In Scoring the Stack, Jazzy Khaneja and Redouan Bulaid explore the full range of security capabilities available in Microsoft 365 Business Premium and the add‑ons available to extend it, showing how Microsoft has become a complete, enterprise‑grade security platform for SMBs.
Know Your Stack - Episode 1: Entra ID Hardening
In this episode, find out what “good” Entra ID security actually looks like and how to standardise it at scale. From misconfigured MFA to risky legacy authentication and policy drift, we’ll highlight the common gaps we see across tenants - and how to close them. Learn how to harden Entra ID environments efficiently, reduce risk across your customer base, and build a repeatable identity security baseline you can rely on.
Hello and welcome everyone. Good afternoon depending on where you are in the world though. Good morning, good afternoon, good evening. We cover all of whatever whichever part of the country or the world you guys are in. Love that. I'm guessing that it's not night for someone in the world right now or in this meeting. Well, hopefully not. If it is night, they absolutely love these webinars and wanted to join during this time. Absolutely love it. Absolutely love it. Well, good to have you all. Thank you for being part of our webinar, part one of our Know Your Stack series, a four-part webinar, where we'll talk about a few things in the Microsoft world and the things we love doing every day. I think it's 2-3-1. What do you think? Should we get cracking? Should we get started? Hopefully people can see. I guess so. It's already 2 minutes past 4, so I'm guessing that most people have joined so far. Do we have a Q&A section or do we just use the chat within Teams? I'm guessing we're using the chat then, right? Yeah. Yeah. Let's use the chat. Anyone that wants to ask some questions. Greetings from Switzerland. Greetings from South Africa. Actually, I'm in South Africa right now for some onsite engagements for Inforcers. I've been here for about a week now. So greetings from South Africa, but I'm actually based in the Netherlands. We'll jump into intros in a bit, I guess. We've got someone from the UAE as well. I mean, right now it feels like the UAE in the UK. I'm based in Richmond, United Kingdom. It's almost 100 degrees here. Not really, but that's what it feels like. I am melting slightly. But I think we'll be okay, mate. We have people from all over the world right now. We've got Haiti in the house. Yeah, as well, bro. What? Greece. Are you guys making things up? They're just putting in countries right now. Well, the Netherlands is not going anywhere in terms of football, but otherwise the Netherlands is in the house too, boys. Someone says 100 degrees in the USA. Man, we measure in Celsius. 37. Yeah. Yeah. 37. I mean, that is what it feels like to be fair. I really need AC. Cries hearts, actually. Awesome. Let's get going. I'll move over to the next slide. So, a little bit about us and who we are. Welcome guys. I'm Jazzy. I'm part of the Microsoft 365 Solutions Architect team here. I'm a Microsoft fanboy first of all. That's all I love. That's all I talk about. Even with my missus, somehow I manage to bring Microsoft into the conversation. I'm also the official IT support for my parents. Without a doubt, anything that ever goes wrong is a phone call straight to me. Somehow I know everything about phones, TVs, and the fan that sometimes doesn't work and swivels in the wrong direction, even though there is no right direction for a fan to realistically swivel. My whole IT career has been MSP. That's all I've ever done, guys. I've only ever worked in MSPs. I've been heavily involved with the Microsoft ecosystem, things like Intune, Entra, Exchange, and a little bit of Azure Virtual Desktop here and there. That's a little bit about me and nice to have you all. We're 134 strong right now on this webinar, so thank you for joining. I did create this slide about 10 minutes ago. Yeah, I was going to ask you, what did you put under my name? At least you're over here for no reason. You're not going to have time to add anything. I will introduce myself as well. My name is Rayon Bulite. I'm actually based in the Netherlands. As I said, right now I'm in South Africa, so that's really fun. I'm here for some onsite engagements. I used to work for an MSP as well, just like Jazzy. I worked for an MSP based in the Netherlands in Anto. For all the people from the Netherlands right now, they probably know where it is. I was the lead consultant there for the Modern Workplace team, so I did a lot of project work around the Microsoft ecosystem. We were really focused on the Microsoft ecosystem, Defender, Office, Defender for Cloud Apps, all of those shenanigans within Microsoft 365. We configured it and were really focused on it. Since about a month or two ago, I'm now a Solutions Architect here at inforcer. Thank you all for joining, man. We have a good group today, Jazzy. Absolutely. I think we're ready to hopefully inspire some knowledge that wasn't already there and maybe learn some from all of the other experts on the call as well. We're happy for all of your inputs and questions in the chat, so feel free to go. I am controlling the slides, so Rayon, whenever you need me to go to the next one, you can tell me as well and we'll do this together. FYI guys, none of this is rehearsed. We're doing it on the fly as we always do, so we'll make it work as we always do. Things we'll cover: we'll cover some of the stack that you already own and talk about some of the foundation work that we can harden that sometimes gets missed. Obviously conditional access. Can't speak about Entra ID without speaking about conditional access and some external and cross-tenant collaboration that we may have missed. We'll talk about guest security and infrastructure available inside Entra ID and making sure that we configure things and make sure they stay inforced, right? Because configuring a policy, turning it on and not applying it means nothing, does it? How many times have we deployed something and forgotten to assign someone to it? I've made that mistake once or twice myself. About you, Rayon? Yep. I know exactly what you're talking about. Awesome. Awesome. So, stack you already own guys. You're paying for Business Premium, hopefully all of you are, and that includes Entra ID P1. That is included with the licensing. Sometimes where we struggle is when we have too