Bridging the gap between academic research and real-world solutions

In the pursuit of scientific advancement, the journey from theoretical research to tangible solutions is often fraught with challenges.

Written by

Joshua Ashton

Insight

21 Sept 2026

4 min read

Post Image

Can Microsoft 365 Be Used for OFFICIAL and OFFICIAL-SENSITIVE Information?

For many organisations in the UK Defence supply chain, Microsoft 365 sits at the centre of day-to-day operations.

Email is in Exchange Online. Documents are stored in SharePoint and OneDrive. Teams is used for collaboration. Entra ID controls identities. Intune manages devices. Microsoft Defender provides security monitoring.

That creates an important question for Defence suppliers:

Can Microsoft 365 actually be used to store, process and share OFFICIAL and OFFICIAL-SENSITIVE information?

The short answer is:

Yes — Microsoft 365 can be used at the OFFICIAL tier, including information marked OFFICIAL-SENSITIVE, provided the environment is appropriately configured, governed and used in accordance with the organisation's contractual and security requirements.

In fact, the UK Government publishes specific Microsoft 365 configuration guidance designed to enable secure use of the platform at the OFFICIAL tier. That guidance covers secure configuration, information protection and external collaboration.

But that does not mean any Microsoft 365 tenant is automatically suitable.

Configuration matters.

First: what does OFFICIAL-SENSITIVE actually mean?

A common misunderstanding is that OFFICIAL-SENSITIVE is a separate Government security classification.

It isn't.

The Government Security Classifications Policy has three classification tiers:

  • OFFICIAL

  • SECRET

  • TOP SECRET

-SENSITIVE is an additional marking applied to certain information within the OFFICIAL tier.

It is used where OFFICIAL information is not intended for public release and where its compromise could cause a greater degree of harm.

That distinction matters technologically.

Government guidance explicitly warns organisations not to look for a system that is simply declared "approved for OFFICIAL-SENSITIVE".

A system capable of handling OFFICIAL information may also be appropriate for sensitive information, provided appropriate technical, procedural and personnel controls are applied based on the risks involved.

In other words:

OFFICIAL-SENSITIVE isn't solved by buying a particular product.

It is solved by designing and operating an appropriate security environment.

Does the UK Government use Microsoft 365 for OFFICIAL information?

Yes.

UK Government guidance specifically exists for configuring Microsoft 365 for users operating at the OFFICIAL tier.

The guidance was developed through work involving Microsoft, the Government Digital Service, Central Digital and Data Office, Government Security Group and the National Cyber Security Centre.

Government's own 2023 Information Security Review went further, stating that Microsoft 365 is the day-to-day working environment for most departments at the OFFICIAL security classification.

Microsoft's accompanying Information Protection guidance explicitly states that its Secure Configuration Blueprint covers Microsoft 365 tenant use at the OFFICIAL tier including the OFFICIAL-SENSITIVE marking.

So the question for most Defence suppliers isn't:

"Can Microsoft 365 technically be used?"

It is:

"Is our Microsoft 365 environment configured and governed appropriately for the information we need to handle?"

That is a very different question.

What does a properly configured Microsoft 365 environment look like?

Simply having Microsoft 365 Business Premium, E3 or E5 does not automatically create an OFFICIAL-ready environment.

Security comes from how the tenant is configured and operated.

There are several areas organisations should consider.

1. Identity and access management

Identity is one of the most important security boundaries in Microsoft 365.

A strong environment should consider controls including:

  • multi-factor authentication;

  • Conditional Access;

  • separate administrative accounts;

  • least privilege;

  • privileged role management;

  • blocking legacy authentication;

  • joiner, mover and leaver processes;

  • guest-account governance;

  • dormant-account management; and

  • monitoring suspicious authentication activity.

Microsoft's UK Government Secure Configuration Blueprint specifically addresses identities, privileged users, devices and controls over how users access Microsoft 365 services.

If an attacker can compromise an administrator account, many other controls become significantly less valuable.

2. Managed and compliant devices

The device accessing the information matters almost as much as where the information is stored.

An organisation should understand:

Which devices are allowed to access Defence-related information?

That could involve the use of Microsoft Intune and Conditional Access to require devices to meet defined security conditions.

