Microsoft 365 Security Hardening Checklist for Compliance-Driven SMBs
Default Microsoft 365 tenants fail audits. Here are the identity, email, data, and logging settings auditors and cyber insurers actually check.
Last updated:
A default Microsoft 365 tenant is built for adoption, not for audit. Every SOC 2, HIPAA, and cyber insurance review we run finds the same handful of gaps — and all of them are configuration, not licensing.
Identity: Where Every Breach Starts
- Enforce phishing-resistant MFA for all users via Conditional Access. Per-user MFA toggles are not a control an auditor accepts.
- Block legacy authentication protocols entirely.
- Restrict and monitor Global Administrator accounts; target fewer than five, each with a break-glass account excluded from Conditional Access and stored offline.
- Turn on risk-based sign-in policies and review risky sign-ins weekly with a documented reviewer.
Email: The Attack Surface Everyone Underestimates
- SPF, DKIM, and DMARC published — DMARC at enforcement, not p=none.
- Disable automatic external mail forwarding at the tenant level. This single setting stops most BEC data exfiltration.
- Enable Safe Links and Safe Attachments where licensed, and external-sender warnings everywhere.
- Alert on inbox rule creation that forwards or deletes mail.
Data: Know Where Regulated Records Live
- Sensitivity labels for regulated data, with auto-labeling on the obvious patterns (PHI, PII, payment data).
- Restrict anonymous sharing links in SharePoint and OneDrive; default to organization-only with expiry.
- Retention policies matched to your actual legal obligations — over-retention is a breach amplifier.
- Review guest access quarterly and remove dormant external accounts.
Devices and Endpoints
- Require compliant or hybrid-joined devices for access to email and files.
- Enforce disk encryption and screen-lock policy through Intune, with a compliance report you can export.
- Block unmanaged device downloads of regulated content.
Logging: The Part Auditors Fail You On
- Confirm unified audit logging is on and retained for the full audit window — default retention is usually shorter than your observation period.
- Ship logs to a SIEM or archive so retention survives license changes.
- Configure alert policies for admin role changes, mass downloads, and impossible-travel sign-ins, and document who responds.
Prove It Quarterly
Hardening is not a one-time project. Export your Secure Score, Conditional Access policy set, and admin role list every quarter and file them as evidence. That folder is the difference between a smooth audit and a scramble.
Our Remote IT Support and fractional CISO engagements run this checklist as a standing quarterly control, with the results feeding your Senticit Intelligence Score.
This article is part of our comprehensive Managed IT guide.
Read the complete guide →