Checklist

Microsoft 365 Secure workplace controls

A practical security checklist for protecting your Microsoft 365 environment across identities, email, devices, endpoints, collaboration, data compliance and continuous monitoring.

For: IT Hedds, CISO's, M365 Admins 11 Topics 70 minutes
CyberAxis M365 Secure Workplace
About this resource

Identify gaps before they become business risks

# Microsoft 365 Secure Workplace Controls
This security baseline is designed primarily for organizations using Microsoft 365 Business Premium. Some controls appear in more than one section because Microsoft Entra ID, Conditional Access, Intune, Defender, Exchange Online and Microsoft Purview operate as interconnected security components.
Resource Content

Topics covered

1

1. Tenant Foundation

1.1 Tenant Ownership

Document the Microsoft 365 tenant ID, primary domain, subscription owner, billing contacts, technical contacts and authorised administrators. This information should be securely maintained and regularly updated.

1.2 Administrative Access

Limit Global Administrator access to the minimum number of authorised personnel. Normally, an organisation should maintain between two and four appropriately secured Global Administrator accounts.

1.3 Separate Administrator Accounts

Administrators must use separate accounts for administrative activities and routine work. Privileged accounts should not be used for regular email, internet browsing or day-to-day office activities.

1.4 Emergency Access Accounts

Maintain two cloud-only emergency-access accounts to prevent complete tenant lockout. Protect these accounts with phishing-resistant authentication, securely store their credentials, monitor every login and test them quarterly.

1.5 Custom Domains

Verify all approved business domains configured within Microsoft 365. Remove any unused, expired or unrecognised domains from the tenant.

1.6 Domain and DNS Protection

Protect the domain registrar account using MFA, registrar lock and restricted administrative access. Maintain controlled documentation of Microsoft verification, SPF, DKIM and DMARC DNS records.

1.7 Organisation Contacts

Configure valid security, privacy, compliance, technical-support and service-health notification addresses. These mailboxes should be actively monitored.

1.8 Licensing Governance

Assign Microsoft 365 licences only to authorised users, preferably through controlled groups. Review unused, duplicate and unnecessarily assigned licences every month.

1.9 Release Management

Use Targeted Release only for a selected group of pilot users. Keep production users on the Standard Release channel unless there is a specific operational requirement.

1.10 Group and Site Creation

Restrict the creation of Microsoft 365 Groups, Teams and SharePoint sites to authorised users. Alternatively, implement a documented creation, naming and approval process.

1.11 Naming Standards

Establish consistent naming conventions for users, groups, devices, Conditional Access policies, enterprise applications, Teams and SharePoint sites.

1.12 Baseline Security Configuration

Review the Microsoft 365 Baseline Security Mode settings and enable applicable controls after completing an impact assessment and dependency review.

1.13 Unified Audit Logging

Confirm that Microsoft Purview Audit is enabled. Periodically verify that user activities and administrative changes are being recorded.

1.14 Configuration Register

Maintain an approved configuration register containing tenant settings, security policies, exceptions, responsible owners, approval information and implementation dates.

1.15 Change Control

Test material tenant configuration changes using pilot groups. Record the approval, expected impact, implementation steps and rollback procedure before applying changes to production.

2

2. Identity and Access Management

2.1 User Account Provisioning

Create user accounts only against approved employee, contractor or third-party onboarding requests. Every account should have a documented owner and business purpose.

2.2 Unique User Identity

Every person must have an individually assigned Microsoft 365 account. Shared user accounts should not be permitted because they prevent accountability and effective auditing.

2.3 Joiner–Mover–Leaver Process

Establish documented procedures for employee onboarding, role changes, department transfers, account suspension and termination.

2.4 Employee Offboarding

Immediately block sign-in, revoke active sessions, reset credentials, remove privileged roles and group memberships, transfer business data and remove unnecessary licences when employment ends.

2.5 Administrative Accounts

Maintain separate standard and privileged accounts for administrators. Dedicated administrative accounts should not have regular mailboxes unless there is a documented requirement.

2.6 Role-Based Access Control

Assign the least-privileged administrative role required for each responsibility. Do not assign Global Administrator when a more limited role can perform the required task.

