Microsoft 365 Cyber Essentials Checklist (Danzell v3.3, 2026)
Published 8 June 2026
Why Microsoft 365 is its own checklist
Most UK SMEs we certify run their business out of Microsoft 365 – mail, files, identity, sometimes endpoints. That makes M365 the single most important thing to get right for Cyber Essentials. The Danzell question set tightened the rules around cloud MFA and bypass paths, and M365 is where most of those bypass paths live.
What changed for Microsoft 365 tenants in 2026
Assessment accounts created from 27 April 2026 are marked against the Danzell question set, which sits alongside version 3.3 of the NCSC Requirements for IT Infrastructure. The five controls are the same; the marking is stricter, and Microsoft 365 is where most of the new strictness lands:
- MFA on cloud services is now an auto-fail area. The MFA questions are marked pass or fail rather than scored, so one uncovered account sinks the whole submission. Administrative roles – Global Administrator, Exchange Administrator, anything that can change security settings – are the first place an assessor looks.
- Every route that bypasses MFA counts against you. Legacy authentication, app passwords and unmanaged service accounts are treated as bypass paths, not exceptions.
- Cloud services have a formal definition and cannot be excluded from scope. You must list Microsoft 365 as a third-party cloud service, along with anything else holding organisational data (Xero, Dropbox, Salesforce and so on). Once listed, every control applies to it.
- Passwordless is explicitly recognised. FIDO2 passkeys and Microsoft Authenticator number matching satisfy the requirement comfortably. SMS still passes but is the weakest option you can declare.
Microsoft has also been switching more tenants to mandatory MFA for admin portal sign-in, so part of this is often already done. Confirm it rather than assume it.
Do it in this order
The work that actually takes time is discovery, not remediation. Run it in this sequence and a tenant of 20 to 50 users is usually ready in an afternoon:
- List every identity that can sign in. Members, guests, shared mailboxes with sign-in enabled, service accounts, break-glass accounts. Export the user list from the Microsoft Entra admin centre so nothing is missed.
- Record how each one authenticates. Authenticator app, passkey, SMS, or nothing at all. Anything in the last column is a fail waiting to happen.
- Find what would break. Multifunction printers relaying mail, backup tools, CRM connectors and old mobile mail clients are the usual culprits behind legacy authentication.
- Fix the bypass paths first, then enforce MFA tenant-wide, then re-test with a real sign-in from a clean browser.
- Save the evidence (see below) on the same day you make the change, while the screens still show what you did.
The six M365 settings that decide pass or fail
1. MFA enforced on every account
Use either Security Defaults (good for small tenants) or a Conditional Access policy that requires MFA for all users. Verify by signing in as a test user from a fresh browser – you should be challenged for MFA. Document any service-account exceptions in writing.
2. Legacy authentication disabled
POP, IMAP, SMTP basic auth and other legacy protocols can bypass MFA entirely. Under the Danzell question set, you must confirm legacy auth is blocked. Use a Conditional Access policy to "Block legacy authentication" or set it via the Authentication Policies in the Exchange admin centre.
3. Conditional Access policies
If you have Entra ID P1 or higher, set at least:
- Require MFA for all users
- Block legacy authentication
- Require compliant or hybrid-joined device for admin roles
- Block sign-in from unsupported countries (if relevant)
If you only have Business Basic / Standard, Security Defaults is acceptable for CE.
4. Defender for Endpoint or third-party AV
Every Windows device needs active anti-malware that auto-updates and scans downloads. Microsoft Defender (the built-in one) is sufficient for CE provided it's enabled and not disabled by GPO or third-party policy. Macs need either built-in protections or a managed AV.
5. Intune or another MDM for device compliance
You don't strictly need MDM for basic CE, but it makes evidence collection ten times easier. With Intune you can produce a single compliance report showing OS version, encryption, AV status and patch level for every device. Without MDM you'll be screenshotting devices one by one.
6. Documented leavers process
When someone leaves: account disabled within 1 working day, MFA tokens revoked, mailbox converted to shared, OneDrive ownership reassigned. Write this down. Assessors ask for the document, not just the action.
The patching question for M365 businesses
Windows Update for Business (or Intune compliance policies) should be set to deliver high/critical updates within the 14-day window. Office apps must be on the Current Channel or Monthly Enterprise Channel – not Semi-Annual, which lags too far behind. macOS devices need automatic updates enabled.
What about Exchange Online specifically?
- Block legacy authentication (covered above)
- Disable IMAP and POP unless genuinely needed
- Configure SPF, DKIM, DMARC for sending domains (not strictly required for CE but you'll be asked)
- Enable mailbox audit logging
Sharing and external collaboration
CE doesn't mandate "no external sharing" – that would be unrealistic for most businesses. It does require you to know who can share with whom and to control admin-level sharing settings. Default-allow-anyone external sharing on a tenant-wide basis is a flag.
The common M365 fails we see
- Founder's "convenience" admin account without MFA
- Service account with mailbox access using basic auth
- One user excluded from MFA "because it broke their phone"
- Old leaver mailbox still active, still receiving mail
- Office channel set to Semi-Annual on every device
The 30-minute M365 audit
- Entra admin centre → Users → confirm MFA status for every account
- Conditional Access → confirm "Block legacy authentication" policy is enabled
- Microsoft 365 admin centre → Active users → check no leavers still active
- Exchange admin centre → Authentication Policies → confirm basic auth disabled
- Intune (if used) → Device compliance report → save as evidence
The evidence to keep
For the self-assessment you are declaring, not uploading, but keep these to hand – they answer most follow-up questions from your assessor, and you will need them again for Cyber Essentials Plus:
- Entra user export showing every account and its authentication methods
- Screenshot of the Conditional Access policy list, or of Security Defaults enabled
- Screenshot showing legacy authentication blocked in Exchange authentication policies
- Intune or MDM compliance report covering OS version, encryption, anti-malware and patch level
- Your written joiners and leavers procedure, with a date and an owner
- Office update channel setting for the estate
Pair this with our general Cyber Essentials readiness checklist for the non-M365 parts, and see the cloud services in scope guide for how to list the rest of your SaaS.
