Account and workload inventory
Map every active user, guest, break-glass account, workload identity, and high-impact application.
Assess and strengthen Microsoft 365 identity, admin access, email, collaboration, data protection, endpoints, monitoring, recovery, and remediation with practical technical guidance.
Microsoft 365 security control areas
Identity creates the access decision. Administrator privilege changes the tenant. Email and collaboration move data. Endpoint, security operations, recovery, and remediation determine whether the organization can prevent, detect, contain, and improve.
Tenant control baseline
Begin with the controls that most often reveal access, administrative, and email-security gaps. The full guide expands these prompts into evidence-led validation.
A checklist helps structure the review; it does not replace a professional cybersecurity audit, compliance assessment, penetration test, or legal/compliance review.
Access foundations
Map who and what can access the tenant, use modern authentication methods, and validate recovery paths before enforcing policy.
Map every active user, guest, break-glass account, workload identity, and high-impact application.
Confirm an authentication-method policy is current and legacy MFA/SSPR policy management is no longer relied upon.
Require strong MFA for privileged roles and test phishing-resistant methods for high-risk users.
Maintain at least two controlled emergency access accounts with separate credential storage and scheduled sign-in tests.
Target Conditional Access policies deliberately, capture report-only results, and document exclusions.
Block or control legacy authentication paths before treating modern sign-in controls as complete.
Administrative governance
Inventory sensitive rights, use time-bound elevation where available, and certify access on a documented cadence.
Inventory Global Administrators, role assignments, group-based assignments, delegated administration, and service principals.
Replace routine permanent high privilege with eligible, time-bound PIM assignments where licensing supports it.
Require activation justification, an approver, notification, and finite activation duration for sensitive roles.
Review role-assignable groups and administrative units for scope creep.
Schedule recurring reviews for tenant administrators, guests with elevated access, and application owners.
Preserve exported role assignments and completed review decisions as evidence.
Messaging resilience
Set a deliberate Defender baseline, reduce bypass paths, and validate domain authentication against actual mail flow.
Confirm the tenant has an intentional baseline: built-in, Standard, Strict, or documented custom Defender policies.
Review Safe Links coverage for email, supported Office apps, and Teams when licensing and workload scope support it.
Review Safe Attachments coverage, dynamic delivery behavior, and exclusions.
Protect impersonated users and domains, and validate anti-spoofing outcomes against real mail flow.
Inspect external forwarding controls, mail flow rules, and allow entries that could bypass protection.
Verify SPF, DKIM, and a tested progressive DMARC policy for each outbound domain and relevant subdomain.
Control review continuation
Use these prompts to examine how workload settings, data controls, endpoint health, operations, recovery, and change decisions combine into a defensible Microsoft 365 operating model.
Review area 01
Set clear boundaries for external sharing, guest participation, and the services that support team work.
Control 01
Review tenant and site-level external sharing settings; record the most permissive effective level.
Control 02
Locate anonymous links, broad anyone links, stale guests, and sites without accountable owners.
Control 03
Set a policy for guest invitation, shared channels, cross-tenant access, and guest lifecycle.
Control 04
Use sensitivity labels where appropriate to apply collaboration boundaries to Teams and sites.
Control 05
Review Teams app permissions, org-wide app settings, and high-privilege consent requests.
Control 06
Retain sharing and guest-change evidence that supports investigation and access review.
Review area 02
Validate how labels, loss prevention, retention, and evidence practices protect sensitive business information.
Control 07
Inventory sensitivity labels, publishing policies, label scope, encryption behavior, and exceptions.
Control 08
Run DLP changes in simulation or test mode, review matches and alerts, then approve enforcement deliberately.
Control 09
Verify DLP covers the intended Microsoft 365 locations rather than assuming a policy applies everywhere.
Control 10
Separate data-protection goals from retention, records management, eDiscovery, and backup objectives.
Control 11
Review retention labels, policies, disposition, legal hold readiness, and role separation.
Control 12
Capture sample policy alerts and test artifacts without retaining customer-sensitive data unnecessarily.
Review area 03
Confirm that device posture, endpoint security, and access decisions reinforce one another.
Control 13
Assess which Windows, macOS, mobile, and unmanaged devices can reach Microsoft 365 data.
Control 14
Connect Microsoft Defender for Endpoint to Intune only after confirming role and licensing prerequisites.
