Skip to content
Resources

Microsoft 365 security configuration checklist.

The most important Microsoft 365 security configuration items based on CIS Benchmark Level 1 recommendations. A practical starting point for any organisation reviewing its M365 security posture.

Identity and access

Identity and access management.

  • MFA enabled for all users, including admins
  • Legacy authentication protocols disabled
  • Global Administrator accounts are cloud-only and dedicated
  • Break-glass accounts exist and are monitored
  • No fewer than 2 and no more than 4 Global Admins
  • Password expiry disabled (MFA is the primary control)
  • Privileged Identity Management (PIM) configured where licensed
  • Guest access reviewed and restricted
  • User consent for OAuth applications disabled or restricted
Email and collaboration

Exchange Online and Teams.

  • SPF, DKIM, and DMARC configured for all sending domains
  • Anti-phishing policies with impersonation protection enabled
  • Safe Attachments policy enabled (requires Defender P1)
  • Safe Links policy enabled (requires Defender P1)
  • External mail forwarding disabled or restricted
  • Teams external access configured with known-good domains only
  • Anonymous meeting join disabled or restricted
Audit and monitoring

Audit logs and alerting.

  • Unified audit log enabled and retention period set
  • Admin activity audit logging enabled
  • Microsoft Secure Score reviewed and tracked
  • Alert policies configured for high-severity events
  • Mailbox auditing enabled for all mailboxes
  • Security & Compliance alerts reviewed regularly

This checklist is a starting point, not a full assessment.

The CIS Microsoft 365 Benchmark Level 1 contains significantly more controls than those listed here. This checklist covers the highest-impact items. A full Datatechs assessment covers every applicable control with pass/fail status, evidence, and remediation guidance.

Want a complete assessment of your M365 environment?

The Datatechs CIS M365 Benchmark assessment covers all applicable controls with a written report and remediation plan.