Home » Blog » Microsoft 365 Security Checklist: 12 Settings Every Business Should Check

Microsoft 365 Security Checklist: 12 Settings Every Business Should Check

Microsoft 365 Security Checklist: 12 Settings Every Business Should Check

Key takeaways

  • Microsoft 365 is secure by design, but many protective settings depend on how your tenant is configured.
  • Turn on multi-factor authentication for every user and limit the number of global administrators.
  • Block legacy authentication, protect email with anti-phishing policies and authenticate your domain with SPF, DKIM and DMARC.
  • Review external sharing in SharePoint, OneDrive and Teams so files are not shared more widely than intended.
  • Microsoft keeps your service running, but you are responsible for your data, so plan independent backups.

A Microsoft 365 security checklist is a list of tenant settings and practices that protect your business email, files, Teams chats and user accounts from common threats such as phishing, password attacks and accidental data sharing. Microsoft provides strong security tools, but many of them need to be switched on or configured correctly. The 12 checks below are a practical starting point for small and medium businesses.

Why Microsoft 365 needs to be configured, not just bought

Microsoft operates the cloud platform, but under its shared responsibility model your organisation remains responsible for its accounts, devices, data and how they are used. A tenant set up quickly years ago, with default sharing settings and no multi-factor authentication, can leave significant gaps.

The 12-point Microsoft 365 security checklist

1. Require multi-factor authentication for everyone

Enable MFA for every user, using security defaults or Conditional Access policies depending on your licences. Prefer the Microsoft Authenticator app or other phishing-resistant methods over SMS codes where possible.

2. Limit and protect admin accounts

Keep the number of global administrators small, give people only the admin roles they need, and use separate admin accounts that are not used for everyday email or browsing.

3. Set up emergency access accounts

Create a small number of carefully secured “break-glass” accounts so you cannot be locked out of your tenant if something goes wrong with normal sign-in or MFA.

4. Block legacy authentication

Older sign-in protocols do not support MFA and are a common route for password attacks. Make sure legacy authentication is blocked for your organisation.

5. Strengthen email protection

Review anti-phishing, anti-spam and anti-malware policies, and use protections such as Safe Links and Safe Attachments if your licences include Microsoft Defender for Office 365.

6. Authenticate your email domain

Publish correct SPF, DKIM and DMARC records for your domain. They help receiving servers detect spoofed emails that pretend to come from you and improve delivery of your genuine messages.

Want a Microsoft 365 security review?

Ignite System reviews and hardens Microsoft 365 tenants, then keeps them secure with ongoing monitoring.

7. Review external sharing

Check sharing settings in SharePoint, OneDrive and Teams. Decide whether files can be shared with anyone, with authenticated guests only, or not at all, and consider expiry dates for sharing links.

8. Turn off automatic email forwarding to external addresses

Attackers who compromise a mailbox often create rules that forward email outside the organisation. Block automatic external forwarding unless there is a specific business need.

9. Manage and secure devices

Use device management, such as Microsoft Intune where licensed, to require encryption, screen locks, updates and endpoint protection on laptops and phones that access company data.

10. Make sure audit logging is available

Audit logs record important activity such as sign-ins, file access and admin changes. Confirm logging is enabled so you can investigate incidents if they happen.

11. Back up Microsoft 365 data

Microsoft 365 includes features such as recycle bins and retention policies, but these are not the same as an independent backup. A third-party backup protects you against accidental deletion, ransomware and retention gaps. Read our guide to the 3-2-1 backup rule.

12. Train staff and review regularly

Show staff how to spot phishing and suspicious sign-in prompts, and review your security settings regularly, especially when staff join or leave.

Where to start

If you only do three things this week, enable MFA for everyone, review your global administrators and block legacy authentication. Then work through the rest of the list. For a broader view of protections beyond Microsoft 365, see our guide to cybersecurity for small businesses.

Frequently asked questions

Is Microsoft 365 secure by default?

Microsoft 365 includes strong security features, and newer tenants enable some protections by default. However, important settings such as MFA policies, sharing controls and email protection should still be reviewed and configured for your organisation.

Does Microsoft back up my Microsoft 365 data?

Microsoft keeps the service available and provides recycle bins and retention features, but it does not replace an independent backup. Many businesses use a third-party backup service to protect email, OneDrive, SharePoint and Teams data.

What is the most important Microsoft 365 security setting?

Multi-factor authentication for every user is one of the most important steps, because it protects accounts even when a password is stolen.

Which Microsoft 365 plan includes advanced security?

Advanced features such as Conditional Access, Intune device management and Defender for Office 365 are included in some business plans, such as Microsoft 365 Business Premium, or can be added separately. Check your current licences before planning changes.

Need help securing Microsoft 365? Talk to Ignite System.

Keep reading

More guides from our team

Ready to ignite your IT?

Book a free, no-obligation consultation. Tell us what you need and we will recommend the right solution with a clear, written quote.

Discover more from Ignite System

Subscribe now to keep reading and get access to the full archive.

Continue reading