Microsoft 365 security check

How well defendedis your Microsoft 365?

Twenty-two questions, about ten minutes. It runs entirely in your browser: nothing is sent to us or stored, and at the end you get a scored report you can print or save.

Identity and access

Who can sign in, and how hard that is to fake.

Is multi-factor authentication enforced for every user?

Through Conditional Access or security defaults, rather than left to each person to set up.

Is legacy authentication blocked?

Older sign-in methods can't do multi-factor authentication, so attackers use them to get round it.

Do administrators sign in with phishing-resistant methods, such as passkeys or security keys?

Codes and push approvals can be phished; passkeys and FIDO2 keys can't.

Are admin roles held by separate, dedicated accounts, with fewer than five Global Administrators?

Microsoft recommends fewer than five Global Administrators, and admin accounts without mailboxes.

Do you have two emergency access accounts, and would you know if one were used?

So a Conditional Access mistake or an outage can't lock every admin out.

Is admin access granted just in time, rather than held permanently?

Privileged Identity Management needs Entra ID P2 or Entra ID Governance.

Devices

Whether the laptops and servers touching your data can be trusted.

Does access to company data require a managed, compliant device?

Intune compliance policies, checked by Conditional Access at sign-in.

Is endpoint detection and response running on every device and server?

For example Microsoft Defender for Endpoint, with tamper protection on.

Are operating system and application updates installed within 14 days of release?

Fourteen days is the Cyber Essentials requirement for critical and high-risk updates.

Are disks encrypted, and are local admin rights removed from everyday users?

BitLocker or FileVault, with the built-in admin password rotated by Windows LAPS.

Email

Your most attacked front door.

Are SPF, DKIM and DMARC in place, with DMARC set to quarantine or reject?

Without enforcement, anyone can send email that claims to come from your domain.

Are Safe Links, Safe Attachments and anti-phishing policies switched on?

Defender for Office 365, ideally through Microsoft's preset security policies.

Is automatic forwarding of email to external addresses blocked?

A favourite way for attackers to copy a mailbox quietly.

Data and sharing

Where your files can travel, and who decides.

Is external sharing in SharePoint and OneDrive restricted?

For example, links limited to specific people, with expiry dates on anything shared outside.

Are sensitivity labels or data loss prevention policies applied to sensitive information?

Microsoft Purview, starting with the data that matters most.

Backup and recovery

What happens on the worst day.

Is Microsoft 365 data backed up beyond its built-in retention?

Retention settings and recycle bins are not a backup.

Have you restored something from that backup in the last six months, and timed it?

A successful backup job proves the job ran, not that the restore works.

Is there a written plan for a compromised account or ransomware, and has anyone rehearsed it?

Who calls whom, who can make decisions, and the first ten things to do.

Monitoring and response

Whether anyone would notice.

Is audit logging switched on, with logs kept for at least 180 days?

The unified audit log in Microsoft Purview.

Does someone review security alerts and risky sign-ins every working day?

Alerts nobody reads are the same as no alerts.

Do you track Microsoft Secure Score and act on it?

It turns Microsoft's recommendations into a measurable backlog.

Are the third-party apps your users have granted access to reviewed?

Apps with consent to read mail or files can be as risky as a compromised account.

0 of 22 answered