First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Blog/Zero Trust in Microsoft 365: What It Actually Lo…

Zero Trust in Microsoft 365: What It Actually Looks Like in Production

2026-06-16·IT PartnerNewSecurityComplianceMicrosoft 365Zero Trust

Microsoft 365 tenants rarely fail because Zero Trust was ignored. They fail because MFA has exceptions, unmanaged devices still get full access, legacy protocols are left open for one dependency, OAuth app consent is uncontrolled, and nobody owns policy drift after rollout. In production, Zero Trust is not a slogan. It is a set of enforceable controls that reduce common attack paths without blocking legitimate work.

The production problem: the tenant is only partly controlled

A real Microsoft 365 Zero Trust project usually starts with an audit. MFA is enabled for most users, but not every administrator. Conditional Access exists, but it has overlapping policies created by different teams. Exclusions cover executives, scanners, finance users, service accounts, guest users, named locations, or entire countries because something broke during rollout.

Attackers use those gaps. A common path is simple: phish a user, steal or replay a session token, find access from an unmanaged device, consent to or abuse an OAuth app, create mailbox forwarding or inbox rules, search SharePoint and Teams for finance or client data, then exfiltrate quietly. If Basic authentication or other legacy protocols remain available, password spray and credential stuffing become easier.

A production Zero Trust configuration assumes the password may be known, the user may click, the device may be unhealthy, and the attacker will move from identity to data. Each step should require a stronger signal: verified identity, managed device, least privilege, controlled session, monitored activity, and protected data.

Identity: eliminate weak authentication and consent paths

Identity is where most tenants become defensible or stay performative. Start with a clean Conditional Access model, not dozens of policies with unclear ownership.

A practical baseline:

  • Block legacy authentication. Use Conditional Access where applicable, Exchange Online authentication policies, and service-level settings such as SMTP AUTH controls. Do not keep IMAP, POP, Basic authentication, or legacy Office clients alive without a documented exception owner, migration plan, and expiration date.
  • Require phishing-resistant MFA for privileged roles. Use FIDO2 security keys, Windows Hello for Business, or certificate-based authentication where supported and properly configured. Do not rely on SMS or push-only MFA for administrators.
  • Require MFA for all users. If Microsoft Entra ID P2 is licensed, use sign-in risk and user risk policies so medium or high risk triggers stronger authentication, password reset, or block decisions instead of only producing alerts.
  • Require compliant or Microsoft Entra hybrid joined devices for administrative access, including the Microsoft Entra admin center, Microsoft 365 admin center, Exchange admin center, SharePoint admin center, Microsoft Defender portal, Microsoft Purview portal, and Azure management.
  • Disable user consent to applications by default. Use admin consent workflow and review requested permissions, publisher verification, app owner, and business justification before approval.

Emergency access accounts need explicit handling. Maintain two cloud-only break-glass accounts, exclude them from Conditional Access, assign only the roles required for recovery, and store long random passwords in an offline or privileged vault. Do not use them for daily administration. Alert on every sign-in and test them on a schedule. One account can remain password-only for true MFA or Conditional Access outage recovery; the other can use phishing-resistant authentication if it does not depend on the same controls you might need to bypass.

Devices: compliant must mean managed, encrypted, patched, and observable

The Conditional Access grant control “require device to be marked as compliant” only helps if compliance policies are strict enough to matter.

For Windows endpoints, require Intune enrollment or Microsoft Entra hybrid join, BitLocker, Secure Boot where supported, Microsoft Defender Antivirus, current supported operating system versions, and update rings for quality and security updates. Use Microsoft Defender for Endpoint device risk in access decisions where licensing and deployment support it.

For macOS, decide whether Macs are managed or only tolerated. At minimum, enforce FileVault, supported OS versions, password requirements, endpoint protection, inventory, and compliance reporting.

For iOS and Android, full device enrollment is not always the right model. For personally owned devices, Microsoft Intune app protection policies can protect Outlook, Teams, OneDrive, Edge, and Microsoft 365 apps without enrolling the device. Require PIN or biometrics, encrypt app data, restrict copy and paste to unmanaged apps, block saving to personal locations, and wipe corporate app data when the user leaves.

Roll out device enforcement in stages. Start with administrator access. Then enforce it for high-impact apps such as Exchange Online, SharePoint Online, OneDrive for Business, and Teams. For unmanaged devices, use lower-trust access: web-only access, download restrictions, limited session lifetime, and no sync where supported. Contractors, shared devices, kiosks, and executive exceptions should be documented, scoped, and time-bound.

Data: reduce blast radius after the first click

Assume a user will eventually approve something, open something, or lose a session token. Data controls limit the damage.

In Exchange Online, disable automatic external forwarding by default and allow it only by exception. Monitor inbox rules that forward, delete, hide, or move messages to unusual folders. Use Exchange Online Protection for baseline anti-spam, anti-malware, and anti-phishing. If Microsoft Defender for Office 365 is licensed, enable Safe Links, Safe Attachments, and impersonation protection for executives, finance, HR, IT, and other high-risk groups.

In SharePoint Online and OneDrive for Business, anonymous sharing links should not be the default. Scope external sharing by site sensitivity. Finance, legal, board, M&A, HR, source code, and client-data sites should have tighter sharing settings, limited external domains where appropriate, sensitivity labels where the organization can maintain them, and owner review.

Microsoft Purview Data Loss Prevention should start narrow. Use high-confidence policies for financial data, identity documents, health data, source code, and regulated client content. Broad DLP policies that generate thousands of false positives get bypassed or disabled. Production DLP blocks or warns on specific risky actions, alerts the right owner, and is tuned regularly.

