Free · 22 checks · about 5 minutes · no sign-up

How secure is your Microsoft 365 tenant?

Answer 22 yes or no questions about identity, devices, email, data and monitoring. You get a score out of 100, a bar for each area, and for every gap the exact Microsoft setting to change and where to find it, in the order to fix them. Built for small and mid-sized businesses by IT Rapid Support in Vaughan.

Your answers never leave your browser. This page does not connect to your tenant, does not ask for an email address and stores nothing. Close the tab and the answers are gone.
Answer what you know. Not sure is a fine answer.0 of 22

Identity

Is every user required to sign in with multifactor authentication, not just offered it?
1 of 22
Do administrator accounts have to complete multifactor authentication every time they sign in?
2 of 22
Is legacy authentication (older IMAP, POP3 and SMTP clients and pre-modern Office apps) blocked?
3 of 22
Is the Global Administrator role held by fewer than five people, each using a separate admin account rather than their everyday email account?
4 of 22
Do you have two cloud-only emergency access ("break glass") accounts, stored safely and excluded from your sign-in policies?
5 of 22
Are staff prevented from granting third-party apps access to company data on their own?
6 of 22
If you have Entra ID P2 (for example Microsoft 365 E5), are sign-in risk and user risk policies turned on in Conditional Access?
7 of 22

Devices

Is every company laptop and desktop onboarded to Microsoft Defender for Business or Defender for Endpoint?
8 of 22
Do you have Intune device compliance policies, with devices that have no policy marked as not compliant?
9 of 22
Does Conditional Access require a compliant device before anyone opens company email and files?
10 of 22
Are Windows laptops encrypted with BitLocker through a managed policy, with recovery keys held by the company?
11 of 22

Email

Is automatic forwarding of mail to outside addresses turned off?
12 of 22
Are the Standard or Strict preset security policies applied to your users?
13 of 22
Is DKIM signing turned on for every custom domain you send mail from?
14 of 22
Does your domain publish SPF and a DMARC record set to quarantine or reject, not only p=none?
15 of 22

Data

Is SharePoint and OneDrive external sharing limited to people who sign in, rather than Anyone links that work for whoever holds the link?
16 of 22
If you do allow Anyone links, do they expire automatically and default to view only?
17 of 22
Do you have at least one Microsoft Purview data loss prevention policy, for example for credit card numbers or sensitive files shared outside?
18 of 22

Monitoring

Is the unified audit log recording user and admin activity?
19 of 22
Has anyone confirmed that mailbox auditing on by default has not been turned off in your tenant?
20 of 22
Do Microsoft 365 security alerts (suspicious outbound mail, restricted users, risky sign-ins) go to a mailbox someone reads every day?
21 of 22
Does someone review Microsoft Secure Score and its recommended actions at least monthly?
22 of 22

Questions you skip count as Not sure.

What this check is, and what it is not

This is a self-assessment. It scores the answers you give, not your actual tenant, and it cannot see a setting you believe is on but is not. Microsoft Secure Score in the Microsoft Defender portal is the authoritative view, because Microsoft calculates it from your real configuration across identity, devices, apps and data. Reading that score automatically would require an administrator in your organisation to grant consent to a connected app. This page deliberately does not do that, so there is nothing to approve and nothing to revoke.

Every setting name and menu path on this page was checked against Microsoft Learn in September 2026, and each recommendation links to the Microsoft page it came from.

Related help

Frequently asked questions

Does this tool connect to my Microsoft 365 tenant?

No. It is a self-assessment. You answer the questions, and the scoring runs in your own browser. Nothing is sent to IT Rapid Support or anyone else, and your answers disappear when you close the tab. Reading your real Secure Score would need an administrator in your tenant to grant consent to an app, and this page deliberately does not ask for that.

How is the score calculated?

Each of the 22 checks carries a weight from 3 to 10 based on how often that gap is how attackers get in, for a total of 121 points. A Yes earns the full weight. A No or a Not sure earns nothing, because a control you cannot confirm should be treated as missing until someone checks. The score is your points as a share of 121, from 0 to 100.

Is this the same as Microsoft Secure Score?

No. Microsoft Secure Score is calculated by Microsoft from your actual tenant settings and covers far more recommendations. This checklist picks the controls that matter most for a small or mid-sized business and explains each one in plain words, with the exact setting to change. Use both: this page to understand the gaps, Secure Score to confirm them.

Which Microsoft 365 licences do these settings need?

Security defaults need no extra licence. Conditional Access needs at least Microsoft Entra ID P1, and the sign-in risk and user risk policies need Entra ID P2. Device compliance and disk encryption policies need Intune. Safe Links, Safe Attachments and impersonation protection need Microsoft Defender for Office 365, which comes with Microsoft 365 E5 or as an add-on. Data loss prevention licensing varies by plan. Check your own plan before you buy anything new.

What should I fix first?

Work top down through the priority list on your results. It is sorted by weight, with a definite No ahead of a Not sure at the same weight. For most businesses the first three are multifactor authentication for everyone, blocking legacy authentication and turning off automatic forwarding to outside addresses.

Can IT Rapid Support check these settings for me?

Yes. As part of a free IT health check, an engineer can review these controls with you and give you a written list of findings that is yours to keep, whether or not you ever work with us.

We use cookies for analytics and ads. Cookie Policy · Privacy