ASD's Blueprint for Secure Cloud

Services

This section describes the configuration of services in Microsoft 365 associated with systems built according to the guidance provided by ASD's Blueprint for Secure Cloud.

Estimated reading time: 6 minutes

Account Linking

ItemValue
Allow users to connect their Microsoft Entra ID and MSA accountsDisabled

Adoption Score

ItemValue
Insight calculations and display
Select users and groups for calculating insightsInclude all users (recommended)
Turn on group-level insightsUnchecked

Azure Speech Services

ItemValue
Allow the organization-wide language modelChecked

Bookings

ItemValue
Allow your organization to use BookingsUnchecked

Calendar

ItemValue
Let your users share their calendars with people outside of your organization who have Office 365 or ExchangeUnchecked

Cortana

ItemValue
Allow Cortana in Windows 10 (version 1909 and earlier), and the Cortana app on iOS and Android, to access Microsoft-hosted data on behalf of people in your organizationUnchecked

Developer Portal for Teams

ItemValue
Allow app usage for all custom apps to show in the Developer PortalUnchecked

Dynamics 365 Customer Voice

ItemValue
Security
Prevent phishing attemptsChecked
Collect namesChecked
Restrict survey accessUnchecked

Microsoft 365 Groups

ItemValue
Let group owners add people outside your organization to Microsoft 365 Groups as guestsUnchecked
Let guest group members access group contentUnchecked
When there’s no owner, email and ask active group members to become an ownerUnchecked

Microsoft 365 installation options

ItemValue
Feature updates
As soon as they’re ready (Current Channel, recommended)Selected
Installation
Apps for Windows and mobile devices
- Office (includes Skype for Business)Checked
- Skype for Business (Standalone)Checked
Apps for Mac
- OfficeChecked
- Skype for Business (X El Capitan 10.11 or higher)Checked

Microsoft 365 on the web

ItemValue
Let users open files store in third-party storage services in Microsoft 365 on the webUnchecked

Microsoft communication to users

ItemValue
Let people in my organization receive emails from Microsoft about how to use Microsoft 365 productsUnchecked

Microsoft Forms

ItemValue
Send a link to the form and collect responsesChecked
Share to collaborate on the form layout and structureChecked
Share the form as the template that can be duplicatedChecked
Share form result summaryUnchecked
Record named by defaultChecked
Include Bing search, YouTube videosUnchecked
Add internal phishing protectionChecked
Allow respondents to edit their responsesUnchecked

Microsoft Graph Data Connect

ItemValue
Turn on Microsoft Graph Data Connect on or off for you entire organizationUnchecked

Microsoft Loop

ItemValue
Microsoft Loop workspaces are available to all users in my organizationChecked

Microsoft Planner

ItemValue
Allow Planner users to publish their plans and assigned tasks to Outlook or other calendars through iCalendar feedUnchecked

Microsoft Teams

ItemValue
Turn on Microsoft Teams for all usersChecked
Allow guest access in TeamsUnchecked

Microsoft To Do

ItemValue
Allow your users to receive push notificationsUnchecked

Microsoft Viva Insights

ItemValue
Personal and organization insights web experienceChecked
Digest emailChecked
Insights Outlook add-in and inline suggestionsChecked
Meeting effectiveness surveysChecked
Schedule send suggestionsChecked
Allow Microsoft to contact me about my feedbackUnchecked

Modern Authentication

ItemValue
Turn on modern authentication for Outlook 2013 for Windows and later (recommended)Checked
Authenticated SMTPUnchecked

News

ItemValue
General
IndustryNone
TopicsNone
Exclude ContentNone
Allow user to customize their own topicsUnchecked
Turn on industry news content in Microsoft FeedUnchecked
Industry updates
Send daily email updatesUnchecked
Bing homepage
Include industry newsUnchecked
Microsoft Edge new tab page
Show Microsoft 365 content on the Microsoft Edge new tab pageUnchecked
Show My Feed content on the Microsoft Edge new tab pageUnchecked
Users default to My FeedUnselected
Users default to Work FeedUnselected

Reports

ItemValue
Display concealed user, group, and site names in all reportsUnchecked
Make report data available to Microsoft 365 usage analytics for Power BIUnchecked

Self-service trials and purchases

ItemValue
Dynamics 365 Marketing
- Do not allowSelected
Dynamics 365 Marketing Additional Application
- Do not allowSelected
Dynamics 365 Marketing Additional Non-Prod Application
- Do not allowSelected
Dynamics 365 Marketing Attach
- Do not allowSelected
Microsoft 365 Copilot
- Do not allowSelected
Microsoft 365 F3
- Do not allowSelected
Microsoft ClipChamp
- Do not allowSelected
Microsoft Purview Discovery
- Do not allowSelected
Power Apps per user
- Do not allowSelected
Power Automate per user plan
- Do not allowSelected
Power Automate Per User with Attended RPA Plan
- Do not allowSelected
Power Automate RPA
- Do not allowSelected
Power BI Premium per user
- Do not allowSelected
Power BI Pro
- Do not allowSelected
Planner Plan 1
- Do not allowSelected
Project Plan 3
- Do not allowSelected
Python in Excel
- Do not allowSelected
Teams Exploratory Upgrade Request
- Do not allowSelected
Teams Exploratory
- Do not allowSelected
Microsoft Teams Premium
- Do not allowSelected
Visio Plan 1
- Do not allowSelected
Visio Plan 2
- Do not allowSelected
Viva Goals
- Do not allowSelected
Viva Learning
- Do not allowSelected
Windows 365 Buisness
- Do not allowSelected
Windows 365 Buisness with Windows Hybrid Benefit
- Do not allowSelected
Windows 365 Enterprise
- Do not allowSelected

SharePoint

ItemValue
Only people in your Organization - no external sharing allowedSelected

Sway

ItemValue
Let people in your organization share their sways with people outside you organizationUnchecked
Let people in your organization look up people and security groupsUnchecked
FlickrUnchecked
PickitUnchecked
WikipediaUnchecked
YouTubeUnchecked

User owned apps and services

ItemValue
Let users access the Office StoreUnchecked
Let users start trials on behalf of your organizationUnchecked
Let users auto-claim licences the first time they sign inUnchecked

Viva Learning

ItemValue
Required Diagnostic Data. Send the minimum data necessary to Microsoft to keep Viva Learning secure, up-to-date, and performing as expectedUnchecked
Optional Diagnostic Data. Additional data that helps us make product improvements and provides enhanced information to help us detect, diagnose, and remediate issuesUnchecked

Whiteboard

ItemValue
Turn on Whiteboard for everyone in your orgChecked
Neither - No diagnostic data about Whiteboard client software running on the devices in your organizations is sent to MicrosoftSelected
Allow the use of optional connected experiences in legacy WhiteboardUnchecked
Enable easy sharing of legacy whiteboards from Surface HubUnchecked

Security and governance

  • None identified

Design

Configuration

References

  • None identified

Do you have a suggestion on how the above page could be improved? Get in touch! ASD's Blueprint for Secure Cloud is an open source project, and we would love to get your input. Submit an issue on our GitHub, or send us an email at blueprint@asd.gov.au

Acknowledgement of Country icon

Acknowledgement of Country
We acknowledge the Traditional Owners and Custodians of Country throughout Australia and their continuing connections to land, sea and communities. We pay our respects to them, their cultures and their Elders; past, present and emerging. We also recognise Australia's First Peoples' enduring contribution to Australia's national security.

Authorised by the Australian Government, Canberra