Microsoft 365
A 12-point security check for your Microsoft 365.
Microsoft 365 is secure when it’s set up well, and most small-business tenants never are. Run these twelve checks, or hand them to whoever looks after your IT.
The hard part
Why it’s rarely checked
Microsoft 365 works on day one, so nobody goes back to lock it down.
-
What it costs you
Email is where most small-business breaches start, and a stolen password opens everything.
-
What it feels like
The admin center is huge, and it’s hard to know which settings matter.
-
Why it shouldn’t be this way
A dozen settings cover most of the risk. You can check them in an afternoon.
Twelve checks
The checklist
-
MFA on every account
A password alone is easy to steal.
Good looks like Every account uses MFA, admins included.
-
Legacy sign-in blocked
Older sign-in methods skip MFA entirely.
Good looks like Legacy authentication is turned off.
-
Admin accounts
Every admin is a target.
Good looks like Two or three global admins at most, each with MFA.
-
Former employees
Old accounts are open doors.
Good looks like No active accounts for people who’ve left.
-
Mail forwarding
Attackers set rules that quietly copy your email out.
Good looks like No automatic forwarding outside the company.
-
External sharing
Files shared “with anyone” spread further than intended.
Good looks like Sharing limited to what the business actually needs.
-
Guest accounts
Guests pile up and are rarely reviewed.
Good looks like Guests reviewed and removed when no longer needed.
-
Email authentication
Without it, anyone can send email that looks like yours.
Good looks like SPF, DKIM and DMARC set up for your domain.
-
Audit logging
Without logs you can’t tell what happened.
Good looks like Audit logging turned on.
-
Secure Score
Microsoft’s own measure of your setup.
Good looks like Reviewed, with the top recommendations done.
-
Backups
Microsoft doesn’t back up your data the way most people assume.
Good looks like Microsoft 365 data backed up separately, with a restore tested.
-
Emergency admin
If your only admin is locked out, so are you.
Good looks like A protected emergency admin account, stored safely.
If more than two or three of these are unclear, that’s the finding.
Who we are
How we audit it
Our free IT risk review covers all twelve, and you keep the results. Clients on a monthly plan get these checks every month, not once.
All twelve checked
The same list, done properly.
Fixed in order of risk
The biggest gaps first.
Rechecked monthly
Settings drift over time.
Yours to keep
The findings are yours, whatever you decide.
Where to start
Where to start
The choice is yours.
- Want all twelve checked for you? Book my free IT risk review →
- A team of 15 to 70 who want IT fully handled. Our Fully Managed IT Support Program →
- A small team, mostly in the cloud. IT Essentials →
What success looks like
Microsoft 365 you can trust.
And prove it when someone asks.
- Every account uses MFA.
- Nothing forwards outside without you knowing.
- A restore has actually been tested.
Questions about a Microsoft 365 audit
How long does this take?
An experienced admin can check all twelve in an afternoon. Fixing what they find takes longer.
Can I do it myself?
Many of the checks, yes, if you have admin access. The fixes are where mistakes get expensive.
Does Microsoft do this for us?
No. Microsoft provides the settings; configuring them is up to you.
What’s Secure Score?
Microsoft’s rating of how your tenant is set up, with a list of recommended improvements.
What if we find a forwarding rule we didn’t create?
Treat it as a possible compromise: remove it, reset that account’s password, and check what else changed.
Is this part of your risk review?
Yes. All twelve checks are covered, and you keep the findings.
Want these checked for you?
Book a free IT risk review and we’ll run all twelve, in writing. Or start with a few questions about your tech.