What Microsoft 365 solution baseline settings are recommended?
This article outlines the recommended settings for Microsoft 365 solution baselines, helping you align with best practices while optimizing user experience, performance, and security. Adjust these settings as needed to meet your organization's requirements and compliance needs.
Important!
These recommendations follow Microsoft's best practices and Nerdio’s expertise from years of experience. Before implementing these changes, consult with your Security and Operations teams.
Before configuring your solution baseline, we recommend cloning it to ensure a fresh starting point. For details, see Solution Baselines: MSP-level Management.
Consider the following solution baselines recommendations:
Defender for Endpoint: Recommended solution baseline settings
SharePoint and OneDrive: Recommended solution baseline settings
Defender for Endpoint: Recommended solution baseline settings
Consider the following solution baselines recommendations:
Group |
Settings |
Recommendations and additional details |
---|---|---|
Prerequisites |
Name and Description |
|
License validation |
|
|
Permissions |
|
|
Nerdio Manager for MSP |
|
|
Integrations |
Intune |
|
Entra – Conditional Access |
|
|
Device Onboarding |
Device Onboarding |
|
Baseline Endpoint Security Policies |
|
|
Notifications |
Notifications |
|
Summary |
Summary |
This provides a high-level overview of how enabling the solution baseline affects the customer. It includes Enforce, Report-only, and Exclude mode details per each configuration tab. |
Options |
|
Entra ID: Recommended solution baseline settings
Consider the following solution baselines recommendations:
Group |
Settings |
Recommendations and additional details |
---|---|---|
General |
Name and Description |
|
M365 Org Settings |
|
|
Identity |
Users |
|
Groups |
|
|
External Identities |
|
|
Enterprise Apps |
|
|
Auth & Passwords |
Registration Campaign |
|
Summary |
Summary |
This provides a high-level overview of how enabling the solution baseline affects the customer. It includes Enforce, Report-only, and Exclude mode details per each configuration tab. |
Options |
|
Exchange Online: Recommended solution baseline settings
Consider the following solution baselines recommendations:
Group |
Settings |
Recommendations and additional details |
---|---|---|
Prerequisites |
Name and Description |
|
Licenses |
|
|
Permissions |
|
|
Organization |
Default domain |
|
Authentication |
|
|
Add-ins |
|
|
Mail flow settings |
General |
|
Security |
|
|
Reply-all storm protection |
|
|
Message Recall |
|
|
Mailbox settings |
Security |
|
Retention |
|
|
Sharing |
|
|
User preferences |
|
|
Exchange Online Protection (EOP) |
Anti-malware |
|
Anti-spam |
|
|
Anti-phishing |
|
|
Summary |
Summary |
This provides a high-level overview of how enabling the solution baseline affects the customer. It includes Enforce, Report-only, and Exclude mode details per each configuration tab. |
Options |
|
Intune: Recommended solution baseline settings
Consider the following solution baselines recommendations:
Group |
Settings |
Recommendations and additional details |
---|---|---|
Intune |
Name and Description |
|
Nerdio Manager for MSP |
|
|
General Enrollment |
Entra |
|
Intune device limit |
|
|
Device clean-up rules |
|
|
Device compliancy |
|
|
Enrollment restrictions |
Android Enterprise (work profile) |
|
IOS / iPad OS |
|
|
MacOS |
|
|
Windows (MDM) |
|
|
Remove existing enrollment restrictions |
|
|
Windows |
Automatic Enrollment |
|
Autopilot Enrollment |
|
|
Enrollment Status Page |
|
|
Local Administrator Passwords Solution (LAPS) |
|
|
Windows Update for Business Reports |
|
|
Policy Baseline deployment |
|
|
Apple |
Enrollment types |
|
Diagnostics |
Windows |
|
General |
|
|
Prerequisites |
License |
|
Permissions |
|
|
Windows |
|
|
Apple |
|
|
|
SharePoint and OneDrive: Recommended solution baseline settings
Consider the following solution baselines recommendations:
Group |
Settings |
Recommendations and additional details |
---|---|---|
Sharing |
Name and Description |
|
External Sharing |
|
|
Access Control |
Modern authentication |
|
SharePoint |
Notifications |
|
Pages |
|
|
OneDrive |
Retention |
|
Sync |
|
|
Prerequisites |
Licenses |
|
Permissions |
|
|
Summary |
Summary |
This provides a high-level overview of how enabling the solution baseline affects the customer. It includes Enforce, Report-only, and Exclude mode details per each configuration tab. |
Options |
|
Teams: Recommended solution baseline settings
Consider the following solution baselines recommendations:
Group |
Settings |
Recommendations and additional details |
---|---|---|
Teams & Channels |
Name and Description |
|
Teams Settings |
|
|
External Collaborators |
Guest Access Settings |
|
Calling |
|
|
Meeting |
|
|
Messaging |
|
|
External access |
|
|
Meetings & Events |
Meeting scheduling |
|
Meeting Join & Lobby |
|
|
Meeting Engagement |
|
|
Content Sharing |
|
|
Recording & Transcription |
|
|
Participants |
|
|
Voice & Messaging |
|
Coming soon. Follow the Release Notes page for updates. |
Prerequisites |
License Validation |
|
Permissions |
|
|
Summary |
Summary |
This provides a high-level overview of how enabling the solution baseline affects the customer. It includes Enforce, Report-only, and Exclude mode details per each configuration tab. |
Options |
|
Comments (0 comments)