---
title: "Microsoft 365 Security Checklist | EFROS"
description: "A practical Microsoft 365 hardening checklist for small and mid-sized businesses — identity, Conditional Access, Defender, DLP, mailbox auditing, and cyber-insurance evidence."
canonical: https://efros.com/resources/microsoft-365-security-checklist/
---

- [Home](https://efros.com/)
- /[Resources](https://efros.com/resources/)
- /Microsoft 365 Security Checklist

Resource · Operational Checklist

# Microsoft 365 security checklist.

A practical CIS-aligned hardening checklist for small and mid-sized businesses running Microsoft 365. Use it as a self-audit, a vendor-onboarding scorecard, or evidence for a cyber-insurance renewal.

By [Stefan Efros](https://www.linkedin.com/in/stefanefros-cyberdefense/), CEO & Founder, EFROS

Updated · May 17, 2026

## 1. Identity baseline
- MFA enforced for every user (Authenticator app, not SMS where possible)
- Legacy authentication blocked (POP, IMAP, SMTP basic, EWS, MAPI)
- Global Administrator role limited to 2–4 named individuals with separate admin accounts
- Privileged Identity Management (PIM) enabled for admin roles where the license allows
- Conditional Access policy: block sign-in from outside the operating geography
- Conditional Access policy: require compliant device for admin roles
- Self-service password reset enabled with security questions disabled
- Identity Protection policies: user risk and sign-in risk enabled

## 2. Email security
- SPF record with hard-fail (-all) or strict soft-fail (~all) policy
- DKIM signing enabled on every active sending domain
- DMARC policy at quarantine or reject with aggregate reporting enabled
- MTA-STS policy file published and DNS records present
- TLS-RPT reporting endpoint configured
- Defender for Office 365: Safe Links, Safe Attachments, anti-phish policy enabled
- Impersonation protection on executive and finance mailboxes
- External mailbox forwarding blocked or alerted on creation
- Mailbox audit logging enabled with 365-day retention minimum
- Quarantine review process documented and assigned to an owner

## 3. Devices and endpoints
- Microsoft Intune (or equivalent MDM) enrolling every Windows, macOS, iOS, and Android device that touches Microsoft 365
- Device compliance policies: encryption required, screen lock enforced, jailbreak/root blocked
- Conditional Access tied to device compliance
- Microsoft Defender for Endpoint (or third-party EDR) deployed on every workstation and server
- Attack Surface Reduction rules enabled in block mode
- Local administrator accounts removed from standard user devices
- USB control policy in place (block or warn) for removable storage
- Patch management cadence documented (monthly minimum, weekly for security updates)

## 4. Data protection
- Data Loss Prevention (DLP) policies on email, SharePoint, OneDrive, and Teams
- Sensitivity labels deployed for Confidential and Restricted content
- Retention policies defined per regulatory scope (HIPAA, PCI, GDPR)
- External sharing scoped: anonymous sharing disabled, link expiry enforced
- OAuth app review: third-party apps with mailbox-read or files-read scopes reviewed quarterly
- Microsoft 365 backup with documented restore tests (Microsoft does not back up your data by default)

## 5. Monitoring and response
- Sign-in logs forwarded to SIEM or Sentinel with 90-day retention minimum
- Audit logs forwarded with 365-day retention minimum
- Defender XDR alerts triaged by named owner with documented response procedure
- Risky sign-in detection enabled with auto-remediation for high-risk events
- Session revocation tested as a documented runbook step
- Incident-response contact named, on-call rotation documented

## 6. Cyber-insurance evidence pack
- MFA enforcement screenshot or report
- EDR deployment report with coverage percentage
- Backup configuration and last successful restore-test evidence
- Patch management report (last 90 days)
- Phishing simulation results or security-awareness training completion log
- Incident response plan document with last review date
- Logging and monitoring configuration evidence

## FAQ.

### What Microsoft 365 license tier is required?

+ Business Premium covers most of this checklist. Microsoft 365 E3 + a Defender XDR / Sentinel add-on adds the full monitoring and response stack. The exact licensing depends on your size and compliance scope.

