A Microsoft 365 security assessment is the fastest way to surface misconfigurations that leak data, weaken identity, or break mail flow. This checklist is the same one we use on senior-led engagements at CloudPair.
1. Identity & Entra ID
- Audit Conditional Access policies — confirm MFA is enforced for every admin and external app
- Disable legacy authentication (Basic Auth, IMAP/POP, SMTP AUTH where unused)
- Review privileged role assignments — convert standing roles to PIM-eligible
- Validate break-glass accounts (excluded from CA, monitored, MFA-bound)
- Check sign-in risk policies and Identity Protection sensitivity
2. Exchange Online & Mail Flow
- Verify SPF, DKIM, DMARC alignment for every sending domain
- Inspect inbound/outbound connectors for shadow routing
- Review transport rules — flag overly broad bypass rules
- Audit anti-phishing, Safe Links, and Safe Attachments policies
- Check quarantine and message-trace retention
3. Defender for M365
- Confirm Defender for Office 365, Endpoint, and Identity coverage matches license
- Run the attack-simulator baseline and review user click-through rate
- Review attack-surface-reduction (ASR) rule mode (audit vs block)
4. Purview, DLP & Compliance
- Map data classifications to sensitivity labels with auto-labeling
- Set retention policies for Exchange, SharePoint, OneDrive, Teams
- Review DLP policy hits and false-positive rate
- Validate eDiscovery hold readiness
5. Intune & Endpoint Compliance
- Apply Microsoft security baselines for Windows and Edge
- Require compliant device in CA for managed apps
- Enable BitLocker policy and recovery key escrow
6. SharePoint, OneDrive & Teams (Copilot-ready)
- Audit external sharing defaults and guest expiration
- Find oversharing risks before Copilot rollout — labeled, but world-readable, sites
- Review Teams external/federation settings
7. Secure Score remediation
Don't chase 100% — chase the highest-impact items. Focus on identity (MFA, CA), mail flow (DMARC enforcement, ATP), and endpoint compliance before cosmetic items.
Want the same checklist applied to your tenant? CloudPair runs a fixed-scope 30/60/90 assessment with executive and technical reports.