Data Protection
Practical guidance on Microsoft 365 security, Azure protection, Sentinel SIEM, and managed detection and response. Written by security engineers who configure, harden, and monitor Microsoft environments every day.
Is Outlook HIPAA Compliant? Email Rules, Encryption, and the BAA
Outlook with Exchange Online is in Microsoft's BAA scope; Outlook.com is not. When emailing PHI is permitted and the settings that make it defensible.
Read moreIs OneDrive HIPAA Compliant? BAA Coverage and Required Settings
OneDrive for Business is in Microsoft's BAA scope; personal OneDrive is not. The sharing, DLP, and device settings that make it defensible for PHI.
Read moreIs Microsoft Copilot HIPAA Compliant? BAA Scope and Setup Guide
Microsoft 365 Copilot is in Microsoft's BAA scope, but only a configured tenant supports HIPAA compliance. What to set up before rollout.
Read moreIs Microsoft Teams HIPAA Compliant? Configuration Guide
Microsoft Teams is not HIPAA compliant by default. Learn which plans qualify, how to configure access controls, DLP, and retention for PHI protection.
Read moreNew Microsoft security guidance, when it lands.
One email when we publish. Practitioner analysis on detection, response, and hardening. No product pitches, unsubscribe anytime.