Organisations should consider:

  • device enrolment;

  • encryption;

  • endpoint protection;

  • operating-system support;

  • patching;

  • compliance policies;

  • local administrator privileges;

  • mobile-device controls;

  • lost-device response; and

  • whether unmanaged or personal devices should be permitted.

Access from an unmanaged home laptop should not automatically receive the same trust as access from a secured and managed corporate endpoint.

3. Information classification and sensitivity labels

This is where Microsoft Purview becomes particularly relevant.

Microsoft and UK Government have published specific guidance for implementing Government security classifications through Microsoft Purview Information Protection.

Purview can be used to classify and protect documents, emails, meetings and other information through sensitivity labels.

For example, an organisation might implement labels reflecting its information-handling requirements so that users can clearly identify:

OFFICIAL

and

OFFICIAL-SENSITIVE

information.

But labels should do more than place text at the top of a document.

Depending on the organisation's requirements, labels can be linked to technical controls such as:

  • encryption;

  • restricted sharing;

  • access restrictions;

  • visual markings;

  • Data Loss Prevention policies; and

  • controls over SharePoint and Teams locations.

The Government's Information Protection guidance specifically addresses sensitivity labels and DLP features aligned with the Government Security Classifications Policy.

4. External sharing

This deserves particular attention for Defence suppliers.

Microsoft 365 makes collaboration extremely easy.

That is one of its strengths.

It can also become one of its biggest risks.

Organisations should understand:

  • who can invite guest users;

  • whether anonymous links are allowed;

  • whether external sharing is enabled by default;

  • which domains can receive information;

  • how guest users are reviewed;

  • whether Teams members can add external participants;

  • how SharePoint sites are configured; and

  • what happens when a project or supplier relationship ends.

UK Government has published separate Microsoft 365 guidance covering external collaboration, including Teams, SharePoint, document sharing and shared channels.

For OFFICIAL-SENSITIVE material, the need-to-know principle becomes particularly important.

Government guidance says OFFICIAL information marked -SENSITIVE should only be stored in locations where those with access have a legitimate need to know the information.

5. Data Loss Prevention

Users make mistakes.

Someone attaches the wrong document.

A sensitive spreadsheet gets shared with an external account.

A Teams file is copied into an inappropriate location.

Technical controls can help reduce the likelihood that a simple mistake becomes a security incident.

Microsoft Purview Data Loss Prevention can identify certain categories of sensitive information and apply restrictions or warnings around its use.

A mature implementation might consider:

  • email;

  • SharePoint;

  • OneDrive;

  • Teams;

  • endpoints; and

  • other Microsoft 365 workloads.

DLP does not remove the need for users to understand information handling.

It provides another layer of protection.

6. Logging, detection and response

An organisation handling sensitive information also needs to understand what is happening inside its environment.

That means asking questions such as:

  • Can we identify suspicious logins?

  • Can we detect unusual mailbox activity?

  • Do we know when administrator privileges change?

  • Can we investigate inappropriate file sharing?

  • Are security alerts actually monitored?

  • How long are logs retained?

  • Who responds to an incident?

Depending on licensing and requirements, Microsoft technologies such as Defender, Purview and Sentinel can form part of this capability.

Having security tooling switched on is not the same as having an operational security-monitoring capability.

Someone needs to review and act upon what those systems detect.

Does OFFICIAL-SENSITIVE require a separate Microsoft 365 environment?

Not automatically.

This is another common misconception.

Government guidance does not treat OFFICIAL-SENSITIVE as a new classification tier requiring a completely separate IT platform.

Instead, the additional marking indicates that further handling controls may be appropriate depending on the sensitivity and associated risk.

This is why Microsoft's Information Protection guidance focuses heavily on classification, access control and information protection within Microsoft 365 rather than simply prescribing a completely different platform.

However, particular contracts or information sets can impose additional requirements.

And for a Defence supplier, that contractual context is crucial.

Defence suppliers need to look beyond generic Government guidance

A supplier working for the Ministry of Defence also needs to consider the requirements attached to its particular contract.

The MOD's Cyber Security Model Version 4 and Defence Standard 05-138 Issue 4 establish minimum cyber-security requirements for Defence suppliers according to their Cyber Risk Profile.

The standard takes an organisation-wide approach to resilience rather than considering only one isolated system.

