PCC Resource Guide
Microsoft 365 Security Checklist for Small Businesses
Use this practical checklist to identify common Microsoft 365 security gaps and strengthen how your business protects accounts, email, devices, and company information.
How to Use This Resource
Review the Checklist One Area at a Time
Microsoft 365 security is not controlled by one setting. Effective protection depends on how identities, administrator privileges, email, file sharing, devices, backups, monitoring, and employee behavior work together.
Identity and Sign-In Protection
Make Stolen Passwords Less Useful
Most Microsoft 365 attacks begin with a compromised identity. These controls reduce the likelihood that a stolen password will give an attacker unrestricted access to email, files, and business systems.
Require multifactor authentication for every user
Do not limit MFA to executives or administrators. Every active account can provide an entry point into company information.
Use stronger authentication methods where possible
Microsoft Authenticator, passkeys, and security keys generally provide stronger protection than text-message verification. Prioritize phishing-resistant methods for sensitive roles.
Use Security Defaults or properly designed Conditional Access
Smaller environments may use Microsoft Security Defaults. Organizations with appropriate licensing can use Conditional Access for more granular requirements. Do not disable Security Defaults until replacement protections are ready.
Block outdated authentication methods
Legacy authentication can allow older applications to bypass modern sign-in protections. Confirm that it is blocked unless there is a documented and actively managed exception.
Review inactive, guest, and shared accounts
Remove unnecessary accounts and access promptly. Avoid shared user accounts because they weaken accountability and make suspicious activity harder to investigate.
Technical reference: Microsoft guidance for multifactor authentication
Administrator Protection
Separate Privileged Access From Everyday Work
Administrator accounts can change security controls, access sensitive systems, and create additional accounts. They require stronger protection than ordinary user accounts.
Give each administrator a separate administrative account
Administrators should use standard accounts for email, browsing, and everyday work. Privileged accounts should be reserved for administrative tasks.
Limit the number of Global Administrators
Assign the least-privileged role capable of completing the task. Global Administrator access should be tightly restricted and reviewed regularly.
Require strong MFA for every privileged account
Administrator accounts should use phishing-resistant authentication whenever available and should never rely on a password alone.
Review administrator roles on a defined schedule
Remove access that is no longer required after staffing, vendor, or responsibility changes. Do not allow temporary privileges to become permanent by default.
Maintain a documented emergency-access process
A carefully controlled emergency-access account can help prevent a complete lockout. Its credentials and activity should be protected, monitored, and tested by qualified administrators.
Technical reference: Microsoft 365 security best practices
Email Security
Strengthen Protection Against Phishing and Impersonation
Microsoft 365 includes baseline email protections, but those defaults should not be treated as a complete defense. Email authentication, threat policies, impersonation protection, and employee reporting must work together.
Configure SPF, DKIM, and DMARC for every sending domain
These standards help receiving systems determine whether email using your domain is legitimate. Include third-party platforms that send invoices, marketing messages, alerts, or other email on your behalf.
Review Microsoft 365 anti-phishing and anti-spam policies
Confirm that threat policies reflect your organization’s risk. Businesses with Microsoft Defender for Office 365 should evaluate Microsoft’s Standard or Strict preset security policies.
Protect high-risk people and frequently impersonated domains
Executives, accounting employees, HR personnel, and anyone who approves payments are common impersonation targets. Configure available protection for these users and trusted domains.
Enable link and attachment protection when licensed
Microsoft Defender for Office 365 can inspect links and attachments for malicious content. Confirm that licensed users are included in the appropriate protection policies.
Control automatic forwarding to external addresses
Attackers frequently create forwarding rules after compromising a mailbox. Block unnecessary external forwarding and monitor approved exceptions.
Give employees a clear method for reporting suspicious email
Reporting must be easy and well understood. Define what employees should do, who reviews submissions, and how quickly potentially malicious messages are investigated.
Technical references: Microsoft email security recommendations and Microsoft email authentication guidance
Files and Permissions
Control How Company Information Is Shared
OneDrive, SharePoint, and Teams make collaboration easier, but convenient sharing can also create long-lived access that nobody remembers approving. Sharing settings should reflect the sensitivity of the information involved.
Define when external sharing is permitted
Establish clear rules for sharing with clients, vendors, and other outside parties. Employees should understand which information may never be shared externally.
Restrict anonymous “Anyone” links
Anonymous links can be forwarded without your knowledge. Disable them where they are unnecessary, or apply expiration dates and limited permissions when business needs require their use.
Separate sensitive information from externally shared content
Microsoft recommends storing confidential information in sites where external sharing is disabled. Use separate collaboration locations for content intended for outside parties.
Review site owners, Teams membership, and guest access
Assign accountable owners and periodically remove former employees, expired guests, abandoned teams, and permissions that are no longer required.
Use the least-permissive sharing option that meets the need
Prefer named recipients over unrestricted links. Use view-only access when editing is unnecessary, and avoid broad access granted for convenience.
Evaluate sensitivity labels and data-loss prevention
Organizations handling regulated or confidential information should evaluate Microsoft Purview controls when supported by their licensing and compliance requirements.
Technical reference: Microsoft guidance for SharePoint and OneDrive external sharing
Devices and Applications
Control What Can Connect to Company Data
Strong account security is incomplete if unmanaged computers, vulnerable applications, or excessively privileged third-party apps can access Microsoft 365 data.
