Microsoft 365 security checklist guides are everywhere, and almost all of them were written for a generic office. A property management business is not a generic office. It holds passport scans collected for right-to-rent checks, bank details for standing orders and deposit returns, landlord statements, contractor invoices, keys, alarm codes and the personal circumstances of people who live in the buildings it manages. It runs on shared mailboxes that half the branch can open, and it hands access to letting negotiators, block managers, out-of-hours contractors and part-time weekend staff who come and go.

That combination — high-value personal data, high staff churn and shared credentials — is exactly what attackers look for. This Microsoft 365 security checklist takes the fifteen controls that matter most in that setting and puts them in the order you should actually do them, with the licence each one needs and the regulatory driver behind it. Every setting named below exists in a standard tenant; nothing here requires an enterprise agreement.

Two things changed in 2026 and both raise the floor. Microsoft finished enforcing multi-factor authentication on the Microsoft 365 admin centre on 9 February 2026, so an admin without MFA can no longer sign in at all. And from 26 April 2026 the Cyber Essentials scheme moved to its new Danzell question set, where MFA on cloud services is a straight auto-fail rather than a recommendation. If your firm certifies to win managing-agent contracts, the bar moved while you were not looking.

This guide sits alongside our wider IT support guide for property management companies and our tenant-wide Microsoft 365 security audit walkthrough, which covers the audit method rather than the sector. Where the audit guide asks what is the state of this tenant, this Microsoft 365 security checklist asks what must a managing agent fix first.

Why Property Firms Need a Microsoft 365 Security Checklist

microsoft 365 security checklist property management b brick wall three courses

A Microsoft 365 security checklist for this sector is not driven by paranoia. It is driven by the fact that lettings and block management combine money movement with identity documents, and both sit in the same mailbox.

The national picture is not improving

The government’s Cyber Security Breaches Survey 2025/2026, published on 30 April 2026, found that 43 per cent of UK businesses — roughly 612,000 organisations — identified a breach or attack in the previous twelve months. Phishing was involved in 38 per cent of business cases and was rated the single most disruptive attack type by 69 per cent of those affected. For a managing agent, phishing is not an abstract nuisance; it is the delivery mechanism for the invoice-redirection fraud that empties a client account.

Small does not mean safe

UK businesses identifying a breach or attack, by size (CSBS 2025/2026)
Micro 42%
Small 46%
Medium 65%
Large 69%

A twelve-person letting agency sits in the micro or small band, where more than four in ten firms were hit. The gap between small and medium is where most property companies grow into trouble: you cross into the 65 per cent band around the time you open a second branch, and nothing about the tenancy has changed.

The regulator already fined this exact sector

The Information Commissioner’s Office fined the London estate agency Life at Parliament View Limited £80,000 after it left the personal data of 18,610 tenants and landlords openly accessible for almost two years. The cause was mundane: during a server transfer to a partner, an anonymous-authentication setting was left switched on. The exposed records included bank statements, salary details, dates of birth and passport copies, and were accessed more than half a million times. That penalty landed under the old Data Protection Act 1998; under UK GDPR the ceiling is £17.5 million or four per cent of global turnover.

How to Use This Microsoft 365 Security Checklist

microsoft 365 security checklist property management c closed ring binder folder upright

Work through the Microsoft 365 security checklist in the numbered order. It is sequenced by dependency and by blast-radius reduction, not by how interesting the feature is.

The three-block sequence

Controls 1 to 5 close the identity door, because every other control is worthless while an attacker can simply sign in as a negotiator. Controls 6 to 11 protect the money and the tenant records. Controls 12 to 15 make failure survivable. A firm that completes only the first block still removes the most common route to a breach, which is why this Microsoft 365 security checklist front-loads identity rather than spreading effort evenly.

