Registered office
20 Wenlock Road
London N1 7GU
Registered office
20 Wenlock Road
London N1 7GU

Use this Microsoft 365 security checklist to protect small-business accounts, administrators, devices, email, sharing, data, recovery and ongoing monitoring.
A secure Microsoft 365 setup for a small business starts with identity: require strong sign-in protection, separate everyday and administrator accounts, remove access promptly when somebody leaves, and keep a tested recovery route. Then work outwards through devices, email, sharing, data protection, monitoring and incident response. The checklist below gives each control an owner and a result you can verify.
Reviewed: 9 September 2026
| Priority | Check | Useful evidence |
|---|---|---|
| Now | Protect every user and administrator with MFA or a passkey | Registration and sign-in reports |
| Now | Separate administrator accounts and reduce privileged roles | Role assignment export |
| Now | Confirm recovery and emergency access | Dated recovery test |
| This week | Secure devices, email and external sharing | Policy screenshots or exports |
| This month | Review logs, alerts, Secure Score and data handling | Named actions with owners and dates |
| Ongoing | Run joiner, mover and leaver checks | Completed checklist for each change |
This is a practical baseline, not a guarantee that an organisation is secure or compliant. Microsoft 365 features vary by licence, tenant configuration and region. Confirm what your subscription includes before designing controls around it.
Before changing a policy, identify the people and services that keep the tenant reachable. Record the tenant’s primary domain, billing owner, licence partner, DNS host, support contact and the people authorised to approve access changes. Confirm that the business—not only an employee or supplier—can reach those accounts.
A password known by several people is not a resilient ownership model. Give each person their own account and keep auditable emergency access for the situations normal administration cannot cover.
Turn on multifactor authentication (MFA) across the tenant and complete registration rather than assuming a policy alone has protected everyone. Microsoft’s current security guidance for Microsoft 365 business customers recommends security defaults for many organisations and Conditional Access where more detailed requirements are needed.
Choose one coherent enforcement route. Security defaults provides a broad baseline; Conditional Access supports more precise rules but depends on suitable licensing and careful rollout. Use report-only or a controlled pilot where available, check service accounts and legacy applications, and keep an exclusion path for emergency access before enforcing a policy tenant-wide.
The NCSC’s small-organisation account guidance also recommends strong, unique sign-in credentials and 2-step verification for important services.
An administrator should not read normal email or browse the web from the same account used to change tenant-wide settings. Create a separate named administrator account for each authorised person, protect it with strong authentication and assign only the roles needed for the work.
Microsoft recommends maintaining at least two cloud-only emergency access accounts for resilience, using authentication that does not share the same dependency as normal admin access, monitoring every use and testing them regularly. Follow the live Microsoft emergency access guidance; a badly designed exception can either become an easy route in or fail when it is needed.
Older mail clients and protocols may not support modern authentication. They can also undermine an MFA rollout. Identify them before blocking access, replace or reconfigure legitimate dependencies, and document any temporary exception with an owner and expiry date.
Review inbox forwarding, mail-flow rules, connectors, application passwords, OAuth application consent and broad allow lists. Microsoft warns that IP allow-list entries can bypass parts of spam filtering and sender authentication, so keep exceptions narrow and review them rather than using a whole provider range as a permanent fix.
Microsoft 365 account security is weakened if an unmanaged laptop keeps an active session after it is lost or runs unsupported software. Decide which devices may access business data and what each device must prove.
Microsoft 365 Business Premium includes additional device-management and security capabilities, but they still need to be configured and monitored. If a lower licence does not provide the control you need, use an appropriate third-party service or change the licence—do not simply write the requirement into a policy that the technology cannot enforce.
Configure SPF, DKIM and DMARC for the domain shown in the From address. Microsoft’s email authentication guidance explains why the three mechanisms work together: SPF identifies permitted sending infrastructure, DKIM signs messages, and DMARC evaluates alignment with the visible sender domain.
Use ACA’s SPF checker, DKIM inspector and DMARC checker to inspect public records. A record being present does not prove every legitimate message is aligned, so verify actual message headers and DMARC reports before requesting rejection.
