Microsoft 365 security guides for MSPs and IT admins
Practical, vendor-neutral guides to assessing and hardening Microsoft 365 tenants, written from the checks we run every day. Each one links to Microsoft's own documentation.
Free: the printable Microsoft 365 security checklist
Every check from our assessment guide, ready to print and grouped by Entra ID, Intune, email, SharePoint and Teams, Defender, Purview and licensing. Print it or save it as a PDF.
Security assessment
What to check in a Microsoft 365 tenant, and how to fix what you find without disrupting people.
- Pillar guide
Microsoft 365 security assessment checklist (2026)
What to check, where to find it and why it matters, across identity, devices, email, collaboration, threat protection, data protection and licensing.
How to improve Microsoft Secure Score without breaking users
Secure Score is a useful to-do list and a poor target. Here's how to work through it in an order that raises protection without a wave of help-desk tickets.
Intune device compliance baseline for small and mid-size businesses
Compliance policies for Windows, macOS, iOS and Android that an SMB can actually run, the tenant settings people forget, and an enforcement plan that doesn't lock anyone out.
Phishing-resistant MFA in Microsoft 365: moving users to passkeys, FIDO2 and Windows Hello
Why push notifications and codes aren't enough against modern phishing, which methods Microsoft Entra ID treats as phishing-resistant, and how to roll them out without stranding anyone.
SPF, DKIM and DMARC for Microsoft 365: a step-by-step setup
Email authentication stops attackers sending as your domain and helps your own mail get delivered. Here's the order to set it up, the records involved and how to reach an enforcing DMARC policy.
Safe external sharing and guest access in SharePoint, OneDrive and Teams
Collaboration with outside people is the point of Microsoft 365. Here's how to keep it deliberate: the settings that matter, sensible defaults, and how to clean up years of old links and guests.
Getting a tenant ready for Microsoft 365 Copilot: oversharing and data governance first
Copilot respects existing permissions, which is exactly why permissions matter. A practical sequence for finding overshared content, tightening access and putting governance in place before rollout.
Conditional Access
The sign-in policies every tenant needs, how they relate to Security Defaults, and how to retire legacy authentication.
- Pillar guide
Conditional Access baseline policies every Microsoft 365 tenant should have
A practical set of Conditional Access policies, the exclusions that keep you safe from lockouts, and a rollout plan that uses report-only mode properly.
Security Defaults vs Conditional Access: which should your tenant use?
Both enforce MFA and block legacy authentication. They differ in control, licensing and how exceptions work. Here's how to choose, and how to move from one to the other safely.
How to find and block legacy authentication in Microsoft 365
Legacy protocols can't do MFA, so they're a favorite route for password spraying. Here's how to find what still uses them, deal with printers and scripts, and block the rest.
Privileged access
Admin roles, PIM, break-glass accounts and application permissions: the access an attacker wants most.
- Pillar guide
Entra ID privileged access: admin roles, PIM and break-glass accounts
Who holds admin rights, how they get them, and what happens when everything else fails. A practical approach for small and mid-size tenants.
Finding risky OAuth apps and consent grants in Entra ID
Applications with the right permissions can read mail and files without ever knowing a password. Here's how to inventory them, judge which are risky, and stop new ones being approved casually.
MSP playbook
Turning Microsoft 365 assessments into a repeatable, priced service your customers understand.
- Pillar guide
Running Microsoft 365 assessments as an MSP: packaging, pricing and QBRs
Where assessments fit in the customer lifecycle, how to package them, what to show in a quarterly business review, and how findings become scoped projects.
Microsoft 365 Business Premium vs E3 vs E5: security features compared for SMBs
A feature-by-feature comparison of the security and compliance capabilities in each plan, drawn from Microsoft's service descriptions, and how to use it in licensing conversations.
How to price and package Microsoft 365 security assessments as an MSP
Work out what an assessment really costs you, choose a pricing model that fits how you sell, and package tiers customers can say yes to. No invented benchmarks, just the arithmetic.
Looking for product how-tos?
Step-by-step instructions for M365Assessments itself (onboarding customers, running assessments, reading reports) live in the Help Center.
See where a tenant stands in minutes
M365Assessments runs these checks for you with read-only modules and turns them into a prioritized, plain-English report.
Requires a Microsoft Entra ID (work or school) account.