Skip to content

Configure and Audit Microsoft 365 Security

Use Microsoft 365 Security to review and configure organization-level security settings from one MSPControl screen. The current product exposes controls for:

  • Unified Audit Log report notifications;
  • Safe Links domains and URLs that must not be rewritten;
  • anti-malware, anti-phishing, and anti-spam policies;
  • global quarantine report delivery;
  • Standard Protection users, domains, and exclusions.
Microsoft 365 Security settings for a customer organization
  • Open the customer organization whose Microsoft 365 settings you want to review.
  • Confirm that your account can view and change Microsoft 365 Security settings.
  • Confirm the organization has the Microsoft licensing required for the protection feature you intend to configure. MSPControl performs product checks for Safe Links and Standard Protection before applying those settings.
  • Record the current values before changing production protection policies.

Review the current Microsoft 365 security configuration

Section titled “Review the current Microsoft 365 security configuration”
  1. Open the customer organization in MSPControl.
  2. Open Microsoft 365 Security.
  3. Review each section before changing it:
    • Security Settings for Unified Audit Log report notifications;
    • Safe Links Settings for protected domains and URL rewrite exclusions;
    • Spam Filtering Settings for anti-malware, anti-phishing, and anti-spam configuration;
    • Global Quarantine Report Settings for report delivery;
    • Standard Protection Settings for protected users, protected domains, and exclusions.
  4. Note whether Override Global Policy is enabled for spam filtering. When it is disabled, MSPControl uses the applicable global policy values instead of an organization-specific override.

Configure Unified Audit Log report notifications

Section titled “Configure Unified Audit Log report notifications”
  1. In Security Settings, select Enable Unified Audit Log Notifications.
  2. Enter the email address that should receive the report notification.
  3. Continue reviewing the other sections before saving the page.

The setting controls MSPControl’s Unified Audit Log reporting workflow. It does not enable the Microsoft 365 audit service itself.

  1. In Safe Links Settings, select Enable Safe Links.
  2. Add the domains that the policy should protect.
  3. Add any URLs that must remain in the Do Not Rewrite URLs in Email list.
  4. Review the entries for spelling and scope before saving.
  1. In Spam Filtering Settings, select Enable Spam Filtering.
  2. Enable Override Global Policy only when this organization needs settings that differ from the global policy.
  3. Review the anti-malware, anti-phishing, and anti-spam policy values shown on the page.
  4. Continue to the remaining sections before saving.
  1. In Global Quarantine Report Settings, select Send Global Quarantine Report to Customer.
  2. Enter the email address that should receive the report.
  3. Verify that the address belongs to the intended customer or administrator.
  1. In Standard Protection Settings, select Enable Standard Protection.
  2. Add the targeted users and domains that require protection.
  3. Add excluded senders or domains only when the exception is approved.
  4. Review every target and exclusion before saving.
  1. Select Save Changes.
  2. Wait for MSPControl to finish its configuration checks and apply the selected settings.
  3. Reopen Microsoft 365 Security for the same organization.
  4. Confirm that each enabled setting, email address, target, and exclusion matches the intended configuration.
  5. If a protection section reports that it is not configured, confirm the organization’s licensing and the values entered for that section before retrying.