Book online or chat with usAnswered 24/7Licensed, insured & bondedSchedule a Consultation
Request serviceUrgentConsultation

Microsoft 365 Security Checklist for Small Businesses (2026)

Microsoft 365 security checklist review at a small business office desk in Arizona

A Microsoft 365 security checklist is the short list of tenant settings that decide whether a stolen password turns into a breach. Most small businesses run email, files and Teams in Microsoft 365, and much of the protection is already in the license. It just isn’t all switched on, and some of it is off by default on business plans.

This guide covers each item in plain terms: MFA, legacy authentication, admin accounts, email protection, auditing, file sharing, DLP, device compliance, Secure Score and backup. If you would rather have a team set it up and keep it from drifting, our Microsoft 365 and SaaS security service covers tenant administration, posture checks and email protection.

Settings are current as of October 2026. Microsoft changes defaults and portal names often, so confirm each one in your own admin centers.

Key takeaways

  • Microsoft says MFA plus blocking legacy authentication stops more than 99.9% of common identity attacks. Start there.
  • Security defaults is free and on/off only. Conditional Access is customizable but needs Entra ID P1, included in Business Premium.
  • Keep Global Administrators few and on separate admin-only accounts: fewer than five per Microsoft, two to eight per CISA.
  • The unified audit log isn’t on by default for Business Basic, Standard or Premium. Turn it on before you need it.
  • Block automatic forwarding to outside domains, tag external senders, and back up Microsoft 365 data separately.

Where this guidance comes from. This checklist draws on Microsoft Learn documentation for Entra ID, Exchange Online, Defender for Office 365, Purview, SharePoint, Intune and Secure Score, and on CISA’s Secure Cloud Business Applications (SCuBA) baselines for Microsoft 365, including the required configurations CISA published with Binding Operational Directive 25-01. It also reflects our team’s work reviewing tenants and investigating compromised mailboxes. This is general information, not legal advice; confirm regulatory or contractual obligations with counsel or your assessor.

Security defaults vs Conditional Access

Every tenant needs one of two identity baselines. Security defaults is a single switch in Microsoft Entra ID. Per Microsoft Learn, it requires every user to register for MFA, requires MFA at every sign-in for 16 admin roles including Global, Exchange and SharePoint Administrator, blocks legacy authentication, and protects admin portals and PowerShell. Microsoft removed the 14-day MFA registration grace period on July 29, 2024.

Conditional Access replaces security defaults when you need control: break-glass exclusions, device compliance, location or risk rules, and stronger MFA for admins. It requires at least Entra ID P1, and Microsoft says that if you have P1 or P2, security defaults is probably not right for you.

Microsoft states that organizations replacing security defaults with Conditional Access must disable security defaults. Build your policies in report-only mode first, then switch in one change window. A tenant with neither is the worst case, and older tenants are the most likely to be in that state, since automatic rollout at creation applies to tenants created on or after October 22, 2019.

The Microsoft 365 security checklist at a glance

Use this table as the working checklist. Plan availability follows Microsoft’s business plan comparison; the last column shows the matching CISA SCuBA policy.

