Runbook 02 — Microsoft 365 Security Review
Microsoft 365 has become a critical enterprise security boundary.
Organizations use it for:
Identity
Email
Messaging
Meetings
Documents
File Sharing
External Collaboration
Business Applications
Sensitive Data
Security MonitoringThis means a Microsoft 365 security weakness can affect far more than a single mailbox.
A compromised or poorly governed tenant may expose:
Executive Communications
Customer Information
Financial Documents
HR Records
Intellectual Property
Authentication Data
Business RelationshipsThe purpose of this runbook is to provide a repeatable methodology for performing an authorized Microsoft 365 security review.
Runbook Information
Section titled “Runbook Information”Runbook: Microsoft 365 Security Review
Type: Defensive Cloud Security Assessment
Level: Intermediate
Primary Roles: Microsoft Security Engineer, Cloud Security Engineer, Security Consultant
Supporting Roles: SOC Analyst, Identity Engineer, Microsoft 365 Administrator, GRC Analyst
Primary Objective: Identify Microsoft 365 security weaknesses and convert them into prioritized remediation actions
Runbook Outcome
Section titled “Runbook Outcome”At completion, you should have:
Tenant Architecture Summary
Administrative Access Matrix
Privileged Identity Review
Exchange Security Review
Mailbox Security Review
Email Protection Assessment
Teams Security Review
SharePoint Security Review
OneDrive Security Review
External Sharing Inventory
Application Access Review
Data Protection Assessment
Audit and Monitoring Assessment
Security Findings
Remediation Roadmap
Retest Plan
Executive Security ReportMicrosoft 365 Assessment Mental Model
Section titled “Microsoft 365 Assessment Mental Model”Use this sequence:
SCOPE ↓TENANT ↓IDENTITY ↓PRIVILEGE ↓EXCHANGE ↓EMAIL SECURITY ↓MAILBOXES ↓TEAMS ↓SHAREPOINT ↓ONEDRIVE ↓EXTERNAL SHARING ↓APPLICATIONS ↓DATA ↓AUDIT ↓MONITORING ↓INCIDENT READINESS ↓FINDINGS ↓REMEDIATION ↓RETEST01 — Confirm Authorization
Section titled “01 — Confirm Authorization”Before reviewing the tenant, confirm:
Written Authorization
Tenant in Scope
Services in Scope
Administrative Access Provided
Permitted Assessment Activities
Excluded Services
Assessment Window
Evidence Handling Requirements
Emergency ContactsDocument:
Assessment Name:
Tenant:
Business Owner:
Technical Owner:
Security Owner:
Start Date:
End Date:
Services in Scope:
Services Excluded:
Change Restrictions:02 — Define the Security Objectives
Section titled “02 — Define the Security Objectives”Typical objectives include:
Reduce Administrative Risk
Strengthen Identity Security
Protect Email
Reduce Phishing Exposure
Control External Sharing
Review Guest Access
Protect Sensitive Data
Reduce Application Risk
Improve Audit Visibility
Improve Incident Readiness03 — Define Services in Scope
Section titled “03 — Define Services in Scope”A Microsoft 365 assessment may include:
Microsoft Entra ID
Exchange Online
Microsoft Teams
SharePoint Online
OneDrive
Microsoft Defender Capabilities
Microsoft Purview Capabilities
Enterprise Applications
Audit and MonitoringCapabilities vary according to tenant configuration and licensing.
Do not report:
Feature Not Enabledas a vulnerability without first establishing whether that feature is:
Licensed
Required
Relevant
Part of the Approved Baseline04 — Understand Shared Responsibility
Section titled “04 — Understand Shared Responsibility”Microsoft protects the underlying cloud service.
The customer remains responsible for areas such as:
Identity
Access
Configuration
Applications
Data
Sharing
Governance
MonitoringThink:
MICROSOFT ↓CLOUD PLATFORMORGANIZATION ↓IDENTITY +CONFIGURATION +ACCESS +DATA +MONITORING05 — Establish an Evidence Repository
Section titled “05 — Establish an Evidence Repository”Use a controlled location.
Example:
M365-Security-Review|+-- 01-Scope|+-- 02-Tenant|+-- 03-Identity|+-- 04-Administration|+-- 05-Exchange|+-- 06-Email-Security|+-- 07-Mailboxes|+-- 08-Teams|+-- 09-SharePoint|+-- 10-OneDrive|+-- 11-External-Sharing|+-- 12-Applications|+-- 13-Data-Protection|+-- 14-Audit|+-- 15-Findings|+-- 16-Report06 — Protect Assessment Evidence
Section titled “06 — Protect Assessment Evidence”Evidence may contain:
Usernames
Email Addresses
Tenant Information
Administrative Roles
Application Names
Security Configuration
Sharing Relationships
Sensitive File MetadataApply:
Least-Privilege Access
Approved Storage
Encryption
Retention Requirements
Secure DisposalNever unnecessarily collect:
Passwords
Tokens
Private Keys
Authentication Secrets
Sensitive Message Contents07 — Establish the Tenant Baseline
Section titled “07 — Establish the Tenant Baseline”Document the current environment before recommending changes.
Capture:
Tenant Name
Verified Domains
User Population
Guest Population
Administrative Roles
Primary Services
Security Products
Data Protection Capabilities
Logging Architecture08 — Build the Tenant Overview
Section titled “08 — Build the Tenant Overview”Example:
| Area | Current State |
|---|---|
| Primary Domain | example.com |
| Users | Review |
| Guests | Review |
| Privileged Users | Review |
| Exchange Online | Enabled |
| Teams | Enabled |
| SharePoint | Enabled |
| OneDrive | Enabled |
| Central Monitoring | Review |
09 — Review Verified Domains
Section titled “09 — Review Verified Domains”Inventory business domains.
Capture:
Domain
Purpose
Owner
Verification Status
Mail Usage
Current RequirementAsk:
Is Every Domain Still Required?
Who Owns It?
Is It Used for Email?
Are Legacy Domains Still Present?10 — Review Administrative Roles
Section titled “10 — Review Administrative Roles”Identify tenant-level administrative access.
