Skillplan M365 Checklist
2026-07-20 19:25
M365
Microsoft 365 Security Checklist
de
en
fr
it
System Online
← Back to sections
Mitigation Controls · Section 7 of 17
Exchange Online Hardening
Assessment Progress
0
/ 136 items
0%
Fulfillment so far
0
/ 0 controls
0%
Explain this control
Disable SMTP AUTH, IMAP, and POP at the tenant level; allow per-mailbox only with documented justification.
Not Fulfilled
Fulfilled
Accepted
Disable automatic forwarding to external recipients via the Anti-spam outbound policy.
Not Fulfilled
Fulfilled
Accepted
Verify mailbox audit logging is enabled for every mailbox.
Not Fulfilled
Fulfilled
Accepted
Configure DKIM signing for every accepted domain; publish a strict DMARC p=reject after a monitoring period.
Not Fulfilled
Fulfilled
Accepted
Enable the Anti-phishing policy with mailbox intelligence and impersonation protection for executives and high-value users.
Not Fulfilled
Fulfilled
Accepted
Apply the External sender warning tag to all inbound mail from outside the organization.
Not Fulfilled
Fulfilled
Accepted
Disable user-created Exchange Online mailbox auto-forwarding rules to external addresses.
Not Fulfilled
Fulfilled
Accepted
Restrict the Mail Recipient Creation management role to a small named group; review quarterly.
Not Fulfilled
Fulfilled
Accepted
Save and Continue →