The at-a-glance control table

#ControlWhat it stopsLicence needed
1Phishing-resistant MFA for all staffPassword spray, credential stuffingAny plan
2Block legacy authenticationMFA bypass via old protocolsAny plan
3Conditional Access baselineSign-ins from unmanaged devicesEntra ID P1
4Separate admin accounts, no standing rightsTotal tenant takeoverAny plan
5Shared mailboxes with sign-in blockedUntraceable branch-wide loginsAny plan
6Defender for Office 365 policiesMalicious links and attachmentsBusiness Premium
7SPF, DKIM and DMARC at rejectSpoofed rent and deposit emailsAny plan
8Block external auto-forwarding, alert on rulesSilent mailbox exfiltrationAny plan
9DLP on identity documentsPassport scans leaving the tenantBusiness Premium
10Retention and deletion scheduleHolding tenant data foreverBusiness Premium
11Sharing defaults and per-property sitesAnyone-links to landlord filesAny plan
12Intune enrolment and complianceData on personal, unencrypted laptopsBusiness Premium
13Fourteen-day patching for critical fixesKnown-exploit compromiseAny plan
14Third-party backup of Microsoft 365Permanent loss after deletionAdd-on
15Audit logging and a written response planMissing the ICO 72-hour clockAny plan

Where most firms actually stand

Only 47 per cent of UK businesses use any form of two-factor authentication, 30 per cent run cyber security risk assessments, 25 per cent hold a formal incident response plan and just 5 per cent are Cyber Essentials certified. Measured against those baselines, completing this Microsoft 365 security checklist puts a managing agent well ahead of its peer group — and, more usefully, ahead of the assumptions its insurers and institutional landlords are starting to make.

Microsoft 365 Security Checklist Controls 1–5: Identity and Access

microsoft 365 security checklist property management d three upright dominoes in a row

Identity is where property firms lose, which is why every Microsoft 365 security checklist should start here. A negotiator’s password is worth more to a fraudster than any file on the server, because it opens the mailbox where completion statements live.

1. Enforce phishing-resistant MFA on every account

Turn MFA on for every licensed user, without exception for directors or long-serving branch managers. Then go further than the tick-box: attacker-in-the-middle phishing kits proxy the login page, capture the session token after a successful MFA prompt and replay it elsewhere. Microsoft detects roughly 40,000 token-theft events a day, and token theft accounted for around 31 per cent of Microsoft 365 breaches in 2025.

Only device-bound methods — passkeys, FIDO2 keys and Windows Hello for Business — defeat the proxy itself. Authenticator push approvals are a floor, not a finish line, and treating them as the end of the Microsoft 365 security checklist is how firms with MFA still get breached.

2. Block legacy authentication protocols

Legacy protocols such as IMAP, POP and older SMTP clients cannot present an MFA prompt, so they hand attackers a bypass around control 1. Block them tenant-wide in Entra ID and treat any exception as a project with an end date. Old scanning printers in branch offices and ancient property software with a built-in mail client are the usual objectors, and both have modern alternatives.

3. Build a Conditional Access baseline

Microsoft 365 Business Premium includes Entra ID P1, which is the licence that unlocks Conditional Access. A workable starting baseline for a property firm: require MFA for all users, require a compliant or hybrid-joined device for anyone with admin rights, block sign-ins from countries you never operate in, and enable token protection for sign-in sessions so a stolen token cannot be replayed from another machine. Token protection is not a silver bullet, but it makes a stolen session materially harder to use.

4. Separate admin accounts and remove standing rights

Nobody should browse tenancy paperwork and administer the tenant from the same account. Create dedicated administrator accounts with no mailbox and no licence beyond what they need, keep two break-glass accounts excluded from Conditional Access and stored offline, and remove Global Administrator from anyone who does not need it daily. Microsoft’s own enforcement caught up with this pattern on 9 February 2026, when MFA became unavoidable for admin centre sign-in.

5. Convert shared logins into shared mailboxes

Almost every agency has a lettings@, maintenance@ or blockmanagement@ address that several people sign into with one password. Convert each to a proper shared mailbox with sign-in blocked, then grant named staff delegated access. You keep the workflow and gain per-person accountability in the audit log, which is the difference between “someone in the branch sent that bank-detail change” and knowing exactly who did.

