FarosGuard AI

Microsoft 365 security checklist

The Microsoft 365 security checklist every small business should complete

Microsoft 365 is secure by capability, not by default. This checklist covers the identity, email, sharing, device and monitoring controls that protect a small business tenant — the same controls FarosGuard AI verifies automatically in a read-only assessment, mapped to ISO 27001 and NIS2 references.

Identity & sign-in

Compromised accounts are the most common way attackers enter a small business tenant.

  • Multi-factor authentication (MFA) is required for every user, not only administrators
  • Administrator accounts use MFA and are separate from day-to-day user accounts
  • Legacy authentication protocols (basic auth) are blocked
  • Risky sign-ins are challenged or blocked with Conditional Access policies
  • Guest and external accounts are reviewed regularly and removed when no longer needed

Email protection

Email is the main delivery channel for phishing and malware targeting SMEs.

  • Anti-phishing and anti-spam policies are enabled and tuned
  • Attachments and links are scanned before delivery (Safe Attachments / Safe Links or equivalent)
  • SPF, DKIM and DMARC records are published so others cannot spoof your domain
  • Automatic external forwarding of mailboxes is disabled or restricted

Sharing & data

Oversharing in SharePoint, OneDrive and Teams is a frequent source of data leakage.

  • Anonymous "anyone" sharing links are disabled or expire automatically
  • External sharing is limited to approved domains where possible
  • Default sharing links are set to "specific people" rather than organisation-wide
  • Access to sensitive sites and teams is reviewed on a schedule

Devices & access

Unmanaged devices can bypass account protections entirely.

  • Company devices are enrolled and compliant before they can reach company data
  • Access from unmanaged or unknown devices is blocked or limited to the web
  • Sessions on risky devices expire quickly

Monitoring & auditing

You cannot respond to what you cannot see.

  • The unified audit log is enabled and retained
  • Sign-in and audit logs are reviewed for unusual activity
  • Alert policies notify you of suspicious behaviour such as mass downloads or impossible travel

Prefer not to check all of this by hand?

FarosGuard AI connects to your Microsoft 365 tenant read-only, runs these checks for you, explains every finding in plain language and produces a prioritised remediation plan. The first assessment is free.