Home / Insights / M365 Security Checklist

Microsoft 365

M365 Security Checklist

Free download: the essential settings every Irish SME should have configured.

Close up of a smartphone showing a lock icon, representing device security
Five Microsoft 365 security settings to check first: MFA, Conditional Access, limited admin rights, Intune enrollment, independent backup

Most Microsoft 365 tenants are set up with default settings and never revisited. Here is a practical checklist covering the highest-impact security settings, five minutes to skim, worth acting on this week.

Identity & access

  • Multi-factor authentication (MFA) enforced for every user, no exceptions
  • Legacy authentication protocols disabled (they bypass MFA entirely)
  • Conditional Access policies in place for at least sign-in risk and location
  • Admin accounts separated from everyday user accounts

Email protection

  • SPF, DKIM, and DMARC correctly configured for your domain
  • Anti-phishing and anti-spoofing policies enabled, not left on Microsoft defaults
  • External email tagged clearly so staff can spot spoofed internal-looking messages

Data protection

  • Data Loss Prevention (DLP) policies covering at minimum financial and personal data
  • Sensitivity labels applied to confidential document libraries
  • Sharing settings reviewed, Anyone with the link is rarely the right default

Device & backup

  • Devices enrolled in Intune or an equivalent MDM, not accessing company data unmanaged
  • Microsoft 365 data backed up independently of Microsoft own retention

If more than two or three of these are not in place, that is a reasonable starting point for a proper audit rather than trying to fix everything piecemeal.

Have a Similar Question About Your Own Setup?