2.7 Privileged Access Review

Review Global Administrator and other privileged role assignments at least quarterly. Remove unnecessary, duplicate or outdated access promptly.

2.8 Group-Based Access

Grant access through approved security groups wherever possible instead of directly assigning permissions to individual users.

2.9 Group Ownership

Assign at least two accountable owners to important security groups and Microsoft 365 Groups. This prevents groups from becoming unmanaged when an owner leaves the organisation.

2.10 Inactive Accounts

Identify and disable inactive, duplicate, test and orphaned accounts. Account inactivity should be reviewed at least monthly.

2.11 Guest Account Lifecycle

Assign a business owner, purpose and expected duration to every guest account. Review guest accounts quarterly and remove access that is no longer required.

2.12 Service Accounts

Document the owner and purpose of every service account. Block interactive sign-in where possible and use certificates, managed identities or other secure authentication methods instead of permanent passwords.

2.13 Password Management

Use Microsoft Entra Password Protection to block known weak passwords and organisation-specific terms. Passwords should be changed after suspected compromise rather than routinely changed without a security or regulatory reason.

2.14 Self-Service Password Reset

Enable Self-Service Password Reset for authorised users and require combined MFA and SSPR security-information registration.

2.15 Licence Removal

Remove unnecessary licences promptly. Before licence removal, preserve or transfer required mailbox, OneDrive and business information according to the organisation’s retention requirements.

3

3. Microsoft Entra ID Security

3.1 Multifactor Authentication

Require multifactor authentication for all users through Microsoft Entra Conditional Access.

3.2 Administrator Authentication

Require phishing-resistant MFA for administrator roles. Preferred authentication methods include Windows Hello for Business, passkeys or FIDO2 security keys, and certificate-based authentication.

3.3 Conditional Access Framework

Maintain documented Conditional Access policies with clear naming, scope, ownership, exclusions, dependencies and emergency-access arrangements.

3.4 Legacy Authentication

Block legacy authentication protocols that cannot support MFA, Conditional Access or device-compliance controls.

3.5 Authentication Methods

Centrally manage the authentication methods users are allowed to register. Prefer Windows Hello, passkeys and Microsoft Authenticator. Avoid SMS and voice authentication for administrators.

3.6 Security Defaults

Do not use Microsoft Security Defaults and Conditional Access together. Organisations with Microsoft 365 Business Premium should generally use Conditional Access for more granular control.

3.7 Emergency Account Exclusions

Exclude emergency accounts only from organisation-created Conditional Access policies that could cause complete tenant lockout. These accounts must still comply with applicable Microsoft platform MFA requirements.

3.8 Device Registration

Require MFA for Microsoft Entra device registration and restrict which users are allowed to join devices to the organisation’s directory.

3.9 Compliant Device Access

Require Intune-enrolled and compliant devices for access to Microsoft 365 and sensitive business applications wherever operationally possible.

3.10 Geographic Access Restrictions

Block sign-ins from countries where the organisation does not operate. Maintain documented exceptions for approved travel and legitimate business requirements.

3.11 Named Locations

Configure trusted office public IP addresses where required. Trusted network location must not be treated as a substitute for MFA and device compliance.

3.12 Application Consent

Allow users to provide consent only to verified applications requesting approved low-impact permissions. Route all other application-consent requests through an administrator approval process.

3.13 Enterprise Applications

Regularly review enterprise application owners, permissions, user assignments, certificates, secrets and usage information. Remove unused applications and excessive permissions.

3.14 Guest Access Restrictions

Apply the most restrictive practical guest-directory visibility and limit which users or administrative roles can invite external users.

3.15 Sign-In Monitoring

Monitor failed sign-ins, unusual locations, legacy authentication attempts, administrator logins, MFA failures and emergency-account activity.

3.16 Audit Monitoring

Monitor changes to administrative roles, Conditional Access, authentication methods, enterprise applications, credentials and guest access settings.

3.17 Entra Log Retention

Export Microsoft Entra sign-in and audit logs to Log Analytics, Azure Storage or a SIEM platform when retention beyond the native period is required.

3.18 Identity Secure Score

Review identity-related Microsoft Secure Score recommendations every month. Document completed actions, accepted risks and approved exceptions.