Review the protection available in the selected licence and apply Microsoft’s recommended preset security policies where they fit. Pay particular attention to impersonation, malicious links and attachments, user-reported messages and the handling of high-confidence phishing.
Do not solve recurring false positives by broadly trusting a sender or disabling protection. Investigate the sending route, authentication and message pattern, then use the narrowest supported remediation. Regularly search for unexpected forwarding rules, inbox rules and newly granted mailbox permissions; attackers often use these to retain access or hide replies after an account compromise.
Decide how staff may share information outside the business. The answer should reflect the information, the recipient and the working relationship rather than one unrestricted tenant-wide setting.
Information protection, sensitivity labels and data loss prevention can help where the licence and business requirement justify them. These features support a data-handling policy; they do not create one or establish legal compliance by themselves.
Retention, recycle bins, version history and backup solve different problems. Document which Microsoft 365 data the business cannot operate without, how long it must be retained, how quickly it needs to be restored and which recovery scenarios the chosen service covers.
Test recovery for a deleted file, mailbox item, user and shared workspace. If a third-party backup is used, monitor job results, restrict backup-administrator access and test restores rather than treating a successful job notification as proof of recoverability.
The NCSC advises small organisations using online services to identify and back up critical data, protect administrator accounts, create separate user accounts and use the security features built into the service. Its using online services safely collection provides an independent starting point.
Logs matter only if the right people can reach them and know what to investigate. Confirm audit logging and retention for the licences in use, record who reviews alerts and decide how evidence will be preserved during an incident. Microsoft’s published audit-retention periods vary by licence and workload, so check the current audit retention documentation rather than relying on an old assumption.
Use Microsoft Secure Score as a prioritisation aid, not a certificate. Review recommended actions, understand their operational effect, implement the ones that fit, and document why a recommendation is deferred or handled another way. A higher score can show progress, but it does not measure every risk or prove that controls work in practice.
Access changes should follow an authorised request and a checklist. For a leaver, block sign-in at the agreed time, revoke sessions, remove privileged roles, preserve or transfer required business data, review forwarding and delegates, recover devices, and remove access from connected applications. Do not immediately delete an identity if retention, investigation or handover work still depends on it.
ACA’s joiner, mover and leaver checklist builder creates a task list for the selected scenario. Add your own approval, retention and application-specific steps before using it as an operating procedure.
Write down who can declare an incident, contact Microsoft or the IT provider, reset credentials, revoke sessions, isolate devices, inspect mailbox rules and communicate with affected people. Keep key contact details outside the tenant so they remain available if normal email is inaccessible.
Run a short exercise: an employee approves an unexpected MFA prompt and a suspicious forwarding rule appears. Ask who receives the alert, who can contain the account, which logs are preserved, how payment or data-exposure risks are checked, and who decides that normal access can resume. Record the gaps and assign dates rather than ending with a general promise to “be more careful”.
If ownership is unclear or the tenant contains years of undocumented changes, begin with discovery and a risk-ranked plan. ACA’s managed IT support for UK SMEs can cover Microsoft 365 administration alongside devices, helpdesk and ongoing security work.
They provide a useful broad identity baseline for many tenants, but they do not replace device management, email authentication, sharing controls, recovery testing or operational review. Organisations needing more precise sign-in rules may require Conditional Access and suitable licensing.
Yes, including administrators and guests where your policies can enforce it. Prefer phishing-resistant methods for privileged and high-risk access where practical, and provide controlled recovery options.
Microsoft provides retention, recovery and availability features, but the fit depends on the workload, licence, configuration and recovery scenario. Define your recovery requirements first, then verify whether native capabilities or an additional backup service meets them.
Review alerts and critical changes continuously or at an agreed operational frequency. Review users, guests, privileged roles, devices and exceptions at least on a regular schedule and whenever staff, suppliers, licences or business systems change.
No. Secure Score helps prioritise Microsoft recommendations. It does not cover every business risk, confirm that a process is followed or certify compliance.