Identity comes first
Most incidents now begin with an account rather than a device. Multi-factor authentication on every account, including administrators, is the highest-value change available to most organisations.
- MFA enabled for all users, with no permanent exclusions
- Administrators using separate accounts from their daily login
- Leavers disabled the day they finish
Check mail flow settings
Email remains the most common delivery route for fraud, and the most common way a domain is abused.
- SPF, DKIM and DMARC records published correctly
- Auto-forwarding to external addresses reviewed
- A clear, quick way for staff to report a suspicious message
Review sharing before it becomes a problem
SharePoint and OneDrive sharing defaults are often left as they were on day one. Over time, links accumulate and access widens without anyone deciding it should.
Know what Microsoft does not do for you
Microsoft protects the platform and provides retention features. Deciding what to keep, for how long, and how to recover it remains your responsibility — which means a defined backup and recovery approach for cloud data.
Do it in order, not all at once
Work through identity, then devices, then mail, then sharing, then recovery. Each step is small, reversible and measurable, which is far easier to sustain than a single large project.