Category Best Practices

[BP 2.4] The Exchange Online Quick Checklist

Overhead view of a blank clipboard and pen surrounded by eight squared stacks of blank cards

Every action from the Exchange Online baseline as a scannable list, with the way to check each one and a pointer to the article that argues for it. Tiered critical, recommended and optional, grouped by control-plane domain.

[BP 2.1.1] Build Sheet: Mail Authentication to Enforcement

Three brass dies in ascending order on a slate bench with rule and dividers

Taking a domain from no email authentication at all to a rejecting DMARC policy, on a worked estate, then going one layer further and authenticating the transport as well as the message. Includes the negative test that most implementations skip and the only one that proves anything.

[BP 2.1] The Exchange Online Baseline: The Critical Tier

Hands pressing a brass seal into amber wax on a blank letter

The controls I will not hand over a tenant without. Mail authentication end to end, including the DKIM record format that changed underneath every build guide, the protocols that predate your Conditional Access policy, and the audit log that is off by default on exactly the licences most estates run.

[BP 2] Exchange Online: The Surface Strangers Can Reach

Envelopes pushed through a letter slot and fanned across the floor, one hand picking one up

Every control in the identity baseline defends accounts you own. Mail is the one surface any stranger can address directly, unauthenticated, thousands of times an hour. This is the frame for the Exchange baseline, and the four platform changes that turned familiar recommendations into no-ops.

[BP 1.5] The Entra ID Quick Checklist

The whole Entra baseline compressed into a list you can run down in an afternoon. Every action the reasoned articles defended, grouped by the eight control-plane domains and tiered by obligation.