Incident Response Plan with M365BP Publication

Insta-550

I’ve just finished off a new publication – Incident Response Plan with Microsoft 365 Business Premium. The details are:

Executive Summary

This playbook provides a comprehensive, step-by-step approach for responding to security incidents in Microsoft 365 Business Premium environments. It follows the NIST incident response lifecycle and integrates Microsoft’s best practices for cloud security. The plan is designed to help organizations minimize damage, protect sensitive data, restore operations quickly, and meet legal and regulatory requirements.

Key Components

Length = Over 90 pages

Quick Start Guide

  • Emergency Checklist: Immediate actions for newly discovered incidents, with a printable 1–2 page checklist for high-pressure situations.
  • Decision Tree: Rapid classification of incident severity (Critical, High, Medium, Low) to guide response urgency.

Notable Features

  • Checklists and Templates: Ready-to-use forms for incident logs, evidence collection, communications, and insurance claims.
  • Technical Guidance: PowerShell scripts and portal instructions for investigation and remediation.
  • Compliance Alignment: Guidance for GDPR, HIPAA, CCPA, and other regulatory notifications.
  • Continuous Improvement: Emphasis on regular drills, lessons learned, and updating the plan after incidents.

Intended Outcomes

  • Swift, organized response to security incidents.
  • Minimized business disruption and data loss.
  • Compliance with legal and regulatory requirements.
  • Improved cyber resilience through ongoing training and process refinement.

Like my last publication:

Implementing ACSC Essential Eight Maturity Level 3 with Microsoft 365 Business Premium publication

You can get your copy by heading over to my Ko-Fi at:

https://ko-fi.com/ciaops

and leaving me a one time tip for whatever you feel it is worth I’ll then email you a copy. Also ensure you include a message letting me know you want this particular publication

Note – All CIAOPS Patrons receive all my publications for free as part of their subscription. The benefits of membership.

Need to Know podcast–Episode 357

Welcome to another podcast episode where I aim to bring you up to date with the latest in the Microsoft Cloud as well as share my knowledge and insights. In this episode I dig into how you need to focus and avoid distractions as well as building your knowledge with products and automations you already have.

Brought to you by www.ciaopspatron.com

you can listen directly to this episode at:

https://ciaops.podbean.com/e/episode-357-less-is-more/

Subscribe via iTunes at:

https://itunes.apple.com/au/podcast/ciaops-need-to-know-podcasts/id406891445?mt=2

or Spotify:

https://open.spotify.com/show/7ejj00cOuw8977GnnE2lPb

Don’t forget to give the show a rating as well as send me any feedback or suggestions you may have for the show.

Resources

Explore the tools, communities, and content mentioned in this episode:

Announcements

Show Notes

Advancing Microsoft 365: New capabilities and pricing update | Microsoft 365 Blog

Available today: GPT-5.2 in Microsoft 365 Copilot | Microsoft 365 Blog

Meet Agents in OneDrive : Your AI assistant built with your own content | Microsoft Community Hub

What’s New in Copilot Studio: November 2025 Updates and Features

View or restore previous versions of Microsoft 365 Copilot Pages

Security and governance innovations for Microsoft 365 Copilot and agents from Ignite 2025 | Microsoft Community Hub

New! Centralized Agent Dashboard and Enhanced Reporting | Microsoft Community Hub

Security and governance innovations for Microsoft 365 Copilot and agents from Ignite 2025 | Microsoft Community Hub

What’s new in Microsoft Intune: December 2025 – Microsoft Intune Blog

Microsoft 365 adds advanced Microsoft Intune solutions at scale – Microsoft Intune Blog

What’s New in Microsoft Sentinel: December 2025 | Microsoft Community Hub

What’s new in Microsoft Entra – November 2025

Microsoft Ignite 2025: Top Security Innovations You Need to Know | Microsoft Community Huba

CIA Brief 20251214

image

What’s new in Microsoft Intune: December 2025 –

https://techcommunity.microsoft.com/blog/microsoftintuneblog/whats-new-in-microsoft-intune-december…

Breaking down security silos: Microsoft Defender for Cloud Expands into the Defender Portal –

https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/breaking-down-security-silos-mi…

Imposter for hire: How fake people can gain very real access –

https://www.microsoft.com/en-us/security/blog/2025/12/11/imposter-for-hire-how-fake-people-can-gain…

What’s New in Microsoft Sentinel: December 2025 –

https://techcommunity.microsoft.com/blog/microsoftsentinelblog/what%E2%80%99s-new-in-microsoft-sent…

