Microsoft 365 ships with a substantial security and compliance toolkit, and most Australian businesses use a fraction of it. The licences are paid for; the policies are left at default. That gap — between capability purchased and capability configured — is where most incidents and most audit findings live.
This guide walks through what is actually included in Microsoft 365, how Microsoft Purview handles data classification and compliance, how sensitivity labels work in practice, what the Australian Privacy Act requires of you, and which Essential Eight controls Business Premium can meet.
What security features are included in Microsoft 365?
The answer depends on the plan, and the differences matter commercially.
Business Basic and Business Standard include Exchange Online Protection (anti-spam and anti-malware mail filtering), basic Entra ID with security defaults, audit logging, and standard data encryption. They do not include device management, Conditional Access, or advanced threat protection. They are collaboration licences, not security licences.
Business Premium is the plan most Australian small and medium businesses should be on. It adds:
- Microsoft Defender for Business — endpoint detection and response, next-generation antivirus, attack surface reduction rules, vulnerability management, and automated investigation across up to 300 users.
- Defender for Office 365 Plan 1 — Safe Links, Safe Attachments, anti-phishing with impersonation protection, and real-time detonation of suspicious content.
- Entra ID P1 — Conditional Access, self-service password reset with writeback, group-based licensing, and Application Proxy.
- Microsoft Intune Plan 1 — full device management, compliance policies and app protection.
- Azure Information Protection Plan 1 — sensitivity labels with manual classification and encryption.
E3 adds enterprise-scale Purview features including manual retention and eDiscovery Standard, plus Windows Enterprise. E5 adds Defender for Endpoint Plan 2, Defender for Cloud Apps, Entra ID P2 with risk-based Conditional Access and Privileged Identity Management, Purview automatic classification, insider risk management, communication compliance, and eDiscovery Premium.
A properly configured Business Premium tenant is significantly more secure than a default E5 tenant. Spend the money on configuration before you spend it on upgrade.
The controls we deploy as standard for Australian clients under managed security services are: MFA for all users through Conditional Access, legacy authentication blocked, device compliance required for Microsoft 365 access, Defender for Business fully onboarded with attack surface reduction rules, Safe Links and Safe Attachments enabled, external sender warnings, audit logging retained, quarantine review, and DMARC enforced.
Microsoft Purview — data classification and compliance
Microsoft Purview is the compliance and data governance layer of Microsoft 365. Where Defender protects against attackers, Purview governs the information itself.
Data classification. Sensitive information types identify content patterns — credit card numbers, Australian Tax File Numbers, Medicare numbers, driver licence numbers, passport numbers, bank account details. Purview ships with Australian-specific detection types, which matters for local compliance work.
Data loss prevention (DLP). Policies detect sensitive content and act on it — warn the user, require a business justification, block the action, or notify a compliance officer. DLP applies across Exchange Online, SharePoint, OneDrive, Teams chat and channels, and endpoints. A common first policy for Australian businesses blocks external email containing more than a handful of TFNs or credit card numbers.
Retention and records. Retention policies keep content for a defined period and delete it afterwards, either across a workload or targeted by label. This addresses both regulatory record-keeping and the opposite problem — data hoarding that increases breach exposure.
Audit and eDiscovery. Unified audit log searching, content search across mailboxes and sites, and legal hold. Business Premium retains audit logs for 180 days; E5 extends this and adds long-term audit retention.
Insider risk and communication compliance (E5) detect risky internal behaviour such as mass downloads before resignation, and monitor for inappropriate or regulated communications.
Start narrow. Purview projects fail when businesses attempt full enterprise classification on day one. Pick the two or three information types that would genuinely cause harm if leaked, write policies for those, run them in simulation mode, then expand.
Sensitivity labels and information protection
Sensitivity labels are the most useful Purview capability for a typical Australian business, and also the most commonly over-engineered.
A label applies protection that travels with the content — it persists when a file is emailed, downloaded, copied to a USB drive, or opened outside your tenant. Depending on configuration, a label can apply visual markings (headers, footers, watermarks), enforce encryption with defined permissions, restrict copying and printing, prevent forwarding, and control external sharing.
A workable label taxonomy for a business of 20 to 300 staff has four labels, not fourteen:
- Public — approved for external release. No protection.
- General — ordinary internal business content. Visual marking only.
- Confidential — commercially sensitive; encrypted, restricted to internal users, no external sharing without an exception.
