Free resource

The Microsoft 365 security checklist

52 checks, ready to print, from our Microsoft 365 security assessment guide. Print it, or save it as a PDF, and work through it with the admin centers open.

Read the full guide

Each item is explained, with links to Microsoft's documentation, in the full assessment checklist. Tick what's in place; everything else goes on your plan.

Identity: authentication Microsoft Entra ID

  • Every user who can sign in is registered for MFA
  • MFA is enforced by security defaults or Conditional Access, not per-user MFA alone
  • Admins use phishing-resistant MFA (passkeys, Windows Hello, certificates)
  • SMS and voice are being phased out where possible
  • Self-service password reset uses strong methods
  • Password protection blocks common and company-specific weak passwords

Identity: Conditional Access Entra ID P1 / P2

  • Legacy authentication is blocked for all users
  • MFA is required for all users and all resources
  • Security-info registration is protected
  • Guests must use MFA
  • Two emergency access accounts exist, are excluded narrowly and alert on sign-in
  • No policy is left in report-only mode without a date to enforce
  • Risk-based policies are on (if Entra ID P2)

Admin roles and apps Privileged access

  • Fewer than five Global Administrators
  • Daily admin work uses least-privileged roles
  • Admin accounts are separate and cloud-only
  • Admin roles are eligible through PIM, not permanent (if Entra ID P2)
  • User consent is limited to verified publishers and low-risk permissions
  • High-privilege enterprise apps have an owner and a reason to exist
  • Guest invitations and guest directory access are restricted
  • Stale enabled accounts are reviewed

Devices Microsoft Intune

  • Every platform in use has a compliance policy
  • Devices with no policy are marked not compliant
  • Conditional Access requires a compliant device (or app protection on phones)
  • BitLocker and FileVault are on, with recovery keys escrowed
  • Windows LAPS rotates unique local admin passwords
  • Update rings keep devices on supported builds
  • Stale devices (30+ days without check-in) are cleaned up

Email Exchange Online, Defender for Office 365

  • SPF published for every sending domain
  • DKIM signing enabled for every custom domain
  • DMARC published and moving toward quarantine or reject
  • Automatic external forwarding is blocked
  • No suspicious inbox rules on admin or finance mailboxes
  • Standard or Strict preset security policies applied (if licensed)
  • SMTP AUTH off, except named mailboxes that need it

Sharing and collaboration SharePoint, OneDrive, Teams

  • Organization-wide external sharing is no wider than needed
  • Default link type is Specific people or People in your organization
  • "Anyone" links expire, or are turned off
  • Guest access expires or is reviewed
  • Anonymous meeting participants wait in the lobby
  • Every team and group has at least two owners

Threat protection Microsoft Defender

  • All Windows and macOS devices are onboarded to Defender
  • Tamper protection is on
  • Attack surface reduction rules are in audit or block mode
  • Defender for Identity covers domain controllers (if on-premises AD and licensed)
  • Alerts reach a person with an agreed response time

Data, audit and licensing Microsoft Purview, admin center

  • Audit logging is on and retention is understood
  • Sensitivity labels are published and used
  • DLP covers the data types that matter, tested first
  • Oversharing reviewed before any Copilot rollout
  • No licenses on disabled or long-inactive accounts
  • Security features already licensed are actually configured

Prioritize: fix this week anything that lets an attacker in with just a password; plan this quarter what needs testing and communication; tidy up the rest.

Full guide with explanations and Microsoft documentation links: m365assessments.com/resources/microsoft-365-security-assessment-checklist

Assessed tenant: ______________________   Date: ____________   By: ______________________