Free IT tools

Is your Microsoft 365 tenant as locked down as you assume?

Twelve questions on the tenant settings that decide whether one stolen password becomes an incident. Built for small businesses across Chester County PA, northern Delaware, and northern Maryland, though the questions apply anywhere.

Microsoft 365 Security Check

12 questions, about two minutes. Everything runs in your browser and nothing you enter is sent anywhere.

What it walks through
  • Admin accounts
  • Sign-in
  • Mail flow
  • Monitoring
  • Data and sharing
  • Recovery

Question 1 of 12

Admin accountsDo the people who administer Microsoft 365 use a separate account for it, rather than their everyday one?That is, a second login used only for admin work, not the one they read email on all day.
Admin accountsHow many people hold full global administrator access?
Sign-inHave the older sign-in methods that cannot use a second step been switched off?Often called legacy authentication. Older mail apps, scanners and copiers use it, and it bypasses multi-factor entirely.
Sign-inCan generic mailboxes like info@ or accounts@ be signed into directly?Shared mailboxes do not need their own login. When they have one, it usually has a password several people know.
Mail flowWould you find out if someone set up a rule quietly forwarding their mail outside the company?
Mail flowIs impersonation protection turned on, so mail pretending to be from you or your directors gets flagged?
Sign-inWhen someone leaves, are their active sessions ended as well as their sign-in blocked?Blocking sign-in stops the next login. It does not sign out a phone that is already signed in.
Sign-inAre there any rules about where or on what people can sign in from?For example blocking sign-ins from countries you do not operate in, or requiring a managed device.
MonitoringDoes anyone actually look at sign-in reports for logins from unexpected places?
Data and sharingDo you know what has been shared outside the company from SharePoint or OneDrive?
MonitoringIf you needed to find out who opened a file or mailbox three months ago, could you?
RecoveryIf a mailbox were deleted today and nobody noticed for four months, could you get it back?Microsoft keeps the service running. Keeping your data recoverable after a deletion or a compromise is separate, and by default it is yours.

Who this is for

It assumes you run the business rather than the network. If you can answer questions about how your office works, you can complete it.

  • Businesses running Microsoft 365 Business Standard or Premium
  • Office managers who were handed the admin login
  • Internal IT generalists with a dozen other jobs
  • Anyone who inherited a tenant somebody else set up

Why these questions and not others

The tenant is where the money is

Email holds your invoices, your payment instructions, and a copy of nearly every conversation the business has had. That makes a Microsoft 365 tenant a more valuable target than anything on the office network, and it is reachable from anywhere in the world without touching your building.

The defaults are not the same as configured

A tenant that was set up to get everyone onto email quickly works perfectly and is wide open in specific, well-known ways. Nothing warns you, because nothing is broken. This walks the settings that get skipped during a migration and never revisited.

Deeper than the general check, on purpose

The IT Health Check asks whether everyone signs in with a second step. This asks whether old sign-in methods that bypass it entirely have been switched off, which is the question that decides whether the first one is worth anything.

Not knowing counts

Several answers here are things nobody has looked at. That is a genuine finding rather than a failure to complete the quiz, and it is scored as one. A tenant nobody is watching behaves exactly like a tenant with nothing turned on, right up until it does not.

How the score is worked out

Each answer carries a weight based on what it costs you when it is the one that goes wrong. Blocked legacy sign-in and mailbox forwarding visibility are not the same size of question as link expiry dates, so they are not scored as though they were.

What is missingWeightExample from this check
Critical control missing15 pointsLegacy sign-in still permitted, or no visibility over external mail forwarding
High-risk control missing10 pointsAdmin rights on everyday accounts, or shared mailboxes with live logins
Moderate gap5 pointsNobody reviewing sign-in reports, or external sharing never audited

Two things worth knowing about the number

It is scaled, not subtracted. There are 110 points of possible weight in this check, so the score is your weighted total expressed against the worst case rather than counted down from 100.

Missing critical controls cap the rating. One missing critical control holds the overall rating at "needs attention" or lower whatever the number says, and two hold it at "high risk". Both criticals here are bypasses: one lets an attacker skip multi-factor entirely, the other lets them read your mail unnoticed. A tenant with either is not in good shape, and a number alone would say it was.

What this tool cannot tell you

It asks, it does not check. Every answer here is something I could confirm in a few minutes inside the tenant, and confirming is a different piece of work from asking. It also covers Microsoft 365 only: your computers, your network and your firewall are all outside it, and an attacker will not respect that boundary.

  • IT Health CheckThe broader one. Devices, backups, payments and process, for the ground this tool deliberately leaves alone.
  • Network Security AssessmentOver 45 controls checked rather than asked about, including the tenant, with a written report and a cyber insurance answer sheet.

Questions about this tool

How is this different from the IT Health Check?

Depth. The health check asks whether everyone signs in with a second step. This asks whether the older sign-in methods that bypass that step entirely have been blocked, whether administrators use separate accounts, and whether anyone would notice a mailbox forwarding rule. It also stays inside Microsoft 365, where the health check covers devices, backups and process as well. Run the health check if you want the broad picture, this one if Microsoft 365 is where your business actually lives.

I do not have admin access. Can I still do this?

You can attempt it, and "I am not sure" is a real answer that still scores. If you end up answering that to most of them, that is itself the finding, and the result will say so. A tenant nobody can describe is a tenant nobody is watching.

What is legacy authentication and why does it matter so much?

It is the older way apps sign in to Microsoft 365, used by things like old mail clients, scanners and copiers. It cannot present a second step, so if it is still permitted, someone with a stolen password can sign in through it and is never challenged. It is the control that decides whether your multi-factor rollout is worth anything, which is why it is weighted as heavily as it is.

Is this free, and do I have to give you my email?

Free, and the full result appears without entering anything. Email is only for the written version, which is optional. Nothing you enter leaves your browser.

Does fixing these things cost money?

Mostly no. Blocking legacy sign-in, separating admin accounts, blocking external forwarding, and stopping shared mailboxes from signing in are all configuration on licences you already pay for. The ones that do cost are independent backup and, sometimes, longer audit retention or the licensing tier that allows sign-in conditions.

Will this break things for my staff?

Some of it can if it is done carelessly, which is why the order matters. Blocking legacy sign-in will stop an old scanner that emails documents, so you find those first and deal with them rather than switching it off on a Friday afternoon. Separating admin accounts and blocking external forwarding are invisible to everyone who is not an administrator.

Do you need access to my tenant to talk about the result?

No. The result is yours and it stands on its own, and you can hand it to whoever looks after your Microsoft 365 today. If you want me to check whether the answers hold up, that is the Network Security Assessment, and it uses named read-only accounts you create and disable afterwards. Never your passwords.

Want someone to go through the result with you?

I will walk through what came back, tell you which items genuinely need attention and which can wait, and you are under no obligation after it.

Free, no obligation, and you talk directly with a senior engineer.

Call nowBook a call