Microsoft 365 includes security controls for identities, devices, email, collaboration and information protection. However, the level of protection an organisation receives depends on its licences, configuration, monitoring and internal processes.
For healthcare organisations, a configuration gap can affect access to sensitive information, external collaboration, staff devices and the ability to investigate an incident. Using Microsoft 365 does not, by itself, confirm that an organisation is secure or meeting its regulatory responsibilities.
This checklist helps healthcare IT managers, practice managers, operations teams and information governance leads identify areas that may require closer review. It is relevant to private clinics, care providers, diagnostic services, pharmacies, HealthTech companies and organisations working with NHS data or systems.
Who Should Use This Microsoft 365 Security Checklist?

Use this checklist if your organisation:
- Stores or shares healthcare information through Microsoft 365
- Uses Teams, SharePoint or OneDrive for collaboration
- Allows staff to access information from personal or mobile devices
- Works with external clinicians, suppliers or partner organisations
- Uses Microsoft 365 without a recent security assessment
- Has changed licences, staff, locations or IT providers
- Needs clearer evidence of how access and information are controlled
Organisations accessing NHS patient data or systems may also need to complete the Data Security and Protection Toolkit. The toolkit helps organisations measure performance against the National Data Guardian’s ten data security standards. Microsoft 365 controls may support this work, but Microsoft 365 configuration does not automatically satisfy DSPT requirements.

1. Confirm Multi-Factor Authentication Covers Every Account
Multi-factor authentication adds another verification step when someone signs in. It reduces the likelihood that a stolen password alone can provide access to Microsoft 365.
Review whether MFA applies to all users, administrators, temporary workers and third parties with active accounts. Any exception should have a documented reason, an accountable owner and a review date.
Check:
- Is MFA required for every relevant account?
- Are administrative accounts subject to stronger controls?
- Are legacy authentication methods blocked?
- Are inactive accounts still able to sign in?
- Are authentication methods appropriate for higher-risk users?
- Are exceptions regularly reviewed?
Not all MFA methods provide the same protection against phishing. Authentication choices should reflect the risk attached to the user, role and information being accessed.
2. Separate and Protect Administrative Accounts
Administrative accounts can change security settings, create users, access services and grant permissions. They should not be used for routine email, browsing or day-to-day collaboration.
Administrators should have a standard account for ordinary work and a separate account for privileged tasks. The number of highly privileged roles should also be limited.
Review:
- How many Global Administrator accounts exist?
- Does each administrator still require their assigned role?
- Are administrative accounts separate from standard accounts?
- Are privileged activities monitored?
- Are temporary administrative permissions removed promptly?
- Are emergency-access accounts documented and tested?
Microsoft recommends assigning the fewest permissions needed to perform a role. Permanent high-level access should not be used simply because it is convenient.
3. Review Conditional Access and Sign-In Controls
Conditional Access can evaluate factors such as the user, device, application, sign-in risk and location before access is permitted. This can prevent a valid username and password from being used under unacceptable conditions.
Policies should reflect how the organisation works. A clinician accessing Microsoft 365 from a managed device may require different controls from an external supplier accessing a shared project area.
Review whether:
- Risky sign-ins are detected and investigated
- Sensitive applications require stronger authentication
- Unmanaged devices have appropriate restrictions
- Legacy authentication is blocked
- Policy exclusions are documented
- Changes are tested before wider deployment
Conditional Access capabilities depend on the organisation’s Microsoft licences. Policies should be introduced carefully to avoid unintentionally blocking legitimate users or administrators.
4. Control Devices Accessing Healthcare Information

