Microsoft 365 Security Checklist for Growing Businesses
September 3, 2026
Microsoft 365 security depends on identity, administration, sharing, devices, email, and recovery—not a single security setting. Use this checklist as a baseline.
.jpeg)
Microsoft 365 is often the center of a company's identity, email, files, collaboration, and administrative access. That makes the tenant one of the most important environments to manage well.
A secure Microsoft 365 configuration is not one checkbox. It is a set of identity, administrative, email, sharing, device, and recovery controls that need ongoing ownership.
1. Require MFA
Multi-factor authentication should protect users wherever the licensing and environment allow it, with special attention to administrators and employees with access to sensitive systems.
Also define a process for lost phones, replacement devices, and unexpected MFA prompts. An MFA process that is easy to bypass through support can undermine the control.
2. Minimize Global Administrator access
Global Administrator is a highly privileged role. Review who has it, whether each assignment is still necessary, and whether lower-privilege roles can accomplish the employee's normal administrative work.
Administrative accounts should be clearly owned and removed promptly when staff or vendors change.
3. Review former and inactive users
Offboarding mistakes can leave active accounts, licenses, inbox rules, application sessions, forwarding, or shared access behind. Regularly reconcile active employees against tenant users.
For a practical offboarding sequence, see our Microsoft 365 employee offboarding checklist.
4. Review email protection
Phishing and business email compromise remain major risks. Email security should be reviewed alongside user training, identity controls, and reporting procedures.
Understand how suspicious messages are filtered, how employees report them, and who investigates potentially compromised mailboxes.
5. Check external forwarding
Unexpected forwarding rules can be a sign of account compromise or an intentional configuration that creates data risk. Review whether external forwarding is needed and how it is controlled.
6. Review SharePoint and OneDrive sharing
External sharing is useful, but unmanaged links can persist much longer than intended. Review how external guests are invited, which sites may share externally, whether anonymous links are allowed, and how old guest access is removed.
7. Control application consent
Third-party applications can request access to Microsoft 365 data. Understand how users are allowed to authorize applications, which apps have privileged permissions, and who reviews high-risk consent requests.
8. Protect devices that access company data
Identity controls are stronger when the business also knows which devices are accessing company information. Depending on the organization, that may involve endpoint management, supported operating-system requirements, encryption, endpoint protection, or application-level controls.
9. Review mailbox and administrative auditing
Logging is valuable only if it is available when an incident needs investigation. Understand what audit information your licensing and configuration provide, how long relevant records are retained, and who can access them.
10. Define backup and recovery expectations
Microsoft operates the platform, but every company should understand its own recovery requirements for mail, files, SharePoint content, and accidental deletion.
Retention features and third-party backup solve different problems. Decide what recovery capability the business expects before an incident happens.
11. Monitor service and identity alerts
Service health, suspicious sign-ins, security alerts, and administrative changes can require action. Define who is responsible for reviewing important notifications.
12. Document the tenant
Useful documentation includes administrative ownership, domains, licensing, major security settings, shared mailboxes, service accounts, important groups, third-party integrations, backup configuration, and vendor contacts.
A Microsoft 365 security baseline
- MFA is enforced appropriately
- Administrative roles are limited and reviewed
- Former users are removed through a consistent process
- Email protection and phishing reporting are defined
- External forwarding and sharing are controlled
- Third-party application access is reviewed
- Managed-device expectations are defined
- Audit and alert ownership is clear
- Recovery expectations are documented
The exact configuration depends on licensing, business requirements, and risk. Two Factor's Microsoft 365 Managed Services cover the operational administration behind these controls, while broader security work is addressed through Managed Cybersecurity Services.