Augmentt access, turning a compliance conversation into something you can show, not just describe.

HIPAA

The Health Insurance Portability and Accountability Act governs how healthcare providers, insurers, and their business associates (which can include an MSP) protect patient health information. HIPAA’s Security Rule requires administrative, physical, and technical safeguards; access controls, audit controls, encryption, and breach notification procedures among them.

If you support any healthcare client, you’re very likely a HIPAA “business associate,” which means you need a signed Business Associate Agreement and a genuine security program behind it, not just a promise. Many of the technical safeguards HIPAA requires (access control, audit logging, encryption of data in transit, session timeouts) overlap directly with the CIS Microsoft 365 controls Augmentt already monitors.

SOC 2

SOC 2 is an attestation, not a government regulation. A CPA firm audits a company against the AICPA’s Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy) and issues a report. SOC 2 matters to MSPs in two directions: clients in SaaS and professional services increasingly need a SOC 2 report to win their own enterprise customers, and MSPs themselves are sometimes asked by clients to prove their own SOC 2 compliance, since the MSP has privileged access to client systems.

Notably, Augmentt has undergone its own SOC 2 Type 2 audit as a vendor, giving its MSPs even more peace of mind.

CMMC (Cybersecurity Maturity Model Certification)

CMMC applies to companies in the Department of Defense supply chain, and it’s built on NIST SP 800-171. It has tiered levels of maturity, and unlike some frameworks, third-party or government assessment is required at the higher levels. If you have clients who are defense contractors or subcontractors, CMMC compliance isn’t optional, and the underlying controls (access control, audit and accountability, incident response, configuration management) again overlap heavily with what CIS-aligned Microsoft 365 hardening already covers.

PCI DSS

The Payment Card Industry Data Security Standard applies to any organization that stores, processes, or transmits cardholder data. It’s prescriptive about things like network segmentation, encryption, and access restrictions. MSPs supporting retail, hospitality, or e-commerce clients will run into PCI DSS regularly, particularly around securing the systems and email accounts that touch payment workflows.

ISO/IEC 27001

ISO 27001 is an international standard for information security management systems (ISMS). It’s less common among small and mid-sized MSP clients in North America than SOC 2, but it shows up often with clients that do business internationally or with enterprise customers overseas. Like the others, its control set (access control, cryptography, operations security) overlaps substantially with CIS and NIST.

GDPR and state privacy laws

The EU’s General Data Protection Regulation applies to any organization processing the personal data of EU residents, which catches more MSP clients than people expect, especially those with any European customers, employees, or web traffic. In the U.S., a growing patchwork of state privacy laws (California, Colorado, Virginia, and others) imposes similar obligations around data access, deletion rights, and breach notification. These aren’t security control frameworks in the same technical sense as NIST or CIS, but they create legal requirements around how quickly and thoroughly a client (and their MSP) can respond to a data request or breach, which is where good audit logging and access reporting (the kind Augmentt’s alerting provides) becomes evidence rather than just good practice.

How the frameworks relate to each other

The reason this list feels overwhelming at first is that most MSPs try to treat each framework as a separate project. In practice, the frameworks share a large overlapping core:

Access control and MFA enforcement appear in every single one of them, just under different names — NIST CSF calls it PR.AC, SOC 2 addresses it under CC6.1, HIPAA covers it in the Access Control standard, ISO 27001 handles it in Annex A.9, and CMMC maps it to the AC domain. The same is true of audit logging, encryption, and incident response.

That means the highest-leverage work an MSP can do is harden the common core — strong MFA, tight admin access, audit logging turned on, legacy authentication blocked, DLP and sharing policies configured correctly — and treat framework-specific requirements as the smaller layer on top. This is exactly the approach the CIS Microsoft 365 Foundations Benchmark takes, and it’s why it functions as a practical starting point regardless of which specific framework a given client ultimately needs to satisfy.

Where Augmentt fits

Augmentt isn’t a compliance certification body, and it won’t issue you a HIPAA or SOC 2 attestation. What it does is give MSPs continuous visibility into the Microsoft 365 security controls that sit underneath nearly every framework on this list:

  • Security posture checks mapped directly to the CIS Microsoft 365 Foundations Benchmark v2.0.0, covering MFA enforcement, legacy authentication, conditional access, Purview audit logging, mailbox auditing, DLP policies, Sharepoint and Teams sharing settings, and more.
  • The Security Posture Report, which scores a tenant’s compliance status (compliant, partially compliant, not compliant, resolved, or risk-accepted) against those checks, ties each item to its Microsoft Secure Score impact, and exports as a branded PDF for clients.
  • Alerting on risky sign-ins, role and permission changes, self-service password reset activity, and mail forwarding rule changes — the kind of continuous monitoring that HIPAA, SOC 2, and CMMC all expect to see in place, not just configured once and forgotten.
  • Scheduled reporting, so posture and compliance status can go out to clients automatically on a recurring cadence rather than requiring a manual pull before every QBR.

For an MSP juggling multiple clients with different compliance obligations, that combination — one dashboard mapped to a benchmark that overlaps with nearly every other framework, plus reporting you can hand to a client or auditor — turns compliance from a once-a-year scramble into an ongoing, demonstrable process.

Getting started

If you’re not sure where a given client stands, the fastest starting point is usually the same regardless of which framework they ultimately need to satisfy: run a CIS Microsoft 365 Foundations Benchmark assessment, close the highest-impact gaps (MFA, legacy auth, audit logging, admin role hygiene), and build reporting into your regular client cadence so compliance becomes a running conversation instead of a fire drill. From there, layer in the framework-specific requirements — a signed BAA for HIPAA clients, evidence collection for a SOC 2 audit, NIST 800-171 documentation for CMMC — on top of that hardened baseline.

Compliance will keep getting more complicated as more frameworks and state laws come online. But the underlying security work barely changes. Get the fundamentals right once, and you’re most of the way to satisfying whatever framework comes up next.

Want to check your own clients’ security posture? Try Augmentt for free!

Cover Photo by Jakub Żerdzicki on Unsplash

Microsoft 365 updates July 2026

July 2026 brings a lighter but no less consequential wave of Microsoft 365 changes: licensing finally catches up with the Copilot promotional push, Entra ships several identity-governance upgrades, and Purview starts locking down AI data flows at the network layer. A few items carry hard dates worth calendaring now.

Intune

Advanced Intune Capabilities Are Rolling Into Microsoft 365 E3 and E5

Microsoft is folding several Intune Suite capabilities directly into Microsoft 365 E3 and E5, no separate add-on required. E3 (via EMS E3) gains Remote Help, Advanced Analytics, and Intune Plan 2 (Microsoft Tunnel for MAM, specialty device management, FOTA updates). E5 adds Endpoint Privilege Management, Enterprise Application Management, and Microsoft Cloud PKI on top of that. Rollout is automatic and gradual, with a 30-day admin center notice before it lands in any given tenant. MSPs should revisit client licensing conversations now — capabilities you may have been quoting as a paid upsell are about to become “already included” for E3/E5 clients, which changes both your pricing story and your renewal risk.

Multi Admin Approval Now Enforces on API Calls Made by Automation

Multi Admin Approval (MAA) previously only gated interactive admin actions; it now also applies to Microsoft Graph API calls made by service principals, scripts, and third-party tools. If a tenant has MAA policies configured, automation lacking the required approval headers will start returning HTTP 403 errors. MSPs running RMM or custom Graph-based automation against MAA-enabled tenants need to update those scripts to the new approval workflow, or use the new Exclusions tab to carve out specific applications before this breaks a client’s automated workflows.

New Android Enterprise Setting Blocks Apps From Exposing Functions to AI Agents

A new settings catalog option, “Block apps from exposing app functions,” lets admins prevent managed apps on corporate-owned Android devices from exposing programmatic actions that on-device AI agents or assistants can invoke. As agentic AI features spread across mobile OSes, MSPs should treat this as a new baseline control worth adding to Android Enterprise configuration profiles, particularly for clients with regulated or sensitive data on managed devices.

Managed Win32 App Content Now Requires HTTPS Delivery

Intune now requires HTTPS for managed Win32 app content delivery. This mainly affects organizations using Microsoft Connected Cache without HTTPS configured on their cache nodes — those clients will silently fall back to CDN delivery, bypassing the cache and increasing internet bandwidth usage. MSPs managing Connected Cache deployments should audit cache node configuration now rather than waiting for a client to notice slower or costlier app deployments.

ChatGPT Added as a Protected App for Intune

ChatGPT is now available as a protected app under Intune’s app protection policy framework, meaning MAM controls (data cut/copy/paste restrictions, save-as blocks, etc.) can be applied to it like other managed apps. With generative AI tools spreading into client environments largely ungoverned, MSPs should treat this as an opportunity to bring at least one major GenAI consumer app under formal data-loss controls.

Entra ID

Microsoft Entra Backup and Recovery Reaches General Availability

Entra Backup and Recovery — daily, Microsoft-managed snapshots of core directory objects (users, groups, apps, service principals, Conditional Access policies, and more) — is now generally available, having been in preview as recently as last month. Tenants with Entra ID P1/P2 get one backup per day retained for 7 days, with diff reports and point-in-time restore. MSPs should formally add this to incident response runbooks now that it’s GA rather than treating it as an optional preview feature.

New Built-In “SOC Identity Responder” Role for Defender-Initiated Containment (Preview)

A new built-in Entra role lets SOC analysts perform identity containment actions — disabling users, revoking sessions, forcing password resets — triggered from Microsoft Defender, without being granted broad directory admin privileges. It supports role-assignable groups and optional PIM just-in-time activation. For MSPs running a SOC or MDR-style service across client tenants, this closes a real gap where analysts previously needed high-privilege roles just to act on an active incident.

AD Group Enforcement Prevents Drift Between Entra and On-Prem AD Groups (Preview)

For hybrid environments using group provisioning to Active Directory, admins can now designate specific AD groups so that changes are only accepted if made through the Entra provisioning service — direct edits made outside Entra are blocked. This is a meaningful control for MSPs managing hybrid identity, where AD group drift is a common source of access-review headaches and audit findings.

BYOD Support for Windows Client Using Entra Registration Reaches GA

Windows BYOD support via Entra-registered (not domain-joined) devices is now generally available, letting users and partners access corporate resources from personal Windows devices via the Private Application traffic profile, including internal guest users. MSPs supporting clients with contractor or BYOD-heavy workforces can now offer a fully supported non-domain-joined access path instead of workarounds.

Conditional Access Gains Dedicated Controls for AI Agent Accounts (Preview)

Conditional Access now supports targeting AI agents’ user accounts directly — scoping policies by custom security attributes, enforcing compliant-device requirements (including Windows 365 for Agents), and applying Agent Risk-based conditions. As agentic AI identities proliferate in client tenants, this gives MSPs a familiar policy framework to extend Zero Trust controls to non-human, agent-driven accounts rather than treating them as an unmanaged blind spot.

Defender

Codename MDASH Brings Multi-Agent Vulnerability Scanning to Private Preview

Codename MDASH orchestrates a panel of specialized AI agents to discover, validate, and help remediate vulnerabilities across complex environments, routing confirmed findings into Defender workflows and engineering pipelines. MSPs supporting clients with custom or proprietary applications should consider signing up for the private preview, particularly where traditional scanners have historically missed logic-level vulnerabilities.

