Microsoft 365 security depends on configuration and ongoing administration. Use this checklist to identify high-value areas for review with your technology and security team.

Identity foundation

Use unique accounts, require MFA, block legacy authentication, review authentication methods, establish emergency access, and apply conditional access based on user, device, application, location, and risk. Higher-risk users and administrators may need stronger authentication methods.

Administrative access

Separate administrator accounts from normal email and browsing, assign the minimum role required, monitor privileged changes, review role membership, protect emergency accounts, and remove access promptly when responsibilities change.

Email protection

Configure domain authentication, anti-phishing, impersonation protection, malicious link and attachment defenses, external sender awareness, user reporting, quarantine workflows, and monitoring for forwarding rules or suspicious inbox changes.

Devices and applications

Define which devices can access business data, whether they must be managed or compliant, how mobile devices are handled, and which third-party applications can request access. Review OAuth application consent and remove unused integrations.

Teams, SharePoint, and OneDrive

Establish ownership, naming, external sharing, guest access, anonymous links, sensitivity, retention, lifecycle, and permission review. Avoid unmanaged site and Team creation without a business owner.

Data protection and retention

Understand legal and business retention requirements, sensitivity, data loss prevention options, eDiscovery needs, and the limits of native recovery. Determine whether independent backup is required.

Monitoring and response

Define who reviews identity, email, endpoint, application, and administrative alerts. Establish severity, escalation, investigation, containment, and documentation procedures.

User lifecycle

Standardize onboarding, role changes, leave, and termination. Include licenses, groups, Teams, SharePoint, mailboxes, applications, devices, sessions, forwarding, ownership transfer, and retention.

Regular review

Microsoft 365 changes continuously. Review secure score findings, licensing, policies, exceptions, inactive accounts, guests, applications, administrators, sharing, and backup on a recurring schedule.

DH
About the author

Donovan Huff leads Huff Data Systems, a Texas-based managed IT and cybersecurity company focused on reliable operations, cybersecurity, cloud, and CTO-level technology leadership for growing businesses.

View author profile →
Editorial purpose: This resource provides general business and technology education. It is not legal, insurance, compliance, or financial advice. Requirements should be reviewed with the appropriate qualified professionals.