Skip to content

Microsoft 365 security checklist for SMEs

Microsoft 365 security starts with identity, but it does not end with multi-factor authentication. A defensible small-business setup also controls administrators, devices, email, application access, data sharing, logging and recovery. Work through this checklist in priority order and record both the decision and the person responsible for each control.

1. Protect every sign-in with MFA

Require multi-factor authentication for all users, with administrators addressed first. Security Defaults can provide a useful baseline for many smaller tenants; Microsoft 365 Business Premium organisations can use Conditional Access for more precise controls.

Prefer phishing-resistant methods such as passkeys, FIDO2 security keys or certificate-based authentication for privileged and high-risk roles where practical. Reduce reliance on SMS. Maintain a controlled recovery process so a lost phone does not become either an outage or a shortcut around security.

2. Separate and reduce administrator access

Give each administrator a named privileged account that is separate from their ordinary email and browsing account. Assign the least powerful role that completes the task; very few people need Global Administrator.

Keep at least two cloud-only emergency-access accounts, protect them strongly, exclude them from dependencies that could lock out the whole tenant, monitor their use and test the documented recovery process. Review roles, partner delegated access and inactive privileged accounts regularly.

3. Block legacy and insecure authentication

Legacy authentication protocols cannot enforce modern protections reliably and are heavily targeted. Confirm they are blocked, then identify old mail clients, scanners and applications that still depend on them before enforcement.

Avoid leaving a broad exception in place for one device. Replace or reconfigure the dependency, or restrict a temporary exception tightly with a named owner and removal date.

4. Secure user lifecycle and authentication

  • Use unique named accounts; do not share user credentials
  • Create a documented joiner, mover and leaver process
  • Disable leavers promptly and preserve business data according to policy
  • Review guest users and dormant accounts on a schedule
  • Block common or weak passwords and use smart lockout controls
  • Protect self-service password reset with strong verification
  • Review risky sign-ins and users where licensing provides the capability

5. Strengthen email protection

Configure SPF, DKIM and DMARC for every sending domain, then move DMARC towards enforcement after monitoring legitimate senders. Review anti-phishing, anti-spam, malware and Safe Links or Safe Attachments policies available in your licence.

Protect senior staff, finance teams and shared payment processes against impersonation. Disable automatic forwarding to external addresses unless there is an approved business need. Make reporting suspicious messages easy and connect reports to a response process.

6. Manage devices that reach business data

Know which laptops, desktops and mobiles can access Microsoft 365. Apply supported operating systems, security updates, disk encryption, screen lock, endpoint protection and device-compliance rules. Microsoft Intune and Defender for Business, included with Business Premium, can help centralise those controls.

Decide what unmanaged and personal devices may do. Conditional Access can block them or limit access, while application protection policies can separate organisational data on mobile devices. The correct choice depends on the work pattern and data sensitivity.

7. Control applications and consent

Attackers increasingly seek access through malicious or over-privileged applications. Restrict user consent to apps, establish an approval route and review enterprise applications, service principals and granted permissions.

Remove unused integrations and expired secrets. Prefer managed identities or certificates over long-lived passwords where supported. Treat third-party backup, migration and security tools as privileged suppliers and review their access.

8. Reduce accidental data exposure

  • Set SharePoint and OneDrive external-sharing defaults deliberately
  • Review anonymous “anyone” links and apply sensible expiry
  • Control who can create Teams and Microsoft 365 groups
  • Use sensitivity labels for important data where appropriate
  • Apply retention and deletion policies based on business and legal needs
  • Review mailbox delegation, forwarding and shared-mailbox access
  • Use data-loss prevention for high-risk information where licensing and risk justify it

9. Turn on visibility and use it

Review Microsoft Secure Score as a prioritisation tool, not a target to maximise blindly. Recommended actions differ in benefit, licensing need and user impact; record why an action is implemented, scheduled or accepted.

Confirm audit logging and alerting are available, retained for the period the business needs and reviewed by someone able to respond. At minimum, monitor changes to administrators, authentication methods, forwarding rules, application consent and security policies. An alert without an owner is only noise.

10. Plan for recovery

Microsoft provides resilient services, retention and recovery features, but the organisation remains responsible for account security, configuration and its recovery objectives. Assess whether native retention meets the need for deleted, encrypted or maliciously altered data and consider an independent Microsoft 365 backup.

Document recovery for a compromised administrator, deleted user, damaged SharePoint site and widespread ransomware event. Test representative restores and ensure backup administration is not dependent on the same identities it is intended to recover.

11. Review licences and the baseline regularly

Security capability varies by licence. Map the controls you intend to use to the licences actually assigned, especially Conditional Access, Intune, Defender and Purview features. Avoid designing a policy that only some users can satisfy.

Revisit the baseline after major changes and at least quarterly. Microsoft Secure Score, sign-in data, device compliance, privileged roles, guest access, forwarding rules and third-party applications provide a practical review agenda. Security is a maintained configuration, not a one-off project.

Priority checklist

  • MFA required for every user and stronger methods used for administrators
  • Privileged accounts separated and least-privilege roles applied
  • Emergency access accounts documented, protected and tested
  • Legacy authentication blocked
  • Joiner, mover, leaver and guest reviews operating
  • SPF, DKIM and DMARC configured
  • Anti-phishing policies and external forwarding reviewed
  • Managed devices encrypted, patched and protected
  • Unmanaged-device access decided and enforced
  • Application consent and delegated supplier access reviewed
  • External sharing, retention and sensitive-data controls agreed
  • Secure Score, logs and actionable alerts reviewed
  • Recovery objectives documented and restores tested

Want an expert review of your tenant?

Merr IT provides Microsoft 365 management, security and backup for established businesses across Wiltshire. We can assess the current tenant, prioritise the changes that matter and maintain the controls as the organisation evolves.