MICROSOFT 365 SECURITY CHECKLIST

How secure is your Microsoft 365 environment?

Review your Microsoft 365 identity, email, sharing, backup, device and monitoring controls through a practical security checklist.

Identity
Email security
Device security
Backup
0 of 21 answered0%
1
Identity

Is multi-factor authentication enabled for every Microsoft 365 user?

MFA should protect all standard users, administrators and shared business accounts.

2
Identity

Are administrator accounts separated from normal daily-use accounts?

Administrators should use separate privileged accounts and avoid using Global Administrator access for everyday work.

3
Identity

Is the number of Global Administrator accounts kept to a minimum?

Only authorised people who genuinely require full tenant access should hold the Global Administrator role.

4
Identity

Are Conditional Access or equivalent sign-in security policies configured?

Policies can restrict access based on user risk, location, device compliance and authentication conditions.

5
Identity

Is legacy authentication disabled?

Older authentication methods may bypass modern security protections such as MFA and Conditional Access.

6
Email Security

Are anti-phishing and impersonation-protection policies configured?

Microsoft 365 should help protect users from executive impersonation, supplier fraud and credential-stealing emails.

8
Email Security

Are SPF, DKIM and DMARC configured for your business domain?

Email authentication helps reduce spoofing and unauthorised use of your domain.

9
Email Security

Is automatic external email forwarding restricted or monitored?

Attackers may create forwarding rules to secretly copy business emails outside the organisation.

10
Data Protection

Is external sharing controlled in SharePoint, OneDrive and Microsoft Teams?

External access should be limited, reviewed and removed when it is no longer required.

11
Data Protection

Are guest users and external collaborators reviewed regularly?

Old guest accounts can retain access to files, Teams and SharePoint sites after a project ends.

12
Data Protection

Are sensitive files protected with appropriate access, labels or sharing restrictions?

Customer, employee, financial and confidential business data should have stronger controls.

13
Backup

Is Microsoft 365 data backed up independently?

Important Exchange Online, OneDrive, SharePoint and Teams data should be protected by a suitable backup strategy.

14
Backup

Are Microsoft 365 backups monitored and recovery-tested?

The business should confirm that emails, files and SharePoint data can be restored when required.

15
Devices

Are business devices managed through Microsoft Intune or another device-management platform?

Device management helps enforce security requirements, updates, access controls and compliance policies.

16
Devices

Is device encryption enabled on business laptops and computers?

BitLocker and FileVault help protect business information if a device is lost or stolen.

17
Devices

Are non-compliant or unmanaged devices restricted from sensitive Microsoft 365 data?

Access policies can reduce the risk of business data being accessed from insecure devices.

18
Monitoring

Are Microsoft 365 audit logs enabled and reviewed?

Audit logs help investigate suspicious logins, mailbox activity, file access and administrative changes.

19
Monitoring

Are Microsoft 365 security alerts monitored and assigned for follow-up?

Suspicious sign-ins, risky users, malware and configuration changes should be reviewed promptly.

20
Access Management

Are inactive users, former employees and unnecessary licences reviewed regularly?

Unused accounts and excessive access should be removed as part of regular access reviews.

21
Access Management

Is there a documented Microsoft 365 offboarding process?

Leavers should have sign-in blocked, sessions revoked, access removed and business data retained appropriately.

Please answer all questions to calculate your Microsoft 365 security score.