Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
Productivity SuitePLAIN-LANGUAGE GUIDE

Microsoft 365 setup guide

Email, files, Teams, and identity for the whole company. Work through the ten requirements below — each has a diagram and a checklist you can follow click by click.

Print checklist ↧
Before you store CUI here

Commercial Microsoft 365 is generally NOT authorized to store CUI. Most ITAR / CUI contractors need Microsoft 365 GCC High.

REQUIREMENT 01 OF 10

Phishing-Resistant Multi-Factor Authentication

IT-013.5.3IA.L2-3.5.3
IN PLAIN WORDS

A password is like a house key that anyone can copy if they trick you into handing it over. Phishing-resistant MFA uses a physical security key or your face/fingerprint that is tied to the real login page, so a fake website can't steal it. Even if a hacker knows your password, they can't get in without the key that's physically with you.

WHY IT MATTERS

Stolen passwords are the number-one way attackers break into cloud accounts, and text-message or app-tap codes can still be phished; without phishing-resistant MFA an admin account takeover can expose the whole tenant.

TOOLS YOU WILL USE
Microsoft Entra IDConditional AccessAuthentication strengthsFIDO2 security keysWindows Hello for Business
HOW THE SETUP FLOWS
  1. 1List admins
  2. 2Enable FIDO2 keys
  3. 3Enroll admins
  4. 4Report-only test
  5. 5Enforce policy
  6. 6Block legacy auth
STEP-BY-STEP CHECKLIST
Pro tip

Always exclude two break-glass accounts before you enforce, or a bad policy can lock every admin out of the tenant.

Government cloud & CUI

Commercial (Entra ID) tenants are generally NOT authorized to store CUI; for ITAR/CUI you typically need GCC High, where these same phishing-resistant MFA controls exist and are required for DFARS 252.204-7012 compliance.

EVIDENCE TO KEEP
Conditional Access policy export (JSON)Authentication methods registration reportSign-in logs showing phishing-resistant sign-ins
See the full IT-01 practice guide →
FAQ

Frequently asked questions

What does the Microsoft 365 setup guide cover?

It walks through ten security requirements — including phishing-resistant multi-factor authentication, least-privilege access control, asset & account inventory, and more — mapped to the DoW Brilliant at the Basics IT Top 10 and to NIST SP 800-171 / CMMC Level 2. Each requirement has a plain-language explanation, a process-flow diagram, and a click-by-click checklist.

Where do I perform these M365 steps?

In the Microsoft 365 admin center + Microsoft Entra admin center. Every step names the exact portal or console path to follow.

Is my checklist progress saved anywhere?

Your step checklist progress is saved only in your own browser (local storage). Nothing is sent to the site, and you can reset it at any time.

Can I store CUI in commercial Microsoft 365?

Generally no. Commercial Microsoft 365 is typically not authorized to store Controlled Unclassified Information (CUI). Most ITAR and CUI contractors need Microsoft 365 GCC High.

What is the government-cloud version of Microsoft 365?

Microsoft 365 GCC High — a US-sovereign environment with FedRAMP High and DoD Impact Level 4/5 authorization, operated by screened US persons — is the standard choice for CUI and ITAR workloads.