M365 security was designed to manage one tenant… MSPs manage more.
The challenge isn't knowing how to secure Microsoft 365; instead, we must keep security consistent across every customer. Manually checking tenant after tenant doesn't scale!
Cybersecurity

Microsoft 365 has no shortage of security features. Conditional Access, Defender, Intune, MFA, mailbox controls, identity management, and more give MSPs plenty of tools to secure their customers. What we do (or rather, don’t do) with these tools is what causes issues. These tools and settings must be configured correctly across every tenant, and we need to be sure they stay that way.
For an MSP managing a handful of customers, manually checking these settings might not seem like a big deal... As your customer base grows, though, the amount of work increases significantly: One tenant has a different Conditional Access configuration. Another has a few dormant accounts. Someone added an exception to a policy three months ago and forgot about it. A former employee still has access to a shared mailbox. One customer has a completely different security standard because they were onboarded before your current processes were in place.
While none of these issues are particularly complicated on their own, the problem is locating and resolving them quickly and consistently across all your customer environments.
Security standardization
Most MSPs already have some kind of security standard they want to apply to their customers. Many MSPs use onboarding checklists, or PowerShell scripts. Many also have extensive documentation on their preferred Conditional Access policies, Defender configurations, or Microsoft 365 security controls.
These are all good things! Standardization gives your technicians something to work toward and gives your customers a consistent level of service. The problem comes when you must maintain the same standard across dozens of tenants.
We've seen this come up repeatedly in discussions with MSPs and in the wider MSP community. One of the common requests is the ability to configure something once and then apply that configuration across multiple tenants, rather than logging into each customer environment and repeating the same work. This makes sense! If you've already decided what a secure Microsoft 365 tenant should look like, why should your technicians have to manually recreate that configuration every time?
Post-onboarding troubles
Getting a customer to your security standard is only the beginning. Microsoft 365 environments are constantly changing. Over time, these changes can create configuration drift.
For example, a Conditional Access policy might originally exclude a small number of users for a legitimate reason. A few months later, that exclusion group has grown considerably. The policy is still enabled, but it isn't necessarily providing the same level of protection it did when it was first configured.
Additionally, the same thing can happen with permissions. For example: A technician gives someone access to a shared mailbox to troubleshoot an issue. An administrator is added to a privileged role temporarily. A service account is created for a project. The project finishes, but nobody goes back and removes access.
This is one of the key reasons regular security reviews are so important. On top of that, this is also one of the reasons manual security reviews become so difficult to maintain as an MSP grows.
Lots of settings to track
M365 security isn’t just “turn on MFA and call it a day”. There are lots of smaller settings that can make huge impacts on your overall security posture. For example:
- Are all users actually protected by your MFA policies?
- Are there broad exclusions in your Conditional Access policies?
- Are dormant users still enabled?
- Are former employees still assigned permissions?
- Are there external mailbox forwarding rules that shouldn't be there?
- Are shared mailboxes being accessed by users who no longer need access?
- Can users grant applications access to organizational data?
- Are legacy authentication methods still enabled?
- Are your break-glass accounts configured correctly?
- Are administrators being given more access than they need?
These are the types of issues MSPs find during M365 security reviews. In fact, we’ve previously covered some of the most common security gaps MSPs find when onboarding new customers. You can read more here: https://www.octiga.io/insights/the-top-5-microsoft-365-security-gaps-msps-find-in-new-customer-tenants
The issue isn’t just knowing that these settings exist. Instead, MSPs must check them frequently to make sure security gaps haven’t opened. This is the Achilles heel of manual reviews. Of course, manual security reviews are important and have their place in an MSPs toolkit, but relying on them as a primary way of maintaining security can cause problems the more your customer base grows.
If your team has to log into every tenant, check hundreds of settings, compare those settings against your standards, document the differences, and then make the necessary changes, you're wasting a lot of time doing the same work over and over again. As we've discussed before, manual reviews can lead to configuration changes going unnoticed, different security standards between customers, and senior engineers becoming responsible for most security reviews. Unfortunately, that isn’t all; there’s also another problem.
If your process relies on someone remembering to check something, what happens if/when they don’t? This is where automated processes become important. This is why management platforms like Octiga have become so popular with MSPs, they can make it much easier to manage multiple Microsoft 365 environments and reduce some of the repetitive work involved in administration.
There is still a catch, though. Automation is only as useful as the process behind it. A PowerShell script can tell you that a setting is wrong, but a technician still needs to investigate it. A management platform can help deploy a configuration, but what happens when someone changes that configuration later, or an exception arises? A baseline can tell you what a secure tenant should look like, but how do you know when the tenant no longer matches that baseline?
