Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
BRILLIANT AT THE BASICS · CLOUD SETUPMicrosoft 365
Productivity Suite

Security Setup Checklist

70 steps across the ten Brilliant at the Basics requirements. Check each box as you complete it. Confirm every step against Microsoft 365’s own documentation before you rely on it.

Where you work
Microsoft 365 admin center + Microsoft Entra admin center
Content reviewed
2026-07-21
Prepared for
________________________________
Date started
________________________________
Before you store CUI here

Commercial Microsoft 365 is generally NOT authorized to store CUI. Most ITAR / CUI contractors need Microsoft 365 GCC High.

01

Phishing-Resistant Multi-Factor Authentication

IT-013.5.3IA.L2-3.5.3

Evidence to keep: Conditional Access policy export (JSON) · Authentication methods registration report · Sign-in logs showing phishing-resistant sign-ins

02

Least-Privilege Access Control

3.1.5AC.L2-3.1.5

Evidence to keep: PIM role settings export · List of eligible vs. permanent role assignments · Completed access review report

03

Asset & Account Inventory

IT-023.4.1CM.L2-3.4.1

Evidence to keep: Intune All devices export (CSV) · Entra Users and Devices export · Enterprise applications list

04

Logging, Monitoring & Audit

3.3.1AU.L2-3.3.1

Evidence to keep: Screenshot of UnifiedAuditLogIngestionEnabled = True · Sample audit log search export · Audit retention policy configuration

05

Network Segmentation & Boundary Protection

IT-053.13.5SC.L2-3.13.5

Evidence to keep: Named locations configuration export · Conditional Access policy set export · Global Secure Access / Private Access app list

06

Vulnerability & Patch Management

IT-063.11.2RA.L2-3.11.2

Evidence to keep: Defender Vulnerability Management recommendations export · Intune Update rings configuration · Windows Autopatch / update compliance report

07

Data Protection & Encryption

3.13.11SC.L2-3.13.11

Evidence to keep: Sensitivity label and policy export · Intune BitLocker (Disk encryption) policy · Entra-escrowed BitLocker recovery keys report

08

Backup & Recovery

IT-093.8.9MP.L2-3.8.9

Evidence to keep: Microsoft 365 Backup policy configuration · Screenshot of available restore points · Successful test-restore record

09

Secure Configuration Baseline

3.4.2CM.L2-3.4.2

Evidence to keep: Secure Score history export · Intune security baseline assignment and compliance report · Conditional Access or Security Defaults configuration

10

Secure AI Adoption & Data Loss Prevention

IT-083.1.3AC.L2-3.1.3

Evidence to keep: Purview DLP policy export (Copilot location) · Endpoint DLP rule for generative AI sites · DLP simulation / alert report

This checklist is independent education from the Brilliant at the Basics Resource Center, published by inDirectIT. It does not by itself establish compliance, satisfy a contract clause, or confer CMMC certification. Cloud consoles change often — verify each step against the provider’s documentation. The official DoW campaign remains authoritative: https://dowcio.war.gov/BrilliantBasics/

Back to the guide