Microsoft 365 Security Checklist for Small Practices

By jhcollierReviewed by Upgrade Your PracticeLast reviewed 2026-09-12

A same-week sequence: MFA for everyone, kill anonymous sharing, lock down mailboxes, and review guests — plus an explicit list of what this does not prove.

Microsoft 365 is where many practices keep email, files, and calendars. Attackers know that. You do not need a security department to make the default tenant much harder to abuse. Do these items in order. Have an admin account that is not used for daily mail.

Turn on MFA

Require multi-factor authentication for all users, including owners who “just need to get in quickly.” Prefer an authenticator app over SMS when you can. Remove legacy protocols that bypass MFA. If a vendor integration still needs a password-only mailbox, isolate that mailbox and plan to replace the integration.

Shared passwords in a notebook are not MFA. They are a reason to finish this checklist this week.

Sharing and files

Disable anonymous “anyone with the link” sharing for SharePoint and OneDrive unless a specific public resource requires it. Default new links to people in your organization. Review the last 90 days of sharing for client or patient folders that should never have been public.

Dental and legal files do not belong in a personal OneDrive that leaves with an employee. Move working files into a practice-owned library with named permissions.

Mailboxes

Give each person their own mailbox. Convert “info@” and “appointments@” to shared mailboxes with a short list of delegates. Enable anti-phishing policies Microsoft includes in your SKU and turn on mailbox auditing.

If you forward all mail to a personal Gmail account, stop. That is not a backup and it is not confidential.

Guest access

List every guest user in Entra ID (Azure AD). Remove guests whose project ended. Guests should not be global admins. If an accountant or IT vendor needs access, use a guest account you can disable tomorrow.

What this does not prove

This checklist does not make you HIPAA compliant, cyber-insurance approved, or immune to ransomware. It does not replace a backup that includes practice-management data outside Microsoft 365. It is the floor. After you finish, score the rest of the practice and read backup questions.

Not sure where to start?

The Practice Technology Scorecard turns plain-language answers into a prioritized roadmap. Results appear before any contact form.