This is where continuous monitoring becomes important. Instead of checking a tenant every few months and hoping nothing has changed in between, you can continuously monitor the environment and identify when something moves away from your defined standard. This allows your team to address issues as they happen, rather than waiting for the next scheduled security review.
Continuous monitoring
A security baseline gives your team a standard to work toward. It tells your technicians what a secure Microsoft 365 tenant should look like and gives you a way to identify where a customer is falling short. However, a baseline is only the beginning.
Your customer environment is going to change. Users will come and go, policies will be modified, new applications will be introduced, and customers will inevitably have legitimate reasons for requesting exceptions.
The important thing is knowing when those changes happen and whether they introduce a security gap.
This is why continuous monitoring and automated remediation are so important. Rather than relying on a technician to remember to check a setting during the next security review, an automated process can identify the change and bring it to your team's attention.
In some cases, the issue can even be remediated automatically. This doesn't mean that every change should automatically be reverted. There are plenty of legitimate reasons why a customer may need a different configuration. Instead, your team should be able to understand what changed, why it changed, and whether the change needs to be addressed.
This is where having a defined security standard becomes especially useful.
If you already know what the tenant should look like, it's much easier to identify when something doesn't look right.
Standardizing M365 security with Octiga
This is one of the problems we wanted to solve with Octiga. MSPs shouldn't have to manually check every customer tenant just to make sure the same security standards are still being followed.
With Octiga, you can define the security standards you want your customers to follow and apply those standards across your customer base. From there, Octiga continuously monitors the environment and identifies when something changes or falls out of compliance.
This gives your technicians a much more consistent process to follow. Instead of manually checking hundreds of settings across dozens of tenants, they can focus their attention on the areas that actually need it.
Octiga can also automatically remediate supported issues, which means your team doesn't necessarily have to manually fix the same problem every time it appears.
This is particularly useful for MSPs because the goal isn't just to secure one customer. The goal is to provide the same level of security to every customer. As already discussed, as your customer base grows, that becomes increasingly difficult to do manually.
Beyond security baselines
This is also why we don't view Octiga as simply a security baseline tool.
Baselines are an important part of the platform, but M365 security is much bigger than a checklist of settings. MSPs need visibility into what is happening across their tenants, the ability to identify security gaps, and ways to act on those issues without creating more manual work for their technicians.
Octiga helps bring these processes together in one place. You can monitor Microsoft 365 security configurations, track changes, identify gaps, and automate remediation where appropriate. This gives your team a way to move away from the traditional model of periodically checking each tenant and instead move toward continuously managing security.
We've talked about this before in our article on the evolution of Octiga from a baseline and Secure Score tool into a Microsoft 365 security operations platform. You can read more about that here: https://www.octiga.io/insights/separating-yesterdays-perceptions-from-todays-microsoft-365-security-operations-platform
The goal isn't more alerts
There is one thing worth keeping in mind when talking about automation and monitoring. The goal isn't to give your technicians another dashboard full of alerts and noise. MSPs already have enough alerts! The goal is to reduce the amount of work your technicians need to do manually while making sure important security issues don't get missed.
If a security setting changes, your team should know about it. If a user is given access they shouldn't have, you should be able to identify it. If a tenant falls out of compliance with your standards, you should be able to see it. Even better, the problem can be fixed automatically when it's safe to do so!
This allows your technicians to spend less time checking settings and more time dealing with the issues that actually require their attention.
M365 security should scale with your MSP
At the end of the day, securing one Microsoft 365 tenant isn't particularly difficult. Most MSPs already know what needs to be done. The difficult part is doing it consistently across every
customer, especially as your customer base grows. A security standard that works for five customers should still work when you have fifty. Your technicians shouldn't have to remember
hundreds of settings, and your senior engineers shouldn't have to spend their
time performing the same security review over and over again.
This is where automation can make a huge difference. Instead of relying on individual technicians to remember what needs to be checked, you can define your standards once and apply them across your customer base. From there, continuous monitoring can help make sure those standards remain in place.
That's the real value of security standardization. It isn't about making every customer exactly the same. It's about making sure every customer starts from the same secure foundation and
that you know when something changes.
Define your standards. Apply them across your customer base. Monitor them continuously. Remediate issues when they arise.
That's how M365 security can scale with your MSP.
If you're interested in seeing how Octiga can help you standardize and manage M365 security across your customer environments, start an Octiga trial today.
Subscribe for updates
Curated information for MSPs