Prioritize roles capable of affecting:
Identity
Security
Exchange
Applications
Compliance
Tenant Configuration11 — Build the Administrative Access Matrix
Section titled “11 — Build the Administrative Access Matrix”| Identity | Role | Purpose | Permanent | Strong Authentication | Review |
|---|---|---|---|---|---|
| Admin-A | Tenant Admin | Emergency | Review | Yes | |
| Admin-B | Exchange Admin | Messaging | Yes | Yes | |
| User-C | Broad Admin | Unknown | Yes | Review |
12 — Validate Administrative Need
Section titled “12 — Validate Administrative Need”For every privileged identity ask:
Who Owns the Account?
Which Administrative Task Requires It?
Could a Smaller Role Work?
Does Access Need to Be Permanent?
How Is Its Use Monitored?13 — Review Least Privilege
Section titled “13 — Review Least Privilege”The preferred model is:
ADMINISTRATIVE TASK ↓MINIMUM REQUIRED ROLEnot:
ADMINISTRATIVE TASK ↓MAXIMUM TENANT PRIVILEGEFinding Example
Section titled “Finding Example”Finding:Excessive Microsoft 365 AdministrativePrivilege
Observation:An identity retains a broad tenantadministrative role despite requiring onlyservice-specific administration.
Risk:Compromise or misuse of the identity couldaffect multiple Microsoft 365 services andenterprise information.
Recommendation:Replace broad tenant privilege with theminimum administrative role required forthe documented responsibilities.14 — Review Privileged Account Separation
Section titled “14 — Review Privileged Account Separation”Determine whether administrators use separate identities for:
Normal Productivityand:
Privileged AdministrationA stronger model is:
rohit.user ↓Email / Teams / Documentsadm-rohit ↓Authorized Administration15 — Review Standing Privilege
Section titled “15 — Review Standing Privilege”Determine whether sensitive roles are:
Permanently Assignedor activated only when needed.
Where supported by the organization’s identity architecture, consider:
Just-In-Time Access
Approval
Time Limits
Audit Trail16 — Review Emergency Access
Section titled “16 — Review Emergency Access”Emergency or break-glass access should be:
Limited
Documented
Strongly Protected
Monitored
Tested
Excluded Only Where Explicitly RequiredDo not assume an emergency account is secure merely because it is rarely used.
17 — Review Administrative Authentication
Section titled “17 — Review Administrative Authentication”For privileged identities assess:
MFA
Authentication Methods
Conditional Access
Device Controls
Session Controls
Risk-Based ControlsSecurity Principle
Section titled “Security Principle”The combination:
HIGH PRIVILEGE +WEAK AUTHENTICATIONshould receive high assessment priority.
18 — Review Conditional Access Architecture
Section titled “18 — Review Conditional Access Architecture”Review policies affecting:
Administrators
Standard Users
Guests
Applications
Devices
Locations
Authentication RiskDocument:
Policy
Scope
Conditions
Controls
Exclusions
Business Owner19 — Review Conditional Access Exclusions
Section titled “19 — Review Conditional Access Exclusions”Pay particular attention to:
Excluded Users
Excluded Groups
Excluded Applications
Legacy Exceptions
Temporary ExceptionsAsk:
Why Does the Exclusion Exist?
Who Approved It?
Is It Still Required?
When Will It Expire?Finding Example
Section titled “Finding Example”Finding:Broad Conditional Access Exclusion
Observation:A user group is excluded from an importantidentity security policy without a currentdocumented requirement.
Risk:Excluded identities may authenticatewithout controls required by the tenantsecurity baseline.
Recommendation:Validate the exception, remove unnecessaryexclusions, and implement expiration andperiodic review for approved exceptions.20 — Review Guest Identities
Section titled “20 — Review Guest Identities”Inventory external users.
For each guest determine:
Sponsor
Organization
Business Purpose
Resources Accessed
Last Review
Current Requirement21 — Guest Lifecycle Model
Section titled “21 — Guest Lifecycle Model”Use:
INVITE ↓APPROVE ↓GRANT ACCESS ↓REVIEW ↓REMOVEnot:
INVITE ↓KEEP FOREVERFinding Example
Section titled “Finding Example”Finding:Stale Guest Accounts
Observation:External guest identities remain enabledafter the associated business relationshipor project has ended.
Risk:Former external collaborators may retainaccess to Microsoft 365 resources withoutcurrent authorization.
Recommendation:Remove stale guest access and implementrecurring sponsor-based access reviews.22 — Review Authentication Methods
Section titled “22 — Review Authentication Methods”Review which authentication methods are:
Allowed
Required
Used by Administrators
Used by Standard Users
Used for RecoveryAssess them against the organization’s security strategy.
23 — Review Risky Authentication Activity
Section titled “23 — Review Risky Authentication Activity”Where identity-risk capabilities are available, review:
Risky Sign-Ins
Risky Users
Unusual Locations
Unusual Devices
Suspicious Authentication PatternsDo not automatically conclude:
Risk Event=CompromiseValidate context.
24 — Review Exchange Online Architecture
Section titled “24 — Review Exchange Online Architecture”Document:
Accepted Domains
Mail Flow
Connectors
Transport Rules
Shared Mailboxes
External Forwarding
Delegated Access25 — Review Accepted Domains
Section titled “25 — Review Accepted Domains”For every domain determine:
Business Purpose
Current Requirement
Mail Role
OwnerIdentify obsolete or unexplained configurations.
26 — Review Mail Flow Rules
Section titled “26 — Review Mail Flow Rules”Create:
| Rule | Purpose | Owner | Security Impact | Review |
|---|---|---|---|---|
| Rule-A | Business routing | Messaging | Medium | Current |
| Rule-B | Filter bypass | Unknown | High | Review |
Look for rules that:
Bypass Filtering
Redirect Messages
Modify Security Handling
Apply Broad Exceptions27 — Review Mail Connectors
Section titled “27 — Review Mail Connectors”For each connector identify:
Source
Destination
Purpose
Authentication
Owner
Current RequirementLegacy connectors should receive particular attention.
28 — Review External Mail Forwarding
Section titled “28 — Review External Mail Forwarding”Identify mailboxes configured to forward externally.
