
Microsoft 365 Security Checklist for Australian Businesses
Microsoft 365 has become central to how many organisations communicate, collaborate and store business information.
Email, Teams, SharePoint, OneDrive and Microsoft cloud services can contain some of an organisation's most important information. That makes the security of user identities, devices and data increasingly important.
Microsoft provides a broad range of security controls, but the protections available and how they should be configured depend on your Microsoft 365 licensing, users, devices and business requirements.
This checklist provides a practical starting point for reviewing the security of a Microsoft 365 environment.
Start With the Areas That Matter Most
Protect accounts and strengthen the way users sign in.
Reduce phishing, malicious links and account compromise.
Control how business information is accessed.
Review SharePoint, OneDrive, Teams and external access.
Maintain visibility and prepare for security incidents.
Microsoft 365 security is not a single setting. Effective protection comes from combining identity, device, email, application and information security controls.
Microsoft 365 Is Powerful, But Configuration Matters
Microsoft 365 includes security capabilities across identity, email, applications, devices and data. However, simply using Microsoft 365 does not mean every available security control is configured for your organisation.
Identity
User accounts are the gateway to email, files, Teams and other Microsoft cloud services.
Phishing and fraudulent messages can target employees through everyday business communication.
Devices
Business information may be accessed from laptops, desktops and mobile devices in multiple locations.
Information
SharePoint, OneDrive and Teams can contain sensitive business information requiring appropriate protection.
Identity, email, devices, applications, sharing and data protection are interconnected. Improving one area while overlooking another can leave unnecessary gaps.
Enable and Review Multi-Factor Authentication
Protecting user identities is one of the most important parts of Microsoft 365 security. Multi-factor authentication adds an additional verification step when users sign in.
Protect All Users
Review MFA coverage across the organisation rather than protecting only selected employees.
Protect Administrators
Privileged accounts require particular attention because of the level of access they can provide.
Review Authentication Methods
Understand which authentication methods are being used and adopt stronger methods where appropriate.
Review Sign-In Policies
Where licensing and requirements permit, consider additional identity and access controls based on the organisation's security requirements.
If a Microsoft 365 Password Was Stolen, What Would Happen Next?
Consider whether another authentication control would prevent access, whether suspicious sign-in activity would be detected and how quickly your team could respond.
Review Administrator and Privileged Access
Administrator accounts can make significant changes across a Microsoft 365 environment. Privileged access should therefore be controlled carefully.
Review which users currently hold administrator roles.
Remove administrator access that is no longer required.
Avoid assigning excessive privileges simply for convenience.
Use individual accounts rather than shared administrator credentials wherever practical.
Ensure privileged accounts are appropriately protected with strong authentication.
Strengthen Email Security
Email is one of the most frequently used Microsoft 365 services and a common target for phishing, impersonation, malicious links and fraudulent payment requests.
Email security should be reviewed alongside user identity protection because successful phishing attempts often aim to obtain credentials or persuade users to approve a fraudulent request.
Available protections will vary depending on Microsoft licensing and the wider security environment.
Areas to Consider
Anti-phishing protection
Malicious attachment protection
Suspicious and malicious links
Impersonation and spoofing protection
Mailbox forwarding rules
User reporting of suspicious email
Understand Which Devices Access Microsoft 365
Microsoft 365 can be accessed from many locations and devices. Businesses should understand how company information is being accessed and what controls apply to those devices.
Device Visibility
Maintain an understanding of which business devices are accessing company information.
Security Updates
Ensure supported devices receive operating system and application security updates.
Endpoint Protection
Use appropriate endpoint protection and monitoring based on the organisation's security requirements.
Device Management
Consider centralised device management where appropriate to apply security policies and improve visibility.
Review SharePoint, OneDrive and External Sharing
Microsoft 365 makes collaboration easy, including sharing information with people outside the organisation. That flexibility should be balanced with appropriate controls.
External Sharing
Review how SharePoint and OneDrive information can be shared outside the organisation.
Guest Users
Periodically review external and guest accounts and remove access that is no longer required.
Site Permissions
Review access to SharePoint sites containing financial, operational or other sensitive information.
Sharing Practices
Help employees understand the appropriate way to share business information internally and externally.
A permission or guest account that was appropriate when it was created may no longer be required months or years later. Regular access reviews can help identify unnecessary access.
Understand and Protect Sensitive Information
Before an organisation can protect sensitive information effectively, it needs to understand what information it holds, where it is stored and who should have access to it.
Identify
Understand where financial, personal, contractual and other sensitive business information is stored.
Control
Review who can access sensitive information and whether that access remains appropriate.
Protect
Where appropriate, consider Microsoft information protection and data loss prevention capabilities available within your licensing.
Review Security Alerts, Sign-Ins and Audit Information
Security controls help reduce risk, but organisations also need visibility when unusual or suspicious activity occurs.
Review suspicious sign-in activity and security alerts.
Understand what Microsoft 365 audit information is available under the organisation's licensing.
Ensure important security notifications are reaching the appropriate people.
Investigate unexpected changes to user accounts, administrator roles and mailbox settings.
Establish a process for escalating suspicious activity when further investigation is required.
Review Microsoft 365 Backup and Recovery
Microsoft 365 provides resilience and native retention and recovery capabilities, but organisations should still consider their own requirements for protecting and recovering business information.
Define What Matters
Identify the Microsoft 365 data the organisation depends on, including Exchange, SharePoint and OneDrive information.
Understand Recovery
Understand available retention, recovery and backup arrangements and whether they meet business requirements.
Test Restoration
Where backups are maintained, periodically verify that important information can be restored when required.
Review your organisation's recovery objectives rather than assuming that simply storing information in Microsoft 365 provides the recovery arrangement the business requires.
Review Your Microsoft 365 Licensing
Microsoft 365 security capabilities vary considerably between licence plans and security add-ons.
A business may identify a security control it wants to implement only to discover that the required capability is not included in its current licences.
Reviewing licensing alongside security requirements can help determine which controls are already available, which require configuration and where an uplift may be appropriate.
Ask These Questions
Which Microsoft 365 licences are currently assigned?
Which security features are already available?
Are available controls actually configured?
Are different users on different licence levels?
Would an uplift address a genuine security requirement?
Microsoft 365 Security Checklist
If you are reviewing an existing Microsoft 365 environment, these questions provide a useful starting point.
Is MFA enabled across the organisation?
Are administrator accounts and privileges regularly reviewed?
Are appropriate email and anti-phishing controls configured?
Do you know which devices are accessing Microsoft 365?
Are SharePoint and OneDrive external sharing settings appropriate?
Are guest users and external access periodically reviewed?
Do you know where sensitive business information is stored?
Are security alerts, sign-ins and audit information reviewed?
Do backup and recovery arrangements meet business requirements?
Have you reviewed whether your licensing supports the security controls you need?
Microsoft 365 Security With a Practical Approach
City Systems helps Australian organisations review and improve the security of their Microsoft 365 environments.
This can include identity and MFA, Microsoft 365 security configuration, device management, email protection, data security, backup and recovery, monitoring and cyber security awareness.
City Systems is ISO 27001 certified, supporting a structured approach to information security, risk management and the protection of client information.
Microsoft 365 Security Review
Identity & MFA
Administrator access
Email security
Device management & security
SharePoint, OneDrive & Teams
Backup, monitoring & recovery
How Secure Is Your Microsoft 365 Environment?
City Systems can review your existing Microsoft 365 environment, licensing and security configuration and help identify practical areas for improvement.