Microsoft 365

A 12-point security check for your Microsoft 365.

Microsoft 365 is secure when it’s set up well, and most small-business tenants never are. Run these twelve checks, or hand them to whoever looks after your IT.

Twelve checks, one afternoon What good looks like for each Veteran-owned, founder-led since 2020

The hard part

Why it’s rarely checked

Microsoft 365 works on day one, so nobody goes back to lock it down.

  1. What it costs you

    Email is where most small-business breaches start, and a stolen password opens everything.

  2. What it feels like

    The admin center is huge, and it’s hard to know which settings matter.

  3. Why it shouldn’t be this way

    A dozen settings cover most of the risk. You can check them in an afternoon.

Twelve checks

The checklist

  1. MFA on every account

    A password alone is easy to steal.

    Good looks like Every account uses MFA, admins included.

  2. Legacy sign-in blocked

    Older sign-in methods skip MFA entirely.

    Good looks like Legacy authentication is turned off.

  3. Admin accounts

    Every admin is a target.

    Good looks like Two or three global admins at most, each with MFA.

  4. Former employees

    Old accounts are open doors.

    Good looks like No active accounts for people who’ve left.

  5. Mail forwarding

    Attackers set rules that quietly copy your email out.

    Good looks like No automatic forwarding outside the company.

  6. External sharing

    Files shared “with anyone” spread further than intended.

    Good looks like Sharing limited to what the business actually needs.

  7. Guest accounts

    Guests pile up and are rarely reviewed.

    Good looks like Guests reviewed and removed when no longer needed.

  8. Email authentication

    Without it, anyone can send email that looks like yours.

    Good looks like SPF, DKIM and DMARC set up for your domain.

  9. Audit logging

    Without logs you can’t tell what happened.

    Good looks like Audit logging turned on.

  10. Secure Score

    Microsoft’s own measure of your setup.

    Good looks like Reviewed, with the top recommendations done.

  11. Backups

    Microsoft doesn’t back up your data the way most people assume.

    Good looks like Microsoft 365 data backed up separately, with a restore tested.

  12. Emergency admin

    If your only admin is locked out, so are you.

    Good looks like A protected emergency admin account, stored safely.

If more than two or three of these are unclear, that’s the finding.

Who we are

How we audit it

Our free IT risk review covers all twelve, and you keep the results. Clients on a monthly plan get these checks every month, not once.

All twelve checked

The same list, done properly.

Fixed in order of risk

The biggest gaps first.

Rechecked monthly

Settings drift over time.

Yours to keep

The findings are yours, whatever you decide.

Where to start

Where to start

The choice is yours.

What success looks like

Microsoft 365 you can trust.

And prove it when someone asks.

  • Every account uses MFA.
  • Nothing forwards outside without you knowing.
  • A restore has actually been tested.

Questions about a Microsoft 365 audit

How long does this take?

An experienced admin can check all twelve in an afternoon. Fixing what they find takes longer.

Can I do it myself?

Many of the checks, yes, if you have admin access. The fixes are where mistakes get expensive.

Does Microsoft do this for us?

No. Microsoft provides the settings; configuring them is up to you.

What’s Secure Score?

Microsoft’s rating of how your tenant is set up, with a list of recommended improvements.

What if we find a forwarding rule we didn’t create?

Treat it as a possible compromise: remove it, reset that account’s password, and check what else changed.

Is this part of your risk review?

Yes. All twelve checks are covered, and you keep the findings.

Want these checked for you?

Book a free IT risk review and we’ll run all twelve, in writing. Or start with a few questions about your tech.