Cloud

A Microsoft 365 security checklist for growing businesses

Most Microsoft 365 problems come from a handful of settings that were never turned on. Here is the short list to check first.

4 min read

Microsoft 365 ships with strong security tools, but many are off or partly set up by default. A short review of a few settings closes most of the common gaps.

The checklist

  • Turn on multi-factor authentication for every user, not just admins
  • Keep admin accounts separate from daily email, and limit how many there are
  • Block old sign-in methods that skip MFA
  • Turn on anti-phishing and safe links protection for email
  • Review external sharing in SharePoint and OneDrive so files are not open to anyone with a link
  • Require devices to be managed and up to date before they can reach company data
  • Back up mailboxes and files separately. Microsoft protects the service, not your ability to undo a mistake

Why the backup line surprises people

Microsoft keeps the platform running, but deleted or overwritten data has limited recovery windows. A separate backup gives you a way back after a mistake, a malicious deletion, or a compromised account.

If nobody at your company can say which of these are on, that is the first thing to find out.

Gravity supports Microsoft 365 as part of managed IT and platform support, including backup.

Need help choosing the right path?

Tell us about your environment and we'll recommend a practical next step.

Get a quote