Microsoft 365 security checklist for small businesses

These are the settings that matter most for a company of 5 to 500 people on Microsoft 365, in roughly the order to tackle them.

Updated October 4, 2026

Accounts and sign-in

  • MFA required for everyone, through security defaults or Conditional Access
  • Legacy authentication blocked
  • Two to four Global Administrators, using separate admin accounts
  • One emergency access account, excluded from Conditional Access and monitored
  • Leavers blocked and their sessions revoked on their last day

Email

  • Automatic external forwarding turned off, with named exceptions
  • No unexpected inbox rules that forward or hide mail
  • SPF, DKIM and DMARC set up for every domain
  • External sender tagging turned on
  • Mailbox auditing on

Apps and sharing

  • Users can't consent to apps that access company data without an admin
  • Existing app consents reviewed
  • Guest access reviewed and limited
  • SharePoint and OneDrive external sharing set to what you actually need

Run the checklist automatically

TenantWard checks each of these with a read-only connection, explains anything that fails and fixes most of them with one click. Weekly rechecks keep the list green.

See where your company stands

Check a domain for free, then connect Microsoft 365 or Google Workspace for the full checkup. Every new workspace gets a 7-day trial, no card needed.