Microsoft 365 security checklist
Most business email compromise we are called into involves a Microsoft 365 tenant left on its default settings. The twelve items below close the gaps that attackers rely on. None of them need extra software; they are settings you already pay for.
1. Multi-factor authentication for every account
Why it matters: Password spraying against Microsoft 365 is constant and automated.
How to verify: Filter users by sign-in method and confirm no account, including admins, is exempt.
2. Block legacy authentication
Why it matters: Older protocols like IMAP and POP bypass MFA entirely.
How to verify: Check sign-in logs for legacy client app entries, then block them by policy.
3. Separate, unlicensed admin accounts
Why it matters: Daily email on a Global Admin account turns one phishing click into full tenant control.
How to verify: Count Global Admins. Under five, each with no mailbox in daily use, is the target.
4. Disable mailbox auto-forwarding to external addresses
Why it matters: Attackers quietly forward invoices out of a compromised mailbox for weeks.
How to verify: Run a report of forwarding rules and external forwarding across all mailboxes.
5. External sender warnings
Why it matters: Staff approve payment changes because a display name looked internal.
How to verify: Send a test from an outside address and confirm the banner appears.
6. Anti-phishing and impersonation protection
Why it matters: Directors and finance staff are impersonated by name, not by domain.
How to verify: Add your executives and your own domain to the protected list in the anti-phishing policy.
7. Safe Links and Safe Attachments
Why it matters: Malicious links are often weaponised after the email is delivered.
How to verify: Confirm policies apply to all users, including shared and resource mailboxes.
8. SPF, DKIM and DMARC on your domain
Why it matters: Without these, anyone can send email that appears to come from your company.
How to verify: Check DKIM is enabled per domain and DMARC is at least at quarantine, not none.
9. Audit logging turned on and retained
Why it matters: After an incident you need to know what was accessed and when.
How to verify: Confirm unified audit log is on and search a mailbox action from last month.
10. Conditional access on location and device
Why it matters: Sign-ins from unexpected countries are the earliest usable warning sign.
How to verify: Review the last 30 days of sign-ins for countries you do not operate in.
11. Restrict who can consent to third-party apps
Why it matters: A single OAuth consent can grant a rogue app permanent mailbox access.
How to verify: Set user consent to admin approval and review existing enterprise applications.
12. A backup of Microsoft 365 data
Why it matters: Microsoft protects the platform, not your data from deletion or ransomware.
How to verify: Restore one deleted item from more than 90 days ago. If you cannot, you have no backup.
Want us to run this on your tenant?
We review all twelve settings and send you a written list of what is exposed and the order to fix it in. Onsite in Durban and KwaZulu-Natal, remote anywhere.
Next: Ransomware protection for South African businesses or the POPIA security readiness checklist.