Microsoft 365 Security Checklist

Microsoft 365 Security Checklist: 15 Settings Every Small Business Should Review

A secure Microsoft 365 tenant depends on more than turning on multifactor authentication. Small businesses also need to review administrator privileges, legacy authentication, external forwarding, application permissions, audit logging, email protection, and sharing controls. This Microsoft 365 security checklist highlights 15 settings that are easy to overlook but can have a direct effect on account compromise, data exposure, and business continuity. Franklin Web Technologies uses this type of configuration-focused review to help businesses identify gaps that basic security setup can leave behind. 

1. Confirm that MFA protects every user 

Multifactor authentication should cover regular users, administrators, contractors, and other accounts that can access business data. A password alone provides limited protection against phishing, password spraying, and reused credentials. 

Businesses without Microsoft Entra ID P1 or P2 can use Security Defaults as a baseline. Security Defaults require MFA registration and block several older authentication methods. Organizations with Microsoft Entra ID P1 or higher can use Conditional Access for more granular policies. 

Example configuration: 

Microsoft Entra admin center > Entra ID > Overview > Properties > Manage security defaults 

Do not assume MFA is active simply because some employees receive authentication prompts. Check the tenant configuration and sign-in reports to verify coverage. 

2. Review the authentication methods employees can register 

MFA is only as strong as the authentication methods behind it. Microsoft 365 administrators should review which methods users can register and remove methods that do not fit the organization’s security requirements. 

For privileged users, phishing-resistant methods such as passkeys or FIDO2 security keys provide stronger protection against phishing than methods that depend entirely on passwords or approval prompts. 

A useful Microsoft 365 security assessment should identify users with weak, outdated, or unnecessary authentication methods and verify that recovery options are also controlled. 

3. Protect administrator accounts separately 

A Global Administrator account should not be the same account used for routine email, Teams conversations, web browsing, and document work. 

Create dedicated administrator accounts and assign only the roles required for administrative duties. Microsoft recommends least-privileged administrative roles as part of identity security guidance. 

Review the following: 

  • Global Administrator assignments 

  • Exchange Administrator assignments 

  • Security Administrator assignments 

  • Privileged Role Administrator assignments 

  • Inactive administrator accounts 

This is a central part of Microsoft 365 admin security because a compromised administrator account can affect far more than one employee’s mailbox. 

4. Create and test emergency access accounts 

An emergency access account is designed for situations such as an administrator lockout or authentication-policy failure. It should not become someone’s everyday account. 

Microsoft recommends maintaining at least two cloud-only emergency access accounts, protecting them with phishing-resistant authentication, storing credentials securely, monitoring their use, and validating them regularly. 

Example: 

Create two dedicated .onmicrosoft.com accounts, document their purpose, secure their credentials separately, and test access at least every 90 days. 

These accounts should be treated as controlled recovery mechanisms, not spare administrator accounts. 

5. Block legacy authentication 

Legacy authentication is one of the settings that deserves immediate attention during Microsoft 365 hardening. 

Older protocols such as POP3, IMAP, and other basic authentication methods do not support modern security controls such as MFA. Microsoft specifically recommends blocking legacy authentication because attackers can use these protocols to bypass protections applied to modern sign-ins. 

Check sign-in logs before enforcing the policy. Identify devices, applications, scanners, or other services still relying on older authentication and migrate them first. 

6. Review device code authentication 

Device code authentication can be useful for devices with limited input capabilities, but it can also be abused in phishing attacks. Microsoft Security Defaults block device code flow as part of their baseline protections. 

Organizations using Conditional Access should review policies covering device code authentication and determine if any legitimate business process requires an exception. 

An overlooked authentication flow can give an attacker another route into a tenant even after conventional MFA controls are enabled. 

7. Limit unnecessary application consent 

Employees can sometimes grant applications access to Microsoft 365 data. An employee may approve an application without realizing that the permission allows access to mail, files, calendars, contacts, or other organizational information. 

Review Microsoft Entra application consent settings and decide who can approve applications. For higher-risk permissions, route requests through administrator approval. 

Example policy approach: 

Require administrator approval for applications requesting sensitive Microsoft Graph permissions. 

This reduces the chance that a malicious or poorly configured third-party application becomes an indirect path to business data. 

8. Review inactive users and guest accounts 

Old employee accounts, dormant users, former contractors, and unused guest accounts increase the number of identities that need protection. 

Run regular reviews of: 

  • Disabled and inactive accounts 

  • Guest users 

  • Users with administrative roles 

  • Accounts that have not signed in for extended periods 

Microsoft’s identity security recommendations specifically include removing dormant accounts from sensitive groups and using least-privileged administrative roles. 

Account cleanup should be part of normal Microsoft 365 administration rather than an occasional security project. 

9. Check external email forwarding 

Automatic forwarding deserves special attention because it can quietly move company information outside the tenant. 

Microsoft identifies automatic forwarding to external recipients as a security concern because it can expose organizational information. Users can create forwarding through inbox rules, while administrators can configure mailbox forwarding. 

Review existing forwarding rules and determine which external destinations are legitimate. 

