Security Operations

Data Security Checklist for Microsoft 365 Admins (2026 Edition)

Published Jul 25, 20267 min readBy Security Engineering

Direct answer: verify identity and emergency access first, then audit coverage, sharing, data controls, backup, and incident response. Do not close a checklist item because a setting exists. Close it only after a named owner captures the configuration, generates a test event, verifies the expected result, and records any exception.

This checklist is a risk-review starting point, not a universal secure configuration or substitute for Microsoft licensing review, threat modeling, or a tenant-specific assessment. Test changes with report-only modes and controlled accounts before broad enforcement.

Priority Control Table

PriorityDecision and pass conditionOwnerRequired evidence
1. Emergency accessAt least two monitored emergency accounts are usable, excluded only where necessary, and tested without weakening daily administrationIdentity leadAccount inventory, alert test, access test
2. Admin authenticationPrivileged roles use dedicated accounts and approved phishing-resistant authentication where supportedIdentity leadRole export, authentication-method report
3. Conditional AccessLegacy authentication and high-risk access paths are blocked after dependencies and rollback are testedIdentity leadReport-only results, exception list, sign-in test
4. Audit and alertsRequired events are retained long enough and each priority detection has produced a test alertSecurity operationsLicense map, audit query, alert ticket
5. Sharing and accessHigh-risk sites have owners, approved sharing settings, and reviewed broad accessCollaboration ownerSite report, owner response, exception
6. Data controlsLabels and DLP rules are simulated, measured, and enforced only for approved outcomesInformation protectionPolicy export, simulation metrics, test event
7. RecoveryRequired objects have successful backup evidence and a representative restore accepted by the data ownerRecovery ownerJob result, item errors, timed restore record

Owner Fields

Runbook 1: Identity and Privileged Access

  1. Export privileged Microsoft Entra role assignments. Separate eligible from active assignments, identify service dependencies, and confirm every assignment has an owner and expiry or review date.
  2. Use dedicated privileged identities for administration. Do not use arbitrary holder counts as a pass condition; minimize permanent Global Administrator assignments according to operational needs and emergency coverage.
  3. Require approved phishing-resistant methods for privileged access where the tenant, devices, and break-glass design support them. Microsoft documents built-in authentication strengths for Conditional Access. Keep emergency access separately designed and monitored.
  4. Inventory legacy authentication before blocking it. Use sign-in logs and a report-only policy, contact application owners, migrate or isolate dependencies, define rollback, then enforce. Follow Microsoft's legacy authentication policy guidance.
  5. Where licensed, configure Microsoft Entra Privileged Identity Management with justified activation, limited duration, notification, and periodic review. Test activation and emergency access after policy changes.

Runbook 2: Audit, Detection, and Response

Confirm the tenant's actual Purview Audit license and retention. Audit Standard generally retains records for 180 days. Audit Premium provides a default one-year policy for specified Exchange, SharePoint, OneDrive, and Microsoft Entra records generated by appropriately licensed users; other records can remain at 180 days, and longer retention has additional requirements. Use Microsoft's audit retention documentation rather than assuming that an E5 tenant gives every event one year.

  1. List incidents the organization must detect: privileged-role changes, authentication-method changes, risky sign-ins, inbox forwarding, external sharing, bulk deletion, retention-policy changes, and backup failure.
  2. Map each incident to its audit source, license, query, alert rule, ticket route, responder, and required retention.
  3. Generate a controlled test event. Confirm ingestion time, alert content, assignment, escalation, and closure evidence.
  4. Export or forward records when the approved investigation window exceeds native retention. Protect access to the destination and test retrieval.

Runbook 3: Sharing, Classification, and DLP

Use SharePoint and OneDrive reporting to identify broad access, guests, anonymous links, stale owners, and unique permissions. Do not impose a universal link-expiry value. Data owners should approve link type and duration based on collaboration need, sensitivity, and external-party lifecycle. Record exceptions and expiration.

Define sensitivity labels from handling outcomes. A label may apply protection when configured, and DLP can evaluate labels or content classifiers in supported locations. Neither control is complete by default. Simulate policies, sample false positives and false negatives, test user overrides and alerts, then enforce in stages. The DLP versus backup guide provides an outcome matrix, while the governance framework assigns business ownership.

Runbook 4: Backup and Recovery

  1. List required Exchange, SharePoint, OneDrive, and Teams object types. Include metadata, permissions, versions, and destination requirements where they matter.
  2. Record native recovery and independent backup coverage separately. A backup handler does not imply a restore handler or legal export.
  3. Review the administrative boundary, storage responsibilities, retention, deletion controls, monitoring, and operator access. Require implementation evidence for any immutability or air-gap claim.
  4. Run a representative restore from a known recovery point. Record elapsed time, changed identifiers or metadata, unsupported objects, and data-owner acceptance.
  5. Exercise a destructive-event scenario using the Microsoft 365 ransomware recovery runbook.

Evidence Checklist

Limitations and Decision Gate

North Brook Vault manages its backup infrastructure and storage but does not currently provide native Object Lock configuration or enforcement, universal Microsoft 365 object recovery, or a guaranteed RPO or recovery outcome. This checklist does not certify security or compliance.

Decision gate: mark a control complete only when the named owner can show current configuration, a successful test, retained evidence, and a reviewed exception path.

Schedule a recovery control review