Resources
Microsoft 365 security configuration checklist.
The most important Microsoft 365 security configuration items based on CIS Benchmark Level 1 recommendations. A practical starting point for any organisation reviewing its M365 security posture.
Identity and access
Identity and access management.
- MFA enabled for all users, including admins
- Legacy authentication protocols disabled
- Global Administrator accounts are cloud-only and dedicated
- Break-glass accounts exist and are monitored
- No fewer than 2 and no more than 4 Global Admins
- Password expiry disabled (MFA is the primary control)
- Privileged Identity Management (PIM) configured where licensed
- Guest access reviewed and restricted
- User consent for OAuth applications disabled or restricted
Email and collaboration
Exchange Online and Teams.
- SPF, DKIM, and DMARC configured for all sending domains
- Anti-phishing policies with impersonation protection enabled
- Safe Attachments policy enabled (requires Defender P1)
- Safe Links policy enabled (requires Defender P1)
- External mail forwarding disabled or restricted
- Teams external access configured with known-good domains only
- Anonymous meeting join disabled or restricted
Audit and monitoring
Audit logs and alerting.
- Unified audit log enabled and retention period set
- Admin activity audit logging enabled
- Microsoft Secure Score reviewed and tracked
- Alert policies configured for high-severity events
- Mailbox auditing enabled for all mailboxes
- Security & Compliance alerts reviewed regularly
This checklist is a starting point, not a full assessment.
The CIS Microsoft 365 Benchmark Level 1 contains significantly more controls than those listed here. This checklist covers the highest-impact items. A full Datatechs assessment covers every applicable control with pass/fail status, evidence, and remediation guidance.
Want a complete assessment of your M365 environment?
The Datatechs CIS M365 Benchmark assessment covers all applicable controls with a written report and remediation plan.