Crucially, Defence Standard 05-138 states that its requirements are minimums and that individual contracts may require greater levels of protection, including requirements specified through a Security Aspects Letter.

So a supplier should never conclude:

Microsoft 365 can handle OFFICIAL-SENSITIVE, therefore anything the MOD sends us can automatically go into our tenant.

Instead, establish:

  • the classification of the information;

  • any additional markings or handling instructions;

  • the Cyber Risk Profile associated with the contract;

  • applicable DEFCONs;

  • Defence Standard 05-138 requirements;

  • any Security Aspects Letter;

  • contractual restrictions;

  • nationality or access restrictions;

  • the approved scope of systems and users; and

  • any customer-specific controls.

The contract and the information owner ultimately matter.

What about SECRET information?

This article is specifically about the OFFICIAL tier.

SECRET is different.

Government policy defines SECRET as information requiring enhanced protective controls and infrastructure capable of defending against highly capable and determined threat actors.

An organisation should therefore not assume that because its standard Microsoft 365 environment is appropriate for OFFICIAL information, it can also be used for SECRET or TOP SECRET information.

Those classifications require a separate security assessment and appropriate approved arrangements.

A practical Microsoft 365 checklist for Defence suppliers

If your business expects to handle OFFICIAL or OFFICIAL-SENSITIVE information, consider whether you can confidently answer yes to the following:

  • Do we know what Government information we hold?

  • Do users understand OFFICIAL and OFFICIAL-SENSITIVE?

  • Is MFA appropriately enforced?

  • Are administrator accounts protected separately?

  • Are devices centrally managed?

  • Is access from unmanaged devices controlled?

  • Is Conditional Access properly configured?

  • Are external sharing settings understood?

  • Are guest users regularly reviewed?

  • Have we configured Microsoft Purview appropriately?

  • Can sensitive information be labelled and protected?

  • Are appropriate DLP controls in place?

  • Is security logging enabled?

  • Are alerts actively monitored?

  • Can we investigate a security incident?

  • Are backups and recovery arrangements understood?

  • Do we know our contractual Cyber Risk Profile?

  • Do we understand our DCC requirements?

  • Have we reviewed DEFSTAN 05-138?

  • Do any Security Aspects Letters impose additional requirements?

If several of those questions cannot be answered confidently, the organisation may have work to do before describing its environment as Defence-ready.

Microsoft 365 can support Defence work — configuration is the differentiator

The important message is that Microsoft 365 itself is not the obstacle.

There is explicit UK Government guidance for using Microsoft 365 at the OFFICIAL tier, including information marked OFFICIAL-SENSITIVE.

The challenge is ensuring the tenant has been designed, configured and operated appropriately.

For many SMEs, Microsoft 365 environments have developed gradually over several years.

Users have been added.

Teams have been created.

Guest accounts have accumulated.

Sharing has been enabled.

Administrators have changed.

New security products have been switched on without necessarily being fully configured.

An environment like that may function perfectly well as a productivity platform.

That does not automatically make it ready for Defence information.

How Symposium IT can help

Symposium IT helps UK Defence suppliers assess and strengthen the Microsoft cloud environments underpinning their operations.

Through Symposium Defence, we can review areas including:

  • Microsoft 365;

  • Entra ID;

  • Intune;

  • Microsoft Defender;

  • Microsoft Purview;

  • identity and privileged access;

  • endpoint management;

  • Conditional Access;

  • external collaboration;

  • information protection;

  • logging and monitoring;

  • Azure; and

  • wider cyber resilience.

We combine this technical assessment with an understanding of the evolving Cyber Security Model, Defence Cyber Certification and the security expectations placed on organisations operating within the Defence supply chain.

The objective is not simply to make Microsoft 365 "more secure".

It is to establish whether the environment supports the information, contractual and assurance requirements the organisation is actually expected to meet.

Handling OFFICIAL or OFFICIAL-SENSITIVE information?

If your organisation supplies the MOD, a Defence prime or another company in the UK Defence supply chain, your Microsoft 365 environment should form part of your wider cyber-readiness assessment.

Explore Symposium Defence to understand how we can help assess your Microsoft environment and identify the gaps between your current configuration and a Defence-ready operating model.

https://defence.symposium-it.co.uk

Continue reading