Microsoft 365 Small Business
Dexfense ReviewedReference architecture for a Microsoft 365 deployment covering cloud identity, email, cloud storage, MFA and Windows endpoints.
Overview
Covers a small-to-medium business running Microsoft 365 Business Premium or equivalent. Includes Entra ID (formerly Azure AD) as the cloud identity provider, Exchange Online for email, SharePoint and OneDrive for file storage, Intune-managed Windows workstations, and mobile devices running Microsoft Authenticator. Conditional Access policies enforce MFA for all users; BYOD is addressed through Intune App Protection Policies.
Intended for
IT administrators, MSPs and security consultants responsible for Microsoft 365 environments in small and medium businesses.
Architecture Assumptions
This template assumes the following conditions. If your environment differs, use Remix to adapt the component selection.
- All identity is managed through Microsoft Entra ID (cloud-only, no on-premises sync)
- MFA is enforced for all user accounts via Conditional Access
- Devices are enrolled in Microsoft Intune
- Microsoft Defender for Business or equivalent endpoint protection is active on all workstations
Out of Scope
- Custom Entra ID app registrations are not individually assessed
- Power Platform and low-code application components are not modelled
- On-premises Active Directory hybrid sync scenarios are not covered
- Assumes Microsoft licensing at Business Premium or M365 E3/E5 level
Architecture Components10 components selected
Servers
Mail Servers
Email servers and services
Auth & IAM
Active Directory
Directory service for user and resource management
Single Sign-On
Centralized authentication service
Multi-Factor Auth
Additional authentication verification layer
Endpoints
Windows Clients
Windows-based end-user devices
Mobile Devices
Smartphones and tablets (iOS, Android)
BYOD
Bring your own device environment
Storage
Cloud Storage
Cloud-based object or file storage
Backup Systems
Data backup and recovery systems
Cloud
Azure Services
Microsoft Azure cloud services
Security Preview
Based on this architecture's component selection
Indicative Risk Score
50/100
26 techniques identified
3 Critical · 2 High
Top Attack Techniques
- CriticalT1068Exploitation for Privilege Escalation
- CriticalT1003OS Credential Dumping
- CriticalT1486Data Encrypted for Impact
- HighT1133External Remote Services
- HighT1574Hijack Execution Flow
Top Recommended Controls
- 1Implement comprehensive cloud security posture management
- 2Implement privileged access management and monitor for suspicious directory queries
- 3Focus on Network Segmentation as your highest priority security initiative
The full defense plan — mitigations, detection methods, NIST CSF 2.0 mapping and exportable report — is available when you use this architecture in the planner.
Remix copies the components so you can add or remove items before generating your assessment.
Dexfense does not scan your systems. This template identifies threats and controls relevant to this architecture. Product and version validation is still required.