Checklist itemHowBusiness plansCISA SCuBA
MFA for all usersSecurity defaults, or a Conditional Access policy for all usersAll plans; Conditional Access needs Business PremiumMS.AAD.3.1v1
Stronger MFA for adminsPasskeys (FIDO2) or Windows Hello for BusinessAll plans; Premium can require itMS.AAD.3.6v1
Block legacy authenticationSecurity defaults or a Conditional Access blockAll plansMS.AAD.1.1v1
Limit Global AdministratorsFew named admins on separate cloud-only accounts, plus two emergency accountsAll plansMS.AAD.7.1v1, MS.AAD.7.3v1
Email threat protectionStandard and Strict preset security policiesAll plans (EOP); Premium adds Defender for Office 365 P1MS.DEFENDER.1.1v1
Tag external sendersSet-ExternalInOutlookAll plansMS.EXO.7.1v1
Block outside auto-forwardingOutbound spam policy set to OffAll plansMS.EXO.1.1v2
Audit logging onEnable unified audit log; confirm mailbox auditingAll plans (180 days)MS.DEFENDER.6.1v1
Restrict external sharingExisting guests or internal only, or tightly scoped linksAll plansMS.SHAREPOINT.1.1v1
Data loss preventionPurview DLP, simulation mode firstBusiness PremiumNot in BOD 25-01 list
Device complianceIntune compliance plus Conditional AccessBusiness PremiumNot in BOD 25-01 list
Measure progressSecure Score monthly; run ScubaGearAll plansAssessment tool
Back up M365 dataMicrosoft 365 Backup or third-party, with restore testsSeparate purchaseNot in BOD 25-01 list

Identity: MFA, legacy authentication and admin accounts

Because Microsoft says MFA and blocking legacy authentication stop more than 99.9% of common identity-related attacks, these are the highest-value items on any Microsoft 365 security checklist.

Require MFA for every user

Security defaults enforces MFA automatically. With Conditional Access, Microsoft recommends a baseline policy for all users and all resources that excludes only emergency access and service accounts, starting in report-only mode. CISA’s baseline calls for phishing-resistant MFA for all users and requires it for highly privileged roles. Our identity and access security service handles the rollout, including the lost-device process where MFA programs usually break.

Block legacy authentication

Older protocols such as basic authentication over POP, IMAP and older ActiveSync clients cannot do MFA. Microsoft’s Conditional Access documentation states that 97% of credential stuffing attacks and 99% of password spray attacks use legacy authentication. Security defaults blocks it. With Conditional Access, block the Exchange ActiveSync and Other clients conditions in report-only mode first, and check sign-in logs for scanners or old apps that still depend on it.

Clean up admin accounts

Microsoft recommends fewer than five Global Administrators and two cloud-only emergency access accounts not tied to one person. CISA’s baseline sets two to eight Global Administrators and requires privileged users to have cloud-only accounts separate from any on-premises directory.

  • Give each admin a separate admin-only account. The everyday account handles email; the admin account does admin work only.
  • Use narrower roles, such as User Administrator instead of Global Administrator for creating accounts.
  • Avoid account names that advertise privilege, such as admin@.
  • Store emergency credentials offline and alert on any sign-in to them.
  • Review role assignments monthly and remove former staff and vendors the day they leave.

Not sure where your tenant stands? We can review it against this Microsoft 365 security checklist and the CISA baselines, then fix what we find. Request a Microsoft 365 security review online with your plan type and user count.

Email: Defender for Office 365, external tags and forwarding

Once an attacker is inside a mailbox, the usual goal is business email compromise: a quiet inbox rule, a forwarded invoice thread, and a changed bank account number. Three settings make that harder.

Turn on preset security policies

Exchange Online Protection gives every plan anti-spam, anti-malware and anti-phishing. Defender for Office 365 Plan 1, listed for Business Premium, adds impersonation protection, Safe Links and Safe Attachments. Instead of tuning settings by hand, apply the Standard preset to all users and Strict to owners and anyone who approves payments. CISA’s baseline requires both presets.

Tag external senders

Exchange Online can add an External tag to outside messages in Outlook for Windows, Mac, web, iOS and Android. Turn it on with Set-ExternalInOutlook -Enabled $true; Microsoft notes it can take 24 to 48 hours to appear. It costs nothing and makes a lookalike domain easier to spot. CISA’s baseline requires external sender warnings.

Block automatic forwarding to outside domains

The outbound spam policy offers three forwarding choices: Automatic (system-controlled), On and Off. Microsoft recommends an explicit value rather than Automatic. Set it to Off, then allow exceptions only where there is a business reason, which matches CISA’s per-domain rule. Check the Auto forwarded messages report first to see who is affected.

