Interactive checklist
Microsoft 365 hygiene checklist: 12 baseline settings to verify.
Most small businesses pay for Microsoft 365 and leave half the built-in protections switched off. This is a self-check list of the baseline settings Microsoft documents publicly — check off the ones your tenant already has on. Nothing you tick leaves your browser.
What this is: a checklist you answer yourself, so you can see which basics are switched on in your own tenant. What it isn't: a security audit, a risk rating, or professional advice. It can't see your tenant, and it doesn't replace an IT professional or a proper security review.
0 of 12 checked
Sign-in protection
Email authentication
Activity logging & sharing
Your checklist result
Tick the boxes above — your result appears here.
This counts checklist coverage, nothing more. It is not a security rating of your tenant. For Microsoft's own scored view of your tenant, see Secure Score in the Microsoft Defender portal (security.microsoft.com) — that's Microsoft's data about your tenant, and it's free.
Sources
Every item above comes from Microsoft's own documentation: the Microsoft Secure Score recommended actions (MFA for all users, MFA for admin roles, block legacy authentication), the Identity Secure Score recommendations (least-privileged admin roles, remove dormant accounts), the Conditional Access planning guide (security defaults and Conditional Access can't be combined), and the Purview audit-log documentation (turning on unified audit logging). Microsoft changes features and licensing over time — verify each setting's current location in your own admin portals before relying on it.