Simplify. Strategize. Secure.

Resource · Microsoft 365 security

Check the tenant, not just the license name.

Microsoft 365 security depends on configuration, assigned responsibility, user behavior, devices, and ongoing review. Use this checklist to find the controls that exist only on paper.

01Identity and ownership

Start with the accounts that control everything else.

Confirm each item in the tenant and record who owns it. Do not treat a purchased license as proof that a control is configured.

  • 01

    Tenant and domain ownershipThe organization controls registrar, DNS, tenant billing, and recovery details rather than depending on one employee or vendor account.

  • 02

    Multifactor authenticationMFA is required through security defaults or a documented Conditional Access design, with exceptions explicitly reviewed.

  • 03

    Administrator separationNamed admin accounts are protected, privileged roles are limited, and shared administrator credentials are not normal practice.

  • 04

    Joiner, mover, and leaver processAccount creation, access changes, offboarding, session revocation, mailbox/data handling, and device return have accountable owners.

  • 05

    Legacy access reviewOlder authentication paths and protocols are blocked unless a recorded business dependency requires a controlled exception.

  • 06

    Sign-in reviewSomeone reviews risky or anomalous access signals available in the organization’s licensing and records the response.

Microsoft states that security defaults provide a baseline available to Microsoft 365 organizations; Conditional Access requires eligible licensing and must be designed before replacing that baseline.

02Data, devices, and collaboration

Trace how information leaves the tenant.

The right settings depend on licensing, operational needs, contractual duties, and risk. These questions reveal where a deliberate decision is missing.

  • Which devices may access work data, and what makes a device acceptable?

    Check update status, screen lock, disk protection, endpoint security, lost-device response, and personal-device boundaries.

  • Who can create external sharing links, guest access, forwarding rules, and third-party app connections?

    Convenient collaboration paths need ownership, sensible defaults, expiration or review where appropriate, and a removal process.

  • Which email protections are configured, monitored, and tested?

    Review domain authentication, malicious-content controls, impersonation risk, reported-message handling, and the response path available under current licenses.

  • What activity is logged, how long is it available, and who reviews it?

    Logging is useful only when the required event exists, remains available long enough, and leads to an assigned response.

  • How are SharePoint, OneDrive, Teams, and mailbox data recovered from deletion or corruption?

    Document native retention behavior, any separate backup scope, restore ownership, and the test used to confirm the answer.

03Decision boundary

Keep three different claims separate.

Product availability, configuration, and verified operation are three different states.

Included in a plan

The Microsoft product or feature is available under the organization’s current subscription and prerequisites.

Configured for this tenant

A named owner has applied a reviewed policy that fits the organization’s people, devices, workflows, and exceptions.

Verified in operation

Reports, sign-in evidence, alerts, test results, or sampled configurations show that the intended control is working and being reviewed.

04Primary guidance

Review Microsoft’s current baseline before changing it.

Microsoft recommends MFA and protection for privileged administrator accounts. Its MFA setup guidance also warns against turning off security defaults unless equivalent baseline policies are being established through Conditional Access.

Read Microsoft 365 security best practices

Minimum review record

Date, reviewer, tenant, current licensing, configured baseline, exceptions, evidence inspected, unresolved risks, assigned owner, and next review trigger.

Re-run the review after licensing, identity architecture, a merger, a significant incident, or a material workflow change.

05Review the tenant

Turn the checklist into a prioritized configuration plan.

ICT Solutions can assess the current tenant, identify gaps, plan changes, and define ongoing Microsoft 365 administration. Recommendations depend on the environment, licensing, and agreed scope.

Or call (734) 772-9499 · A human answers