Control 15
Review device compliance criteria and the Conditional Access policies that depend on them.
Control 16
Validate disk encryption, firewall, antivirus, attack-surface reduction, and tamper-protection states.
Control 17
Confirm security baselines and configuration policies do not conflict with compliance policy expectations.
Control 18
Review device-risk handling, remediation ownership, and stale device records.
Review area 04
Establish accountable monitoring, useful audit evidence, and an investigation process that spans Microsoft 365 signals.
Control 19
Read Secure Score as prioritization guidance, not as proof that the tenant cannot be compromised.
Control 20
Define monitoring ownership for Defender incidents, alert queues, Purview Audit, and service health.
Control 21
Verify audit is enabled for the actual license type; do not assume small-business tenants have it active by default.
Control 22
Document expected audit retention, search permissions, export limits, and evidence custody requirements.
Control 23
Exercise incident triage across email, endpoint, identity, collaboration, and cloud app signals.
Control 24
Use advanced hunting only with permitted roles, a defined investigation question, and record handling discipline.
Review area 05
Make application permissions, consent decisions, and ongoing ownership reviewable and defensible.
Control 25
Inventory enterprise applications, service principals, OAuth grants, owners, permissions, and tenant-wide consent.
Control 26
Review high-privilege or broadly authorized OAuth applications before assuming delegated consent is low risk.
Control 27
Define an approval process for user consent, admin consent, publisher verification, and risky application investigation.
Control 28
Use App governance policies where available to alert on high permission scope, unusual authorization volume, or anomalous behavior.
Control 29
Remove or block applications that no longer have a business owner, valid purpose, or acceptable permission scope.
Control 30
Preserve consent, owner, permission, review, and removal decisions as part of the tenant evidence set.
Review area 06
Separate recovery capabilities, test real restoration paths, and protect the controls that support business continuity.
Control 31
Document native recovery, recycle-bin, retention, legal hold, backup, and archive behaviors separately.
Control 32
When Microsoft 365 Backup is used, verify policy coverage, restore-point creation, roles, and workload scope.
Control 33
Establish restore owners and test mailbox, SharePoint, OneDrive, and collaboration recovery scenarios.
Control 34
Record recovery-test timing, exceptions, data validation, and corrective actions rather than relying on policy screenshots.
Control 35
Protect recovery administration from ordinary user or help-desk compromise.
Control 36
Align resilience evidence with business-critical data, recovery priorities, and incident response decisions.
Review area 07
Turn risk findings into accountable, reversible, validated improvements with a usable evidence trail.
Control 37
Rate each finding by business impact, exposure, exploitability, evidence confidence, and control dependency.
Control 38
Assign an accountable owner, technical implementer, validation method, and target date to every accepted item.
Control 39
Use change windows and reversible test plans for Conditional Access, mail flow, DLP, sharing, and privileged access changes.
Control 40
Retest the intended policy outcome and the potential business-impact scenario before closure.
Control 41
Document exceptions, compensating controls, expiration dates, and executive risk acceptance.
Control 42
Refresh the tenant evidence set after material implementation, not only at the next annual review.
Ali Hassani, CISO
Ali Hassani is a CISO, cybersecurity and IT consultant, and IT infrastructure leader with 25+ years of experience. His certifications include CISSP, CCISO, CCNP, CCNA, MCSE, MCSA Security, MCITP, MCP, and MCTS.
Authoritative technical references
Features, roles, licensing, data locations, and supported behavior can vary. Confirm the tenant’s current configuration before changing production controls.
Frequently asked questions
It includes identity, privileged access, email, collaboration, information protection, endpoints, monitoring, recovery, and governance controls that work together in one tenant.
No. Secure Score helps prioritize improvements but Microsoft states that it is not an absolute measurement of breach likelihood.
When it needs independent evidence review, risk-rated findings, control validation, compliance readiness support, or a practical remediation plan.
This guidance is for initial planning and does not replace a professional cybersecurity audit, compliance assessment, penetration test, legal advice, or a review of your organization’s specific licensing and regulatory obligations.
Next step
OC Security Audit can review evidence, validate key controls, explain material risks in business terms, and help build a practical Microsoft 365 remediation plan.
This website uses essential cookies for security and operation. Optional analytics and advertising cookies help measure site use and outreach. Choose Allow or Deny. You can change your choice at any time.