Skillplan M365 Checklist
2026-07-20 19:33
M365
Microsoft 365 Security Checklist
de
en
fr
it
System Online
← Back to sections
Mitigation Controls · Section 2 of 17
Entra ID — Identity Foundations
Assessment Progress
0
/ 136 items
0%
Fulfillment so far
0
/ 0 controls
0%
Explain this control
Block legacy authentication protocols (POP, IMAP, SMTP AUTH, EAS basic) tenant-wide via Conditional Access.
Not Fulfilled
Fulfilled
Accepted
Enable Entra Password Protection with a custom banned-password list aligned with your organization.
Not Fulfilled
Fulfilled
Accepted
Require all users to register a strong authentication method (Authenticator, FIDO2, or Windows Hello).
Not Fulfilled
Fulfilled
Accepted
Disable the 'Stay signed in?' prompt across sign-in branding contexts to reduce token persistence on shared devices.
Not Fulfilled
Fulfilled
Accepted
Set the password expiration policy aligned with NIST 800-63B (no forced rotation, only on suspicion of compromise).
Not Fulfilled
Fulfilled
Accepted
Configure tenant restrictions v2 to block sign-ins to external tenants from managed devices.
Not Fulfilled
Fulfilled
Accepted
Investigate and remediate every 'high' sign-in risk event within 24 hours via Entra ID Protection.
Not Fulfilled
Fulfilled
Accepted
Disable users' ability to invite external guests unless they hold the Guest Inviter role.
Not Fulfilled
Fulfilled
Accepted
Save and Continue →