The Baseline Builder

How do MSPs deploy a Microsoft 365 security baseline?

Every My365 plan ships with the Baseline Builder: the same Microsoft Zero Trust security and compliance configuration we operate on Netlogic’s own endpoints, packaged so you can deploy it in minutes. Use it on your own tenant on Learn. Roll it out to every client tenant on Plus.

5 Zero Trust pillars protected Identity, Devices, Apps, Data, Infrastructure
57+ Device-level controls Aligned to Microsoft Win11 25H2 Security Baseline
18 Defender ASR rules in Block mode Not Audit. Block credential theft, Office macros, ransomware behaviors
11+ Compliance frameworks aligned CIS L1, NIST CSF, ISO 27001, MITRE ATT&CK, more

What’s in the Baseline, by Microsoft Zero Trust pillar.

Every control uses Microsoft-native technology. No third-party agents, no extra trust boundaries.

Identity

Strong authentication, conditional access, and identity-layer threat detection across cloud and on-premises Active Directory.

  • Entra ID
  • Conditional Access
  • Strong Auth (MFA)
  • Defender for Identity

Devices

Hardened endpoints under continuous configuration management with EDR, attack surface reduction, and managed updates. Silent BitLocker enablement with Entra recovery escrow.

  • Intune
  • Defender for Endpoint
  • 18 ASR Rules (Block)
  • BitLocker
  • Autopatch

Apps

Application control, cloud app security, OAuth governance, and email protection at the strictest preset Microsoft publishes.

  • App Control for Business
  • Defender for Cloud Apps
  • Defender for Office 365 (Strict)

Data

Sensitivity labeling with auto-classification, data loss prevention, and retention with defensible disposition. Personal Data Encryption layered on top of BitLocker.

  • Purview Information Protection
  • Purview DLP
  • Purview Data Lifecycle
  • Personal Data Encryption

Infrastructure

Host-based firewall hardened across all profiles, NTLMv2-only authentication, network protection, and unified XDR detection across all signals.

  • Windows Firewall
  • Defender Network Protection
  • Defender XDR
  • NTLM Hardening
Mapped to:
  • Microsoft Win11 25H2 Security Baseline
  • CIS Microsoft Windows 11 Benchmark Level 1
  • NIST Cybersecurity Framework
  • ISO/IEC 27001
  • MITRE ATT&CK
  • CIS Controls v8

How you use the Baseline, by plan.

My365 Learn

Run it on your own tenant first.

Deploy the Baseline to your MSP’s internal Microsoft 365 tenant. Learn how every control behaves with your own apps and workflows before you ever touch a client tenant. Drift detection via Intune compliance reporting and Defender Vulnerability Management means you’ll know the moment configuration shifts.

  • Internal-only deployment
  • Practice operating it before selling it
  • Calibrated exceptions documented and versioned (current: Winter 2025)
My365 Plus

Roll it out to every client tenant.

Multi-tenant Baseline deployment across all the Microsoft 365 tenants you manage. The same configuration we run, the same configuration you’ve practiced internally, now on every client. When an auditor asks how a tenant is configured, you have a defensible, documented, framework-aligned answer.

  • Multi-tenant rollout & tenant assessments
  • Versioned baseline updates ship as Service Activities
  • Premium for the Baseline can be billed at $399–$999/mo per client as part of your MSP agreement

Pair the Baseline with end-user guides that cut your ticket volume.

Interactive, illustrated walk-throughs for users running our hardened baseline — sign-in, BitLocker recovery, MFA, app-install flows, OneDrive, Teams, and the everyday tasks that turn into Level 1 and Level 2 tickets when nobody documents them. Send your clients the link and reclaim the time your techs were spending on resets.

Windows 11

Windows 11 Get Started Guide

Interactive walkthrough of the Windows 11 experience under our baseline. Covers sign-in, BitLocker recovery flows, the Microsoft Store install model under SmartScreen App Install Control, OneDrive setup, Teams onboarding, and the everyday tasks end-users would otherwise call you about.

  • First-login & MFA setup
  • Approved-apps install paths
  • BitLocker recovery key retrieval
  • OneDrive, Teams, Outlook quick-starts
Open the Windows 11 guide →
macOS

macOS Get Started Guide

The Mac counterpart, calibrated to how your clients actually use Microsoft 365 on macOS. FileVault, Microsoft 365 apps, Teams meetings, OneDrive sync, identity flows. Same look, same tone, same self-serve outcome — written for users, not for IT.

  • First-login & identity setup
  • Microsoft 365 apps on macOS
  • FileVault essentials
  • OneDrive, Teams, Outlook quick-starts
Open the macOS guide →

Why this matters to your bottom line: every “how do I sign in,” “where’s my recovery key,” and “why can’t I install this app” ticket your team doesn’t take is margin. Send the link as part of your onboarding email; we keep both guides current with each baseline release.

Want every control, mapped to Microsoft documentation? We publish the entire Baseline in our Public Security Posture & Compliance Architecture report. Each card explains what the control protects against, exactly how it’s configured, and which framework it satisfies. ~90% Microsoft Win11 25H2 baseline coverage with documented, calibrated exceptions where Microsoft’s enterprise assumptions don’t fit small-business operating realities.
Read the full report →
Book a Consultation
Scroll to Top