New Microsoft 365 Tenant Security Checklist
Essential security configurations for a newly created Microsoft 365 tenant. Complete this checklist within the first 30 days to establish a secure foundation.
Prerequisites
- •Global Admin access to Microsoft 365 tenant
- •Microsoft Entra admin center access
- •Basic understanding of identity concepts
Day 1: Critical Security Settings
These settings should be configured immediately upon tenant creation.
Require multi-factor authentication for Global Admins and other privileged roles.
Related: ID-01Tips:
- • Use phishing-resistant MFA methods like FIDO2 or Windows Hello
- • Enable number matching for Microsoft Authenticator
Remove unnecessary Global Admin assignments and use role-specific admin roles.
Related: PA-01Create a Conditional Access policy to block IMAP, POP3, SMTP AUTH, and other legacy protocols.
Related: CA-09Set up 2 cloud-only emergency access accounts excluded from Conditional Access.
Related: PA-05Tips:
- • Use long, randomly generated passwords (32+ characters)
- • Store credentials in a secure physical location
- • Test accounts quarterly
Week 1: Authentication Security
Strengthen authentication across the organization.
Create Conditional Access policy requiring MFA for all cloud apps.
Related: CA-01Disable password expiration, enable banned password list.
Related: ID-02Enable SSPR with appropriate authentication methods.
Week 2: Access Controls
Implement proper access management.
Configure just-in-time access for privileged roles.
Related: PA-04Restrict who can invite guests and from which domains.
Related: EXT-01Require admin approval for user app consent.
Related: APP-02Week 3-4: Monitoring & Governance
Set up ongoing monitoring and governance.
Ensure unified audit log is capturing all activities.
Related: LOG-01Set up alerts for suspicious activities and admin actions.
Configure quarterly reviews for privileged roles and groups.
Related: GOV-03Automate this checklist with TrueConfig
TrueConfig automatically monitors your Microsoft 365 configuration against these best practices and alerts you when settings drift.