Microsoft 365
Microsoft 365 security checklist: the ten settings to fix first
A new Microsoft 365 tenant is configured for adoption, not for safety. Microsoft's defaults are chosen so that nothing gets in the way on day one, which means legacy protocols linger, sharing is open, and admin rights sprawl. This Microsoft 365 security checklist covers the ten settings to fix first, whether you look after one tenant for your own organisation or dozens for clients.
Why the defaults are not enough
Most Microsoft 365 breaches do not involve anything clever. They are password sprays against accounts without MFA, sign-ins through legacy protocols that cannot enforce it, a compromised mailbox quietly forwarding invoices to an attacker, or an ex-employee account that stayed live for six months. Every one of those is closed by configuration, not by buying anything.
Microsoft has been tightening the baseline, and security defaults now come switched on for new tenants, but "on by default" is not the same as "configured for your organisation". Defaults do not know which of your accounts are admins in practice, what your sharing posture should be, or who left last month. The checklist below is deliberately short and ordered by impact. Most items cost nothing beyond the licences you already have.
The Microsoft 365 security checklist
- Enforce MFA for every account, no exceptions. Not just admins, and not "registered but optional". A single unprotected mailbox is a foothold, and attackers do not care whose it is. Conditional Access is the cleaner way to enforce it if your licensing includes it; security defaults are the fallback if not.
- Give admins stronger authentication and separate accounts. Admin roles should sit on dedicated accounts that are not used for daily email, protected by phishing-resistant methods such as passkeys or FIDO2 keys rather than SMS codes. An admin who reads mail with the same account that holds Global Administrator is one convincing phish away from handing over the tenant.
- Cut the Global Administrator list and create a break-glass account. Two to four global admins is plenty for almost any organisation. Everyone else gets a scoped role: Exchange admin, Helpdesk admin, User admin. Then create one emergency access account, excluded from Conditional Access, with a very long password stored offline, so a bad policy change cannot lock you out of your own tenant.
- Block legacy authentication. Protocols like IMAP, POP and SMTP basic auth cannot do MFA, which makes them the open window next to your locked front door. Check the sign-in logs first for anything still using them, fix or retire it, then block the lot with Conditional Access.
- Confirm unified audit logging is on and actually recording. When something does go wrong, the audit log is the difference between an investigation and a guess. It is enabled by default on current tenants, but verify it, and run a test search so the first time you use it is not during an incident.
- Turn on the preset email security policies. Exchange Online Protection and, if licensed, Defender for Office 365 ship with Standard and Strict presets covering anti-phishing, anti-spoofing, Safe Links and Safe Attachments. The presets are better than most hand-rolled policies and they update as threats change. Apply Standard broadly and Strict to finance and executives.
- Rein in external sharing. The default SharePoint and OneDrive posture allows broad external sharing. Set the tenant default to "new and existing guests" or tighter, put expiry on guest links, and review existing guest accounts quarterly. Most organisations that do this for the first time are surprised by what has been shared and forgotten.
- Block auto-forwarding and watch for new inbox rules. The classic sign of a compromised mailbox is a rule that forwards or deletes mail so the owner never sees the replies. Disable automatic external forwarding at the transport level and alert on new forwarding rules. This one setting has quietly defeated a large share of business email compromise attempts.
- Tie sign-ins to devices you trust. Where licensing allows, require compliant or Entra-joined devices for access to company data, or at minimum block sign-ins from countries you never operate in. Identity controls work best when the endpoint itself is known and properly patched, so treat device health and tenant hardening as one exercise.
- Make offboarding immediate and complete. Disable the account, revoke active sessions, remove it from groups, convert or archive the mailbox, and reclaim the licence, on the day the person leaves. Stale accounts are the cheapest attack surface there is, and they also cost you real money in licences.
Do not over-harden in one afternoon. The most common failure mode is enthusiasm: someone applies every control on a Friday, Monday brings a flood of locked-out users, and the changes get rolled back in a panic, often further back than where you started. Roll out in stages, use report-only mode for Conditional Access policies first, and communicate before you enforce.
Settings drift, so a checklist is not a one-off
A tenant hardened in January is not hardened in July. New starters join outside the MFA policy, someone grants a contractor Global Administrator "temporarily", a vendor asks for an app consent that never gets reviewed, and a sharing exception made for one project becomes permanent. None of these announce themselves.
The fix is the same discipline that applies to backups: checking once proves nothing, so verify continuously. A green tick you saw six months ago is not evidence of anything today. Put a quarterly review in the calendar, track Secure Score as a trend rather than a trophy, and treat any drop as a question to answer, not a number to ignore.
Making it stick as a small team
If you are a one or two person team, or an MSP juggling many tenants, the checklist only works if it is cheap to repeat. Three habits keep it that way:
- Write down your intended state. One page per tenant: who the global admins are, what the sharing default is, which Conditional Access policies exist and why. Drift is invisible without a baseline to compare against.
- Alert on the changes that matter. New admin role assignments, new forwarding rules, and risky sign-ins deserve an alert. Everything else can wait for the quarterly review.
- Automate the checking, not just the fixing. The scarce resource is attention. Anything that turns "log in and look" into "get told when it changes" pays for itself within a month.
Where this fits with Helios
Helios connects to Microsoft 365 alongside the devices, patching, antivirus and backup state it already monitors, so tenant posture sits in the same view as the rest of the estate instead of in a portal you remember to check. Helio, the AI layer, uses that context when it triages tickets and investigates devices: a sign-in problem looks very different when the platform can see both the endpoint and the identity side. The checklist above is exactly the kind of routine verification we think platforms should carry for you.
Keep your Microsoft 365 security checklist honest
Helios is an AI-native platform for MSPs and in-house IT teams: monitoring, patching, security and Microsoft 365 in one place, with a 14-day trial and no feature gating.
Start free