SOP — Microsoft 365 Intune and Defender
| Version | 1.1 |
| Date | 2026-06-22 |
| Scope | Tenant signup → Intune device management (Windows, macOS, iOS, Android) → Microsoft Defender endpoint protection → SOC 2 / ISO 27001 control mapping and evidence (assessment handled outside Purview) |
| Primary admin portals | M365 admin (admin.microsoft.com), Entra (entra.microsoft.com), Intune (intune.microsoft.com), Defender (security.microsoft.com) |
Important framing: the Microsoft toolset enables and evidences SOC 2 and ISO 27001 controls — it does not by itself make an organization compliant. Certification still requires written policies, organizational processes, and an independent assessor/auditor. This SOP configures the technical controls and the evidence pipeline that an audit will draw on. Control assessment and tracking are handled outside Microsoft Purview (see Phase 6).
1. Prerequisites
1.1 Choose the right license
Intune (device management) requires a Microsoft 365 plan — not an Office 365 plan. The plan also determines the level of endpoint protection and security reporting you get.
| Plan | Best for | Intune | Endpoint protection | Security reporting / evidence |
|---|---|---|---|---|
| Microsoft 365 Business Premium | ≤ 300 users (SMB) | Plan 1 | Defender for Business (EDR-class) + Defender for Office 365 P1 | Secure Score; Entra & Defender logs as evidence |
| Microsoft 365 E3 | Enterprise, baseline | Plan 1 | Defender for Endpoint P1 (next-gen AV, ASR, firewall — no EDR) | Secure Score; Entra & Defender logs |
| Microsoft 365 E5 | Enterprise, full security | Plan 1 | Defender for Endpoint P2 (adds EDR, automated investigation, vulnerability mgmt) + full Defender XDR | Secure Score + full Defender XDR |
Recommendation: for SOC 2 / ISO 27001 you want EDR. Choose Business Premium if under 300 users, or E5 at enterprise scale (or E3 + the E5 Security add-on to add EDR to an existing E3 estate). Plan for the July 2026 packaging change that folds several Intune Suite features into E3/E5 with a ~$3/user/month increase.
1.2 Before you start
- A verifiable DNS domain you control (for the vanity domain and email).
- Decide on Apple and Android management: an Apple ID for Apple Business Manager, and a Google account for Android Enterprise / Managed Google Play.
- An Apple MDM Push certificate (APNs) will be required for all Apple (iOS + macOS) management — renewed annually.
- Two break-glass / emergency-access admin accounts (cloud-only, excluded from Conditional Access, stored offline).
- A chosen GRC / compliance-automation platform (or a manual control register) for SOC 2 / ISO 27001 assessment and evidence — see Phase 6.
2. Phase 1 — Sign up for Microsoft 365
- Go to
microsoft.com/microsoft-365/business(or the Business Premium / E5 product page) and start the purchase or a free trial. Provide company details and create the first Global Administrator account on the default*.onmicrosoft.comtenant. - In the Microsoft 365 admin center (
admin.microsoft.com), add and verify your custom domain (add the TXT/MX/CNAME records at your DNS host). - Purchase/assign the chosen license to a test user. Licenses are managed here, not in the Intune or Entra portals.
- Create the two break-glass Global Admin accounts; document and secure them.
- Reduce standing Global Admins to the minimum and plan role-based delegation (Phase 2).
3. Phase 2 — Identity foundation (Microsoft Entra)
Identity is the first SOC 2 / ISO 27001 control surface; configure it before enrolling devices.
- In the Entra admin center (
entra.microsoft.com), enforce multifactor authentication for all users (via security defaults for small tenants, or Conditional Access for granular control). - Create Conditional Access policies: require MFA for admins and all users; later, require compliant or hybrid-joined devices for access to corporate apps (completed after Intune compliance policies exist in Phase 4–5). Exclude the break-glass accounts.
- Apply least privilege with Entra role-based access control and, where licensed (P2), Privileged Identity Management (PIM) for just-in-time admin elevation.
- Create the security groups (and/or dynamic groups) you will target with Intune policies — e.g., by platform, department, and corporate-vs-BYOD.
