← Strondex

M365 Security Hardening Checklist

Free preview. You're seeing the first 10 of 80 controls. 80 CIS-based controls for Microsoft 365 — close the gaps before attackers find them.
Identity & Access — MFA 6 controls
CRITICAL M365-01 MFA

Require multi-factor authentication for every user, not just admins.

How to verify / fix

In Entra admin center → Protection → Conditional Access → Overview, confirm an MFA policy covers All users. The modern path is a Conditional Access policy (see M365-07); for unlicensed tenants enable Security defaults under Entra → Overview → Properties → Manage security defaults. Audit gaps with Get-MgUserAuthenticationMethod.

CRITICAL M365-02 MFA

Enforce MFA on all Global Administrator accounts.

How to verify / fix

List Global Admins under Entra → Roles & admins → Global Administrator, then confirm each is in scope of an MFA Conditional Access policy. Best practice is a dedicated CA policy targeting all privileged directory roles. Verify members with Get-MgDirectoryRoleMember.

CRITICAL M365-03 MFA

Block legacy (Basic) authentication protocols with Conditional Access.

How to verify / fix

In Entra → Protection → Conditional Access, create a policy that targets Client apps → Exchange ActiveSync & Other clients and sets Block access. Legacy auth (POP, IMAP, SMTP AUTH, older Office) bypasses MFA entirely. Review legacy sign-ins under Entra → Monitoring → Sign-in logs first.

HIGH M365-04 MFA

Use the Microsoft Authenticator app (push) rather than SMS where possible.

How to verify / fix

In Entra → Protection → Authentication methods → Policies, enable Microsoft Authenticator and set it as preferred; phase out SMS / Voice. Enable number matching and app context for phishing resistance. SMS is vulnerable to SIM-swap interception.

HIGH M365-05 MFA

Require MFA verification before a user can perform a self-service password reset.

How to verify / fix

In Entra → Protection → Password reset → Authentication methods, set Number of methods required to reset to 2 and require strong methods (Authenticator / FIDO2). Confirm SSPR is scoped under Properties.

MEDIUM M365-06 MFA

Turn on the MFA registration campaign to enroll users who haven't registered yet.

How to verify / fix

In Entra → Protection → Authentication methods → Registration campaign, set state to Enabled and target the users or groups still on weaker methods. This nudges users to set up Microsoft Authenticator at sign-in.

Identity & Access — Conditional Access 4 controls
CRITICAL M365-07 Conditional Access

Run an active Conditional Access policy that requires MFA for all users.

How to verify / fix

In Entra → Protection → Conditional Access → Policies, confirm an enabled policy targeting All users and All cloud apps with grant control Require multifactor authentication. Exclude only break-glass accounts (M365-18). Use the templates if starting fresh.

CRITICAL M365-08 Conditional Access

Run an active Conditional Access policy that blocks legacy authentication.

How to verify / fix

Confirm an enabled CA policy with conditions Client apps → Exchange ActiveSync clients and Other clients, grant set to Block access. This is the enforcement half of M365-03 — without it, MFA can be bypassed by older protocols.

HIGH M365-09 Conditional Access

Configure a sign-in risk policy (require MFA or block high-risk sign-ins).

How to verify / fix

Requires Entra ID P2. In Entra → Protection → Conditional Access, create a policy with condition Sign-in risk = High and grant Require multifactor authentication (or Block). Review detections under Protection → Identity Protection → Risky sign-ins.

HIGH M365-10 Conditional Access

Configure a user risk policy that forces a password reset for high-risk users.

How to verify / fix

Requires Entra ID P2. Create a CA policy with condition User risk = High and grant Require password change (with MFA). Monitor flagged users under Protection → Identity Protection → Risky users.

70 more controls — unlock the full checklist

The full M365 Security Hardening Checklist has 80 controls with the interactive self-assessment tool (track Pass / Fail / Partial, see your readiness score, and export a PDF report). One-time purchase, instant access.

Not ready to buy? Try the free Cyber Insurance Readiness Score.