[{"data":1,"prerenderedAt":370},["ShallowReactive",2],{"blog-\u002Fen\u002Fblog\u002Fobjectif-100-securite-microsoft365":3,"blog-\u002Fen\u002Fblog\u002Fobjectif-100-securite-microsoft365-surround":251,"blog-\u002Fen\u002Fblog\u002Fobjectif-100-securite-microsoft365-certifications":309},{"id":4,"title":5,"body":6,"categories":234,"cover":236,"cover_contain":237,"credly_badge_id":238,"date":239,"description":240,"extension":241,"meta":242,"navigation":243,"path":244,"related_certifications":245,"seo":247,"slug":248,"stem":249,"__hash__":250},"blog\u002Fen\u002Fblog\u002Fobjectif-100-securite-microsoft365.md","Goal: 100% - Microsoft 365 Security at Its Maximum",{"type":7,"value":8,"toc":210},"minimark",[9,14,18,21,24,31,38,44,49,55,60,64,67,70,74,82,85,91,94,100,103,109,112,116,122,125,131,134,140,143,149,152,156,162,165,171,174,180,183,189,192,198,201,207],[10,11,13],"h2",{"id":12},"real-world-use-case","Real-world use case",[15,16,17],"p",{},"You want to reach a maximum Secure Score on Microsoft 365: here's my concrete feedback, combining best practices with a Zero Trust vision.",[15,19,20],{},"In 2020, when setting up my Microsoft 365 tenant, I immediately implemented several recommendations from Microsoft Secure Score. But my goal went beyond simply following best practices: I wanted to aim for excellence and guarantee a maximum level of protection. That's what pushed me to deepen my skills, both technically and organizationally.",[15,22,23],{},"Microsoft Secure Score is a cybersecurity maturity gauge for the Microsoft 365 environment. It measures the implementation of security best practices across identities, devices, applications, and data. This feedback is set in a simple but representative production context: about ten devices, around twenty identity accounts (on-premises and cloud included), and several cloud applications used daily.",[25,26,27],"ol",{},[28,29,30],"li",{},"Our secure score as of August 1, 2025:",[15,32,33],{},[34,35],"img",{"alt":36,"src":37},"","\u002Fimages\u002Fblog\u002Fobjectif-100-securite-microsoft365\u002Fb7aeea2fd2.png",[25,39,41],{"start":40},2,[28,42,43],{},"Our 4 justified exceptions as of August 1, 2025:",[15,45,46],{},[34,47],{"alt":36,"src":48},"\u002Fimages\u002Fblog\u002Fobjectif-100-securite-microsoft365\u002F2feb082339.png",[25,50,52],{"start":51},3,[28,53,54],{},"Our remaining actions to implement as of August 1, 2025:",[15,56,57],{},[34,58],{"alt":36,"src":59},"\u002Fimages\u002Fblog\u002Fobjectif-100-securite-microsoft365\u002Fd246fc5fa5.png",[10,61,63],{"id":62},"a-matter-of-choice-not-size","A matter of choice, not size",[15,65,66],{},"You might think my approach only applies to an organization with little technical debt, well-managed interoperability, and applications compatible with modern security standards. That's partly true: I made the choice, from the start, to rigorously select my vendors and document my business processes before deploying all the Microsoft 365 building blocks.",[15,68,69],{},"Some will say these security measures hurt the user experience. Yes, partly, strengthening controls and implementing protections does require internal adjustments. But it's not a hindrance: it's an opportunity. Thanks to a well-designed single identity, we found a balance between security and smoothness. What may seem paradoxical actually becomes a lever for simplification and trust.",[10,71,73],{"id":72},"our-security-measures","Our security measures",[75,76,78],"h3",{"id":77},"_1-securing-identities-the-first-line-of-defense",[79,80,81],"strong",{},"1. Securing identities, the first line of defense",[15,83,84],{},"Protecting user accounts is at the heart of any cybersecurity strategy. Enabling (strong) MFA for everyone considerably strengthened access security by adding an essential verification layer. This measure, combined with fine-grained privilege management via PIM, limits elevated rights over time and reduces risks tied to privileged accounts.",[75,86,88],{"id":87},"_2-hardening-devices-without-complicating-usage",[79,89,90],{},"2. Hardening devices without complicating usage",[15,92,93],{},"Endpoint security is ensured through rigorous configuration: encryption, antivirus, automatic updates. Thanks to Intune, we control device compliance and block access from unmanaged or non-compliant devices. This hardening