4. Phase 3 — Stand up Intune
- In the Intune admin center (
intune.microsoft.com), confirm Intune is your MDM authority (default for new tenants) and that licensed users can enroll. - Windows auto-enrollment: in Entra → Mobility (MDM and MAM), set the MDM user scope so Entra-joined Windows devices auto-enroll into Intune.
- Apple enrollment prerequisites:
- Upload the Apple MDM Push (APNs) certificate (Devices → Enrollment → Apple).
- Connect Apple Business Manager and configure Automated Device Enrollment (ADE) tokens for corporate-owned Macs, iPhones, and iPads.
- Android enrollment prerequisites: connect Managed Google Play (Devices → Enrollment → Android) to enable Android Enterprise (work profile for BYOD, fully managed for corporate).
- Define enrollment restrictions (which platforms/ownership types are allowed) and the Company Portal branding.
5. Phase 4 — Enroll and manage devices
For every platform, create a compliance policy (the gate Conditional Access enforces) and configuration profiles (settings/security baselines), then deploy required apps.
5.1 Windows
- Provision corporate devices with Windows Autopilot (import hardware hashes via the vendor or ADE-equivalent); BYOD users enroll via Company Portal / Entra join.
- Apply the Windows security baseline and configuration profiles (password/PIN, BitLocker, Microsoft Defender settings, update rings via Windows Update for Business).
- Compliance policy: require BitLocker, Secure Boot, minimum OS build, Defender AV healthy, and (with P2) machine risk at/below an allowed level.
5.2 macOS
- Corporate Macs enroll automatically via ADE; BYOD via Company Portal.
- Configuration profiles: FileVault disk encryption (escrow the recovery key to Intune), firewall, password policy, Platform SSO, and the Microsoft Defender for Endpoint configuration.
- Compliance policy: require FileVault, minimum macOS version, firewall on, and Defender healthy.
5.3 iOS / iPadOS
- Corporate devices via ADE; BYOD via Company Portal (user enrollment) or App Protection Policies (MAM) for an unmanaged-device, app-only model.
- Configuration profiles: passcode, encryption (on by default with passcode), restrictions, and deploy apps from the App Store / VPP.
- Compliance policy: require passcode, non-jailbroken, minimum iOS version.
5.4 Android
- Work profile (BYOD) or fully managed (corporate) via Android Enterprise; assign apps from Managed Google Play.
- Configuration profiles and App Protection Policies to contain corporate data in managed apps.
- Compliance policy: require screen lock, encryption, non-rooted, Play Integrity / SafetyNet attestation, minimum patch level.
After compliance policies exist, return to Conditional Access (Phase 2) and require a compliant device for access to Microsoft 365 and other corporate apps. This is the linchpin that ties device posture to access.
6. Phase 5 — Endpoint protection (Microsoft Defender)
- Connect Intune to Defender: in the Defender portal (
security.microsoft.com) → Settings → Endpoints, enable the connection to Intune (and toggle it on in Intune → Endpoint security → Microsoft Defender for Endpoint). This lets Intune deploy onboarding and consume Defender risk signals. - Onboard devices to Defender for Endpoint via Intune Endpoint security policies (Windows onboarding is largely automatic once connected; deploy the Defender app/profile to macOS, iOS, and Android).
- Configure endpoint security policies in Intune:
- Next-generation antivirus (real-time protection, cloud-delivered protection, tamper protection).
- Attack surface reduction (ASR) rules and controlled folder access.
- Firewall and network/web protection.
- Disk encryption (BitLocker / FileVault) if not already set in Phase 4.
- EDR policy (Defender for Endpoint P2 / Defender for Business): endpoint detection and response, automated investigation and remediation.
- Vulnerability management (P2 / Defender for Business): review the exposure/score dashboard and feed remediation tasks back into Intune.
- Risk-based Conditional Access: require devices to be compliant and at or below an acceptable Defender machine-risk level before granting access.
- Track Microsoft Secure Score (Defender portal) as the security posture KPI; work the top recommendations.
7. Phase 6 — Compliance: SOC 2 and ISO 27001 (without Purview)
The technical controls configured in Phases 2–5 (Entra identity, Intune device management, Defender endpoint protection) implement most of the SOC 2 Trust Services Criteria and ISO 27001 Annex A technical controls. What remains is to assess, track, and evidence those controls and to centralize logging — handled here without Microsoft Purview.
