Microsoft 365 security is a shared responsibility
Microsoft protects the underlying cloud platform, but each organisation remains responsible for its identities, permissions, devices, data and many tenant settings. A secure configuration therefore depends on more than a Microsoft 365 subscription being active.
The right controls vary with licences and risk. A five-person business, a school handling safeguarding information and an organisation with regulated data will not need identical policies. The checklist below establishes a sensible baseline and highlights where stronger controls may be appropriate.
1. Require multi-factor authentication for every user
A stolen password should not be enough to open email, OneDrive, SharePoint or Teams. Require multi-factor authentication for staff, pupils where appropriate, contractors, guests and administrators rather than protecting only senior users.
Security Defaults provides a straightforward baseline for organisations without Microsoft Entra ID premium licences. It requires MFA registration, protects privileged activity and blocks older authentication methods that cannot enforce MFA. Organisations with Microsoft Entra ID P1 or P2 licences can use Conditional Access for more precise controls based on users, devices, locations and risk. Security Defaults and a replacement Conditional Access design should not be left half-configured between the two approaches.
Use phishing-resistant authentication such as passkeys or FIDO2 security keys where practical, especially for administrators and people with access to sensitive data. Authenticator-app methods remain preferable to SMS or telephone calls when stronger options are available.
- Confirm every active user has registered approved authentication methods.
- Remove obsolete telephone numbers and devices from security information.
- Review accounts excluded from Conditional Access and document the reason.
- Block legacy authentication and investigate applications that still depend on it.
- Teach users never to approve an unexpected sign-in request.
2. Separate and protect administrator accounts
Everyday email accounts should not hold permanent Global Administrator access. Create separate cloud-only administration accounts and use them only for tasks that genuinely require elevated privileges. Give each administrator the least powerful role that can complete the job.
Microsoft recommends emergency access accounts so the organisation is not locked out if normal administrator sign-in fails. These highly privileged accounts need strong protection, monitoring and a documented process; they should not be used for daily work.
Review administrator roles regularly. Remove access when a supplier, employee or volunteer no longer needs it, and avoid shared administrator usernames because they weaken accountability.
3. Strengthen email protection and authenticate your domain
Email remains a common route for account theft, fraudulent payment requests and malware. Microsoft recommends its Standard or Strict preset security policies where the relevant Defender for Office 365 features are licensed. These policies provide a supported starting point for anti-phishing, Safe Links and Safe Attachments protection without relying on a collection of forgotten individual settings.
Configure SPF, DKIM and DMARC for every domain used to send email. SPF identifies permitted sending services, DKIM signs messages and DMARC tells receiving systems how to handle messages that fail aligned authentication. Include third-party services such as invoicing, marketing, safeguarding or management systems in the review—adding Microsoft 365 alone to DNS may not cover everything that sends as your domain.
Disable automatic forwarding to external addresses unless there is an approved business need. Configure the Outlook reporting button so suspicious messages reach the people responsible for investigation, and give staff a simple, blame-free reporting process.
- Review anti-phishing, anti-spam and anti-malware policies.
- Protect senior staff, finance teams and commonly impersonated addresses.
- Check SPF contains every legitimate sender without exceeding technical limits.
- Enable DKIM for accepted domains and introduce DMARC with monitored reporting.
- Remove broad allow lists that could let malicious messages bypass filtering.
4. Control sharing, guests and connected applications
OneDrive, SharePoint and Teams make collaboration easy, which also makes accidental oversharing possible. Set external-sharing rules deliberately rather than accepting one tenant-wide level for every site. Sensitive finance, HR, safeguarding and leadership areas may need tighter controls than general project or teaching resources.
Review guest users, anonymous links and public sharing regularly. Every external user should have a current purpose and an internal owner. Access should be removed when a project, placement, contract or governing role ends.
Users can also grant applications access to Microsoft 365 data. Review enterprise applications and consent grants for unfamiliar, unused or excessively powerful access. Restrict user consent where the organisation needs administrator approval before new applications can reach company or school information.
