Microsoft 365How-To & HardeningRetrospectives

Microsoft 365 Security Baseline Checklist for New Tenants

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2017, written in 2026 with the benefit of hindsight.

New and long-neglected Microsoft 365 tenants share the same weaknesses. This checklist covers the baseline settings that stop the most common attacks. Treat each unchecked item as a priority.

Identity

  • Two emergency access (break-glass) accounts exist and are monitored.
  • MFA is required for all users through Conditional Access or Security Defaults.
  • Legacy authentication is blocked.
  • Fewer than five permanent Global Administrators; admins use separate accounts.
  • Users cannot consent to third-party apps requesting broad permissions.
  • Self-service password reset requires strong verification methods.

Email

  • SPF, DKIM and DMARC are configured for every sending domain, with DMARC moving toward enforcement.
  • Defender for Office 365 Standard or Strict preset security policies are applied.
  • Automatic external forwarding is blocked by default.
  • Mailbox auditing is on (it is by default — confirm it hasn't been disabled).

Collaboration

  • External sharing in SharePoint and OneDrive is limited to what the business needs.
  • The default sharing link is "Specific people."
  • Guest access has an expiry or review process.
  • Teams external access is limited to trusted domains if feasible.

Devices

  • Devices must be enrolled and compliant to access corporate data, or at least use app protection policies.
  • BitLocker and Defender are enforced on Windows devices.

Visibility

  • The unified audit log is enabled.
  • Sign-in and audit logs are retained long enough for investigations (consider exporting to a SIEM).
  • Microsoft Secure Score is reviewed monthly.

Free tools such as CISA's ScubaGear and Microsoft's Zero Trust Assessment can check many of these automatically.

microsoft 365 security baseline checklistMicrosoft 365 E5 launch2017

More on this story