Microsoft Security · Customer Best Practices

Driving Operational Excellence

A daily, weekly, and monthly rhythm for the Microsoft Security portals — Defender, Purview, and Entra. Mapped to a real ransomware attack chain so every activity has a clear why.

24/7
Threats operate continuously — our defenses must too.
28-day
Microsoft's rolling window for measuring active protection & usage.
10+ days
Minimum usage days per workload for active-protection credit.
3 → 1
Defender, Purview, and Entra — one rhythm across all three.

The three portals, one estate

Each portal owns a distinct surface — threats, data, and identity. Used together they form the operational core of E5 Security.

Microsoft Defender

security.microsoft.com

Extended Detection & Response (XDR). Endpoints · Email · Identity · Cloud Apps. Unified incidents, advanced hunting, automated investigation & response.

Microsoft Purview

purview.microsoft.com

Data Security & Compliance. Sensitivity labels, encryption, Endpoint DLP, Insider Risk Management, data lifecycle & records management.

Microsoft Entra

entra.microsoft.com

Identity & Access. Conditional Access, Identity Protection, Privileged Identity Management, Access Reviews, Entitlement Management.

The cadence framework

Daily, weekly, monthly — each frequency has a purpose

Not every activity needs to happen every day. Map the work to the cadence that fits its value curve. The three layers compound — missing the daily rhythm starves the weekly and monthly ones of signal.

Daily

React & reduce dwell time

Incidents, alerts, false positives, sensor health, user-reported messages, risky sign-ins. These decay fast — if you miss a day, you lose the signal.

Weekly

Tune & trend

Secure Score drift, emerging threats, policy assessments, targeted-user reports, access review check-ins. Pattern detection, not firefighting.

Monthly

Govern & optimize

Policy audits, configuration baselines, access certifications, insider risk posture, data loss trends, license optimization. Slower cycles tied to governance and ROI.

Attack-chain context · interactive

Anatomy of a modern ransomware attack

Eight stages an attacker walks through. Defenders win by breaking the chain at any one of them. Click any stage to highlight every Defender, Purview, and Entra activity that helps detect, prevent, or respond at that stage.

No filter — showing all activities
Portal deep dive

Activity dashboard

The concrete actions that compress mean time to detect & respond. Pick a portal, pick a cadence, work the cards. The attack-chain chips at the bottom of each card show which ransomware stages that activity helps break — and they sync with the filter above.

The non-negotiables

Best practices per portal

Cadence without controls is just dashboards. Eight non-negotiables for each portal — the guardrails that turn activity into real protection.

Getting started

A 30 / 60 / 90 day adoption plan

Don't try to switch on every activity at once. Build the rhythm in three steps — the layers compound. A team that tries to start with monthly governance before they have daily rhythm ends up doing neither.

What consistent rhythm delivers

Cadence is the input — these are the outcomes

Indicative figures based on typical Microsoft engagement patterns. Your mileage may vary by tenant size, industry, and maturity — but the direction is consistent.

Where to go next

Documentation & references

Bookmark these. Every activity in this dashboard has a corresponding Microsoft Learn doc that's the source of truth when you need to go deeper.