M365 Security Hardening Checklist
Identity & Access — MFA 6 controls
Require multi-factor authentication for every user, not just admins.
How to verify / fix
In Entra admin center → Protection → Conditional Access → Overview, confirm an MFA policy covers All users. The modern path is a Conditional Access policy (see M365-07); for unlicensed tenants enable Security defaults under Entra → Overview → Properties → Manage security defaults. Audit gaps with Get-MgUserAuthenticationMethod.
Enforce MFA on all Global Administrator accounts.
How to verify / fix
List Global Admins under Entra → Roles & admins → Global Administrator, then confirm each is in scope of an MFA Conditional Access policy. Best practice is a dedicated CA policy targeting all privileged directory roles. Verify members with Get-MgDirectoryRoleMember.
Block legacy (Basic) authentication protocols with Conditional Access.
How to verify / fix
In Entra → Protection → Conditional Access, create a policy that targets Client apps → Exchange ActiveSync & Other clients and sets Block access. Legacy auth (POP, IMAP, SMTP AUTH, older Office) bypasses MFA entirely. Review legacy sign-ins under Entra → Monitoring → Sign-in logs first.
Use the Microsoft Authenticator app (push) rather than SMS where possible.
How to verify / fix
In Entra → Protection → Authentication methods → Policies, enable Microsoft Authenticator and set it as preferred; phase out SMS / Voice. Enable number matching and app context for phishing resistance. SMS is vulnerable to SIM-swap interception.
Require MFA verification before a user can perform a self-service password reset.
How to verify / fix
In Entra → Protection → Password reset → Authentication methods, set Number of methods required to reset to 2 and require strong methods (Authenticator / FIDO2). Confirm SSPR is scoped under Properties.
Turn on the MFA registration campaign to enroll users who haven't registered yet.
How to verify / fix
In Entra → Protection → Authentication methods → Registration campaign, set state to Enabled and target the users or groups still on weaker methods. This nudges users to set up Microsoft Authenticator at sign-in.
Identity & Access — Conditional Access 4 controls
Run an active Conditional Access policy that requires MFA for all users.
How to verify / fix
In Entra → Protection → Conditional Access → Policies, confirm an enabled policy targeting All users and All cloud apps with grant control Require multifactor authentication. Exclude only break-glass accounts (M365-18). Use the templates if starting fresh.
Run an active Conditional Access policy that blocks legacy authentication.
How to verify / fix
Confirm an enabled CA policy with conditions Client apps → Exchange ActiveSync clients and Other clients, grant set to Block access. This is the enforcement half of M365-03 — without it, MFA can be bypassed by older protocols.
Configure a sign-in risk policy (require MFA or block high-risk sign-ins).
How to verify / fix
Requires Entra ID P2. In Entra → Protection → Conditional Access, create a policy with condition Sign-in risk = High and grant Require multifactor authentication (or Block). Review detections under Protection → Identity Protection → Risky sign-ins.
Configure a user risk policy that forces a password reset for high-risk users.
How to verify / fix
Requires Entra ID P2. Create a CA policy with condition User risk = High and grant Require password change (with MFA). Monitor flagged users under Protection → Identity Protection → Risky users.
70 more controls — unlock the full checklist
The full M365 Security Hardening Checklist has 80 controls with the interactive self-assessment tool (track Pass / Fail / Partial, see your readiness score, and export a PDF report). One-time purchase, instant access.
Not ready to buy? Try the free Cyber Insurance Readiness Score.