Privileged access
Identify administrators and how privileged accounts are used. Check that the access is justified and reviewed.
Useful evidence: An agreed role inventory and records of privileged-access reviews.
Practical guide / Microsoft 365
A starting point for New Zealand organisations reviewing identity, email, information and operational controls. Ask what is configured, what it achieves and which evidence demonstrates that it works.
Use the checklistTwelve areas to examine
Identify administrators and how privileged accounts are used. Check that the access is justified and reviewed.
Useful evidence: An agreed role inventory and records of privileged-access reviews.
Review coverage, exclusions and recovery arrangements. Test changes before enforcing a policy that could block legitimate access.
Useful evidence: Coverage and exception records, plus a controlled rollout plan.
Trace a joiner, role change and leaver through the approval and access-removal process.
Useful evidence: Approved requests and evidence that access changed as intended.
Inventory legitimate senders. Review SPF, DKIM and DMARC alignment before moving to a restrictive policy.
Useful evidence: Sender inventory, authentication results and monitoring evidence.
Review anti-phishing and related protection settings against the available licences and business workflow.
Useful evidence: Policy configuration, exceptions and a record of reviewed outcomes.
Review guest accounts, sharing links and ownership of collaborative sites.
Useful evidence: An access review with accountable decisions and follow-up.
Identify the information that needs protection and where it is held before choosing labels or restrictive controls.
Useful evidence: Agreed classification and control decisions linked to business use.
Confirm what events are collected, how long they remain available and who reviews relevant alerts.
Useful evidence: Logging configuration, ownership and a tested investigation example.
Check recovery responsibilities and test a realistic restoration scenario; do not infer recoverability from a successful backup indicator.
Useful evidence: Restore-test records with results, limits and follow-up actions.
Review permissions granted to connected applications and whether an owner still requires them.
Useful evidence: An application inventory and permission-review decisions.
Record the intended outcome, approval, test and recovery plan before security-impacting changes.
Useful evidence: A change record with pre-change evidence and post-change verification.
Assign owners and review triggers for the controls. A one-time assessment does not keep a tenant secure indefinitely.
Useful evidence: A maintained action register with dates, owners and evidence links.
Turn observations into action
Prioritise the business exposure, the strength of evidence and the dependencies. Assign an owner and a verification step to every agreed change. Retain a clear distinction between settings observed, risks inferred and outcomes tested.
Discuss a Microsoft 365 security assessment · Explore email security · Explore data protection
Using this guide
No. This is an original review aid, not a complete Microsoft baseline or a guarantee of security. Tenant configuration, licensing, integrations and business requirements change the appropriate controls. Validate current Microsoft guidance and assess impact before making changes.
No. Changes to authentication, mail flow, sharing and retention can affect access and business operations. Establish authority, test the proposed change, record exceptions and define recovery steps before enforcing it.
Yes. An assessment can establish the current state and prioritise actions, with implementation separately scoped and approved. The proposal defines the environment, access, deliverables and responsibilities; this guide is not a fixed-price implementation package.
Primary references
Page prepared and source references checked . References explain the relevant standard or technology; they are not endorsements of Aegentra.
Discuss the next step
Start with the requirement, the systems involved and the outcome you need. Please do not send passwords, sensitive records or unrestricted tenant access in an initial enquiry.