Businesses run on Baseline.
Security is not a pile of products. It is a maintained standard.
Baseline builds security into employee sign-in, company computers, access, and Microsoft 365, then keeps those settings consistent over time.
- One documented setup, used for every customer
- Preventive controls built in, not bolted on
- Administrative handoff on exit
The operating model
Security that arrives already turned on.
Baseline turns on the security tools included with Microsoft 365 Business Premium, applies the same settings to every supported employee and computer, and keeps those settings consistent over time.
Most small businesses already pay for these tools. What is usually missing is somebody turning them on everywhere and keeping them that way. The nine sections below are what Baseline actually sets up, in plain language first and Microsoft product names second.
One
One company sign-in, without a normal password.
Each employee gets one company account for email, files, apps, and computer access. They use a face, fingerprint, or device PIN instead of a normal password.
The technical detail
- Microsoft Entra for the company sign-in
- Windows Hello on supported company computers
- Passkeys, which stay on a device the employee already controls
Two
Computers watched for suspicious behavior.
Microsoft Defender for Business protects supported company computers against malware and suspicious activity. Its endpoint detection and response technology helps find, investigate, and respond to threats.
The technical detail
- Microsoft Defender for Business
- Endpoint detection and response, or EDR
- Real-time protection and behavior monitoring
- Automated investigation and remediation, which can act on many threats but is not promised to resolve every one
- Microsoft Defender for Business is built on Microsoft Defender for Endpoint technology.
Three
Email links and attachments checked.
Microsoft Defender for Office 365 Plan 1 checks messages, links, and attachments for phishing, malware, and impersonation attempts.
The technical detail
- Microsoft Defender for Office 365 Plan 1
- Exchange Online Protection
- Safe Links
- Safe Attachments
- Anti-phishing and impersonation protection
- Protection for supported links and files in Teams, OneDrive, and SharePoint
Four
Risky websites blocked.
Web filtering can block selected categories of unsafe or inappropriate websites on supported company computers, including when an employee is away from the office.
This reduces exposure to known categories of risky sites. It is not a promise that every malicious site is blocked.
The technical detail
- Microsoft Defender for Business web content filtering
- Applies to supported browsers on supported company computers
Five
A lost laptop is not an open drive.
BitLocker encrypts the computer drive. If a laptop is lost or stolen, somebody cannot simply remove the drive and read the files on another computer.
Encryption protects the drive. It does not make a lost laptop harmless, and no single control guarantees data can never be reached.
The technical detail
- BitLocker drive encryption
- Enabled and managed on compatible supported devices
- Recovery keys held in your company’s Microsoft setup
Six
Common work folders are protected in OneDrive.
Desktop, Documents, and Pictures are automatically saved to OneDrive. Common work files are not trapped on one laptop, and they come back when a replacement computer is set up.
This protects those folders. It is not a backup of the whole computer, of installed programs, or of files saved somewhere else on the drive.
The technical detail
- OneDrive Known Folder Move
Seven
Firewall settings stay on and consistent.
Windows Firewall is turned on and managed as part of the standard. Employees do not have to find it, configure it, or remember to keep it running.
The technical detail
- Windows Firewall, managed through Microsoft Defender for Business and Microsoft Intune
Eight
Security settings arrive automatically.
When a supported computer joins Baseline, the security settings are delivered automatically. When Baseline updates the standard, the new settings can be applied across supported computers without asking every employee to change anything by hand.
The technical detail
- Microsoft Intune
- Policy-based configuration
- Device enrollment and central management, which is the technical name for connecting a computer to Baseline
Nine
Access ends in one place.
When an employee leaves, a manager starts the shutdown from the Manager Portal. Their company sign-in controls email, files, apps, and computer access, so removal starts from one place.
Baseline starts the change immediately. Microsoft may take a few minutes to finish applying it.
Ten
What runs continuously, and what does not.
What runs continuously
The security tools run continuously. They do not stop at 5:00 p.m. Microsoft Defender can detect threats and carry out automated investigation and remediation actions at any hour.
What Baseline does not provide
Baseline does not provide a human security team watching and responding to every alert 24 hours a day. That service is usually called a security operations center, or SOC.
A client, insurer, or industry rule may require specific settings. Baseline will compare those requirements with the exact standard used for your company and explain what matches and what does not.
The next step
Bring your hardest technical question.
The first conversation is where the configuration gets described in detail against what your business actually has to satisfy.
In 30 minutes, we will map how your company works today, show what Baseline would change, and outline the clearest path forward.