Microsoft 365 Security Checklist Controls 6–8: Email and Payment Fraud

microsoft 365 security checklist property management e dome alarm bell wall mounted

Rent, deposits, service charges and contractor invoices all move on the back of an email. This block of the Microsoft 365 security checklist protects that channel.

6. Configure Defender for Office 365 properly

Business Premium includes Defender for Office 365, but the default policies are conservative. Enable Safe Links and Safe Attachments across Exchange, SharePoint, OneDrive and Teams, then add impersonation protection for the specific people fraudsters imitate: directors, the finance manager and the client-accounts mailbox. Add your largest landlords and managing agents as protected external senders. Impersonation protection is the control that catches a display-name lookalike asking for a deposit to be released early.

7. Publish SPF, DKIM and DMARC and move to reject

Payment redirection is the signature loss in this sector, and it usually starts with a spoofed message that looks like it came from your own domain. Publish SPF, sign outbound mail with DKIM, then move DMARC from p=none to p=quarantine and finally p=reject. Do it in that order, reading the aggregate reports at each stage. A domain at p=reject cannot be trivially spoofed, which removes an entire fraud pattern rather than filtering it.

Fraud patternHow it arrivesControl that stops it
Deposit return to a changed accountSpoofed tenant emailDMARC at reject, callback policy
Contractor invoice with new bank detailsCompromised supplier mailboxOut-of-band verification, DLP alert
Completion funds divertedLookalike display nameImpersonation protection
Silent mailbox monitoringStolen session tokenToken protection, forwarding block
Landlord statement alteredAnyone-link to a shared fileSharing defaults, sensitivity labels

8. Block external auto-forwarding and alert on inbox rules

The first thing an intruder does in a compromised mailbox is create a rule that files or forwards anything containing the words “invoice”, “bank” or “deposit”. Disable automatic external forwarding at the tenant level, then create an alert policy for new inbox rules that forward, redirect or delete. Our Microsoft 365 business email compromise response plan covers what to do in the first hour once that alert fires.

Microsoft 365 Security Checklist Controls 9–11: Tenant Data and Sharing

microsoft 365 security checklist property management f upright torch flashlight

Property firms collect more special-category and identity data than they realise, and they keep it long after any lawful reason to do so has expired. This is the part of the Microsoft 365 security checklist that turns a technical exercise into a data protection one.

9. Apply DLP to identity documents and bank details

Right-to-rent checks mean passport and visa scans sit in mailboxes and SharePoint libraries across the business. Microsoft Purview Data Loss Prevention ships with Business Premium and already understands UK passport numbers, National Insurance numbers and bank account details. Start in audit-only mode so you can see the volume before you start blocking, then move to policy tips and finally to blocking external sharing of anything containing those types. Expect the audit run to surprise you; it usually does.

10. Write a retention schedule and let it delete

Retention is not backup, and neither is a policy nobody enforces. Decide how long each category is kept, then let Purview delete on schedule rather than trusting staff to tidy up. Our guide on Microsoft 365 data retention versus backup explains why the two are not interchangeable — a point this Microsoft 365 security checklist repeats deliberately, because conflating them is the most common gap we find in a property tenant.

Data categoryTypical driverMicrosoft 365 control
Right-to-rent document copiesTenancy plus one yearPurview retention label, DLP
Client money recordsSix years, accounting practiceRetention policy, immutable backup
Tenancy agreements and depositsSix years from tenancy endPer-property SharePoint site
Building safety informationLife of the buildingSite with restricted membership
Failed applicant recordsMonths, not yearsAuto-delete retention label
CCTV and door-entry footageDays to weeksOut of scope, document it anyway

11. Fix sharing defaults before they fix themselves

Change the SharePoint and OneDrive default link type from “Anyone with the link” to “People in your organisation”, set an expiry on any external link, and stop storing every building in one enormous library that all staff can read. One site per property or per block, with membership that matches who actually manages it, is the structural fix. It also makes offboarding a contractor a two-minute job rather than an archaeology project.

Microsoft 365 Security Checklist Controls 12–13: Devices and Patching

Two controls, both boring, both now capable of failing a certification outright — which is why no Microsoft 365 security checklist can quietly drop them to the bottom of the list.

