← SOP Library

Runbooks

M365 Configuration & Test Checklist — Intune · Encryption · PPPC · Defender · SSPM · Huntress

Owner Jerry Updated 2026-06-24 For Internal — engineering

M365 Configuration & Test Checklist

One scannable place to configure and test everything in Microsoft 365 for the CyberSuite stack on the internal tenant (and the template for a customer tenant via GDAP). Each section has Configure then Test with checkboxes. Deep-dive steps live in the linked runbooks; this is the do-and-verify index. Do sections in order — each gates the next.

Internal vs customer: internal tenant uses IUR licenses (Partner Success Core, internal-only). Customer tenants get the same config via GDAP + Pax8 CSP licensing. Never assign IUR to a customer.


0. Licensing & access (the gate)

Configure

Test


1. Entra / Identity (C-04, C-05)

Configure

Test


2. Intune / MDM (C-10 enabler + the Mac unblock)

Configure

Test


3. Endpoint encryption — BitLocker + FileVault (C-10)

Configure

Test (the PASS proof = key escrowed AND retrievable, not just “encryption on”)


4. ⭐ PPPC profile — makes Action1 + Huntress work on Mac (load-bearing)

macOS gates RMM/EDR agents behind TCC (Privacy); only an MDM-pushed PPPC profile pre-approves them. Configure

Test


5. Microsoft Defender for Endpoint (internal hardening; optional MS-native EDR)

(Huntress is the EDR at every tier; Defender for Endpoint here is internal hardening + the Huntress↔Defender telemetry integration. See sspm-defender-poc-internal-tenant.md Parts B/C.) Configure

Test


6. SSPM — Microsoft Defender for Cloud Apps (the Sentinel deliverable)

(Sentinel tier, M365 only. See sspm-defender-poc-internal-tenant.md Part A.) Configure

Test


7. Huntress (the EDR — all tiers)

(Deployed via Action1; see runbooks/action1-setup-and-deployment.md + action1-scripts/.) Configure

Test


8. Action1 (RMM — the endpoint-management leg, adjacent)

Configure


Cross-cutting sign-off

Honest limits to not overclaim: Action1 security config is via scripts, not enforced MDM profiles (enforced profiles = Intune); Action1 Mac patching excludes major-OS upgrades; Sentinel SSPM is M365-only. State these; don’t claim native coverage that isn’t there.