Document:
Mailbox
Destination
Owner
Business Reason
Approval
Review DateFinding Example
Section titled “Finding Example”Finding:Unapproved External Mail Forwarding
Observation:A mailbox automatically forwards corporateemail to an external destination without adocumented business exception.
Risk:Sensitive communications may leave theorganization's managed Microsoft 365environment.
Recommendation:Disable unapproved forwarding and establisha controlled approval and periodic reviewprocess for legitimate exceptions.29 — Review Mailbox Delegation
Section titled “29 — Review Mailbox Delegation”Assess:
Full Access
Send As
Send on BehalfFor sensitive mailboxes ask:
Who Has Delegated Access?
Why?
Who Approved It?
Is It Still Required?30 — Review Executive and High-Value Mailboxes
Section titled “30 — Review Executive and High-Value Mailboxes”Prioritize:
Executives
Finance
HR
Legal
IT Administrators
Security TeamsReview:
Delegation
Forwarding
Inbox Rules
Authentication
Recent Security Events31 — Review Shared Mailboxes
Section titled “31 — Review Shared Mailboxes”Create:
| Mailbox | Owner | Members | Sensitive | External Forwarding | Review |
|---|---|---|---|---|---|
| finance@ | Finance | 6 | Yes | No | Current |
| support@ | IT | 12 | Medium | Review | Review |
32 — Review Inbox Rules
Section titled “32 — Review Inbox Rules”Suspicious mailbox rules may:
Move Messages
Delete Messages
Hide Alerts
Redirect InformationValidate unexpected rules with the mailbox owner.
33 — Mailbox Rule Investigation Model
Section titled “33 — Mailbox Rule Investigation Model”RULE IDENTIFIED ↓OWNER VALIDATION ↓CREATION CONTEXT ↓SIGN-IN REVIEW ↓FORWARDING REVIEW ↓IMPACT ASSESSMENT34 — Review Email Authentication
Section titled “34 — Review Email Authentication”Assess the organization’s email domains for:
SPF
DKIM
DMARCEmail Authentication Mental Model
Section titled “Email Authentication Mental Model”SPF ↓Which Systems May Send?DKIM ↓Was the Message Signed?DMARC ↓How Should Authentication ResultsInfluence Handling?35 — Review SPF
Section titled “35 — Review SPF”Assess:
Authorized Sending Sources
Third-Party Senders
Legacy Providers
Record GovernanceAvoid making DNS changes without understanding all legitimate sending services.
36 — Review DKIM
Section titled “36 — Review DKIM”Determine:
Which Domains Are Configured?
Who Owns the Configuration?
Are Legitimate Mail Flows Covered?37 — Review DMARC
Section titled “37 — Review DMARC”Assess:
Policy
Reporting
Authorized Senders
Deployment Maturity
Exception HandlingA mature deployment typically evolves through:
VISIBILITY ↓VALIDATION ↓CONTROLrather than enforcing a strict policy without first understanding legitimate mail flows.
38 — Review Anti-Phishing Controls
Section titled “38 — Review Anti-Phishing Controls”Assess controls addressing:
Impersonation
Spoofing
Phishing
Suspicious Links
Suspicious Attachmentsaccording to available Microsoft 365 security capabilities.
39 — Review Security Exceptions
Section titled “39 — Review Security Exceptions”Identify:
Allowed Senders
Allowed Domains
Transport Exceptions
Filter Bypasses
Administrative ReleasesFinding Example
Section titled “Finding Example”Finding:Overly Broad Email Security Exception
Observation:A broad sender or domain exception reducesnormal email-security inspection.
Risk:Compromise or impersonation of the exemptedsource may increase the likelihood ofmalicious content reaching users.
Recommendation:Remove unnecessary exceptions and narrowlyscope documented business exceptions.40 — Review Quarantine Governance
Section titled “40 — Review Quarantine Governance”Assess:
Who Can Review Quarantine?
Who Can Release Messages?
What Can Users Self-Release?
Are Releases Audited?41 — Review Phishing Reporting
Section titled “41 — Review Phishing Reporting”Determine whether users have a clear method to report:
Suspicious Email
Phishing
Spam
Potential Business Email CompromiseThen ask:
Who Receives the Report?
How Quickly Is It Reviewed?
Can Similar Messages Be Identified?42 — Review Microsoft Teams
Section titled “42 — Review Microsoft Teams”Teams combines:
Identity
Messaging
Meetings
Files
Applications
External CollaborationReview all of these dimensions.
43 — Review Teams Guest Access
Section titled “43 — Review Teams Guest Access”Determine:
Whether Guests Are Allowed
Who Can Invite Them
What Guests Can Access
How Guest Access Is Reviewed44 — Review Teams External Access
Section titled “44 — Review Teams External Access”Assess:
External Communication
Federation
Approved Domains
Business RequirementDo not confuse:
External Accesswith:
Guest AccessThey represent different collaboration models.
45 — Review Teams Membership
Section titled “45 — Review Teams Membership”For sensitive teams assess:
Owners
Members
Guests
Business Purpose
Sensitivity46 — Review Team Ownership
Section titled “46 — Review Team Ownership”A team should not become:
Ownerlessor rely on an employee who has left the organization.
Review ownership continuity.
47 — Review Teams Meeting Policies
Section titled “47 — Review Teams Meeting Policies”Assess controls relevant to:
Anonymous Participation
Lobby Behavior
Screen Sharing
Recording
External ParticipantsConfiguration should match the business use case.
48 — Review Teams Applications
Section titled “48 — Review Teams Applications”Inventory important:
Microsoft Applications
Third-Party Applications
Custom Applications
Bots
ConnectorsFor each ask:
Who Approved It?
What Data Can It Access?
Who Owns It?
Is It Still Required?49 — Review SharePoint Online
Section titled “49 — Review SharePoint Online”SharePoint may contain:
Policies
Projects
Financial Data
Contracts
HR Data
Technical DocumentationCreate an inventory of critical sites.
