Microsoft 365 security checklist
The Microsoft 365 security checklist every small business should complete
Microsoft 365 is secure by capability, not by default. This checklist covers the identity, email, sharing, device and monitoring controls that protect a small business tenant — the same controls FarosGuard AI verifies automatically in a read-only assessment, mapped to ISO 27001 and NIS2 references.
Identity & sign-in
Compromised accounts are the most common way attackers enter a small business tenant.
- Multi-factor authentication (MFA) is required for every user, not only administrators
- Administrator accounts use MFA and are separate from day-to-day user accounts
- Legacy authentication protocols (basic auth) are blocked
- Risky sign-ins are challenged or blocked with Conditional Access policies
- Guest and external accounts are reviewed regularly and removed when no longer needed
Email protection
Email is the main delivery channel for phishing and malware targeting SMEs.
- Anti-phishing and anti-spam policies are enabled and tuned
- Attachments and links are scanned before delivery (Safe Attachments / Safe Links or equivalent)
- SPF, DKIM and DMARC records are published so others cannot spoof your domain
- Automatic external forwarding of mailboxes is disabled or restricted
Sharing & data
Oversharing in SharePoint, OneDrive and Teams is a frequent source of data leakage.
- Anonymous "anyone" sharing links are disabled or expire automatically
- External sharing is limited to approved domains where possible
- Default sharing links are set to "specific people" rather than organisation-wide
- Access to sensitive sites and teams is reviewed on a schedule
Devices & access
Unmanaged devices can bypass account protections entirely.
- Company devices are enrolled and compliant before they can reach company data
- Access from unmanaged or unknown devices is blocked or limited to the web
- Sessions on risky devices expire quickly
Monitoring & auditing
You cannot respond to what you cannot see.
- The unified audit log is enabled and retained
- Sign-in and audit logs are reviewed for unusual activity
- Alert policies notify you of suspicious behaviour such as mass downloads or impossible travel
Prefer not to check all of this by hand?
FarosGuard AI connects to your Microsoft 365 tenant read-only, runs these checks for you, explains every finding in plain language and produces a prioritised remediation plan. The first assessment is free.