Skillplan M365 Checklist
2026-07-20 19:33
M365
Microsoft 365 Security Checklist
de
en
fr
it
System Online
← Back to sections
Mitigation Controls · Section 10 of 17
Defender for Office 365
Assessment Progress
0
/ 136 items
0%
Fulfillment so far
0
/ 0 controls
0%
Explain this control
Enable the Standard or Strict Preset Security Policy in Defender for Office 365 for all eligible users.
Not Fulfilled
Fulfilled
Accepted
Enable Safe Attachments for SharePoint, OneDrive, and Microsoft Teams.
Not Fulfilled
Fulfilled
Accepted
Enable Safe Links with Time-of-click protection and 'Do not allow users to click through' for high-risk policies.
Not Fulfilled
Fulfilled
Accepted
Configure Zero-hour Auto Purge (ZAP) for both phishing and malware classifications.
Not Fulfilled
Fulfilled
Accepted
Enable Automated Investigation and Response (AIR) playbooks for the top alert types.
Not Fulfilled
Fulfilled
Accepted
Run an Attack Simulator phishing campaign each quarter and track click-through and credential-entry rates.
Not Fulfilled
Fulfilled
Accepted
Configure alert policies for 'User restricted from sending email' and 'Email forwarding rule created'.
Not Fulfilled
Fulfilled
Accepted
Process user-reported phishing via the built-in Report Phishing button for tenant-wide analysis.
Not Fulfilled
Fulfilled
Accepted
Save and Continue →