Microsoft 365 Security Checklist for UK SMEs (2025)
Microsoft 365 Security Checklist for UK SMEs (2025)
Microsoft 365 is the primary attack target for ransomware groups, BEC fraudsters, and nation-state actors targeting UK SMEs. Here are the 20 most important controls to implement.
Identity & Access (Highest Priority)
☐ 1. Enable MFA for all users — blocks 99.9% of automated credential attacks ☐ 2. Enable MFA for all admin accounts — use hardware keys (FIDO2) for Global Admins ☐ 3. Remove unused admin accounts — audit your Global Admins list ☐ 4. Enable Privileged Identity Management (PIM) — time-limited admin elevation ☐ 5. Configure Conditional Access policies — block high-risk countries, legacy auth ☐ 6. Enable Microsoft Entra ID Protection — detect risky sign-ins automatically ☐ 7. Audit guest accounts — remove external users who shouldn't have access
Email Security
☐ 8. Configure DMARC, DKIM, and SPF — prevent domain spoofing ☐ 9. Enable Microsoft Defender for Office 365 — anti-phishing, safe links ☐ 10. Enable impersonation protection — protect executives from impersonation ☐ 11. Disable auto-forwarding to external domains — common attacker persistence ☐ 12. Enable mailbox audit logging — critical for UK GDPR investigations
Data Protection
☐ 13. Enable sensitivity labels — classify Confidential, Internal, Public data ☐ 14. Configure DLP policies — prevent sensitive data leaving via email ☐ 15. Review SharePoint/OneDrive sharing — restrict 'Anyone with the link' ☐ 16. Enable Microsoft 365 Backup — Microsoft doesn't auto-backup your data
Endpoint & Device
☐ 17. Enroll devices in Intune — enforce security policies on all devices ☐ 18. Require device compliance — block unmanaged device access ☐ 19. Enable BitLocker — encrypt all Windows devices
Monitoring
☐ 20. Enable unified audit logs — minimum 90 days retention (1 year recommended) ☐ Bonus: 24/7 monitoring — Gridisys monitors Entra ID continuously for suspicious events
UK GDPR Implications
Documented security controls (MFA, audit logging, DLP) demonstrate 'appropriate technical measures' under Article 32 UK GDPR and reduce ICO enforcement risk.