← All articles
When your MSP takes on a new Microsoft 365 client, the first thing you want to know is: what state is this tenant in? What was the previous IT provider doing? What's missing? What's a risk?
Going through this manually takes hours and relies on remembering to check every setting. This checklist covers the most important things to verify in the first week of a new client engagement.
Identity and access
- ☐ MFA enabled and enforced for all users (not just admins)
- ☐ Conditional Access policies configured (if Business Premium or E3+)
- ☐ Security Defaults enabled (if no Conditional Access)
- ☐ Legacy authentication blocked
- ☐ Admin accounts have dedicated admin accounts (not dual-purpose user+admin)
- ☐ Global Admin count minimised (2–4 max, with break-glass accounts documented)
- ☐ Privileged Identity Management configured (if E5)
- ☐ Guest accounts reviewed and any stale guests removed
Email security
- ☐ SPF record configured correctly
- ☐ DKIM enabled in Exchange admin centre
- ☐ DMARC record present (at minimum p=none with reporting)
- ☐ Anti-spam policies reviewed
- ☐ Anti-phishing policies configured (impersonation protection)
- ☐ Safe Links and Safe Attachments enabled (Defender for Office 365 required)
- ☐ External email tagging enabled (shows [EXTERNAL] on inbound emails)
- ☐ Mailbox auditing enabled
Data and sharing
- ☐ SharePoint external sharing policy reviewed and set appropriately
- ☐ OneDrive sharing policy reviewed
- ☐ DLP policies configured (if Business Premium or E3+)
- ☐ Sensitivity labels configured (if E3+)
- ☐ Teams guest access policy reviewed
- ☐ Teams external access (federation) policy reviewed
Devices
- ☐ Intune enrolled and compliance policies configured (if Business Premium)
- ☐ BitLocker encryption enforced on Windows devices
- ☐ Defender for Business onboarded (if Business Premium)
- ☐ Windows Autopilot configured for new device deployment
Compliance and monitoring
- ☐ Audit logging enabled and retention period noted
- ☐ Microsoft Secure Score reviewed and baseline recorded
- ☐ Alert policies configured for high-risk events (forwarding rules, admin changes)
- ☐ Scheduled scan configured to monitor ongoing
Licensing
- ☐ Licence assignment reviewed — no users paying for unused licences
- ☐ Licence utilisation documented — client aware of what they're paying for
- ☐ Features included in licence but not configured identified and discussed with client
M365Clarity automates most of this checklist. Connect the client tenant, run a scan, and get a colour-coded report covering 97 settings in 30 seconds. Use it as the foundation for your onboarding conversation — red and amber findings become your first 30-day action plan.
Turning findings into a client conversation
The goal of an onboarding audit isn't just to fix things — it's to demonstrate value to the client. A well-presented finding showing that their previous IT provider left MFA disabled is a powerful conversation about why your MSP does things differently.
M365Clarity's Executive Summary and Compliance tabs generate client-ready summaries automatically — no PowerPoint required.
Check your Microsoft 365 configuration in 2 minutes
Connect your tenant, run a scan, and see exactly what needs attention — in plain English. Free plan available.
Scan your tenant free →