Sharepoint Security Checklist
Critical security items for SharePoint Online and on-premises. Use this checklist to ensure your SharePoint environment is secure, compliant, and protected against threats.
Permissions & Access Control
Critical Security Items
- ☐ MFA enforced for all SharePoint users
- ☐ Conditional access policies configured for SharePoint access
- ☐ Site permissions audited quarterly
- ☐ Direct user permissions minimized (use groups instead)
- ☐ Broken inheritance documented and reviewed
- ☐ Site owners reviewed and validated
- ☐ Access request workflows configured
- ☐ Guest access policies defined and enforced
- ☐ Orphaned permissions removed regularly
- ☐ Permission inheritance restored where appropriate
External Sharing Controls
Critical Security Items
- ☐ External sharing policy defined at tenant level
- ☐ Site-level external sharing restrictions configured
- ☐ Anonymous sharing links disabled or restricted
- ☐ Guest access expiration policies implemented
- ☐ External sharing monitoring enabled
- ☐ Allowed domains list configured for partner sharing
- ☐ Sharing link expiration policies set
- ☐ Guest user review process established
- ☐ External sharing audit logging enabled
- ☐ DLP policies for external sharing configured
Information Protection & DLP
Critical Security Items
- ☐ Sensitivity labels defined and deployed
- ☐ Default sensitivity labels configured for sites
- ☐ Auto-labeling rules implemented
- ☐ DLP policies for SharePoint configured
- ☐ Sensitive information types defined
- ☐ Policy tips enabled for user education
- ☐ DLP alerts and incident management configured
- ☐ Encryption applied to sensitive content
- ☐ Watermarking enabled for labeled documents
- ☐ External sharing blocked for high-sensitivity labels
Retention & Compliance
Critical Security Items
- ☐ Retention policies defined for document types
- ☐ Retention labels applied to SharePoint libraries
- ☐ Legal hold processes established
- ☐ eDiscovery configured for SharePoint content
- ☐ Compliance boundaries implemented if required
- ☐ Audit logging enabled for all SharePoint activities
- ☐ Record management in place for official records
- ☐ Disposition review processes configured
- ☐ Compliance reports generated regularly
- ☐ Regulatory requirements mapped to retention policies
Threat Protection & Monitoring
Critical Security Items
- ☐ Microsoft Defender for Office 365 enabled
- ☐ Safe attachments configured for SharePoint
- ☐ Safe links configured for SharePoint content
- ☐ Anti-phishing policies enabled
- ☐ Threat explorer configured for monitoring
- ☐ Automated incident response configured
- ☐ Real-time threat monitoring enabled
- ☐ Security alerts configured for critical events
- ☐ SIEM integration for centralized monitoring
- ☐ Regular security reviews and assessments
Site & Content Governance
Critical Security Items
- ☐ Site creation policies enforced
- ☐ Site naming conventions established
- ☐ Site classification implemented
- ☐ Hub site architecture configured
- ☐ Regular site cleanup and archival
- ☐ Content types and metadata defined
- ☐ Large file monitoring configured
- ☐ Versioning limits configured appropriately
- ☐ Recycle bin retention policies set
- ☐ Site usage monitoring enabled
Backup & Recovery
Critical Security Items
- ☐ SharePoint backup solution implemented
- ☐ Backup schedule defined (daily for critical sites)
- ☐ Backup retention policies configured
- ☐ Recovery procedures documented and tested
- ☐ Disaster recovery plan in place
- ☐ Backup encryption enabled
- ☐ Offsite backup storage configured
- ☐ Regular restore testing performed
- ☐ Backup monitoring and alerting configured
- ☐ Business continuity plan documented
Security Implementation Priority
Critical (Implement Immediately)
- MFA enforcement
- Conditional access
- External sharing controls
- Sensitivity labels
- Audit logging
High (Implement Within 30 Days)
- DLP policies
- Retention policies
- Threat protection
- Backup solution
- Permission audit
Medium (Implement Within 60 Days)
- Advanced monitoring
- SIEM integration
- Automated response
- Compliance reporting
- Security optimization
Need Help Securing Your SharePoint Environment?
Get expert guidance on implementing SharePoint security for your organization. Let's assess your current security posture and create a customized security plan.