Small-business team reviewing Microsoft 365 account, email and device security with an IT specialist

Microsoft 365 Security Checklist for Small Businesses

Use this Microsoft 365 security checklist to protect small-business accounts, administrators, devices, email, sharing, data, recovery and ongoing monitoring.

A secure Microsoft 365 setup for a small business starts with identity: require strong sign-in protection, separate everyday and administrator accounts, remove access promptly when somebody leaves, and keep a tested recovery route. Then work outwards through devices, email, sharing, data protection, monitoring and incident response. The checklist below gives each control an owner and a result you can verify.

Reviewed: 9 September 2026

Microsoft 365 security checklist at a glance

Priority Check Useful evidence
Now Protect every user and administrator with MFA or a passkey Registration and sign-in reports
Now Separate administrator accounts and reduce privileged roles Role assignment export
Now Confirm recovery and emergency access Dated recovery test
This week Secure devices, email and external sharing Policy screenshots or exports
This month Review logs, alerts, Secure Score and data handling Named actions with owners and dates
Ongoing Run joiner, mover and leaver checks Completed checklist for each change

This is a practical baseline, not a guarantee that an organisation is secure or compliant. Microsoft 365 features vary by licence, tenant configuration and region. Confirm what your subscription includes before designing controls around it.

1. Record who owns the tenant and its critical dependencies

Before changing a policy, identify the people and services that keep the tenant reachable. Record the tenant’s primary domain, billing owner, licence partner, DNS host, support contact and the people authorised to approve access changes. Confirm that the business—not only an employee or supplier—can reach those accounts.

  • List every accepted email domain and who controls its DNS.
  • Record the current Microsoft 365 licences and renewal route.
  • Name an internal decision-maker and a technical administrator.
  • Document any identity synchronisation, third-party backup, mail gateway and device-management service.
  • Keep support agreements and recovery details where authorised people can reach them during an outage.

A password known by several people is not a resilient ownership model. Give each person their own account and keep auditable emergency access for the situations normal administration cannot cover.

2. Require strong sign-in protection for every user

Turn on multifactor authentication (MFA) across the tenant and complete registration rather than assuming a policy alone has protected everyone. Microsoft’s current security guidance for Microsoft 365 business customers recommends security defaults for many organisations and Conditional Access where more detailed requirements are needed.

Choose one coherent enforcement route. Security defaults provides a broad baseline; Conditional Access supports more precise rules but depends on suitable licensing and careful rollout. Use report-only or a controlled pilot where available, check service accounts and legacy applications, and keep an exclusion path for emergency access before enforcing a policy tenant-wide.

  • Prefer passkeys, FIDO2 security keys or other phishing-resistant methods for high-value accounts where practical.
  • Do not rely on SMS as the only recovery route for privileged accounts.
  • Enable users to report unexpected authentication prompts and explain who they should contact.
  • Check sign-in logs for accounts still using older authentication methods.
  • Review guest and service accounts as well as employees.

The NCSC’s small-organisation account guidance also recommends strong, unique sign-in credentials and 2-step verification for important services.

3. Separate daily work from administration

An administrator should not read normal email or browse the web from the same account used to change tenant-wide settings. Create a separate named administrator account for each authorised person, protect it with strong authentication and assign only the roles needed for the work.

  • Review Global Administrator, Exchange, SharePoint, Teams, Security and Billing roles.
  • Remove privileges that are unused, duplicated or no longer justified.
  • Avoid shared administrator identities; named accounts make investigation and handover clearer.
  • Alert on privileged-role changes and unexpected administrator sign-ins.
  • Review delegated partner access and remove relationships that are no longer required.

Microsoft recommends maintaining at least two cloud-only emergency access accounts for resilience, using authentication that does not share the same dependency as normal admin access, monitoring every use and testing them regularly. Follow the live Microsoft emergency access guidance; a badly designed exception can either become an easy route in or fail when it is needed.

4. Remove legacy access and risky exceptions

Older mail clients and protocols may not support modern authentication. They can also undermine an MFA rollout. Identify them before blocking access, replace or reconfigure legitimate dependencies, and document any temporary exception with an owner and expiry date.

Review inbox forwarding, mail-flow rules, connectors, application passwords, OAuth application consent and broad allow lists. Microsoft warns that IP allow-list entries can bypass parts of spam filtering and sender authentication, so keep exceptions narrow and review them rather than using a whole provider range as a permanent fix.

5. Bring every work device under a minimum standard

Microsoft 365 account security is weakened if an unmanaged laptop keeps an active session after it is lost or runs unsupported software. Decide which devices may access business data and what each device must prove.

  • Maintain an inventory with owner, operating system, encryption and support status.
  • Require supported software, automatic security updates, screen locking and storage encryption.
  • Use endpoint protection and monitor whether it is active and healthy.
  • Define rules for personally owned devices, local downloads and removable media.
  • Provide a route to isolate, wipe or revoke a lost device.

Microsoft 365 Business Premium includes additional device-management and security capabilities, but they still need to be configured and monitored. If a lower licence does not provide the control you need, use an appropriate third-party service or change the licence—do not simply write the requirement into a policy that the technology cannot enforce.

6. Authenticate every service that sends email

Configure SPF, DKIM and DMARC for the domain shown in the From address. Microsoft’s email authentication guidance explains why the three mechanisms work together: SPF identifies permitted sending infrastructure, DKIM signs messages, and DMARC evaluates alignment with the visible sender domain.

