In this guide
Why a tenant that 'works fine' can still be wide open
Microsoft 365 is secure by design and insecure by default in the way that matters: almost every protective feature has to be switched on, scoped and maintained by someone. Microsoft's own security overview for business plans lists Conditional Access, Intune enrolment and the preset email security policies as things an administrator configures after setup. A tenant that was set up in an afternoon in 2019 and has "worked fine" since is usually running on that afternoon's defaults.
The checklist below is what we work through on every new client, grouped the way an attacker thinks about it: get in (accounts), move around (permissions), land somewhere (devices), arrive by email, and avoid being noticed (monitoring). Each line says what we check and why. If your IT provider cannot show you the answer to a line, that is the answer.
1. Accounts and sign-in
| Check | Why it matters |
|---|---|
| MFA enforced for every user, not just "enabled" or "registered" | The single control that stops most account takeovers. Registered-but-not-required is the most common gap we find. |
| Legacy authentication blocked | Old protocols (IMAP, POP, SMTP basic auth) skip MFA entirely. |
| Security defaults or Conditional Access in use (Conditional Access needs Business Premium) | Rules for who gets in, from where, on what device. |
| Separate admin accounts, no admin rights on everyday mailboxes | A phished admin mailbox is a phished tenant. |
| Break-glass account exists, is excluded from Conditional Access, and its password is stored offline | So a locked-out admin cannot lock out the business. |
| Global Administrator count is two or three, not eight | Every extra admin is another way in. |
| No shared or generic logins | Shared accounts cannot have MFA that means anything and cannot be audited. |
| Passwordless or phishing-resistant MFA for admins | Push-notification fatigue attacks work; security keys and Windows Hello do not fall for them. |
2. Sharing and permissions
| Check | Why it matters |
|---|---|
| SharePoint default sharing link is "specific people", not "anyone with the link" | Anonymous links are how documents leave the business silently. |
| External sharing restricted to what the business needs, and reviewed | Guests from a project three years ago still have access. |
| "Everyone" and "Everyone except external users" groups removed from HR, finance and client sites | The oversharing that Copilot makes easy to find. |
| Mailbox forwarding to external addresses blocked or alerted | Attackers add a forwarding rule as their first act after a compromise. |
| App consent restricted so users cannot grant third-party apps access to mail and files | Consent phishing bypasses passwords entirely. |
| Sensitivity labels and DLP for the data that would hurt most (Business Premium) | Stops card numbers and personal data leaving by email, and travels with the document. |
3. Devices
| Check | Why it matters |
|---|---|
| Every company device enrolled in Intune with a compliance policy | A device you cannot see is a device you cannot wipe, patch or trust. |
| Disk encryption enforced (BitLocker, FileVault) | A lost laptop becomes a lost laptop rather than a data breach. |
| Updates managed with evidence of the 14-day fix window for critical vulnerabilities | Cyber Essentials requires it; ransomware exploits the gap. |
| Defender for Business deployed and reporting on every device (Business Premium) | Detection and response, not just antivirus. |
| App protection policies on staff-owned phones with Outlook and Teams | Company data on personal phones, contained and wipeable. |
| Conditional Access requires a compliant or protected device for company data | Turns the policies above from advice into enforcement. |
Our Intune and BYOD guide covers how to roll these out without locking anyone out.
4. Email protection
| Check | Why it matters |
|---|---|
| SPF, DKIM and DMARC at reject on every domain you own | Stops criminals sending as you. Check yours with the free audit. |
| Preset security policies (Standard or Strict) applied | Microsoft's recommended baseline for spam, malware and phishing settings. |
| Safe Links and Safe Attachments on (Defender for Office 365, in Business Premium) | Links checked at click time; attachments detonated before delivery. |
| Impersonation protection listing your directors and key suppliers | The invoice-fraud layer. |
| A way for staff to report suspicious email in one click, and someone who reviews the reports | Reporting is how you find the campaign that got through. |
| Auto-forwarding and inbox rules audited | See Permissions above; it belongs in both lists. |
Our email security guide explains the records; the phishing and invoice fraud guide covers the inbound side.
5. Backup, logging and monitoring
| Check | Why it matters |
|---|---|
| A real backup of mailboxes, OneDrive and SharePoint, tested | Microsoft's recycle bins keep data for days, not years; see the backup guide. |
| Unified audit logging on | Without it there is no record of what an attacker did. |
| Alerts configured and going somewhere a person reads them | Risky sign-ins, new forwarding rules, mass downloads, admin role changes. |
| Someone watching out of hours | Attacks are timed for evenings and weekends; see the 24/7 SOC guide. |
| Secure Score reviewed and trending up, not just reported | Microsoft's own measure of the configuration. |
| A quarterly review of all of the above | Joiners, leavers, new tools and Microsoft's monthly changes all move the picture. |
Want a second opinion before you buy licences?
We will look at your tenant, tell you who would actually benefit, and what needs fixing first. An engineer, not a salesperson.
How Black Sheep Support runs this for you
We run this checklist as a Microsoft 365 security review: read-only access to your tenant, a written report of what is on, off and misconfigured against each line, ranked by risk, with the fix for each. For managed clients the fixes are made, the settings are maintained, and the review repeats quarterly. [TO CONFIRM: whether the review is offered as a fixed-fee standalone service, and its price.]
If you want to know which licence gives you the tools on this list, the Microsoft 365 licensing and security guide explains Business Basic, Standard and Premium; if you want a quick outside-in check first, the free IT Health Check takes a few minutes.
Want a second opinion before you buy licences?
We will look at your tenant, tell you who would actually benefit, and what needs fixing first. An engineer, not a salesperson.
Frequently asked questions
Is Microsoft 365 secure out of the box?
The platform is; a new tenant's configuration is not. MFA enforcement, Conditional Access, device enrolment, email protection presets, sharing restrictions, backup and alerting all have to be set up. Microsoft's own documentation tells administrators to configure them after the basic setup.
What is the single most important item on the list?
MFA enforced for every account, with legacy authentication blocked. It stops the majority of account takeovers on its own.
Do we need Business Premium to complete the checklist?
Several items (Conditional Access, Intune, Defender for Business, Safe Links and Attachments, sensitivity labels) need Business Premium. The account, sharing and forwarding items apply to every plan.
How long does a review take?
Read-only access and a day or two of engineering time for a typical small business, then a written report. Fixing what it finds ranges from an afternoon to a few weeks depending on what has to change.
Can we do this ourselves?
Yes, with an administrator who knows the tenant and the time to work through Microsoft's guidance. The lines above tell you what to prove. Most businesses without in-house IT find it faster to have it done and then maintained.
What is Secure Score?
Microsoft's built-in measure of how much of the available security configuration a tenant has applied, shown in the Defender portal. Useful as a trend, less useful as a single number, and it does not check backup or monitoring.
Find out what is actually switched on
A Microsoft 365 security review gives you the answer to every line above for your own tenant, ranked by risk, with the fix for each.
- Read-only review of your tenant against the checklist.
- A plain-English report: what is on, what is off, what is wrong, in risk order.
- The licence you would need for anything missing, with prices.
- A clear next step, whether or not that involves us.
Sources
Prices and product facts on this page were checked against the following Microsoft pages on the dates shown.
- 1.Microsoft Learn: Microsoft 365 for business security overview · accessed 10 September 2026
- 2.Microsoft Learn: Recommended settings for EOP and Defender for Office 365 (preset security policies) · accessed 10 September 2026
What has changed on this page
- 10 September 2026Page published.



