Checklist
Microsoft 365 security baseline checklist
A baseline for Microsoft 365 security. Check each item against your tenant; anything you can't confirm is worth a closer look.
Identity
- MFA required for every user through Conditional Access
- Phishing-resistant MFA for administrators
- Legacy authentication blocked
- Break-glass accounts documented, excluded correctly and monitored
- Separate admin accounts, with just-in-time elevation where licensed
- Risky sign-in and user risk policies where licensed
Devices
- Devices managed in Intune, with compliance required for access to company data
- BitLocker, firewall and Defender Antivirus enforced
- Local admin rights removed, with Windows LAPS for local passwords
- Updates managed through update rings or Autopatch
- App protection policies for personal mobile devices
Read the rest of this checklist
Enter your work details to unlock this and every other guide on the site. We'll also send you a note in case you want to talk it through with an engineer.
- Defender for Office 365 anti-phishing, Safe Links and Safe Attachments configured
- SPF, DKIM and DMARC in place for every domain
- Automatic forwarding to external addresses blocked
- Mailbox auditing on
Data and sharing
- External sharing set to the narrowest level that works for you
- Guest access reviewed on a schedule
- Sensitivity labels published with a default
- Data loss prevention for the most sensitive data types
Logging and administration
- Unified audit log on and retained for investigations
- Admin roles reviewed, with no more Global Administrators than needed
- App registrations and consented permissions reviewed
- User consent to third-party apps restricted
- Secure Score reviewed monthly
Next step
This guide supports Microsoft 365 security and tenant health assessment. Talk to an engineer if you want it worked through for your environment.
Start a conversation
Check your tenant against evidence.
Talk to an engineer about a Microsoft 365 security assessment.
Talk to an Engineer