Hamblett Consultancy
Laptop showing a Microsoft 365 security checklist in a Yorkshire business office

MICROSOFT 365 SECURITY

Yorkshire SME Microsoft 365 Security Checklist

A practical checklist for business owners who want Microsoft 365 to be more than email, files and crossed fingers.

26 July 2026

Why This Checklist Matters

Microsoft 365 sits at the centre of most small and medium-sized businesses. It holds email, files, Teams messages, calendars, contacts, SharePoint sites, user accounts, devices, permissions and often the first signs of a cyber incident. For many Yorkshire SMEs, it is not just a productivity platform. It is the front door to the business.

The problem is that Microsoft 365 can look fine while carrying avoidable risk. Staff can sign in, email works, files open, and Teams keeps pinging away. Underneath that, there may be weak administrator accounts, missing multi-factor authentication, risky mailbox rules, unmanaged devices, stale users, poor backup assumptions or phishing exposure.

This checklist gives business owners and managers a practical way to review the basics. It is not written for enterprise security teams with endless tooling. It is for real businesses that need sensible controls, clear priorities and fewer nasty surprises.

1. Multi-Factor Authentication

Every Microsoft 365 user should have multi-factor authentication enabled, especially anyone with access to email, finance systems, management information, client data or administrator permissions. Passwords alone are not enough. They get reused, phished, leaked and guessed.

Check whether MFA is enforced for all users, whether old per-user MFA settings have been replaced with a cleaner policy approach, and whether any accounts are excluded for convenience. Exclusions should be rare, documented and temporary.

For higher-risk accounts, use stronger methods where possible. Authenticator app approval is better than SMS. Number matching and phishing-resistant methods are better again. The aim is simple: a stolen password should not be enough to get into the business.

2. Administrator Accounts

Administrator accounts need special attention because one compromised admin account can give an attacker control over users, mailboxes, security settings and data access. Review who has admin rights, why they have them, and whether those rights are still needed.

Every admin should have MFA. Admin accounts should not be used for day-to-day email and browsing. If possible, keep separate named admin accounts for administration tasks and ordinary user accounts for normal work. Shared admin accounts are messy, hard to audit and much harder to hold accountable.

Also check for old supplier accounts, previous IT providers, unused global admins and emergency accounts that have quietly become permanent. If an account has powerful access, someone should know exactly why.

3. Conditional Access and Sign-In Risk

Conditional Access helps control how, where and when users can sign in. For many SMEs, a sensible starting point is to require MFA, block legacy authentication, challenge risky sign-ins and restrict administrative access.

Legacy authentication is a common weak spot because it can bypass modern security controls. If it is still enabled without a good reason, it should be reviewed. Older mail apps, scanners and line-of-business systems sometimes rely on outdated methods, but those exceptions need to be understood rather than ignored.

Sign-in logs are also useful. Look for impossible travel, repeated failed logins, unfamiliar countries, old protocols and successful sign-ins that do not match normal business behaviour.

4. Mailbox Forwarding and Inbox Rules

Mailbox rules are a favourite hiding place after an email account compromise. An attacker may create a rule to forward email outside the business, hide security alerts, move invoices, delete replies or watch for payment conversations.

Check for external forwarding, suspicious inbox rules and transport rules that send business email outside the organisation. Finance, directors, sales and admin mailboxes deserve particular attention because they are often targeted for invoice fraud and impersonation.

This is one of the simplest checks with one of the highest potential payoffs. A quiet forwarding rule can leak sensitive information for months.

5. User Joiners, Movers and Leavers

Microsoft 365 security depends on clean user lifecycle management. When someone joins, their access should match their role. When they change role, access should be reviewed. When they leave, access should be removed quickly and consistently.

Check for old active accounts, unused mailboxes, former staff with licences still assigned, shared passwords and guest users who no longer need access. Review group membership, SharePoint permissions and Teams access, not just the main user list.

Leaver processes are not glamorous, but they prevent a lot of risk. They also save money by cleaning up unnecessary licences.