doesn't slow users down, it guarantees that only trusted devices can access resources.",[75,95,97],{"id":96},"_3-securing-cloud-applications-without-difficulty",[79,98,99],{},"3. Securing cloud applications without difficulty",[15,101,102],{},"Access to cloud applications is secured via SSO and Conditional Access, allowing smooth yet controlled authentication. By centralizing access, we reduced Shadow IT and gained visibility into usage. Data within applications is protected through DLP policies and sensitivity labels, ensuring fine-grained management of information based on its criticality.",[75,104,106],{"id":105},"_4-protecting-data-wherever-it-lives",[79,107,108],{},"4. Protecting data wherever it lives",[15,110,111],{},"The classification and protection of sensitive data is handled via Microsoft Purview, which identifies, tags, and secures critical content. DLP policies apply to email, SharePoint, OneDrive, and more, to prevent data leaks. Encryption and granular access control ensure only authorized people can view or edit documents.",[10,113,115],{"id":114},"the-pros","The pros",[75,117,119],{"id":118},"a-single-identity-toward-simplification-and-security",[79,120,121],{},"A single identity, toward simplification and security",[15,123,124],{},"Adopting a single identity has transformed the user experience. Fewer passwords to remember, less risk of reuse, and fewer entry points to monitor. Users log in once, access everything they need, and enjoy a smooth experience that encourages the adoption of secure tools.",[75,126,128],{"id":127},"reducing-invisible-risks",[79,129,130],{},"Reducing invisible risks",[15,132,133],{},"By centralizing access, we reduced Shadow IT: users can't use unapproved tools or weak, personal passwords. This improves traceability, with a single activity log per user, making audits and detection of abnormal behavior easier.",[75,135,137],{"id":136},"automation-and-adaptability",[79,138,139],{},"Automation and adaptability",[15,141,142],{},"Security policies are automated: MFA, conditional access, session expiration… everything is applied consistently, without manual intervention. Thanks to centralized identity, we've put in place adaptive security, able to react dynamically depending on the access context (e.g., blocking or enforced MFA from a non-compliant device).",[75,144,146],{"id":145},"finally-ready-for-the-zero-trust-model",[79,147,148],{},"Finally ready for the Zero Trust model",[15,150,151],{},"This approach prepares us to take a new step: moving from a defense-in-depth model to a Zero Trust model. The latter relies on continuous verification, least privilege, and conditional trust. Single identity, constant monitoring, and dynamic controls are already in place... we're ready to move toward the most mature security model.",[10,153,155],{"id":154},"the-cons","The cons",[75,157,159],{"id":158},"increased-maintenance",[79,160,161],{},"Increased maintenance",[15,163,164],{},"While automation allows for consistent policy enforcement, it still requires ongoing maintenance to stay effective against evolving threats. It's therefore essential to keep a regular watch, apply security updates, and adjust settings based on usage feedback and new recommendations. This requirement is the price to pay for a robust, sustainable security posture.",[75,166,168],{"id":167},"alert-and-incident-management",[79,169,170],{},"Alert and incident management",[15,172,173],{},"A secure environment naturally generates more security signals. To avoid the \"noise\" effect, we connected Microsoft 365 Defender to our external SIEM, to centralize alert management, correlate them with other sources, and make incident handling easier. This requires rigorous organization, but it's essential to keep control over critical events.",[75,175,177],{"id":176},"organizational-complexity",[79,178,179],{},"Organizational complexity",[15,181,182],{},"Some policies, such as PIM (Privileged Identity Management) or DLP (Data Loss Prevention), require close coordination between IT teams and business units. You need to understand operational needs, anticipate impacts, and sometimes adjust rules so as not to slow down processes. This complexity is manageable, but it requires dialogue and clear governance.",[75,184,186],{"id":185},"heightened-sensitivity-to-user-experience",[79,187,188],{},"Heightened