AHANIX working resource
Microsoft 365 Security Checklist
Review identity, administrator roles, MFA, email protection, sharing, logging and recovery for a Microsoft 365 tenant.
For: Microsoft 365 business administrators and responsible service providers.
Section 01
Identity and administration
- Keep a small number of separately named administrator accounts.
- Require strong MFA using methods appropriate to the risk.
- Review legacy authentication, guest users, stale accounts and role assignments.
- Maintain at least one documented emergency-access process with strong protection.
Section 02
Email and collaboration
- Configure and monitor SPF, DKIM and DMARC deliberately.
- Review anti-phishing, impersonation and external-forwarding controls.
- Set sharing defaults and expiry appropriate to the organisation.
- Teach users how to report suspicious messages without forwarding harmful content casually.
Section 03
Visibility and recovery
- Enable appropriate audit and sign-in visibility for the subscribed licence.
- Review high-risk alerts and administrator changes.
- Understand retention and backup responsibilities rather than assuming Microsoft provides every recovery scenario.
- Document tenant ownership, support contacts and incident escalation.