Defender Expands Local AI Agent Discovery to 25+ Agent Types, Adds macOS Coverage (Preview)

Defender now discovers more than 25 types of local AI agents and MCP servers across managed Windows and macOS devices, and can block prompt-injection attempts against coding agents like GitHub Copilot CLI or Claude Code at runtime. This builds meaningfully on last month’s Windows-only preview. MSPs should reassess client environments for macOS-based developer or power-user endpoints that were previously blind spots for local AI agent risk.

Defender for Cloud Extends Database Threat Protection to AWS RDS Open-Source Databases (GA)

Built-in threat detection for anomalous access and brute-force attempts, plus automated sensitive-data discovery, now covers open-source relational databases on Amazon RDS. For MSPs with clients running multi-cloud or AWS-hosted workloads, this closes a coverage gap without requiring a separate AWS-native tool.

Defender for Cloud Multicloud Coverage Expands Across AWS and Google Cloud

Microsoft added roughly 90 new resource types and 200+ security recommendations to multicloud coverage in Defender for Cloud. MSPs managing security posture across AWS and GCP alongside Azure should refresh client posture assessments, since previously invisible resource types may now be generating new findings.

Licensing

Microsoft 365 Business with Copilot SKUs Are Now Generally Available

As of July 1, the previously promotional Business Standard with Copilot ($23.50/user/month) and Business Premium with Copilot ($32/user/month) are now permanent, standalone SKUs (300-license cap, annual billing). Two companion promos also went live: Business Basic + Copilot Business at $21/user/month (25% off through December 2026), and standalone Copilot Business at $18/user/month (15% off through December 2026). MSPs should update quoting tools now — every SMB renewal is a built-in, no-longer-time-boxed Copilot upsell.

New Licensing Prerequisite for Agent 365 Purchases

Effective June 1 and now formally documented for partners, new Agent 365 purchases require one of: Microsoft 365 E5/A5/Business Premium, or Defender Suite + Purview Suite (or their Edu/FLW equivalents). Microsoft 365 E7 customers are unaffected since E7 already bundles these. MSPs positioning Agent 365 should audit client licensing before the conversation goes further — customers without the prerequisite may hit capability gaps mid-deployment.

FY27 CSP Promotions for Microsoft 365 and Copilot Extended and Expanded

ME3 and ME5 promotions (10–20% off) are extended through September 30, 2026; ME7 promotions (10–15% off) run through December 31, 2026. New SMB-only Copilot promotions launched July 1: 15% off 1-year (300–999 licenses) and 30% off 1-year (1,000+ licenses), both through September 30. MSPs should prioritize accounts with existing E3/E5/Business investment and active Copilot pilots for expansion before these windows close.

New Windows 365 CSP Promotions Offer Up to 25% Off

Windows 365 Business gets 25% off through June 2027; Enterprise gets 20% off through September 30, 2026; Flex and Government get 20% off through June 2027. For MSPs selling Cloud PC alongside M365 management, this is a low-friction way to open cost-conscious client conversations.

Partner Code of Conduct Update Adds Anti-Corruption Remediation Requirements (Effective August 1)

Microsoft is adding a clause requiring partners to participate in anti-corruption and remediation programs when assigned, separate from standard compliance training. No immediate action is required, but MSPs should review the updated terms before the August 1 effective date.

Purview

DLP Can Now Inspect Text and AI Prompts at the Network Layer via Entra Global Secure Access (Preview)

A new DLP integration with Entra Global Secure Access intercepts and inspects text and AI interactions at the network layer — across browsers, apps, APIs, and add-ins — and can enforce DLP actions or feed Insider Risk Management based on risky activity. This is a notable escalation from app-level DLP: MSPs can now help clients prevent sensitive data from reaching untrusted generative AI platforms and social/collaboration tools regardless of which app or endpoint is being used.

Insider Risk Management Gets a Unified Alert Experience (Preview)

Classic and agent-triaged alerts now appear in a single alerts list, with agent summaries, alert details, and user details previewable inline. MSPs running insider risk programs for clients should expect a smoother triage workflow rather than switching between two dashboards.

Insider Risk Management Adds Expanded User Profile Signals (Preview)

The unified alert view now surfaces additional Entra-sourced user signals — office location, employee type, department, and last working date — directly alongside alerts. This gives MSP analysts faster context (e.g., is this a departing employee?) without pivoting to a separate HR or directory lookup.

Insider Risk Management Adds Notes on Alerts and Cases (Preview)

Analysts can now add and view notes on both alerts and cases, with system-generated notes automatically logged on status changes, reassignment, closure, or escalation. This creates a cleaner audit trail for MSPs that need to document investigative reasoning for client reporting or compliance purposes.

Teams

Teams Now Flags Automated Participants in Meetings

Teams can now help identify automated participants — bots, AI note-takers, and similar automated join tools — in meetings, giving organizers and admins more visibility into who or what is actually present. As AI meeting assistants proliferate across client organizations, MSPs should treat this as a useful visibility layer for clients concerned about unauthorized recording or data-capture tools joining sensitive meetings; it surfaces what’s present rather than blocking it outright.

Users Can Now Report and Block Suspicious Calls Directly in Teams

Teams now lets users flag a suspicious call and optionally block the caller directly from the call interface, feeding into Microsoft’s broader fraud and impersonation protections. MSPs supporting clients on Teams Phone should make sure end users know this option exists — it’s a low-effort way to crowdsource fraud signal with no admin configuration required.

Image Sharing Now Preserves OneDrive/SharePoint Permissions

Quick share for images now preserves file-level permissions when the image lives in OneDrive or SharePoint, so recipients only get access if they’re already entitled to it — though images pasted directly into chat don’t carry that same permission enforcement. MSPs advising clients on data-sharing hygiene should flag the paste-vs-share distinction, since it’s an easy way for permissions to quietly not apply the way an end user assumes.

Copilot

Copilot Chat in Outlook Expands to Reason Over Full Inbox, Calendar, and Enterprise Data — No Copilot License Required

Copilot Chat in Outlook is expanding from single-thread reasoning to reasoning across a user’s entire inbox, calendar, meetings, and other Microsoft 365 data they already have access to — and this applies even without a Microsoft 365 Copilot license. This is a meaningful expansion of what an “unlicensed” AI feature can see and use. MSPs should review Copilot Chat governance and data access policies now, since the scope of what this free-tier feature can surface just grew substantially.

Copilot-Generated Files Automatically Inherit Sensitivity Labels

When Microsoft 365 Copilot generates a file, it now automatically applies the highest sensitivity label found in the source data used to create it — and notifies the user if it can’t determine an appropriate label. This closes a real data-governance gap where AI-generated output previously had no automatic protection inheritance. MSPs should confirm sensitivity label policies are actually configured for clients using Copilot generation features, since this control only helps if labels exist to inherit.

Admins Can Now Edit Permission Handling on Existing ServiceNow Copilot Connectors

Admins previously had to recreate ServiceNow Knowledge and Catalog connector configurations to adopt hierarchical permissions; they can now edit existing connections directly to switch between Simple and Advanced permission handling. MSPs managing ServiceNow-integrated Copilot deployments can now tighten permission models without a disruptive rebuild.

Watermarking Policy Now Available for AI-Generated Video and Audio

A new Cloud Policy service setting lets admins turn on visual or audio watermarks for AI-generated or AI-altered video and audio content in Microsoft 365 (image watermarking remains a separate, user-controlled setting). MSPs advising clients in regulated or reputation-sensitive industries should evaluate turning this on as a low-cost transparency control.

Outlook

No updates worth noting this month.

OneDrive & SharePoint

SharePoint Server Subscription Edition Security Update Ships With 26H1 Feature Update (KB5002873)

The June 9, 2026 cumulative update for SharePoint Server Subscription Edition (build 16.0.19725.20384) patches a large batch of CVEs, including remote code execution and spoofing vulnerabilities, and introduces the SharePoint Server Subscription Edition 26H1 feature update as a baseline for all future public updates. MSPs managing on-premises SharePoint farms should schedule patching now — this replaces the prior KB5002863 update and closes several actively-tracked CVEs. No OneDrive-specific updates were published this period.


July’s list is shorter than June’s, but the shape of the changes matters more than the count: licensing is catching up to the AI push Microsoft has been driving all year, Entra and Purview are both extending governance to AI agents and AI data flows rather than just user identities and user data, and several previews from last month (Entra Backup and Recovery, local AI agent discovery) have already matured toward GA. For MSPs, the through-line is the same one from last month — the AI surface area in Microsoft 365 keeps growing, and the compliance and access-control tooling around it is being built in near-real-time alongside it.

Cover Photo by Christian Wiediger on Unsplash

person using computer

Every new client onboard starts the same way: a senior technician logs into Partner Center, then Entra, then Defender, then Intune, rebuilding the same policies they built last week for a different client. Four hours later, the tenant is configured, but the security projects that were supposed to get done this quarter got bumped again.

MSPs automate Microsoft 365 onboarding by replacing that portal-hopping with templated workflows that push a security baseline to a new tenant in minutes instead of hours. This article covers the full process, from tenant connection through drift monitoring, and shows where automation delivers leverage and where human judgment still matters.

What M365 onboarding includes for an MSP

MSPs automate Microsoft 365 onboarding by connecting identity workflows, security baseline templates, and multi-tenant management platforms into a single repeatable process. When a new client signs, the MSP connects to the tenant through Partner Center, runs an audit against a predefined baseline, and pushes Conditional Access, Defender, and Intune policies in one deployment. The work that used to require logging into four or five admin portals now happens from one dashboard.

M365 onboarding in the MSP context actually covers two distinct workflows that often get lumped together. Client onboarding is the initial setup of a new tenant relationship, including GDAP configuration, baseline deployment, and documentation. User provisioning is the ongoing work of adding and removing individual users after the client is already live.

A complete client onboarding typically includes:

  • Tenant connection: Partner Center setup, GDAP roles, and admin consent
  • Environment audit: Comparing current state to the MSP’s security standard
  • Security baseline deployment: Conditional Access policies, Defender settings, Intune enrollment configuration
  • User provisioning setup: License assignment rules, group templates, mailbox and Teams defaults
  • Documentation and handoff: Recording what was deployed and who owns ongoing management

Why manual M365 onboarding breaks at scale

The operational ceiling hits faster than most MSPs expect. When every onboard requires a senior technician to log into Entra, then Defender, then Intune, then Partner Center, the math stops working somewhere around 30 to 40 clients. At that point, growth becomes a headcount problem instead of a process problem.

Senior technician hours spent on L1 work

Portal-hopping across Microsoft admin centers eats senior time on work that could be templated. A single client onboard can take four to six hours of senior technician time when done manually. That time comes directly out of project work, escalations, and the security improvements that keep getting bumped because break-fix jumped the queue again.

Inconsistent baselines across client tenants

Without a standard, each technician builds configurations differently. One tech enables MFA with a 14-day grace period, another sets it to immediate enforcement, and a third forgets to exclude the break-glass account. Six months later, the MSP has 40 tenants with 40 slightly different security postures, and no easy way to know which is which.

