Architecture · Enterprise Architecture
Microsoft 365 Organisation Architecture
A reference design for a cloud first organisation running identity, collaboration, endpoint management and security in one Microsoft 365 tenant.
IntermediateUpdated 2026-09-01
Overview
This pattern places Entra ID at the centre, with Conditional Access as the access control plane, Intune managing devices, Microsoft 365 services holding data, Defender providing detection, and Purview governing retention and classification.
The architecture is defined less by product selection than by policy: who may create Teams and sites, how external sharing works, which devices may access data, what is retained and for how long, and who holds privileged roles.
Layer model
Identity
Entra ID tenant with named domainsConditional Access baselinePIM for privileged rolesBreak glass accounts with monitoringGuest access model
Devices
Intune enrolment for corporate devicesApp protection for BYODSecurity baselines and update ringsCompliance required for data access
Data & collaboration
Exchange Online with DMARC enforcementSharePoint and OneDrive with governed sharingTeams creation and lifecycle policySensitivity labels and DLP
Security & governance
Defender across endpoint, identity, email and cloud appsUnified audit logging with defined retentionPurview retention policiesThird party backup for critical data
Design considerations
- Single tenant wherever possible; multi tenant estates complicate collaboration, licensing and security consistently.
- Decide external sharing and guest lifecycle before adoption sets expectations.
- Confirm licence entitlements for each security control you plan to rely on.
- Plan the retirement of on premises Exchange and file servers rather than leaving them indefinitely.
Security considerations
- Block legacy authentication, restrict app consent, and require phishing resistant MFA for admins.
- Monitor mailbox rules, forwarding, sharing links and role changes.
- Validate that data can be recovered from malicious deletion, not only from service failure.
Failure points
- Identity provider dependency with no alternate access
- Unmonitored break glass accounts
- Retention misconfiguration causing permanent data loss
