Mastering Microsoft 365 Administration: The checklist


Following settings are considered to be checked / validated:

1. Entra ID Settings

  • Admin Accounts
    πŸ‘‰ Use named accounts or at least know who is (single person) using the account
    πŸ‘‰ Use break glass admin accouts (BGA); they’re the last resort to get access to a tenant. BGA are ecluded from any DA plicies and are only used in case of emergency; create alerts for usage of high privilege accounts
    πŸ‘‰ restrict guest invite settings to moset restrictive setting
    πŸ‘‰ make sure that you have Β«Terms of useΒ» (properly) set up

  • Users Settings
    πŸ‘‰ Use privileged administrative workstations (PWA) for administrative access to Microsoft 365
    πŸ‘‰ enforce MFA for all users
    πŸ‘‰ disable the ability for users to register applicationsy
    πŸ‘‰ restrict guest users access to the most restrictive setting

  • CA for Admin Accounts, User Accounts, Zero Trust πŸ‘‰ restrict acceess to suggested personas for CA: Internals, Externals, Admins, Developers, Guests, Guest Admins, Services Accounts, Workload Identities

  • Applications (Enterprise Apps, App Registrations)
    πŸ‘‰ Document the usage of your application (ownership, lifecycle, description)

2. Microsoft 365 Admin Center

  • Integrated Apps
    πŸ‘‰ Make sure that you enable only approved apps within the tenant, block any other app and nay future app

  • Org Settings
    πŸ‘‰ Disallow these settings: Excahnge Calendar Sharing, User Owned Apps, Bookings, Forms, Graph Data Connect, Microsoft 365 Groups, Modern Authentication, Microsoft 365 Web, Viva Learning, Whiteboard

  • Collaboration Settings (SPO, OD4B, Teams)
    πŸ‘‰ Restrict: Sharing Settings, Device Restrictions, App Store, Policies

3. Power Platform Settings

  • On-premises Data Gageway
  • Environment Management
  • Self Service Licensing
    πŸ‘‰ Disable the β€˜trial’ experience to the end user by using Get-AllowedContestPlans from PowerApps PowerShell
  • Connectors πŸ‘‰ consider a Data Loss rpevention policy level to restrict data using

Resources

#BishopTells