50 — Build the SharePoint Site Matrix
Section titled “50 — Build the SharePoint Site Matrix”| Site | Owner | Sensitivity | Guests | External Sharing | Review |
|---|---|---|---|---|---|
| Finance | Finance | High | 0 | Restricted | Current |
| Project-X | PMO | Medium | 4 | Enabled | Review |
| Legacy | Unknown | Unknown | Review | Review | Review |
51 — Review Site Ownership
Section titled “51 — Review Site Ownership”For each important site confirm:
Business Owner
Technical Owner
Purpose
Membership
SensitivityFinding Example
Section titled “Finding Example”Finding:Unowned SharePoint Site
Observation:A business SharePoint site contains activecontent but has no documented currentbusiness owner.
Risk:Access, sharing, retention, and lifecycledecisions may not receive appropriategovernance.
Recommendation:Assign an accountable business owner andperform an access and data review.52 — Review SharePoint Permissions
Section titled “52 — Review SharePoint Permissions”Assess:
Owners
Members
Visitors
Guests
Direct Permissions
Sharing LinksAsk:
Who Can Read?
Who Can Edit?
Who Can Manage?
Who Can Share?53 — Review External Sharing
Section titled “53 — Review External Sharing”External sharing should be aligned with:
Data Sensitivity
Business Requirement
Recipient Identity
Link Type
Expiration
ReviewExternal Sharing Mental Model
Section titled “External Sharing Mental Model”DATA ↓SENSITIVITY ↓BUSINESS NEED ↓RECIPIENT ↓SHARING METHOD ↓EXPIRATION54 — Review Broad Sharing Links
Section titled “54 — Review Broad Sharing Links”Prioritize links that are:
Broad
Long-Lived
Unowned
Used for Sensitive Data
No Longer RequiredFinding Example
Section titled “Finding Example”Finding:Excessive External File Sharing
Observation:Sensitive business information isaccessible using sharing permissionsbroader than the documented collaborationrequirement.
Risk:Information may remain accessible tounintended recipients.
Recommendation:Restrict sharing to explicitly authorizedidentities and periodically review activeexternal access.55 — Review OneDrive
Section titled “55 — Review OneDrive”Assess:
External Sharing
Sensitive Data
Ownership
Offboarding
Data Transfer
Retention56 — Review OneDrive Offboarding
Section titled “56 — Review OneDrive Offboarding”When an employee leaves, determine:
Who Receives Required Business Data?
How Long Is It Retained?
When Is User Access Removed?
How Are Existing Sharing Links Handled?57 — Review Former Employee Sharing
Section titled “57 — Review Former Employee Sharing”Look for cases where:
Former Employee ↓Previously Shared Data ↓External Recipientmay remain accessible without current ownership.
58 — Build the External Sharing Inventory
Section titled “58 — Build the External Sharing Inventory”| Resource | Owner | External Recipient | Sensitivity | Expiration | Review |
|---|---|---|---|---|---|
| Project Site | PMO | Partner-A | Internal | Review | |
| Finance File | Finance | External | High | None | Urgent |
59 — Review Enterprise Applications
Section titled “59 — Review Enterprise Applications”Inventory applications connected to the tenant.
Prioritize those with access to:
Directory
Mail
Files
Calendars
Teams
User Profiles
Administrative Operations60 — Build the Application Matrix
Section titled “60 — Build the Application Matrix”| Application | Owner | Permissions | Users | Business Need | Review |
|---|---|---|---|---|---|
| App-A | Finance | Limited | 25 | Yes | Current |
| App-B | Unknown | Broad | Tenant | Review | Urgent |
61 — Review Application Ownership
Section titled “61 — Review Application Ownership”Every significant application should have:
Business Owner
Technical Owner
Purpose
Permission Justification
Lifecycle62 — Review Application Permissions
Section titled “62 — Review Application Permissions”Ask:
What Can the Application Access?
Does It Need That Access?
Is Access Delegated or Application-Level?
Is the Scope Broader Than Necessary?63 — Review Administrative Consent
Section titled “63 — Review Administrative Consent”High-impact permissions should receive appropriate governance.
Assess:
Who Can Grant Consent?
How Is It Approved?
How Is It Reviewed?
How Is It Revoked?Finding Example
Section titled “Finding Example”Finding:Over-Privileged Enterprise Application
Observation:A connected application has access toMicrosoft 365 data beyond the minimumrequired for its documented function.
Risk:Application compromise or misuse couldexpose a larger portion of tenant data thannecessary.
Recommendation:Reduce permissions to the minimum requiredand establish periodic application-accessreviews.64 — Review Application Credentials
Section titled “64 — Review Application Credentials”For applications using credentials, assess:
Secret Ownership
Certificate Use
Credential Age
Expiration
Storage
RotationAvoid exposing actual secrets during assessment evidence collection.
65 — Review Unused Applications
Section titled “65 — Review Unused Applications”Identify applications with:
No Current Owner
No Business Use
Old Projects
Unused IntegrationsUnused integrations should not retain unnecessary access.
66 — Review Data Classification
Section titled “66 — Review Data Classification”Determine whether the organization distinguishes data such as:
Public
Internal
Confidential
Highly Confidential67 — Review Sensitivity Protection
Section titled “67 — Review Sensitivity Protection”Where sensitivity-label capabilities are used, assess:
Label Definitions
User Understanding
Protected Data Types
External Sharing Behavior
Governance68 — Review Data Loss Prevention
Section titled “68 — Review Data Loss Prevention”Assess whether sensitive information receives appropriate controls.
Examples:
Personal Information
Financial Information
Customer Data
Credentials
Intellectual PropertyDLP Mental Model
Section titled “DLP Mental Model”SENSITIVE DATA ↓USER ACTION ↓POLICY EVALUATION ↓ALLOW / WARN / RESTRICTdepending on the organization’s policy design.
69 — Review DLP Exceptions
Section titled “69 — Review DLP Exceptions”Exceptions should be:
Documented
Owned
Justified
Time-Bounded Where Appropriate
Reviewed70 — Review Retention
Section titled “70 — Review Retention”Assess:
Retention Requirements
Business Records
Legal Requirements
Deletion
OwnershipRemember:
Retention≠Backup71 — Review Audit Capabilities
Section titled “71 — Review Audit Capabilities”Audit records should help answer:
WHO?
DID WHAT?
TO WHAT?
WHEN?