  1. Inventory Microsoft 365 and every website, CRM, finance, marketing, support and alerting platform that sends as your domain.
  2. Keep one valid SPF record and remain within SPF’s lookup limits.
  3. Enable DKIM for each sending route and confirm real messages pass with the expected signing domain.
  4. Start DMARC with reporting, review representative traffic, then move towards enforcement in controlled stages.

Use ACA’s SPF checker, DKIM inspector and DMARC checker to inspect public records. A record being present does not prove every legitimate message is aligned, so verify actual message headers and DMARC reports before requesting rejection.

7. Tighten anti-phishing and mailbox rules

Review the protection available in the selected licence and apply Microsoft’s recommended preset security policies where they fit. Pay particular attention to impersonation, malicious links and attachments, user-reported messages and the handling of high-confidence phishing.

Do not solve recurring false positives by broadly trusting a sender or disabling protection. Investigate the sending route, authentication and message pattern, then use the narrowest supported remediation. Regularly search for unexpected forwarding rules, inbox rules and newly granted mailbox permissions; attackers often use these to retain access or hide replies after an account compromise.

8. Control Teams, SharePoint, OneDrive and guest access

Decide how staff may share information outside the business. The answer should reflect the information, the recipient and the working relationship rather than one unrestricted tenant-wide setting.

  • Review anonymous links and set sensible default link types and expiry periods.
  • Use named guests for continuing collaboration where accountability matters.
  • Assign an owner to each Team, Microsoft 365 Group and important SharePoint site.
  • Remove stale guests and access to completed projects.
  • Check whether users can create new groups, teams and public sharing links without review.

Information protection, sensitivity labels and data loss prevention can help where the licence and business requirement justify them. These features support a data-handling policy; they do not create one or establish legal compliance by themselves.

9. Decide what must be retained, restored and backed up

Retention, recycle bins, version history and backup solve different problems. Document which Microsoft 365 data the business cannot operate without, how long it must be retained, how quickly it needs to be restored and which recovery scenarios the chosen service covers.

Test recovery for a deleted file, mailbox item, user and shared workspace. If a third-party backup is used, monitor job results, restrict backup-administrator access and test restores rather than treating a successful job notification as proof of recoverability.

The NCSC advises small organisations using online services to identify and back up critical data, protect administrator accounts, create separate user accounts and use the security features built into the service. Its using online services safely collection provides an independent starting point.

10. Turn on useful logging, alerts and review

Logs matter only if the right people can reach them and know what to investigate. Confirm audit logging and retention for the licences in use, record who reviews alerts and decide how evidence will be preserved during an incident. Microsoft’s published audit-retention periods vary by licence and workload, so check the current audit retention documentation rather than relying on an old assumption.

Use Microsoft Secure Score as a prioritisation aid, not a certificate. Review recommended actions, understand their operational effect, implement the ones that fit, and document why a recommendation is deferred or handled another way. A higher score can show progress, but it does not measure every risk or prove that controls work in practice.

11. Make joiners, movers and leavers repeatable

Access changes should follow an authorised request and a checklist. For a leaver, block sign-in at the agreed time, revoke sessions, remove privileged roles, preserve or transfer required business data, review forwarding and delegates, recover devices, and remove access from connected applications. Do not immediately delete an identity if retention, investigation or handover work still depends on it.

ACA’s joiner, mover and leaver checklist builder creates a task list for the selected scenario. Add your own approval, retention and application-specific steps before using it as an operating procedure.

12. Prepare for a compromised account

Write down who can declare an incident, contact Microsoft or the IT provider, reset credentials, revoke sessions, isolate devices, inspect mailbox rules and communicate with affected people. Keep key contact details outside the tenant so they remain available if normal email is inaccessible.

Run a short exercise: an employee approves an unexpected MFA prompt and a suspicious forwarding rule appears. Ask who receives the alert, who can contain the account, which logs are preserved, how payment or data-exposure risks are checked, and who decides that normal access can resume. Record the gaps and assign dates rather than ending with a general promise to “be more careful”.

A sensible order for a small business

  1. Protect access: complete MFA registration, separate admin accounts and validate recovery.
  2. Reduce exposure: remove stale users, guests, roles, forwarding and legacy access.
  3. Secure the working environment: manage devices, email authentication and sharing.
  4. Prove recovery: test restores and the emergency-access route.
  5. Operate the controls: review alerts, access changes and exceptions on a schedule.

If ownership is unclear or the tenant contains years of undocumented changes, begin with discovery and a risk-ranked plan. ACA’s managed IT support for UK SMEs can cover Microsoft 365 administration alongside devices, helpdesk and ongoing security work.

Frequently asked questions

Are Microsoft 365 security defaults enough for a small business?

They provide a useful broad identity baseline for many tenants, but they do not replace device management, email authentication, sharing controls, recovery testing or operational review. Organisations needing more precise sign-in rules may require Conditional Access and suitable licensing.

Should every Microsoft 365 user have MFA?

Yes, including administrators and guests where your policies can enforce it. Prefer phishing-resistant methods for privileged and high-risk access where practical, and provide controlled recovery options.

Does Microsoft 365 back up all business data?

Microsoft provides retention, recovery and availability features, but the fit depends on the workload, licence, configuration and recovery scenario. Define your recovery requirements first, then verify whether native capabilities or an additional backup service meets them.

How often should Microsoft 365 security be reviewed?

Review alerts and critical changes continuously or at an agreed operational frequency. Review users, guests, privileged roles, devices and exceptions at least on a regular schedule and whenever staff, suppliers, licences or business systems change.

Can Secure Score prove that a tenant is secure?

No. Secure Score helps prioritise Microsoft recommendations. It does not cover every business risk, confirm that a process is followed or certify compliance.

Leave a Reply

Your email address will not be published. Required fields are marked *