Reviewed August 15, 2026. Microsoft 365 security is a tenant-specific control program, not a one-time “MSP setup.” Microsoft’s current small-business guidance prioritizes MFA, protected administrator accounts, preset email-security policies, managed devices, safer sharing, and ongoing maintenance. Licensing determines which controls are available.
This checklist avoids fixed security scores and plan assumptions. Administrators should test policies in report-only, pilot, or nonproduction modes where available, maintain emergency access, and verify that dependent applications and service accounts continue to work before broad enforcement.
Protect identity and administration
Microsoft's 2026 Baseline Security Mode guidance highlights phishing-resistant administrator authentication, blocking legacy authentication, restricting weak application credentials, and limiting end-user app consent. Evaluate those controls against the tenant's exact licensing and application dependencies.
- Maintain separate administrator accounts and keep routine email and browsing on standard user identities.
- Require MFA for all users; require phishing-resistant authentication for privileged administrators where supported.
- Block legacy authentication and remove unused protocols, app passwords, stale sessions, and dormant accounts.
- Use Conditional Access for risk, device, location, application, and authentication-strength decisions when licensed.
- Protect and test emergency-access accounts; monitor privileged-role assignments and sign-ins.
Harden email, Teams, SharePoint, and OneDrive
Microsoft recommends Standard or Strict preset security policies for Defender for Office 365 rather than hand-copying old setting tables. Start with a pilot, review false positives and business mail flows, and keep allow entries narrow and time-bounded.
| Workload | Baseline |
|---|---|
| Exchange Online | Anti-phishing, anti-spam, anti-malware, impersonation protection, safe links and attachments as licensed |
| Teams | External access, guest access, app permissions, meeting policy, safe links, retention and DLP as licensed |
| SharePoint and OneDrive | External sharing defaults, link expiry, sensitivity, DLP, safe attachments, retention |
| Domains | SPF, DKIM, DMARC rollout, monitoring, and authorized sender inventory |
Manage endpoints, applications, and data
Conditional Access can lock out users or break integrations when applied without testing. Maintain exclusions only when documented, monitored, and owned; broad permanent exclusions create policy gaps.
- Enroll supported devices in management and define compliance, update, encryption, screen-lock, and endpoint-protection baselines.
- Use app-protection policies for supported mobile scenarios and gate sensitive access on compliant devices where appropriate.
- Restrict OAuth consent, review enterprise applications and service principals, and remove stale credentials and permissions.
- Classify sensitive data and implement labels, DLP, retention, eDiscovery, and audit according to legal requirements.
- Inventory third-party backup and recovery coverage; SaaS availability and retention are not a complete business recovery plan.
Operate the tenant continuously
Record change ownership, evidence, rollback, and follow-up. Security settings evolve as Microsoft changes defaults and threats; a dated checklist must never become an unattended configuration standard.
- Establish the tenant baseline and record licensed capabilities and exceptions.
- Prioritize identity, administrator, and legacy-authentication risk.
- Pilot email, endpoint, sharing, and app-consent policies with representative users.
- Monitor sign-ins, alerts, audit events, message reports, endpoint health, and policy drift.
- Test account recovery, data restore, incident communications, and administrator access on a schedule.
- Review secure score recommendations as signals, not as proof of security or compliance.
Implementation and review gate
A tenant administrator must validate every item against current Microsoft documentation, licensing, dependencies, and business requirements. No change should be applied from this article without a tested tenant-specific plan and rollback.
ITECS can help Dallas organizations plan and validate this work through Microsoft 365 consulting. Product, legal, security, and compliance decisions remain subject to the organization’s current requirements and the named review gate below.
Primary sources
continue reading
More ITECS blog articles
About Brian Desmot
The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.
View full profile and articles