Is multi-factor authentication enabled for every Microsoft 365 user?
MFA should protect all standard users, administrators and shared business accounts.
Review your Microsoft 365 identity, email, sharing, backup, device and monitoring controls through a practical security checklist.
MFA should protect all standard users, administrators and shared business accounts.
Administrators should use separate privileged accounts and avoid using Global Administrator access for everyday work.
Only authorised people who genuinely require full tenant access should hold the Global Administrator role.
Policies can restrict access based on user risk, location, device compliance and authentication conditions.
Older authentication methods may bypass modern security protections such as MFA and Conditional Access.
Microsoft 365 should help protect users from executive impersonation, supplier fraud and credential-stealing emails.
Microsoft Defender for Office 365 or equivalent controls can inspect links and attachments for threats.
Email authentication helps reduce spoofing and unauthorised use of your domain.
Attackers may create forwarding rules to secretly copy business emails outside the organisation.
External access should be limited, reviewed and removed when it is no longer required.
Old guest accounts can retain access to files, Teams and SharePoint sites after a project ends.
Customer, employee, financial and confidential business data should have stronger controls.
Important Exchange Online, OneDrive, SharePoint and Teams data should be protected by a suitable backup strategy.
The business should confirm that emails, files and SharePoint data can be restored when required.
Device management helps enforce security requirements, updates, access controls and compliance policies.
BitLocker and FileVault help protect business information if a device is lost or stolen.
Access policies can reduce the risk of business data being accessed from insecure devices.
Audit logs help investigate suspicious logins, mailbox activity, file access and administrative changes.
Suspicious sign-ins, risky users, malware and configuration changes should be reviewed promptly.
Unused accounts and excessive access should be removed as part of regular access reviews.
Leavers should have sign-in blocked, sessions revoked, access removed and business data retained appropriately.
Please answer all questions to calculate your Microsoft 365 security score.