Microsoft 365 security depends on configuration and ongoing administration. Use this checklist to identify high-value areas for review with your technology and security team.
Identity foundation
Use unique accounts, require MFA, block legacy authentication, review authentication methods, establish emergency access, and apply conditional access based on user, device, application, location, and risk. Higher-risk users and administrators may need stronger authentication methods.
Administrative access
Separate administrator accounts from normal email and browsing, assign the minimum role required, monitor privileged changes, review role membership, protect emergency accounts, and remove access promptly when responsibilities change.
Email protection
Configure domain authentication, anti-phishing, impersonation protection, malicious link and attachment defenses, external sender awareness, user reporting, quarantine workflows, and monitoring for forwarding rules or suspicious inbox changes.
Devices and applications
Define which devices can access business data, whether they must be managed or compliant, how mobile devices are handled, and which third-party applications can request access. Review OAuth application consent and remove unused integrations.
Teams, SharePoint, and OneDrive
Establish ownership, naming, external sharing, guest access, anonymous links, sensitivity, retention, lifecycle, and permission review. Avoid unmanaged site and Team creation without a business owner.
Data protection and retention
Understand legal and business retention requirements, sensitivity, data loss prevention options, eDiscovery needs, and the limits of native recovery. Determine whether independent backup is required.
Monitoring and response
Define who reviews identity, email, endpoint, application, and administrative alerts. Establish severity, escalation, investigation, containment, and documentation procedures.
User lifecycle
Standardize onboarding, role changes, leave, and termination. Include licenses, groups, Teams, SharePoint, mailboxes, applications, devices, sessions, forwarding, ownership transfer, and retention.
Regular review
Microsoft 365 changes continuously. Review secure score findings, licensing, policies, exceptions, inactive accounts, guests, applications, administrators, sharing, and backup on a recurring schedule.