sensitivity to user experience",[15,190,191],{},"Every security measure can affect daily usage. Stronger authentication, access restrictions, or an overly strict classification policy can create friction. It's therefore crucial to anticipate impacts, test configurations, and above all support users through the change. Security shouldn't be experienced as a constraint, but as a new framework of trust.",[75,193,195],{"id":194},"rigorous-documentation",[79,196,197],{},"Rigorous documentation",[15,199,200],{},"For certain recommendations that aren't applied or that are adapted to our context, clear, well-reasoned documentation is essential. It helps justify choices, keep a record of decisions, and make audits or security reviews easier. It's also a knowledge-transfer tool for teams, ensuring consistency over time.",[10,202,204],{"id":203},"conclusion",[79,205,206],{},"Conclusion",[15,208,209],{},"Reaching a score of 98.37% is possible, just like 100%, provided you know what you're doing and can justify the recommendations you haven't applied. Of course, you need the right licenses, technical and organizational knowledge of the scope, but standardizing your security management practices lets us aim for the maximum score in the coming days. This isn't an end in itself, but an important milestone in an ongoing effort to move toward the Zero Trust model.",{"title":36,"searchDepth":40,"depth":40,"links":211},[212,213,214,220,226,233],{"id":12,"depth":40,"text":13},{"id":62,"depth":40,"text":63},{"id":72,"depth":40,"text":73,"children":215},[216,217,218,219],{"id":77,"depth":51,"text":81},{"id":87,"depth":51,"text":90},{"id":96,"depth":51,"text":99},{"id":105,"depth":51,"text":108},{"id":114,"depth":40,"text":115,"children":221},[222,223,224,225],{"id":118,"depth":51,"text":121},{"id":127,"depth":51,"text":130},{"id":136,"depth":51,"text":139},{"id":145,"depth":51,"text":148},{"id":154,"depth":40,"text":155,"children":227},[228,229,230,231,232],{"id":158,"depth":51,"text":161},{"id":167,"depth":51,"text":170},{"id":176,"depth":51,"text":179},{"id":185,"depth":51,"text":188},{"id":194,"depth":51,"text":197},{"id":203,"depth":40,"text":206},[235],"Sécurité","\u002Fimages\u002Fblog\u002Fobjectif-100-securite-microsoft365\u002Fac33e55464.jpg",false,null,"2025-08-01","How I secured my Microsoft 365 environment using Secure Score recommendations. Feedback combining best practices with a Zero Trust vision.","md",{},true,"\u002Fen\u002Fblog\u002Fobjectif-100-securite-microsoft365",[246],"certificat-microsoft-security-compliance-and-identity-fundamentals",{"title":5,"description":240},"objectif-100-securite-microsoft365","en\u002Fblog\u002Fobjectif-100-securite-microsoft365","7E-p2WfhkpIunwR912A9RlRFO2YaBsXHTDEkMi7iE-A",[252,259,266,273,280,287,295,302],{"title":253,"path":254,"stem":255,"date":256,"cover":257,"categories":258,"children":-1},"Goal: 100%, Veeam Backup & Replication v12 Security","\u002Fen\u002Fblog\u002Fobjectif-100-securite-veeam-backup-replication","en\u002Fblog\u002Fobjectif-100-securite-veeam-backup-replication","2025-08-18","\u002Fimages\u002Fblog\u002Fobjectif-100-securite-veeam-backup-replication\u002Ffd1cbd3a9e.png",[235],{"title":260,"path":261,"stem":262,"date":263,"cover":264,"categories":265,"children":-1},"Optimal Hardening of Active Directory Security","\u002Fen\u002Fblog\u002Fdurcissement-optimal-securite-active-directory","en\u002Fblog\u002Fdurcissement-optimal-securite-active-directory","2025-08-13","\u002Fimages\u002Fblog\u002Fdurcissement-optimal-securite-active-directory\u002F9dc4acd9d6.png",[235],{"title":267,"path":268,"stem":269,"date":270,"cover":271,"categories":272,"children":-1},"Full Application of the Zero Trust Model in Microsoft 365","\u002Fen\u002Fblog\u002Fapplication-complete-modele-zero-trust-microsoft365","en\u002Fblog\u002Fapplication-complete-modele-zero-trust-microsoft365","2025-08-10","\u002Fimages\u002Fblog\u002Fapplication-complete-modele-zero-trust-microsoft365\u002Fcea858f515.png",[235],{"title":274,"path":275,"stem":276,"date":277,"cover":278,"categories":279,"children":-1},"Goal: 100%, Microsoft 365 Exposure Management","\u002Fen\u002Fblog\u002Fobjectif-100-securite-exposition-microsoft365","en\u002Fblog\u002Fobjectif-100-securite-exposition-microsoft365","2025-08-09","\u002Fimages\u002Fblog\u002Fobjectif-100-securite-exposition-microsoft365\u002Fe8a06eec09.png",[235],{"title":281,"path":282,"stem":283,"date":284,"cover":285,"categories":286,"children":-1},"Ensuring