- Highly Confidential — personal information, contracts, board material; encrypted and restricted to a named group, no forwarding or printing.
Practical guidance from deployments we have run:
- Set a default label (usually General) so unlabelled content is the exception rather than the rule.
- Use mandatory labelling only after a period of voluntary use, and pair it with clear guidance.
- Auto-labelling based on sensitive information types (E5, or service-side in some plans) removes the reliance on user judgement — this is where the real value sits.
- Test encryption with external recipients before rolling out. Encrypted files that clients and suppliers cannot open generate immediate pressure to abandon the whole programme.
- Label containers as well as content — Teams, SharePoint sites and Microsoft 365 groups can carry labels that control external sharing and unmanaged device access, which is often more effective than labelling individual documents. That governance sits alongside the managed SharePoint structure.
Microsoft 365 compliance and the Australian Privacy Act
Australian businesses handling personal information have obligations under the Privacy Act 1988 and the Australian Privacy Principles, with reforms tightening those obligations and increasing penalties. Three APPs drive most Microsoft 365 configuration decisions.
APP 11 — security of personal information. You must take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. "Reasonable steps" is assessed against the sensitivity of the information and the size of your business, but in 2026 a court or the OAIC is unlikely to accept an environment without multi-factor authentication as reasonable. MFA, Conditional Access, device compliance, encryption and access logging are the practical implementation.
APP 11.2 — destruction or de-identification. Personal information no longer needed for a permitted purpose must be destroyed or de-identified. Purview retention policies with automatic deletion implement this; indefinite retention of everything is a compliance risk, not a safe default.
APP 8 — cross-border disclosure. You remain accountable for personal information disclosed overseas. Microsoft 365 data for Australian tenants is stored at rest in Australian datacentres (Sydney and Melbourne) when the tenant is provisioned in Australia, though some services process data elsewhere. Document this in your privacy policy and record where data resides.
The Notifiable Data Breaches scheme requires assessment within 30 days and notification to the OAIC and affected individuals where serious harm is likely. Meeting that timeframe requires the ability to determine what was accessed — which requires audit logging that is switched on and retained before the incident, not configured afterwards. Verify audit log retention, sign-in log export, and Defender alert history now.
We work through the full mapping of Privacy Act obligations to Microsoft 365 controls in governance and compliance readiness engagements, including breach response planning and evidence collection.
Essential Eight controls met by Microsoft 365 Business Premium
A correctly configured Business Premium tenant reaches Essential Eight Maturity Level 2 for the majority of controls.
| Control | Business Premium capability | Maturity Level 2 achievable |
|---|---|---|
| Application control | Intune App Control for Business | Yes, with audit-mode preparation |
| Patch applications | Intune, Defender vulnerability management | Yes |
| Configure Microsoft Office macro settings | Intune configuration profiles | Yes |
| User application hardening | Defender attack surface reduction rules | Yes |
| Restrict administrative privileges | Entra ID roles, admin accounts, access reviews | Partly — PIM requires Entra ID P2 |
| Patch operating systems | Intune update rings, Windows Autopatch | Yes |
| Multi-factor authentication | Entra ID P1 Conditional Access | Yes — Level 3 needs phishing-resistant methods |
| Regular backups | Purview retention plus third-party M365 backup | Yes, with a dedicated backup product |
Two caveats are worth stating plainly. Microsoft 365 retention is not a backup — it protects against deletion within policy, not against a compromised tenant or a bad-faith administrator, so a separate Microsoft 365 backup is required for the backup control. And Privileged Identity Management, which makes just-in-time administrative access practical, needs Entra ID P2 as an add-on to Business Premium.
Where to start
If your tenant has never had a security review, the order of work that produces the most risk reduction is: enforce MFA through Conditional Access and block legacy authentication; onboard every device to Intune with compliance enforced; fully deploy Defender for Business and enable Safe Links, Safe Attachments and anti-phishing; verify audit logging and retention; then implement DLP and sensitivity labels for your two or three most sensitive information types.
Mycelium 365 is a Microsoft Solutions Partner based in Melbourne. We assess, configure and manage Microsoft 365 security and compliance for businesses across Australia and New Zealand — Defender, Purview, Conditional Access, Intune and Essential Eight maturity reporting — as a managed service rather than a one-off project, because a security baseline that is not maintained drifts within months.