FROM WHERE?72 — Review Important Audit Activities
Section titled “72 — Review Important Audit Activities”Prioritize:
Administrative Changes
User Changes
Role Changes
Mailbox Changes
Forwarding Changes
Sharing Changes
Application Changes
Security Policy Changes73 — Review Audit Retention
Section titled “73 — Review Audit Retention”Ask:
How Long Is Audit Data Available?
Does That Meet Investigation Requirements?
Does It Meet Compliance Requirements?
Is Important Data Exported Centrally?74 — Review Central Security Monitoring
Section titled “74 — Review Central Security Monitoring”Determine whether Microsoft 365 telemetry reaches:
Security Operations
SIEM
XDR
Incident Managementas appropriate.
Monitoring Model
Section titled “Monitoring Model”M365 ACTIVITY ↓AUDIT / SECURITY TELEMETRY ↓CENTRAL SECURITY PLATFORM ↓DETECTION ↓ANALYST ↓RESPONSE75 — Review Alert Ownership
Section titled “75 — Review Alert Ownership”For security alerts determine:
Who Receives Them?
Who Triages Them?
What Is the SLA?
How Are Incidents Escalated?
Who Owns Remediation?76 — Review High-Value Detection Scenarios
Section titled “76 — Review High-Value Detection Scenarios”The security team should consider visibility for events such as:
Privileged Role Assignment
Suspicious Authentication
External Forwarding Creation
Unexpected Mailbox Rule
Sensitive Sharing Change
High-Impact Application Consent
Security Policy Change
Unusual Administrative Activity77 — Review Business Email Compromise Readiness
Section titled “77 — Review Business Email Compromise Readiness”The organization should be able to investigate:
Suspicious Sign-In
Mailbox Rules
Forwarding
Delegation
Sent Messages
Authentication Changes
Sessions
Related RecipientsBEC Investigation Model
Section titled “BEC Investigation Model”ALERT ↓IDENTITY ↓SIGN-IN ↓MAILBOX ↓RULES ↓FORWARDING ↓MESSAGES ↓SESSIONS ↓IMPACT78 — Review Phishing Response Readiness
Section titled “78 — Review Phishing Response Readiness”Determine whether the organization can answer:
Who Received the Message?
Who Clicked?
Was an Attachment Opened?
Were Credentials Entered?
Did Authentication Change?
Did Similar Messages Reach Others?79 — Review Compromised Identity Response
Section titled “79 — Review Compromised Identity Response”Validate documented procedures for:
Account Containment
Session Revocation
Credential Reset
Authentication Method Review
Role Review
Mailbox Review
Application Review
Impact Analysis80 — Review External Sharing Incident Readiness
Section titled “80 — Review External Sharing Incident Readiness”Security teams should be able to investigate:
Which File?
Who Shared It?
With Whom?
How?
When?
What Was the Data Sensitivity?
Was Access Used?81 — Review Administrative Change Management
Section titled “81 — Review Administrative Change Management”Sensitive tenant changes should follow:
REQUEST ↓APPROVAL ↓IMPLEMENT ↓VALIDATE ↓MONITOR ↓DOCUMENT82 — Review Security Exceptions
Section titled “82 — Review Security Exceptions”Create a central exception inventory.
Include:
Conditional Access Exclusions
Email Filtering Exceptions
External Sharing Exceptions
DLP Exceptions
Application Exceptions
Administrative ExceptionsException Principle
Section titled “Exception Principle”An exception should have:
OWNER +REASON +SCOPE +EXPIRATION +REVIEW83 — Establish the Microsoft 365 Baseline
Section titled “83 — Establish the Microsoft 365 Baseline”Example:
| Area | Expected State |
|---|---|
| Privileged Roles | Minimum required |
| Admin Authentication | Strong |
| Conditional Access | Controlled |
| Guest Access | Reviewed |
| External Forwarding | Restricted |
| Email Authentication | Governed |
| Security Exceptions | Minimal |
| External Sharing | Controlled |
| Applications | Least privilege |
| Sensitive Data | Protected |
| Audit | Available |
| Monitoring | Operational |
84 — Compare Baseline to Actual State
Section titled “84 — Compare Baseline to Actual State”Example:
| Control | Expected | Actual | Result |
|---|---|---|---|
| Privileged Roles | Minimal | Excessive | Fail |
| Admin MFA | Required | Enabled | Pass |
| Guest Reviews | Current | Stale guests | Fail |
| Forwarding | Restricted | External found | Fail |
| App Permissions | Minimum | Broad app | Fail |
| Audit | Available | Available | Pass |
85 — Validate Every Finding
Section titled “85 — Validate Every Finding”Before reporting:
VERIFY CONFIGURATION ↓VERIFY BUSINESS CONTEXT ↓VERIFY SCOPE ↓VERIFY IMPACT ↓CHECK COMPENSATING CONTROLSDo not report assumptions as confirmed vulnerabilities.
86 — Classify Findings
Section titled “86 — Classify Findings”Use the organization’s approved risk model.
A simplified approach:
Critical
High
Medium
Low
InformationalConsider:
Privilege
Exposure
Data Sensitivity
Likelihood
Business Impact
Detectability
Compensating Controls87 — Finding Template
Section titled “87 — Finding Template”Use:
Finding ID:
Title:
Severity:
Affected Service:
Affected Scope:
Observation:
Evidence:
Security Risk:
Business Impact:
Recommendation:
Owner:
Target Date:
Validation Method:88 — Finding Example — Excessive Administration
Section titled “88 — Finding Example — Excessive Administration”Finding ID:M365-001
Title:Excessive Tenant Administrative Privilege
Severity:High
Observation:Multiple identities retain broad tenantadministrative roles despite requiring onlyservice-specific access.
Risk:Compromise of an unnecessarily privilegedidentity may result in broad Microsoft 365tenant impact.
Recommendation:Reduce administrative assignments to theminimum roles required and implementrecurring privileged-access reviews.89 — Finding Example — External Forwarding
Section titled “89 — Finding Example — External Forwarding”Finding ID:M365-002
Title:Unapproved External Mail Forwarding
Severity:High
Observation:A mailbox forwards corporate email to anexternal address without documentedbusiness approval.
Risk:Sensitive communications may leave themanaged enterprise environment.
