What Microsoft 365 solution baseline settings are recommended?
This article outlines the recommended settings for Microsoft 365 solution baselines, helping you align with best practices while optimizing user experience, performance, and security. Adjust these settings as needed to meet your organization's requirements and compliance needs.
Important!
These recommendations follow Microsoft's best practices and Nerdio’s expertise from years of experience. Before implementing these changes, consult with your Security and Operations teams.
Before configuring your solution baseline, we recommend cloning it to ensure a fresh starting point. For details, see Solution Baselines: MSP-level Management.
Consider the following solution baselines recommendations:
Defender for Endpoint: Recommended solution baseline settings
SharePoint and OneDrive: Recommended solution baseline settings
Defender for Endpoint: Recommended solution baseline settings
Consider the following solution baselines recommendations:
Group |
Settings |
Recommendations and additional details |
---|---|---|
Prerequisites |
Name and Description |
These settings allow you to assign a unique name and description to each baseline, making it easier to determine its applicability for a customer. |
License validation |
This setting is report-only because there is no enforcement action. |
|
Permissions |
This setting is report-only because there is no enforcement action. It verifies if the correct API permissions are applied. |
|
Enable Defender for Endpoint in Nerdio Manager for MSP |
|
|
Integrations |
Intune |
|
Entra – Conditional Access |
|
|
Device Onboarding |
Device Onboarding |
|
Baseline Endpoint Security Policies |
|
|
Notifications |
Notifications |
|
Summary |
Summary |
This provides a high-level overview of how enabling the solution baseline affects the customer. It includes Enforce, Report-only, and Exclude modes. |
Options |
|
Entra ID: Recommended solution baseline settings
Consider the following solution baselines recommendations:
Group |
Settings |
Recommendations and additional details |
---|---|---|
General |
Name and Description |
These settings allow you to assign a unique name and description to each baseline, making it easier to determine its applicability for a customer. |
M365 Org Settings |
|
|
Identity |
Users |
|
Groups |
|
|
External Identities |
|
|
Enterprise Apps |
|
|
Auth & Passwords |
Registration Campaign |
|
Summary |
Summary |
This provides a high-level overview of how enabling the solution baseline affects the customer. It includes Enforce, Report-only, and Exclude modes. |
Options |
|
Exchange Online: Recommended solution baseline settings
Consider the following solution baselines recommendations:
Group |
Settings |
Recommendations and additional details |
---|---|---|
Prerequisites |
Name and Description |
These settings allow you to assign a unique name and description to each baseline, making it easier to determine its applicability for a customer. |
Licenses |
|
|
Permissions |
|
|
Organization |
Default domain |
|
Authentication |
|
|
Add-ins |
|
|
Mail flow settings |
General |
|
Security |
|
|
Reply-all storm protection |
|
|
Message Recall |
|
|
Mailbox settings |
Security |
|
Retention |
|
|
Sharing |
|
|
User preferences |
|
|
Exchange Online Protection (EOP) |
Anti-malware |
|
Anti-spam |
|
|
Anti-phishing |
|
|
Summary |
Summary |
This provides a high-level overview of how enabling the solution baseline affects the customer. It includes Enforce, Report-only, and Exclude modes. |
Options |
|
SharePoint and OneDrive: Recommended solution baseline settings
Consider the following solution baselines recommendations:
Group |
Settings |
Recommendations and additional details |
---|---|---|
Sharing |
Name and Description |
These settings allow you to assign a unique name and description to each baseline, making it easier to determine its applicability for a customer. |
External Sharing |
|
|
Access Control |
Modern authentication |
|
SharePoint |
Notifications |
|
Pages |
|
|
OneDrive |
Retention |
|
Sync |
|
|
Prerequisites |
Licenses |
|
Permissions |
|
|
Summary |
Summary |
This provides a high-level overview of how enabling the solution baseline affects the customer. It includes Enforce, Report-only, and Exclude modes. |
Options |
|
Teams: Recommended solution baseline settings
Consider the following solution baselines recommendations:
Group |
Settings |
Recommendations and additional details |
---|---|---|
Teams & Channels |
Name and Description |
These settings allow you to assign a unique name and description to each baseline, making it easier to determine its applicability for a customer. |
Teams Settings |
|
|
External Collaborators |
Guest Access Settings |
|
Calling |
|
|
Meeting |
|
|
Messaging |
|
|
External access |
|
|
Meetings & Events |
Meeting scheduling |
|
Meeting Join & Lobby |
|
|
Meeting engagement |
|
|
Content Sharing |
|
|
Recording & Transcription |
|
|
Participants |
|
|
Voice & Messaging |
|
Coming soon. Follow the Release Notes page for updates. |
Prerequisites |
License Validation |
|
Permissions |
|
|
Summary |
Summary |
This provides a high-level overview of how enabling the solution baseline affects the customer. It includes Enforce, Report-only, and Exclude modes. |
Options |
|
Comments (0 comments)