Available today: GPT-5.2 in Microsoft 365 Copilot –

https://www.microsoft.com/en-us/microsoft-365/blog/2025/12/11/available-today-gpt-5-2-in-microsoft-…

From awareness to action: Building a security-first culture for the agentic AI era –

https://www.microsoft.com/en-us/microsoft-cloud/blog/2025/12/10/from-awareness-to-action-building-a…

What’s new in Microsoft Entra – November 2025 –

https://techcommunity.microsoft.com/blog/microsoft-entra-blog/what%E2%80%99s-new-in-microsoft-entra…

Native macOS screen sharing in Teams meetings –

https://techcommunity.microsoft.com/blog/microsoft365insiderblog/native-macos-screen-sharing-in-tea…

Now generally available: Modernizing Microsoft Entra ID auth flows with WebView2 in Windows 11 –

https://techcommunity.microsoft.com/blog/windows-itpro-blog/now-generally-available-modernizing-mic…

Microsoft 365 adds advanced Microsoft Intune solutions at scale –

https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-…

New! Centralized Agent Dashboard and Enhanced Reporting –

https://techcommunity.microsoft.com/blog/microsoft365copilotblog/new-centralized-agent-dashboard-an…

Transforming mining: How Frontier Firms lead with AI and agentic innovation –

https://www.microsoft.com/en-us/industry/blog/energy-and-resources/mining/2025/12/08/transforming-m…

Security and governance innovations for Microsoft 365 Copilot and agents from Ignite 2025 –

https://techcommunity.microsoft.com/blog/microsoft365copilotblog/security-and-governance-innovation…

Secure Boot playbook for certificates expiring in 2026 –

https://techcommunity.microsoft.com/blog/windows-itpro-blog/secure-boot-playbook-for-certificates-e…

Multi-agentic AI: Unlocking the next wave of business transformation –

https://www.microsoft.com/en-us/microsoft-cloud/blog/2025/12/04/multi-agentic-ai-unlocking-the-next…

Microsoft Defender: Smart Containment Stops Exposed Privileged AD Domain Accounts –

https://techcommunity.microsoft.com/blog/microsoft-security-blog/microsoft-defender-smart-containme…

After hours

[HOONIGAN] Gymkhana 2025: Aussie Shred — Travis Pastrana Does the IMPOSSIBLE in a Subaru Brat

https://www.youtube.com/watch?v=daYgg2YSA2g

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week

Implementing ACSC Essential Eight Maturity Level 3 with Microsoft 365 Business Premium publication

bp

I’ve developed a new publication called – “Implementing ACSC Essential Eight Maturity Level 3 with Microsoft 365 Business Premium”. Here is the summary:


This guide is designed for small and medium business managed service providers (MSPs) aiming to achieve ACSC Essential Eight Maturity Level 3 (ML3) using Microsoft 365 Business Premium. ML3 is the highest standard of cyber resilience recommended by the Australian Cyber Security Centre (ACSC), focusing on proactive defense against sophisticated cyber threats and regulatory compliance.


  • The Essential Eight are eight interlocking security controls: Application Control, Patch Applications, Configure Office Macro Settings, User Application Hardening, Restrict Administrative Privileges, Patch Operating Systems, Multi-Factor Authentication (MFA), and Regular Backups.
  • ML3 requires proactive, defense-in-depth measures, rapid patching, advanced identity management, and centralized logging.
2. Microsoft 365 Business Premium as the Foundation
  • Integrates productivity tools with enterprise-grade security (Intune, Entra ID, Defender for Business, Purview).
  • The new Microsoft Defender Suite for Business Premium (formerly E5 Security add-on) provides advanced features like privileged identity management, threat hunting, and extended data retention.
3. Implementation Guidance for Each Control
  • Application Control: Use Windows Defender Application Control (WDAC) to prevent unauthorized code/drivers. Requires hardware support (TPM 2.0, VBS).
  • Patch Management: Enforce rapid patching for applications and OS, automate updates via Intune, and use Defender Vulnerability Management for monitoring.
  • Restrict Admin Privileges: Separate admin accounts, enforce least privilege, use Entra Privileged Identity Management (PIM), and centralize logging.
  • MFA: Only phishing-resistant, cryptographically bound factors (FIDO2, smartcards, Windows Hello for Business) are permitted at ML3.
  • Macro & Application Hardening: Block macros from the Internet, enforce signed macros, remove legacy components (IE11, old .NET), and apply Attack Surface Reduction rules.
  • Regular Backups: Use Microsoft Purview for retention, Azure Backup for non-M365 workloads, and test restores regularly.
  • Governance: Continuous compliance monitoring with Purview Compliance Manager, Sentinel, and regular audits.
4. Business & Operational Benefits
  • Enhanced security, regulatory compliance, operational efficiency, business continuity, and competitive advantage.
5. Licensing & Cost Considerations
  • ML3 can be achieved with Business Premium plus the Defender Suite add-on.
  • The guide provides a staged implementation plan (gap assessment, MFA rollout, patching, advanced controls, continuous improvement).

