Microsoft 365 Security Checklist for Small Businesses

PCC Resource Guide

Microsoft 365 Security Checklist for Small Businesses

Use this practical checklist to identify common Microsoft 365 security gaps and strengthen how your business protects accounts, email, devices, and company information.

Review the Checklist One Area at a Time

Microsoft 365 security is not controlled by one setting. Effective protection depends on how identities, administrator privileges, email, file sharing, devices, backups, monitoring, and employee behavior work together.

Important: Available controls vary by Microsoft 365 license. A setting being unavailable does not mean it is unnecessary. It may indicate that your licensing or security strategy requires review.
Download the Checklist
01

Make Stolen Passwords Less Useful

Most Microsoft 365 attacks begin with a compromised identity. These controls reduce the likelihood that a stolen password will give an attacker unrestricted access to email, files, and business systems.

Require multifactor authentication for every user

Do not limit MFA to executives or administrators. Every active account can provide an entry point into company information.

Use stronger authentication methods where possible

Microsoft Authenticator, passkeys, and security keys generally provide stronger protection than text-message verification. Prioritize phishing-resistant methods for sensitive roles.

Use Security Defaults or properly designed Conditional Access

Smaller environments may use Microsoft Security Defaults. Organizations with appropriate licensing can use Conditional Access for more granular requirements. Do not disable Security Defaults until replacement protections are ready.

Block outdated authentication methods

Legacy authentication can allow older applications to bypass modern sign-in protections. Confirm that it is blocked unless there is a documented and actively managed exception.

Review inactive, guest, and shared accounts

Remove unnecessary accounts and access promptly. Avoid shared user accounts because they weaken accountability and make suspicious activity harder to investigate.

Technical reference: Microsoft guidance for multifactor authentication

02

Separate Privileged Access From Everyday Work

Administrator accounts can change security controls, access sensitive systems, and create additional accounts. They require stronger protection than ordinary user accounts.

Give each administrator a separate administrative account

Administrators should use standard accounts for email, browsing, and everyday work. Privileged accounts should be reserved for administrative tasks.

Limit the number of Global Administrators

Assign the least-privileged role capable of completing the task. Global Administrator access should be tightly restricted and reviewed regularly.

Require strong MFA for every privileged account

Administrator accounts should use phishing-resistant authentication whenever available and should never rely on a password alone.

Review administrator roles on a defined schedule

Remove access that is no longer required after staffing, vendor, or responsibility changes. Do not allow temporary privileges to become permanent by default.

Maintain a documented emergency-access process

A carefully controlled emergency-access account can help prevent a complete lockout. Its credentials and activity should be protected, monitored, and tested by qualified administrators.

Technical reference: Microsoft 365 security best practices

03

Strengthen Protection Against Phishing and Impersonation

Microsoft 365 includes baseline email protections, but those defaults should not be treated as a complete defense. Email authentication, threat policies, impersonation protection, and employee reporting must work together.

Configure SPF, DKIM, and DMARC for every sending domain

These standards help receiving systems determine whether email using your domain is legitimate. Include third-party platforms that send invoices, marketing messages, alerts, or other email on your behalf.

Review Microsoft 365 anti-phishing and anti-spam policies

Confirm that threat policies reflect your organization’s risk. Businesses with Microsoft Defender for Office 365 should evaluate Microsoft’s Standard or Strict preset security policies.

Protect high-risk people and frequently impersonated domains

Executives, accounting employees, HR personnel, and anyone who approves payments are common impersonation targets. Configure available protection for these users and trusted domains.

Enable link and attachment protection when licensed

Microsoft Defender for Office 365 can inspect links and attachments for malicious content. Confirm that licensed users are included in the appropriate protection policies.

Control automatic forwarding to external addresses

Attackers frequently create forwarding rules after compromising a mailbox. Block unnecessary external forwarding and monitor approved exceptions.

Give employees a clear method for reporting suspicious email

Reporting must be easy and well understood. Define what employees should do, who reviews submissions, and how quickly potentially malicious messages are investigated.

Technical references: Microsoft email security recommendations and Microsoft email authentication guidance

04

Control How Company Information Is Shared

OneDrive, SharePoint, and Teams make collaboration easier, but convenient sharing can also create long-lived access that nobody remembers approving. Sharing settings should reflect the sensitivity of the information involved.

Define when external sharing is permitted

Establish clear rules for sharing with clients, vendors, and other outside parties. Employees should understand which information may never be shared externally.

Restrict anonymous “Anyone” links

Anonymous links can be forwarded without your knowledge. Disable them where they are unnecessary, or apply expiration dates and limited permissions when business needs require their use.

Separate sensitive information from externally shared content

Microsoft recommends storing confidential information in sites where external sharing is disabled. Use separate collaboration locations for content intended for outside parties.

Review site owners, Teams membership, and guest access

Assign accountable owners and periodically remove former employees, expired guests, abandoned teams, and permissions that are no longer required.

Use the least-permissive sharing option that meets the need

Prefer named recipients over unrestricted links. Use view-only access when editing is unnecessary, and avoid broad access granted for convenience.

Evaluate sensitivity labels and data-loss prevention

Organizations handling regulated or confidential information should evaluate Microsoft Purview controls when supported by their licensing and compliance requirements.

Technical reference: Microsoft guidance for SharePoint and OneDrive external sharing

05

Control What Can Connect to Company Data

Strong account security is incomplete if unmanaged computers, vulnerable applications, or excessively privileged third-party apps can access Microsoft 365 data.

Maintain an accurate inventory of devices

Know which company-owned and personal devices access Microsoft 365. Remove obsolete device registrations and define who is responsible for approving new devices.

Keep operating systems and applications patched

Establish a managed update process for Windows, browsers, Microsoft 365 applications, and other software used to access business information.