Security gaps that surface after go-live

Skipped steps during manual onboarding create vulnerabilities that only appear later. A missed Conditional Access policy or an incomplete Defender configuration becomes a client call three months down the road. Without an audit trail, there is no way to know what was actually deployed versus what was supposed to be deployed.

Onboarding capacity capped by headcount

Manual onboarding ties growth directly to hiring. If each onboard takes a senior tech six hours, and the senior tech has 30 available hours per week for project work, the MSP can onboard roughly five clients per week at maximum capacity. Automation changes that ratio entirely.

What can be automated in M365 onboarding and what still needs a human

Not everything in onboarding is automatable, and setting realistic expectations upfront prevents frustration later. The technical deployment work automates well. The scoping conversations and exception handling still require human judgment.

Can be automatedStill needs a human
Security baseline deploymentScoping and success criteria
License and group assignmentException handling for custom client needs
Policy push to Entra, Defender, IntuneClient communication and kickoff
Environment audit against baselineValidating exceptions and sign-off
Drift detection post-onboardingEscalation and remediation decisions

The goal is not to remove humans from the process. The goal is to remove humans from the repetitive parts so they can focus on the parts that actually require judgment.

How to automate M365 client onboarding step by step

The workflow below covers the full onboarding process from signed contract to go-live. Each step identifies what gets automated and what the technician still handles manually.

Step 1. Confirm scope, licensing, and success criteria

Automation starts with clean inputs. The technician confirms which M365 licenses the client has, what is in scope for the engagement, and what success looks like. Business Premium or equivalent licensing is typically required for the security features that deliver ROI. This step is human work, and skipping it creates problems downstream.

Step 2. Connect the tenant through Partner Center

GDAP setup and tenant connection happen through Partner Center. GDAP, or Granular Delegated Admin Privileges, is Microsoft’s model for giving MSPs access to client tenants with specific role assignments rather than full admin rights.

Some platforms automate the invitation workflow and role assignment, reducing the manual steps from a dozen clicks to a single action. The technician still verifies the connection completed correctly before moving on.

Step 3. Audit the existing environment against a baseline

The platform scans the tenant and compares it to the MSP’s security baseline. The output is a gap report showing what policies exist, what is missing, and what conflicts with the standard. This audit takes minutes instead of the hour or more required to check each setting manually across multiple admin portals.

Step 4. Deploy the security baseline across Entra, Defender, and Intune

This is where automation delivers the most leverage. Platforms like Augmentt let the MSP build a baseline once and deploy it to a new client in minutes. Junior technicians can run the deployment through a prompted workflow without senior oversight on every step, because the platform guides them through the process and prevents configuration errors.

Step 5. Validate the deployment and document exceptions

After deployment, the technician confirms policies applied correctly and documents any client-specific exceptions. Some clients have legacy applications that require Conditional Access exclusions, or specific compliance requirements that modify the standard baseline. Those exceptions get logged for audit and future reference.

Step 6. Hand off to drift monitoring and reporting

The onboarded tenant moves into ongoing management. Drift detection watches for policy changes and flags them before they become client calls. Reporting captures what was deployed for QBRs and compliance documentation. The onboarding is complete, but the monitoring continues.

How to automate M365 user provisioning and offboarding

User provisioning is a separate workflow from client onboarding, though the two often get bundled together in conversation. Once the client is live, adding and removing users becomes a repeatable process that benefits from templating.

Identity and license assignment

Entra ID user creation and license assignment can be automated based on role or group membership. When a new hire is logged in the client’s HR system or submitted through a form, the workflow creates the account and assigns the appropriate license without manual intervention. The technician does not touch the admin portal for routine user adds.

Group, policy, and Conditional Access placement

Users get placed into security groups automatically based on templates. A new sales hire goes into the sales group, which inherits the appropriate Conditional Access policies and application access. The logic is defined once and applied consistently, rather than configured individually for each user.

Mailbox, SharePoint, and Teams configuration

Collaboration tools provision alongside the user account. Mailbox setup, SharePoint permissions, and Teams membership follow the same template logic. The user has access to the right resources on day one without a technician manually configuring each service.

Endpoint enrollment through Intune

Device enrollment and compliance policy assignment can be automated for new users. When the user signs into their device, Intune enrollment triggers automatically and applies the appropriate compliance policies. The device is managed from the moment it connects.

Why multi-tenant architecture beats a golden tenant workaround

Some tools require a golden tenant or master account to push policies across client environments. A golden tenant is a reference environment where the MSP configures all their standard policies, then copies or syncs those policies to client tenants. This workaround creates maintenance overhead and breaks when Microsoft updates admin portals or changes how policies are structured.

True multi-tenant architecture works differently. The MSP manages every tenant independently with consistent configuration, but without a reference tenant to maintain. There are no scripts to update when Microsoft changes something, and no workaround to rebuild every few months.

  • Golden tenant approach: Requires a reference tenant, policies copied manually or via scripts, breaks when Microsoft updates admin portals
  • True multi-tenant architecture: Every tenant managed independently, baseline applied directly, platform handles Microsoft changes

Augmentt is built for true multi-tenant delivery. Every engineer on the team can work in any client environment with consistent configuration, and the platform keeps up with Microsoft when it changes something rather than requiring the MSP to rebuild their process.

Why Microsoft Lighthouse and Partner Center fall short for automated onboarding

Lighthouse and Partner Center provide visibility across tenants, but visibility is not automation. MSPs still log into each tenant to configure policies, and there is no baseline templating or deployment workflow built in.

The limitations become apparent quickly:

  • No baseline templating or deployment automation
  • No drift detection or auto-remediation
  • Limited alerting and no client-facing reporting
  • Manual work required in each tenant for policy configuration

For MSPs managing 500 or more seats across their client base, the native tools become a bottleneck rather than a solution. Lighthouse shows what exists, but it does not help deploy or maintain a consistent standard.

How to delegate M365 onboarding to L1 and L2 technicians

Automation enables delegation. When onboarding is templated and prompted, junior technicians can run the process without senior oversight on every step. The senior technician’s time goes to work that actually requires their expertise, like exception handling and escalations.

Effective delegation requires a few things to be in place:

  • Templated workflows: Junior techs follow prompted steps, not custom builds
  • Guardrails: Platform prevents configuration errors before they happen
  • Least-privilege access: Techs only see and touch what they need for the task
  • Audit trail: Every action logged for review by senior staff

Augmentt’s L1/L2 delegation capabilities let MSPs scale their onboarding capacity without scaling senior headcount. The junior tech runs the deployment, the platform prevents mistakes, and the senior tech reviews the output rather than doing the work themselves.

How to keep the M365 baseline consistent after go-live

Onboarding is not the end. The baseline drifts over time as users, admins, and Microsoft make changes. A client admin disables a Conditional Access policy to troubleshoot a login issue and forgets to re-enable it. Microsoft updates a default setting. A user gets added to the wrong group. Maintaining consistency requires ongoing monitoring.

Drift detection against the deployed baseline

The platform monitors for policy changes and flags drift before it becomes a client call. When a Conditional Access policy gets modified or disabled, the alert includes the details and the remediation action in the same view. The technician knows what changed and what to do about it without digging through logs.

Auto-remediation for common policy changes

Defined alert types can be handled automatically. The environment is protected before the team sees the alert. Overnight changes do not become morning triage, because the platform already reverted the unauthorized modification.

Client-facing reports that prove the work

QBR-ready reports show what was deployed, what drifted, and what was remediated. Augmentt generates branded, schedulable reports as a byproduct of the platform’s work. The report goes out with the bill, and the client sees exactly what the MSP caught and fixed.

See how Augmentt handles baseline deployment, drift detection, and client reporting from one dashboard →

Frequently asked questions about automating M365 onboarding

How long does an automated M365 client onboarding take?

Automated baseline deployment can reduce the technical work from hours to minutes. Total time depends on scoping, exception handling, and validation, which still require human time. The deployment itself is fast; the conversations around it take longer.

Can an MSP automate M365 onboarding without using a golden tenant?

Yes. Platforms with true multi-tenant architecture deploy baselines directly to each client tenant without a golden tenant or master account workaround. The baseline is defined in the platform and applied to each tenant independently.

Does Microsoft Lighthouse automate M365 onboarding for MSPs?

Lighthouse provides visibility across tenants but does not automate baseline deployment, drift detection, or client-facing reporting. MSPs still need a separate platform for full onboarding automation.

Can L1 technicians safely run an automated M365 onboarding?

With templated workflows and guardrails, L1 techs can execute onboarding without senior oversight on every step. The platform prevents configuration errors and logs every action for review. The senior tech reviews the output rather than doing the work.

Cover Photo by Lush Kooch on Unsplash

MSPs standardize device security in Microsoft Intune, then spend their time keeping every client tenant in line as Microsoft changes settings, clients add devices, and compliance requirements shift. Augmentt already handled the core of that: configuration, compliance, and deployment profiles, built once and applied per tenant, edited inline without logging into each customer portal.

This release goes further. Here is what is new and what it means for your team.

Deploy apps and scripts across tenants

Most MSPs have a standard stack, a set of approved applications and scripts they deploy to every client environment. In a single-tenant world, that means logging into each portal, finding the right policy, and pushing the deployment manually. Multiply that by the number of clients you support and it becomes one of those tasks that consumes technician hours without adding any visible value to the client or the business.

With this release, the apps and scripts you have packaged can now be deployed across your client tenants directly from Augmentt. You set it up once and push it where it needs to go, without switching between portals. For MSPs managing more tenants than their team can realistically touch by hand, this is the kind of operation that should have always worked this way.

Manage iOS MDM policies across tenants

iOS device management is increasingly part of the conversation with clients, especially those with field teams, executives on iPhones, or any environment where mobile devices touch business data. The problem MSPs run into is the same one they face with every other Intune configuration: policies have to be set per tenant, which means the work scales with the number of clients you have rather than the quality of your process.

iOS MDM policies are now managed in Augmentt alongside your Windows configuration work. You set your policies up once, apply them per tenant, and edit them inline when something needs to change. Mobile device management no longer lives in a separate workflow from the rest of your Intune work, which sounds like a small thing until you are trying to push a policy change across thirty client environments before the end of the day.

Patch management through our Robopack partnership

Patch management is one of the clearest value propositions an MSP can sell. Clients want to know their devices are up to date, and you want to be able to prove it without it consuming your team. The challenge is that doing it well requires reliable packaging and deployment, which is where a lot of in-house patch workflows break down and where the manual cleanup starts.

Through our partnership with Robopack, patch management is now available in Augmentt. Robopack handles application packaging at a level that takes the fragility out of the process, and it is accessible from the same console where you manage the rest of your Intune environment. More of what you run in Intune, including keeping devices current, is handled without leaving the platform.

Device compliance visibility across every tenant

One of the persistent frustrations of managing Intune across multiple clients is that compliance alerts live in each tenant’s portal. If a device falls out of compliance, you find out when you happen to be in that portal, or when the client tells you. Neither is a great position to be in when your pitch to clients is that you are managing their security proactively.

Microsoft’s device-compliance alerts are now surfaced for all your client tenants in a single view inside Augmentt. You see the full compliance picture across your book of business without checking portals one by one, which makes it a lot easier to catch issues before clients do and to report on device health in a way that actually means something to the people paying for the service.