Recommendation:Remove unapproved forwarding and establishcontrolled exception governance.90 — Finding Example — Stale Guest
Section titled “90 — Finding Example — Stale Guest”Finding ID:M365-003
Title:Stale External Guest Access
Severity:Medium
Observation:Guest identities associated with completedbusiness engagements remain enabled.
Risk:Former collaborators may retain access tocorporate resources beyond the approvedbusiness period.
Recommendation:Remove stale guest access and establishrecurring sponsor-based access reviews.91 — Finding Example — External Sharing
Section titled “91 — Finding Example — External Sharing”Finding ID:M365-004
Title:Excessive External File Sharing
Severity:High
Observation:Sensitive business information is sharedusing access broader than required for theapproved collaboration scenario.
Risk:Corporate information may remain availableto unintended recipients.
Recommendation:Restrict sharing to explicitly approvedrecipients and periodically review externalaccess.92 — Finding Example — Application Access
Section titled “92 — Finding Example — Application Access”Finding ID:M365-005
Title:Over-Privileged Enterprise Application
Severity:High
Observation:An enterprise application has access toMicrosoft 365 data beyond the permissionsrequired for its documented purpose.
Risk:Application compromise could expose alarger scope of enterprise data.
Recommendation:Reduce application permissions andimplement recurring application-accessreviews.93 — Finding Example — Monitoring
Section titled “93 — Finding Example — Monitoring”Finding ID:M365-006
Title:Insufficient Microsoft 365 SecurityMonitoring
Severity:Medium
Observation:Security-relevant Microsoft 365 activity isavailable but is not consistently reviewedthrough the organization's securityoperations process.
Risk:Suspicious identity, administrative, email,or sharing activity may not be detected ina timely manner.
Recommendation:Define monitoring requirements andintegrate required Microsoft 365 telemetrywith the security operations workflow.94 — Build the Findings Summary
Section titled “94 — Build the Findings Summary”| ID | Finding | Severity | Owner | Status |
|---|---|---|---|---|
| M365-001 | Excessive Admin Privilege | High | IAM | Open |
| M365-002 | External Forwarding | High | Messaging | Open |
| M365-003 | Stale Guests | Medium | IAM | Open |
| M365-004 | Broad Sharing | High | Collaboration | Open |
| M365-005 | Application Access | High | App Team | Open |
95 — Prioritize Remediation
Section titled “95 — Prioritize Remediation”Use:
RISK +BUSINESS IMPACT +REMEDIATION EFFORT +DEPENDENCIES96 — Immediate Actions
Section titled “96 — Immediate Actions”Examples:
Remove Confirmed Unauthorized Admin Access
Contain Confirmed Compromised Identities
Disable Malicious Forwarding
Remove Unauthorized Application Access
Restrict Confirmed Sensitive Data Exposure97 — Short-Term Actions
Section titled “97 — Short-Term Actions”Examples:
Reduce Standing Privilege
Review Guest Accounts
Review Mailbox Delegation
Remove Broad Email Exceptions
Review Sharing Links
Review Application Permissions98 — Medium-Term Actions
Section titled “98 — Medium-Term Actions”Examples:
Improve Conditional Access
Strengthen Guest Governance
Improve Email Authentication
Improve Data Classification
Improve DLP
Centralize Security Monitoring99 — Long-Term Improvements
Section titled “99 — Long-Term Improvements”Examples:
Automated Identity Governance
Time-Limited Privilege
Continuous Application Governance
Automated Data Protection
Continuous Configuration Assessment
Integrated Detection and Response100 — Build the Remediation Matrix
Section titled “100 — Build the Remediation Matrix”| Finding | Priority | Owner | Action | Target |
|---|---|---|---|---|
| M365-001 | High | IAM | Reduce admin roles | 14 days |
| M365-002 | High | Messaging | Remove forwarding | Immediate |
| M365-003 | Medium | IAM | Review guests | 30 days |
| M365-004 | High | Data Owner | Restrict sharing | 14 days |
| M365-005 | High | App Team | Reduce permissions | 14 days |
101 — Change Safely
Section titled “101 — Change Safely”For high-impact Microsoft 365 configuration changes use:
UNDERSTAND DEPENDENCY ↓APPROVE ↓TEST / PILOT ↓IMPLEMENT ↓VALIDATE ↓MONITOR ↓ROLL BACK IF REQUIRED102 — Do Not Disable Access Blindly
Section titled “102 — Do Not Disable Access Blindly”Before removing:
Application Permission
Guest Access
Mail Connector
Forwarding
Administrative Role
Conditional Access Exceptionvalidate the business dependency.
103 — Retest Findings
Section titled “103 — Retest Findings”A finding should not be considered closed simply because:
Configuration ChangedPerform:
RETEST104 — Retest Administrative Roles
Section titled “104 — Retest Administrative Roles”Verify:
Unnecessary Role Removed
Required Administration Still Works
Privileged Account Protected
Monitoring Remains Active105 — Retest Conditional Access
Section titled “105 — Retest Conditional Access”Use authorized test identities.
Validate:
Expected User Allowed
Restricted User Blocked
Administrator Receives Required Control
Approved Exception Still Works106 — Retest External Forwarding
Section titled “106 — Retest External Forwarding”Confirm:
Unauthorized Forwarding Removed
Approved Mail Flow Still Functions
Security Monitoring Detects Relevant Changes107 — Retest Guest Access
Section titled “107 — Retest Guest Access”Verify:
Stale Guest Removed
Required Guest Retained
Business Owner Confirmed
Resource Access Correct108 — Retest External Sharing
Section titled “108 — Retest External Sharing”Confirm:
Broad Link Removed
Approved Recipient Retains Access
Unauthorized Recipient Cannot Access
Owner Still Has Required Collaboration109 — Retest Application Permissions
Section titled “109 — Retest Application Permissions”Validate:
Excess Permission Removed
Application Still Functions
Required Permission Retained
Owner Confirmed110 — Retest Monitoring
Section titled “110 — Retest Monitoring”Generate an approved benign administrative change in the test environment.
