Five Security Checks for Microsoft 365 Operations. After Microsoft 365 is deployed, determining whether the current settings remain appropriate can be harder than changing the configuration. Administrator privileges must be reviewed when employees change roles or leave. The same applies to external file sharing and authentication exceptions because the circumstances that justified a rule may change. This article explains five areas to review, where to find the relevant settings, and what information to compare when making decisions.

Administrator Privileges: Are Old Global Administrator Assignments Still in Place?
Start by comparing the accounts in the administrator list with the staff currently responsible for them. The goal is to understand the purpose of each account, rather than simply count the administrators.
Global Administrator is a powerful role that can change many Microsoft 365 settings. Temporary privileges granted to deployment staff or added for troubleshooting are frequently left in place after the work is complete. If one of these accounts is compromised, the impact can be extensive.
The underlying problem is that granting and revoking privileges are handled as separate processes. Deployment completion checklists often verify that services work but omit the removal of temporary privileges, which are then passed on to the next person responsible.
Check Role assignments in the Microsoft 365 admin center. Start with Global Administrator assignments. If the privileges exceed what the work requires, consider a role with a narrower scope, such as User Administrator or SharePoint Administrator.
At a minimum, record the user, the purpose of the account, and whether the privileges are still needed. Do not mark an account as reviewed if its purpose is unknown. Do not delete emergency access accounts solely because they are used infrequently; manage them separately from regular staff accounts.
MFA: Enabled Does Not Necessarily Mean Protected
MFA verifies a user's identity by combining a password with another factor, such as an authentication app. Day-to-day operations require two checks: whether users have registered authentication methods and whether policies enforce MFA. Registering the Microsoft Authenticator app does not necessarily mean that business applications are protected as intended. Common gaps include failing to add new employees to a Conditional Access group or remove temporary exclusions. A policy may exist while some users remain outside its scope. A policy in report-only mode evaluates sign-ins but does not enforce access controls. In the Microsoft Entra admin center, check whether security defaults are enabled and whether users have registered authentication methods. If you use Conditional Access, check the target users and resources, exclusions, and policy status. Then review authentication details and applicable policy results in the sign-in logs. A user may be protected by security defaults or Conditional Access even when the per-user MFA list shows 'Disabled,' so do not rely on that display alone. The review is complete when you have confirmed the intended scope, exceptions, and results for representative accounts in the logs.
External Sharing: Are Links for Completed Projects Still Active?
Reviewing external sharing requires checking both organization-wide settings and the files that are actually shared. Project documents are often retained after work ends, and external permissions may remain unless retention and access removal are managed separately. Prioritize folders for completed projects. Ask the owner whether the external party still needs access and whether edit permission is necessary. An 'Anyone' link can be forwarded and used without authentication, so retain it only when there is a valid business reason. In the SharePoint admin center, review Policies > Sharing and each site's settings, then use Manage Access to inspect links and permissions for relevant files and folders. Changing the default for future links does not remove existing links. Revoke access that is no longer needed and confirm that any remaining view or edit permissions are appropriate. Also check whether anonymous links remain on confidential information.
Audit Logs: Can You Retrieve the Activity Records You Need?
Audit logs record user and administrator actions so they can be traced later. When suspicious file sharing or configuration changes occur, they provide evidence of who acted on which file and when.
Being able to open the admin interface is not enough to verify auditing. Because this feature is used infrequently, many teams only discover that logs are unavailable or that they lack search permissions when an incident prompts an investigation.
Do not assume auditing is enabled by default. Microsoft documentation also states that auditing must be turned on manually for plans such as Business Basic, Business Standard, and Business Premium.
Go to Solutions → Audit in the Microsoft Purview portal.
To check auditing, perform 1 test action at a known time. For example, share a test file subject to auditing, wait briefly, and then search the logs. If you can retrieve the actor, target file, and action timestamp, you can confirm that recording and searching are working.
If the search returns no results, do not immediately assume that no logs exist. Check the search period, activity type, search permissions, and log ingestion delays in sequence.
Log retention is another common oversight. Standard auditing can retain 180 days of logs, but you need to compare this with your licenses and retention policies to confirm that it covers the investigation period your business requires.
Auditing is ready for operational use when investigators can search the required logs and those logs can be retained for the required period.
Licenses: Have the Purchased Features Been Assigned to the Intended Users?
Licenses define the contractual rights to use each feature. Review the plans purchased by the organization separately from the licenses assigned to individual users.
For example, if a higher-tier plan was initially trialed by a subset of users and later expanded, check that the users covered by the configuration match those assigned licenses. Review the paid subscription arrangements after the trial ends as well.
| Feature in Use | Main License Requirements |
| Standard Conditional Access | Microsoft Entra ID P1. Also included in Microsoft 365 Business Premium. |
| Controls based on user risk and sign-in risk | Requires capabilities equivalent to Microsoft Entra ID P2 |
In the Microsoft 365 admin center, open Billing → Licenses and each user's Licenses and apps page. Compare the intended feature users with license assignments. If licenses are assigned through groups, check for assignment errors as well.
This check is complete when the required usage rights are assigned to the intended users, the services they use are enabled, and trial expiration dates are known. The presence of a setting in the admin interface alone does not prove compliance with licensing terms.
The 5 areas covered here are fundamental checks for maintaining Microsoft 365 security. Deployment settings can drift out of alignment with actual conditions over time, so regular reviews are recommended. Excessive privileges, abandoned sharing links, and overlooked MFA settings can become unnoticed sources of risk. Use this checklist to assess the security of your Microsoft 365 environment.



