Microsoft 365 security protecting business email, files and cloud applications
Microsoft 365 Security

Microsoft 365 Security Checklist for Australian Businesses

Microsoft 365 has become central to how many organisations communicate, collaborate and store business information.

Email, Teams, SharePoint, OneDrive and Microsoft cloud services can contain some of an organisation's most important information. That makes the security of user identities, devices and data increasingly important.

Microsoft provides a broad range of security controls, but the protections available and how they should be configured depend on your Microsoft 365 licensing, users, devices and business requirements.

This checklist provides a practical starting point for reviewing the security of a Microsoft 365 environment.

Microsoft 365 Security

Start With the Areas That Matter Most

01
Identity & MFA

Protect accounts and strengthen the way users sign in.

02
Email Security

Reduce phishing, malicious links and account compromise.

03
Devices & Applications

Control how business information is accessed.

04
Sharing & Data

Review SharePoint, OneDrive, Teams and external access.

05
Monitoring & Recovery

Maintain visibility and prepare for security incidents.

Microsoft 365 security is not a single setting. Effective protection comes from combining identity, device, email, application and information security controls.

Security Beyond the Basics

Microsoft 365 Is Powerful, But Configuration Matters

Microsoft 365 includes security capabilities across identity, email, applications, devices and data. However, simply using Microsoft 365 does not mean every available security control is configured for your organisation.

01

Identity

User accounts are the gateway to email, files, Teams and other Microsoft cloud services.

02

Email

Phishing and fraudulent messages can target employees through everyday business communication.

03

Devices

Business information may be accessed from laptops, desktops and mobile devices in multiple locations.

04

Information

SharePoint, OneDrive and Teams can contain sensitive business information requiring appropriate protection.

Microsoft 365 security should be reviewed as an environment.

Identity, email, devices, applications, sharing and data protection are interconnected. Improving one area while overlooking another can leave unnecessary gaps.

Checklist 01

Enable and Review Multi-Factor Authentication

Protecting user identities is one of the most important parts of Microsoft 365 security. Multi-factor authentication adds an additional verification step when users sign in.

01

Protect All Users

Review MFA coverage across the organisation rather than protecting only selected employees.

02

Protect Administrators

Privileged accounts require particular attention because of the level of access they can provide.

03

Review Authentication Methods

Understand which authentication methods are being used and adopt stronger methods where appropriate.

04

Review Sign-In Policies

Where licensing and requirements permit, consider additional identity and access controls based on the organisation's security requirements.

A Simple Security Question

If a Microsoft 365 Password Was Stolen, What Would Happen Next?

Consider whether another authentication control would prevent access, whether suspicious sign-in activity would be detected and how quickly your team could respond.

Checklist 02

Review Administrator and Privileged Access

Administrator accounts can make significant changes across a Microsoft 365 environment. Privileged access should therefore be controlled carefully.

01

Review which users currently hold administrator roles.

02

Remove administrator access that is no longer required.

03

Avoid assigning excessive privileges simply for convenience.

04

Use individual accounts rather than shared administrator credentials wherever practical.

05

Ensure privileged accounts are appropriately protected with strong authentication.

Checklist 03

Strengthen Email Security

Email is one of the most frequently used Microsoft 365 services and a common target for phishing, impersonation, malicious links and fraudulent payment requests.

Email security should be reviewed alongside user identity protection because successful phishing attempts often aim to obtain credentials or persuade users to approve a fraudulent request.

Available protections will vary depending on Microsoft licensing and the wider security environment.

Email Security Review

Areas to Consider

✓

Anti-phishing protection

✓

Malicious attachment protection

✓

Suspicious and malicious links

✓

Impersonation and spoofing protection

✓

Mailbox forwarding rules

✓

User reporting of suspicious email

Checklist 04

Understand Which Devices Access Microsoft 365

Microsoft 365 can be accessed from many locations and devices. Businesses should understand how company information is being accessed and what controls apply to those devices.

01

Device Visibility

Maintain an understanding of which business devices are accessing company information.

02

Security Updates

Ensure supported devices receive operating system and application security updates.

03

Endpoint Protection

Use appropriate endpoint protection and monitoring based on the organisation's security requirements.

04

Device Management

Consider centralised device management where appropriate to apply security policies and improve visibility.