3.19 Conditional Access Deployment

Deploy new Conditional Access policies initially in Report-only mode. Review the impact and then enable them through phased pilot and production groups.

4

4. Exchange Online Security

4.1 Preset Security Policies

Apply the Standard preset security policy to all users. Apply the Strict preset security policy to administrators, directors, finance staff and other high-risk users.

4.2 Anti-Phishing Protection

Enable spoof protection, mailbox intelligence, user and domain impersonation protection, phishing thresholds and relevant safety tips.

4.3 Anti-Malware Protection

Enable malware filtering, Zero-hour Auto Purge and common attachment-type filtering to prevent malicious files from reaching users.

4.4 Inbound Anti-Spam Protection

Apply Microsoft-recommended actions for spam, high-confidence spam, phishing and high-confidence phishing messages.

4.5 Outbound Anti-Spam Protection

Configure outbound sending limits and alerts to identify compromised accounts, unusual sending patterns and restricted users.

4.6 Safe Links

Enable Safe Links for email and supported Microsoft 365 applications. Apply time-of-click URL scanning to protect users against malicious links.

4.7 Safe Attachments

Enable Safe Attachments for all users, with stronger protection for administrators, finance staff and other high-risk users.

4.8 SPF Configuration

Publish one accurate SPF record for every sending domain. The record should include only approved Microsoft and third-party email services.

4.9 DKIM Configuration

Enable DKIM signing for every custom domain used to send email through Microsoft 365 or another approved email platform.

4.10 DMARC Configuration

Implement DMARC after validating SPF and DKIM. Progress from monitoring to quarantine and then rejection after confirming all legitimate email sources.

4.11 External Sender Identification

Enable Microsoft 365 external sender identification or an approved external-email banner to help users recognise messages originating outside the organisation.

4.12 External Auto-Forwarding

Block automatic email forwarding to external domains by default. Permit forwarding only through formally approved and documented exceptions.

4.13 Authenticated SMTP

Disable SMTP AUTH across the organisation unless required by an approved application. Prefer OAuth and restrict exceptions to dedicated application accounts.

4.14 Mail Flow Rules and Connectors

Review transport rules, mail connectors, approved domains, IP allowlists and filtering bypass rules quarterly. Avoid broad rules that bypass spam, phishing or malware protection.

4.15 Mailbox Permissions

Regularly review Full Access, Send As, Send on Behalf, delegate access and forwarding permissions assigned to user mailboxes.

4.16 Shared Mailboxes

Provide shared-mailbox access only to approved named users or groups. Block direct sign-in and review shared-mailbox membership quarterly.

4.17 User Reporting

Enable the Report Message or Report Phishing capability. Establish a process for reviewing, investigating and responding to user-reported messages.

4.18 Quarantine Management

Configure quarantine policies and notifications appropriate to each threat category. Restrict the release of malware and high-confidence phishing messages to authorised administrators.

4.19 Mailbox Auditing

Confirm that mailbox auditing is enabled. Monitor mailbox-rule creation, forwarding changes, permission changes and unusual mailbox access.

4.20 Email Security Monitoring

Regularly review threat-protection, mail-flow, auto-forwarding, restricted-user, phishing and malware reports.

5

5. Device Management – Microsoft Intune

5.1 Intune Management Authority

Confirm that Microsoft Intune is the approved Mobile Device Management authority and that all required Microsoft service connectors are properly configured and healthy.

5.2 Automatic Enrolment

Enable automatic Intune enrolment for licensed users who access business information from organisation-managed devices.

5.3 Enrolment Restrictions

Block unsupported platforms, obsolete operating-system versions and unauthorised device manufacturers where applicable.

5.4 Personally Owned Devices

Block personally owned device enrolment when only corporate devices are permitted. Use Mobile Application Management and App Protection Policies where approved BYOD access is required.

5.5 Device Enrolment Limits

Set a reasonable maximum number of devices that each user can enrol in Microsoft Intune.

5.6 Windows Autopilot

Use Windows Autopilot for consistent corporate-device provisioning, Microsoft Entra joining, Intune enrolment and security-policy deployment.

5.7 Intune Administration

Apply Intune Role-Based Access Control, least privilege and scope tags. Do not use Global Administrator accounts for routine device-management activities.

