Key takeaways
- Microsoft 365 is secure by design, but many protective settings depend on how your tenant is configured.
- Turn on multi-factor authentication for every user and limit the number of global administrators.
- Block legacy authentication, protect email with anti-phishing policies and authenticate your domain with SPF, DKIM and DMARC.
- Review external sharing in SharePoint, OneDrive and Teams so files are not shared more widely than intended.
- Microsoft keeps your service running, but you are responsible for your data, so plan independent backups.
A Microsoft 365 security checklist is a list of tenant settings and practices that protect your business email, files, Teams chats and user accounts from common threats such as phishing, password attacks and accidental data sharing. Microsoft provides strong security tools, but many of them need to be switched on or configured correctly. The 12 checks below are a practical starting point for small and medium businesses.
Why Microsoft 365 needs to be configured, not just bought
Microsoft operates the cloud platform, but under its shared responsibility model your organisation remains responsible for its accounts, devices, data and how they are used. A tenant set up quickly years ago, with default sharing settings and no multi-factor authentication, can leave significant gaps.
The 12-point Microsoft 365 security checklist
1. Require multi-factor authentication for everyone
Enable MFA for every user, using security defaults or Conditional Access policies depending on your licences. Prefer the Microsoft Authenticator app or other phishing-resistant methods over SMS codes where possible.
2. Limit and protect admin accounts
Keep the number of global administrators small, give people only the admin roles they need, and use separate admin accounts that are not used for everyday email or browsing.
3. Set up emergency access accounts
Create a small number of carefully secured “break-glass” accounts so you cannot be locked out of your tenant if something goes wrong with normal sign-in or MFA.
4. Block legacy authentication
Older sign-in protocols do not support MFA and are a common route for password attacks. Make sure legacy authentication is blocked for your organisation.
5. Strengthen email protection
Review anti-phishing, anti-spam and anti-malware policies, and use protections such as Safe Links and Safe Attachments if your licences include Microsoft Defender for Office 365.
6. Authenticate your email domain
Publish correct SPF, DKIM and DMARC records for your domain. They help receiving servers detect spoofed emails that pretend to come from you and improve delivery of your genuine messages.
Want a Microsoft 365 security review?
Ignite System reviews and hardens Microsoft 365 tenants, then keeps them secure with ongoing monitoring.
7. Review external sharing
Check sharing settings in SharePoint, OneDrive and Teams. Decide whether files can be shared with anyone, with authenticated guests only, or not at all, and consider expiry dates for sharing links.
8. Turn off automatic email forwarding to external addresses
Attackers who compromise a mailbox often create rules that forward email outside the organisation. Block automatic external forwarding unless there is a specific business need.
9. Manage and secure devices
Use device management, such as Microsoft Intune where licensed, to require encryption, screen locks, updates and endpoint protection on laptops and phones that access company data.
10. Make sure audit logging is available
Audit logs record important activity such as sign-ins, file access and admin changes. Confirm logging is enabled so you can investigate incidents if they happen.
11. Back up Microsoft 365 data
Microsoft 365 includes features such as recycle bins and retention policies, but these are not the same as an independent backup. A third-party backup protects you against accidental deletion, ransomware and retention gaps. Read our guide to the 3-2-1 backup rule.
12. Train staff and review regularly
Show staff how to spot phishing and suspicious sign-in prompts, and review your security settings regularly, especially when staff join or leave.
Where to start
If you only do three things this week, enable MFA for everyone, review your global administrators and block legacy authentication. Then work through the rest of the list. For a broader view of protections beyond Microsoft 365, see our guide to cybersecurity for small businesses.
Frequently asked questions
Microsoft 365 includes strong security features, and newer tenants enable some protections by default. However, important settings such as MFA policies, sharing controls and email protection should still be reviewed and configured for your organisation.
Microsoft keeps the service available and provides recycle bins and retention features, but it does not replace an independent backup. Many businesses use a third-party backup service to protect email, OneDrive, SharePoint and Teams data.
Multi-factor authentication for every user is one of the most important steps, because it protects accounts even when a password is stolen.
Advanced features such as Conditional Access, Intune device management and Defender for Office 365 are included in some business plans, such as Microsoft 365 Business Premium, or can be added separately. Check your current licences before planning changes.
Need help securing Microsoft 365? Talk to Ignite System.



