Skip to content

Microsoft 365 Apps Security Baseline

Violet Hansen edited this page May 1, 2026 · 11 revisions

Microsoft 365 Apps Security Baseline | Harden System Security

Microsoft 365 Apps Security Baselines - Harden Windows Security GitHub repository

The security baseline for Microsoft 365 Apps for enterprise is published twice a year, usually in June and December. Use the Harden System Security App to effortlessly apply them onto your system.

On this page, the Harden System Security app enables you to apply the Microsoft 365 Apps Security Baselines on your system, verify compliance, and remove the applied policies.

You can measure the compliance level of your system using the built-in compliance assessment functionality by simply pressing the Verify button on this page. You will receive a detailed report of every security measure inside the Microsoft 365 Apps Security Baseline and you will be able to export this security report to a properly formatted JSON file as well.

Each security measure has the following details:

  1. Friendly Name: Helps you easily identify the security measure and its purpose.
  2. Source: Shows you which part of the Microsoft 365 Apps Security Baseline this security measure belongs to.
  3. Status: Whether the current system applies the security measure or not.
  4. Current Value: The current value of the security measure on the system.
  5. Expected Value: The correct and secure value the security measure should be in order to be compliant.

  • You can use the Baseline selector Dropdown button to select an older or newer baseline to be applied, removed or verified on your system.

  • Use the Browse button to browse for a Microsoft 365 Apps Security Baseline ZIP file that you've already downloaded on your device, this way you can use it on systems that have no Internet connectivity.

    • The Remember option which is on by default, will remember the file path you select so that when you close and reopen the app, you won't have to browse and select it again.
  • When the results are loaded, you can right-click or tap + hold on each security measure in this page to access additional options such as Delete or Apply in order to selectively remove it from your system or apply it to your system. The Delete key on your keyboard can also be used as a shortcut for removal. These functionalities allow you to fine-tune the Microsoft 365 Apps Security baseline policies so that if you don't want or need some of the policies it offers, you can undo and remove them from your system or apply only a subset of them.


Note

Either when downloading the Microsoft 365 Apps Security Baseline from Microsoft Servers or when browsing for the zip file manually, the Harden System Security app will process it entirely in memory, and apply it without writing any temporary files to disk. The same is true for verification or removal processes.

While this approach increases development complexity, it significantly improves security by preventing malicious interference with temporary files before application.

The app caches the baseline in memory to avoid unnecessary re-downloads and/or re-reads. The cache expires every 2 hours, after which it is refreshed with the latest data from the Microsoft Server/File path you provided, and this only happens if the app is open. The cache is compressed to minimize memory usage.


Microsoft 365 Apps Security Baseline | Harden System Security









C#


Clone this wiki locally