You don't need a consultant to find out whether your Microsoft 365 tenant has the basics covered. Work through these twenty checks. Most take a minute or two in the admin portals. Click an item to check it off, and your progress is saved in this browser.
If you can check all twenty, you're ahead of most small businesses I review. If you can't, the unchecked items are your to-do list, roughly in priority order.
Admin accounts
- You have two to four Global Administrators, not one and not ten (Entra ID -> Roles and administrators -> Global Administrator)
- Admins use separate admin accounts, not their everyday mailbox account
- You have two break-glass accounts, cloud-only and excluded from Conditional Access, whose sign-ins alert someone
- Former employees and old vendors don't hold admin roles
Sign-in security
- Every user is required to use MFA, through Conditional Access or security defaults
- Legacy authentication is blocked (check the sign-in logs for "Other clients" or legacy protocols)
- Admins use phishing-resistant MFA (passkeys or security keys) where possible
- Self-service password reset is enabled, so resets don't go through email to IT
- SPF, DKIM, and DMARC are all published for every domain you send from (how)
- Automatic external forwarding is blocked in the outbound spam policy. It's how attackers quietly copy mailboxes.
- Defender for Office 365 Safe Links and Safe Attachments are on, if you're licensed (Business Premium includes them)
- External sender tagging is on, so users can see when mail comes from outside the company
Devices
- Company laptops are enrolled in Intune or another management tool
- Devices are encrypted with BitLocker (or FileVault on Macs), with keys escrowed
- Defender for Business (or another EDR) is onboarded and reporting
- Devices with no compliance policy are treated as non-compliant, not compliant (why it matters)
Data and sharing
- External sharing in SharePoint and OneDrive is set deliberately (not "Anyone" links by default)
- Guest access is reviewed. You know who your guests are and why.
- Unified audit logging is on (Purview -> Audit)
- Users can't consent to apps on their own. Admin consent workflow is on instead (Entra ID -> Enterprise apps -> Consent and permissions).
What next?
- Most checks passed? Look at Secure Score in the Defender portal for your next improvements, and run a free tool like Maester for a deeper report.
- Several unchecked? Start with the sign-in security section. It blocks the most common attacks.
- Need to prove it to an insurer? See the cyber insurance cheat sheet.