15 Microsoft 365
security checks.
Every small business should know where it stands. Use these questions with your IT team to review the fundamentals and identify what deserves a closer look.
PDF · 15 checks · Free to use with your IT team
Record the evidence, owner, and next action for each check. Features and licensing vary. Review changes with an authorized administrator, test access policies before rollout, and maintain a recovery path.
Know your Global Administrators
List accounts with Global Administrator and other privileged roles. Confirm each role has a current business reason and owner; use narrower roles where possible.
Verify MFA is enforced
Review how MFA is required through security defaults or Conditional Access. Registration alone does not show that all relevant sign-ins are protected.
Review legacy authentication
Identify applications and protocols relying on older authentication. Plan any blocking policy with your IT team and test business-critical dependencies.
Protect emergency access
Document emergency administrator access, protect the accounts, monitor their use, and test the recovery procedure without weakening normal access controls.
Remove stale employee access
Review former employees, inactive users, and role changes. Confirm sessions, application access, and company devices are addressed during offboarding.
Review guests and external sharing
Check guest accounts, shared links, Teams, SharePoint, and OneDrive access. Confirm information is only shared with the intended people.
Check application consent
Review enterprise applications, app registrations, and granted permissions. Investigate unnecessary or unrecognized access with an authorized administrator.
Account for every company device
Compare your device inventory with Intune or your management platform. Identify unmanaged, inactive, and personally owned devices accessing business data.
Verify encryption and recovery keys
Check BitLocker or appropriate disk encryption on company laptops. Confirm recovery keys are safely stored and available to authorized staff when needed.
Review device compliance and access
Check device compliance policies and access decisions. Test changes in stages; some controls require additional Microsoft licenses.
Confirm endpoint protection is healthy
Check Defender or the protection service you use for onboarding, current status, and unresolved alerts. Know who reviews and responds to findings.
Check patching and local admin access
Review update coverage, unsupported operating systems, and local administrator privileges. Assign owners and deadlines to exceptions.
Review email protection
Check anti-phishing settings, suspicious forwarding rules, and mail authentication records. Validate proposed changes before applying them to production mail.
Make logs and alerts useful
Confirm audit and sign-in data are available for the required time period. Route actionable alerts to an accountable person and document the response process.
Test recovery, not just backups
Identify critical information, recovery requirements, and backup coverage. Test an authorized restore and record what worked, what failed, and what needs attention.
This guide supports an initial conversation. It is not an exhaustive audit, a compliance attestation, or a guarantee against security incidents.
Reference guidance
Use the current Microsoft Entra security defaults guidance, Intune encryption guidance, and Microsoft email protection recommendations alongside your licensing and configuration documentation.