Example check: 

Exchange admin center > Mail flow > Remote domains / outbound spam policies 

For most small businesses, external automatic forwarding should be restricted unless there is a documented business requirement. 

10. Tighten external sharing in SharePoint and OneDrive 

SharePoint and OneDrive can contain contracts, financial documents, customer information, employee records, and internal procedures. A permissive sharing configuration can make sensitive files accessible outside the organization. 

Review default sharing links, guest access, anonymous links, and domain restrictions. Apply stricter controls to sites containing confidential information. 

A useful configuration principle is simple: users should have an easy internal sharing process while external access requires a clear business reason. 

11. Turn on the right email protection policies 

Microsoft Defender for Office 365 provides controls such as Safe Links, Safe Attachments, and enhanced anti-phishing protection. Microsoft notes that the built-in protection preset provides basic Safe Links and Safe Attachments protection for eligible Defender customers, while Standard and Strict preset policies provide stronger configurations. 

Review: 

  • Anti-phishing policies 

  • Impersonation protection 

  • Safe Links 

  • Safe Attachments 

  • Anti-malware policies 

Pay particular attention to executive accounts, finance users, and employees who frequently handle payment or customer information. 

12. Protect against impersonation attacks 

A basic spam filter does not address every impersonation scenario. Attackers may imitate executives, suppliers, domains, or trusted contacts to convince employees to transfer money or disclose information. 

Microsoft Defender for Office 365 supports impersonation protection through its security policies. The default anti-phishing policy includes spoof protection and mailbox intelligence, while additional impersonation controls require configuration through preset or custom policies. 

Add high-value users and important business domains to the appropriate protection policies and review alerts regularly. 

13. Verify that audit logging is useful 

Audit logs are valuable only when the organization knows what activity it needs to investigate. 

Confirm that auditing is available and that administrators know where to review activity involving users, administrators, mailboxes, applications, and other Microsoft 365 services. 

A security review should also establish a basic retention and investigation process. Suspicious sign-ins, unexpected permission changes, forwarding rules, and administrator actions should have a clear path for investigation. 

For emergency access accounts, Microsoft specifically recommends monitoring sign-in and audit logs. 

14. Review Microsoft Secure Score instead of ignoring it 

Microsoft Secure Score provides a useful starting point for identifying security improvements. The identity portion evaluates configuration against recommended controls and recalculates based on the tenant’s security posture. 

Do not treat the score as a complete security rating. A high score does not prove that every important business risk has been addressed. 

Use it as a review queue. Prioritize recommendations based on the sensitivity of your data, user roles, current threats, licensing, and operational requirements. 

15. Review Conditional Access policies for gaps and exceptions 

Conditional Access can apply rules based on factors such as user, application, device, location, and authentication requirements. The danger is not only missing policies. Poorly managed exclusions can create the same problem. 

Review every policy for: 

  • Users or groups excluded from MFA 

  • Emergency access exclusions 

  • Legacy authentication blocks 

  • Administrator protection 

  • Unmanaged device access 

  • Report-only policies that were never enforced 

Microsoft recommends using Conditional Access when organizations need more customization than Security Defaults provides. 

Document every exception and assign an owner. An exception without an owner can remain in place long after the original business need has disappeared. 

How To Turn The Checklist Into A Practical Security Review 

A useful Microsoft 365 security assessment should not stop at checking boxes. Record the current configuration, identify the business reason for exceptions, assign a responsible administrator, and set a review date. 

For example, a small business might find that MFA is enabled for employees but three administrator accounts are excluded from a Conditional Access policy. Another review might uncover external forwarding from an old mailbox or guest accounts that have not been used for months. 

Those findings have different levels of urgency, so prioritize them by business impact. An administrator account without strong authentication generally deserves faster remediation than a low-risk configuration preference. 

Franklin Web Technologies can use this configuration-first approach to help businesses examine Microsoft 365 security settings beyond the obvious controls. The goal is to identify settings that attackers could exploit and translate technical findings into practical actions for the business. 

A Simple Review Schedule For Small Businesses

Security settings should be reviewed after major Microsoft 365 changes, administrator changes, new applications, acquisitions, employee departures, and significant changes to how staff access company data. 

A quarterly review can cover administrator roles, inactive users, guest accounts, authentication methods, forwarding rules, Conditional Access exclusions, external sharing, and Defender policies. A deeper annual review can examine the complete tenant configuration and compare it against current Microsoft 365 security best practices. 

The process also gives business owners a clearer picture of their Microsoft 365 security risks instead of relying on assumptions about default protection. 

Final Thoughts 

Microsoft 365 can provide strong built-in security, but secure configuration still requires attention. MFA, administrator protection, legacy authentication controls, forwarding restrictions, application consent, email defenses, sharing policies, and audit visibility all contribute to a safer tenant. 

The most effective checklist is one that reflects how your business actually uses Microsoft 365. Review the settings, document exceptions, remove unnecessary access, and test recovery controls instead of assuming they work. 

For small businesses that need a more detailed review or assistance with secure Microsoft 365 for small business, Contact Us Now to discuss your Microsoft 365 configuration and identify practical security improvements.