6. Device Access and Endpoint Management

Microsoft 365 is only as safe as the devices connecting to it. If staff can access business email and files from any unmanaged laptop, personal phone or unknown browser session, the business has less control than it may think.

Review which devices are connected, whether they are encrypted, patched and protected, and whether lost or old devices still have access. Microsoft Intune can help enforce device compliance, manage mobile devices and protect business data on laptops, tablets and phones.

For SMEs, the goal is not to make work painful. It is to make sure business data is not sitting unprotected on forgotten devices.

7. SharePoint, OneDrive and Teams Permissions

Files often move from old file servers into SharePoint and OneDrive without enough structure. Over time, permissions can become messy: too many owners, too many external guests, broken inheritance, public links and sensitive folders shared more widely than intended.

Check who can access key SharePoint sites, which external users are present, whether anonymous links are allowed, and whether Teams have grown into unmanaged file stores. Sensitive areas such as finance, HR, legal, client data and management documents should be reviewed carefully.

Good permissions reduce both cyber risk and everyday operational confusion. People should be able to find what they need without exposing what they should not.

8. Backup and Retention Assumptions

Microsoft 365 has retention and recovery features, but that is not the same as a full independent backup strategy. Deleted emails, overwritten files, ransomware, malicious activity, retention misconfiguration and long-term recovery requirements all need proper consideration.

Check whether Exchange, OneDrive, SharePoint and Teams are backed up independently. Confirm how long backups are kept, how quickly data can be restored, and whether restore tests have actually been performed. A backup that nobody has tested is still a question mark.

This matters for cyber incidents, accidental deletion, staff disputes, compliance requests and business continuity. Hope is not a restore plan. Stylish, yes. Useful, no.

9. Phishing Readiness

Most Microsoft 365 compromises still begin with a convincing email. Technical controls help, but staff need to recognise suspicious links, login pages, attachments, QR codes, payment changes and impersonation attempts.

Review whether staff receive security awareness training, whether phishing simulations are used, and whether people know how to report suspicious messages. Reporting is important because a fast report can help stop a live attack before it spreads.

Hamblett Consultancy can support this with phishing simulation and awareness training powered by uSecure, alongside Microsoft 365 hardening and email security checks.

10. Audit Logs and Alerting

Security controls are stronger when someone is watching the signals. Review whether audit logging is enabled, whether alerts are configured for risky behaviour, and whether somebody actually receives and acts on those alerts.

Useful alerts include suspicious sign-ins, admin role changes, mailbox forwarding, malware detection, impossible travel, mass file deletion and unusual sharing activity. Alerting should be tuned so it does not become background noise, but silence is not a strategy.

11. Licensing and Security Features

Many Microsoft 365 security features depend on the licence plan in use. Business Basic, Business Standard and Business Premium do not provide the same controls. If a business needs Intune, Conditional Access, Defender features or stronger identity protection, licensing should be reviewed against the actual risk.

This is not about buying the most expensive licence for everyone. It is about matching controls to the people, data and devices that need protection. Sometimes a targeted licensing change gives the business a much stronger security position without waste.

12. Document the Baseline

A checklist is only useful if the findings turn into action. Record what was checked, what passed, what needs work, who owns each action and when it will be reviewed again. Keep the language plain enough that a business owner can understand the risk without needing to decode technical shorthand.

A good Microsoft 365 baseline should cover users, administrators, MFA, Conditional Access, devices, mailbox rules, external sharing, backups, phishing readiness, licences and alerting. Once the baseline is documented, future reviews become easier and more consistent.

When to Get Help

If you are not sure what your Microsoft 365 tenant looks like under the surface, that is a good reason to review it. The earlier you find gaps, the easier and cheaper they are to fix.

Hamblett Consultancy provides Microsoft 365 management, tenant reviews, security hardening, licensing advice, backup planning, phishing simulation and practical cyber security services for SMEs across Yorkshire and the wider UK.

If you want a plain-English review of your Microsoft 365 setup, we can check the configuration, explain the risks and help prioritise the fixes that matter.