Toolkit · Security · about 5 minutes
Microsoft 365 Security Check
Most SME compromises begin in a mailbox, not at a firewall. These questions cover the tenant settings that decide whether an attacker who has one password gets anything further.
23 questions. Nothing is sent anywhere as you answer — the scoring runs in your browser, and we only receive anything if you ask for the written version at the end.
Identity
The front door to the tenant.
Is multi-factor authentication enforced for every administrator account?
Has legacy authentication been blocked?
POP, IMAP and SMTP basic auth bypass MFA entirely. If they are still enabled, MFA is optional in practice.
Is MFA enforced for all users, not only administrators?
Are there Conditional Access policies restricting sign-in by location, device or risk?
Are Global Administrator accounts limited to a small number, separate from daily-use accounts?
Is there a break-glass account, excluded from Conditional Access and stored securely offline?
Email security
Where the money actually leaves.
Are automatic external mail forwarding rules blocked or alerted on?
The standard invoice-fraud pattern: a rule quietly forwards finance mail to an attacker for weeks.
Are SPF, DKIM and DMARC configured for every sending domain?
Is Safe Links and Safe Attachments, or an equivalent, enabled?
Are external senders visibly tagged in the client?
Is impersonation protection configured for your executives and finance team?
Data and sharing
What leaves SharePoint and OneDrive.
Are external sharing defaults restricted rather than "anyone with the link"?
Do you know which files are currently shared externally, and with whom?
Are sensitivity labels or DLP policies applied to regulated data?
Are guest accounts reviewed and removed when no longer needed?
Devices
What is allowed to reach company data.
Are devices enrolled in Intune or an equivalent, with compliance policies enforced?
Is disk encryption enforced and its status reported centrally?
Can a lost or stolen device be wiped remotely?
Is personal-device access to company data controlled rather than unrestricted?
Monitoring and recovery
Whether you would notice, and what you could restore.
Is Microsoft 365 data backed up to a third-party service?
Microsoft protects the platform, not your data. Retention policies are not backup — a deleted or encrypted mailbox past the retention window is gone.
Is unified audit logging enabled, and would you have the history to investigate a compromise?
Do risky sign-ins and admin changes generate an alert someone actually sees?
Do you review the Secure Score or an equivalent baseline periodically?