01
Protect identity
MFA, privileged access and recovery are the first controls to understand.
A practical way to review the Microsoft 365 controls that protect identities, email, devices, business data and the ability to recover when something goes wrong.
Microsoft 365 can become the operating centre of a small business: email, calendars, Teams, SharePoint, OneDrive, documents, identities and administrative controls may all sit in the same tenant. That concentration is useful, but it also means a weakness in one area can have consequences across the organisation.
This guide sets out a practical NorthWave review rather than a list of every Microsoft 365 feature. The aim is to answer a simpler question: if a business relies on Microsoft 365 every day, are the important security controls understood, configured and reviewed?
Important licensing note
Microsoft 365 security capabilities vary by subscription and configuration. This guide deliberately separates baseline controls from features that require additional licensing. Always check the capabilities available in the tenant before treating a recommendation as a required control.
The NorthWave review
A good review should produce decisions, not just a security score. Record what is configured, what is missing, who owns the decision and what needs to happen next.
Priority 1
MFA, administrator access, recovery information and emergency access.
Priority 2
Mail protection, sharing, permissions and external access.
Priority 3
Audit activity, Secure Score, devices, reviews and documented ownership.
Confirm that users are protected by an appropriate MFA approach. Microsoft documents Security Defaults as a baseline option for organisations without Microsoft Entra ID P1/P2, while Conditional Access provides more granular control where licensed.
List every highly privileged account, identify why it needs the role and remove unnecessary permanent privilege. Day-to-day email and work should normally be performed from a lower-privileged account.
Document how the organisation would regain control if an administrator lost access. Recovery details, break-glass arrangements and stored recovery codes should be protected and tested rather than existing only in someone's memory.
Review older protocols, applications and devices that may still depend on outdated authentication. Do not simply disable something critical without checking dependencies; identify the application, replace or modernise it where necessary, then block the obsolete path.
A leaver process should cover the Microsoft 365 account plus shared mailboxes, Teams, SharePoint sites, OneDrive data, groups, applications, devices and third-party integrations that rely on the identity.
Microsoft 365 provides built-in protection for cloud mailboxes, including quarantine of malware and high-confidence phishing. Review exceptions, allow lists and mail-flow rules carefully because broad exceptions can undermine the protection.
Review SPF, DKIM and DMARC for the organisation's domains and identify every legitimate service that sends mail. Avoid creating a record that only works for today's systems if marketing, CRM or other platforms may be added later.
Review external sharing, guest access, anonymous links where applicable, site ownership and sensitive information. Ask whether staff can explain where company data lives and who can share it outside the organisation.
Confirm that audit logging is available and that someone knows how to investigate sign-ins, administrator changes, mailbox activity and other important events. Microsoft notes that audit capabilities and retention vary by licence and configuration, so verify the actual tenant rather than assuming.
Use Microsoft Secure Score as a source of recommendations and visibility, not as the only measure of security. Record which recommendations are relevant, which are mitigated by another control and which risks the business has consciously accepted.
1. Identity comes first
Microsoft 365 contains valuable information and administrative control, so identity is the natural starting point. If an attacker takes over a user's mailbox, they may gain access to sensitive conversations, documents and password-reset messages. If they compromise a privileged account, the impact can be much larger.
For smaller organisations, the practical question is not whether every advanced identity feature is enabled. It is whether the organisation has a clear answer to three questions: Who can administer the tenant? How are those accounts protected? How would we recover control?
Microsoft's current guidance distinguishes Security Defaults from Conditional Access. Security Defaults provide a simpler baseline, while Conditional Access can provide more granular policies when Microsoft Entra ID P1 or P2 is available. The important point is to choose a deliberate approach rather than leaving identity controls in an unknown state.
A common small-business weakness is giving one account every role because it is convenient. Convenience becomes a problem when that same account is used for ordinary email, web browsing and administration.
NorthWave's practical approach is to keep privileged access small, named and reviewable. Maintain a record of privileged roles, use lower-privileged accounts for normal work, and make sure there is a documented recovery path. Microsoft also recommends using roles with the fewest permissions necessary and treating Global Administrator as a highly privileged role.
Review question
If your main Microsoft 365 administrator were unavailable tomorrow, could another authorised person identify the correct recovery process without guessing?
Microsoft 365 provides resilience and recovery features, but a business should still define what data it needs to recover, how quickly it needs it and what its recovery process is. Accidental deletion, malicious activity, compromised accounts and business continuity requirements can all lead to different recovery needs.
