Microsoft 365 Security

Microsoft 365 Security Checklist
Stop Phishing & Breaches

Twenty-eight Microsoft 365 settings that block 95% of SME phishing and breach attempts. Brisbane SME-friendly walkthrough with screenshots and cost estimates.

April 2026
12 min read
Brisbane, QLD
ACSC Aligned
ACL Compliant
ASD Trained

Microsoft 365 ships with most of the controls a small Australian business needs — but very few SMEs have them turned on, configured properly, or monitored. This 28-point checklist is what we apply to every Brisbane SME tenant during a hardening project. It blocks an estimated 95% of phishing and breach attempts and aligns with ACSC Essential Eight Maturity Level 1.

Tick what is done, plan what is not. Then book a chat if you are stuck — most points take 5-30 minutes apiece, but the order and dependencies matter.

What this checklist achieves

Aligns your Microsoft 365 tenant to ACSC Essential Eight Maturity Level 1, satisfies most Australian cyber-insurance renewal questionnaires, and demonstrates 'reasonable steps' under the Privacy Act 1988.

Why This Checklist, Right Now

2025 was the year M365 phishing went mainstream in Australia. Attacker-in-the-middle (AITM) kits like EvilProxy and Tycoon now bypass simple SMS MFA in seconds. Brisbane SMEs in legal, accounting and health practices have been the most-targeted local sectors.

What works against AITM and modern phishing:

  • Number-matching MFA + Conditional Access
  • Token-protection / device compliance
  • Anti-phishing & safe-links policies
  • Active monitoring of risky sign-ins

Identity (8 Controls)

  1. 1. MFA enforced for every user (number-matching)
    Microsoft Authenticator with number-matching enabled. SMS as fallback only.
  2. 2. Block legacy authentication
    Conditional Access policy: block POP, IMAP, SMTP-AUTH.
  3. 3. Conditional Access — require compliant device
    Block sign-ins from unmanaged devices.
  4. 4. Conditional Access — geo-block
    Allow only Australia (or AU+NZ). Add countries case-by-case.
  5. 5. Hardware FIDO2 keys for admins
    Yubikey or Microsoft Authenticator passkey for tenant/global admins.
  6. 6. Just-in-time admin (Microsoft Entra PIM)
    Admin role granted on demand, expires automatically. Requires Entra P2.
  7. 7. Self-service password reset (with MFA challenge)
    Reduces helpdesk load and risky password sharing.
  8. 8. Token protection (preview/GA)
    Binds session token to device; defeats AITM relay attacks.

Email & Messaging (7 Controls)

  1. 9. SPF, DKIM, DMARC live
    DKIM enabled in Defender > Email; DMARC at p=quarantine minimum.
  2. 10. Anti-phishing policy on (Strict preset)
    Mailbox intelligence + impersonation protection for VIPs.
  3. 11. Safe-Links on (inbound, internal, outbound)
    URL detonation in email and Teams.
  4. 12. Safe Attachments on (Block action)
    Sandbox detonation for incoming attachments.
  5. 13. Block common malicious attachment types
    htm, html, iso, scr, vbs, js — block at gateway.
  6. 14. External email banner
    Visual warning on every external email.
  7. 15. Mailbox audit logging on
    Default in 2026, but verify it is on for every mailbox.

Device & Endpoint (6 Controls)

  1. 16. Microsoft Intune enrolled (or equivalent MDM)
    Centralised policy, compliance, remote wipe.
  2. 17. BitLocker / FileVault enforced
    Required for compliance. Recovery keys backed up to Entra/Azure AD.
  3. 18. Defender for Endpoint (or equivalent EDR)
    Not just free Defender — Defender for Endpoint with cloud-delivered protection.
  4. 19. Windows / macOS auto-patching enforced
    Intune Autopatch (Win), Intune for Mac, or Jamf.
  5. 20. Block USB / removable media (or audit)
    Defender attack surface reduction rule.
  6. 21. App-protection policies for mobile
    BYOD phones can read M365 mail without enrolling — but data is sandboxed.

Data & DLP (4 Controls)

  1. 22. M365 cloud-to-cloud backup
    Microsoft does not back up the way you think. Datto, Spanning, Veeam, Synology Active Backup.
  2. 23. Sensitivity labels (Public / Internal / Confidential / Highly Confidential)
    Auto-label TFNs, Medicare numbers, credit cards.
  3. 24. DLP policy — block external sharing of sensitive content
    Sharepoint, OneDrive, Teams, Exchange.
  4. 25. Sharing defaults — disable anonymous link sharing
    Existing-employees-only or specific-people-only by default.

Monitoring & Response (3 Controls)

  1. 26. Risky sign-in alerts (Entra ID Protection)
    Impossible-travel, anonymous IP, unfamiliar location.
  2. 27. Mailbox forwarding-rule alert
    Most reliable single indicator of an active BEC.
  3. 28. Documented incident response plan
    Print and stick on the wall: 'who do I call?'.

