A Microsoft 365 hardening guide should not begin with a long checklist of settings. It should begin with the services your organisation cannot afford to lose: executive email, sensitive SharePoint sites, Teams collaboration, privileged accounts and the identities that control them. Attackers do not care whether a control looks green in a portal. They care whether a compromised account can reach valuable data, create persistence or interrupt a critical service.

For regulated organisations and complex estates, the challenge is rarely a lack of Microsoft security capability. The challenge is knowing which controls are actually enforced, where exceptions have accumulated and whether the configuration reflects current business risk. Effective hardening turns that uncertainty into evidence and prioritised action.

Start with exposure, not settings

Microsoft 365 spans identity, endpoints, messaging, collaboration and cloud applications. Treating each area as a separate project creates gaps between teams and a great deal of manual assurance work. Start by establishing a clear baseline of what is connected and exposed.

This means identifying every active tenant, verified domain, administrator account, guest relationship, application registration and privileged service account. It also means understanding which business services rely on them. A dormant Global Administrator account is a problem. A dormant Global Administrator account tied to a payroll integration or an emergency access process is a problem that needs careful remediation, not blind removal.

Hardening decisions need this context. Security teams should be able to answer three basic questions quickly: what is exposed, who owns it and what business impact follows if it is compromised. Without those answers, teams tend to work through generic recommendations while more consequential weaknesses remain open.

Secure identity first

Identity is the control plane for Microsoft 365. A weak sign-in policy can undermine well-configured email, SharePoint and endpoint controls in a single successful attack.

Enforce phishing-resistant authentication where it matters most

Multi-factor authentication should be enforced for all users, but not all methods provide the same assurance. SMS and voice-based methods are better than passwords alone, yet they remain vulnerable to social engineering, SIM swapping and adversary-in-the-middle attacks. Prioritise phishing-resistant methods such as FIDO2 security keys, passkeys or certificate-based authentication for administrators, finance teams, senior leaders and users with access to sensitive services.

Conditional Access should then enforce the policy rather than merely record a recommendation. Require stronger authentication for privileged roles, unfamiliar locations, unmanaged devices and high-risk sign-ins. Use report-only mode to assess likely disruption before enforcement, but set a defined end date for that assessment. Report-only policies that remain indefinitely are not a compensating control.

Emergency access accounts need particular discipline. Maintain a small number, protect them with strong credentials and test them. Exclude them only where necessary to prevent tenant lock-out, then monitor every use. An excluded account that is never reviewed is an attractive path around your strongest identity controls.

Remove legacy paths and excessive privilege

Disable legacy authentication protocols unless a documented dependency requires them. These protocols bypass modern authentication controls and continue to feature in password-spray and credential-stuffing attacks. Where an exception is unavoidable, record the service owner, expiry date, source addresses and replacement plan.

Apply least privilege to Microsoft Entra roles and Microsoft 365 administration. Global Administrator should be exceptional, not a convenient default for IT staff or third parties. Use role-specific administration and just-in-time elevation where licensing and operating models permit it. The trade-off is operational: narrower access can slow urgent support work if processes are poorly designed. That is a reason to improve access workflows, not to leave standing privilege in place.

Review enterprise applications and app registrations with the same care. Consent grants, high-privilege API permissions and long-lived secrets can give attackers a route that survives a user password reset. Restrict user consent, review privileged permissions, remove unused applications and rotate credentials on a defined schedule.

Apply the Microsoft 365 hardening guide to collaboration

Email and collaboration are where identity compromise becomes data loss, fraud or operational disruption. Hardening must account for how people actually share information, including with suppliers, advisers and public-sector partners.

Protect mail from impersonation and malicious content

Configure SPF, DKIM and DMARC for every domain that sends mail on your behalf. Move DMARC from monitoring towards quarantine or reject once legitimate sending sources are understood. Domain protection is not just an email-team task: marketing platforms, CRM systems and outsourced services often send as your organisation and must be included.

