Microsoft 365 Security Baseline Checklist for New Tenants
Retrospective: this article looks back at events from July 2017, written in 2026 with the benefit of hindsight.
New and long-neglected Microsoft 365 tenants share the same weaknesses. This checklist covers the baseline settings that stop the most common attacks. Treat each unchecked item as a priority.
Identity
- Two emergency access (break-glass) accounts exist and are monitored.
- MFA is required for all users through Conditional Access or Security Defaults.
- Legacy authentication is blocked.
- Fewer than five permanent Global Administrators; admins use separate accounts.
- Users cannot consent to third-party apps requesting broad permissions.
- Self-service password reset requires strong verification methods.
- SPF, DKIM and DMARC are configured for every sending domain, with DMARC moving toward enforcement.
- Defender for Office 365 Standard or Strict preset security policies are applied.
- Automatic external forwarding is blocked by default.
- Mailbox auditing is on (it is by default — confirm it hasn't been disabled).
Collaboration
- External sharing in SharePoint and OneDrive is limited to what the business needs.
- The default sharing link is "Specific people."
- Guest access has an expiry or review process.
- Teams external access is limited to trusted domains if feasible.
Devices
- Devices must be enrolled and compliant to access corporate data, or at least use app protection policies.
- BitLocker and Defender are enforced on Windows devices.
Visibility
- The unified audit log is enabled.
- Sign-in and audit logs are retained long enough for investigations (consider exporting to a SIEM).
- Microsoft Secure Score is reviewed monthly.
Free tools such as CISA's ScubaGear and Microsoft's Zero Trust Assessment can check many of these automatically.