Free resource
The Microsoft 365 security checklist
52 checks, ready to print, from our Microsoft 365 security assessment guide. Print it, or save it as a PDF, and work through it with the admin centers open.
Identity: authentication Microsoft Entra ID
- Every user who can sign in is registered for MFA
- MFA is enforced by security defaults or Conditional Access, not per-user MFA alone
- Admins use phishing-resistant MFA (passkeys, Windows Hello, certificates)
- SMS and voice are being phased out where possible
- Self-service password reset uses strong methods
- Password protection blocks common and company-specific weak passwords
Identity: Conditional Access Entra ID P1 / P2
- Legacy authentication is blocked for all users
- MFA is required for all users and all resources
- Security-info registration is protected
- Guests must use MFA
- Two emergency access accounts exist, are excluded narrowly and alert on sign-in
- No policy is left in report-only mode without a date to enforce
- Risk-based policies are on (if Entra ID P2)
Admin roles and apps Privileged access
- Fewer than five Global Administrators
- Daily admin work uses least-privileged roles
- Admin accounts are separate and cloud-only
- Admin roles are eligible through PIM, not permanent (if Entra ID P2)
- User consent is limited to verified publishers and low-risk permissions
- High-privilege enterprise apps have an owner and a reason to exist
- Guest invitations and guest directory access are restricted
- Stale enabled accounts are reviewed
Devices Microsoft Intune
- Every platform in use has a compliance policy
- Devices with no policy are marked not compliant
- Conditional Access requires a compliant device (or app protection on phones)
- BitLocker and FileVault are on, with recovery keys escrowed
- Windows LAPS rotates unique local admin passwords
- Update rings keep devices on supported builds
- Stale devices (30+ days without check-in) are cleaned up
Email Exchange Online, Defender for Office 365
- SPF published for every sending domain
- DKIM signing enabled for every custom domain
- DMARC published and moving toward quarantine or reject
- Automatic external forwarding is blocked
- No suspicious inbox rules on admin or finance mailboxes
- Standard or Strict preset security policies applied (if licensed)
- SMTP AUTH off, except named mailboxes that need it
Sharing and collaboration SharePoint, OneDrive, Teams
- Organization-wide external sharing is no wider than needed
- Default link type is Specific people or People in your organization
- "Anyone" links expire, or are turned off
- Guest access expires or is reviewed
- Anonymous meeting participants wait in the lobby
- Every team and group has at least two owners
Threat protection Microsoft Defender
- All Windows and macOS devices are onboarded to Defender
- Tamper protection is on
- Attack surface reduction rules are in audit or block mode
- Defender for Identity covers domain controllers (if on-premises AD and licensed)
- Alerts reach a person with an agreed response time
Data, audit and licensing Microsoft Purview, admin center
- Audit logging is on and retention is understood
- Sensitivity labels are published and used
- DLP covers the data types that matter, tested first
- Oversharing reviewed before any Copilot rollout
- No licenses on disabled or long-inactive accounts
- Security features already licensed are actually configured
Prioritize: fix this week anything that lets an attacker in with just a password; plan this quarter what needs testing and communication; tidy up the rest.
Full guide with explanations and Microsoft documentation links: m365assessments.com/resources/microsoft-365-security-assessment-checklist
Assessed tenant: ______________________ Date: ____________ By: ______________________