Skip to main content

AHANIX working resource

Microsoft 365 Security Checklist

Review identity, administrator roles, MFA, email protection, sharing, logging and recovery for a Microsoft 365 tenant.

For: Microsoft 365 business administrators and responsible service providers.

Section 01

Identity and administration

  • Keep a small number of separately named administrator accounts.
  • Require strong MFA using methods appropriate to the risk.
  • Review legacy authentication, guest users, stale accounts and role assignments.
  • Maintain at least one documented emergency-access process with strong protection.

Section 02

Email and collaboration

  • Configure and monitor SPF, DKIM and DMARC deliberately.
  • Review anti-phishing, impersonation and external-forwarding controls.
  • Set sharing defaults and expiry appropriate to the organisation.
  • Teach users how to report suspicious messages without forwarding harmful content casually.

Section 03

Visibility and recovery

  • Enable appropriate audit and sign-in visibility for the subscribed licence.
  • Review high-risk alerts and administrator changes.
  • Understand retention and backup responsibilities rather than assuming Microsoft provides every recovery scenario.
  • Document tenant ownership, support contacts and incident escalation.