Taken together, more of what MSPs do in Intune on a daily basis is now handled from one console. If you want to see it in action, try it for free today!

June 2026 brings a dense wave of Microsoft 365 changes across identity, security, licensing, and AI, several of which require MSP action before deadlines hit.

Intune

Hotpatching Enabled by Default Starting May 2026 Security Update

Windows Autopatch now enables hotpatch updates by default for all eligible devices, reducing the number of restarts required during patch deployment. If your clients aren’t ready for hotpatching, you need to opt out at the tenant or policy level proactively; waiting means it activates automatically across all eligible managed devices.

Windows 11 25H2 Security Baseline Now Available

The updated security baseline for Windows 11 version 25H2 is available in Intune, bringing new settings, updated defaults, and retired settings. Existing baseline profiles do not auto-update, so you must manually create or migrate profiles to the new baseline and review every setting change before pushing to client devices.

Microsoft Edge v139 Security Baseline Released

An updated Edge security baseline with new settings and revised defaults is now available in Intune. Like the Windows baseline, existing Edge profiles require a manual update — test in a pilot group before broad deployment to avoid breaking browser configurations across client tenants.

Platform SSO During macOS ADE Now Supported

macOS devices enrolled via Automated Device Enrollment can now complete Platform SSO registration during the setup flow, giving users immediate Entra ID resource access at first desktop login. This requires specific prerequisites: a settings catalog policy, Company Portal 5.2604.0 or later, a configured ADE policy, and macOS 26 or later. MSPs deploying new Mac fleets should update enrollment profiles now to take advantage of this.

Intune RBAC Roles Now Inherit Copilot in Intune Access Automatically

All built-in and custom Intune RBAC roles now automatically receive Security Copilot contributor access when Intune is enabled as a Copilot data source, no separate role assignments needed. MSPs should review whether this expanded access aligns with the least-privilege model in place for client tenants, since it applies to custom roles as well.

Entra ID

Microsoft Entra Connect Sync to Cloud Sync Migration Announced — Phased Starting July 2026

Microsoft will begin notifying customers via M365 Message Center and Entra Connect Health of their transition timelines from Connect Sync to Cloud Sync starting July 2026. MSPs managing hybrid identity environments need to assess client readiness now, identify configurations not yet supported by Cloud Sync, and start migration planning before assigned transition windows arrive.

Hard Match Blocked for Users with Entra Roles — Effective June 1, 2026

Entra Connect Sync and Cloud Sync can no longer hard-match a new AD object to an existing cloud user that holds Entra ID roles, effective June 1. This is a breaking change for any migration or re-sync scenario involving privileged cloud accounts. Audit hybrid environments for affected users immediately and use the new Graph API recovery path if hard-match errors occur.

Entra Backup and Recovery Now in Public Preview

Built-in daily snapshots of critical directory objects (users, groups, apps, Conditional Access policies, and more) are now available in public preview with 5-day retention and admin-initiated restore capability. This gives MSPs a native safety net for accidental tenant configuration changes; familiarize yourself with the restore workflow and add it to your incident response runbooks.

SAP SuccessFactors Provisioning Must Migrate from Basic Auth by November 2026

Workload identity-based authentication for SAP SuccessFactors provisioning is now in public preview, with basic auth deprecation set for November 2026. MSPs managing SuccessFactors provisioning integrations need to plan and execute migration to workload identity auth before the deadline to avoid provisioning failures.

Sensitivity Labels Now Supported on Entra Security Groups (Preview)

Microsoft Purview sensitivity labels can now be applied to Entra cloud security groups to govern settings like guest access. MSPs managing group-based access controls should evaluate whether existing label policies need updating to cover this new scope.

Defender

Local AI Agent Discovery and Runtime Protection on Windows Endpoints (Preview)

Defender now automatically discovers local AI agents — coding agents, IDE extensions, desktop AI assistants — on onboarded Windows devices and can block risky activity in the agent loop at runtime. Before broad enforcement, MSPs should assess whether any legitimate local AI tools used by client employees will generate alerts and tune accordingly.

Automatic Attack Disruption Can Now Isolate Compromised Devices (Preview)

High-confidence incident analysis can now trigger automatic network isolation of devices identified as active attacker footholds, with time-limited scope and operator release capability. This is a significant operational change. MSPs must ensure clients understand that devices may be isolated without manual intervention, and SOC runbooks need to account for this response action.

Identity Security Dashboard and Risk Score Now in Preview

A new Identity Security dashboard surfaces identity provider coverage, non-human identities, and a 0–100 risk score per identity that can be used directly in Conditional Access policies. This gives MSPs a consolidated identity risk view across human and non-human identities; evaluate the risk score integration with Conditional Access for clients where risk-based policy enforcement makes sense.

AgentsInfo Table Replaces AIAgentsInfo in Advanced Hunting — Deadline July 1, 2026

The new unified AgentsInfo table covers all agent types; the AIAgentsInfo table retires July 1, 2026. Any custom detection rules, hunting queries, or automation referencing AIAgentsInfo must be updated before that date to avoid query failures.

Built-in Alert Tuning Rules Now Generally Available

Suppression rules for common benign activity in Defender for Endpoint and Defender for Office 365 are now GA, without affecting AIR investigations. MSPs managing high-alert-volume tenants should review which rules are active and confirm they align with client security posture before relying on suppression.

Licensing

Microsoft 365 Business Standard with Copilot and Business Premium with Copilot Become Permanent SKUs July 1, 2026

The promotional offers for M365 Business Standard with Copilot and Business Premium with Copilot transition to permanent subscriptions at $23.50 and $32 USD per user/month respectively, with new SKUs available July 1 and price list preview in Partner Center starting June 1. Update quoting tools, renewal motions, and SMB offer packaging now. Every Business Standard and Premium renewal is a built-in Copilot upsell opportunity with stable, predictable pricing.

Agent 365 Now Requires Microsoft 365 E5 as Licensing Prerequisite (Effective June 1)

New Agent 365 purchases now require M365 E5 for enterprise, F5-level Defender and Purview for frontline workers, and M365 Business Premium for SMB customers. Audit client licensing before positioning Agent 365. Clients without the prerequisite licenses will lack access to certain capabilities, which creates risk of failed deployments or uncomfortable upsell conversations mid-engagement.

Work IQ API Reaches GA June 16 with Consumption-Based Copilot Credits Billing

Work IQ API is generally available June 16; custom agents using Work IQ via Copilot Studio, Foundry, or third-party platforms are billed via Copilot Credits. Admins must enable consumptive billing before use. MSPs building or managing custom AI agents need to ensure client admins configure payment methods, access policies, and spend limits in the M365 Admin Center before June 16 to avoid service interruption or uncontrolled spend.

EEA Currency Pricing Precision Updates for Select M365/O365 SKUs Effective July 1

Minor cent-level price adjustments are coming to M365 and O365 SKUs in EUR, DKK, NOK, SEK, and CHF for EU settlement compliance, effective July 1. The amounts are small, but discrepancies in automated billing systems should be corrected proactively to avoid invoice inaccuracies for clients billed in EEA currencies.

Dynamics 365 Business Central Dual Use Rights License Keys Must Be Refreshed Every Six Months

Effective June 5, on-premises Business Central deployments via Dual Use Rights require license key download and replacement every six months. MSPs managing Business Central on-premises deployments must establish a recurring process to download and apply updated DUR license keys to prevent service interruption.

Purview

Data Security Posture Management (DSPM) New Version Now Generally Available

The updated DSPM with guided workflows for proactive risk management is now GA; partner solutions for non-Microsoft sources and the Data Security Posture Agent remain in preview. MSPs advising clients on data security governance should update deployment guidance and assess whether clients need the GA version’s administrative unit support for scoped administration.

DLP Policy Device Scoping Now Available

Endpoint DLP policies can now be scoped to specific device groups (for example, enforcing a policy only on Windows devices for Finance users, not macOS) using dynamic Entra ID device groups. MSPs should review existing Endpoint DLP policies to determine whether device-scoped rules would reduce false positives or improve coverage for clients with mixed-OS environments.

Anthropic Claude Enterprise Now Supported in DSPM (Preview)

Claude interactions can now be monitored alongside Copilot, ChatGPT Enterprise, and other AI apps in DSPM activity explorer. MSPs should configure the Anthropic Claude connector for clients with Claude Enterprise deployments so AI interaction visibility and data security controls apply consistently.

eDiscovery Review Set Limit Increased from 20 to 100

The maximum number of review sets per eDiscovery case has been raised from 20 to 100. MSPs supporting legal or compliance teams running large investigations no longer need to work around the previous limit by managing case sprawl; update client guidance accordingly.

Sensitivity Label Auto-Labeling Can Now Override Manually Applied Labels (GA)

Auto-labeling policies for SharePoint and OneDrive can now be configured to always override lower-priority labels, even if manually applied, a capability previously limited to email. This is a behavior change that could override user-applied labels on files; MSPs must review auto-labeling policy configurations for clients to confirm the override option is intentionally set and that users are informed.

Teams

Copilot Call Delegation Rolling Out to Frontier in June

Copilot can now answer incoming Teams Phone calls on a user’s behalf, capture intent, and schedule follow-ups via Microsoft Bookings when the user is unavailable. This feature requires Teams Phone licensing and may trigger questions about call recording consent and data retention. Review client policies before enabling.

Scam and Impersonation Detection Now Live

Teams now detects when callers may be impersonating trusted brands (banks, IT admins) and warns users with options to decline, leave, or report. This is a default-on security control that requires no configuration; MSPs should communicate it to clients as a meaningful reduction in social engineering risk.

Video Recap for Recorded Meetings

AI-generated narrated highlight reels are now available for recorded Teams meetings, surfacing key moments without requiring full playback. This feature uses meeting recordings and transcripts, so MSPs should confirm clients have appropriate retention and compliance policies in place for AI-generated recap content.

Recap Deletion Now Available Without Admin Setup

Meeting organizers can now permanently delete recordings, transcripts, AI summaries, and notes from the recap page via a single menu action, no admin configuration required. This self-service deletion capability may conflict with client retention policies; MSPs should verify that retention labels or compliance holds are in place to prevent premature deletion.

Mobile Queues App Now Available

The Teams Queues app for collaborative call queue management is now available on Teams mobile for iOS and Android. MSPs should validate that mobile device policies permit the app and that queue agent permissions are correctly scoped before clients start using it in the field.

Copilot

ISO/IEC 42001 Certification Expanded Across Copilot Portfolio

Microsoft has extended ISO 42001 AI management certification to Copilot Studio, GitHub Copilot, Dragon Copilot, and Copilot Health, adding to existing certifications for M365 Copilot, Security Copilot, and Microsoft Foundry. Clients in regulated industries requiring AI governance documentation can now reference expanded third-party certification coverage. Update your compliance evidence packages accordingly.

Federated Copilot Connectors via MCP Now Available

Real-time enterprise data from SaaS systems (HubSpot, Notion, LSEG, Moody’s) can now be connected to Work IQ via Model Context Protocol, with native security controls maintained. Enabling these connectors requires admin configuration and access policy review; assess data exposure risk before activating third-party connectors for clients.

