16 articles
Reference·8 min

1. Use the Service only for authorized tenants

Use M365Suite only for Microsoft tenants, sites, and data that your organization is authorized to administer. Do not use another person's credentials, tokens, consent, certificate, or delegated scope.

2. Protect administrator access

Customer administrators should:

  • require Microsoft Entra MFA for privileged users;
  • use least-privilege permissions and review consent periodically;
  • assign the narrowest M365Suite role and site scope needed;
  • remove departed users promptly;
  • protect generated certificates, private keys, recovery codes, and session devices; and
  • investigate unexpected backup, restore, export, purge, or role-change activity.

3. Prohibited activity

Do not use M365Suite to:

  • bypass tenant isolation, MFA, authorization, subscription limits, or Microsoft controls;
  • scan, attack, overload, or interfere with M365Suite, Microsoft, service providers, or another customer's systems;
  • upload malware, exploit code, unlawful content, or content that infringes another person's rights;
  • use automation that creates excessive API traffic or defeats rate limits;
  • attempt to discover another customer's data, URLs, credentials, backups, or billing information; or
  • process data in a way that violates applicable law, your organization's policies, Microsoft's terms, or the Privacy Policy.

4. Data minimization

M365Suite is designed for SharePoint navigation backup and recovery. Keep unrelated personal, financial, health, authentication, and secret information out of site labels, navigation links, support requests, and uploaded templates. Use the Service's retention and purge controls to remove data that is no longer needed.

5. Report a security concern

Report suspected unauthorized access, exposed credentials, data leakage, or abuse to contact@m365suite.com. Include the affected tenant, approximate time, relevant operation, and safe contact details. Do not include passwords, private keys, access tokens, or full backup payloads in email.

6. M365Suite security controls

M365Suite applies tenant-bound authentication, role and scope enforcement, privileged-access safeguards, protected storage, encrypted transport, audit records, and operational monitoring. These controls reduce risk but do not replace Customer's Microsoft tenant security or access-management responsibilities.

7. Enforcement

We may investigate suspected misuse, restrict an operation, suspend an account, or preserve relevant audit information when reasonably necessary to protect customers, the Service, Microsoft infrastructure, or people. We will restore access when the risk is resolved where reasonably possible.