Microsoft 365 can support productive and secure work, but the default setup should be reviewed before an organisation depends on it.

Protect every identity

Enable multi-factor authentication for all users and use stronger, separate controls for administrative accounts. Administrators should not use privileged accounts for routine email and browsing.

Reduce administrative access

Global administrator access should be limited to the smallest practical number of trusted people. Assign narrower roles when a task does not require full control.

Define account ownership

Each mailbox, shared account and service identity should have a documented owner. Joiner, mover and leaver procedures help prevent dormant access.

Review external sharing

OneDrive, SharePoint and Teams sharing should reflect the organisation’s actual collaboration needs. Broad anonymous links are convenient, but they also reduce control.

Prepare for recovery

Document who can recover accounts, where emergency access is kept and how the organisation will continue operating if a key administrator is unavailable.

A baseline is valuable because it is repeatable. Review it periodically, record exceptions and improve controls as the organisation grows.