Microsoft 365 security checklist

A practical, interactive checklist for securing a Microsoft 365 tenant across identity, devices, applications, email, logging, patch, and data. Check items off as you go, your progress is saved in your browser.

Every item below is something Senserva checks automatically as part of its 650+ security checks, mapped to CISA SCuBA and MCSB. Work the list by hand, or scan your own tenant free and let Senserva check all of it in one pass. For the why behind each item, read the how to harden Microsoft 365 guide.

0 of 0

Identity and access

The highest-impact, lowest-effort wins. Start here.

Privileged access

Limit the blast radius of a compromised account.

Applications and consent

The most overlooked attack surface in Microsoft 365.

Devices and endpoints (Intune and Defender)

Where hardening most often drifts. One of the largest check areas.

Patch and vulnerabilities

Prioritize by real-world exploitation, not raw counts.

Email and collaboration

The front door for phishing, and where data leaves.

Logging and detection

You cannot investigate what you did not log.

Data protection (Purview)

Control where sensitive data goes.

Frameworks and drift

Make hardening provable, and keep it from decaying.

Check all of this in one scan

Senserva runs every item on this checklist as part of its 650+ checks, maps each to a framework, and proposes a validated fix. No agents, no cloud pipeline.

Scan your tenant free See all 650+ checks

Frequently asked questions

Does Senserva cover every item on this checklist?

Yes. Every item here maps to one or more of Senserva's 650+ automated checks across identity, privileged access, applications, devices, patch, email, logging, and data. A single read-only scan evaluates the whole list and ranks findings by Severity. See the full checks catalog.

Is this checklist free to use?

Yes. The checklist is free and your progress is saved locally in your browser, nothing is sent to us. Running an automated scan of your own tenant is also free after a quick registration.

How is this different from Microsoft Secure Score?

Secure Score is a single number. This checklist is concrete, ordered actions, and Senserva turns each into a finding-by-finding result mapped to CISA SCuBA and MCSB with a validated remediation, including device posture, patch coverage, and log health that Secure Score is light on.

How often should I run through it?

Hardening decays as tenants change, so treat it as continuous rather than one-time. Re-check after any significant change, and use drift monitoring to catch the slow slide between reviews.