Microsoft 365 is where many practices keep email, files, and calendars. Attackers know that. You do not need a security department to make the default tenant much harder to abuse. Do these items in order. Have an admin account that is not used for daily mail.
Turn on MFA
Require multi-factor authentication for all users, including owners who “just need to get in quickly.” Prefer an authenticator app over SMS when you can. Remove legacy protocols that bypass MFA. If a vendor integration still needs a password-only mailbox, isolate that mailbox and plan to replace the integration.
Shared passwords in a notebook are not MFA. They are a reason to finish this checklist this week.
Sharing and files
Disable anonymous “anyone with the link” sharing for SharePoint and OneDrive unless a specific public resource requires it. Default new links to people in your organization. Review the last 90 days of sharing for client or patient folders that should never have been public.
Dental and legal files do not belong in a personal OneDrive that leaves with an employee. Move working files into a practice-owned library with named permissions.
Mailboxes
Give each person their own mailbox. Convert “info@” and “appointments@” to shared mailboxes with a short list of delegates. Enable anti-phishing policies Microsoft includes in your SKU and turn on mailbox auditing.
If you forward all mail to a personal Gmail account, stop. That is not a backup and it is not confidential.
Guest access
List every guest user in Entra ID (Azure AD). Remove guests whose project ended. Guests should not be global admins. If an accountant or IT vendor needs access, use a guest account you can disable tomorrow.
What this does not prove
This checklist does not make you HIPAA compliant, cyber-insurance approved, or immune to ransomware. It does not replace a backup that includes practice-management data outside Microsoft 365. It is the floor. After you finish, score the rest of the practice and read backup questions.