Healthcare information may be accessed through desktop computers, laptops, tablets and mobile phones. Without an accurate device inventory, it can be difficult to know where organisational information is being stored or whether devices meet security requirements.
Microsoft Intune and related controls can help manage organisation-owned devices and protect work data within approved applications. The exact approach should depend on information sensitivity, working practices and whether personal devices are permitted.
Check:
- Which devices currently access Microsoft 365?
- Are operating systems and applications supported and updated?
- Is device encryption required?
- Can lost devices be locked or organisational data removed?
- Are personal devices subject to suitable application controls?
- Can non-compliant devices access sensitive services?
- Is there a process for returning or retiring equipment?
A bring-your-own-device policy should specify what information users may access and what happens when a device is lost, replaced or no longer used for work.
5. Strengthen Email and Phishing Protection
Email remains a common route for credential theft, malicious attachments, impersonation and payment fraud. Healthcare organisations should combine technical email controls with clear reporting and investigation processes.
Microsoft 365 provides built-in anti-spam and anti-malware capabilities. Additional protections, such as Safe Links, Safe Attachments and advanced anti-phishing policies, depend on the licence and Defender plan in use.
Review:
- Are senior, finance and administrative accounts given additional protection?
- Is external automatic forwarding restricted?
- Are domain impersonation and spoofing controls configured?
- Can staff report suspicious messages easily?
- Are suspicious inbox rules and forwarding changes monitored?
- Is there a defined owner for investigating reported emails?
- Are email security policies tested rather than assumed to be working?
Security training should support these controls, but staff should not be expected to identify every sophisticated threat without technical protection.
6. Review Teams, SharePoint and OneDrive Sharing
Teams, SharePoint and OneDrive allow healthcare teams to collaborate efficiently, but information can become exposed when guest access, anonymous links and inherited permissions are not controlled.
Review sharing according to the purpose and sensitivity of each site rather than applying the same permissions everywhere.
Check:
- Can users create anonymous or public links?
- What is the default sharing-link type?
- Are inactive guest accounts still present?
- Does every Team and SharePoint site have an accountable owner?
- Are external users reviewed when projects or contracts end?
- Can users identify whether a file is shared internally or externally?
- Are unused Teams and sites archived or removed?
- Are permissions inherited in ways that create unexpected access?
External collaboration may be necessary. The objective is to ensure that it is intentional, limited and periodically reviewed.
Is Your Microsoft 365 Environment Configured for Healthcare Use?
Ultralink can review identity controls, device access, email protection, external sharing and information-governance settings to identify areas requiring attention.
7. Classify and Protect Sensitive Healthcare Information

Security controls are more effective when the organisation knows what information it holds and how sensitive it is. Microsoft Purview can support information classification, sensitivity labels, encryption and Data Loss Prevention policies.
Before introducing controls, define clear categories that staff can understand and apply consistently. A complex classification system may be ignored or used incorrectly.
Review:
- Where is sensitive healthcare information stored?
- Are classification categories clearly defined?
- Do labels apply appropriate protection?
- Can sensitive information be sent to personal email accounts?
- Are Teams, SharePoint, OneDrive and Exchange covered appropriately?
- Are Data Loss Prevention alerts reviewed?
- Are policies tested for false positives before strict enforcement?
- Is there a process for handling justified exceptions?
Sensitivity labels and Data Loss Prevention can support information protection, but they do not replace staff responsibilities, access management or organisational data-protection processes.
8. Check Retention, Deletion and Records Responsibilities
Keeping information indefinitely can increase exposure and make records harder to govern. Deleting information too early can also create operational, contractual or legal problems.
Retention decisions should be agreed by information governance, legal, clinical and operational stakeholders where appropriate. The IT team should implement approved requirements rather than decide retention periods alone.
Check:
- Is there an agreed retention schedule?
- Are Microsoft 365 retention policies aligned with it?
- Is information being kept without a defined reason?
- What happens to files and email when a user leaves?
- Can deletion be suspended when legitimately required?
- Are duplicate records stored in several Teams or SharePoint sites?
- Who approves changes to retention policies?
- Are policy outcomes tested and documented?
Do not apply one retention period to every type of healthcare information. Requirements vary according to the record, purpose and organisation.
9. Secure the Joiner, Mover and Leaver Process
Access can become excessive when staff change roles, leave the organisation or complete temporary assignments. These risks often result from process gaps rather than missing Microsoft technology.
The organisation should connect HR, management and IT processes so access changes happen at the correct time.
Review:
- Who approves new accounts and access?
- Are permissions based on the user’s role?
- Are previous permissions removed when responsibilities change?
- How quickly are leaver accounts blocked?
- Are active sessions revoked when necessary?
- Are organisation-owned devices returned?
- Are shared mailboxes and files transferred to a new owner?
- Do contractor and temporary accounts have expiry dates?
- Is guest access removed when an external relationship ends?
Periodic access reviews can identify accounts and permissions that remain active after the original requirement has ended.
10. Enable Logging, Alerting and Security Monitoring
Audit logs and security alerts help an organisation identify suspicious activity and reconstruct events after an incident. Their value depends on whether the right information is available and someone is responsible for reviewing it.
Check:
- Is relevant audit logging enabled?
- Who reviews Microsoft 365 security alerts?
- How quickly must critical alerts be investigated?
- Are unusual sign-ins monitored?
- Are administrative and permission changes visible?
- Is log retention appropriate for the organisation’s needs?
- Can alerts be escalated outside normal working hours?
- Are actions and outcomes recorded?
- If monitoring is outsourced, are responsibilities clearly defined?
Simply enabling alerts is not sufficient. The organisation needs an investigation process, accountable owners and clear escalation thresholds.
11. Test Incident Response and Business Continuity

