Microsoft 365 security check: 10 points to check yourself
With these ten points, you can assess the baseline security of your tenant yourself in about an hour. All you need is a role with read access, e.g. Global Reader. The menu paths reflect the admin centers as of October 2026.
- Points 1–4IdentitiesMFA, legacy authentication, administrators, emergency access accounts
- Points 5–6Accounts and guestsFormer employees and guest access
- Points 7–8Apps and emailApp consent and external forwarding
- Points 9–10MonitoringAudit log and Secure Score
-
Have all users registered for MFA?
Microsoft Entra admin center → Entra ID → Authentication methods → User registration details.
-
Is legacy authentication blocked?
Filter the sign-in logs in the Microsoft Entra admin center by client app (legacy clients such as IMAP, POP or SMTP). Successful sign-ins here are a risk.
-
How many Global Administrators are there?
Microsoft Entra admin center → Entra ID → Roles & admins → Global Administrator. Microsoft recommends fewer than five. Day-to-day work should never be done with a Global Administrator account.
-
Are there emergency access accounts (break-glass)?
Two cloud-only accounts, excluded from Conditional Access, with strong authentication and monitoring.
-
Are the accounts of former employees blocked?
Sort the user list by last sign-in. Active, licensed accounts with no sign-in for months are both a security risk and a cost risk.
-
Who has guest access?
Review guest users regularly, ideally with access reviews.
-
Can users consent to apps on their own?
Microsoft Entra admin center → Entra ID → Enterprise apps → Consent and permissions. Unrestricted user consent opens the door to consent phishing.
-
Is automatic forwarding to external recipients blocked?
Microsoft Defender portal → Email & collaboration → Policies & rules → Threat policies → Anti-spam, outbound spam policy. Forwarding rules are a popular tool after an account takeover.
-
Is the audit log turned on?
Microsoft Purview portal → Audit. Without the audit log, an incident is hard to investigate after the fact.
-
What does your Secure Score look like?
Microsoft Defender portal → Exposure management → Secure Score. It does not give you the complete picture, but it shows which basics are still open and where the priorities are.
What next?
If several points are still open, that is the rule rather than the exception for SMEs. What matters is a clear order: identities first (MFA, legacy authentication, administrators), then data and devices.