Teams Meeting Watermarks Reach DoD in June

Watermark overlay of attendee email addresses on shared meeting content is rolling out to DoD environments in June, following GA in March and GCC-High in May. MSPs supporting government cloud clients should validate this feature is enabled for clients handling sensitive meeting content, as it requires organizer-level configuration in Meeting options.

Learning Agent Rolling Out in June

A new in-flow learning agent powered by Work IQ delivers personalized Copilot and AI skill-building, assessments, and roleplay practice directly within user workflows. This agent will appear in licensed tenants automatically. MSPs should be prepared to field end-user questions and advise clients on whether to promote or restrict it via policy.

Anthropic Claude Opus 4.8 and GPT-5.5 Instant Now Available in Copilot

Two new AI models are available for M365 Copilot licensed users: Claude Opus 4.8 for complex multi-step tasks and GPT-5.5 Instant for faster everyday responses. Expanded model choice increases the surface area for data handling considerations. Confirm clients understand which models are active and review any data residency or compliance implications.

Outlook

Copilot Chat Now Available in Pop-Out Windows

Copilot chat is now accessible in popped-out Outlook message windows, enabling use while reading or composing separate messages. No admin action is required, but MSPs should confirm clients with Copilot licenses have appropriate usage policies in place as this expands the Copilot surface area in Outlook.

Shared Calendars Assigned by Admin Now Appear Automatically

Calendars assigned to users by admins now populate automatically in the calendar list without any user action. This should reduce helpdesk tickets for shared calendar setup, but MSPs should verify that existing admin-assigned calendar configurations are correctly scoped to avoid unexpected calendar visibility for users.

DLP Warn Dialog Now Includes Justification and False Positive Fields

The DLP warning dialog in new Outlook for Windows now includes justification, false positive reporting, and acknowledgment fields, matching the behavior of classic Outlook. MSPs managing DLP policies should confirm that client configurations include appropriate justification options and that compliance teams are reviewing override and false positive reports.

Outlook Background Sync Now On by Default When App Is Closed

Outlook now syncs email in the background even when the app is closed; users can disable this in Settings > General > Offline. This may affect battery life and data usage on managed devices. Assess whether this behavior conflicts with client endpoint management policies or mobile device profiles.

OneDrive

Custom OneDrive Folder Name Now in Deferred Ring

Admins can now set a custom name for the local OneDrive sync folder via Group Policy, replacing the default “OneDrive – {org name}” convention. This reached the Deferred ring June 1, 2026. Shorter folder names increase available path length for nested files (relevant for clients with deep folder structures) so MSPs managing Deferred ring deployments should plan rollout and update GPO configurations.

Move Folders to OneDrive from File Explorer Now in Deferred Ring

A right-click context menu option to move local folders directly to OneDrive reached the Deferred ring June 1, 2026. This feature may prompt end users to inadvertently move large local folder structures to OneDrive; communicate expected behavior to clients and confirm storage quotas are adequate before this lands broadly.

Mark of the Web for Outlook Attachments Now in Deferred Ring

Email attachments saved to OneDrive from Outlook now include the Mark of the Web security tag, enabling Windows Protected View when opened. This reached the Deferred ring as of June 1. No admin action is required, but MSPs should be aware it may affect workflows where users rely on immediate full editing of downloaded attachments.

SharePoint

SharePoint Server Patch Released May 12, 2026

KB 5002863 (version 16.0.19725.20280) was released for SharePoint Server Subscription Edition; KB 5002870 and 5002872 for SharePoint Server 2019; KB 5002868 and 5002869 for SharePoint Server 2016. MSPs managing on-premises SharePoint farms must apply the May 2026 cumulative update to maintain security patch compliance. Schedule patching windows if you haven’t already.

Custom Skills for Copilot in SharePoint Now GA

Users can now create and save reusable, site-specific Copilot skills using natural language to automate repeatable multi-step workflows. Custom skills are user-created and site-scoped, so MSPs should assess whether clients need governance controls around skill creation to prevent unintended automation or data exposure.


June 2026 is a high-action month for MSPs, with hard deadlines around Entra hard-match changes, hotpatch opt-outs, Work IQ billing configuration, and the AgentsInfo table retirement all requiring attention before July 1. The broader theme is clear: AI capabilities are expanding rapidly across the Microsoft 365 stack, and the compliance, governance, and licensing structures around them are maturing just as fast. Staying current with these changes is the difference between managing client environments proactively and reacting to problems after they’ve already landed.

Featured image by Jonas Leupe on Unsplash

Microsoft 365 security policies are configurable rules that control how users, devices, and applications interact with your organization’s data. Built on Zero Trust principles—verify explicitly, enforce least privilege, and assume breach—these policies safeguard access, secure email, protect endpoints, and govern administrative rights.

This guide covers the twelve foundational policies every tenant needs, the Conditional Access configurations to prioritize first, and how to align your security posture with frameworks like CIS, NIST, and Microsoft Secure Score.

What Are Microsoft 365 Security Policies

Microsoft 365 security policies are configurable rules that control how users, devices, and applications interact with your organization’s data. Built on Zero Trust principles—verify explicitly, enforce least privilege, and assume breach—these policies safeguard access, secure email, protect endpoints, and govern administrative rights.

Think of policies as automated guardrails. They define what’s allowed, what’s blocked, and what triggers additional verification, all without requiring someone to manually approve every decision. Policies span identity (who can sign in), email protection (what gets through), device compliance (which endpoints connect), and data protection (what can be shared). Together, they form layered defenses that reduce your attack surface across the entire Microsoft 365 environment.

Core Pillars of Microsoft 365 Security

Before getting into specific policies, it helps to understand the five interconnected domains they address. Each pillar represents a category of risk, and effective security requires policies across all of them.

Identity and Access Management

This pillar controls who can sign in and under what conditions. Conditional Access and multi-factor authentication are the primary policy tools here. When someone attempts to access Microsoft 365, identity policies evaluate whether that person is who they claim to be and whether the sign-in context looks trustworthy.

Threat Protection

Email remains the most common attack vector. Threat protection policies in Microsoft Defender for Office 365 defend against phishing, malware, and business email compromise through Safe Links, Safe Attachments, and anti-phishing rules. These policies scan content before it reaches users and block malicious payloads.

Information Protection

Information protection policies classify, label, and prevent unauthorized sharing of sensitive data. Data Loss Prevention (DLP) and sensitivity labels work together to identify confidential content and control where it can travel. A DLP policy might block an email containing credit card numbers from leaving the organization, for example.

Device and Endpoint Management

Intune compliance and configuration policies ensure only secure, managed devices access corporate resources. If a laptop lacks encryption or runs an outdated operating system, device policies can block access until the issue is resolved.

Security and Risk Management

This pillar provides governance through audit logging, Secure Score tracking, and continuous monitoring. It ties everything together by giving you visibility into what’s happening across your tenant and highlighting areas that still need attention.

Essential Microsoft 365 Security Policies Every Tenant Needs

Here’s the foundational checklist. These twelve policies address the most common attack vectors and compliance gaps across Microsoft 365 tenants.

1. Enforce Multi-Factor Authentication for All Users

MFA is the single most effective identity protection available. According to Microsoft, MFA blocks 99.9% of account compromise attacks. You can enable MFA through Security Defaults (available in all plans) or Conditional Access (requires Entra ID P1 or higher).

Phishing-resistant methods like FIDO2 security keys or Windows Hello are preferable to SMS codes. SMS remains vulnerable to SIM-swapping attacks, where an attacker convinces a mobile carrier to transfer your phone number to their device.

2. Block Legacy Authentication Protocols

Legacy authentication refers to older protocols like POP, IMAP, and SMTP AUTH that don’t support MFA. Attackers specifically target legacy auth because it bypasses multi-factor requirements entirely. If MFA is your front door lock, legacy auth is an unlocked side entrance.

Blocking legacy auth is a Conditional Access policy that takes minutes to configure but closes one of the most exploited gaps in Microsoft 365 security.

3. Apply Conditional Access Baselines

Conditional Access policies are “if-then” rules that evaluate sign-in context before granting access. If a user signs in from an unmanaged device, then require MFA. If sign-in risk is high, then block access completely.

Common baseline conditions include:

  • Device compliance status: Is the device managed and meeting security requirements?
  • User location: Is the sign-in coming from a known or suspicious geography?
  • Application sensitivity: Does the app being accessed contain sensitive data?
  • Real-time risk signals: Has Microsoft Entra ID Protection detected suspicious behavior?

4. Turn on Microsoft Defender Preset Security Policies

Microsoft offers pre-configured email protection that can be enabled without manual tuning. Preset policies apply recommended settings for anti-spam, anti-malware, anti-phishing, Safe Links, and Safe Attachments all at once.

For most organizations, the Standard preset provides balanced protection. High-security environments may prefer the Strict preset, though it can increase false positives and may require more user exceptions.

5. Configure Safe Links and Safe Attachments

Safe Links scans URLs at time-of-click, protecting users even if a link was safe when the email arrived but became malicious later. Safe Attachments detonates files in a sandbox environment before delivery, watching for malicious behavior.

Both features protect email and Microsoft Teams messages, addressing the two primary channels attackers use to deliver malware and credential-harvesting pages.

6. Enable Data Loss Prevention Policies

DLP policies detect and block sensitive information from being shared inappropriately. You define three components: conditions (what triggers the policy), actions (block, notify, or encrypt), and locations (Exchange, SharePoint, Teams, or endpoints).

Even a basic DLP policy covering common sensitive data types like credit card numbers or Social Security numbers significantly reduces accidental data exposure.

7. Apply Sensitivity Labels and Information Rights Management

Sensitivity labels classify documents and emails by confidentiality level. When combined with Information Rights Management (IRM), labels can encrypt content and restrict actions like forwarding, printing, or copying.

Labels follow the content wherever it travels. A document labeled “Confidential” remains protected even when downloaded, emailed externally, or copied to a USB drive.

8. Enforce Device Compliance with Intune

Compliance policies in Microsoft Intune check device health before granting access to Microsoft 365 resources. Common checks include BitLocker encryption, firewall status, antivirus presence, and minimum OS version.

When paired with Conditional Access, non-compliant devices are blocked automatically. A user with an unencrypted laptop simply can’t access SharePoint until encryption is enabled.

9. Apply App Protection Policies for Mobile Devices

App protection policies (sometimes called MAM policies) protect corporate data within apps on personal devices without requiring full device enrollment. They can enforce PIN requirements, prevent copy/paste to personal apps, and encrypt corporate data at rest.

This approach works well for BYOD environments where users resist full device management. Corporate data stays protected inside Outlook and Teams while personal apps remain untouched.

10. Restrict External Sharing in SharePoint and OneDrive

Sharing policies control whether users can share files externally and with whom. Default settings are often more permissive than organizations realize, sometimes allowing anonymous sharing links that anyone can access.

Options include restricting sharing to authenticated guests only, limiting sharing to specific domains, or disabling external sharing entirely for sensitive sites.

11. Enable Unified Audit Logging

Audit logs record user and admin activity across all Microsoft 365 services. Without them, investigating a security incident becomes nearly impossible because you have no record of what happened.

Unified audit logging is enabled by default in most tenants, but it’s worth verifying. Logs are retained for 180 days with E5 licensing or 90 days with lower tiers.

