AegentraNew Zealand

Practical guide / Microsoft 365

Microsoft 365 security hardening checklist

A starting point for New Zealand organisations reviewing identity, email, information and operational controls. Ask what is configured, what it achieves and which evidence demonstrates that it works.

Use the checklist
On this page

Twelve areas to examine

Start with evidence, not a score.

Privileged access

Identify administrators and how privileged accounts are used. Check that the access is justified and reviewed.

Useful evidence: An agreed role inventory and records of privileged-access reviews.

Multi-factor authentication

Review coverage, exclusions and recovery arrangements. Test changes before enforcing a policy that could block legitimate access.

Useful evidence: Coverage and exception records, plus a controlled rollout plan.

User lifecycle

Trace a joiner, role change and leaver through the approval and access-removal process.

Useful evidence: Approved requests and evidence that access changed as intended.

Email authentication

Inventory legitimate senders. Review SPF, DKIM and DMARC alignment before moving to a restrictive policy.

Useful evidence: Sender inventory, authentication results and monitoring evidence.

Mailbox protection

Review anti-phishing and related protection settings against the available licences and business workflow.

Useful evidence: Policy configuration, exceptions and a record of reviewed outcomes.

External collaboration

Review guest accounts, sharing links and ownership of collaborative sites.

Useful evidence: An access review with accountable decisions and follow-up.

Sensitive information

Identify the information that needs protection and where it is held before choosing labels or restrictive controls.

Useful evidence: Agreed classification and control decisions linked to business use.

Logs and monitoring

Confirm what events are collected, how long they remain available and who reviews relevant alerts.

Useful evidence: Logging configuration, ownership and a tested investigation example.

Backup and recovery

Check recovery responsibilities and test a realistic restoration scenario; do not infer recoverability from a successful backup indicator.

Useful evidence: Restore-test records with results, limits and follow-up actions.

Applications and integrations

Review permissions granted to connected applications and whether an owner still requires them.

Useful evidence: An application inventory and permission-review decisions.

Change control

Record the intended outcome, approval, test and recovery plan before security-impacting changes.

Useful evidence: A change record with pre-change evidence and post-change verification.

Ongoing ownership

Assign owners and review triggers for the controls. A one-time assessment does not keep a tenant secure indefinitely.

Useful evidence: A maintained action register with dates, owners and evidence links.

Turn observations into action

Agree what changes first.

Prioritise the business exposure, the strength of evidence and the dependencies. Assign an owner and a verification step to every agreed change. Retain a clear distinction between settings observed, risks inferred and outcomes tested.

Discuss a Microsoft 365 security assessment · Explore email security · Explore data protection

Using this guide

Your questions, answered.

Is this a complete security baseline?

No. This is an original review aid, not a complete Microsoft baseline or a guarantee of security. Tenant configuration, licensing, integrations and business requirements change the appropriate controls. Validate current Microsoft guidance and assess impact before making changes.

Should I enable every security setting immediately?

No. Changes to authentication, mail flow, sharing and retention can affect access and business operations. Establish authority, test the proposed change, record exceptions and define recovery steps before enforcing it.

Can Aegentra help apply the checklist?

Yes. An assessment can establish the current state and prioritise actions, with implementation separately scoped and approved. The proposal defines the environment, access, deliverables and responsibilities; this guide is not a fixed-price implementation package.

Primary references

Check the current platform guidance.

Page prepared and source references checked . References explain the relevant standard or technology; they are not endorsements of Aegentra.

Discuss the next step

Make the scope clear.

Start with the requirement, the systems involved and the outcome you need. Please do not send passwords, sensitive records or unrestricted tenant access in an initial enquiry.