Security / Assessment

Assessment

Answer as the owner, not as the brochure. “Not sure” counts as a gap — you cannot claim a control you cannot name.

This is not an audit and not a legal opinion. We do not keep these answers on the server.

1. Does every person with a mailbox have to complete multifactor authentication to sign in — including owners and the person who “just uses Outlook”?

2. For Global Administrator (or equivalent) accounts, is the second factor an authenticator app, a passkey, or Windows Hello — not SMS as the only method?

3. Are Global Admin accounts used only when someone is actually changing the tenant — not for daily mail, Teams, and browsing?

4. Do you have two cloud-only emergency admin accounts, stored outside the password manager everyone uses, excluded from most Conditional Access, and actually tested?

5. Are the people who handle mail and files on Microsoft 365 Business Premium — or another plan that includes Intune and Conditional Access — not Business Standard alone?

6. Are company Windows and Mac computers enrolled in Intune (or another MDM) so you can require encryption and push a wipe?

7. If a laptop or phone went missing this afternoon, could you lock or wipe it without waiting for the employee to come in?

8. Must mail and SharePoint be opened on a device you manage, or in an app-protected mobile client — not on any browser that knows the password?

9. Have you blocked legacy email protocols (IMAP, POP, basic authentication) so a stolen password cannot pull mail without MFA?

10. Is Exchange, SharePoint, and Teams file data backed up somewhere other than a PC that syncs OneDrive?

11. In the last year, has someone restored a mailbox or a SharePoint library and confirmed the files opened?

12. Can you name every Global Administrator in the tenant today, without hunting through a spreadsheet from last year?



© 2026 - EAC Partners
Privacy
An unhandled error has occurred. Reload 🗙