Microsoft 365 security
Microsoft 365 security: a practical control guide
A secure Microsoft 365 environment starts with phishing-resistant access for privileged roles, controlled administration, protected email and collaboration settings, managed devices, useful audit data and a tested response process. Secure Score can help prioritise improvements, but each recommendation still needs to be assessed against business context and existing controls.
Control checklist
What to verify first.
Use evidence from the real environment. A written policy without current configuration, ownership or testing is not enough.
Require strong multi-factor authentication for every administrator and high-risk account.
Separate day-to-day user accounts from privileged administration accounts.
Review Global Administrator, role assignments and emergency-access accounts.
Protect Exchange Online against impersonation, malicious forwarding and risky attachments.
Set intentional SharePoint, OneDrive, Teams and guest-sharing boundaries.
Connect managed-device and sign-in risk to access decisions where licensing permits.
Retain the audit and sign-in evidence needed for investigation and assurance.
Test the account-compromise and tenant-recovery process with named owners.
Decision flow
Move from uncertainty to evidence.
The sequence keeps discovery, control changes and proof connected.
- 01
Inventory
Identify tenants, domains, administrators, licences and connected applications.
- 02
Prioritise
Address privileged access, active exposure and high-impact misconfiguration first.
- 03
Control
Deploy changes in monitored stages with owners and rollback decisions.
- 04
Evidence
Retain configuration, exceptions, reviews and response tests.
Assessment template
Record control status and evidence.
Use the blank fields in a workshop or print this page. Mark a control evidenced only when the supporting record is current and attributable.
Related service
Cloud & Identity Security
Review and improve Microsoft 365 identity, privilege, sharing, device and audit controls through a defined managed service.
Official sources
Continue with primary guidance.
Requirements and platform capabilities change. Confirm time-sensitive decisions against the current source.
Related analysis
Apply the guide to current risks.
July 2026 threat landscape: massive Patch Tuesday and supply chain disruption
Microsoft releases 570+ patches, CISA warns of Langflow vulnerabilities, and Coca-Cola suffers ransomware disruption. Speed of containment is paramount.
Read insight ↗
Dolphin X: the rise of AI-driven behavioral profiling in malware
Researchers report that Dolphin X is marketed with AI-assisted profiling designed to prioritize high-value targets. Here is what defenders should take from the claim.
Read insight ↗