5.8 Pilot and Production Groups

Maintain separate pilot and production assignment groups for applications, configuration profiles, security baselines and operating-system updates.

5.9 Intune Security Baselines

Deploy the current Microsoft Intune Windows security baseline after compatibility testing. Review and test new baseline versions before migration.

5.10 Configuration Profiles

Centrally manage Windows, browser, OneDrive, Microsoft 365 Apps, firewall, encryption and device-restriction settings through Intune configuration profiles.

5.11 Application Management

Deploy approved business applications through Microsoft Intune or Company Portal. Restrict unapproved and obsolete software where possible.

5.12 Mobile Application Protection

Apply App Protection Policies to Outlook, Teams, OneDrive and Microsoft 365 mobile applications, particularly when users access corporate data from personal devices.

5.13 Windows Update Management

Configure pilot and production Windows update rings with installation deadlines, restart controls and expedited security-update procedures.

5.14 Feature Update Management

Control approved Windows feature versions and prevent devices from remaining on unsupported or end-of-life releases.

5.15 Device Inventory

Review enrolled, inactive, duplicated, unmanaged and noncompliant devices every month.

5.16 Device Retirement and Wipe

Use Retire for removing organisational data from approved personal devices. Use Wipe or Autopilot Reset for lost, compromised or reassigned corporate devices.

5.17 Policy Monitoring

Regularly review configuration conflicts, policy deployment failures and devices that have stopped communicating with Microsoft Intune.

6

6. Endpoint Protection – Microsoft Defender

6.1 Endpoint Onboarding

Onboard all supported corporate Windows and macOS devices to Microsoft Defender for Business.

6.2 Sensor Health

Monitor endpoints that are inactive, misconfigured, not reporting or unsuccessfully onboarded to Microsoft Defender.

6.3 Real-Time Protection

Keep Microsoft Defender Antivirus real-time protection enabled on all supported endpoints.

6.4 Behaviour Monitoring

Enable behaviour monitoring and script scanning to detect suspicious actions that may not be identified through traditional file scanning.

6.5 Cloud-Delivered Protection

Enable cloud-delivered protection and automatic security-intelligence updates for faster detection of emerging threats.

6.6 Automatic Sample Submission

Enable safe automatic sample submission according to the organisation’s privacy and security requirements.

6.7 Tamper Protection

Enable Tamper Protection to prevent users, malware and unauthorised processes from modifying important Defender security settings.

6.8 Potentially Unwanted Applications

Configure Potentially Unwanted Application protection in Block mode.

6.9 Network Protection

Enable Microsoft Defender Network Protection to block malicious and suspicious domains, URLs and internet content.

6.10 Attack Surface Reduction

Deploy Microsoft-recommended Attack Surface Reduction rules in Audit mode. Validate business applications and progressively move compatible rules into Block mode.

6.11 Controlled Folder Access

Test Controlled Folder Access in Audit mode and enable it for systems handling important data where application compatibility allows.

6.12 Microsoft Defender Firewall

Keep Microsoft Defender Firewall enabled for Domain, Private and Public network profiles.

6.13 Web Content Filtering

Configure web-content filtering categories according to the organisation’s security, compliance and acceptable-use requirements.

6.14 Removable Media

Audit removable-storage activity and restrict USB write or execute access according to business requirements. Maintain controlled exceptions for approved devices.

6.15 Vulnerability Management

Regularly review exposed software, known vulnerabilities, missing updates and Microsoft Defender security recommendations.

6.16 Antivirus Exclusions

Keep antivirus exclusions to the minimum required. Document the owner, justification, scope and expiry or review date for every exclusion.

6.17 Incident Handling

Review Microsoft Defender incidents and alerts daily. Assign an owner and record investigation, containment and remediation actions.

6.18 Action Centre

Review automated remediation actions and pending approvals. Verify that affected endpoints return to a healthy and protected state.

7

7. Device Security and Compliance

7.1 Platform Compliance Policies

Create separate compliance policies for Windows, macOS, Android and iOS where those device platforms are permitted.

7.2 Devices Without Compliance Policies

Configure devices without an assigned compliance policy to be treated as noncompliant.

7.3 BitLocker Encryption

Require BitLocker encryption on corporate Windows devices. Securely store recovery keys in Microsoft Entra ID.