many subscriptions or already have an identity platform that we're using. We're using Entra ID P1, we've got the Business Premium licensing under our wings, and that's where it's brilliant to configure it. But are we configuring it to its full extent? Sometimes we don't find the things we're looking for within Entra ID. That covers other workloads as well like Defender and antivirus, Exchange email security gateways, and things like that. It starts stacking up, right? You start having more portals to cover, more work for the invoicing team to ask for money for other products you're covering, and just more consoles ultimately. Yeah, I mean you're hopping from portal to portal enough within the Microsoft ecosystem and now you have other third-party applications that also have portals you have to hop to. I'm guessing that for a lot of people this is making sense. I've been on some onsite engagements here in South Africa as well. I see a lot of MSPs that utilise third-party applications where they don't really know that it's already included within Business Premium, or it might even be cheaper to move to Business Premium and leave some of those tools. Nowadays Microsoft technologies, I mean you can check the Gartner Quadrant charts, Microsoft is at the top of the charts. I guess the goal of this series is to focus on what you already have within the Microsoft ecosystem since it makes so much sense to consolidate into that if that makes sense. Yeah, absolutely. You're spot on. What that sometimes means is that you only need one type of expert within your MSP, someone who knows the Microsoft ecosystem. You're not looking for people with other skills because they know Microsoft. We live and breathe Microsoft. It's easier to manage and configure because we know it and we've been trained on it. Ultimately, who wants to jump between more portals when we already have so many Microsoft portals to jump between, right? You said that spot on. Wasn't it also recently that Microsoft announced price rises and the only thing that wasn't raised was Business Premium licensing? Yeah. Yeah, that is correct. That's a very good argument for an MSP to actually move towards Business Premium since it is the only SKU that is not being raised in price and Business Standard is being raised. So yeah, it makes even more sense to move towards Business Premium. Absolutely. So what do we get? We get Entra ID P1 in Business Premium. We've got things we can configure such as conditional access that we'll talk about in a minute. We've got SSPR in there, self-service password reset. We've even got password protection where we can apply certain words that are banned from being used as passwords, like a banned user password list. We've got named locations where we can decide which IP addresses are part of the allow/block list. It could be your office IP address or customer office IP addresses around the world. We could block certain countries from being accessed into their Entra tenant environment and only allow certain countries. You've got proper security reporting that comes out of Entra. There are so many reports, especially with workbooks as well, isn't there? When you do diagnostic settings there is lots of reporting that can be pulled out. If I'm not wrong, by standard in Entra ID you get 30 days of history in terms of sign-in logs as well that we can export out. That's already paid for as part of your Entra ID P1. Things like built-in MFA. We've got passkeys we can use. We've got the Microsoft Authenticator app. We don't necessarily need third-party vendors to help us with MFA. We do have an add-on, P2, which can be purchased on top of your Business Premium. It's part of some suites as well. I think the Defender Suite and the Purview Suite come with P2 and you can have standalone P2 licenses as well. That gives you things like risk-based protection and Privileged Identity Management. The just-in-time, just-enough-access protocol to make sure that we're covering that framework. With PIM you can elevate up to a certain role and only have it for certain hours, assign them to specific users, so we're not sprawling out all of the roles to everyone. Give everyone GA because that's what turns out to be happening. It does still happen though. Unfortunately it does. Absolutely. I've seen it too. We should really rein that in and start controlling it. It was like that in my MSP as well. We tended to give out a lot of global admin across the board and had to rein that in as much as we could. I'm not going to go deep into GDAP and PIM there as well. You want to make this a two-hour webinar, Jess. All right. All right. Like I said, Microsoft fanboy out here. We usually had to revert to P2 licences for our administrative accounts whenever GDAP wasn't able to do specific things within GDAP. At the time, only a couple of months ago, you couldn't manage Teams within GDAP. I'm pretty sure that's still the case. We'd still have to have a P2 licence if we were going to properly configure the roles with PIM. Yeah. Yeah. Making sure every user gets that P2 licence. Not just the one to unlock it in the tenant like some people have been doing. Every user benefiting from that should be having a P2 licence. We're not going to go into deep licensing talk either. That's fine. No. No. Please no.
Know Your Stack - Episode 2: Microsoft Defender for Office 365
In this session, Jazzy and Redouan dive into how to properly configure, standardise, and manage Defender for Office 365 across your customer base. From anti-phishing policies to Safe Links and Safe Attachments, we’ll uncover the most common misconfigurations leaving tenants exposed - and how to fix them at scale.
Know Your Stack - Episode 3: Microsoft Defender for Cloud Apps
In this session, Jazzy and Redouan break down how to operationalise Defender for Cloud Apps across customer environments, moving beyond basic visibility to real-time control and automated protection. You’ll learn how to uncover risky app usage, enforce policies at scale, and protect sensitive data - without adding complexity to your workflows.
Know Your Stack - Episode 4: Microsoft Defender for Endpoint
In this session, Jazzy and Redouan show you how to turn Defender for Endpoint into a scalable, high-impact security layer for your customers. From onboarding and configuration to threat detection and response, you’ll learn how to move from reactive alert handling to proactive endpoint security.