A Microsoft 365 Security Checklist for Growing Businesses
The Microsoft 365 security settings growing businesses should review first: MFA, admin accounts, email authentication, sharing, devices and more.
By Benicio Hernandez · September 27, 2026 · 7 min read
Microsoft 365 has strong security capabilities, but many of them depend on how the tenant is configured. This checklist covers the areas we look at first. It isn't exhaustive, and the right settings depend on your licensing and how your company works.
Identity and sign-in
- Require MFA for every user, using Conditional Access or Security Defaults.
- Block legacy authentication protocols that can't enforce MFA.
- Prefer the Microsoft Authenticator app or phishing-resistant methods over SMS where practical.
- Enable self-service password reset with MFA-backed verification.
Administrative access
- Keep the number of Global Administrators small, and use less-privileged admin roles where possible.
- Use separate admin accounts that aren't used for everyday email and browsing.
- Maintain secured emergency-access (break-glass) accounts.
- Review admin role assignments regularly.
- Publish SPF, enable DKIM signing and publish a DMARC policy for your domains.
- Apply Microsoft Defender for Office 365 or Exchange Online Protection preset security policies.
- Disable or restrict automatic forwarding to external addresses.
Sharing and data
- Review SharePoint and OneDrive external sharing settings, and set sensible link defaults.
- Restrict users from granting third-party apps access to company data without admin approval.
- Confirm audit logging is on and you know how to search it.
- Decide on a backup approach for Microsoft 365 data that matches your needs.
Devices
- Enroll company devices in Intune with encryption, updates and security baselines.
- Define what personal devices can access, and apply app protection policies.
- Use device compliance in Conditional Access for sensitive apps.