Security is not all-or-nothing.
Covenant Fortify organizes Microsoft 365 security into four practical stages, so your business can strengthen the controls attackers target, insurers expect, and AI can expose.
F1 and F2 are the foundation we expect every client to stand on. F3 and F4 are where Fortify goes further when your business gives us a reason to: sensitive data, compliance requirements, Copilot adoption, or other AI-enabled work.
Here is a familiar situation. A business has Microsoft 365, a cyber-insurance renewal coming up, a few remote employees, and leadership asking whether Copilot or another AI tool should be part of next year’s plan. Nothing looks broken. Email works. Teams works. Files are moving. People are productive.
Then someone asks three simple questions:
The use case: when “good enough” Microsoft 365 security stops being enough.
- Can we prove MFA is fully enforced for the right users?
- Do we know which devices can access company data?
- If Copilot is turned on, will it surface files that were shared too broadly years ago?
That is usually the moment Microsoft 365 security changes from an IT checklist into a business issue. Attackers care about weak identity and unmanaged devices. Insurers care about whether foundational controls are actually deployed. AI cares about permissions and data access because it can only work with what your environment allows it to see.
That is the point of the Covenant Fortify framework. It separates the security controls every organization should confirm from the deeper protections that become important based on your environment, risk, and business plans.
The foundation we expect: F1 and F2.
Some controls are no longer optional. They are the floor. When we look at a client environment, F1 and F2 are the two stages we believe should already be in place. If they are not, they are the first things we close.
F1: People
Most incidents start with a person, not a firewall. An attacker does not break in so much as sign in, using a password that leaked, a convincing phishing email, or an account with more access than it needs.
In the real-world scenario above, F1 answers the cyber-insurance and breach-prevention question first: are the right identity controls actually in place? That means multi-factor authentication, phishing defense, and access controls that make sure people can only reach what their role requires.
What F1 solves
F1 gives leadership confidence that sign-ins are better protected, access is more intentional, and the organization can speak more clearly to the controls insurers and auditors increasingly expect to see.
F2: Devices
Your people work from laptops in the office, at home, and everywhere in between. Every one of those devices is a door. An unmanaged or unmonitored endpoint can turn a single mistake into a business-wide problem.
F2 is where the organization stops assuming every laptop is safe simply because the user is trusted. It secures endpoints through consistent configuration, monitoring, and management whether a device sits at a desk or moves between locations.
What F2 solves
F2 reduces the risk that an unmanaged device becomes the starting point for ransomware, data exposure, or a support problem that quietly becomes a security problem.
Where Fortify goes next: F3 and F4.
F3 and F4 are added based on business needs, not sold by default. They matter when your organization holds sensitive information, has compliance pressure, or is getting ready to put AI to work.
F3: Data
If you handle client records, contracts, financial data, health information, or anything you would not want walking out the door, F3 is where that risk gets addressed.
Think about a folder that was shared broadly during a project and never locked back down. Or a departing employee who still has access to records they no longer need. Or a department that stores sensitive files in a place nobody has reviewed in years. F3 brings encryption, retention rules, access controls, and data loss prevention to the information that matters most.
It turns “we think it is fine” into “we know who can see what, and we can prove it.”
F4: AI readiness
AI is the fastest way to discover how much your data was overshared. Copilot works inside your Microsoft 365 environment. It uses your data, respects your permissions, and surfaces whatever a user is technically allowed to see.
That is helpful when permissions are clean. It is risky when access has quietly drifted over the years. F4 closes those gaps before AI amplifies them, so the productivity win arrives without avoidable exposure.
The practical difference
Without F3 and F4, a business may be technically able to adopt AI but not operationally ready. With F3 and F4, leadership has a clearer answer to the question that matters most: can we use AI without creating new data risk?
How to tell where you stand.
You should not have to guess which Fortify stage you are on. Fortify starts with evidence, not assumptions.
A Cyber Risk Assessment benchmarks your real risk in plain language: email exposure, dark web credentials, Microsoft 365 configuration gaps, identity concerns, and other signals that help leadership understand what matters first.
From there, you get a staged F1–F4 roadmap: what changes, why it matters, and what comes next. Leadership sees the plan before anything is implemented, and every stage is measured against Microsoft Secure Score, Microsoft’s own measure of tenant security posture.
Most organizations see a 30 to 50+ point Secure Score lift after staged hardening.
Nothing is a big-bang project. You approve one stage at a time, and the work is scheduled to keep your team running.
Take the Cyber Risk AssessmentThe bottom line.
F1 and F2 are the foundation we hold with every client: identity and devices, the two areas attackers and insurers care about most. F3 and F4 are how Fortify grows with you when you have sensitive data to protect or AI to adopt safely. The first step is simply seeing where you stand.
Related Covenant resources.
Fortify often starts with a benchmark and grows into a broader Microsoft security, data governance, and AI-readiness roadmap.
Fortify
Move from Microsoft security findings to staged hardening across identity, devices, data, and AI readiness.
Explore FortifyMicrosoft 365 Secure Score Assessment
Benchmark your Microsoft 365 security posture and prioritize practical improvements across your tenant.
Explore Secure ScoreCopilot Readiness Assessment
Review permissions, data exposure, governance, licensing, and rollout planning before AI expands.
Explore Copilot ReadinessSource note from article draft: Hiscox Cyber Readiness Report 2025; Accenture Cybercrime Study; Coalition; Gartner; Microsoft Digital Defense Report 2024.
See where your Microsoft 365 security stands today.
Explore the Fortify framework or take the Cyber Risk Assessment to benchmark your current posture and understand which stage should come next.


