Microsoft 365 security guide
Microsoft 365 security checklist for small businesses
Use this Microsoft 365 security checklist to have a concrete conversation with your IT provider. For each item, record an owner, the evidence reviewed, the review date and any action required. UK businesses can use it to prepare evidence conversations alongside the relevant Cyber Essentials requirements.
Published · Last reviewed · By CyberProva
Run your free Microsoft 365 security assessmentNo card required · Optional read-only Microsoft 365 connection
Free downloadable resource
The UK Small Business Microsoft 365 Security Checklist 2026
40 practical checks across eight areas, an evidence request template and an action worksheet to complete with your IT provider.
Download the checklist PDFNo email or account required. Read the accessible HTML version.
Check accounts and administrator access
Start with who can sign in and who can change your environment. Include external support accounts and people who have left.
- Review all Global Administrators and other privileged roles.
- Confirm MFA protection and document exclusions.
- Use separate accounts for routine work and administration.
- Remove unnecessary access and review emergency-access arrangements.
Check email and external access
Email and sharing settings need both policy review and a check of what is actually allowed. Document legitimate exceptions.
- Review automatic external forwarding and mailbox forwarding rules.
- Review phishing protection and alerts for suspicious changes.
- Check guest access and external file-sharing permissions.
- Review how SPF, DKIM and DMARC are configured for your domains.
Check recovery and ownership
Microsoft 365 settings alone cannot establish that your organisation can recover from a serious incident.
- Document backup coverage and retention for the data you rely on.
- Request a restore test with a date, scope and outcome.
- Check how devices are updated and protected.
- Name the people who will handle incidents and outstanding findings.
Make the answer provable
Evidence to request
- A dated access review, including leavers and provider accounts.
- Configuration evidence for email and external sharing.
- A restore-test record and an action list with owners.
How CyberProva helps
CyberProva turns selected Microsoft 365 settings and evidence-based controls into findings you can review. Some items in this checklist require your organisation or provider to supply evidence; they are not all automatically scanned.
See what a Microsoft 365 security assessment should cover →
See exactly what CyberProva checks · Learn how CyberProva assesses security · Review Microsoft permissions
Common questions
How often should we repeat the checklist?
Agree a review cadence with your IT team and repeat relevant checks after staffing, access, service or configuration changes. Record what changed rather than just copying the previous answers.
Does completing this checklist certify us?
No. It is a starting point for assessment and evidence collection, not certification or a guarantee of security.
Official guidance
Use these sources with your IT provider when reviewing the controls described above.
From assumptions to evidence
See what needs attention in your organisation
Start with a free CyberProva assessment. Review the findings, identify evidence gaps and agree priorities with your IT team.
Free includes 3 lifetime core assessments. Report exports and advanced features require a paid plan.