Microsoft Security Insights
Practical guidance on Microsoft 365 security, Azure protection, Sentinel SIEM, and managed detection and response. Written by security engineers who configure, harden, and monitor Microsoft environments every day.
Is Outlook HIPAA Compliant? Email Rules, Encryption, and the BAA
Outlook with Exchange Online is in Microsoft's BAA scope; Outlook.com is not. When emailing PHI is permitted and the settings that make it defensible.
Read moreIs OneDrive HIPAA Compliant? BAA Coverage and Required Settings
OneDrive for Business is in Microsoft's BAA scope; personal OneDrive is not. The sharing, DLP, and device settings that make it defensible for PHI.
Read moreIs Microsoft Copilot HIPAA Compliant? BAA Scope and Setup Guide
Microsoft 365 Copilot is in Microsoft's BAA scope, but only a configured tenant supports HIPAA compliance. What to set up before rollout.
Read more7 Conditional Access Policies Every M365 Tenant Should Review
Most Microsoft 365 tenants don’t get breached because Entra ID lacks security controls. They get breached because the right Conditional Access policies were never
Read moreNew Microsoft security guidance, when it lands.
One email when we publish. Practitioner analysis on detection, response, and hardening. No product pitches, unsubscribe anytime.



