Microsoft 365 Security Checklist for Australian Small Businesses
Most Microsoft 365 environments are not as secure as their owners assume. Default settings, accumulated permissions and years of unreviewed configuration leave gaps that are visible to anyone who looks. This checklist covers the 15 controls that matter most for an Australian SMB — not as a compliance exercise, but as a practical test of whether your environment is actually defensible.
Before working through the checklist: Microsoft 365 security is not primarily about buying the right product. It is about configuration. A Business Premium licence gives you the tools. Whether those tools are actually turned on and configured correctly is a different question entirely.
The 15 controls to check
- 1
MFA is enabled for every user without exception
Multi-factor authentication is the single most effective control against account compromise. Enabling it for most users and leaving it off for one or two (usually a senior person who found it inconvenient) defeats the purpose. Attackers target the exception.
- 2
Admin accounts have separate, dedicated credentials
Global Administrator accounts should not be used for day-to-day email and browsing. A compromised admin account gives an attacker full control of your tenant. Admins should have separate, non-email accounts used only when performing administrative tasks.
- 3
The number of Global Administrators is minimal
Most small businesses have three to five Global Admins when they need one or two. Each additional admin account is an additional attack surface. Use role-specific admin roles (Exchange Admin, Teams Admin, etc.) for everything that does not require Global Admin.
- 4
An emergency access (break-glass) account exists and is documented
A break-glass account is a Global Admin account that is excluded from Conditional Access policies and MFA, stored securely offline, and used only if normal admin access is lost. Every tenant should have one, and it should be monitored for any sign of use.
- 5
Conditional Access policies are configured
Security Defaults give you basic MFA. Conditional Access gives you granular control: block legacy authentication, require MFA always, require compliant devices, block access from high-risk locations. This requires an Entra ID P1 licence (included in Business Premium).
- 6
Legacy authentication protocols are blocked
Older protocols like SMTP, IMAP, and POP3 do not support modern MFA. Attackers use them specifically because they bypass your MFA controls. If your organisation has no legitimate use for legacy auth, block it via Conditional Access.
- 7
Automatic external email forwarding is disabled
Attackers who compromise an account often set up forwarding rules to an external address and sit quietly reading your email. Microsoft has controls to prevent this, but they need to be configured. Check your Exchange transport rules and individual mailbox rules.
- 8
SharePoint and OneDrive external sharing is reviewed and restricted
Default SharePoint settings allow users to share documents with anyone via link, with no expiry. Understand what your current sharing settings are, who has been granted external access, and whether those permissions are still appropriate.
- 9
Microsoft Defender for Office 365 is configured
If you are on Business Premium, you have Defender for Office 365 Plan 1. Safe Links rewrites URLs in email and checks them at click time. Safe Attachments detonates email attachments in a sandbox before delivery. Neither is on by default — both need to be configured.
- 10
Intune device compliance policies are in place
If staff use personal or unmanaged devices to access Microsoft 365, you have no visibility or control over what those devices do with your data. Intune device compliance policies define minimum requirements (encryption, PIN, OS version) and can block non-compliant devices via Conditional Access.
- 11
Unified audit logging is enabled
Audit logging records what happens in your Microsoft 365 tenant: who signed in, what was accessed, what changed, what was deleted. Without it, investigating any incident is close to impossible. Confirm that unified audit log is enabled and that retention is set to an appropriate period.
- 12
Guest and external users are reviewed
Every person who has ever been invited to a Teams channel or SharePoint site exists as a guest account in your Entra ID. Review who they are, whether they still need access, and whether their permissions are appropriately scoped.
- 13
Third-party application permissions are reviewed
Applications connected to your Microsoft 365 tenant via OAuth can read email, access files, and take actions on behalf of users. Review what is connected, what permissions those applications have, and whether each one is still in use.
- 14
Offboarding procedure is documented and tested
When a staff member leaves, their account, active sessions, shared mailbox access, Teams membership, SharePoint permissions, mobile device access, and any delegated admin roles all need to be addressed. Most organisations handle some of these. Very few handle all of them, same day.
- 15
Microsoft Secure Score is reviewed and tracked
Microsoft Secure Score gives you a numeric measure of your tenant's security posture based on your current configuration. It is not a perfect measure, but it provides a baseline and tracks whether things are improving over time. Review it, understand what the recommendations mean, and prioritise accordingly.
What this checklist is not
This list covers the controls that catch the majority of Microsoft 365 security incidents. It does not cover data loss prevention policy, Microsoft Purview information protection, privileged identity management, advanced threat hunting, or the full range of Defender for Endpoint capabilities. Those are relevant for environments with more complex requirements.
MFA being enabled does not mean the tenant is secure. A checklist of ticked boxes does not mean anything if the configuration behind those boxes is incorrect. What matters is whether the controls are actually implemented and working, not whether someone has theoretically turned them on.
If you go through this list and find more than two or three unchecked items, your environment has meaningful security gaps. The controls listed here are not advanced security — they are the baseline. Finding gaps at this level means the environment has not been actively managed.
Next step
Cloud Security Baseline
The Cloud Security Baseline implements these controls in your Microsoft 365 environment: MFA enforcement, Conditional Access policies, Defender configuration, Intune device compliance, and Secure Score baseline. Fixed scope, fixed price, documented on completion.
Learn more