EXOUSIASEC
Let’s talk
Field guide 001 / Free checklist

15 Microsoft 365
security checks.

Every small business should know where it stands. Use these questions with your IT team to review the fundamentals and identify what deserves a closer look.

Download the checklist

PDF · 15 checks · Free to use with your IT team

A starting point for your review

Record the evidence, owner, and next action for each check. Features and licensing vary. Review changes with an authorized administrator, test access policies before rollout, and maintain a recovery path.

  1. Know your Global Administrators

    List accounts with Global Administrator and other privileged roles. Confirm each role has a current business reason and owner; use narrower roles where possible.

  2. Verify MFA is enforced

    Review how MFA is required through security defaults or Conditional Access. Registration alone does not show that all relevant sign-ins are protected.

  3. Review legacy authentication

    Identify applications and protocols relying on older authentication. Plan any blocking policy with your IT team and test business-critical dependencies.

  4. Protect emergency access

    Document emergency administrator access, protect the accounts, monitor their use, and test the recovery procedure without weakening normal access controls.

  5. Remove stale employee access

    Review former employees, inactive users, and role changes. Confirm sessions, application access, and company devices are addressed during offboarding.

  6. Review guests and external sharing

    Check guest accounts, shared links, Teams, SharePoint, and OneDrive access. Confirm information is only shared with the intended people.

  7. Check application consent

    Review enterprise applications, app registrations, and granted permissions. Investigate unnecessary or unrecognized access with an authorized administrator.

  8. Account for every company device

    Compare your device inventory with Intune or your management platform. Identify unmanaged, inactive, and personally owned devices accessing business data.

  9. Verify encryption and recovery keys

    Check BitLocker or appropriate disk encryption on company laptops. Confirm recovery keys are safely stored and available to authorized staff when needed.

  10. Review device compliance and access

    Check device compliance policies and access decisions. Test changes in stages; some controls require additional Microsoft licenses.

  11. Confirm endpoint protection is healthy

    Check Defender or the protection service you use for onboarding, current status, and unresolved alerts. Know who reviews and responds to findings.

  12. Check patching and local admin access

    Review update coverage, unsupported operating systems, and local administrator privileges. Assign owners and deadlines to exceptions.

  13. Review email protection

    Check anti-phishing settings, suspicious forwarding rules, and mail authentication records. Validate proposed changes before applying them to production mail.

  14. Make logs and alerts useful

    Confirm audit and sign-in data are available for the required time period. Route actionable alerts to an accountable person and document the response process.

  15. Test recovery, not just backups

    Identify critical information, recovery requirements, and backup coverage. Test an authorized restore and record what worked, what failed, and what needs attention.

This guide supports an initial conversation. It is not an exhaustive audit, a compliance attestation, or a guarantee against security incidents.

Reference guidance

Use the current Microsoft Entra security defaults guidance, Intune encryption guidance, and Microsoft email protection recommendations alongside your licensing and configuration documentation.

Need a closer look?