PG Solutions/Resources/Microsoft 365 Security Checklist

MICROSOFT 365 SECURITY GUIDE

A practical Microsoft 365 security checklist.

Microsoft 365 security is not one switch or license. It is a connected operating system for identity, devices, email, collaboration, information, recovery, and employee behavior. This checklist helps small businesses organize the review.

1. Require strong identity controls

Require multifactor authentication for every user and use stronger, phishing-resistant methods where the environment and risk justify them. Review legacy authentication, unusual sign-ins, risky accounts, and exceptions that weaken the policy.

Conditional Access can apply different requirements based on user, role, device, application, location, and risk. Design policies carefully, preserve tested emergency access, and stage changes so the business is not locked out.

  • Confirm every active user is covered by MFA.
  • Review excluded accounts and document the business reason.
  • Protect emergency access accounts and monitor their use.

2. Separate and minimize administrative access

Do not use a highly privileged account for ordinary email and daily work. Assign the least privilege needed, use separate administrative identities when appropriate, and regularly review privileged roles.

Record who can administer Microsoft 365, domains, DNS, backup, security tools, and connected applications. Administrative ownership should survive employee turnover and vendor changes.

3. Harden email and payment-change procedures

Configure the available anti-phishing, impersonation, malicious-link, attachment, and spam protections for the selected Microsoft 365 plan. Review mailbox forwarding rules and alerts for suspicious behavior.

Technical controls cannot validate every business request. Establish a second-channel verification procedure for payment instructions, bank changes, payroll, gift cards, credential resets, and sensitive-data requests.

  • Publish SPF, DKIM, and DMARC deliberately and monitor the effect before enforcing a strict policy.
  • Use external-sender and impersonation signals without teaching employees to trust a banner alone.
  • Train employees to report suspicious messages through a known process.

4. Review collaboration and information sharing

Teams, SharePoint, and OneDrive make collaboration easier, but guest access, anonymous links, broad groups, and inherited permissions can expose information unintentionally. Review sharing defaults and the sites or teams that contain sensitive material.

Define how owners review guest users, inactive teams, shared links, and access to confidential data. Avoid using classification or retention labels unless the organization understands how they affect real workflows.

5. Connect device health to cloud access

A protected cloud account can still be used from an unsafe device. Decide which devices may access company information and what baseline is required: supported software, encryption, screen lock, endpoint protection, update status, and management.

Plan for lost or stolen equipment, departing employees, personal devices, and remote work. The response should cover both the device and the cloud sessions or tokens associated with it.

7. Define retention, backup, and recovery expectations

Retention, recycle bins, legal hold, and backup solve different problems. Define what the business must preserve, what users may delete, how long information should remain, and which recovery scenarios must be supported.

Test representative recovery for important mail, files, permissions, and collaboration data. Record the result, time required, dependencies, and any gaps between business expectations and the actual capability.

8. Prepare for incidents and recurring review

Document how to respond to a suspicious sign-in, compromised mailbox, malicious forwarding rule, stolen device, harmful application consent, or fraudulent payment request. Include containment, evidence, communication, password and session actions, vendor escalation, and follow-up.

Review security posture, risky events, administrators, guest access, applications, exceptions, licenses, and improvement priorities on a recurring schedule. Controls drift as the business and Microsoft 365 change.

Security settings are only effective when the organization can operate, review, and respond around them.

Turn the checklist into a practical IT plan.

PG Solutions helps Miami businesses prioritize support, security, Microsoft 365, resilience, and technology decisions around real operating needs.

Schedule an IT consultation