Cyber Security GuidesChecklist and Guide

Microsoft 365 Security Baseline Checklist

10 minutes to completeEvergreen guide — kept up to date

Microsoft 365 is not securely configured for every business by default. Use this checklist to review seven core security controls — authentication, administrator privilege, external sharing, device access, audit logging, baseline configuration and ongoing risk monitoring.

Microsoft 365 is not insecure by default — but it is not securely configured for every business by default either. Default settings allow users to work. Security configuration requires deliberate decisions about authentication, administrator access, external sharing, device controls, audit logging and ongoing monitoring.

Buying the security licence is not the same thing as implementing the security control.

The Seven-Control Framework

Use the IT Club Microsoft 365 Security Baseline: AUTHENTICATE → LIMIT → CONTROL → TRUST → RECORD → STANDARDISE → REVIEW

1 — Authenticate: Identity Controls

  • □ MFA is enforced for all users
  • □ Authentication methods are reviewed — weaker methods phased out where possible
  • □ Administrator accounts use stronger authentication (passkey or phishing-resistant MFA)
  • □ Legacy authentication protocols are blocked where technically feasible
  • □ Break-glass (emergency access) accounts are documented and stored securely
  • □ Temporary Access Pass policy is configured for MFA recovery

2 — Limit: Privileged Access

  • □ Global Administrators are reviewed — number minimised
  • □ Daily user accounts and administrator identities are separated where appropriate
  • □ Standing privilege is minimised — PIM considered where licensed
  • □ Former IT suppliers no longer retain unnecessary privileged roles
  • □ External delegated administration is reviewed and appropriately scoped
  • □ Emergency access is documented separately from routine administrator access

3 — Control: External Sharing

  • □ SharePoint external sharing level is reviewed and intentionally set
  • □ OneDrive external sharing level is reviewed and intentionally set
  • □ Teams guest access is reviewed and intentionally configured
  • □ Guest accounts are periodically reviewed — inactive guests removed
  • □ Anonymous sharing links are controlled — expiry configured where permitted
  • □ A process exists for creating and reviewing external sharing

4 — Trust: Device Access

  • □ Supported operating system versions are required
  • □ Disk encryption (BitLocker for Windows) is verified
  • □ Endpoint protection (Microsoft Defender) is active and reporting
  • □ Device compliance policies are defined and enforced via Conditional Access
  • □ Unmanaged device access has been explicitly decided — not left as default
  • □ Mobile device access is addressed through device management or app protection

5 — Record: Audit Logging

  • □ Microsoft Purview Audit is verified as active
  • □ Audit log retention period is understood and appropriate
  • □ Administrator actions — role changes, policy changes — can be investigated
  • □ Sign-in activity is available and reviewed
  • □ Critical events (consent grants, mass downloads, role changes) alert a named owner

6 — Standardise: Security Baseline

  • □ Identity settings (MFA, Conditional Access, auth methods) are documented
  • □ Exchange Online security configuration is documented
  • □ SharePoint and OneDrive settings are documented
  • □ Teams security configuration is documented
  • □ Endpoint and device controls are documented
  • □ Exceptions to the baseline are documented with justification and review dates

7 — Review: Risk Monitoring

  • □ Secure Score is reviewed regularly — at least quarterly
  • □ Risky users are reviewed and remediated
  • □ Risky sign-ins are reviewed and investigated
  • □ Administrator role changes are reviewed regularly
  • □ Conditional Access changes and new exclusions are reviewed
  • □ Corrective actions from previous reviews are tracked and assigned

Self-Assessment Guide

For each of the seven areas, mark: Green — reviewed and controlled; Amber — partially implemented or not recently reviewed; Red — unknown, absent or uncontrolled.

After completing the assessment: identify the strongest area (Green); identify the highest-risk area (Red or Amber); choose a single next action that would most improve the overall position. Start there.

The biggest warning sign is not a low Secure Score. It is not knowing what the current configuration actually is.

About CIS and Secure Score

The CIS Microsoft 365 Foundations Benchmark (current version: v7.0.0, June 2026 — verify at cisecurity.org) provides community-developed configuration recommendations. Microsoft Secure Score measures adoption of Microsoft-recommended security actions. Neither is the same as Cyber Essentials certification. None of the three proves that an organisation cannot be breached.

For each Secure Score recommendation, document one of four positions: Implement; Accept risk (with documented reason); Not applicable; Defer (with review date).

Want the full explanation?

Read our Technology Intelligence article for a plain-English guide to the seven controls, the CIS benchmark, Microsoft Secure Score, common mistakes and warning signs.

Microsoft 365 Security Checklist: 7 Controls Every Business Should Review

Plain-English Takeaway

Microsoft 365 security is a configuration discipline, not a licensing decision. Establish a baseline, compare the tenant against current CIS and Microsoft recommendations, document exceptions, prioritise identity and privilege, control access and review the environment repeatedly as users, devices, suppliers and Microsoft itself change.

Downloadable guide

Microsoft 365 Security Baseline Checklist

Two-page A4 PDF covering the seven controls with the full review checklist across identity, privilege, sharing, devices, logging, baseline and monitoring — plus the self-assessment guide and maturity model.

Download Checklist (PDF)

A4 PDF · 2 pages · Selectable text · Print or use on screen.

Still unsure what applies to your business?

Ask the IT Club Advisor about Microsoft 365, browsers, cyber security, productivity or any everyday technology problem.

Free to ask. No credit card. No sales pressure. Fair usage applies.