12. Enrol devices in Intune and enforce compliance

Business Premium includes Intune Plan 1. Enrol every company laptop and phone, require disk encryption, a screen lock and a supported operating system, then use Conditional Access to allow tenant access only from compliant devices. Property staff work from vans, site offices and their own kitchens, so the perimeter is the device, not the building. Where personal phones are genuinely needed for out-of-hours calls, use app protection policies so company data stays in the managed app and can be wiped independently.

13. Patch critical and high-risk vulnerabilities within fourteen days

This is now an auto-fail question. The Cyber Essentials Danzell question set, which took effect on 26 April 2026, added two questions requiring critical and high-risk security updates to be installed within fourteen days across operating systems, firmware and applications. Autopatch and Intune update rings make this achievable without anyone chasing laptops. The tightened Cyber Essentials Plus rules also close the old loophole of patching only the devices due to be tested, and a second failed retest now revokes the certificate.

Cyber Essentials 2026 changeConsequenceMatching checklist control
MFA mandatory on all cloud servicesAutomatic failureControls 1 and 3
Fourteen-day critical patchingAutomatic failureControl 13
Board declaration of ongoing complianceYear-round obligationControl 15
No selective patching before Plus testingRandom device resamplingControl 12
Second retest failure revokes certificateContract eligibility at riskWhole checklist

Microsoft 365 Security Checklist Controls 14–15: Backup and Response

The final block of the Microsoft 365 security checklist assumes something will go wrong anyway.

14. Back Microsoft 365 up properly

Microsoft protects its infrastructure; your data is your responsibility. Retention policies stop deletion, but they will not help you roll a SharePoint library back to the state it was in before a ransomware-encrypted sync, and default recycle bins expire. Take a third-party or Microsoft-native backup of Exchange Online, SharePoint, OneDrive and Teams, set it to a retention that matches your client-money obligations, and — this is the part firms skip — test a restore of one property’s document set every quarter.

15. Turn on audit logging and write the response plan

Confirm the unified audit log is on, extend retention as far as your licensing allows, and configure alerts for the events that matter: impossible-travel sign-ins, new inbox rules, mass downloads and privilege changes. Then write the plan — the last item on the Microsoft 365 security checklist is the only one that lives outside Microsoft 365. Only 25 per cent of UK businesses hold a formal incident response plan, yet the UK GDPR clock for reporting a notifiable personal data breach to the ICO runs for 72 hours from awareness. Name who declares an incident, who calls the ICO, who tells landlords and who briefs tenants.

The rollout most firms can actually sustain

A realistic sequence is thirty days for controls 1 to 5, thirty for 6 to 11 and thirty for 12 to 15. Identity first because it is cheap and stops the most attacks; data and email second because they need policy decisions; devices and resilience last because they need budget. Firms that try to do all fifteen simultaneously reliably stall at the retention schedule, which is the only control that requires the business, not the cybersecurity function, to make decisions.

What the Microsoft 365 Security Checklist Costs

Most of the fifteen controls cost configuration time rather than licence money — but two of them decide the bill.

Licence tiers that matter

PlanPer user, per monthSecurity capability included
Business Basic£5.40MFA, basic anti-spam only
Business Standard£10.80As Basic, plus desktop apps
Business Premium£16.90Entra ID P1, Intune, Defender, DLP
Defender Suite add-on£7.70Extended detection and response
Purview Suite add-on£7.70Advanced compliance and eDiscovery
Both suites together£11.50Combined, cheaper than separately

All figures are UK list prices per user per month on an annual subscription, excluding VAT, as published by Microsoft in August 2026.

The upgrade arithmetic for a twenty-five person agency

Annual licence cost, 25 staff, at published UK list prices
Business Standard, £10.80 £3,240
Business Premium, £16.90 £5,070
Premium plus both suites, £28.40 £8,520

Moving twenty-five staff from Business Standard to Business Premium costs £6.10 per user per month, or £1,830 a year. That single decision unlocks controls 3, 6, 9, 10 and 12 — five of the fifteen — and it is the cheapest line item in any credible Microsoft 365 security checklist for a firm this size. Weigh it against the £80,000 the ICO issued to one agency under weaker legislation than we have now, and the arithmetic answers itself. Our Microsoft 365 licence audit guide usually finds enough unused seats to part-fund the upgrade.