Access: least privilege must be operational

Most tenants have too many standing administrators. Use Microsoft Entra Privileged Identity Management, which requires Microsoft Entra ID P2 or suites that include it, for eligible access instead of permanent role assignment. Keep Global Administrator rare. Separate Exchange Administrator, SharePoint Administrator, Teams Administrator, Security Administrator, Compliance Administrator, and User Administrator by job function.

A workable model is direct: standard accounts for daily work, separate administrator accounts for privileged work, just-in-time activation with justification, MFA, approval for high-impact roles, and short activation windows. Do not allow privileged activation from unmanaged devices. Require phishing-resistant MFA for the roles that can change identity, mail flow, security, compliance, or tenant-wide settings.

Apply the same discipline to applications. Review enterprise applications and app registrations for permissions, owners, sign-in activity, credential age, publisher verification, and consent history. Any app with permissions such as Mail.ReadWrite, Files.ReadWrite.All, Sites.ReadWrite.All, Directory.ReadWrite.All, RoleManagement.ReadWrite.Directory, or offline_access needs a clear owner and business purpose. Remove stale apps and expired integrations.

Guest access needs ownership. Use access reviews where licensed, expiration where possible, and restrictions on guest enumeration and sharing. The risk is not one guest account. The risk is years of accumulated guests with no sponsor, no review, and access to Teams or sites that still contain sensitive work.

The finished state: fewer exceptions, better telemetry, measurable risk reduction

A production Microsoft 365 Zero Trust tenant is easier to explain and harder to abuse. Conditional Access policies are fewer and named by purpose. Exceptions have owners and expiration dates. Legacy authentication is blocked. Administrator access requires phishing-resistant MFA and managed devices. Unmanaged devices receive restricted sessions, not full trust. External sharing is intentional. High-impact data locations are protected before the organization tries to classify everything.

Licensing matters, but it should follow control maturity. Microsoft 365 Business Premium gives many small and midsize organizations a strong base: Microsoft Entra ID P1, Intune, Defender for Business, Defender for Office 365 Plan 1, and core Purview capabilities. Microsoft 365 E3 includes strong management and identity foundations but may need add-ons for Entra ID P2, advanced email protection, advanced endpoint protection, identity risk, Privileged Identity Management, access reviews, or broader compliance features. Microsoft 365 E5 and security/compliance add-ons can be valuable, but buying advanced tooling before enforcing baseline controls usually creates shelfware.

Measure the rollout. Track MFA coverage, legacy authentication attempts, Conditional Access exclusions, unmanaged device access, privileged role activations, stale privileged accounts, risky sign-ins, external forwarding attempts, anonymous sharing links, high-impact sharing events, and DLP policy outcomes. If those numbers are not improving, the Zero Trust program is not changing the tenant.

Control area Production baseline Microsoft 365 implementation points Evidence to track
Legacy authentication Block weak protocols and Basic authentication paths Conditional Access client app controls where applicable; Exchange Online authentication policies; disable SMTP AUTH unless explicitly required Legacy auth sign-in attempts; SMTP AUTH exceptions; exception expiration dates
Administrator access Phishing-resistant MFA, managed device, least privilege Conditional Access; FIDO2, Windows Hello for Business, or certificate-based authentication; Microsoft Entra Privileged Identity Management Admins without phishing-resistant MFA; standing privileged roles; PIM activations
User MFA MFA for all users with risk-based escalation where licensed Conditional Access; Microsoft Entra ID Protection with Entra ID P2 MFA registration coverage; risky users; risky sign-ins; blocked or remediated events
Device trust Compliance means encrypted, supported, protected, and managed Intune compliance policies; update rings; Microsoft Defender for Endpoint integration where licensed Noncompliant devices; unmanaged access; unsupported OS versions; device risk
Mobile access Protect corporate data on personal devices Intune app protection policies for Outlook, Teams, OneDrive, Edge, and Microsoft 365 apps App protection coverage; blocked copy/paste or save actions; selective wipes
OAuth and apps No uncontrolled user consent; review high-permission apps Disable user consent; admin consent workflow; enterprise app and app registration reviews New consents; apps with high-risk permissions; stale credentials; ownerless apps
Exchange Online Prevent stealthy mail exfiltration Disable external forwarding by default; monitor inbox rules; EOP; Defender for Office 365 where licensed Forwarding exceptions; suspicious inbox rules; phishing detections
SharePoint and OneDrive Restrict high-impact sharing Site-level sharing controls; sensitivity labels; domain allow/deny lists where appropriate Anonymous links; external users; sharing events on sensitive sites
Data loss prevention Start narrow and tune Microsoft Purview DLP for high-confidence regulated or sensitive data Policy matches; false positives; user overrides; blocked actions
Guest access Guests have sponsors, scope, and review Access reviews where licensed; guest restrictions; Teams and SharePoint ownership Stale guests; guests without sponsor; sensitive sites with external users

Key takeaways

  • Production Zero Trust in Microsoft 365 starts by closing weak paths: legacy authentication, standing admin rights, unmanaged devices, excessive app consent, and uncontrolled external sharing.
  • Conditional Access should be simpler, stricter, and owned. Exceptions need scope, justification, and expiration.
  • Device compliance must mean encrypted, patched, managed, supported, and observable. Otherwise it is only a checkbox.
  • Data controls should start with the sites, mailboxes, Teams, and repositories that would create the largest breach impact.
  • Licensing matters, but operating discipline matters more. Enforce the controls you already own before buying advanced tools.

If you need a practical rollout plan, IT Partner can help assess your tenant, prioritize controls, and implement Microsoft 365 Zero Trust architecture through our Microsoft Zero Trust Architecture Implementation service. The focus is configuration, rollout sequencing, licensing tradeoffs, and measurable risk reduction.

Questions this article didn’t answer?

Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.