DSE security knowledge hub

Cybersecurity
Knowledge

Page 22 of the DSE Cybersecurity knowledge center, with source-backed guidance and practical next steps.

DSE-authoredOfficial sourcesReviewed guidance
Explore this topic

Cybersecurity knowledge center

Source-backed guidance for identity, vulnerability reduction, ransomware readiness, detection, response, and recovery.

Start with the cornerstone guide
DSE post stream

Cybersecurity

230 articles
DSE visual briefIdentity & cloud

SharePoint and OneDrive external sharing: reduce exposure without stopping collaboration

SharePoint and OneDrive sharing is governed by tenant, site, link, group, and Microsoft Entra settings. A safer model uses intentional collaboration sites, authenticated guests where practical, restrictive defaults, ownership, and recurring access review.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefIdentity & cloud

Microsoft 365 offboarding: secure access and preserve business records in the right order

Offboarding is an identity, device, records, and continuity workflow. Blocking sign-in is urgent, while mailbox, OneDrive, ownership, legal hold, forwarding, licensing, and account deletion decisions must follow an approved sequence.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the checklist
DSE visual briefIdentity & cloud

Microsoft 365 Copilot permissions readiness: fix oversharing before rollout

Microsoft 365 Copilot works within a user's existing permissions. That boundary does not correct excessive access: content already visible to a user may become easier to discover, so SharePoint, OneDrive, Teams, ownership, labels, and sharing need review first.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefContinuity & recovery

Ransomware first response: a calm containment checklist

When ransomware or destructive encryption is suspected, activate the incident plan, isolate affected systems in a coordinated way, preserve evidence, use known-safe communications, protect identities and backups, and involve qualified responders before rebuilding.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the checklist
DSE visual briefIdentity & cloud

Microsoft Intune compliance: design the signal before enforcing access

Intune compliance policies evaluate whether managed devices meet defined requirements. Blocking access requires a coordinated Microsoft Entra Conditional Access policy, suitable licensing, representative testing, and a supportable path back to compliance.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the explainer
DSE visual briefCyber defense
ExplainerInformationCybersecurityIT

Microsoft Defender for Business: understand the protection and the boundaries

Microsoft Defender for Business brings endpoint prevention, detection, investigation, and response capabilities to eligible organizations with up to 300 users. Onboarding, configuration, licensing, monitoring, and server coverage still require deliberate planning.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the explainer