12. Create Break-Glass Emergency Access Accounts

Break-glass accounts are cloud-only admin accounts excluded from Conditional Access policies. They exist solely for emergency scenarios when normal admin access fails, like a misconfigured policy that locks out all administrators.

Create at least two break-glass accounts, secure them with ultra-strong passwords stored offline, and monitor them for any sign-in activity. These accounts are your safety net.

Conditional Access Policies You Should Configure First

Conditional Access deserves special attention because it’s the policy engine that ties identity protection together. Here are the highest-priority policies to configure.

PolicyTrigger ConditionAction
Risk-based MFAMedium or high sign-in risk detectedRequire MFA
Block legacy authClient uses legacy protocolBlock access
Password change for risky usersHigh user risk scoreRequire password reset
Require compliant devicesDevice fails Intune complianceBlock access
Approved apps onlyMobile app not on approved listBlock access
Block risky locationsSign-in from blocked countryBlock access

Require MFA Based on Sign-In Risk

Risk-based Conditional Access uses Microsoft Entra ID Protection signals to trigger MFA only when sign-in behavior looks suspicious. A user signing in from their usual location on their usual device might not see an MFA prompt, while the same user signing in from a new country at 3 AM would.

Block Clients That Do Not Support Modern Authentication

This policy forces users onto modern authentication clients, eliminating legacy protocol vulnerabilities. Older versions of Outlook and other applications that rely on basic authentication simply won’t connect.

Require Password Change for High-Risk Users

When Entra ID Protection detects compromised credentials or high-risk user behavior, this policy forces an immediate password reset. The user can’t access anything until they create a new password.

Require Compliant Devices for Microsoft 365 Access

Combining Conditional Access with Intune compliance ensures only healthy, managed devices connect. If a device falls out of compliance, access is revoked until the issue is fixed.

Require Approved Apps or App Protection Policies

This policy restricts mobile access to apps that support app protection policies or appear on an approved list. Users can’t access corporate email through an unapproved third-party mail client.

Block Access From Risky Locations and Countries

Named locations in Conditional Access let you block sign-ins from countries where you have no business presence. If no one in your organization travels to a particular region, blocking sign-ins from there eliminates a category of risk.

Tip: Start with Conditional Access policies in report-only mode. This lets you see what would be blocked without actually enforcing the policy, reducing the risk of locking out legitimate users during rollout.

Preset Security Policies in Microsoft Defender for Office 365

Microsoft Defender for Office 365 offers three tiers of pre-configured protection. Understanding the differences helps you choose the right level for each environment.

Built-In Protection for Safe Links and Safe Attachments

Built-in protection is automatic baseline protection applied to all tenants with Defender for Office 365 licensing. It provides Safe Links and Safe Attachments coverage without any configuration required.

Standard Preset Security Policy

The Standard preset balances protection with user experience. It applies recommended settings for anti-phishing, anti-spam, anti-malware, Safe Links, and Safe Attachments. Most organizations find this tier appropriate for their needs.

Strict Preset Security Policy

The Strict preset applies the most aggressive filtering. It catches more threats but also generates more false positives, which means legitimate emails may occasionally be quarantined. This tier suits high-security environments where the tradeoff is acceptable.

When to Use Custom Policies Over Presets

Custom policies make sense when presets don’t fit your specific requirements. You might need exceptions for specific user groups, different settings for partner communications, or configurations that meet particular compliance mandates.

Aligning Microsoft 365 Policies With CIS, NIST, SCuBA, and Secure Score

Mapping your policies to recognized frameworks simplifies compliance reporting and builds trust with stakeholders who want to see alignment with industry standards.

  • CIS Microsoft 365 Foundations Benchmark: Prescriptive hardening recommendations with specific pass/fail controls that auditors recognize.
  • NIST Cybersecurity Framework: Organizes security into Identify, Protect, Detect, Respond, and Recover functions, providing a common language for security discussions.
  • CISA SCuBA: US government guidance specifically for Microsoft 365 security baselines, increasingly referenced in compliance requirements.
  • Microsoft Secure Score: Built-in prioritized improvement list showing scoring impact for each recommended action, useful for tracking progress over time.

How to Deploy Microsoft 365 Security Policies Across Multiple Tenants

For MSPs managing many clients, consistent policy deployment at scale is the real challenge. Manual configuration tenant-by-tenant doesn’t scale and introduces configuration drift over time.

Step 1: Establish a Standard Security Baseline

Document a set of policies that apply to all clients regardless of size or industry. This becomes your repeatable starting point and ensures no tenant falls below a minimum security threshold.

Step 2: Build Reusable Policy Templates

Create exportable or templatized configurations that can be deployed repeatedly without rebuilding from scratch. Templates save time and reduce the chance of configuration errors.

Step 3: Pilot Policies in Report-Only Mode

Test policy impact before enforcement. Conditional Access report-only mode shows what would be blocked without actually blocking it, letting you identify potential issues before users are affected.

Step 4: Roll Out Policies Tenant by Tenant

Deploy in phases, validating each tenant before moving to the next. This catches environment-specific issues early and prevents a single misconfiguration from affecting all clients simultaneously.

Step 5: Monitor for Configuration Drift

Settings change over time, sometimes intentionally and sometimes not. Continuous monitoring and remediation keeps tenants aligned with your baseline and catches unauthorized changes quickly.

Augmentt’s Secure Autopilot enables one-click deployment of security baselines aligned with CIS, NIST, SCuBA, and Secure Score across all your tenants, with ongoing drift detection and automated remediation.

Frequently Asked Questions About Microsoft 365 Security Policies

What licenses are required to enforce Microsoft 365 security policies?

Basic policies like Security Defaults and audit logging are available in all Microsoft 365 plans. Advanced features like Conditional Access, Defender for Office 365, and Intune require Business Premium, E3, or E5 licensing.

Are Microsoft Security Defaults sufficient without Conditional Access policies?

Security Defaults provide baseline MFA and block legacy authentication but lack granular control. Organizations with compliance requirements or complex environments typically benefit from upgrading to Conditional Access policies.

How often should Microsoft 365 security policies be reviewed?

Quarterly reviews are a reasonable minimum. Immediate review is warranted after significant changes in licensing, user population, compliance requirements, or following a security incident.

Can L1 or L2 technicians safely apply Microsoft 365 security policies?

With proper tooling that provides guardrails and pre-built templates, junior technicians can safely apply standardized security policies without needing deep expertise or direct access to Microsoft admin portals.


Cover Photo by Windows on Unsplash

Paying for Microsoft 365 licenses that nobody uses is one of the quietest budget leaks in IT. Under annual NCE terms, every idle seat you miss at renewal locks you into another twelve months of waste.

The good news: yes, tools exist that surface unused licenses automatically without manual exports or PowerShell scripts. This guide covers how automatic detection works, what to look for in a tool, and how MSPs can reclaim idle licenses across dozens of tenants from a single dashboard.

What is an unused Microsoft 365 license

Yes, several specialized tools automatically surface unused Microsoft 365 licenses. SaaS management platforms like Zylo and Torii pull usage data and highlight idle accounts, while MSP-focused solutions like Augmentt and CoreView do the same across multiple customer tenants without manual effort.

An unused license is one assigned to a user account that shows no sign-in or app activity over a defined period, typically 30 to 90 days. This differs from an unassigned license, which sits in your subscription inventory waiting to be allocated to someone. The distinction matters because unused licenses quietly drain budget month after month, while unassigned ones are at least visible when you check your subscription count.

Why detecting unused Microsoft 365 licenses matters

Idle licenses create problems that compound over time. The longer they go unnoticed, the more they cost you in dollars, security exposure, and audit headaches.

Cut shelfware and renewal costs

Paying for licenses nobody uses inflates your renewal bills. Under Microsoft’s New Commerce Experience (NCE) annual terms, you cannot reduce seat counts mid-contract. Every unused license you miss at renewal locks you into another year of waste.

For organizations with a few hundred seats, even a small percentage of idle licenses can translate to thousands of dollars annually. That money could go toward security tools, staffing, or other priorities instead of inflating SaaS costs.

Tighten security during offboarding

Licenses tied to departed or inactive users can become Microsoft 365 security risks if the accounts remain enabled. A former employee’s mailbox with an active license is still a valid target for credential stuffing or phishing attempts.

Linking license detection to your offboarding process closes this gap. When you catch idle accounts early, you can disable them before they become a liability.

Stay ready for audits and true-ups

Accurate license inventory simplifies Microsoft true-ups and compliance checks. When you know exactly who is using what, you avoid scrambling during an audit or overpaying because your records do not match reality.

How to find unused Microsoft 365 licenses in the admin center

The manual route starts in the Microsoft 365 Admin Center. You navigate to Reports, then Usage, select the relevant usage report, and review the last activity date for each user. From there, you can export the data to Excel for further analysis.

Here is the basic process:

  • Sign in to admin.microsoft.com
  • Go to Reports, then Usage
  • Select the usage report for the app you want to check, such as Exchange, Teams, or OneDrive
  • Review the last activity date column
  • Export the report if you want to filter or share it

This approach works for a single tenant, but it does not scale. You will repeat the process for every customer, and there is no automation. Just manual exports and spreadsheets that get stale the moment you finish them.

How to detect unused Microsoft 365 licenses with PowerShell

PowerShell combined with Microsoft Graph lets you pull sign-in logs and compare them against assigned licenses programmatically. You can script a threshold check, flagging anyone who has not signed in for 60 days, and run it on a schedule.

  • Last sign-in date: Pulled from Azure AD sign-in logs via Graph API
  • Assigned licenses: Retrieved with Get-MgUserLicenseDetail
  • Threshold comparison: Your script flags users inactive beyond your policy window

This method is flexible and free, but it requires scripting skills and ongoing maintenance. Scripts break when Microsoft updates APIs, and you have to manage credentials and permissions for each tenant. For MSPs managing dozens of customers, running and updating scripts per tenant quickly becomes unsustainable.

How to detect unused Microsoft 365 licenses automatically

Automated tools handle the heavy lifting by continuously aggregating activity data and surfacing idle accounts without manual intervention. The workflow typically follows a predictable pattern.

Step 1. Define what inactive means

Most tools let you set an inactivity threshold, commonly 30, 60, or 90 days of no sign-in or app usage. Your policy here aligns with HR and offboarding workflows so you are not flagging someone on extended leave or sabbatical.

The threshold you choose depends on your organization. A 30-day window catches idle accounts quickly but may generate false positives. A 90-day window is more conservative but lets waste accumulate longer.

Step 2. Pull sign-in and app activity signals

Automated platforms pull from multiple data sources: Azure AD sign-in logs, Microsoft 365 usage reports, and app-level activity like mail sent, Teams calls, or SharePoint edits. Aggregating all of these signals gives a fuller picture than sign-in data alone.

Someone might sign in once a month to check email but never touch Teams or OneDrive. A tool that only looks at sign-in dates would miss that the Teams license is going unused.

Step 3. Flag idle and misassigned licenses

The tool compares activity against assigned licenses to surface accounts with no usage. Some platforms also catch misassignment, like an E5 license assigned to someone who only uses email. In that case, you could downgrade to a cheaper SKU and save the difference.

Step 4. Trigger alerts or PSA tickets

Good tools push alerts via email, webhook, or directly into your PSA. Technicians can act without logging into another dashboard, and nothing slips through the cracks.

