Microsoft 365 can support productive and secure work, but the default setup should be reviewed before an organisation depends on it.
Protect every identity
Enable multi-factor authentication for all users and use stronger, separate controls for administrative accounts. Administrators should not use privileged accounts for routine email and browsing.
Reduce administrative access
Global administrator access should be limited to the smallest practical number of trusted people. Assign narrower roles when a task does not require full control.
Define account ownership
Each mailbox, shared account and service identity should have a documented owner. Joiner, mover and leaver procedures help prevent dormant access.
Review external sharing
OneDrive, SharePoint and Teams sharing should reflect the organisationâs actual collaboration needs. Broad anonymous links are convenient, but they also reduce control.
Prepare for recovery
Document who can recover accounts, where emergency access is kept and how the organisation will continue operating if a key administrator is unavailable.
A baseline is valuable because it is repeatable. Review it periodically, record exceptions and improve controls as the organisation grows.