Countdown until the UK analogue phone switch-off on 31 January 2027.Is your business affected?
Free Tool

Microsoft 365 Security Baseline Check

Fifteen guided checks against your own tenant — MFA enforcement, legacy authentication, admin hygiene, mailbox auditing, external sharing and backup — each with guidance on where to look in the admin centres. Instant results, printable report.

Quick answer

This free self-check walks a Microsoft 365 admin through fifteen baseline security checks on their own tenant: MFA enforcement via security defaults or Conditional Access, legacy authentication blocking, Global Administrator count and separation, break-glass account, mailbox auditing, Defender for Office 365 anti-phishing policies, SharePoint and Teams external sharing defaults, independent backup and account lifecycle. Each check explains where to look; "not sure" counts as a gap, because in Microsoft 365 unverified usually means unconfigured.

Microsoft 365 Security Baseline Check

Fifteen checks against your own tenant, each with guidance on where to look. You’ll need admin access to the Microsoft 365 admin centre, the Entra admin centre and the Defender portal. "Not sure" counts as a gap — in M365 security, unverified usually means unconfigured.

  1. 1.Is MFA enforced for all users — via security defaults or Conditional Access policies?

    Entra admin centre: security defaults live under tenant Properties; Conditional Access policies under Protection. If you can sign in from a new device with only a password, it isn’t enforced.

  2. 2.Is legacy authentication (old protocols like IMAP/POP/SMTP basic auth that bypass MFA) blocked?

    Look for a Conditional Access policy blocking legacy authentication clients, or confirm security defaults are on (they include this). Sign-in logs show whether legacy auth is still being attempted.

  3. 3.Does every admin account have MFA registered — not just enabled?

    Entra admin centre: check the MFA registration status of each user holding an admin role.

  4. 4.Is self-service password reset configured for users?

    Entra admin centre, under password reset settings. Reduces helpdesk resets and the social-engineering surface that comes with them.

  5. 5.How many Global Administrators does the tenant have?

    Entra admin centre: review role assignments. Microsoft’s guidance is a small number (typically two to four), each a dedicated admin account.

  6. 6.Are admin accounts separate from the accounts people use for email and day-to-day work?

  7. 7.Is there a documented emergency-access ("break-glass") account excluded from Conditional Access, with credentials stored securely offline?

  8. 8.Is mailbox auditing enabled for the tenant?

    On by default in modern tenants, but worth verifying — check audit configuration in the Purview/compliance portal. If the tenant is old, it may pre-date the default.

  9. 9.Are anti-phishing policies configured in Defender for Office 365 (impersonation protection, spoof intelligence)?

    Defender portal, under email & collaboration policies. The preset security policies (Standard/Strict) are the quick route.

  10. 10.Are Safe Links and Safe Attachments enabled (where your licensing includes Defender for Office 365)?

  11. 11.Can you search the unified audit log when you need to investigate something?

    Purview portal: audit search. Try an actual search — availability and retention depend on licensing.

  12. 12.Have SharePoint and OneDrive default sharing settings been reviewed — with "Anyone" links not the default?

    SharePoint admin centre, sharing settings. The question is whether someone chose the current setting deliberately.

  13. 13.Has Teams external access (which outside organisations can chat/call your users) been deliberately configured?

    Teams admin centre, external access settings. Default is open federation with every Microsoft 365 tenant.

  14. 14.Is Microsoft 365 data (mail, SharePoint, OneDrive, Teams) backed up independently of Microsoft’s retention?

    Retention policies are not backup: they don’t protect against admin error, sync corruption or a compromised admin. Independent backup is a separate product.

  15. 15.Are leaver accounts disabled promptly and stale accounts/licences reviewed?

0/15 answered — results are calculated in your browser.

Self-check, then verify properly

undefined

Run the checklist

Fifteen checks with where-to-look guidance. You'll need admin access to the Microsoft 365, Entra and Defender portals.

undefined

Fix the obvious gaps

MFA enforcement, legacy auth blocking and admin separation are the highest-impact fixes — most tenants can close them in days.

undefined

Book the read-only review

For a definitive picture, AMVIA's engineers run an assisted read-only tenant review — settings interact in ways a checklist can't see.

What the baseline covers

Identity & MFA

MFA enforced for everyone, legacy authentication blocked, admin MFA verified — the front door of the tenant.

Admin hygiene

A small, dedicated set of Global Administrators, separated from daily accounts, with a documented break-glass account.

Email protection & auditing

Mailbox auditing verified on, anti-phishing policies configured, Safe Links and Safe Attachments where licensed.

External sharing

SharePoint, OneDrive and Teams sharing configured deliberately rather than left at open defaults.

Backup & lifecycle

Independent backup of M365 data — retention is not backup — plus leaver and licence discipline.

Private by design

The check runs in your browser against your own eyes on your own tenant. We never see your settings.

Want engineers' eyes on the tenant?

AMVIA's assisted read-only tenant review checks what a checklist can't — policy interactions, licensing fit and the settings behind the settings. Delivered by the Microsoft MSSP team that runs managed M365 day to day.