Conclusion

Achieving ML3 with Microsoft 365 Business Premium and the Defender Suite delivers measurable improvements in security, compliance, and resilience. The guide provides step-by-step instructions, best practices, and references to Microsoft documentation for each control area. Continuous improvement, regular training, and staying current with ACSC/Microsoft updates are emphasized for ongoing compliance and protection.


There is lots that I could keep adding to this publication but I’m going to throw it out there and see whether people find value before I invest more time in it. Currently the report is 31 pages in total.

I have also decided on a different distribution method this time as well. If you want a copy head over to my Ko-Fi at:

https://ko-fi.com/ciaops

and leave me a one time tip for whatever you feel it is worth I’ll email you a copy. Also ensure you include a message letting me know you want the publication.

If you then provide me feedback on the publication, such as how it can be improved or any errors you find, I’ll then send you the next version for free when it becomes available.

This seems to me to be the easiest way to determine whether it is worth my time investing more effort to improve the document.

Let’s see.

CIA Brief 20251206

image

Microsoft Ignite 2025: Top Security Innovations You Need to Know –

https://techcommunity.microsoft.com/blog/microsoft-security-blog/microsoft-ignite-2025-top-security…

Microsoft 365 adds advanced Microsoft Intune solutions at scale –

https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-…

Advancing Microsoft 365: New capabilities and pricing update –

https://www.microsoft.com/en-us/microsoft-365/blog/2025/12/04/advancing-microsoft-365-new-capabilit…

Microsoft Sentinel platform — Unified, Graph-enabled, and AI-ready Security –

https://techcommunity.microsoft.com/blog/microsoftmechanicsblog/microsoft-sentinel-platform-%E2%80%…

View or restore previous versions of Microsoft 365 Copilot Pages –

https://techcommunity.microsoft.com/blog/microsoft365insiderblog/view-or-restore-previous-versions-…

How to build forward-thinking cybersecurity teams for tomorrow –

https://www.microsoft.com/en-us/security/blog/2025/12/02/how-to-build-forward-thinking-cybersecurit…

Microsoft Defender Experts – S.T.A.R. Series –

https://techcommunity.microsoft.com/blog/microsoftsecurityexperts/microsoft-defender-experts—s-t-…

Key findings from product telemetry: top storage security alerts across industries –

https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/key-findings-from-product-telem…

SharePoint Showcase highlights: Biggest news from Microsoft Ignite 2025 –

https://techcommunity.microsoft.com/blog/microsoft365insiderblog/sharepoint-showcase-highlights-big…

After hours

Following Max Verstappen’s Race Day Like NEVER BEFORE | Behind The Charge– https://www.youtube.com/watch?v=PjjQI9W5JkY

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week

CIAOPS Need to Know Microsoft 365 Webinar – December

laptop-eyes-technology-computer_thumb

Join me for the free monthly CIAOPS Need to Know webinar. Along with all the Microsoft Cloud news we’ll be taking a look at Copilot Notebooks.

Shortly after registering you should receive an automated email from Microsoft Teams confirming your registration, including all the event details as well as a calendar invite.

You can register for the regular monthly webinar here:

December Registrations

(If you are having issues with the above link copy and paste – https://bit.ly/n2k2512)

The details are:

CIAOPS Need to Know Webinar – December 2025
Tuesday 30th of December 2025
11.00am – 12.00am Sydney Time

All sessions are recorded and posted to the CIAOPS Academy.

The CIAOPS Need to Know Webinars are free to attend but if you want to receive the recording of the session you need to sign up as a CIAOPS patron which you can do here:

http://www.ciaopspatron.com

or purchase them individually at:

http://www.ciaopsacademy.com/

Also feel free at any stage to email me directly via director@ciaops.com with your webinar topic suggestions.

I’d also appreciate you sharing information about this webinar with anyone you feel may benefit from the session and I look forward to seeing you there.