Confirm:
Activity Logged
Event Searchable
Detection Works Where Expected
SOC Can Investigate111 — Closure Criteria
Section titled “111 — Closure Criteria”Close findings only when:
Remediation Implemented
Technical Validation Complete
Evidence Captured
Business Owner Confirmed
Residual Risk Documented112 — Risk Acceptance
Section titled “112 — Risk Acceptance”If remediation cannot be completed, document:
Finding
Business Reason
Risk Owner
Compensating Controls
Review Date
Expiration DateRisk acceptance should always have an owner.
113 — Final Microsoft 365 Security Report
Section titled “113 — Final Microsoft 365 Security Report”Recommended structure:
01 Executive Summary
02 Scope
03 Tenant Overview
04 Assessment Methodology
05 Administrative Security
06 Identity Security
07 Exchange Online
08 Email Security
09 Mailbox Security
10 Teams
11 SharePoint
12 OneDrive
13 External Sharing
14 Applications
15 Data Protection
16 Audit and Monitoring
17 Incident Readiness
18 Findings
19 Remediation Roadmap
20 Retest Plan114 — Executive Summary
Section titled “114 — Executive Summary”Write for:
CISO
CIO
IT Leadership
Risk Management
Business OwnersFocus on:
What Is the Risk?
Why Does It Matter?
What Should Be Fixed First?Example:
The Microsoft 365 security review identifiedopportunities to strengthen administrativeaccess, external collaboration, mailboxsecurity, application governance, andsecurity monitoring.
The highest-priority actions are to reduceunnecessary privileged access, removeunapproved external forwarding, restrictsensitive external sharing, and reduceover-privileged application permissions.115 — Assessment Methodology
Section titled “115 — Assessment Methodology”Document activities such as:
Stakeholder Interviews
Configuration Review
Administrative Role Review
Identity Review
Email Security Review
Collaboration Review
Application Review
Data Protection Review
Audit Review
Evidence Validation116 — Management Action Plan
Section titled “116 — Management Action Plan”Use an understandable timeline:
0–14 DaysImmediate privilege, exposure, andmail-security issues
15–30 DaysGuest, sharing, application, andconfiguration cleanup
31–90 DaysGovernance, data protection, andmonitoring improvements
90+ DaysAutomation and security maturityimprovements117 — Microsoft 365 Review Checklist
Section titled “117 — Microsoft 365 Review Checklist”Authorization
Section titled “Authorization”- Written authorization confirmed
- Tenant confirmed
- Services in scope documented
- Exclusions documented
- Evidence requirements documented
Tenant
Section titled “Tenant”- Tenant architecture reviewed
- Domains reviewed
- Service inventory created
- Business owners identified
Administration
Section titled “Administration”- Administrative roles reviewed
- Privileged identities reviewed
- Least privilege assessed
- Standing privilege reviewed
- Emergency access reviewed
- Administrative account separation reviewed
Identity
Section titled “Identity”- MFA reviewed
- Authentication methods reviewed
- Conditional Access reviewed
- Policy exclusions reviewed
- Guest identities reviewed
- Identity-risk visibility reviewed
Exchange
Section titled “Exchange”- Accepted domains reviewed
- Mail-flow rules reviewed
- Connectors reviewed
- External forwarding reviewed
- Mailbox delegation reviewed
- Shared mailboxes reviewed
- Inbox rules reviewed
Email Security
Section titled “Email Security”- SPF reviewed
- DKIM reviewed
- DMARC reviewed
- Anti-phishing reviewed
- Link protection reviewed where available
- Attachment protection reviewed where available
- Security exceptions reviewed
- Quarantine governance reviewed
- User phishing reporting reviewed
- Guest access reviewed
- External access reviewed
- Team ownership reviewed
- Sensitive memberships reviewed
- Meeting policies reviewed
- Teams applications reviewed
SharePoint
Section titled “SharePoint”- Critical sites inventoried
- Site ownership reviewed
- Membership reviewed
- External sharing reviewed
- Broad sharing links reviewed
- Sensitive sites reviewed
OneDrive
Section titled “OneDrive”- External sharing reviewed
- Sensitive data reviewed
- Offboarding reviewed
- Former employee access reviewed
- Ownership transfer reviewed
Applications
Section titled “Applications”- Enterprise applications inventoried
- Owners identified
- Permissions reviewed
- Administrative consent reviewed
- Application credentials reviewed
- Unused applications identified
Data Protection
Section titled “Data Protection”- Classification reviewed
- Sensitivity protection reviewed
- DLP reviewed
- DLP exceptions reviewed
- Retention reviewed
- External data handling reviewed
Audit and Monitoring
Section titled “Audit and Monitoring”- Audit capabilities reviewed
- Audit retention reviewed
- Administrative changes reviewed
- Mailbox changes reviewed
- Sharing changes reviewed
- Application changes reviewed
- Central monitoring reviewed
- Alert ownership reviewed
Incident Readiness
Section titled “Incident Readiness”- BEC procedure reviewed
- Phishing response reviewed
- Identity containment reviewed
- Session response reviewed
- External sharing response reviewed
- Escalation process reviewed
Findings
Section titled “Findings”- Findings technically validated
- Business context confirmed
- Severity justified
- Evidence captured
- Recommendations actionable
- Owners assigned
Remediation
Section titled “Remediation”- Immediate actions defined
- Short-term actions defined
- Medium-term improvements defined
- Long-term roadmap defined
Retesting
Section titled “Retesting”- Remediation technically retested
- Required business functionality validated
- Evidence collected
- Residual risk documented
- Findings formally closed
Common Microsoft 365 Review Mistakes
Section titled “Common Microsoft 365 Review Mistakes”Avoid:
Reviewing Only Exchange Online
Ignoring Identity
Ignoring Guest Accounts
Ignoring Conditional Access Exclusions
Ignoring Mailbox Forwarding
Ignoring Inbox Rules
Ignoring Third-Party Applications
Ignoring Application Consent
Ignoring SharePoint Sharing Links
Treating Every Guest as a Security Problem
Treating Every Alert as a Confirmed Incident
Treating Audit Logging as Active Monitoring
Changing DMARC Without UnderstandingMail Sources
Removing Application Permissions WithoutDependency Testing
Disabling Business Collaboration WithoutUnderstanding the Requirement
Reporting Missing Licensed Features asAutomatic VulnerabilitiesMicrosoft 365 Security Maturity Model
Section titled “Microsoft 365 Security Maturity Model”Level 1 — Basic
Section titled “Level 1 — Basic”MFA
Basic Email Security
Basic Administration
Basic AuditLevel 2 — Controlled
Section titled “Level 2 — Controlled”Least Privilege
Conditional Access
Guest Governance
Controlled External Sharing
Email AuthenticationLevel 3 — Managed
Section titled “Level 3 — Managed”Privileged Access Governance
Application Governance
Data Classification
DLP
Central Security MonitoringLevel 4 — Mature
Section titled “Level 4 — Mature”Time-Limited Privilege
Automated Identity Governance
Continuous Application Review
Adaptive Access
Integrated XDR / SIEM
Automated Data Protection
Continuous Security ValidationProfessional Interview Scenarios
Section titled “Professional Interview Scenarios”Scenario 01
Section titled “Scenario 01”You discover several users with broad tenant administrative roles. What do you do?
