Identity · administration · recovery

Free Microsoft 365 security checklist.

Turn a Microsoft 365 security review into a clear list of confirmed controls, unanswered questions and priority follow-ups—without reducing a complex tenant to a misleading score.

Start the tenant review

A review worksheet, not a scanner

Record what you can prove—and what still needs checking.

Use current policy screens, sign-in evidence, audit records, change tickets and recovery tests. “Configured once” is not the same as confirmed today.

ConfirmedCurrent evidence supports it Partly in placeA known gap or exception remains Not checkedEvidence has not been reviewed

Review context

Name the tenant and its identity model

STEP 01

Control review

Choose one honest status for each question

STEP 02

Your answers stay in this page while you build the review.

How to use the result

Treat “not checked” as a useful answer.

A clean review separates known gaps from evidence gaps. Start with emergency access and privileged identity, then work through legacy protocols, audit visibility, sharing and recoverability.

01

Find the evidence

Policy, logs, owners, exceptions and recent tests.

02

Check dependencies

Licensing, identity model and business-critical apps.

03

Change safely

Approval, staged rollout, emergency access and rollback.

Important boundaries

Avoid turning a checklist into false assurance.

Microsoft 365 names, defaults and licensing evolve. The checklist points to review areas; your current tenant, contracts, risk and regulatory obligations determine the right control design.

Do not switch policies blindly

Access changes can lock out administrators or break mail, devices and applications. Use report-only modes, pilots and rollback where appropriate.

Retention is not a restore test

Define what must be restored, from when and how quickly. Then validate the available retention or backup route with representative data.

It is not a compliance verdict

Framework and legal requirements need evidence, scope and accountable interpretation beyond a general-purpose worksheet.

Common questions

Microsoft 365 checklist FAQ.

Does this tool scan our Microsoft 365 tenant?

No. It is a structured self-review and does not ask you to sign in or grant access. The result is only as reliable as the evidence used to answer each question.

Does “confirmed” mean the control is secure?

No. It means you recorded the item as confirmed. Control design, configuration, exceptions, licensing, testing and current threat context still need competent review.

Why ask for two emergency access accounts?

Microsoft's current guidance recommends two or more cloud-only emergency accounts so administrators have an independent recovery route if normal identity controls fail or cause lockout.

Should every tenant use the same settings?

No. Security Defaults, Conditional Access, hybrid identity, mail protection, audit retention and backup options differ by tenant, licence and operating need. Validate the supported design before changing policy.

Need a second pair of eyes?

Turn the review into an owned improvement plan.

ACA Tech Solutions can help UK teams examine Microsoft 365 identity, administration, sharing, audit and recovery with evidence, sequencing and practical change controls.

Explore the IT health check