Copilot Agents licensing usage update

 

Things have changed recently when it comes to licensing Coilot Agents. Here is the latest information I can find. In short, every user that needs access to tenant information for use with Copilot, requires a license.


🔒 Confirmed Licensing Requirements

1. No Included Message Capacity with a Single M365 Copilot License

Confirmation: Correct. Your individual Microsoft 365 Copilot license does not include a pool of Copilot Studio message capacity that can be used by other users in the tenant who are unlicensed.

  • Your License Rights: Your M365 Copilot license grants you the right to:

    • Create and manage Copilot Studio agents for internal workflows at no extra charge for your own usage.

    • Access and use those agents yourself without incurring additional usage costs.

  • The Consumption: The consumption of your unlicensed colleagues is considered an organizational-level cost that must be covered by a separate organizational subscription for Copilot Studio.

2. Unlicensed Users Cannot Use Tenant-Grounded Agents Without Organizational Metering

Confirmation: Correct. Unlicensed users will not be able to use an agent that grounds its answers in shared tenant data (like SharePoint or OneDrive) unless the organization has set up a Copilot Studio billing subscription.

  • Agents that Access Tenant Data (SharePoint/OneDrive):

    • These agents access Graph-grounded data, which is considered a premium function and is billed on a metered basis (using “Copilot Credits”).

    • This metered consumption must be paid for by the organization.

  • The Required Organizational Licensing: To enable the unlicensed users to chat with your agent, the tenant administrator must set up one of the following Copilot Studio subscriptions:

    • Copilot Studio Message Pack (Pre-paid Capacity): Purchase packs of Copilot Credits (e.g., 25,000 credits per pack/month). The unlicensed users’ interactions are consumed from this central pool.

    • Copilot Studio Pay-As-You-Go (PAYG): Link a Copilot Studio environment to an Azure subscription. The interactions from the unlicensed users are billed monthly based on actual consumption (credits used) through Azure.

Official Licensing References

SharePoint / OneDrive Agent — Licensing & Usage Summary

Quick reference table describing what licenses and costs are required for users to access an agent that integrates with SharePoint or OneDrive.

Scenario User’s License Licensing Requirement to Access SharePoint/OneDrive Agent Usage Cost
Licensed User (You) Microsoft 365 Copilot (Add-on License) No additional license required. No additional charges for using the agent you created.
Unlicensed User (Colleague) Eligible M365 Plan (e.g., E3/E5) WITHOUT M365 Copilot Organizational Copilot Studio subscription (Pay‑As‑You‑Go or Message Pack) must be enabled in the tenant. Metered charges (Copilot Credits) are incurred against the organizational capacity / Azure subscription.

Key Reference: Microsoft documentation explicitly states: “If a user doesn’t have a Microsoft 365 Copilot license… if their organization enables metering through Copilot Studio, users can access agents in Copilot Chat that provide focused grounding on specific SharePoint sites, shared tenant files, or third-party data.” This confirms the unlicensed users’ access is contingent on the organizational metering being active.

Summary of Action Required

To make your agent available to your unlicensed colleagues, you need to inform your IT/licensing administrator that they must procure and enable Copilot Studio capacity (either Message Packs or Pay-As-You-Go metering) in your tenant. Your personal M365 Copilot license covers your creation and use, but not the consumption of others who are accessing premium, tenant-grounded data.

Microsoft agent usage estimator

The organizational consumption for agents created in Copilot Studio is measured in Copilot Credits.


💰 Copilot Studio Organizational Pricing (USD)

Microsoft offers two main ways for the organization to purchase the capacity consumed by unlicensed users accessing tenant-grounded data:

 

Copilot Credits — Pricing

Pricing Model Cost Capacity Provided Best For
Prepaid Capacity Pack USD $200.00 per month (per pack) 25,000 Copilot Credits per month (tenant-wide pool) Stable/predictable, moderate usage, budget control (lower cost per credit).
Pay-As-You-Go (PAYG) USD $0.01 per Copilot Credit No upfront commitment. Billed monthly based on actual usage. Pilots, highly variable usage, or as an overage safety net for the Prepaid Packs.

Note: All prices are Estimated Retail Price (ERP) in USD and are subject to change. Your final price will depend on your specific Microsoft agreement (e.g., Enterprise Agreement) and local currency conversion.


📊 Copilot Credit Consumption Rates

The cost is based on the complexity of the agent’s response, not just the number of messages. Since your agent uses SharePoint/OneDrive data, the key consumption rate to note is for Tenant Graph grounding.