After a compromise, the forwarding rule is often the attacker’s lasting foothold, and a password reset does not remove it. Our corporate email investigation and forensics work starts with those rules and the audit trail behind them.

Logging: mailbox auditing and the unified audit log

Microsoft states that mailbox audit logging is on by default in all organizations, including actions such as MailItemsAccessed and UpdateInboxRules. Confirm it with Get-OrganizationConfig; AuditDisabled should read False.

The unified audit log is different. Microsoft Learn states that auditing isn’t enabled by default for Business Basic, Business Standard and Business Premium, and you must turn it on. Check with Get-AdminAuditLogConfig in Exchange Online PowerShell; UnifiedAuditLogIngestionEnabled should read True. It records nothing from before it was enabled.

Audit (Standard) keeps records for 180 days for logs generated on or after October 17, 2023, up from 90 days. Longer retention needs E5-level Audit (Premium) or an add-on, so export logs on a schedule if you need more history.

Data: SharePoint and OneDrive sharing and DLP

SharePoint and OneDrive offer four sharing levels: Anyone, New and existing guests, Existing guests, and Only people in your organization. OneDrive can be stricter than SharePoint but never more permissive. CISA’s baseline limits SharePoint sharing to Existing guests or Only people in your organization.

If you must share with clients, expire or disable Anyone links, default to view-only, limit sharing to approved domains, and expire guest access.

Microsoft Purview DLP, a Business Premium feature on business plans, inspects Exchange, SharePoint, OneDrive, Teams and devices for data such as card numbers and Social Security numbers. It can warn, block with override, or block outright, and Microsoft recommends simulation mode first. Our data loss prevention service starts by finding where sensitive data actually lives.

Devices: compliance with Intune

Intune compliance policies check minimum OS version, encryption, device password and jailbreak or root status. Paired with a Conditional Access rule requiring a compliant device, a noncompliant laptop or phone can be blocked from email and files. Intune Plan 1 is a Business Premium feature.

One setting deserves attention: Mark devices with no compliance policy assigned as defaults to Compliant. Switch it to Not compliant once policies are assigned, or an unenrolled device can pass the check.

Measure it: Secure Score and the CISA SCuBA baselines

Microsoft Secure Score, in the Defender portal, measures completed recommendations across identities, devices, apps and data. Each action is worth 10 points or fewer, with partial credit, so MFA on 50 of 100 users earns half the points.

CISA’s SCuBA project publishes baselines for Entra ID, Defender, Exchange Online, SharePoint and OneDrive, Teams, Power BI and Power Platform. They were written for federal agencies, but the settings apply to any tenant. CISA’s free, open-source ScubaGear tool compares your tenant to those baselines and produces a report, a useful second opinion on your Microsoft 365 security checklist.

Backup: Microsoft keeps the service running, you keep the data

Microsoft’s shared responsibility guidance says the customer always keeps responsibility for data, endpoints, accounts and access management. Microsoft keeps the service available, not your copy of the data.

Microsoft sells Microsoft 365 Backup for SharePoint, OneDrive and Exchange Online, billed pay-as-you-go through an Azure subscription; third-party products are the other route. Whichever you choose, test a restore and keep the result. Our managed backup and disaster recovery service covers SaaS data with immutable copies and documented restore tests.

Business Basic vs Standard vs Premium for security

All three plans include security defaults, built-in email protection, Basic Mobility and Security, and the admin controls above. Business Standard adds installable Microsoft 365 Apps. Business Premium, sold for up to 300 users, adds Conditional Access, Defender for Office 365 Plan 1, Intune Plan 1, Purview DLP, sensitivity labels and message encryption. If your plan needs device rules or DLP, you need Premium or an equivalent add-on.

