Microsoft 365 Security Checklist for SMBs — 20 Essential Controls
20 security controls every SMB with Microsoft 365 should verify. Download the free checklist and protect your business today.
The checklist every SMB needs
If your company uses Microsoft 365, these are the 20 security controls you should verify today. You don't need to be a cybersecurity expert — you just need to know what to check.
Identity and access (controls 1-5)
1. MFA enabled for all users — not just administrators. Microsoft reports that 99.9% of account compromise attacks are prevented by MFA.
2. Conditional Access configured — at least one policy requiring MFA from unrecognized locations or devices.
3. Guest users audited — review who has guest access to your tenant and whether they still need it. Stale guest accounts are a common lateral movement vector.
4. Password policy updated — minimum 12 characters, no forced periodic expiration (Microsoft's current guidance is to NOT force regular password changes as it leads to weaker passwords).
5. Legacy authentication blocked — legacy protocols (basic POP, basic IMAP) don't support MFA and are the favorite vector for credential stuffing attacks.
Email (controls 6-10)
6. SPF configured — your DNS record should limit which servers can send email from your domain. Without SPF, anyone can impersonate your email.
7. DKIM active — cryptographic signature on all outgoing emails proves they weren't tampered with in transit.
8. DMARC enforced — set to "quarantine" or "reject", not "none". DMARC in "none" mode only monitors — it doesn't block spoofed emails.
9. Auto-forwarding disabled — attackers configure silent forwarding rules to exfiltrate data from compromised mailboxes. This should be blocked at the tenant level.
10. Anti-phishing policies active — Microsoft Defender includes anti-impersonation protection that detects emails pretending to be executives or known contacts.
Data (controls 11-15)
11. External sharing controlled — SharePoint/OneDrive should not allow "anyone with the link" by default. Limit to specific people or your organization.
12. DLP policies configured — at least for financial data and personal identifiers (credit cards, tax IDs, social security numbers).
13. Data retention defined — what happens to emails and files when an employee leaves? Without retention policies, data either disappears or lives forever.
14. Sensitivity labels applied — classify documents as "public", "internal", "confidential". This enables automated protection based on content.
15. Access auditing enabled — you need to know who accessed what and when. Enable unified audit log and set retention to at least 90 days.
Devices (controls 16-18)
16. Intune configured — basic device management for any device accessing corporate data. Without it, you have zero visibility into what machines touch your data.
17. Defender for Endpoint active — endpoint protection integrated with your Microsoft 365 tenant. Detects malware, ransomware, and suspicious behavior.
18. Compliance policies enforced — block devices without encryption, without PIN, or with outdated OS from accessing corporate resources.
Operations (controls 19-20)
19. Security alerts configured — at minimum for suspicious sign-in attempts, configuration changes, and new admin role assignments. Without alerts, breaches go undetected for weeks.
20. Incident response plan documented — what does your team do when something goes wrong? Who is called? What gets shut down? A documented plan reduces response time from days to hours.
How many controls do you have active?
- 0-5: Your tenant is exposed. You need an urgent audit.
- 6-12: You have the basics but there are significant gaps.
- 13-17: Good posture, but the remaining gaps are what attackers exploit.
- 18-20: Excellent. Now maintain continuous monitoring.
Don't guess — measure. Our free scanner checks these controls as part of the current 201-rule library. The preview typically appears in minutes. The complete report is delivered on a best-effort basis, with a non-guaranteed estimated target of up to 1 hour.
Scan your Microsoft 365 + Azure for free →
What if you score below 13?
Most SMBs score between 6 and 12 on their first scan. That's normal — Microsoft 365's default settings prioritize usability over security.
The good news: most of these controls can be enabled in under an hour without interrupting your team. The hard part is knowing which ones to prioritize.
Our free Auditoría gives you a prioritized action plan with exact implementation steps, estimated time per fix, and a 30-minute results walkthrough. Everything you need to go from "6" to "18" in a matter of weeks.
For ongoing monitoring after the fixes, Operación runs the full 201-rule scan every week and alerts you if anything changes.
Is your business protected?
A free Microsoft 365 audit—the automated scan delivers a preview in 90 seconds. Find risks before they become incidents.