Microsoft 365 security guide

Microsoft 365 security checklist for small businesses

Use this Microsoft 365 security checklist to have a concrete conversation with your IT provider. For each item, record an owner, the evidence reviewed, the review date and any action required. UK businesses can use it to prepare evidence conversations alongside the relevant Cyber Essentials requirements.

Published · Last reviewed · By CyberProva

Run your free Microsoft 365 security assessment

No card required · Optional read-only Microsoft 365 connection

Free downloadable resource

The UK Small Business Microsoft 365 Security Checklist 2026

40 practical checks across eight areas, an evidence request template and an action worksheet to complete with your IT provider.

Download the checklist PDF

No email or account required. Read the accessible HTML version.

Check accounts and administrator access

Start with who can sign in and who can change your environment. Include external support accounts and people who have left.

  • Review all Global Administrators and other privileged roles.
  • Confirm MFA protection and document exclusions.
  • Use separate accounts for routine work and administration.
  • Remove unnecessary access and review emergency-access arrangements.

Check email and external access

Email and sharing settings need both policy review and a check of what is actually allowed. Document legitimate exceptions.

  • Review automatic external forwarding and mailbox forwarding rules.
  • Review phishing protection and alerts for suspicious changes.
  • Check guest access and external file-sharing permissions.
  • Review how SPF, DKIM and DMARC are configured for your domains.

Check recovery and ownership

Microsoft 365 settings alone cannot establish that your organisation can recover from a serious incident.

  • Document backup coverage and retention for the data you rely on.
  • Request a restore test with a date, scope and outcome.
  • Check how devices are updated and protected.
  • Name the people who will handle incidents and outstanding findings.

Make the answer provable

Evidence to request

  • A dated access review, including leavers and provider accounts.
  • Configuration evidence for email and external sharing.
  • A restore-test record and an action list with owners.

How CyberProva helps

CyberProva turns selected Microsoft 365 settings and evidence-based controls into findings you can review. Some items in this checklist require your organisation or provider to supply evidence; they are not all automatically scanned.

See what a Microsoft 365 security assessment should cover →

See exactly what CyberProva checks · Learn how CyberProva assesses security · Review Microsoft permissions

Common questions

How often should we repeat the checklist?

Agree a review cadence with your IT team and repeat relevant checks after staffing, access, service or configuration changes. Record what changed rather than just copying the previous answers.

Does completing this checklist certify us?

No. It is a starting point for assessment and evidence collection, not certification or a guarantee of security.

Official guidance

Use these sources with your IT provider when reviewing the controls described above.

From assumptions to evidence

See what needs attention in your organisation

Start with a free CyberProva assessment. Review the findings, identify evidence gaps and agree priorities with your IT team.

Free includes 3 lifetime core assessments. Report exports and advanced features require a paid plan.

Run your free assessment →