Microsoft 365 security begins with identity. If an attacker gains control of a user or administrator account, they may be able to read email, change rules, access shared files and impersonate the business. This checklist gives Yorkshire SMEs a practical starting point, but settings should be matched to licence, risk and operational needs.
Protect identities and administrator access
- Require multi-factor authentication using appropriate modern methods
- Block legacy authentication where it is not required
- Use separate named administrator accounts
- Keep emergency access arrangements tightly controlled and monitored
- Review sign-in risk, unusual locations and repeated failures
- Remove leavers promptly and review dormant accounts
Reduce email and collaboration risk
Review anti-phishing, impersonation and malicious-link protection. Configure email authentication for your domains and monitor reports. Users should know how to report suspicious messages without forwarding harmful content around the business.
Check external sharing in SharePoint, OneDrive and Teams. Public or anonymous links should be deliberate, time-limited where appropriate and reviewed regularly. Guest accounts need an owner and a business purpose.
Bring devices into the security boundary
Cloud controls are weakened if an unmanaged or infected device can download sensitive data. Maintain an inventory, require supported software, encrypt storage and apply appropriate device-management and endpoint-protection policies across Windows, Mac and mobile platforms. MSP247’s RMM supports all major platforms and helps identify health and update issues early.
Plan for recovery and investigation
Decide how long logs are retained and who will investigate an alert. Document the steps for a compromised account: disable access, revoke sessions, reset credentials, inspect forwarding rules, preserve evidence and communicate safely. Test the process before a real incident.
Retention settings and recycle bins are not automatically a complete backup strategy. Confirm whether independent backup is required for email, OneDrive, SharePoint and collaboration data, and test actual restores.
Review continuously
Security settings change as Microsoft adds features, licences are altered and staff join or leave. Schedule regular reviews of privileged roles, sharing, application consent, mail rules, device compliance and backup status. Record exceptions and assign an owner.
Turn the checklist into a prioritised plan
MSP247’s free business IT review includes Microsoft 365 security, backup, device management, connectivity and supplier gaps. We can identify quick wins and build a proportionate improvement roadmap for your organisation.

