Checklist Review a Microsoft 365 environment Identities, MFA, roles, sharing, email, endpoints and logging. HomeReview a Microsoft 365 environmentTopicMicrosoft 365 → ♡ Add to favorites View my favorites This review provides a starting point for a small and medium-sized Microsoft 365 holding company. Microsoft 365 Level: Advanced Duration: 60 à 180 min 0 % complete 12 step(s) remaining Inventory of domains, licences and services Identify unused licenses and variances. Control the administrative accounts Critical step Minimum roles, dedicated accounts and absence of daily use. Check MFA coverage Critical step Priority to administrators and external access. Review inactive and invited accounts Disable or remove obsolete accesses. Analyze the transfer rules and compromised boxes Critical step External transfers, suspicious rules and consents OAuth. Control SPF, DKIM and DMARC Check the alignment with authorized shipping services. Review SharePoint Anonymous links, guests and sensitive data. Check policies of conditional access Sensitive countries, devices, risks and applications. Control devices and compliance Intune, encryption, updates and personal devices. Check the audit and alerts Newspapers available, storage and alert recipients. Examine SaaS data backup Define needs beyond the native functions. Formalize an action plan Priority, responsibility, timing and proof of correction. Intervention notes Copy summary Print / PDF Reset
Control the administrative accounts Critical step Minimum roles, dedicated accounts and absence of daily use.
Analyze the transfer rules and compromised boxes Critical step External transfers, suspicious rules and consents OAuth.