Resource • Security
MFA & admin hygiene checklist (Microsoft 365)
A short checklist that reduces the most common causes of account compromise. Use this as a starting point.
10 quick checks
- Enable MFA for all users. Start with admins, then roll out to everyone.
- Use separate admin accounts (no daily browsing/email) for privileged access.
- Confirm legacy authentication is blocked (basic auth is a common risk).
- Apply conditional access policies for high-risk logins and geo anomalies.
- Review global admin count — keep it minimal and justify each account.
- Check that security alerts are configured and routed to the right mailbox.
- Implement strong password policy and discourage password reuse.
- Ensure mailbox forwarding rules are monitored and controlled.
- Confirm device compliance or baseline hardening for corporate devices.
- Validate backups exist for critical data and can be restored.
If you want this done properly
We can assess your tenant, implement a security baseline, and document changes with a clear handover.