the Security of Your Secrets in Your Password Manager with Keeper Security","\u002Fen\u002Fblog\u002Fgarantir-securite-secrets-mots-de-passe-keeper-security","en\u002Fblog\u002Fgarantir-securite-secrets-mots-de-passe-keeper-security","2025-07-25","\u002Fimages\u002Fblog\u002Fgarantir-securite-secrets-mots-de-passe-keeper-security\u002F15b70398a5.png",[235],{"title":288,"path":289,"stem":290,"date":291,"cover":292,"categories":293,"children":-1},"Migrating to PostgreSQL with Veeam Backup & Replication","\u002Fen\u002Fblog\u002Fmigration-postgresql-avec-veeam-backup-replication","en\u002Fblog\u002Fmigration-postgresql-avec-veeam-backup-replication","2025-04-17","\u002Fimages\u002Fblog\u002Fmigration-postgresql-avec-veeam-backup-replication\u002F175ec05d87.png",[294],"Linux",{"title":296,"path":297,"stem":298,"date":299,"cover":300,"categories":301,"children":-1},"Integrating Microsoft 365 Security and Compliance","\u002Fen\u002Fblog\u002Fintegration-microsoft-365-securite-et-conformite","en\u002Fblog\u002Fintegration-microsoft-365-securite-et-conformite","2025-04-14","\u002Fimages\u002Fblog\u002Fintegration-microsoft-365-securite-et-conformite\u002F7d2de9509f.png",[235],{"title":303,"path":304,"stem":305,"date":306,"cover":307,"categories":308,"children":-1},"Digital Forensics on an Android Device","\u002Fen\u002Fblog\u002Fanalyse-numerique-un-appareil-android","en\u002Fblog\u002Fanalyse-numerique-un-appareil-android","2025-04-10","\u002Fimages\u002Fblog\u002Fanalyse-numerique-un-appareil-android\u002F07e1a2cb93.png",[235],[310],{"id":311,"title":312,"body":313,"categories":358,"cover":361,"cover_contain":243,"credly_badge_id":362,"date":363,"description":364,"extension":241,"meta":365,"navigation":243,"path":366,"related_certifications":238,"seo":367,"slug":246,"stem":368,"__hash__":369},"blog\u002Fen\u002Fblog\u002Fcertificat-microsoft-security-compliance-and-identity-fundamentals.md","Microsoft: Security, Compliance, and Identity Fundamentals",{"type":7,"value":314,"toc":354},[315,317,320,323,346,349,351],[10,316,13],{"id":12},[15,318,319],{},"To advise my clients on Microsoft security and compliance, I took the Security, Compliance, and Identity Fundamentals certification.",[15,321,322],{},"The \"Microsoft Security, Compliance, and Identity Fundamentals\" training path is designed for IT professionals in charge of deploying and securing cloud resources.\nThe course catalog covers the following modules:",[324,325,326,331,336,341],"ul",{},[28,327,328],{},[79,329,330],{},"Describe security, compliance, and identity concepts",[28,332,333],{},[79,334,335],{},"Describe the capabilities of Microsoft Entra",[28,337,338],{},[79,339,340],{},"Describe the capabilities of Microsoft security solutions",[28,342,343],{},[79,344,345],{},"Describe the capabilities of Microsoft compliance solutions",[15,347,348],{},"The training takes about 3 days.\nYou should then allow around 1h00 for the certification exam itself: Microsoft Security, Compliance, and Identity Fundamentals.",[10,350,206],{"id":203},[15,352,353],{},"This Microsoft course covers security, compliance, and identity management concepts, as well as the main associated Microsoft solutions (Entra, security, and compliance). It complements the Azure fundamentals already acquired by providing a broader view of protecting Microsoft environments. A useful certification for any professional in charge of securing cloud resources.",{"title":36,"searchDepth":40,"depth":40,"links":355},[356,357],{"id":12,"depth":40,"text":13},{"id":203,"depth":40,"text":206},[359,360],"Certifications","Microsoft","\u002Fimages\u002Fblog\u002Fcertificat-microsoft-security-compliance-and-identity-fundamentals\u002F70ef935f2a.png","82a09914-e95c-43b6-a371-f308b5ee8185","2022-10-17","Microsoft: Security, Compliance, and Identity Fundamentals: course completed as part of my professional watch in cybersecurity and IT.",{},"\u002Fen\u002Fblog\u002Fcertificat-microsoft-security-compliance-and-identity-fundamentals",{"title":312,"description":364},"en\u002Fblog\u002Fcertificat-microsoft-security-compliance-and-identity-fundamentals","pzrV5JRrELrJgaqSoqL2QuFzeb9_7_olBJ4fv_fRsgo",1786644882244]