simpl.
Cybersecurity GRC 15 items

Microsoft 365 Security Baseline Review

Assesses a Microsoft 365 tenant against security baseline recommendations covering identity, email, collaboration, data protection, and auditing.

CIS Microsoft 365 BenchmarkNIST 800-53Microsoft SLA

Free PDF · enter your email to download.

Identity & Access

  • Is MFA enforced for all users, including administrators, via Conditional Access? *
  • Is legacy authentication (basic auth, POP/IMAP) blocked tenant-wide? *
  • Are privileged roles managed with Entra Privileged Identity Management (PIM) and just-in-time activation? *
  • Is Security Defaults or an equivalent Conditional Access policy set enabled? *

Email Security (Exchange Online)

  • Are SPF, DKIM, and DMARC configured and enforced for all sending domains? *
  • Is Microsoft Defender for Office 365 Safe Links and Safe Attachments enabled? *
  • Are external sender warnings and anti-phishing impersonation policies configured? *
  • Is auto-forwarding of email to external domains disabled? *

Collaboration & Data Protection

  • Are external sharing settings for SharePoint and OneDrive restricted to the minimum required? *
  • Are sensitivity labels and DLP policies applied to protect confidential data?
  • Are guest access and Teams external federation controls reviewed and restricted? *

Auditing & Monitoring

  • Is unified audit logging enabled tenant-wide? *
  • Are alerts configured for risky sign-ins and admin activity? *
  • Is Microsoft Secure Score reviewed periodically with improvement actions tracked?
  • Are audit logs exported to a SIEM for long-term retention and correlation?

Download the full Microsoft 365 Security Baseline Review checklist

Get it as a clean, printable PDF — free.