- Control assessment and evidence — use a GRC platform or a manual register. Adopt a compliance-automation/GRC tool (for example Vanta, Drata, Secureframe, or Hyperproof) that connects to Entra, Intune, and Defender, automatically pulls control evidence, maps it to the SOC 2 and ISO 27001 control sets, tracks gaps, and produces auditor-ready reports. If you prefer no third-party tool, maintain a control register (mapping each SOC 2 / ISO 27001 control to its Microsoft enforcement point and owner) plus a restricted evidence library (e.g., SharePoint) with versioned exports.
- Logging and monitoring. Use Microsoft Entra audit logs and sign-in logs and Microsoft Defender XDR for activity and incident records. For centralized retention, correlation, and long-term evidence, forward these to Microsoft Sentinel or a third-party SIEM. Microsoft 365 activity data remains available through the Office 365 Management Activity API for SIEM ingestion without using the Purview portal.
- Security posture KPI. Track Microsoft Secure Score in the Defender portal, work the top recommendations, and export it on a regular cadence as evidence.
- Data-handling controls (DLP, classification, retention). These were Purview capabilities and are out of scope here. If SOC 2 confidentiality or ISO 27001 data-handling controls require data loss prevention, classification/labeling, or records retention, implement them with a dedicated data-security solution selected separately.
- Engage the auditor. SOC 2 (AICPA) and ISO 27001 certification require an independent assessor; provide the control register, evidence exports, Secure Score, and logging reports as the audit package.
8. Control mapping (SOC 2 / ISO 27001 → tooling)
| Control area (SOC 2 TSC / ISO 27001 Annex A) | Feature(s) |
|---|---|
| Logical access, least privilege, MFA | Entra Conditional Access, MFA, RBAC, PIM |
| Asset / device management | Intune device inventory, compliance & configuration policies |
| Malware & endpoint protection | Defender for Endpoint / Defender for Business (AV, ASR, EDR) |
| Encryption (at rest) | BitLocker (Windows), FileVault (macOS), mobile device encryption |
| Logging & monitoring | Entra audit & sign-in logs, Defender XDR; centralized in Microsoft Sentinel or a third-party SIEM |
| Vulnerability & patch management | Defender Vulnerability Management, Windows Update for Business via Intune |
| Data protection & classification | Dedicated third-party DLP / data-security tooling (selected separately — not covered here) |
| Risk assessment & continuous monitoring | Secure Score + a GRC platform (e.g., Vanta/Drata) or a manual control register |
| Incident detection & response | Defender XDR, automated investigation and remediation |
| Change management & traceability | RBAC + Entra/Defender audit logs (via SIEM) + documented approval process |
9. Ongoing operations
| Cadence | Activity |
|---|---|
| Daily / continuous | Defender incident triage and automated remediation; alerts |
| Weekly | Secure Score recommendations; device compliance drift; vulnerability remediation |
| Monthly | Patch/update ring review; enrollment and license reconciliation |
| Quarterly | Export Secure Score and GRC/control-register evidence; review Conditional Access and RBAC; APNs certificate expiry check |
| Annually | Renew Apple APNs and ABM tokens; full SOC 2 / ISO 27001 control review with the auditor |
10. Notes and caveats
- Compliance management is external to this SOP. With Purview excluded, control assessment, scoring, and evidence collection are handled by a GRC platform or a manual register, and centralized logging by a SIEM (e.g., Microsoft Sentinel) fed from Entra and Defender.
- Compliance ≠ configuration. These controls supply technical enforcement and audit evidence; certification still requires written policies, organizational procedures, vendor management, and an independent assessor.
- July 2026 licensing change. E3/E5 gain Intune Suite features (Remote Help, Advanced Analytics, Plan 2; E5 also Endpoint Privilege Management, Enterprise App Management, Cloud PKI) with a ~$3/user/month increase — factor this into any renewal timed near that date.
- APNs certificate must be renewed every year by the same Apple ID; if it lapses, all Apple devices fall out of management. Track its expiry.
- Verify against current vendor docs before relying on exact feature names or pricing — Microsoft re-packages these services frequently.