← Insights and resources

Microsoft 365 security

Microsoft 365 security: a practical control guide

A secure Microsoft 365 environment starts with phishing-resistant access for privileged roles, controlled administration, protected email and collaboration settings, managed devices, useful audit data and a tested response process. Secure Score can help prioritise improvements, but each recommendation still needs to be assessed against business context and existing controls.

Practical assessment guideReviewed UK organisations

Control checklist

What to verify first.

Use evidence from the real environment. A written policy without current configuration, ownership or testing is not enough.

  1. Require strong multi-factor authentication for every administrator and high-risk account.

  2. Separate day-to-day user accounts from privileged administration accounts.

  3. Review Global Administrator, role assignments and emergency-access accounts.

  4. Protect Exchange Online against impersonation, malicious forwarding and risky attachments.

  5. Set intentional SharePoint, OneDrive, Teams and guest-sharing boundaries.

  6. Connect managed-device and sign-in risk to access decisions where licensing permits.

  7. Retain the audit and sign-in evidence needed for investigation and assurance.

  8. Test the account-compromise and tenant-recovery process with named owners.

Decision flow

Move from uncertainty to evidence.

The sequence keeps discovery, control changes and proof connected.

  1. 01

    Inventory

    Identify tenants, domains, administrators, licences and connected applications.

  2. 02

    Prioritise

    Address privileged access, active exposure and high-impact misconfiguration first.

  3. 03

    Control

    Deploy changes in monitored stages with owners and rollback decisions.

  4. 04

    Evidence

    Retain configuration, exceptions, reviews and response tests.

Assessment template

Record control status and evidence.

Use the blank fields in a workshop or print this page. Mark a control evidenced only when the supporting record is current and attributable.

Control areaEvidence to locateStatusOwner / action
Privileged access Administrator inventory, role review date and MFA method Gap Partial Evidenced
Email protection Anti-phishing, forwarding and attachment policy export Gap Partial Evidenced
External sharing Tenant defaults, exception owners and guest review Gap Partial Evidenced
Device access Compliance policy and unmanaged-device decision Gap Partial Evidenced
Detection and recovery Audit retention, alert owner and tested playbook Gap Partial Evidenced

Related service

Cloud & Identity Security

Review and improve Microsoft 365 identity, privilege, sharing, device and audit controls through a defined managed service.

Explore Cloud & Identity SecurityDiscuss this assessment

Official sources

Continue with primary guidance.

Requirements and platform capabilities change. Confirm time-sensitive decisions against the current source.

Related analysis

Apply the guide to current risks.

Start with a conversation

Turn the assessment into an owned plan.

Share the scope, evidence and highest-priority gap. We’ll help define a proportionate next step for your environment.

Talk to an expert