 

Copilot credit consumption per agent action / scenario
Agent Action/Scenario Copilot Credits Consumed (Per Event)
Tenant Graph Grounding (Accessing SharePoint/OneDrive data) 10 Copilot Credits
Generative Answer (Using an LLM to form a non-grounded answer) 2 Copilot Credits
Classic Answer (Scripted topic response) 1 Copilot Credit
Agent Action (Invoking tools/steps, e.g., a Power Automate flow) 5 Copilot Credits

Example Cost Calculation

Let’s assume an unlicensed user asks the agent a question that requires it to search your SharePoint knowledge source (Tenant Graph Grounding) and generate a summary answer (Generative Answer)The Prepaid Pack option is more economical for this level of steady, high usage. Your IT team will need to monitor usage and choose the appropriate mix of Prepaid Packs and PAYG overage protection.

Total Credits = (Credits for Grounding) + (Credits for Generative Answer)
Total Credits = 10 + 2 = 12 Credits per conversation

If 100 unlicensed users each have 5 conversations per day:

Daily Conversations: 100 users × 5 conversations = 500
Daily Credits: 500 conversations × 12 credits/conversation = 6,000 credits

Monthly Credits (approx): 6,000 credits/day × 30 days = 180,000 credits

Monthly Cost Estimate:

Using Prepaid Packs:
180,000 credits / 25,000 credits per pack ≈ 7.2 packs
The organization would need to buy 8 packs per month.

Monthly Cost: 8 packs × $200 = USD $1,600

Using Pay-As-You-Go (PAYG):
Monthly Cost: 180,000 credits × $0.01/credit = USD $1,800

The Prepaid Pack option is more economical for this level of steady, high usage. Your IT team will need to monitor usage and choose the appropriate mix of Prepaid Packs and PAYG overage protection.

Here are the sources that were used to compile the information, each with a direct hyperlink:

  1. Copilot Studio licensing – Microsoft Learn

  2. Billing rates and management – Microsoft Copilot Studio

  3. Microsoft 365 Copilot Pricing – AI Agents | Copilot Studio

  4. Copilot Studio pricing & licensing (2025): packs and credits

  5. Copilot Credits consumption – LicenseVerse – Licensing School

  6. Get access to Copilot Studio – Microsoft Learn

  7. Manage Copilot Studio credits and capacity – Power Platform | Microsoft Learn

 

 

Need to Know podcast–Episode 356

I am joined once again by Phil Meyer to review the most important and relevant announcements from Microsoft Ignite. Plenty around AI but also a few other gems you may have overlooked, so sit back and listen in as we focus on what you should be paying attention to.

Brought to you by www.ciaopspatron.com

you can listen directly to this episode at:

https://ciaops.podbean.com/e/episode-356-philme-is-back/

Subscribe via iTunes at:

https://itunes.apple.com/au/podcast/ciaops-need-to-know-podcasts/id406891445?mt=2

or Spotify:

https://open.spotify.com/show/7ejj00cOuw8977GnnE2lPb

Don’t forget to give the show a rating as well as send me any feedback or suggestions you may have for the show.

Resources

Explore the tools, communities, and content mentioned in this episode:

Announcements

Flight School: Mastering Copilot for IT Pros – https://blog.ciaops.com/2025/11/14/flight-school-mastering-copilot-for-it-pros/
CIAOPS Academy deprecation notification – https://blog.ciaops.com/2025/11/10/ciaops-academy-deprecation-notification/

Show Notes

Microsoft 365 powered by Work IQ: Built to Support How You Work –

https://www.youtube.com/watch?v=ve66gLVYaRw

Synced Passkeys in Microsoft Entra for Phishing-resistant MFA –

https://www.youtube.com/watch?v=36nIaSBJ7_U

Ignite’25 Spotlight: Announcing Microsoft Baseline security mode –

https://techcommunity.microsoft.com/blog/microsoft_365blog/ignite%E2%80%9925-spotlight-announcing-m…

Introducing Microsoft 365 Copilot Business: Empowering Small and Medium Businesses with AI –

https://techcommunity.microsoft.com/blog/microsoft365copilotblog/introducing-microsoft-365-copilot-…

Future-Proofing Your Channel Business: Strategies for Asia Partners – Future-Proofing Your Channel Business: Strategies for Asia Partners | PBRK440 – https://www.youtube.com/watch?v=xvwZYUbVW08

Question – https://youtu.be/xvwZYUbVW08?t=2604