7.4 Secure Boot and TPM

Require Secure Boot and supported Trusted Platform Module capabilities for managed Windows devices.

7.5 Code Integrity

Require operating-system code integrity where supported by the device hardware and Windows version.

7.6 Antivirus Status

Require an active and up-to-date antivirus and antispyware solution on managed devices.

7.7 Firewall Status

Require the host-based firewall to remain enabled on managed endpoints.

7.8 Supported Operating Systems

Define minimum supported operating-system versions. Mark unsupported or end-of-life devices as noncompliant.

7.9 Device Threat Level

Integrate Microsoft Defender device risk with Intune compliance. Mark devices above the organisation’s accepted threat level as noncompliant.

7.10 Windows Hello for Business

Deploy Windows Hello for Business using a secure PIN or biometric authentication backed by the enrolled device.

7.11 Password and PIN Security

Apply appropriate password or PIN length, complexity, retry and lockout requirements to managed devices.

7.12 Screen Lock

Automatically lock devices after an approved period of inactivity and require authentication before access resumes.

7.13 Local Administrator Access

Remove unnecessary local-administrator access. Maintain separate privileged accounts for approved device administrators.

7.14 Windows LAPS

Use Windows Local Administrator Password Solution to generate, rotate and securely store unique local-administrator passwords.

7.15 Rooted or Jailbroken Devices

Mark rooted or jailbroken mobile devices as noncompliant and block them from accessing corporate applications and information.

7.16 Conditional Access Enforcement

Use Conditional Access to prevent noncompliant devices from accessing Microsoft 365, subject to formally approved exceptions.

7.17 Noncompliance Grace Period

Configure an appropriate remediation grace period. Use a shorter period for critical security failures and a reasonable period for routine compliance issues.

7.18 Compliance Exceptions

Place approved exceptions in controlled groups. Document the justification, responsible owner, compensating controls and expiration date.

7.19 Compliance Review

Review noncompliant devices, policy failures and overdue remediation actions at least weekly.

8

8. Collaboration Security – Teams, SharePoint and OneDrive

8.1 External Sharing

Allow external sharing only where there is a valid business requirement. Prefer authenticated guest access instead of anonymous Anyone links.

8.2 Default Sharing Link

Configure Specific People as the default link type when users share information externally.

8.3 Anonymous Links

Disable Anyone links by default. Where anonymous links are permitted, restrict them to view-only access and apply a short expiration period.

8.4 Domain Restrictions

Use allowed-domain or blocked-domain lists for regular business partners and prohibited external organisations.

8.5 Guest Access Expiration

Configure guest-access expiration where supported. Periodically require reauthentication or access renewal for continuing collaboration.

8.6 Unmanaged Devices

Apply limited web-only access or prevent downloads from unmanaged devices when users access sensitive SharePoint and OneDrive content.

8.7 Teams External Access

Permit external Teams chat only with approved organisations where practical. Block inbound contact from unmanaged Teams accounts unless required.

8.8 Teams Guest Access

Enable only the guest capabilities required for business collaboration. Restrict guest calling, meetings, messaging and content access appropriately.

8.9 Meeting Lobby

Require anonymous and untrusted participants to wait in the meeting lobby. Prevent anonymous users from starting meetings.

8.10 Presenter Rights

Configure external meeting participants as attendees by default. Grant presenter permissions only when approved by the meeting organiser.

8.11 Recording and Transcription

Restrict meeting recording and transcription to approved users. Inform participants and apply retention requirements to recordings and transcripts.

8.12 Teams Applications

Allow only approved Microsoft, third-party and custom Teams applications. Review application permissions and data access before approval.

8.13 Team and Site Creation

Restrict Team and SharePoint site creation or implement an approved creation and naming process. Important Teams and sites should have at least two owners.

8.14 Permission Reviews

Review SharePoint site owners, members, visitors, sharing links and guests quarterly. Remove direct and inherited access that is no longer required.

8.15 Safe Attachments

Enable Microsoft Defender Safe Attachments protection for SharePoint, OneDrive and Microsoft Teams.

8.16 Infected File Downloads

Prevent users and administrators from downloading files that Microsoft Defender has identified as malicious.

