Morecambe Bay Partnership is a community-focused organisation dedicated to supporting environmental, economic, and social initiatives across the Morecambe Bay region. Working with a range of stakeholders, partners, and local communities, the organisation relies on secure digital systems to enable collaboration, communication, and the delivery of key projects. As cyber threats continue to evolve, maintaining a strong security posture became an important priority to help protect organisational data and ensure the continued reliability of its Microsoft 365 environment.
As cyber security risks become increasingly sophisticated, Morecambe Bay Partnership wanted to review and strengthen its Microsoft 365 security configuration. While the organisation already had a solid foundation in place, there was an opportunity to align security controls more closely with Microsoft best practices and improve its overall Secure Score.
The review identified several areas where additional protection could be introduced, including identity security, email threat protection, device management, information protection, and user access controls. The organisation also wanted to reduce the risk of phishing attacks, malware infections, unauthorised access, and accidental data exposure while maintaining a positive user experience.
A structured security improvement programme was proposed to enhance protection across multiple layers of the Microsoft 365 environment and support the organisation’s long-term cyber security objectives.
Following a comprehensive review of the Microsoft 365 environment, we developed a security enhancement programme focused on improving both preventative and detective controls.
A key element of the project was the implementation and enforcement of Conditional Access policies. These controls were designed to strengthen identity protection by ensuring that access to organisational resources was governed by appropriate security requirements.
To improve email security, Microsoft Defender Standard policies were enabled alongside updates to Anti-Phish, Anti-Malware, and Anti-Spam policies. These enhancements provided stronger protection against common attack methods and helped reduce the likelihood of malicious emails reaching end users.
Quarantine management was improved through the creation of a dedicated quarantine policy and updates to global security settings, allowing suspicious messages to be managed more effectively and consistently.
Additional governance and compliance improvements included reviewing user consent settings, implementing data sensitivity labels, and introducing company branding within Microsoft 365. These enhancements improved security awareness while helping users identify legitimate organisational resources.
User permissions were further tightened by preventing the installation of Outlook add-ins without administrative oversight and disabling external calendar sharing to reduce potential data exposure.
To support flexible working practices, mobile application protection policies were introduced for Bring Your Own Device (BYOD) scenarios. This ensured organisational data remained protected while allowing authorised users to access business applications securely from personal devices.
Throughout the engagement, security controls were aligned with Microsoft recommendations to maximise the organisation’s Secure Score and create a more resilient security framework.
The project delivered significant improvements to the overall cyber security posture of Morecambe Bay Partnership.
By implementing layered security controls across identity, email, device, and data protection, the organisation significantly reduced its exposure to common cyber threats. Conditional Access policies strengthened account security and provided greater control over how users accessed organisational resources.
Enhanced Microsoft Defender and email security policies improved protection against phishing attempts, malware, and spam, helping to reduce risk and improve operational confidence. Information protection controls, including sensitivity labels and governance improvements, helped establish stronger safeguards around organisational data.
The introduction of BYOD application protection policies supported secure remote and mobile working without compromising data security. At the same time, controls around Outlook add-ins and external calendar sharing reduced potential avenues for data leakage.
One of the most measurable outcomes was the increase in Microsoft Secure Score, demonstrating substantial alignment with Microsoft security best practices. The organisation now benefits from a more secure, well-governed Microsoft 365 environment that supports both current operations and future growth.
- Implemented and enforced Conditional Access policies
- Strengthened protection against phishing attacks
- Enhanced anti-malware and anti-spam controls
- Enabled Microsoft Defender Standard security protections
- Improved email quarantine management and governance