Microsoft 365 includes strong security features, but many are not switched on by default. Use this checklist as a starting point.
The checklist
- MFA for every user, especially administrators
- Block legacy authentication protocols that bypass MFA
- Limit global administrators to two or three named accounts
- Turn on audit logging so incidents can be investigated
- Alert on suspicious forwarding rules
- Configure SPF, DKIM and DMARC for your domain
- Review external sharing in SharePoint and OneDrive
- Enable anti-phishing policies including impersonation protection
- Back up Microsoft 365 data independently
- Remove leavers promptly and convert mailboxes if needed
Need help? Our Microsoft 365 security service works through this list and more. You can also take our free IT health check.