5. Secure the devices that access Microsoft 365
Strong cloud settings cannot protect information displayed or downloaded on an unsupported or compromised device. Keep Windows, macOS, mobile operating systems, browsers and Office applications supported and updated. Use managed anti-malware and disk encryption, and make sure lost devices can be blocked or wiped where the technology and policy allow.
Microsoft Intune and Conditional Access can require compliant devices before sensitive services are opened when suitable licences are available. Smaller organisations without those products still need an accurate device list, patching standards, screen-lock rules, secure local accounts and a clear bring-your-own-device policy.
Remove access tokens and company data when a device is lost, replaced or reassigned. Do not assume changing the user's password automatically deals with every authenticated session or locally synchronised file.
6. Plan backup and recovery separately
Version history, recycle bins and retention features help with many everyday mistakes, but they do not remove the need to decide what must be backed up, how long it must be retained and how it would be restored after malicious deletion, configuration error or a compromised administrator account.
Document which Exchange mailboxes, SharePoint sites, OneDrive accounts and Teams data are protected. Understand what your Microsoft 365 licences retain, what any independent backup product covers and who is responsible for checking failed jobs.
A backup is not proven until a restoration has been tested. Run sample recoveries of email and files, record the result and confirm that the recovery time meets the organisation's operational needs.
7. Use Secure Score, auditing and alerts
Microsoft Secure Score brings together recommended improvements across identities, applications and devices. Use it as a prioritised review tool rather than a target that must reach 100 percent. Microsoft notes that security has to be balanced with usability and that not every recommendation suits every organisation.
Confirm that Microsoft 365 audit logging is available and understand the retention included with your licences. Audit information can help investigate sign-ins, mailbox activity, sharing changes and administrator actions, but only if the right people know how to find it before an incident occurs.
Review alerts for risky sign-ins, unusual inbox rules, suspicious forwarding, mass downloads, malware and administrator changes where your licences support them. Send important alerts to a monitored address or service—not to an unattended global administrator mailbox.
8. Prepare people and an incident response
Technical controls reduce risk but cannot prevent every convincing message or mistaken approval. Give staff short, regular guidance on payment requests, password pages, unexpected file shares, MFA prompts and how to report concerns quickly.
Keep a Microsoft 365 incident checklist with named contacts and access to the required administration tools. It should cover resetting credentials, revoking sessions, checking authentication methods, mailbox rules, forwarding, application consent, sign-in activity and affected devices. Finance, safeguarding, data-protection, insurance and reporting responsibilities may also need to be involved depending on the incident.
Practical Microsoft 365 security checklist
- Require MFA for every user and use stronger phishing-resistant methods where practical.
- Choose a complete Security Defaults or Conditional Access approach.
- Use separate administrator accounts and reduce Global Administrator assignments.
- Maintain protected emergency access accounts and test the process.
- Review leavers, guests, inactive accounts and administrator roles.
- Apply suitable Standard or Strict email security policies where licensed.
- Configure and monitor SPF, DKIM and DMARC for every sending domain.
- Restrict automatic external forwarding, anonymous links and unnecessary app consent.
- Keep every device and application supported, patched, encrypted and protected.
- Check what is backed up and complete a test restoration.
- Review Secure Score recommendations, audit availability and security alerts.
- Give staff a one-click reporting route and maintain an incident checklist.
When to arrange a Microsoft 365 security review
A review is particularly useful after rapid growth, a tenant migration, staff turnover, a change of IT supplier, an account compromise or a long period without documented checks. It can also support preparation for Cyber Essentials, insurer questionnaires and customer security requirements.
Bury I.T. Support can review the Microsoft 365 tenant, prioritise realistic improvements, correct risky settings and document the resulting configuration for businesses and schools across Bury and the North West.
Official sources and further reading
These primary sources were checked when this article was last reviewed.
- Microsoft Learn: Security Defaults in Microsoft Entra ID
- Microsoft Learn: Protect Microsoft 365 privileged accounts
- Microsoft Learn: Recommended email and collaboration threat policies
- Microsoft Learn: Email authentication in Microsoft 365
- Microsoft Learn: Microsoft Secure Score
- Microsoft Learn: Search the Microsoft Purview audit log
- NCSC: Recommended types of multi-factor authentication
