Exchange Online is the workload where a baseline stops being an internal matter. Everything in the identity wave defends accounts you control. Mail is the one surface any stranger can address directly, unauthenticated, several thousand times an hour, using your own domain name if you have not stopped them. This is the frame for the Exchange baseline: what it covers, what has moved under it, and why the version of this list you were given two years ago now contains recommendations that describe work Microsoft has already done for you.
The conventions are the ones set in the first series and I will not restate them. Tiered items, grouped by control-plane domain rather than by portal blade, each carrying the reasoning, the durable product noun and the value, with the automation equivalent consolidated per section. What is worth saying here is which of those domains Exchange actually occupies, because it is not all of them and pretending otherwise produces a checklist padded with rows that belong to another product.
Which domains this series occupies
Data and Email is the centre of gravity and it is the domain the identity series deliberately left empty. That is where mail authentication lives, where the threat policies live, and where retention and archiving decisions get made. If you read only one part of this series, read that one.
Identity and Access appears again here, but narrowly, and only where Exchange carries protocol history that the identity controls cannot reach. Basic authentication over mail submission, sign-in on mailbox accounts nobody thinks of as accounts. These are identity problems that live inside a mail product, which is exactly why they get missed by both reviews.
Monitoring and Response covers the audit record, the alerting that goes with it, and where user-reported mail ends up. Device Trust appears once, for the restrictions worth placing on Outlook when the device is not managed. Tenant Governance appears once, for the legacy collaboration objects that accumulate in every estate older than five years. Application Trust, External Trust and the rest of Device Trust belong to other series and I will not duplicate them.
Four things that changed, and why an old list is now actively misleading
I want to name these at the front rather than burying them in the tiers, because each one turns a familiar recommendation into either a no-op or a mistake, and because the pattern behind them is the point of this whole pillar.
Inbound DMARC honouring is on by default, and it rejects. The anti-phishing policy now honours the sending domain’s published policy in the default policy, not only in the presets: quarantine on quarantine, reject on reject. Telling a reader to switch this on describes work already done. The decision that replaces it is the opposite one, and it is harder: mail from partners with a broken strict policy is now being rejected outright on their instruction, and if a third-party gateway sits in front of your tenant the honouring silently does nothing at all unless enhanced filtering is configured on that connector.
External auto-forwarding is already blocked. The outbound policy default now behaves identically to the explicit off position. The row survives, because an explicit setting is auditable and a default is not, and because the compliance baselines check a different surface entirely. But it is no longer the open exfiltration path it is usually presented as, and presenting it that way costs you credibility with anyone who checks.
Defender for Office 365 Plan 1 is included with E3 as of the first of July 2026. Every argument that starts with an E3 tenant only getting the basic protection stack is now false. Impersonation protection, Safe Links and Safe Attachments are available to a population that was previously told to upgrade or do without, which changes the recommendation for most of the mid-market rather than merely adjusting a licensing footnote. It does not grant Plan 2, so the investigation and training capabilities remain out of reach.
The audit log is off by default on exactly the licences this pillar is mostly written about. It is on for Microsoft 365 organisations generally and explicitly not enabled by default on Business Basic, Business Standard or Business Premium. For a small or mid-sized estate that is not an edge case, it is the common case, and it means the one control that cannot be applied retroactively is the one most likely to be missing.
The part that is not a setting at all
Exchange Online is on a clock in a way no other workload in this pillar currently is. Exchange Web Services stops working. Basic authentication over mail submission stops working. Two client-side surfaces have already gone. These are not hardening opportunities, they are dated obligations with discovery work attached, and the discovery is the expensive half. An organisation that finds out in March 2027 which of its applications used Exchange Web Services has found out too late to do anything but panic.
Alongside them sit a small number of decisions that are quietly irreversible. Enabling auto-expanding archiving cannot be undone and costs you the ability to recover an inactive mailbox later, which is a trade almost nobody is told they are making. That combination, dated retirements and one-way doors, gets its own article rather than a row in a table, because a checklist is the wrong shape for something organised by calendar rather than by control.
What this series contains
| Article | What it covers |
|---|---|
| [BP 2.1] The Critical Tier | The controls I will not hand over a tenant without. Mail authentication end to end, the protocols that predate the policy, and the audit record you cannot create retrospectively. |
| [BP 2.1.1] Build Sheet: Mail Authentication to Enforcement | SPF, DKIM and DMARC from nothing to a rejecting policy on a worked estate, plus the channel half that most baselines never reach. |
| [BP 2.2] Recommended and Optional Tiers | Threat policies and why I use Microsoft’s presets, where user-reported mail actually goes, Outlook restrictions, and the retention and archiving decisions. |
| [BP 2.3] Retirements and One-Way Doors | What Exchange Online stops doing and when, what the discovery work is, and the handful of choices you cannot walk back. |
| [BP 2.4] The Exchange Online Quick Checklist | Every action above as a scannable list, each row cross-referenced to the article that defends it. |
One anchoring note carried over from the first series. I map tier assignments against the federal SCuBA baseline where a corresponding control exists, because it is quotable, stable and free, and because a client’s auditor recognises it. Be aware that its Exchange section was restructured and a good deal of published commentary still cites identifiers that no longer exist. Where SCuBA has no control, and it has none for archiving, deleted-item retention, user reporting or transport-layer authentication, I say so rather than inventing a mapping. A federal floor is a floor, not a ceiling, and the gaps in it are where most of the interesting decisions live.
Best Practices
‹ Previous: [BP 1.5] The Entra ID Quick Checklist
Next: [BP 2.1] The Exchange Online Baseline: The Critical Tier ›