For MSPs, PSA integration is particularly valuable. An alert that creates a ticket in ConnectWise or Autotask means the work gets tracked and assigned like any other service request.

Step 5. Automate removal or downgrade

Some platforms offer auto-remediation. After a grace period or approval workflow, the tool revokes or downgrades the license automatically. This removes the manual step entirely and ensures idle licenses do not linger for months.

Step 6. Tie detection into offboarding

Linking license detection to your offboarding process ensures licenses are reclaimed as soon as a user departs, not months later when someone finally notices the account is still active. This connection between HR events and license management is where automation really pays off.

What to look for in a Microsoft 365 license detection tool

Not all tools offer the same depth. Some generate reports you still have to act on manually. Others automate the entire workflow from detection to reclamation. Here is what separates a basic report from a platform you can rely on.

Multi-tenant visibility

For MSPs, the tool aggregates license data across all customer tenants in one view. Jumping between admin centers is slow and error-prone, and it does not scale when you manage 50 or 100 customers.

Activity-based inactivity detection

Look for tools that go beyond last sign-in and examine actual app usage, including mail sent, Teams calls, and SharePoint edits. A user who signs in but never touches an app is still wasting a license.

Group-based licensing support

Azure AD group-based licensing can complicate reclamation. If a user gets their license through group membership, removing the license directly will not work. The tool you choose understands group membership so you do not accidentally break assignments or create conflicts.

Automated reclamation actions

Reports are helpful, but one-click or scheduled removal actions save time and reduce human error. The fewer manual steps between detection and action, the more likely idle licenses actually get reclaimed.

Brandable license reporting

For MSPs, the ability to generate client-facing reports with your logo and branding turns license management into a visible service. Customers see the value you deliver, and you have documentation for quarterly business reviews.

CapabilityAdmin CenterPowerShellSaaS PlatformMSP Platform
Multi-tenant viewNoManualVariesYes
Activity-based detectionLimitedCustomYesYes
Automated reclamationNoManualVariesYes
PSA integrationNoNoRarelyYes
Brandable reportsNoNoVariesYes

Tools that automatically surface unused Microsoft 365 licenses

Microsoft 365 Admin Center

Free and built-in, but manual and single-tenant only. Good for small organizations checking ad hoc, but not practical for ongoing management or multi-tenant environments.

PowerShell and Microsoft Graph

Free and flexible, yet requires scripting skills and ongoing maintenance. You can build exactly what you want, but you also own all the upkeep. For MSPs managing many tenants, the maintenance burden often outweighs the cost savings.

SaaS management platforms

Tools like Zylo, Torii, and BetterCloud aggregate SaaS usage including Microsoft 365. They are designed for enterprise IT teams managing a single large environment, not MSP multi-tenant workflows. If you only manage one organization, they work well. If you manage many, the per-tenant setup becomes cumbersome.

MSP-focused platforms

Purpose-built for managing many customer tenants, examples include Augmentt, CoreView, and CIPP. These offer multi-tenant dashboards, automated alerts, and PSA integrations that fit how MSPs actually work.

How MSPs detect unused Microsoft 365 licenses across multiple tenants

Jumping between tenants is slow and error-prone. MSP-focused tools connect via CSP Partner Portal or delegated admin and pull license and usage data across all tenants into a single dashboard.

  • Single-pane visibility: See all tenants without switching contexts or logging in and out of different admin centers
  • Per-tenant policies: Set different inactivity thresholds by customer based on their business needs
  • Automated customer reports: Schedule branded reports for each client that show license utilization and savings opportunities

This approach turns license management from a reactive chore into a proactive service you can deliver consistently across your entire customer base.

How to reclaim unused Microsoft 365 licenses safely

Reclaiming a license without proper steps can disrupt users or lose data. A safer approach involves a few key practices.

  • Notify stakeholders: Email the user or their manager before revoking to confirm the account is truly inactive
  • Disable first: Block sign-in or convert the mailbox to shared before deleting the account entirely
  • Export data: Ensure OneDrive and mailbox content are backed up or transferred to another user
  • Log the change: Record the removal in your PSA or ticketing system for audit purposes

Some platforms offer a grace period or approval workflow so nothing gets revoked without review. This extra step prevents accidental removal of licenses from users who are simply on vacation or working remotely with limited connectivity.

Automate unused Microsoft 365 license detection with Augmentt

Augmentt surfaces unused licenses automatically across all customer tenants from a single dashboard. You get multi-tenant license reporting, one-click reclamation actions, and PSA-integrated alerts, so your team can act fast without jumping between portals.

Ready to stop paying for licenses nobody uses? See how Augmentt simplifies Microsoft 365 license management for MSPs.

Frequently asked questions about detecting unused Microsoft 365 licenses

What counts as an inactive Microsoft 365 user?

An inactive user is typically someone who has not signed in or used any Microsoft 365 app, including Exchange, Teams, SharePoint, or OneDrive, within a defined period. Most organizations use a threshold of 30 to 90 days depending on their policy and business context.

Can you remove a Microsoft 365 license without losing user data?

Yes. Removing a license does not immediately delete mailbox or OneDrive data. However, the data enters a retention window and will eventually be purged unless you convert the mailbox to shared or export the content first. The retention period varies based on your tenant settings.

Does Microsoft NCE or CSP billing affect reclaiming unused licenses?

Under NCE annual terms, you cannot reduce seat count mid-term. Reclaimed licenses sit unused until renewal, so detecting them early helps you right-size at the next renewal date rather than paying for another year of waste.

How often should you audit Microsoft 365 license usage?

Most organizations run a usage audit monthly or quarterly. Automated tools surface idle licenses continuously, so you catch issues before the next billing cycle rather than discovering them during annual renewal planning.

Can unused Microsoft 365 licenses be reassigned automatically?

Some platforms support auto-reassignment workflows where a reclaimed license is added back to an available pool and assigned to a new user via group-based licensing or provisioning rules. This keeps licenses in circulation rather than sitting idle after reclamation.


Photo by Ed Hardie on Unsplash

PowerShell scripts were the go-to solution for Microsoft 365 automation…until they weren’t. Managing 50 tenants with custom scripts means maintaining 50 potential points of failure, and every Microsoft Graph API update threatens to break something you don’t have time to fix.

Modern multi-tenant management platforms now handle security baselines, policy enforcement, and breach response without requiring you to write or maintain code. This guide covers why MSPs are moving away from scripts, what to look for in a replacement platform, and how to evaluate the leading alternatives—including options that work without a golden tenant.

Why MSPs are moving away from PowerShell scripts for Microsoft 365 management

Several platforms now handle Microsoft 365 management without requiring you to write or maintain PowerShell code. Tools like M365 Manager Plus, CoreView, and Augmentt provide interfaces for user provisioning, license management, and security configuration that work across multiple tenants. For MSPs managing many clients, platforms such as CIPP, Microsoft Lighthouse, and Nerdio Manager offer centralized control without relying on a golden tenant as a configuration template.

The shift reflects a practical reality. When you’re responsible for 30, 50, or 100 tenants, the hours spent writing and debugging scripts start to outweigh the benefits. What once felt like automation becomes another maintenance burden.

Brittle scripts and constant Microsoft Graph API changes

Microsoft updates the Graph API and deprecates cmdlets on its own schedule, often with limited advance notice. A script that ran perfectly last quarter can fail after an API version change, and the failure might be silent—no error message, just missing data or incomplete actions.

Common breakage scenarios include:

  • Deprecated authentication methods: Basic auth retirement broke thousands of legacy scripts when Microsoft enforced the change
  • Cmdlet parameter changes: Updated modules introduce new required parameters that existing scripts don’t account for
  • Throttling policy updates: Scripts that worked at low volume hit rate limits as your client count grows

Each of these scenarios means unplanned troubleshooting time, usually during a client emergency.

Single point of failure on one scripting expert

Most MSPs have one person who truly understands the PowerShell scripts running in production. Maybe two, if you’re lucky. When that person takes vacation, gets sick, or leaves the company, the scripts become a black box.

L1 and L2 technicians end up escalating routine tasks to senior engineers simply because fixing the issue requires modifying code they didn’t write and don’t fully understand. That’s an expensive bottleneck, and it doesn’t scale.

Portal fatigue across dozens of tenants

Portal fatigue is the exhaustion that comes from logging in and out of multiple Microsoft admin centers throughout the day. If you manage 50 tenants and want to check MFA status in each one, that’s 50 separate login sessions. Conditional Access policies can make this even more tedious, requiring additional authentication steps for each tenant.

The cognitive load compounds quickly. Technicians lose context when switching between tenants, and the repetitive clicking increases the chance of mistakes.

No audit trail for configuration drift

PowerShell scripts rarely log what changed, when it changed, or who ran the script. When a client asks why a Conditional Access policy looks different than it did three months ago, you’re left searching through command history or making educated guesses.

This gap makes compliance reporting difficult and slows down troubleshooting when something breaks.

What is a golden tenant and why it falls short for multi-tenant MSPs

A golden tenant is a reference Microsoft 365 tenant configured with your ideal security settings. The idea is to set it up once, then use it as a template to replicate configurations across client tenants. In theory, this approach standardizes your deployments. In practice, it creates its own set of problems.

Extra licensing costs and tenant overhead

A golden tenant requires its own Microsoft 365 licenses just to exist. You’re paying for a tenant that serves no actual users—it only holds configuration settings. If you work with clients across different industries or compliance requirements, you might end up maintaining multiple golden tenants, multiplying the cost.

Configuration drift between master and client tenants

Client tenants inevitably diverge from the golden tenant over time. Someone makes a manual change to address a specific client request. A new Microsoft feature rolls out and gets enabled differently across tenants. A technician adjusts a setting during troubleshooting and forgets to document it.

There’s no automatic mechanism to detect or correct this configuration drift. The golden tenant becomes a snapshot of what you intended, not a reflection of what actually exists.

Limited fit for mixed client license tiers

A golden tenant configured for Business Premium won’t apply cleanly to clients running Business Basic. Features like Conditional Access, Defender, and Intune require specific licensing tiers. Your template either excludes those settings entirely or fails when applied to tenants that lack the required licenses.

This mismatch forces you to maintain multiple golden tenants or accept that your “standard” configuration only works for a subset of clients.

Core capabilities to look for in a PowerShell alternative

When evaluating platforms, focus on capabilities that directly address the pain points above. The right tool reduces scripting overhead while giving you more visibility and control.

Multi-tenant policy and security baseline management

Look for platforms that let you push Conditional Access, Defender, and Intune policies across all tenants from a single dashboard. This capability replaces the need to write tenant-specific scripts or log into each admin center individually.

The key distinction is centralized visibility combined with centralized action. Seeing all your tenants in one place is helpful, but being able to make changes across them from that same view is what actually saves time.

One-click application of NIST, CIS, and Secure Score best practices

Pre-built security templates aligned to recognized frameworks eliminate hours of research and manual configuration. You select a baseline, apply it to the relevant tenants, and move on.

