Back to all posts
    Microsoft 365
    Checklist
    Security Baseline

    The MSP's Checklist for M365 Security Baselines

    ThreatMate Team
    Sep 28, 2023
    4 min read
    The MSP's Checklist for M365 Security Baselines

    M365 Security Baseline Checklist

    Use this checklist to assess and secure your clients' Microsoft 365 tenants:

    Authentication & Identity

    • [ ] MFA enabled for all users
    • [ ] MFA enforced for all admin accounts
    • [ ] Legacy authentication disabled
    • [ ] Password policies configured (length, complexity)
    • [ ] Self-service password reset enabled
    • [ ] Risky sign-in policies configured

    Email Security

    • [ ] Mailbox audit logging enabled
    • [ ] Auto-forwarding to external domains blocked
    • [ ] Anti-phishing policies configured
    • [ ] Safe Links enabled
    • [ ] Safe Attachments enabled
    • [ ] DMARC with enforcement

    Data Protection

    • [ ] External sharing restricted
    • [ ] Anonymous sharing links disabled
    • [ ] Guest access reviewed and limited
    • [ ] DLP policies configured
    • [ ] Sensitivity labels deployed

    Admin Security

    • [ ] Admin accounts separate from user accounts
    • [ ] Global admin count minimized (<5)
    • [ ] Admin roles reviewed regularly
    • [ ] Privileged Identity Management enabled (if licensed)

    Logging & Monitoring

    • [ ] Unified Audit Log enabled
    • [ ] Alert policies configured
    • [ ] Suspicious activity notifications active

    Automating the Checklist

    ThreatMate automates M365 security baseline assessments using CISA's ScubaGear framework.

    Ready to secure your attack surface?

    See how ThreatMate helps MSPs identify and remediate vulnerabilities across their client base.