Use:
Identify ↓Validate Business Requirement ↓Map Administrative Tasks ↓Select Minimum Role ↓Plan Change ↓RetestDo not blindly remove access.
Scenario 02
Section titled “Scenario 02”You discover external forwarding on the CFO’s mailbox. What should happen next?
Determine:
Destination
Business Approval
Creation Time
Mailbox Rules
Recent Sign-Ins
Authentication Changes
Related ActivityIf unauthorized, treat it as a potential security incident rather than only a configuration issue.
Scenario 03
Section titled “Scenario 03”You find 500 guest accounts. Is that automatically a finding?
No.
Determine:
Ownership
Business Purpose
Resource Access
Age
Review Status
Current RequirementThe problem is unmanaged or unnecessary access, not simply the existence of guests.
Scenario 04
Section titled “Scenario 04”Why are enterprise applications important during a Microsoft 365 review?
Because applications may have access to:
Directory Data
Mail
Files
Calendars
Users
Tenant Resourcesand may operate independently of an interactive human session.
Scenario 05
Section titled “Scenario 05”Why should external sharing be reviewed continuously?
Because:
Business Relationships Change
Projects End
Employees Leave
Data Sensitivity Changes
Sharing Links Remain40 Microsoft 365 Security Review Interview Questions
Section titled “40 Microsoft 365 Security Review Interview Questions”- What is the purpose of a Microsoft 365 security review?
- What should be confirmed before beginning the review?
- What is the Microsoft cloud shared-responsibility model?
- Why should administrative roles be reviewed?
- What is least privilege?
- Why should privileged accounts be separated from normal accounts?
- What is standing privilege?
- What is emergency access?
- Why is MFA important for administrators?
- What is Conditional Access?
- Why should Conditional Access exclusions be reviewed?
- What is guest access?
- Why are stale guests a security concern?
- What is Exchange Online?
- Why should mail-flow rules be reviewed?
- Why should mail connectors be reviewed?
- Why is external forwarding security sensitive?
- What is mailbox delegation?
- Why should inbox rules be investigated?
- What is SPF?
- What is DKIM?
- What is DMARC?
- Why are email-security exceptions risky?
- What is the difference between Teams guest access and external access?
- Why should Teams applications be reviewed?
- Why is SharePoint site ownership important?
- Why are broad sharing links risky?
- What should be reviewed in OneDrive offboarding?
- What is an enterprise application?
- Why are application permissions important?
- What is administrative consent?
- Why should unused applications be removed?
- What is data classification?
- What is DLP?
- What is retention?
- What Microsoft 365 activities should be audited?
- What is the difference between logging and monitoring?
- How would you investigate a suspected mailbox compromise?
- Why must remediation be retested?
- What should a Microsoft 365 security assessment report contain?
Final Microsoft 365 Assessment Mental Model
Section titled “Final Microsoft 365 Assessment Mental Model”Remember:
UNDERSTAND THE TENANT ↓IDENTIFY ADMINISTRATORS ↓PROTECT IDENTITY ↓CONTROL PRIVILEGE ↓SECURE EMAIL ↓REVIEW MAILBOXES ↓CONTROL COLLABORATION ↓CONTROL EXTERNAL SHARING ↓GOVERN APPLICATIONS ↓PROTECT DATA ↓AUDIT IMPORTANT ACTIVITY ↓MONITOR SECURITY EVENTS ↓PREPARE FOR INCIDENTS ↓VALIDATE FINDINGS ↓REMEDIATE ↓RETESTThe key assessment question is not:
Is Microsoft 365 Enabled?It is:
Can the OrganizationControl and MonitorWho Can AccessWhich Microsoft 365 Resources,From Where,Using What Privilege,and What Happens to the Data?Runbook Complete
Section titled “Runbook Complete”You now have a repeatable professional methodology for reviewing:
Microsoft 365 Tenant Security
Administrative Access
Privileged Identity
Conditional Access
Guest Access
Exchange Online
Mailbox Security
Email Protection
Microsoft Teams
SharePoint Online
OneDrive
External Sharing
Enterprise Applications
Data Protection
Audit
Monitoring
Incident Readiness
Remediation
RetestingThis moves the assessment beyond:
Checking Microsoft 365 Settingstoward:
Evaluating EnterpriseIdentity + Collaboration + Data RiskWhat’s Next?
Section titled “What’s Next?”➡️ Runbook 03 — Windows Security Assessment
In the final Microsoft security runbook, you will convert the Windows Security Lab into a repeatable enterprise endpoint and server assessment methodology.
You will work through:
Assessment Preparation ↓Windows Asset Context ↓Operating System Security ↓Local Accounts ↓Administrative Privilege ↓Authentication ↓Security Policy ↓Microsoft Defender ↓Windows Firewall ↓Disk Encryption ↓Applications ↓Services ↓Scheduled Tasks ↓Persistence Review ↓PowerShell Security ↓Audit Policy ↓Security Logs ↓Network Exposure ↓Security Findings ↓Remediation ↓Retesting ↓Final Security ReportYour Microsoft security runbook sequence is now:
Runbook 01 — Active Directory Assessment ↓Runbook 02 — Microsoft 365 Security Review ↓Runbook 03 — Windows Security Assessment