Maintain an accurate inventory of devices
Know which company-owned and personal devices access Microsoft 365. Remove obsolete device registrations and define who is responsible for approving new devices.
Keep operating systems and applications patched
Establish a managed update process for Windows, browsers, Microsoft 365 applications, and other software used to access business information.
Require encryption, screen locks, and endpoint protection
Devices should use full-disk encryption, automatic screen locking, supported security software, and centrally monitored endpoint protection.
Evaluate device compliance and Conditional Access
Organizations with appropriate licensing can use Microsoft Intune and Conditional Access to evaluate device health and restrict access from devices that do not meet company policy.
Define security requirements for personal devices
If employees access company data from personal devices, establish clear rules for supported applications, local storage, remote removal of company information, and reporting lost devices.
Review third-party applications connected to Microsoft 365
OAuth applications can retain access without repeatedly using a password. Review requested permissions, restrict user consent where appropriate, and remove unnecessary or untrusted apps.
Technical references: Microsoft Intune device compliance and application-consent controls
Backup and Recovery
Prepare to Restore More Than Recently Deleted Files
Microsoft operates a resilient cloud platform, but service resilience, retention, recycle bins, and backup serve different purposes. Your organization still needs a recovery strategy for accidental deletion, malicious activity, corruption, and ransomware.
Document which Microsoft 365 data requires backup
Identify the Exchange mailboxes, OneDrive accounts, SharePoint sites, Teams-connected content, and other business information that must be recoverable.
Select a backup solution that meets business requirements
Evaluate Microsoft 365 Backup or a qualified third-party backup service based on coverage, retention, recovery speed, administration, security, and cost.
Do not treat retention policies as a complete backup strategy
Retention supports preservation and compliance, while backup is designed for recoverability. Define both independently and understand what each control can restore.
Protect backup administration and recovery access
Restrict who can change backup policies, delete protected data, or initiate restores. Require strong authentication and monitor privileged activity.
Monitor backup status and coverage
Review failed jobs, newly created accounts, departed users, unprotected sites, licensing changes, and storage or billing issues that could interrupt protection.
Test recovery before an emergency
Perform documented restoration tests for email, files, and SharePoint content. Confirm that recovery time and retained history meet actual business needs.
Technical reference: Microsoft 365 Backup overview
Monitoring and Training
Detect Problems and Prepare People to Respond
Security controls cannot prevent every incident. Businesses also need visibility into suspicious activity, defined response procedures, and employees who understand how to recognize and report potential threats.
Monitor risky sign-ins and unusual account activity
Review alerts involving unfamiliar locations, repeated failed sign-ins, impossible travel, new authentication methods, and unexpected changes to user accounts.
Monitor administrator and mailbox changes
Investigate unexpected role assignments, forwarding rules, inbox rules, application permissions, security-policy changes, and newly created accounts.
Review Microsoft Secure Score without treating it as the goal
Secure Score can help identify improvement opportunities, but a higher score does not automatically mean the environment is secure. Evaluate recommendations against licensing, operations, risk, and business requirements.
Document how Microsoft 365 incidents will be handled
Define who investigates alerts, disables compromised accounts, revokes sessions, resets authentication methods, reviews mailbox rules, communicates with affected parties, and preserves evidence.
Provide recurring security-awareness training
Training should cover phishing, MFA fatigue, fraudulent payment requests, suspicious sharing invitations, password reuse, and how to report a possible incident.
Use phishing simulations to measure behavior
Simulations help identify where additional coaching is needed. Measure reporting behavior and improvement over time instead of focusing only on who clicked.
Maintain a reliable onboarding and offboarding process
Grant access according to job responsibilities and remove it promptly when someone leaves or changes roles. Include accounts, devices, groups, shared mailboxes, files, and third-party apps.
Technical reference: Microsoft Zero Trust guidance for small businesses
Common Questions
Microsoft 365 Security FAQ
Is Microsoft 365 secure without additional configuration?
Microsoft provides substantial built-in security, but protection still depends on licensing, configuration, administration, user behavior, monitoring, and recovery planning. Default settings should be reviewed against your organization’s risks.
Is multifactor authentication enough?
No. MFA is essential, but businesses also need protected administrator accounts, secure email policies, controlled sharing, managed devices, monitoring, backups, and employee training.
Which Microsoft 365 plan offers stronger business security?
Microsoft 365 Business Premium includes additional identity, device-management, endpoint-security, and email-protection capabilities. However, licensing should be evaluated against the organization’s users, devices, compliance requirements, and existing security services.
Does Microsoft automatically back up Microsoft 365 data?
Microsoft provides platform resiliency, retention features, and recovery tools, but these are not interchangeable with a defined backup strategy. Microsoft 365 Backup is a separate service, and qualified third-party backup solutions are also available.
How often should this checklist be reviewed?
Conduct a complete review at least annually and after major staffing, licensing, application, compliance, or business-process changes. Higher-risk controls should be monitored much more frequently.
Can a small business complete this review internally?
Some baseline checks are straightforward. Conditional Access, administrator roles, email authentication, application consent, backup design, and incident response can have significant consequences if configured incorrectly. Use qualified assistance where internal expertise is limited.
Need Help With the Findings?
Strengthen Your Microsoft 365 Environment
Professional Computer Concepts helps Bay Area businesses review, secure, monitor, and support Microsoft 365. We can help identify gaps, prioritize improvements, and implement protections that fit your organization.