### How long does a typical hardening rollout take?

+ Foundations (MFA, Conditional Access, Defender, DMARC visibility) land in two to four weeks. Full baseline (DLP, retention, DMARC reject, EDR coverage, IR runbook) is 60 to 90 days for a 50-to-150-user environment.

### What if we already have most of this in place?

+ Most environments have 30 to 60% of the checklist done. The Cybersecurity Assessment surfaces what is missing, the underlying configuration drift, and the gaps your cyber-insurance carrier or auditor will flag.

[Review My Microsoft 365 Tenant →](https://efros.com/free-security-assessment/) [Microsoft 365 Security Service](https://efros.com/security/microsoft-365/)

Related work

[### Microsoft 365 Security The managed M365 tenant-hardening service the checklist plugs into.Open→](https://efros.com/security/microsoft-365/) [### DMARC Rollout Guide Email authentication hardening — the SPF/DKIM/DMARC piece of M365 security.Open→](https://efros.com/resources/dmarc-rollout-guide/) [### Zero Trust Architecture Conditional Access, identity, and device trust — the identity layer the checklist references.Open→](https://efros.com/security/zero-trust/) [### Endpoint Security Defender for Endpoint deployment, hardening, and 24/7 monitoring.Open→](https://efros.com/security/endpoint/) [### Backup & DR M365 tenant backup — because Microsoft does not back up your data by default.Open→](https://efros.com/security/backup-dr/) [### Free Security Scan Live posture check across SPF/DKIM/DMARC and visible identity gaps in 60 seconds.Open→](https://efros.com/tools/security-scan/)

## Cite this resource

Reference this resource with attribution under [CC-BY-4.0](https://creativecommons.org/licenses/by/4.0/). Copy any of the formats below for academic papers, blog posts, AI citations, or vendor evidence packages.

APA (7th edition)

```
Efros, S. (2026, May). Microsoft 365 Security Checklist. EFROS. https://efros.com/resources/microsoft-365-security-checklist/
```

MLA (9th edition)

```
Efros, Stefan. "Microsoft 365 Security Checklist." EFROS, May 2026, https://efros.com/resources/microsoft-365-security-checklist/.
```

Chicago (author-date)

```
Efros, Stefan. 2026. "Microsoft 365 Security Checklist." EFROS. https://efros.com/resources/microsoft-365-security-checklist/.
```

IEEE

```
S. Efros, "Microsoft 365 Security Checklist," EFROS, May 2026. [Online]. Available: https://efros.com/resources/microsoft-365-security-checklist/
```

BibTeX

```
@misc{efros2026microsoft365secu,
author = {Stefan Efros},
title = {Microsoft 365 Security Checklist},
year = {2026},
month = {May},
publisher = {EFROS},
url = {https://efros.com/resources/microsoft-365-security-checklist/},
note = {Accessed: May 2026}
}
```

Plain text URL

```
https://efros.com/resources/microsoft-365-security-checklist/
```

Site-wide citation metadata is also published as a CITATION.cff file at [/CITATION.cff](https://efros.com/CITATION.cff) for citation-management tools and academic indexers.

Related EFROS resources

## M365 security stack

[### EFROS M365 Security service Managed tenant hardening + monitoring + monthly tuning.Open→](https://efros.com/security/microsoft-365/) [### DMARC rollout Email auth piece of the M365 hardening.Open→](https://efros.com/resources/dmarc-rollout-guide/) [### MDR for M365 telemetry 24/7 SOC ingests M365 audit logs for detection.Open→](https://efros.com/security/mdr/) [### M365 for SOC 2 evidence Tenant configuration that produces SOC 2 evidence.Open→](https://efros.com/resources/soc-2-readiness-checklist/) [### M365 for cyber insurance Carrier-expected M365 control configuration.Open→](https://efros.com/resources/cyber-insurance-readiness-checklist/) [### Zero Trust + M365 Conditional Access M365 hardening within a broader Zero Trust architecture.Open→](https://efros.com/security/zero-trust/)
