Require MFA for all users
CriticalPassword-only access leaves the tenant exposed to credential theft and reuse.
Use Conditional Access or another tenant-wide control to require MFA, with carefully documented exceptions.
MFA is only one layer. Use this practical baseline to review identity, Conditional Access, endpoint, email, data protection and security-operations controls across Microsoft 365.
A Microsoft 365 tenant can have MFA enabled and still carry material security gaps. Conditional Access exclusions, standing administrator privileges, unmanaged endpoints, weak email protections, uncontrolled external sharing and incomplete audit coverage frequently sit outside the simple question: “Is MFA on?”
Identity and administrative access deserve early attention because a compromised privileged account can undermine controls elsewhere in the tenant. Microsoft recommends emergency access accounts for lockout scenarios and emphasizes least privilege for administrative roles. Microsoft Defender for Office 365 guidance also recommends using its maintained preset security policies rather than relying only on ad hoc custom configurations.
The first ten controls below are intentionally public so you can evaluate whether the full checklist is useful before sharing your email address.
Password-only access leaves the tenant exposed to credential theft and reuse.
Use Conditional Access or another tenant-wide control to require MFA, with carefully documented exceptions.
Administrator compromise can expose the entire Microsoft 365 environment.
Prefer FIDO2/passkeys or certificate-based authentication for highly privileged roles where supported.
A badly designed Conditional Access change can lock out all normal administrators.
Maintain cloud-only emergency accounts, protect them strongly, alert on use and test them regularly.
Using privileged identities for email and browsing increases exposure to phishing and session theft.
Use dedicated admin identities for privileged work and standard accounts for normal productivity.
Excess Global Admin access increases the blast radius of one compromised account.
Review membership and use lower-privilege roles wherever possible.
Permanent privilege is harder to govern and easier to abuse.
Where licensed, make high-privilege roles eligible rather than permanently active and require controlled activation.
Microsoft identity risk signals can identify accounts that need investigation or remediation.
Where licensed, define an operating process for Identity Protection detections and risky users/sign-ins.
Older authentication protocols can bypass modern identity controls.
Identify dependencies, remediate them and block legacy authentication after validation.
Independent policies added over time can create gaps, conflicts and lockout risk.
Maintain a documented baseline covering users, admins, devices, risk, applications and emergency-account exclusions.
Strong identity is not enough if sensitive data is accessed from unmanaged or unhealthy endpoints.
For appropriate applications and users, combine Conditional Access with Intune compliance or approved-device controls.
The complete toolkit expands the review across application consent, guest access, Intune, Defender for Office 365, SPF/DKIM/DMARC, Purview sensitivity labels and DLP, external sharing, audit, Secure Score, Sentinel/SIEM integration and incident response.
Treat the checklist as an improvement backlog rather than a compliance certificate. Validate evidence for each control, distinguish licensing gaps from configuration gaps, document exceptions, assign owners and stage high-impact changes before enforcement.
EAKA IT can review Entra ID, Conditional Access, Intune, Defender, Purview and Sentinel/SIEM integration and produce a risk-rated remediation roadmap.
Important: This guide is general security guidance, not an audit opinion or Microsoft endorsement. Microsoft product capabilities and licensing change over time; validate current Microsoft documentation before implementation.