Use anti-phishing and anti-malware policies that protect high-value users and detect impersonation. Block automatic forwarding to external recipients unless there is a controlled business requirement. Review mailbox forwarding rules, inbox rules and delegated access regularly, as these are common persistence mechanisms after account compromise.

Make external email visible to users, but do not rely on banners as the primary control. A convincing fraudulent message can still pass through a crowded inbox. Authentication, policy enforcement and monitored exceptions provide stronger assurance.

Limit uncontrolled sharing in SharePoint, OneDrive and Teams

External collaboration is often necessary. Blanket restrictions can drive users towards personal file-sharing tools, creating a larger visibility problem. Instead, define sharing rules by information sensitivity and business need.

Avoid anonymous links for sensitive sites and set practical expiry periods for external sharing. Restrict who can invite guests, require appropriate authentication and review guest access that has not been used for a defined period. For high-consequence content, use labelled sites and documents with clear ownership, access conditions and retention requirements.

Teams also requires governance. Control who can create teams, understand which teams permit guest access and prevent unmanaged apps or connectors from moving data into unapproved services. The objective is not to eliminate collaboration. It is to ensure collaboration remains accountable and recoverable.

Bring device compliance into the access decision

A well-protected identity can still be used on an unpatched or unmanaged endpoint. Conditional Access should therefore consider device state, particularly for privileged and sensitive data access. Require compliant or hybrid joined devices where the risk warrants it, and use application protection policies for mobile access where full device management is not appropriate.

Baseline configuration matters. Encrypt devices, enforce supported operating systems, maintain endpoint protection, control local administrator rights and apply timely security updates. Yet a device marked compliant is only useful if the compliance policy is meaningful and current. Review policies against real threats, not simply whether they were deployed years ago.

Organisations with mixed estates need proportionate controls. Contractors, frontline workers and personally owned devices may need restricted browser access or app-level protection rather than the same management model as corporate laptops. A single policy applied everywhere is simpler to describe but rarely delivers the right balance of risk and usability.

Turn logging into operational evidence

Hardening without verification is a point-in-time exercise. Configurations change through project work, urgent fixes, acquisitions, licensing changes and delegated administration. Continuous visibility is what turns a baseline into assurance.

Enable and retain audit logging at a level aligned to your investigation and regulatory requirements. Monitor high-impact events, including administrator role assignments, Conditional Access changes, application consent, mailbox forwarding, external sharing and changes to retention or security policies. Make sure alerts have named owners and a response path. An alert no one can investigate is noise, not detection.

Evidence should be available without a manual scramble before an audit, insurance renewal or board review. Security leaders need to show not only that a control exists, but where it applies, what exceptions are approved, when it was last validated and which business services remain exposed.

This is where an integrated assurance approach reduces effort. Rebasoft can provide continuous visibility across Microsoft 365 identities, configurations and services alongside the wider environment, helping teams connect a control gap to the asset, owner and business impact that matter. The value is not another dashboard. It is faster, defensible prioritisation.

Prioritise the gaps that change risk

A hardening score is useful as a prompt, but it is not a risk model. A low-score recommendation affecting an unused feature may be less urgent than one exception that allows legacy sign-in to a finance administrator account. Prioritisation should consider exposure, privilege, data sensitivity, attack likelihood, compensating controls and service criticality.

Create a remediation cadence that distinguishes immediate action from planned improvement. Active high-risk exposure, excessive privilege and unprotected critical identities belong in the urgent queue. Configuration changes with a potential business impact should have an owner, test plan and deadline. Accepted risks should be recorded with an expiry date, not silently absorbed into operational practice.

The most useful closing question is not, “Have we completed the checklist?” It is, “Can we prove that the identities, devices and collaboration services our organisation relies on are configured to resist the threats we face?” If the answer is unclear, start with visibility and evidence. The right next action will become much easier to defend.