5 min read
Microsoft 365 security checklist for growing businesses
A practical Microsoft 365 security checklist covering MFA, conditional access, admin roles, mail security, device management, and backups for teams.
Microsoft 365 ships with strong security features, but very few of them are turned on by default in a way that actually protects a growing business. A tenant set up in a hurry, by whoever happened to click through the setup wizard, usually has basic email and file sharing working and almost nothing else configured. That gap is where most real-world incidents start: a compromised account with no MFA, an old admin account nobody remembers creating, a phishing email that mail security would have caught.
This checklist covers the areas worth reviewing first, in roughly the order we'd tackle them for a new client.
1. Multi-factor authentication (MFA)
If you do only one thing on this list, enable MFA for every user, including admins. Microsoft's own security defaults will do this for you if nothing else is configured, but many tenants have security defaults switched off because a legacy application needed it at some point. Check whether MFA is actually enforced for every account, not just available as an option users can ignore.
2. Conditional access policies
MFA alone is a blunt instrument. Conditional access lets you apply rules based on context: requiring MFA only for risky sign-ins, blocking access from countries you don't operate in, or requiring a compliant, managed device for access to sensitive data. This requires Entra ID P1 licensing (included in most Microsoft 365 Business Premium and E3/E5 plans), and is one of the highest-value security investments available once you have it.
3. Review admin roles regularly
Global Administrator is a powerful role, and it's common to find more accounts holding it than actually need it, often because it was the easiest option when someone needed to do one specific admin task. Use the principle of least privilege: assign the narrowest role that lets someone do their job (Exchange Administrator, User Administrator, and so on) rather than defaulting everyone to Global Administrator. Review the list of admins at least quarterly.
4. Turn on Microsoft Entra ID sign-in and audit logs
You can't investigate an incident you have no record of. Sign-in logs show who accessed what, from where, and whether MFA was satisfied. Audit logs show configuration changes, like a new admin role being granted. Both are available in the Microsoft 365 admin center and Entra ID portal; make sure retention is long enough to be useful (the default retention period depends on your license tier).
5. Mail security: SPF, DKIM, and DMARC
These three DNS records work together to make it harder for someone to send email that looks like it came from your domain. SPF lists which servers are allowed to send mail for your domain. DKIM adds a cryptographic signature. DMARC tells receiving mail servers what to do with messages that fail those checks, and can report back to you when someone tries. Many businesses have SPF configured (often because a marketing tool asked for it) but no DKIM or DMARC, which leaves the door open for domain spoofing.
6. Anti-phishing and Safe Links/Safe Attachments policies
If you're on a plan that includes Microsoft Defender for Office 365, review whether Safe Links (which checks URLs in email at the time they're clicked, not just when the email arrives) and Safe Attachments (which detonates attachments in a sandbox before delivery) are actually configured, not just licensed. It's common to pay for these features without them being switched on.
7. Device management with Intune
If company data is accessed from phones and laptops, some level of device management is worth having: at minimum, the ability to enforce a passcode and remotely wipe a lost or stolen device. Intune, included with Microsoft 365 Business Premium and higher plans, can enforce these policies and, combined with conditional access, can require a compliant device before allowing access to email or files.
8. Data backup, beyond what Microsoft provides by default
This surprises a lot of people: Microsoft's built-in retention policies are not the same as a backup. Deleted items and mailboxes can be recovered for a limited window, and that window is designed for accidental deletion, not for a ransomware event or a long-undetected mistake. If your data matters, a proper backup strategy, either through Microsoft Purview retention policies configured deliberately or a dedicated third-party backup tool, is worth having rather than assuming the platform covers it.
9. Legacy authentication
Older protocols like POP, IMAP, and basic authentication for Exchange don't support modern MFA and are a common target for automated credential-stuffing attacks. Most tenants no longer need these enabled at all. Microsoft has been disabling basic authentication by default for new tenants, but older tenants may still have it available; turning it off, unless you have a specific application that genuinely requires it, closes a real gap.
10. Shared mailboxes and guest accounts
Shared mailboxes often don't have MFA applied directly (since nobody signs into them interactively) but can still be accessed via delegated permissions, which means the security of a shared mailbox depends on the security of everyone who has access to it. Similarly, review guest accounts from external collaborations. It's common to find guest access granted for a project that ended a year ago and never revoked.
A short checklist
- MFA enforced for every user, including admins
- Conditional access policies configured, not just security defaults
- Admin roles reviewed, with least-privilege assignment
- Sign-in and audit logs enabled with adequate retention
- SPF, DKIM, and DMARC all configured for your domain
- Safe Links and Safe Attachments switched on, if licensed
- Device compliance policies in place via Intune, where applicable
- A real backup strategy beyond Microsoft's default retention
- Legacy authentication protocols disabled
- Shared mailbox access and guest accounts reviewed
Most of this can be done without any downtime or disruption to how your team works day to day. The main cost is the time it takes to go through a tenant that's been configured piecemeal over time, and to decide the right conditional access policies for how your business actually operates.
If you'd like a second pair of eyes on your tenant, our Microsoft 365 administration and support service includes a secure setup and hardening review covering everything on this list, along with ongoing support if you'd like it managed on a monthly basis.
Related service
Microsoft 365 administration and support