The MSP's Checklist for M365 Security Baselines

M365 Security Baseline Checklist
Use this checklist to assess and secure your clients' Microsoft 365 tenants:
Authentication & Identity
- [ ] MFA enabled for all users
- [ ] MFA enforced for all admin accounts
- [ ] Legacy authentication disabled
- [ ] Password policies configured (length, complexity)
- [ ] Self-service password reset enabled
- [ ] Risky sign-in policies configured
Email Security
- [ ] Mailbox audit logging enabled
- [ ] Auto-forwarding to external domains blocked
- [ ] Anti-phishing policies configured
- [ ] Safe Links enabled
- [ ] Safe Attachments enabled
- [ ] DMARC with enforcement
Data Protection
- [ ] External sharing restricted
- [ ] Anonymous sharing links disabled
- [ ] Guest access reviewed and limited
- [ ] DLP policies configured
- [ ] Sensitivity labels deployed
Admin Security
- [ ] Admin accounts separate from user accounts
- [ ] Global admin count minimized (<5)
- [ ] Admin roles reviewed regularly
- [ ] Privileged Identity Management enabled (if licensed)
Logging & Monitoring
- [ ] Unified Audit Log enabled
- [ ] Alert policies configured
- [ ] Suspicious activity notifications active
Automating the Checklist
ThreatMate automates M365 security baseline assessments using CISA's ScubaGear framework.
Ready to secure your attack surface?
See how ThreatMate helps MSPs identify and remediate vulnerabilities across their client base.
