Expert Tips

Microsoft 365 Security Checklist for Growing Businesses

September 3, 2026

Microsoft 365 security depends on identity, administration, sharing, devices, email, and recovery—not a single security setting. Use this checklist as a baseline.

Microsoft 365 security checklist for growing businesses

Microsoft 365 is often the center of a company's identity, email, files, collaboration, and administrative access. That makes the tenant one of the most important environments to manage well.

A secure Microsoft 365 configuration is not one checkbox. It is a set of identity, administrative, email, sharing, device, and recovery controls that need ongoing ownership.

1. Require MFA

Multi-factor authentication should protect users wherever the licensing and environment allow it, with special attention to administrators and employees with access to sensitive systems.

Also define a process for lost phones, replacement devices, and unexpected MFA prompts. An MFA process that is easy to bypass through support can undermine the control.

2. Minimize Global Administrator access

Global Administrator is a highly privileged role. Review who has it, whether each assignment is still necessary, and whether lower-privilege roles can accomplish the employee's normal administrative work.

Administrative accounts should be clearly owned and removed promptly when staff or vendors change.

3. Review former and inactive users

Offboarding mistakes can leave active accounts, licenses, inbox rules, application sessions, forwarding, or shared access behind. Regularly reconcile active employees against tenant users.

For a practical offboarding sequence, see our Microsoft 365 employee offboarding checklist.

4. Review email protection

Phishing and business email compromise remain major risks. Email security should be reviewed alongside user training, identity controls, and reporting procedures.

Understand how suspicious messages are filtered, how employees report them, and who investigates potentially compromised mailboxes.

5. Check external forwarding

Unexpected forwarding rules can be a sign of account compromise or an intentional configuration that creates data risk. Review whether external forwarding is needed and how it is controlled.

6. Review SharePoint and OneDrive sharing

External sharing is useful, but unmanaged links can persist much longer than intended. Review how external guests are invited, which sites may share externally, whether anonymous links are allowed, and how old guest access is removed.

7. Control application consent

Third-party applications can request access to Microsoft 365 data. Understand how users are allowed to authorize applications, which apps have privileged permissions, and who reviews high-risk consent requests.

8. Protect devices that access company data

Identity controls are stronger when the business also knows which devices are accessing company information. Depending on the organization, that may involve endpoint management, supported operating-system requirements, encryption, endpoint protection, or application-level controls.

9. Review mailbox and administrative auditing

Logging is valuable only if it is available when an incident needs investigation. Understand what audit information your licensing and configuration provide, how long relevant records are retained, and who can access them.

10. Define backup and recovery expectations

Microsoft operates the platform, but every company should understand its own recovery requirements for mail, files, SharePoint content, and accidental deletion.

Retention features and third-party backup solve different problems. Decide what recovery capability the business expects before an incident happens.

11. Monitor service and identity alerts

Service health, suspicious sign-ins, security alerts, and administrative changes can require action. Define who is responsible for reviewing important notifications.

12. Document the tenant

Useful documentation includes administrative ownership, domains, licensing, major security settings, shared mailboxes, service accounts, important groups, third-party integrations, backup configuration, and vendor contacts.

A Microsoft 365 security baseline

  • MFA is enforced appropriately
  • Administrative roles are limited and reviewed
  • Former users are removed through a consistent process
  • Email protection and phishing reporting are defined
  • External forwarding and sharing are controlled
  • Third-party application access is reviewed
  • Managed-device expectations are defined
  • Audit and alert ownership is clear
  • Recovery expectations are documented

The exact configuration depends on licensing, business requirements, and risk. Two Factor's Microsoft 365 Managed Services cover the operational administration behind these controls, while broader security work is addressed through Managed Cybersecurity Services.

PUT THE GUIDANCE TO WORK

Need help applying this to your environment?

Two Factor can help assess the current setup, identify what actually matters, and turn the recommendation into a practical plan for your team.