Planning guide · Assessment checklist

A Microsoft 365 security assessment checklist built around decisions—not box-ticking.

Use this checklist to prepare the people, scope, evidence, and outputs that make an assessment actionable. Adapt it to your licensing, architecture, risk, and operating model.

Before evidence collection

1. Define why the assessment is happening.

A useful assessment begins with a business question. Without it, teams can spend time collecting settings while missing the decisions stakeholders actually need to make.

  • Name the trigger: risk reduction, leadership planning, customer assurance, audit preparation, insurance, a Microsoft 365 change, or another defined need.
  • Identify the decision owner, technical contacts, report audience, and people who can explain approved exceptions.
  • Record important dates, dependencies, known incidents, open projects, and areas that are explicitly out of scope.
  • Agree that the review is a configuration and control assessment—not a penetration test, continuous monitoring service, legal opinion, or compliance certification.

2. Map the environment and its boundaries.

  • List tenants, verified domains, user populations, identity sources, administrative boundaries, and any mergers or migrations that affect the picture.
  • Document Microsoft 365 licenses and security products so controls can be assessed for applicability rather than assumed.
  • Describe managed and unmanaged devices, supported platforms, remote access patterns, service accounts, workload identities, guests, and external collaborators.
  • Identify third-party security, email, identity, backup, mobile-device, or monitoring tools that alter the intended control design.
Scope test: another reviewer should be able to tell which tenant, identities, services, devices, and evidence sources are included—and which are not.
Control domains

3. Review the connected control system.

The checklist should follow attack paths and operating dependencies across Microsoft 365, not treat product portals as isolated silos.

Identity and privilege

Administrative roles, authentication methods, multifactor authentication registration, emergency access, privileged workflows, inactive identities, guests, and workload identities.

Conditional Access

Policy coverage, exclusions, report-only policies, device and location conditions, authentication requirements, session controls, and change safety. Use the focused Conditional Access checklist.

Email protection

Mail-flow rules, forwarding, mailbox auditing, anti-phishing protections, email authentication, alert paths, and Defender for Office 365 capabilities where licensed.

Collaboration and data

SharePoint, OneDrive, Teams, guest access, sharing defaults, anonymous links, ownership, information protection, and the operational handling of exceptions.

Applications and consent

Enterprise applications, delegated and application permissions, consent settings, service principals, credentials, ownership, and review processes.

Devices and Intune

Enrollment, compliance, configuration, endpoint security, encryption, application protection, platform coverage, exceptions, and stale records. Use the focused Intune checklist.

Detection and response

Audit availability, alert routing, investigation ownership, retention expectations, Microsoft Defender integrations, incident paths, and evidence that workflows operate.

Resilience and recovery

Administrative recovery, emergency access validation, ownership of continuity decisions, recovery dependencies, and the limits of native or third-party protection.

Governance and change

Control ownership, review cadence, exception approval, documentation, license constraints, backlog management, and validation after changes.

Evidence and output

4. Make evidence handling explicit.

  • Choose approved collection methods and least-privilege access appropriate to the agreed scope.
  • Document where evidence is processed, who can access it, how it is transferred, and when it is retained or deleted.
  • Pair configuration evidence with interviews or records that explain intended operation, dependencies, and accepted exceptions.
  • Set a process for ambiguous or unavailable evidence instead of silently treating absence as proof of failure or success.

5. Require deliverables that support action.

  • An executive narrative connecting material findings to business decisions.
  • Technical findings with the observed condition, supporting evidence, risk, recommendation, and affected scope.
  • A prioritized action register that accounts for exposure, impact, dependencies, effort, ownership, and sequencing.
  • Clear separation between assessment findings and any separately approved implementation work.
  • A readout where stakeholders can challenge assumptions, confirm exceptions, and agree on next steps.

See how TenantShield approaches evidence and prioritization, review the sample assessment output, or explore the assessment service.

Turn the checklist into an evidence-backed plan.

Run the free checker for an initial view, or request a defined Microsoft 365 assessment when the decision needs analyst review.