A default Microsoft 365 tenant is not secure out of the box – MFA is often off, admin accounts are exposed, external sharing is wide open, and there is no backup. This checklist is the baseline every small-business tenant should meet.
Identity
- MFA on every account, including admins and shared mailboxes (see MFA explained)
- Conditional access – block legacy authentication, restrict risky sign-ins
- Separate, dedicated admin accounts – never day-to-day accounts with admin rights
- Self-service password reset with strong verification
- Anti-phishing and safe links/attachments (Defender for Office 365)
- SPF, DKIM and DMARC configured, DMARC set to reject (see email security best practices)
- Block auto-forwarding to external addresses
- Alert on suspicious mailbox rules
Data and sharing
- Default external sharing set to a sensible level, not ‘anyone with the link’
- Sensitivity labels for confidential content
- Basic data loss prevention rules for financial or personal data
Devices and monitoring
- Intune device policies – encryption, screen lock, remote wipe
- Defender for Business on every endpoint
- Review the Secure Score monthly and act on the top items
Backup
A third-party backup of the whole tenant – Microsoft does not do this for you.
Need help with Microsoft 365? See our cybersecurity service or talk to our Edmonton team.
Microsoft 365 guides
- Microsoft 365 vs Google Workspace
- Microsoft 365 licensing explained
- What you get with Business Premium
- OneDrive vs SharePoint vs Teams files
- Microsoft 365 security checklist
- Is Microsoft 365 backed up?
- Migrating email to Microsoft 365
Frequently asked questions
Is Microsoft 365 secure by default?
No. The platform is capable, but the default settings leave MFA off, sharing open and admin accounts exposed. It needs configuring.
What is Microsoft Secure Score?
A score Microsoft calculates for your tenant based on which security controls you have enabled, with recommended actions. A useful, prioritised to-do list.
What is the single most important Microsoft 365 security step?
MFA on every account. It blocks the large majority of account-takeover attacks, which are the most common threat to a 365 tenant.
How does Scandifix help?
We work through the full checklist, enable and tune each control, set up backup, and monitor Secure Score and alerts on an ongoing basis.