Skip to content

Checklist

Microsoft 365 security baseline checklist

A baseline for Microsoft 365 security. Check each item against your tenant; anything you can't confirm is worth a closer look.

Identity

  • MFA required for every user through Conditional Access
  • Phishing-resistant MFA for administrators
  • Legacy authentication blocked
  • Break-glass accounts documented, excluded correctly and monitored
  • Separate admin accounts, with just-in-time elevation where licensed
  • Risky sign-in and user risk policies where licensed

Devices

  • Devices managed in Intune, with compliance required for access to company data
  • BitLocker, firewall and Defender Antivirus enforced
  • Local admin rights removed, with Windows LAPS for local passwords
  • Updates managed through update rings or Autopatch
  • App protection policies for personal mobile devices

Read the rest of this checklist

Enter your work details to unlock this and every other guide on the site. We'll also send you a note in case you want to talk it through with an engineer.

Start a conversation

Check your tenant against evidence.

Talk to an engineer about a Microsoft 365 security assessment.

Talk to an Engineer