8.17 Sharing Monitoring

Monitor external sharing, anonymous links, unusual downloads, guest access and changes to site permissions.

8.18 Collaboration Lifecycle Management

Identify inactive, ownerless and obsolete Teams and SharePoint sites. Archive or remove them through an approved governance process.

9

9. Data Protection and Compliance

9.1 Data Classification

Establish an approved data-classification scheme such as Public, Internal, Confidential and Highly Confidential.

9.2 Data Ownership

Assign accountable owners to important data repositories. Data owners should approve access, external sharing, retention and deletion requirements.

9.3 Sensitivity Labels

Publish a simple and understandable set of sensitivity labels for emails and documents. Avoid creating excessive or confusing labels.

9.4 Label-Based Protection

Apply encryption, visual markings and sharing restrictions to Confidential and Highly Confidential information where required.

9.5 Default Labelling

Configure an appropriate default sensitivity label. Where supported, require users to provide business justification when downgrading protected information.

9.6 Data Loss Prevention

Configure Microsoft Purview DLP policies for Exchange, SharePoint and OneDrive to identify and protect personal, financial, employee, client and intellectual-property information.

9.7 DLP User Guidance

Use DLP policy tips to warn users before sensitive information is shared. Permit an override only where appropriate and require business justification.

9.8 DLP Policy Rollout

Deploy DLP policies initially in simulation or test mode. Validate detected matches and progressively enable user notifications and enforcement.

9.9 Sensitive Information Types

Review Microsoft’s built-in sensitive-information types and create organisation-specific types where the available templates do not meet business requirements.

9.10 Retention Schedule

Define retention periods based on legal, contractual, regulatory and operational requirements rather than relying only on technical defaults.

9.11 Retention Policies

Apply Microsoft Purview retention policies to Exchange, SharePoint, OneDrive and relevant Teams content based on the approved retention schedule.

9.12 Deleted File Preservation

Use retention policies to preserve protected OneDrive and SharePoint content even when users delete the active copy.

9.13 Legal Hold and eDiscovery

Maintain a documented legal-hold and eDiscovery process. Confirm that the available Microsoft 365 licence supports the required hold, search or investigation capability.

9.14 Audit Logging

Confirm that Microsoft Purview Audit is enabled. Microsoft Purview Audit Standard generally retains supported audit records for 180 days.

9.15 Encryption

Use Microsoft service encryption for information in transit and at rest. Apply sensitivity-label encryption to highly sensitive information where required.

9.16 Offboarding Data

Transfer required OneDrive, mailbox and business records to an authorised manager or repository before removing the user’s licence and account.

9.17 Data Recovery

Document Microsoft 365 recycle-bin, version-history, retention and restore capabilities. Test important recovery procedures periodically.

9.18 Independent Backup

Microsoft retention provides data preservation but is not a complete independent backup. Consider a third-party Microsoft 365 backup solution where separate copies, extended recovery or protection from configuration failure are required.

9.19 Compliance Review

Regularly review Microsoft Compliance Manager recommendations, DLP incidents, retention exceptions and unresolved compliance actions.

10

10. Monitoring, Governance and Operational Readiness

10.1 Security Ownership

Define accountable owners for Microsoft Entra ID, Intune, Defender, Exchange Online, Teams, SharePoint, OneDrive and Microsoft Purview.

10.2 Alert Contacts

Configure actively monitored email addresses for security alerts, service incidents, privacy notifications and administrative warnings.

10.3 Defender Incident Monitoring

Review high and critical Microsoft Defender incidents daily. Review lower-severity alerts according to an agreed response time.

10.4 Endpoint Health Monitoring

Monitor device onboarding, antivirus status, exposure, vulnerabilities, sensor health and inactive endpoints.

10.5 Email Security Monitoring

Review phishing, malware, spam, impersonation, restricted-user and automatic-forwarding reports.

10.6 Identity Monitoring

Review administrator sign-ins, unusual locations, failed MFA, legacy authentication, application consent and emergency-account activity.

10.7 Unified Audit Review

Use Microsoft Purview Audit to review relevant user and administrator activities during investigations and scheduled control reviews.

