Identity and privilege
Administrative roles, authentication methods, multifactor authentication registration, emergency access, privileged workflows, inactive identities, guests, and workload identities.
Use this checklist to prepare the people, scope, evidence, and outputs that make an assessment actionable. Adapt it to your licensing, architecture, risk, and operating model.
A useful assessment begins with a business question. Without it, teams can spend time collecting settings while missing the decisions stakeholders actually need to make.
The checklist should follow attack paths and operating dependencies across Microsoft 365, not treat product portals as isolated silos.
Administrative roles, authentication methods, multifactor authentication registration, emergency access, privileged workflows, inactive identities, guests, and workload identities.
Policy coverage, exclusions, report-only policies, device and location conditions, authentication requirements, session controls, and change safety. Use the focused Conditional Access checklist.
Mail-flow rules, forwarding, mailbox auditing, anti-phishing protections, email authentication, alert paths, and Defender for Office 365 capabilities where licensed.
SharePoint, OneDrive, Teams, guest access, sharing defaults, anonymous links, ownership, information protection, and the operational handling of exceptions.
Enterprise applications, delegated and application permissions, consent settings, service principals, credentials, ownership, and review processes.
Enrollment, compliance, configuration, endpoint security, encryption, application protection, platform coverage, exceptions, and stale records. Use the focused Intune checklist.
Audit availability, alert routing, investigation ownership, retention expectations, Microsoft Defender integrations, incident paths, and evidence that workflows operate.
Administrative recovery, emergency access validation, ownership of continuity decisions, recovery dependencies, and the limits of native or third-party protection.
Control ownership, review cadence, exception approval, documentation, license constraints, backlog management, and validation after changes.
See how TenantShield approaches evidence and prioritization, review the sample assessment output, or explore the assessment service.
Run the free checker for an initial view, or request a defined Microsoft 365 assessment when the decision needs analyst review.