Start by listing critical SharePoint sites, OneDrive data, mailboxes, Teams content and business documents. Then identify the recovery options available in the tenant and any independent backup service used by the business. Finally, test a realistic restore scenario and record the result.
The test matters. A backup or retention policy that has never been validated should not be described internally as “we can definitely restore everything”.
Email is one of the most important Microsoft 365 security surfaces because it is both a communication system and a route into other services. Microsoft states that cloud mailboxes receive built-in protection, including quarantine for malware and high-confidence phishing. At the same time, business-specific exceptions can weaken protection if they are too broad.
Review mail-flow rules, allowed senders and domains, transport rules, forwarding arrangements and any third-party mail gateway. Each exception should have an owner and a reason. If nobody can explain why an exception exists, it deserves review.
Also review the domain itself. SPF, DKIM and DMARC should reflect the services that legitimately send mail on behalf of the business. This is particularly important when a company uses Microsoft 365 alongside a CRM, marketing platform, website forms or other cloud services.
SharePoint, OneDrive and Teams are designed to make collaboration easy. The security objective is not to prevent collaboration; it is to make sharing understandable and proportionate to the data.
Ask where external sharing is allowed, who can create Teams or sites, whether guest accounts are reviewed and whether sensitive documents have additional controls. A business should also know who owns its important sites and what happens when the original owner leaves.
For smaller organisations, a short quarterly review of guest accounts and externally shared locations can be more useful than creating a complicated governance framework nobody maintains.
Audit logging is valuable only if someone knows what to look for. Microsoft 365 can record user and administrator activity, but retention and available capabilities depend on the tenant and licence.
Define a small set of events worth investigating: unusual administrator changes, suspicious sign-ins, mailbox forwarding changes, unexpected sharing, creation of new privileged accounts and other activity relevant to the business. Document who investigates and what evidence should be preserved if an incident occurs.
This does not mean a small business needs a 24-hour security operations centre. It means that when something looks wrong, the organisation should have enough visibility to answer basic questions rather than starting from zero.
Microsoft Secure Score can provide recommendations and a useful view of security posture. It is a starting point for decisions, not a certificate that the tenant is “secure”. A higher score can be helpful, but a business should still understand the risk behind the recommendations.
For example, a recommendation may be irrelevant because a business does not use a particular feature, or it may already be addressed through another security product. Record those decisions rather than chasing points blindly.
NorthWave rule of thumb
Use Secure Score to create a review list. Use business context to decide what actually needs changing.
A review becomes much more valuable when it can be repeated. A simple spreadsheet or service record can contain: review date, tenant owner, privileged accounts, MFA status, external sharing status, critical mail rules, audit status, recovery test date, major Secure Score recommendations and outstanding actions.
For each action, record an owner and target date. If the business decides not to make a change, record the reason and the risk accepted. This turns Microsoft 365 security from a one-off technical exercise into an operating process.
This order keeps the review focused on controls that can materially affect account compromise, data exposure and recovery.
Trusted guidance
This NorthWave guide is a practical review framework. It is not a Microsoft certification, security guarantee or replacement for professional assessment. Use the official documentation below when implementing or validating specific controls.
NorthWave view
Microsoft 365 is powerful enough that it can be tempting to treat the admin centre as a technical environment that only an IT specialist needs to understand. In practice, the most useful security improvements often start with ordinary business questions: who owns this system, who can access it, what happens when someone leaves, and how would we recover?
A small business does not need every advanced Microsoft security product to have sensible foundations. It needs deliberate identity protection, controlled privilege, sensible email and sharing configuration, useful visibility and a recovery plan that has been tested.
That is the purpose of this review: make the important decisions visible, assign ownership and revisit them as the business changes.
01
MFA, privileged access and recovery are the first controls to understand.
02
Review email, sharing, guest access and where important business information lives.
03
Document the recovery path and test it before an incident forces you to.
Continue reading
IT Management
25 practical checks covering identity, devices, email, backup, suppliers and recovery.
Read the baseline →Cyber Security
A practical checklist for identity, devices, email, backups and incident readiness.
Open checklist →Microsoft 365
Five practical areas to review across identity, access, email and devices.
Read article →Need a second pair of eyes?
If your Microsoft 365 environment has grown without a formal security review, NorthWave can help identify practical priorities and next steps.