
A Microsoft 365 security checklist is the short list of tenant settings that decide whether a stolen password turns into a breach. Most small businesses run email, files and Teams in Microsoft 365, and much of the protection is already in the license. It just isn’t all switched on, and some of it is off by default on business plans.
This guide covers each item in plain terms: MFA, legacy authentication, admin accounts, email protection, auditing, file sharing, DLP, device compliance, Secure Score and backup. If you would rather have a team set it up and keep it from drifting, our Microsoft 365 and SaaS security service covers tenant administration, posture checks and email protection.
Settings are current as of October 2026. Microsoft changes defaults and portal names often, so confirm each one in your own admin centers.
Key takeaways
- Microsoft says MFA plus blocking legacy authentication stops more than 99.9% of common identity attacks. Start there.
- Security defaults is free and on/off only. Conditional Access is customizable but needs Entra ID P1, included in Business Premium.
- Keep Global Administrators few and on separate admin-only accounts: fewer than five per Microsoft, two to eight per CISA.
- The unified audit log isn’t on by default for Business Basic, Standard or Premium. Turn it on before you need it.
- Block automatic forwarding to outside domains, tag external senders, and back up Microsoft 365 data separately.
Where this guidance comes from. This checklist draws on Microsoft Learn documentation for Entra ID, Exchange Online, Defender for Office 365, Purview, SharePoint, Intune and Secure Score, and on CISA’s Secure Cloud Business Applications (SCuBA) baselines for Microsoft 365, including the required configurations CISA published with Binding Operational Directive 25-01. It also reflects our team’s work reviewing tenants and investigating compromised mailboxes. This is general information, not legal advice; confirm regulatory or contractual obligations with counsel or your assessor.
Security defaults vs Conditional Access
Every tenant needs one of two identity baselines. Security defaults is a single switch in Microsoft Entra ID. Per Microsoft Learn, it requires every user to register for MFA, requires MFA at every sign-in for 16 admin roles including Global, Exchange and SharePoint Administrator, blocks legacy authentication, and protects admin portals and PowerShell. Microsoft removed the 14-day MFA registration grace period on July 29, 2024.
Conditional Access replaces security defaults when you need control: break-glass exclusions, device compliance, location or risk rules, and stronger MFA for admins. It requires at least Entra ID P1, and Microsoft says that if you have P1 or P2, security defaults is probably not right for you.
Microsoft states that organizations replacing security defaults with Conditional Access must disable security defaults. Build your policies in report-only mode first, then switch in one change window. A tenant with neither is the worst case, and older tenants are the most likely to be in that state, since automatic rollout at creation applies to tenants created on or after October 22, 2019.
The Microsoft 365 security checklist at a glance
Use this table as the working checklist. Plan availability follows Microsoft’s business plan comparison; the last column shows the matching CISA SCuBA policy.
| Checklist item | How | Business plans | CISA SCuBA |
|---|---|---|---|
| MFA for all users | Security defaults, or a Conditional Access policy for all users | All plans; Conditional Access needs Business Premium | MS.AAD.3.1v1 |
| Stronger MFA for admins | Passkeys (FIDO2) or Windows Hello for Business | All plans; Premium can require it | MS.AAD.3.6v1 |
| Block legacy authentication | Security defaults or a Conditional Access block | All plans | MS.AAD.1.1v1 |
| Limit Global Administrators | Few named admins on separate cloud-only accounts, plus two emergency accounts | All plans | MS.AAD.7.1v1, MS.AAD.7.3v1 |
| Email threat protection | Standard and Strict preset security policies | All plans (EOP); Premium adds Defender for Office 365 P1 | MS.DEFENDER.1.1v1 |
| Tag external senders | Set-ExternalInOutlook | All plans | MS.EXO.7.1v1 |
| Block outside auto-forwarding | Outbound spam policy set to Off | All plans | MS.EXO.1.1v2 |
| Audit logging on | Enable unified audit log; confirm mailbox auditing | All plans (180 days) | MS.DEFENDER.6.1v1 |
| Restrict external sharing | Existing guests or internal only, or tightly scoped links | All plans | MS.SHAREPOINT.1.1v1 |
| Data loss prevention | Purview DLP, simulation mode first | Business Premium | Not in BOD 25-01 list |
| Device compliance | Intune compliance plus Conditional Access | Business Premium | Not in BOD 25-01 list |
| Measure progress | Secure Score monthly; run ScubaGear | All plans | Assessment tool |
| Back up M365 data | Microsoft 365 Backup or third-party, with restore tests | Separate purchase | Not in BOD 25-01 list |
Identity: MFA, legacy authentication and admin accounts
Because Microsoft says MFA and blocking legacy authentication stop more than 99.9% of common identity-related attacks, these are the highest-value items on any Microsoft 365 security checklist.
