Microsoft 365 Tenant Health Check Checklist for Small Businesses
One employee account with weak sign-in protection can expose your email, files, and customer conversations. A Microsoft 365 tenant health check helps you find those gaps before they interrupt work.
You don't need a large IT department to do it. Start with accounts and administrator access, then check email, sharing, devices, logs, licenses, and recovery. Record each gap, give it an owner, and fix the highest-risk items first.
Key takeaways
- Essential first: Require multifactor authentication (MFA), limit administrator access, secure email, and confirm you can recover important data.
- Check what applies: Your Microsoft 365 license determines whether you can use tools such as Conditional Access and device compliance policies.
- Keep the review repeatable: A short, scheduled check catches new users, old guest access, failed protections, and expired exceptions.
Start with an inventory you can trust
Before changing policies, confirm which accounts, subscriptions, and services your business uses. A rushed cleanup can lock out a scanner or remove access that payroll needs.
Match accounts to people and purposes
Export or review active users in the Microsoft 365 admin center. Identify employees, contractors, shared mailboxes, service accounts, and former staff. Every interactive account should have a known owner.
Essential: Disable access for departed users after following your offboarding and data-preservation process. Investigate accounts nobody recognizes. Note any applications or devices that send mail or sign in without a person present.
Check licenses against the protections you expect
Review subscriptions and assigned licenses. Confirm that staff who need security features have the right plan, and reclaim licenses assigned to accounts that no longer need them.
Microsoft 365 Business Premium includes Microsoft Entra ID P1, which supports Conditional Access. It also includes device management capabilities. If you need help reconciling subscriptions with your setup, Microsoft 365 setup and support can cover that work alongside tenant configuration.
Secure every sign-in before adding complex rules
Identity is the first priority in a Microsoft 365 tenant health check. A stolen password can give an attacker access to a mailbox, OneDrive files, and conversations that help them impersonate staff.
Verify MFA for users and administrators
Check the effective sign-in policy, not just whether someone registered an authentication method. Make sure every person who signs in, including owners and administrators, is covered by MFA.
Microsoft's Security Defaults provide a simpler baseline for many small businesses. If they're already enabled, verify coverage and document any exceptions. Review older applications and mail-sending devices before blocking legacy authentication, then replace sign-in methods that can't meet your policy.
For a staged rollout, use a small-business Microsoft 365 MFA plan so employees know how to enroll and where to get help.
Use Conditional Access only when your license supports it
Conditional Access offers more control over who can sign in and under what conditions. It requires a qualifying license, such as Entra ID P1 or Microsoft 365 Business Premium. Security Defaults and Conditional Access can't operate together.
Optional improvement: Use Conditional Access for targeted access rules after testing them with a small group. Risk-based sign-in policies have additional licensing requirements. Check those entitlements before planning around them, and maintain a tested emergency access procedure in case a policy blocks administrators.
Reduce administrator access and document exceptions
Admin accounts can change security settings, grant access, and remove data. Review them separately from ordinary user accounts.
Give admins only the roles they need
In the Microsoft 365 and Entra admin centers, list Global Administrators and other privileged roles. Remove assignments that no longer match someone's job. Use named accounts rather than shared credentials, and give administrators separate accounts for daily work and privileged tasks.
Essential: Confirm every privileged account has strong MFA protection. Include partner and vendor access in the review. If an IT provider manages the tenant, your business should still know who has access and how to contact them.
Prepare for a locked-out administrator
Document who can authorize an emergency change and how to reach your support provider. Keep emergency access accounts under strict control, monitor their use, and test the recovery procedure.
A written exception also needs an owner and an expiration date. Otherwise, temporary access granted for a project can stay in place long after the project ends.
Check email protection and domain authentication
A fake invoice may look like an ordinary message from a vendor. Mail controls should help staff spot it, while making it harder for attackers to impersonate your domain.
Verify SPF, DKIM, and DMARC
Check every domain your business uses to send mail, including services that send invoices or appointment reminders. SPF identifies authorized senders, DKIM signs messages, and DMARC tells receiving systems how to handle messages that fail authentication checks.
Essential: Confirm legitimate senders appear in your configuration before tightening DMARC enforcement. Also review mailbox forwarding and inbox rules for destinations or behavior nobody approved. Unauthorized forwarding can keep leaking mail after a compromised account is secured.
Review filtering and employee reporting
Check the anti-phishing and malware protections available in your plan. Microsoft Defender for Office 365 preset security policies can provide a starting point where licensed. Review how impersonation protection treats owners, finance staff, and anyone who approves payments.
Make it easy for employees to report suspicious messages in Outlook. Then confirm someone receives and investigates those reports. Optional improvement: Add Safe Links or Safe Attachments where your license includes them, and review false positives before making filtering stricter.
Control SharePoint, OneDrive, and guest sharing
File access often outlasts the business reason for granting it. A health check should examine both organization-wide sharing settings and permissions on sensitive sites.
Check link defaults and external access
Review whether people can create links that anyone can open. For client files and financial records, links restricted to named recipients are often easier to control. Check who can invite guests and whether site-level settings are tighter where needed.