Suggested Schedule

Day 1 (4-6 hr)

Identity 1-5. Email 9-15. The 80% protection set.

Week 2

Intune, BitLocker, Defender for Endpoint, Patching.

Week 3-4

DLP, sensitivity labels, sharing defaults, monitoring alerts.

Quarterly

Restore drill, phishing sim, Entra PIM review, sharing audit.

Brisbane SME Context

What we adjust for Brisbane SMEs vs national templates:

  • Conditional Access trusted IP — office IP whitelisted reduces friction in CBD/Fortitude Valley offices, MFA enforced from anywhere else
  • Storm-season offline backup — make sure cloud-to-cloud copy is genuinely offsite from Brisbane data centres
  • Remote/hybrid workers — many Brisbane SMEs have staff in Sunshine Coast or Gold Coast — Conditional Access geo-block at country level, not city

Costs in Brisbane

ServiceEffortCost
M365 hardening (full 28-point)1-3 days$1,230-$2,460
MFA + Conditional Access only4-6hr$615-$820
Defender for Office 365 setup3-4hr$410-$615
M365 cloud-to-cloud backup2hr setup + license$250 + $5/user/mo
Annual re-hardeningHalf dayFrom $820
Managed M365 security planOngoingFrom $99/user/month

Pro tip: Apply Microsoft's 'Standard' or 'Strict' security presets first — that gets you 60% of these controls in 30 minutes. Then layer the remaining custom items on top.

Watch for: Sharing-defaults rolled back. Many M365 tenants have 'Anyone with the link' enabled by default in SharePoint/OneDrive. One misclicked share = a public exposure.

Want Us to Run This Across Your M365?

Brisbane local. ACSC-aligned. From $1,230. Same-week scheduling.

Book M365 Hardening — From $1,230
Geeks Brisbane M365 hardening package

Full 28-point checklist applied, documented, tested. Pilot user, full rollout, staff training, 30-day handover review. From $1,640 for SMEs under 25 staff.

Brisbane SMEs Trust Us

4.9 stars across 100+ Google reviews

★★★★★

"Geeks Brisbane ran the 28-point M365 hardening across our 22-person legal practice. Two days of work, then a clean audit pack we sent straight to our cyber insurer. Renewed at the same premium despite the broader market rising. Worth it."

SM
Stuart M. Teneriffe
★★★★★

"I'm IT manager for a 40-person retail group. We had Conditional Access half-finished and Defender on default. Geeks finished the rollout in three days, found two open M365 OAuth apps we hadn't authorised, and produced a great handover doc."

KB
Karen B. Cleveland
★★★★★

"Sole-trader physiotherapist with M365 Business Premium. Geeks set up MFA, Conditional Access, sensitivity labels and cloud backup remotely in one afternoon. Fair price, super clear, no jargon."

OR
Owen R. Manly

How It Works

From scoping call to a hardened tenant — usually inside two weeks

1

Audit

Review of current M365 settings, licensing, gaps.

2

Plan

Documented 28-point hardening plan, prioritised.

3

Implement

Pilot, full rollout, staff training, handover.

4

Monitor

Quarterly check-ins or full managed plan.

Frequently Asked Questions

Common questions from Brisbane SMEs

For a 10-25 user Brisbane SME, 1-3 days of focused work spread over 1-2 weeks. We pilot identity changes with a small group first to avoid lock-outs.
For full coverage of this checklist — yes, or M365 E3/E5. Business Standard misses Conditional Access, Intune, and Defender. The licence step-up is around $11/user/month — far cheaper than a breach.
Not if rolled out properly. We pilot with one team, fix issues, then progressively roll wider. Self-service password reset and a clear support channel during rollout prevent any prolonged lock-outs.
Yes — Defender for Business is included in M365 Business Premium. Defender for Endpoint Plan 2 (with full EDR features) is included in M365 E5 or buyable as a standalone licence.
Sign into Microsoft 365 admin > SharePoint admin > Sharing. Set External sharing to 'Existing guests' or 'New and existing guests' — never 'Anyone'. OneDrive sharing should match.
Yes — almost the entire checklist is remote-friendly at $125/hr. We rarely need to be onsite for M365 hardening unless your firewall or on-prem servers also need attention.
Quarterly spot check. Full re-audit annually. Whenever Microsoft launches a new security preset or your headcount changes by 25%+.

Related: MFA Setup | Security Check | Internet Security

Harden Your Microsoft 365

Brisbane M365 specialists. 28-point hardening, ACSC aligned. From $1,230. 4.9 stars across 100+ reviews.

ACSC Aligned
Same Week Available
Privacy Act Mapped
4.9★ Google Rating

Main Menu

Contact Us