Require MFA for every user
Security defaults enforces MFA automatically. With Conditional Access, Microsoft recommends a baseline policy for all users and all resources that excludes only emergency access and service accounts, starting in report-only mode. CISA’s baseline calls for phishing-resistant MFA for all users and requires it for highly privileged roles. Our identity and access security service handles the rollout, including the lost-device process where MFA programs usually break.
Block legacy authentication
Older protocols such as basic authentication over POP, IMAP and older ActiveSync clients cannot do MFA. Microsoft’s Conditional Access documentation states that 97% of credential stuffing attacks and 99% of password spray attacks use legacy authentication. Security defaults blocks it. With Conditional Access, block the Exchange ActiveSync and Other clients conditions in report-only mode first, and check sign-in logs for scanners or old apps that still depend on it.
Clean up admin accounts
Microsoft recommends fewer than five Global Administrators and two cloud-only emergency access accounts not tied to one person. CISA’s baseline sets two to eight Global Administrators and requires privileged users to have cloud-only accounts separate from any on-premises directory.
- Give each admin a separate admin-only account. The everyday account handles email; the admin account does admin work only.
- Use narrower roles, such as User Administrator instead of Global Administrator for creating accounts.
- Avoid account names that advertise privilege, such as admin@.
- Store emergency credentials offline and alert on any sign-in to them.
- Review role assignments monthly and remove former staff and vendors the day they leave.
Not sure where your tenant stands? We can review it against this Microsoft 365 security checklist and the CISA baselines, then fix what we find. Request a Microsoft 365 security review online with your plan type and user count.
Email: Defender for Office 365, external tags and forwarding
Once an attacker is inside a mailbox, the usual goal is business email compromise: a quiet inbox rule, a forwarded invoice thread, and a changed bank account number. Three settings make that harder.
Turn on preset security policies
Exchange Online Protection gives every plan anti-spam, anti-malware and anti-phishing. Defender for Office 365 Plan 1, listed for Business Premium, adds impersonation protection, Safe Links and Safe Attachments. Instead of tuning settings by hand, apply the Standard preset to all users and Strict to owners and anyone who approves payments. CISA’s baseline requires both presets.
Tag external senders
Exchange Online can add an External tag to outside messages in Outlook for Windows, Mac, web, iOS and Android. Turn it on with Set-ExternalInOutlook -Enabled $true; Microsoft notes it can take 24 to 48 hours to appear. It costs nothing and makes a lookalike domain easier to spot. CISA’s baseline requires external sender warnings.
Block automatic forwarding to outside domains
The outbound spam policy offers three forwarding choices: Automatic (system-controlled), On and Off. Microsoft recommends an explicit value rather than Automatic. Set it to Off, then allow exceptions only where there is a business reason, which matches CISA’s per-domain rule. Check the Auto forwarded messages report first to see who is affected.
After a compromise, the forwarding rule is often the attacker’s lasting foothold, and a password reset does not remove it. Our corporate email investigation and forensics work starts with those rules and the audit trail behind them.
Logging: mailbox auditing and the unified audit log
Microsoft states that mailbox audit logging is on by default in all organizations, including actions such as MailItemsAccessed and UpdateInboxRules. Confirm it with Get-OrganizationConfig; AuditDisabled should read False.