How to work through the checklist in order

Some changes can lock people out, so order matters:

  1. Create two emergency access accounts and confirm they work.
  2. Turn on the unified audit log.
  3. Enable security defaults, or build Conditional Access policies in report-only mode.
  4. Reduce Global Administrators and move admins to separate accounts.
  5. Apply preset policies, external tagging and the forwarding block.
  6. Tighten sharing, then pilot DLP in simulation mode.
  7. Enroll devices in Intune and require compliance.
  8. Set up backup, test a restore, and record a Secure Score baseline.

For a quick read on your overall exposure first, try the free cyber risk check.

How Honeybadger Solutions secures Microsoft 365 for small businesses

Honeybadger Solutions is a veteran-owned firm delivering cybersecurity and managed IT and network security nationwide. For Microsoft 365, we handle tenant administration as tracked configuration, posture checks against best-practice baselines with drift alerts, OAuth consent reviews, SPF, DKIM and DMARC through to enforcement, anti-phishing and impersonation defense, and account takeover response that includes session revocation and forwarding-rule cleanup.

Because we also do digital forensics, a suspected mailbox compromise can move from containment to a documented, court-ready investigation without changing vendors. No setting makes a tenant breach-proof; we work the checklist and keep it from drifting.

Request Microsoft 365 security help online with your plan type and user count, or book a consultation online to walk through your tenant with our team.

Why the online intake is faster than a phone call: it takes about two minutes, and your answers are routed straight to the specialist team that handles your kind of matter, whether that is cyber and forensics, investigations or field security. That team sees the full picture before it replies, so you skip phone tag and get a real answer and next steps sooner. If it cannot wait for business hours, use the urgent intake form, which is read seven days a week.

Frequently asked questions

Is security defaults enough for a small business on Microsoft 365?

For a tenant without Microsoft Entra ID P1, it is the right starting point. It requires MFA for every user, MFA at every sign-in for 16 admin roles, and blocks legacy authentication. It cannot be tuned, so exceptions, device rules or location rules need Conditional Access, which Microsoft lists as a Business Premium feature.

How many Global Administrators should a small business have?

Microsoft recommends fewer than five, plus two cloud-only emergency access accounts. CISA’s SCuBA baseline sets a range of two to eight. For most small businesses, that means two named admins on separate admin-only accounts, with other tasks handled through narrower roles such as User Administrator.

Is the Microsoft 365 audit log turned on by default?

Not for business plans. Microsoft states that auditing isn’t enabled by default for Business Basic, Business Standard and Business Premium, so you must turn it on. Mailbox auditing is on by default, but the unified audit log holds the sign-in, sharing and admin records an investigation needs.

Do I need Business Premium to secure Microsoft 365?

No, but it adds a lot. All business plans include security defaults, built-in anti-spam, anti-malware and anti-phishing. Microsoft lists Conditional Access, Defender for Office 365 Plan 1, Intune Plan 1, Purview DLP and sensitivity labels as Business Premium features. Business Premium is sold for up to 300 users.

Does Microsoft back up my Microsoft 365 data?

Under Microsoft’s shared responsibility model, your data, accounts and access stay your responsibility. Recycle bins and retention help with short-term mistakes. A separate backup, such as Microsoft 365 Backup (pay-as-you-go through an Azure subscription) or a third-party product, protects against ransomware and malicious deletion.

How often should we review our Microsoft 365 security checklist?

Check Secure Score and admin roles monthly, review sharing and guest accounts quarterly, and test a backup restore on a documented schedule. Re-run the full Microsoft 365 security checklist after a license change, IT staff turnover or any security incident, because settings drift when nobody owns them.

Sources and further reading

Written and reviewed by the Honeybadger Solutions security and investigations team, a veteran-led Arizona firm (Arizona DPS private investigation agency license No. 1759795). Facts checked against the cited sources on October 2, 2026. This article is general information, not legal advice.

Browse by topic

Security guard services  ·  Private investigations  ·  Cybersecurity  ·  Digital forensics  ·  Financial fraud investigation  ·  Executive protection  ·  All articles