Compliance Pressure Behind This Microsoft 365 Security Checklist

The regulatory floor is rising on three fronts at once, and each one raises the value of finishing this Microsoft 365 security checklist early rather than at renewal. None of the three is optional, and none of them will wait for your next IT review.

Cyber Essentials moved the goalposts in April 2026

IASME published the Danzell question set on 13 February 2026 and it took effect on 26 April 2026. Beyond mandatory MFA and fourteen-day patching, the board-level declaration now commits the organisation to maintaining compliance throughout the certification year rather than on assessment day alone. Accounts opened before the changeover have until 26 October 2026 to finish under the previous rules. For managing agents bidding for local authority or housing association work, certification is frequently a gate.

Managed providers come into statutory scope

The Cyber Security and Resilience Bill entered the House of Lords on 25 June 2026, with Royal Assent expected late in the year and duties phased through to 2028. It brings managed service providers and data centre operators into regulation for the first time and creates a category of designated critical suppliers. If a managed IT provider runs your tenant, the security of that relationship becomes a statutory matter rather than a contractual preference — and only 15 per cent of UK businesses currently review the risks posed by their immediate suppliers.

The ICO’s penalties have changed shape

Enforcement in 2025 shifted decisively towards serious security failures. The three largest fines of the year totalled close to £19.4 million, and the average penalty rose from roughly £150,000 to more than £2.8 million. Fewer actions, far heavier ones. A property firm holding passport scans and bank details for several thousand tenants is not a marginal case if those records end up exposed.

Common Microsoft 365 Security Checklist Mistakes to Avoid

These are the four failures we see repeatedly in a property tenant, and each one maps to a control the firm believed it had already completed on its Microsoft 365 security checklist.

Treating the shared inbox as harmless

The info@ mailbox everyone knows the password to is usually the oldest account in the tenant, the one never covered by MFA and the one no leaver was ever removed from. It is the single most common finding in a property tenant review, and control 5 exists specifically for it.

Confusing the recycle bin with a backup

Deleted items and version history expire. Retention policies preserve, they do not restore to a point in time. A firm discovers the difference on the morning it needs a block’s service-charge folder as it stood last Tuesday.

Leaving contractors and ex-staff in place

Weekend viewing staff, seasonal negotiators and maintenance contractors accumulate. Run a quarterly access review against the payroll and the approved contractor list. Our employee IT onboarding and offboarding checklist turns that into a repeatable routine rather than an annual panic.

Buying tools instead of finishing controls

A tenant with Business Premium and default policies is less secure than a tenant on Business Standard with a disciplined identity baseline. Configuration beats procurement in every one of the fifteen items above. Finish the Microsoft 365 security checklist you already own the licences for before you buy anything else.

Microsoft 365 Security Checklist FAQs

How long does the whole checklist take?

For a typical twenty-five to fifty person agency, ninety days at a sensible pace with a managed IT provider doing the configuration. Controls 1 to 5 can genuinely be done in a fortnight; the retention schedule in control 10 is the long pole, because it needs business decisions rather than technical ones.

Do we need Business Premium?

For controls 3, 6, 9, 10 and 12, yes. Everything else on this Microsoft 365 security checklist works on any plan. If budget is genuinely fixed, do the free controls first — they cover the most common attack routes — and licence up at the next renewal.

Does this satisfy Cyber Essentials?

This Microsoft 365 security checklist covers the Microsoft 365 portion of the five technical controls, including both new auto-fail areas. Cyber Essentials also assesses firewalls, secure configuration and malware protection on devices outside the tenant, so treat this as most of the job rather than all of it.

What about property management software?

Anything holding tenancy or client-money data belongs in the same review. Where the vendor supports single sign-on with Entra ID, use it — that pulls the application behind controls 1 to 4 instead of leaving it on a separate password.

References