The unified audit log is different. Microsoft Learn states that auditing isn’t enabled by default for Business Basic, Business Standard and Business Premium, and you must turn it on. Check with Get-AdminAuditLogConfig in Exchange Online PowerShell; UnifiedAuditLogIngestionEnabled should read True. It records nothing from before it was enabled.
Audit (Standard) keeps records for 180 days for logs generated on or after October 17, 2023, up from 90 days. Longer retention needs E5-level Audit (Premium) or an add-on, so export logs on a schedule if you need more history.
Data: SharePoint and OneDrive sharing and DLP
SharePoint and OneDrive offer four sharing levels: Anyone, New and existing guests, Existing guests, and Only people in your organization. OneDrive can be stricter than SharePoint but never more permissive. CISA’s baseline limits SharePoint sharing to Existing guests or Only people in your organization.
If you must share with clients, expire or disable Anyone links, default to view-only, limit sharing to approved domains, and expire guest access.
Microsoft Purview DLP, a Business Premium feature on business plans, inspects Exchange, SharePoint, OneDrive, Teams and devices for data such as card numbers and Social Security numbers. It can warn, block with override, or block outright, and Microsoft recommends simulation mode first. Our data loss prevention service starts by finding where sensitive data actually lives.
Devices: compliance with Intune
Intune compliance policies check minimum OS version, encryption, device password and jailbreak or root status. Paired with a Conditional Access rule requiring a compliant device, a noncompliant laptop or phone can be blocked from email and files. Intune Plan 1 is a Business Premium feature.
One setting deserves attention: Mark devices with no compliance policy assigned as defaults to Compliant. Switch it to Not compliant once policies are assigned, or an unenrolled device can pass the check.
Measure it: Secure Score and the CISA SCuBA baselines
Microsoft Secure Score, in the Defender portal, measures completed recommendations across identities, devices, apps and data. Each action is worth 10 points or fewer, with partial credit, so MFA on 50 of 100 users earns half the points.
CISA’s SCuBA project publishes baselines for Entra ID, Defender, Exchange Online, SharePoint and OneDrive, Teams, Power BI and Power Platform. They were written for federal agencies, but the settings apply to any tenant. CISA’s free, open-source ScubaGear tool compares your tenant to those baselines and produces a report, a useful second opinion on your Microsoft 365 security checklist.
Backup: Microsoft keeps the service running, you keep the data
Microsoft’s shared responsibility guidance says the customer always keeps responsibility for data, endpoints, accounts and access management. Microsoft keeps the service available, not your copy of the data.
Microsoft sells Microsoft 365 Backup for SharePoint, OneDrive and Exchange Online, billed pay-as-you-go through an Azure subscription; third-party products are the other route. Whichever you choose, test a restore and keep the result. Our managed backup and disaster recovery service covers SaaS data with immutable copies and documented restore tests.
Business Basic vs Standard vs Premium for security
All three plans include security defaults, built-in email protection, Basic Mobility and Security, and the admin controls above. Business Standard adds installable Microsoft 365 Apps. Business Premium, sold for up to 300 users, adds Conditional Access, Defender for Office 365 Plan 1, Intune Plan 1, Purview DLP, sensitivity labels and message encryption. If your plan needs device rules or DLP, you need Premium or an equivalent add-on.
How to work through the checklist in order
Some changes can lock people out, so order matters:
- Create two emergency access accounts and confirm they work.
- Turn on the unified audit log.
- Enable security defaults, or build Conditional Access policies in report-only mode.
- Reduce Global Administrators and move admins to separate accounts.
- Apply preset policies, external tagging and the forwarding block.
- Tighten sharing, then pilot DLP in simulation mode.
- Enroll devices in Intune and require compliance.
- Set up backup, test a restore, and record a Secure Score baseline.
For a quick read on your overall exposure first, try the free cyber risk check.
How Honeybadger Solutions secures Microsoft 365 for small businesses
Honeybadger Solutions is a veteran-owned firm delivering cybersecurity and managed IT and network security nationwide. For Microsoft 365, we handle tenant administration as tracked configuration, posture checks against best-practice baselines with drift alerts, OAuth consent reviews, SPF, DKIM and DMARC through to enforcement, anti-phishing and impersonation defense, and account takeover response that includes session revocation and forwarding-rule cleanup.
