Microsoft 365 security depends on how identities, administrator access, email, sharing, devices and recovery are managed day to day. Start with a current inventory and named owners, protect access with appropriate controls, check the configuration that supports real working practices and repeat the review as users, suppliers and services change.

Start with identities and administrator roles

Microsoft 365 accounts are the route to email, files, collaboration and administration, so identity ownership comes first. Maintain a current list of users, shared mailboxes, guests, service accounts and administrators. Define who approves new access, role changes and leavers, and ensure that recovery details are controlled. The goal is to make the normal lifecycle safe and repeatable rather than relying on an emergency tidy-up after a person has left or a supplier relationship changes.

Use appropriate multi-factor authentication and reduce standing administrative access to the people and accounts that genuinely need it. Separate ordinary user work from privileged administration where the service design supports that approach. Document emergency or recovery access carefully, including who can use it and how it is protected. Check sign-in and role information regularly enough to identify unexpected activity or access that no longer reflects a business responsibility.

  • Current users, guests, shared mailboxes and service-account ownership.
  • Appropriate multi-factor protection and secure recovery arrangements.
  • Named administrator accounts with limited, justified privileges.
  • Joiner, mover and leaver process with accountable approvals.

Administer Microsoft 365 with clear ownership

Microsoft’s planning guidance is a useful starting point for considering the tenant, domains, licences, users and services before making changes. Translate that planning into a local operating model: who owns tenant-wide configuration, which external providers have access, where configuration decisions are recorded and how a change is tested before it affects many users. Keep enough documentation for the business to understand its own service, without storing sensitive credentials in ordinary files.

Review privileged roles and delegated administration periodically. Remove access that is no longer needed and investigate accounts whose purpose is unclear. When using a third party, agree the route for requesting work, approving material changes and reporting an incident. Administration should improve control and continuity, not leave a business unable to understand who can access its tenant or how a critical change can be reversed.

  • Tenant, domain, licence and service configuration ownership.
  • Privileged-role and external-provider access reviews.
  • Documented change, testing and rollback considerations.
  • A secure route for handling credentials and recovery information.

Protect email, sharing and collaboration

Email and shared information are frequent routes for both legitimate collaboration and avoidable exposure. Review anti-phishing and impersonation controls, external forwarding, mail-flow rules, shared mailbox permissions and the route for reporting suspicious messages. The exact settings should reflect the organisation’s services and working patterns; a control that users cannot understand may lead to unapproved workarounds, while an overly broad setting can expose information unnecessarily.

Apply the same thought to Teams, SharePoint and OneDrive. Identify who can create or approve external sharing, how guest access is reviewed and how sensitive files are handled. ICO data-security guidance supports a risk-based approach: understand the information involved, use appropriate technical and organisational measures and make responsibilities clear. A periodic permission and sharing review provides a practical way to catch drift as projects and external relationships change.

  • Email protection, forwarding and mail-flow rule governance.
  • Shared mailbox, group and delegated-access ownership.
  • External sharing and guest-access decisions that match business need.
  • A reporting route for suspicious email and access concerns.

Manage devices that reach business data

A secure tenant can still be affected by a poorly managed device. Identify which device types can access business information, whether they are supported, how updates are applied and what happens if a device is lost, replaced or shared. Use configuration and access controls appropriate to the organisation’s risks and the services involved. Record where a device or application falls outside the managed standard so that the business can make an informed decision rather than assume it is protected.

NCSC guidance for small organisations emphasises keeping devices and software updated, managing access and preparing for incidents. Apply those principles to laptop, mobile and remote-working arrangements. Test the practical support route as well as the technical setting: a user should know how to report a lost device, unexpected sign-in prompt or access problem without delaying because they are unsure who is responsible.

  • Supported-device, update and ownership information.
  • Access conditions appropriate to devices and business data.
  • Lost-device, replacement and remote-working escalation steps.
  • Visible exceptions where a device cannot meet the normal standard.

Plan recovery and repeat the checks

Recovery is more than retaining data. Decide which mailboxes, files, collaboration services and identity functions are important to the business, who makes decisions during a disruption and what restore or recovery capability is available. Clarify the distinction between service availability, retention, backup and a tested recovery process. These are related but not interchangeable, and the right arrangement depends on the business information, dependency and continuity needs.

Set a repeatable review cadence for inactive accounts, privileged roles, sharing links, security alerts, licences, devices and documented exceptions. Repeat the review after major supplier, staff or system changes. Record actions with named owners and dates so that a list of concerns becomes an improvement plan. The most useful checklist is one that continues to guide routine administration rather than being filed away after a single configuration exercise.

  • Recovery priorities for identity, email, files and collaboration.
  • Retention, backup and restore responsibilities documented separately.
  • Regular access, privilege, device and sharing reviews.
  • Named actions for alerts, exceptions and material changes.

Make secure working practical for people

Technical controls depend on people knowing what to do when something changes. Provide a straightforward route for access requests, sharing questions, suspicious email reports and lost-device concerns. Explain the few actions that users need to take, such as protecting sign-in prompts and reporting unexpected activity promptly. This makes the security model easier to follow than a long policy people cannot use in the moment.

Use findings from support requests and recurring incidents to improve configuration and guidance. If staff repeatedly need an exception, investigate the underlying business need and decide whether the standard should change, the process should be clarified or an additional control is required. The aim is a service that protects information while allowing legitimate work to happen through understood, supported routes.

  • Simple routes for requests, concerns and security reporting.
  • Useful guidance for sign-in, sharing and device issues.
  • Recurring exceptions investigated rather than normalised silently.
  • Improvements agreed around real working practices and risks.

Configuration must match the tenant and business context

This checklist is a planning aid, not a universal configuration template. Microsoft 365 licences, services, data types, devices, suppliers and working practices vary, so changes should be assessed and tested in the relevant tenant before they are applied broadly. It does not replace a documented risk decision where a legacy system, contractual requirement or legitimate operational need prevents the normal control from being applied.

Questions for the person accountable for Microsoft 365

Use these questions to make ownership and the next review visible.

  • Who owns users, administrator roles and emergency access?
  • Which sharing and email settings need a documented business decision?
  • Which devices can access business data and how are exceptions handled?
  • What recovery capability has been confirmed for the services that matter most?