Essential: Ask site owners to review external members and remove access when work ends. If staff needs another way to exchange sensitive files, secure file sharing with SJC Sync offers controls such as credentialed access and link expiration.
Look for access that no longer fits
Inspect shared folders used for payroll, contracts, and customer records. A site may have appropriate default settings while an old guest or broad link still exposes files.
Optional improvement: Where your license supports them, use sensitivity labels or data loss prevention rules for information that needs stricter handling. Start with a small set of records so employees understand the rules.
Confirm devices can protect business data
A secure account can still expose files through a lost laptop or an unpatched phone. List the devices employees use for Microsoft 365, including personal devices where your policy permits them.
Verify the basic protections
Essential: Check that company laptops receive operating system and browser updates, use screen locks, and run endpoint protection. Confirm disk encryption is active where business data is stored locally. BitLocker and FileVault are common options for Windows and Mac devices.
Don't rely on a policy that exists only in an admin portal. Check a sample of devices for actual protection and follow up on machines that have stopped reporting.
Apply managed-device rules carefully
If your plan includes Microsoft Intune, review enrollment and compliance status. Decide which devices must be managed before accessing sensitive files, then test access with staff who work remotely.
Optional improvement: Pair device compliance with Conditional Access where licensed. Give employees time to enroll their devices before enforcing a rule that could block everyday work.
Verify audit logs and review the right alerts
Logs help you understand suspicious sign-ins, changed permissions, and unusual file activity. They won't help if nobody can search them or knows when to investigate.
Test audit access and retention
Confirm an authorized person can search Microsoft Purview audit records and inspect relevant Entra sign-in activity. Check events involving administrator changes, mailbox rules, guest invitations, and sharing.
Microsoft's Audit (Standard) records generated on or after October 17, 2023, generally have a 180-day default retention period . Verify that your available records meet your investigation and compliance needs. Audit retention is separate from backup retention.
Use Secure Score as a work queue
Microsoft Secure Score recommends actions based partly on your licensed products. Review it for missed controls, assign each useful recommendation an owner, and document why you defer an action.
A higher score doesn't prove your tenant is safe. Restores, endpoint updates, and staff reporting still need attention. For a broader baseline, compare your findings with these Microsoft 365 security basics for small businesses.
Prove you can recover the data that matters
Microsoft 365 keeps services running, but service availability doesn't tell you how quickly your business can restore an accidentally deleted folder or compromised mailbox.
Define the recovery scope
Identify the mailboxes, SharePoint sites, and OneDrive accounts your business depends on. Document how you'll recover each one, who approves a restore, and how long the business can operate without it.
Microsoft 365 Backup covers Exchange mailboxes, SharePoint sites, and OneDrive accounts. If you use it or another backup product, verify the workloads and restore options in your actual configuration. Don't assume every Teams conversation or connected application has the same coverage.
Run a safe restore test
Essential: Restore a test file or mailbox item and confirm the right person can open it. Record the time it took and any missing permissions or steps. Repeat tests after major changes to your backup setup.
For businesses also planning around office outages or storms, backup and disaster recovery services can address recovery beyond the tenant. Optional improvement: Test a larger recovery scenario once routine file restores work reliably.
Put the checklist on a manageable schedule
One person or IT provider should own the findings. Keep a simple record with the issue, priority, owner, due date, and proof that the fix worked.
A small team can start with this review rhythm:
| Frequency | Check | Who should own it |
|---|---|---|
| Weekly | Review security alerts, sign-in concerns, and urgent Secure Score findings. | IT contact or provider |
| Monthly | Review administrators, departed users, forwarding rules, and guest access. | IT contact and business owner |
| Quarterly | Reconcile licenses, inspect device coverage, and test a small restore. | IT contact or provider |
| Annually | Review recovery procedures and rehearse an outage response. | Business owner and IT contact |
These intervals are starting points, not a substitute for responding to an active alert. If no one has time to own the work, a managed IT services checklist for small businesses can help clarify what to assign to a provider.
Frequently asked questions
How often should a small business run a tenant health check?
Review alerts weekly and access changes monthly. Run a broader check after a major hiring change, migration, security incident, or license change. Schedule restore tests rather than waiting for a deletion.
Do we need Business Premium to do this?
No. Account cleanup, role reviews, sharing checks, mail authentication, and recovery planning still matter on other plans. Business Premium adds controls such as Entra ID P1 for Conditional Access. Confirm your exact entitlements before building a policy around a feature.
What should we fix first if several checks fail?
Start with unprotected administrator accounts and users without MFA coverage. Next, investigate unknown accounts, suspicious forwarding, and exposed files. Assign an owner to each remaining issue so lower-priority work doesn't disappear.
Conclusion
The biggest tenant risks often come from ordinary changes: an old account stays active, a guest keeps access, or a backup goes untested. A Microsoft 365 tenant health check turns those loose ends into assigned work.
Secure sign-ins first, confirm your protections apply, and test recovery. Then keep the review short enough that your business can repeat it.