Because we also do digital forensics, a suspected mailbox compromise can move from containment to a documented, court-ready investigation without changing vendors. No setting makes a tenant breach-proof; we work the checklist and keep it from drifting.
Request Microsoft 365 security help online with your plan type and user count, or book a consultation online to walk through your tenant with our team.
Why the online intake is faster than a phone call: it takes about two minutes, and your answers are routed straight to the specialist team that handles your kind of matter, whether that is cyber and forensics, investigations or field security. That team sees the full picture before it replies, so you skip phone tag and get a real answer and next steps sooner. If it cannot wait for business hours, use the urgent intake form, which is read seven days a week.
Frequently asked questions
Is security defaults enough for a small business on Microsoft 365?
For a tenant without Microsoft Entra ID P1, it is the right starting point. It requires MFA for every user, MFA at every sign-in for 16 admin roles, and blocks legacy authentication. It cannot be tuned, so exceptions, device rules or location rules need Conditional Access, which Microsoft lists as a Business Premium feature.
How many Global Administrators should a small business have?
Microsoft recommends fewer than five, plus two cloud-only emergency access accounts. CISA’s SCuBA baseline sets a range of two to eight. For most small businesses, that means two named admins on separate admin-only accounts, with other tasks handled through narrower roles such as User Administrator.
Is the Microsoft 365 audit log turned on by default?
Not for business plans. Microsoft states that auditing isn’t enabled by default for Business Basic, Business Standard and Business Premium, so you must turn it on. Mailbox auditing is on by default, but the unified audit log holds the sign-in, sharing and admin records an investigation needs.
Do I need Business Premium to secure Microsoft 365?
No, but it adds a lot. All business plans include security defaults, built-in anti-spam, anti-malware and anti-phishing. Microsoft lists Conditional Access, Defender for Office 365 Plan 1, Intune Plan 1, Purview DLP and sensitivity labels as Business Premium features. Business Premium is sold for up to 300 users.
Does Microsoft back up my Microsoft 365 data?
Under Microsoft’s shared responsibility model, your data, accounts and access stay your responsibility. Recycle bins and retention help with short-term mistakes. A separate backup, such as Microsoft 365 Backup (pay-as-you-go through an Azure subscription) or a third-party product, protects against ransomware and malicious deletion.
How often should we review our Microsoft 365 security checklist?
Check Secure Score and admin roles monthly, review sharing and guest accounts quarterly, and test a backup restore on a documented schedule. Re-run the full Microsoft 365 security checklist after a license change, IT staff turnover or any security incident, because settings drift when nobody owns them.
Sources and further reading
- Microsoft Learn: Security defaults in Microsoft Entra ID — what security defaults enforces and the 99.9% figure.
- Microsoft Learn: Block legacy authentication — legacy authentication attack statistics.
- Microsoft Learn: Best practices for Entra roles — Global Administrator limits.
- Microsoft Learn: Admin account security for business — separate admin accounts.
- Microsoft Learn: Microsoft 365 for business security best practices — features by business plan.
- Microsoft Learn: Preset security policies — Standard and Strict presets.
- Microsoft Learn: Control external email forwarding — forwarding settings.
- Microsoft Learn: Turn auditing on or off — audit log off by default on business plans.
- Microsoft Learn: Audit log retention policies — 180-day retention.
- Microsoft Learn: SharePoint and OneDrive sharing settings — sharing levels.
- Microsoft Learn: Intune device compliance — compliance policies.
- Microsoft Learn: Microsoft Secure Score — scoring method.
- Microsoft Learn: Shared responsibility in the cloud — customer data responsibility.
- CISA: BOD 25-01 required configurations — SCuBA M365 policy IDs.
Written and reviewed by the Honeybadger Solutions security and investigations team, a veteran-led Arizona firm (Arizona DPS private investigation agency license No. 1759795). Facts checked against the cited sources on October 2, 2026. This article is general information, not legal advice.
Browse by topic
Security guard services  · Private investigations  · Cybersecurity  · Digital forensics  · Financial fraud investigation  · Executive protection  · All articles