10.8 SIEM Integration

Forward relevant Microsoft Entra, Microsoft 365 and Defender logs to Microsoft Sentinel, Wazuh or another SIEM platform where centralised monitoring or extended retention is required.

10.9 Log-Retention Management

Document native log-retention periods. Configure export or archival when legal, regulatory or investigation requirements exceed the available retention period.

10.10 Microsoft Secure Score

Review Microsoft Secure Score every month. Assign improvement actions and document rejected recommendations, approved exceptions and accepted risks.

10.11 Microsoft 365 Service Health

Monitor Microsoft 365 Service Health for active incidents and advisories affecting the organisation’s tenant.

10.12 Microsoft 365 Message Centre

Review Microsoft 365 Message Centre at least weekly for security changes, feature retirements, changes to defaults and required administrative actions.

10.13 Security Policy Review

Review Conditional Access, Intune, Defender, Exchange, Teams, SharePoint and Purview security policies at least every six months.

10.14 Access Reviews

Review administrators, guests, enterprise-application permissions, shared mailboxes, forwarding rules and sensitive-site access at least quarterly.

10.15 Incident Response Plan

Maintain documented incident-response procedures for compromised accounts, phishing, malware, lost devices, data leakage and unauthorised administrative changes.

10.16 Incident Response Playbooks

Document specific containment actions such as blocking sign-in, revoking sessions, resetting credentials, isolating devices and removing malicious email.

10.17 Emergency Access Testing

Test emergency-access accounts at least quarterly and immediately after major identity or Conditional Access policy changes.

10.18 Recovery Testing

Periodically test mailbox, OneDrive, SharePoint, endpoint and configuration-recovery procedures.

10.19 Configuration Change Control

Record significant administrative changes, approvals, test results, implementation times and rollback information.

10.20 Security Reporting

Prepare monthly reports covering security incidents, vulnerable devices, patch compliance, noncompliant devices, phishing, DLP events and Microsoft Secure Score.

10.21 Security Awareness

Train users to identify phishing, protect MFA requests, handle sensitive data correctly and report suspicious emails, messages and devices.

10.22 Operational Documentation

Maintain current documentation covering tenant configuration, administrator contacts, vendors, escalation paths, network information and technical runbooks.

11

11. Microsoft 365 Business Premium Licensing Considerations

11.1 Microsoft Entra ID P2 Capabilities

Risk-based Conditional Access, complete Microsoft Entra ID Protection, Privileged Identity Management and advanced automated access reviews generally require Microsoft Entra ID P2 or another qualifying licence.

11.2 Microsoft Defender for Identity

Microsoft Defender for Identity is not included in the standard Microsoft 365 Business Premium licence and requires an appropriate add-on or upgraded security subscription.

11.3 Microsoft Defender for Cloud Apps

Microsoft Defender for Cloud Apps is not included in the standard Business Premium package and requires additional licensing.

11.4 Defender for Office 365 Plan 2

Advanced email investigation, expanded threat hunting, attack simulation training and other Plan 2 capabilities require Defender for Office 365 Plan 2 or a qualifying security add-on.

11.5 Defender for Endpoint Plan 2

Capabilities such as advanced hunting, live response and extended endpoint data retention may require Defender for Endpoint Plan 2 or an appropriate security add-on.

11.6 Advanced Microsoft Purview Controls

Endpoint DLP, certain Teams message DLP capabilities, automatic sensitivity labelling, advanced records management, Insider Risk Management and Communication Compliance may require additional Microsoft Purview licences.

11.7 Extended Audit Retention

Extended or customised audit retention beyond the standard licence entitlement may require Microsoft Purview Audit Premium or another qualifying subscription.

11.8 Licensing Validation

Validate licensing against the final technical design before committing advanced controls to the implementation scope. Features shown in an administrative portal should not automatically be assumed to be fully licensed for every user.

What happens next?

Turn assessment findings into a practical improvement plan

1Review the topics and complete the high-level assessment
2Identify partial, negative and uncertain responses
3Discuss priority gaps with CyberAxis specialists
4Build a tailored roadmap and implementation plan
Need Expert Guidance?

Get a detailed assessment and implementation roadmap

CyberAxis can validate your current environment, prioritize the findings and implement the controls required for your business.

CyberAxis security guidance illustration