Frameworks worth looking for include:

  • CIS Benchmarks: Consensus-based security configurations maintained by the Center for Internet Security
  • NIST guidelines: Federal standards that many regulated industries reference
  • Microsoft Secure Score: Microsoft’s own scoring system for tenant security posture

Automated breach detection and auto-remediation

Real-time alerting on risky sign-ins matters, but automatic response actions matter more. The ability to block a compromised user or reset a password without waiting for a technician to respond reduces the window of exposure significantly.

Look for platforms that let you customize alert thresholds and remediation actions. Not every risky sign-in warrants the same response, and overly aggressive automation can create its own problems.

Branded reporting and risk assessments

White-label reports for QBRs and prospecting eliminate the manual export work that eats into billable hours. Automated scheduling means reports go out on time without technician involvement.

The best platforms also include risk assessment templates you can use during sales conversations, turning security posture into a tangible deliverable.

GDAP and CSP onboarding without a golden tenant

Direct connection via GDAP (Granular Delegated Admin Privileges)Direct connection via GDAP (Granular Delegated Admin Privileges) or Magic Link removes the need for a reference tenant entirely. You onboard clients in minutes rather than hours, with granular role assignments built into the connection process.

GDAP replaced the older DAP model and requires more specific permission scoping. Platforms that handle this natively save you from manually configuring access for each new client.

Categories of Microsoft 365 management tools that replace PowerShell

Before looking at specific products, it helps to understand the different categories of tools available. Each category serves different needs and comes with different tradeoffs.

CategoryExamplesBest ForTradeoffs
Native Microsoft toolsLighthouse, Admin CenterBasic cross-tenant visibility at no costLimited automation and no PSA integration
Community platformsCIPPMSPs with technical staff to self-hostRequires Azure hosting and ongoing maintenance
Commercial multi-tenant platformsAugmentt, Inforcer, CoreViewTurnkey deployment with vendor supportSubscription costs
RMM/PSA-integrated toolsNerdio, N-ableEndpoint-focused MSPs adding M365 modulesM365 security depth varies

Native Microsoft tools like Lighthouse and the Admin Center

Microsoft 365 Lighthouse is free for CSP partners and provides basic cross-tenant visibility. You can compare Secure Scores across tenants and see which clients have risky configurations.

However, Lighthouse lacks advanced automation, PSA integration, and the remediation workflows that make management efficient at scale. It’s a reasonable starting point, but most MSPs find they outgrow it quickly.

Community platforms like CIPP

CIPP (CyberDrain Improved Partner Portal) is open-source and highly customizable. The community actively develops new features, and the platform handles many common multi-tenant tasks well.

The tradeoff is that you’re responsible for Azure hosting, updates, security patches, and troubleshooting. There’s no vendor support line to call when something breaks at 2 AM.

Commercial multi-tenant platforms built for MSPs

Purpose-built SaaS tools come with support, compliance certifications, and turnkey onboarding. Platforms in this category typically offer SOC 2 Type II compliance and align with frameworks like CIS and NIST out of the box.

Augmentt falls into this category, designed specifically for MSPs managing multiple Microsoft 365 tenants without requiring a golden tenant or premium licensing across all clients.

RMM and PSA-integrated management tools

Endpoint-focused platforms are adding M365 modules to their feature sets. If you’re already invested in a particular RMM, check whether its M365 capabilities meet your actual security and management requirements.

The depth of M365 security baselines varies significantly across RMM platforms. Some offer robust policy management while others provide only basic visibility.

Best alternatives to PowerShell scripts for Microsoft 365 management

1. Augmentt Secure Autopilot

Augmentt is built specifically for MSPs managing multiple Microsoft 365 tenants. The platform works without a golden tenant, supports all license tiers, and enables L1/L2 technicians to handle tasks that previously required senior engineers or custom scripts.

Key capabilities include:

  • One-click security baselines aligned to CIS, NIST, and Secure Score
  • Automated breach detection with configurable auto-remediation
  • Branded reporting and unlimited risk assessments
  • SOC 2 Type II certification with native GDAP support

See how Augmentt simplifies multi-tenant M365 management →

2. CIPP (CyberDrain Improved Partner Portal)

CIPP is a free, community-driven platform with strong automation capabilities. The active development community adds features regularly, and the platform handles many common MSP workflows well.

You’ll need Azure hosting and technical expertise to maintain it. Many MSPs use CIPP successfully, though the lack of vendor support means you’re responsible for troubleshooting and security updates.

3. Microsoft 365 Lighthouse

Lighthouse provides basic tenant comparison and Secure Score visibility at no additional cost beyond your CSP agreement. It’s a reasonable starting point for MSPs new to multi-tenant management.

Most MSPs find they outgrow Lighthouse as their client base expands and their security requirements become more sophisticated.

4. Nerdio Manager for MSP

Nerdio excels at Intune, Azure Virtual Desktop, and endpoint lifecycle management. The platform integrates well with existing Microsoft infrastructure and provides strong device management capabilities.

M365 security baseline features are less comprehensive than dedicated platforms, so Nerdio works best for MSPs whose primary focus is endpoint and infrastructure management.

5. CoreView

CoreView targets enterprise-grade M365 management with deep automation and governance features. The platform offers extensive customization and handles complex organizational structures well.

Pricing may be prohibitive for smaller MSPs, though larger organizations and enterprises often find value in its breadth of capabilities.

6. Inforcer

Inforcer focuses on policy management and compliance reporting for MSPs. The platform emphasizes security baseline enforcement and provides detailed compliance documentation.

As a newer entrant, Inforcer continues to expand its feature set and has positioned itself competitively against more established players.

7. SaaS Alerts

SaaS Alerts monitors behavior and breach indicators across SaaS applications including Microsoft 365. The platform focuses on detecting anomalous activity rather than configuration management.

SaaS Alerts complements configuration management tools rather than replacing them. Many MSPs use it alongside another platform for a more complete security picture.

8. BetterCloud

BetterCloud is a broad SaaS management platform where M365 is one of many supported applications. The platform handles user lifecycle management and data governance across multiple SaaS tools.

BetterCloud is less MSP-centric than purpose-built alternatives, though it offers value for organizations managing diverse SaaS portfolios beyond just Microsoft 365.

How to choose the right Microsoft 365 management platform for your MSP

Match the tool to your service portfolio and client license tiers

Consider whether the platform works across Business Basic, Business Premium, E3, and E5 without requiring premium licensing on every tenant. A tool that only performs well on E5 won’t help you standardize security across your entire client base.

The licensing question matters both for the platform itself and for the Microsoft features it manages. Conditional Access management, for example, requires clients to have appropriate licensing regardless of which platform you use.

Evaluate operational efficiency and L1 to L2 enablement

The best platforms let junior technicians handle routine security tasks confidently. If a tool still requires senior engineers for basic operations, you haven’t actually reduced your operational burden—you’ve just moved it from scripts to a different interface.

Look for platforms with clear workflows, good documentation, and guardrails that prevent accidental misconfigurations.

Verify security, compliance, and SOC 2 posture

For regulated clients, confirm the vendor holds SOC 2 Type II certification, supports GDPR requirements, and aligns with CIS or NIST frameworks. These credentials matter during client security reviews and can become deal-breakers for prospects in healthcare, finance, or government-adjacent industries.

Standardize Microsoft 365 security without a golden tenant using Augmentt

Augmentt addresses the core pain points covered throughout this article. The platform requires no golden tenant, delivers consistent security across all license tiers, and provides one-click baselines, automated breach response, and branded reporting.

L1 and L2 technicians can deliver enterprise-grade security without escalating to senior engineers or maintaining custom scripts. SOC 2 Type II certification and alignment with CIS, NIST, and Microsoft Secure Score frameworks provide the compliance foundation regulated clients expect.

Book a demo to see Augmentt in action →

Frequently asked questions about Microsoft 365 management without PowerShell

Is CIPP safe to use in production MSP environments?

CIPP is community-maintained open-source software. Safety depends on your team’s ability to audit code, apply updates promptly, and secure your Azure hosting environment. Many MSPs use CIPP successfully in production, though you’re accepting responsibility for ongoing maintenance and security.

Do PowerShell alternatives require Microsoft 365 Business Premium licensing?

Most commercial platforms work across all M365 license tiers. However, certain advanced features like Conditional Access management require the client tenant to have appropriate licensing. That’s a Microsoft limitation, not a platform limitation.

How does GDAP affect the choice between scripts and management platforms?

GDAP (Granular Delegated Admin Privileges) replaced DAP and requires tools to support granular role assignments. Modern platforms handle GDAP natively, while legacy scripts often require significant rework to accommodate the new permission model.

Can multi-tenant management platforms fully replace Microsoft 365 Lighthouse?

Yes. Commercial platforms typically offer everything Lighthouse provides plus automated remediation, PSA integration, and branded reporting. Many MSPs use Lighthouse as a free starting point before moving to more capable tools as their requirements grow.

Will moving off PowerShell scripts break existing automations?

Most platforms support APIs and webhook integrations, allowing you to migrate automations incrementally. You can start with the highest-maintenance scripts and expand from there rather than replacing everything at once.


Photo by Glenn Carstens-Peters on Unsplash

Dark Mode in Augmentt Screenshot

It’s the feature you’ve been asking for, and we’re happy to say it’s finally here: Dark Mode has officially arrived in Augmentt.

Your eyes can stop squinting. Your late-night dashboard sessions are about to get a whole lot easier on the retinas.

Dark Mode in Augmentt

Why Dark Mode?

If you spend your day managing multi-tenant security, you’re spending it on a screen. A lot of screen. We’ve heard from plenty of you that a softer, darker interface would make those long sessions more comfortable, especially when you’re digging into reports outside of standard daylight hours.

Beyond just looking good, Dark Mode can help reduce eye strain in low-light environments and save a bit of battery on OLED displays. Small wins, but the kind that add up over a workday.

How to Turn It On

We kept this simple, because you’ve got enough on your plate already.

  1. Click your account icon in the top right corner of Augmentt.
  2. Find the Dark Mode toggle.
  3. Switch it on.

That’s the whole process. No reload, no settings deep-dive, no support ticket. You can flip back to Light Mode any time using the same toggle.

A Quick Note for Light Mode Fans

Not everyone wants their dashboard to look like a moody coffee shop, and that’s completely fair. Light Mode isn’t going anywhere. Use whichever one suits your workflow, your lighting, or your mood on any given day.

Give It a Try

Hop into Augmentt, click your account icon, and give Dark Mode a spin. We think you’ll like it, and we’d love to hear what you think once you’ve taken it for a test drive.

SUBSCRIBE for more resources

Run Unlimited Free M365 Security Reports

Across All Your Customers. Forever.

What our partners are saying

MSPs Leading With Augmentt

Why They Chose Augmentt:

“We built an entire managed service around the Augmentt platform so we can sell our customers a service that will keep their tenants up to date and configured all the time rather than needing to do these professional services engagements periodically. I think not only has the quality improved, but it’s opened up an entirely new service. We’ve been able to sell to our customers very successfully.”

– Tim Campbell, All Covered
What They’re Using Augmentt For:

Ready to get started?

Protect your customers from the growing cyber security threat landscape while growing your MSP by selling enhanced SaaS security services.
Monthly Update Webinar
Get the latest platform updates live every month!
Watch Demo
Take a self guided tour of the Augmentt platform.

© 2026 Augmentt. All Rights Reserved.

Terms & ConditionsPrivacy Policy