Microsoft 365 often holds the email, files and calendars a business needs every day. Start with four checks: multi-factor authentication, separate administrator accounts, prompt staff departures and tested recovery.
Download the JCPIT Microsoft 365 Security Checklist to record the full review. Mark each item Yes, No or Not sure rather than guessing. For an ink-light copy, print pages 2 and 3 only.
Protect every sign-in
Turn on multi-factor authentication for every user. Use an authenticator app or another stronger method where practical. Staff should deny and report an approval prompt they did not start.
Give each person an individual account and a unique password. A business password manager can help staff avoid reusing passwords across services.
Keep administrator accounts separate
Do not use a powerful administrator account for everyday email and web browsing. Administrators should have a normal account for daily work and a separate one for system changes.
Keep the number of administrators small. Confirm that alerts and recovery details go to authorised people who will act when something looks wrong.
Protect email, payments and shared files
Review spam and phishing settings, along with the records that help other mail systems verify messages from your domain. Filters will not catch every scam, so staff should confirm changed bank details by calling a known number.
Check who can access important OneDrive, SharePoint and Teams files. Remove old sharing links and access held by former staff, contractors or suppliers.
Remove access when someone leaves
Block a departing person's sign-in promptly. Before deleting the account, transfer any mailbox, OneDrive files and business records that must be kept.
Review shared mailboxes, test accounts and unused users at the same time. Every account should have a current owner and purpose.
Secure the devices used for work
Require screen locks and software updates on phones, tablets and computers. Use current device protection and know how company data can be removed from a lost or stolen device.
Staff should use approved business devices where practical, not shared or unmanaged computers.
Check recovery with a real restore
Recycle bins, version history and retention settings can help with some losses, but their coverage and time limits depend on the setup. Decide what the business needs to recover and how far back it may need to go.
Where a separate backup is required, protect its administrator access and test a restore. Confirm that the recovered email or file opens and that the right person can use it.
If you want these checks verified rather than left on a list, book a Microsoft 365 security consultation with JCPIT Support. We will review the Microsoft 365 setup and give you a short, prioritised record of what is working and what needs attention.