Interactive checklist

Microsoft 365 hygiene checklist: 12 baseline settings to verify.

Most small businesses pay for Microsoft 365 and leave half the built-in protections switched off. This is a self-check list of the baseline settings Microsoft documents publicly — check off the ones your tenant already has on. Nothing you tick leaves your browser.

What this is: a checklist you answer yourself, so you can see which basics are switched on in your own tenant. What it isn't: a security audit, a risk rating, or professional advice. It can't see your tenant, and it doesn't replace an IT professional or a proper security review.

0 of 12 checked

Sign-in protection

Email authentication

Activity logging & sharing

Your checklist result

Items checked 0 of 12

Tick the boxes above — your result appears here.

This counts checklist coverage, nothing more. It is not a security rating of your tenant. For Microsoft's own scored view of your tenant, see Secure Score in the Microsoft Defender portal (security.microsoft.com) — that's Microsoft's data about your tenant, and it's free.

Sources

Every item above comes from Microsoft's own documentation: the Microsoft Secure Score recommended actions (MFA for all users, MFA for admin roles, block legacy authentication), the Identity Secure Score recommendations (least-privileged admin roles, remove dormant accounts), the Conditional Access planning guide (security defaults and Conditional Access can't be combined), and the Purview audit-log documentation (turning on unified audit logging). Microsoft changes features and licensing over time — verify each setting's current location in your own admin portals before relying on it.