Checklist 05

Review SharePoint, OneDrive and External Sharing

Microsoft 365 makes collaboration easy, including sharing information with people outside the organisation. That flexibility should be balanced with appropriate controls.

01

External Sharing

Review how SharePoint and OneDrive information can be shared outside the organisation.

02

Guest Users

Periodically review external and guest accounts and remove access that is no longer required.

03

Site Permissions

Review access to SharePoint sites containing financial, operational or other sensitive information.

04

Sharing Practices

Help employees understand the appropriate way to share business information internally and externally.

Access changes over time.

A permission or guest account that was appropriate when it was created may no longer be required months or years later. Regular access reviews can help identify unnecessary access.

Checklist 06

Understand and Protect Sensitive Information

Before an organisation can protect sensitive information effectively, it needs to understand what information it holds, where it is stored and who should have access to it.

01

Identify

Understand where financial, personal, contractual and other sensitive business information is stored.

02

Control

Review who can access sensitive information and whether that access remains appropriate.

03

Protect

Where appropriate, consider Microsoft information protection and data loss prevention capabilities available within your licensing.

Checklist 07

Review Security Alerts, Sign-Ins and Audit Information

Security controls help reduce risk, but organisations also need visibility when unusual or suspicious activity occurs.

01

Review suspicious sign-in activity and security alerts.

02

Understand what Microsoft 365 audit information is available under the organisation's licensing.

03

Ensure important security notifications are reaching the appropriate people.

04

Investigate unexpected changes to user accounts, administrator roles and mailbox settings.

05

Establish a process for escalating suspicious activity when further investigation is required.

Checklist 08

Review Microsoft 365 Backup and Recovery

Microsoft 365 provides resilience and native retention and recovery capabilities, but organisations should still consider their own requirements for protecting and recovering business information.

01

Define What Matters

Identify the Microsoft 365 data the organisation depends on, including Exchange, SharePoint and OneDrive information.

02

Understand Recovery

Understand available retention, recovery and backup arrangements and whether they meet business requirements.

03

Test Restoration

Where backups are maintained, periodically verify that important information can be restored when required.

Retention and backup solve different requirements.

Review your organisation's recovery objectives rather than assuming that simply storing information in Microsoft 365 provides the recovery arrangement the business requires.

Checklist 09

Review Your Microsoft 365 Licensing

Microsoft 365 security capabilities vary considerably between licence plans and security add-ons.

A business may identify a security control it wants to implement only to discover that the required capability is not included in its current licences.

Reviewing licensing alongside security requirements can help determine which controls are already available, which require configuration and where an uplift may be appropriate.

Licensing Review

Ask These Questions

✓

Which Microsoft 365 licences are currently assigned?

✓

Which security features are already available?

✓

Are available controls actually configured?

✓

Are different users on different licence levels?

✓

Would an uplift address a genuine security requirement?

Quick Review

Microsoft 365 Security Checklist

If you are reviewing an existing Microsoft 365 environment, these questions provide a useful starting point.

✓

Is MFA enabled across the organisation?

✓

Are administrator accounts and privileges regularly reviewed?

✓

Are appropriate email and anti-phishing controls configured?

✓

Do you know which devices are accessing Microsoft 365?

✓

Are SharePoint and OneDrive external sharing settings appropriate?

✓

Are guest users and external access periodically reviewed?

✓

Do you know where sensitive business information is stored?

✓

Are security alerts, sign-ins and audit information reviewed?

✓

Do backup and recovery arrangements meet business requirements?

✓

Have you reviewed whether your licensing supports the security controls you need?

City Systems

Microsoft 365 Security With a Practical Approach

City Systems helps Australian organisations review and improve the security of their Microsoft 365 environments.

This can include identity and MFA, Microsoft 365 security configuration, device management, email protection, data security, backup and recovery, monitoring and cyber security awareness.

City Systems is ISO 27001 certified, supporting a structured approach to information security, risk management and the protection of client information.

Microsoft 365 Security Review

✓

Identity & MFA

✓

Administrator access

✓

Email security

✓

Device management & security

✓

SharePoint, OneDrive & Teams

✓

Backup, monitoring & recovery

Microsoft 365 Security Review

How Secure Is Your Microsoft 365 Environment?

City Systems can review your existing Microsoft 365 environment, licensing and security configuration and help identify practical areas for improvement.