Require encryption, screen locks, and endpoint protection

Devices should use full-disk encryption, automatic screen locking, supported security software, and centrally monitored endpoint protection.

Evaluate device compliance and Conditional Access

Organizations with appropriate licensing can use Microsoft Intune and Conditional Access to evaluate device health and restrict access from devices that do not meet company policy.

Define security requirements for personal devices

If employees access company data from personal devices, establish clear rules for supported applications, local storage, remote removal of company information, and reporting lost devices.

Review third-party applications connected to Microsoft 365

OAuth applications can retain access without repeatedly using a password. Review requested permissions, restrict user consent where appropriate, and remove unnecessary or untrusted apps.

Technical references: Microsoft Intune device compliance and application-consent controls

06

Prepare to Restore More Than Recently Deleted Files

Microsoft operates a resilient cloud platform, but service resilience, retention, recycle bins, and backup serve different purposes. Your organization still needs a recovery strategy for accidental deletion, malicious activity, corruption, and ransomware.

Document which Microsoft 365 data requires backup

Identify the Exchange mailboxes, OneDrive accounts, SharePoint sites, Teams-connected content, and other business information that must be recoverable.

Select a backup solution that meets business requirements

Evaluate Microsoft 365 Backup or a qualified third-party backup service based on coverage, retention, recovery speed, administration, security, and cost.

Do not treat retention policies as a complete backup strategy

Retention supports preservation and compliance, while backup is designed for recoverability. Define both independently and understand what each control can restore.

Protect backup administration and recovery access

Restrict who can change backup policies, delete protected data, or initiate restores. Require strong authentication and monitor privileged activity.

Monitor backup status and coverage

Review failed jobs, newly created accounts, departed users, unprotected sites, licensing changes, and storage or billing issues that could interrupt protection.

Test recovery before an emergency

Perform documented restoration tests for email, files, and SharePoint content. Confirm that recovery time and retained history meet actual business needs.

Key distinction: Microsoft 365 platform resiliency helps keep the service available. Backup helps return business data to an earlier healthy state after deletion, corruption, or malicious activity.

Technical reference: Microsoft 365 Backup overview

07

Detect Problems and Prepare People to Respond

Security controls cannot prevent every incident. Businesses also need visibility into suspicious activity, defined response procedures, and employees who understand how to recognize and report potential threats.

Monitor risky sign-ins and unusual account activity

Review alerts involving unfamiliar locations, repeated failed sign-ins, impossible travel, new authentication methods, and unexpected changes to user accounts.

Monitor administrator and mailbox changes

Investigate unexpected role assignments, forwarding rules, inbox rules, application permissions, security-policy changes, and newly created accounts.

Review Microsoft Secure Score without treating it as the goal

Secure Score can help identify improvement opportunities, but a higher score does not automatically mean the environment is secure. Evaluate recommendations against licensing, operations, risk, and business requirements.

Document how Microsoft 365 incidents will be handled

Define who investigates alerts, disables compromised accounts, revokes sessions, resets authentication methods, reviews mailbox rules, communicates with affected parties, and preserves evidence.

Provide recurring security-awareness training

Training should cover phishing, MFA fatigue, fraudulent payment requests, suspicious sharing invitations, password reuse, and how to report a possible incident.

Use phishing simulations to measure behavior

Simulations help identify where additional coaching is needed. Measure reporting behavior and improvement over time instead of focusing only on who clicked.

Maintain a reliable onboarding and offboarding process

Grant access according to job responsibilities and remove it promptly when someone leaves or changes roles. Include accounts, devices, groups, shared mailboxes, files, and third-party apps.

Technical reference: Microsoft Zero Trust guidance for small businesses

Turn the Checklist Into an Action Plan

Mark each item as complete, needs review, or not currently available. Then prioritize gaps that could expose administrator accounts, financial workflows, confidential information, or recovery capabilities.

1

Address immediate exposure

Begin with missing MFA, excessive administrator access, unprotected email, and unknown external sharing.

2

Assign responsibility and deadlines

Every improvement should have an owner, target date, and documented verification step.

3

Review the checklist regularly

Revisit the environment after major staffing, licensing, application, compliance, or business-process changes.

Microsoft 365 Security FAQ

Is Microsoft 365 secure without additional configuration?

Microsoft provides substantial built-in security, but protection still depends on licensing, configuration, administration, user behavior, monitoring, and recovery planning. Default settings should be reviewed against your organization’s risks.

Is multifactor authentication enough?

No. MFA is essential, but businesses also need protected administrator accounts, secure email policies, controlled sharing, managed devices, monitoring, backups, and employee training.

Which Microsoft 365 plan offers stronger business security?

Microsoft 365 Business Premium includes additional identity, device-management, endpoint-security, and email-protection capabilities. However, licensing should be evaluated against the organization’s users, devices, compliance requirements, and existing security services.

Does Microsoft automatically back up Microsoft 365 data?

Microsoft provides platform resiliency, retention features, and recovery tools, but these are not interchangeable with a defined backup strategy. Microsoft 365 Backup is a separate service, and qualified third-party backup solutions are also available.

How often should this checklist be reviewed?

Conduct a complete review at least annually and after major staffing, licensing, application, compliance, or business-process changes. Higher-risk controls should be monitored much more frequently.

Can a small business complete this review internally?

Some baseline checks are straightforward. Conditional Access, administrator roles, email authentication, application consent, backup design, and incident response can have significant consequences if configured incorrectly. Use qualified assistance where internal expertise is limited.

Strengthen Your Microsoft 365 Environment

Professional Computer Concepts helps Bay Area businesses review, secure, monitor, and support Microsoft 365. We can help identify gaps, prioritize improvements, and implement protections that fit your organization.