A Microsoft 365 incident may involve a compromised account, malicious email, inappropriate sharing, lost device or service disruption. The response plan should explain how the organisation will contain the event while maintaining essential operations.
Review whether the incident plan covers:
- Blocking or restricting a compromised account
- Revoking active user sessions
- Investigating suspicious email activity
- Removing inappropriate sharing links
- Responding to lost or stolen devices
- Preserving relevant evidence
- Escalating to management and information governance
- Communicating with affected teams
- Meeting applicable reporting obligations
- Recovering essential information and services
Test the plan through scheduled exercises. A written procedure may fail if staff cannot access it, do not understand their responsibilities or lack the permissions needed to take action.
12. Use Microsoft Secure Score as a Starting Point
Microsoft Secure Score provides a view of recommended security actions across supported identities, applications and devices. It can help organisations compare their current position, assign improvement work and monitor progress.
However, a higher score is not proof that an organisation is secure. Microsoft states that Secure Score is not an absolute measurement of breach likelihood or a guarantee against a security incident. Microsoft Secure Score should be interpreted alongside organisational risks and other controls.
Review:
- Is Secure Score checked regularly?
- Are recommendations assigned to accountable owners?
- Are high-risk actions prioritised?
- Are licence-dependent recommendations identified?
- Are decisions not to implement a control documented?
- Are alternative controls recorded?
- Is progress reviewed over time?
The objective is not necessarily to achieve the highest possible number. Security measures must remain appropriate for the organisation’s services, users and information.
How Does This Checklist Relate to UK Healthcare Requirements?
Microsoft 365 controls can support security and data-protection responsibilities, but technology alone does not establish compliance.
Under UK GDPR, organisations need security measures appropriate to the risk. This involves considering the sensitivity and volume of information, potential effects on individuals, working practices and available technical and organisational measures. The ICO’s data security guidance explains the wider responsibilities involved.
Organisations accessing NHS patient data or systems should also assess their responsibilities under the Data Security and Protection Toolkit. Evidence may include policies, training, access controls, incident processes and technical configurations.
The NCSC Cloud Security Principles also distinguish between assessing the security of a cloud service and configuring that service securely. Selecting Microsoft as a cloud provider does not remove the customer’s responsibility to manage identities, permissions, devices and data.
Organisations may also have contractual, professional and sector-specific requirements that affect how Microsoft 365 should be configured and governed.
This checklist provides practical security guidance. It is not legal, regulatory or clinical-safety advice.
Does Your Microsoft 365 Licence Support the Controls You Need?
Microsoft 365 security capabilities vary by plan. Features such as advanced Conditional Access, device management, email threat protection, identity-risk detection and information governance may require particular subscriptions or add-ons.
A licensing review should establish:
- Whether the current plan includes the required identity controls
- Whether devices can be managed appropriately
- Which Defender capabilities are available
- Whether the required Purview functions are licensed
- Whether security products overlap
- Whether paid-for features have actually been configured
- Whether users have been assigned suitable licences
The lowest-priced licence is not always the lowest-cost choice if separate products are needed to address missing controls. Equally, an organisation may be paying for advanced capabilities that have never been implemented.
A Microsoft licensing partner can help relate licensing decisions to the organisation’s users, devices and security requirements.
What Should Healthcare Organisations Review First?

The right sequence depends on the organisation’s risk assessment, but the following framework can help prioritise action.
| Priority | Areas to review |
|---|---|
| Immediate | Unprotected administrator accounts, missing MFA, active leaver accounts and uncontrolled external sharing |
| High | Unmanaged devices, excessive permissions, email threats and missing alert ownership |
| Planned | Information classification, retention, Data Loss Prevention, guest reviews and incident exercises |
| Ongoing | Secure Score, licence usage, policy exceptions, audit logs and security awareness |
Do not delay an obvious high-risk issue simply because it belongs to a later project phase. Where a change could affect access to clinical or operational services, test it with a controlled group before wider implementation.
Need a Clearer View of Your Microsoft 365 Security Position?
A checklist can indicate where to investigate, but it cannot confirm whether individual policies, permissions and controls are configured correctly.
Ultralink can review your Microsoft 365 identities, administrative roles, device access, email protection, collaboration settings and information-governance capabilities. The assessment can also identify whether your current licences support the controls your healthcare organisation requires.
Note: This checklist provides practical security guidance. It is not legal, regulatory or clinical-safety advice.

