Secure your workspace · Part 2 of 4 · 2 min read
Microsoft 365: ten checks for your admin.
A focused checklist for identity, email, app access, sharing, logs, and recovery in Microsoft 365.
Ten checks to complete with your administrator.
Use this with the administrator responsible for your Microsoft 365 tenant. The boxes are a session checklist, not a security score or a saved audit. Record evidence, exceptions, owners, and dates in your team's own tracker.
Confirm MFA coverage and the configured policy. Microsoft's security defaults provide a baseline; organizations using Conditional Access need to review their own policies rather than assume equivalent protection.
Review privileged assignments and use appropriately scoped administrative identities. Remove obsolete roles and accounts. Test how privileges are granted and revoked.
Maintain a documented, monitored recovery route. Microsoft recommends two or more emergency access accounts. Protect them with strong authentication and test access; do not casually exempt everyday accounts from controls.
List connected applications, permissions, and owners. Review how users request consent and remove unused access. Check delegated and application permissions.
Confirm SPF, DKIM, and DMARC for sending domains with the people who operate every legitimate sender. Stage enforcement and inspect reports to avoid disrupting valid mail.
Inspect SharePoint and OneDrive external sharing, anonymous links where permitted, guest access, and sensitive libraries. Set defaults that match actual collaboration needs.
Identify managed and unmanaged devices, patch ownership, encryption requirements, and the response to loss. Confirm the licensing and scope of any device-based access policy.
Check external forwarding, inbox rules, shared mailboxes, and delegated access. Investigate unfamiliar rules rather than deleting evidence during an incident.
Confirm which audit and sign-in events are available, their retention, alert routing, and the person who will investigate. Test an expected event and verify it appears.
Restore a test item and rehearse a departing employee's access removal and data handoff. Record which data depends on retention settings, licensing, or a separate backup.
Before changing a setting, verify its availability in your edition and test the effect on a small group. Document any exception and the person authorized to accept it.
Current configuration references: Microsoft security defaults · Emergency access guidance · CISA ScubaGear.
Edited September 29, 2026. Research and source dates are retained; this edit is not a fresh review of every statistic or legal development.
