Free tool

Is Your Microsoft 365 or Google Workspace Actually Configured Securely?

Buying Microsoft 365 or Google Workspace doesn't make you secure, and it doesn't make you compliant. Both are sold under a shared responsibility model: the vendor secures the platform, and every setting that decides who gets in, from where, and what they can reach afterward belongs to you.

That's not a footnote. It's most of your attack surface, and it's configured in an admin console nobody signed for it.

Below are twelve settings that decide whether a stolen password becomes a breach. Check what's already true in your tenant. It takes about five minutes, it's free, and no email is required to see your results.

One correction worth making up front: your license tier does not determine whether you can sign a Business Associate Agreement. Microsoft makes its BAA available by default to covered entities on all plans, and Google's HIPAA implementation guide imposes no edition restriction. What the lower tiers lack is the controls - Conditional Access, device management, DLP, data retention - that a defensible risk analysis will look for. Buy the tier that gives you controls, not the tier you were told was 'the compliant one.'

The 12-setting checklist
  • Enforced means nobody can turn it off for themselves and no account is exempt. An MFA policy with exceptions is an MFA policy attackers will find.

    Microsoft 365: Entra admin center - security defaults enabled, or a Conditional Access policy requiring MFA for all users.

    Google Workspace: Admin console - Security - Authentication - 2-Step Verification, set to enforced with no exempt org units.

    Addressed by: /services/cyber-risk-management/#process \u2192

  • Every hour a privileged account spends reading email is an hour that account is exposed. Administration happens in a separate account used only for administration.

    Microsoft 365: Entra admin center - Roles - confirm Global Administrators are dedicated accounts, and there are more than one but fewer than five.

    Google Workspace: Admin console - Admin roles - confirm Super Admins are dedicated accounts, not anyone's everyday login.

    Addressed by: /services/cyber-risk-management/#maturity-checklist \u2192

  • The BAA is not tier-gated, but conditional access, device management, and data loss prevention are. If a framework applies to you, price the tier that carries the controls.

    Microsoft 365: Business Basic and Standard do not include Entra ID P1, Intune, or Defender for Business. Business Premium does.

    Google Workspace: Starter lacks Vault, DLP, and context-aware access. Standard adds Vault; Plus adds DLP and context-aware access.

    Addressed by: /services/fractional-leadership/ \u2192

  • Both vendors will sign one. Neither one signs it automatically, and neither covers every service in the suite - the covered-services list is the part to read.

    Microsoft 365: The BAA is part of the Microsoft Products and Services Data Protection Addendum, available to covered entities and business associates by default.

    Google Workspace: Accepted in the Admin console; Google publishes the covered-services list in its HIPAA Implementation Guide.

    Addressed by: /compliance/hipaa/ \u2192

  • The problem isn't the provider, it's the absence of everything around it: no enforced MFA, no audit trail, no way to revoke access when someone leaves, no way to produce the record when someone asks.

    Microsoft 365: Check for mail-forwarding rules to external addresses in the Exchange admin center.

    Google Workspace: Admin console - Apps - Gmail - check automatic forwarding settings and any allowed external routing.

    Addressed by: /services/grc/#process \u2192

  • Default sharing settings are built for convenience. A link set to 'anyone with the link' outlives the project, the employee, and usually the memory of creating it.

    Microsoft 365: SharePoint admin center - Policies - Sharing. Check the default link type and whether external sharing is on.

    Google Workspace: Admin console - Apps - Drive and Docs - Sharing settings, including link sharing defaults.

    Addressed by: /services/cyber-risk-management/#process \u2192

  • An enrolled device you can't identify is either a forgotten personal phone or somebody else's access. Both need answering.

    Microsoft 365: Microsoft 365 admin center - Devices, and Intune if licensed.

    Google Workspace: Admin console - Devices - Endpoints.

    Addressed by: /services/helpdesk-support/#scope \u2192

  • Suspend the account, revoke active sessions, and transfer the data. Changing the password alone leaves live session tokens working - a signed-in session survives a password change.

    Microsoft 365: Block sign-in and revoke sessions in Entra, then convert the mailbox to shared.

    Google Workspace: Suspend the account and use Transfer tool for Drive and Gmail data before deleting.

    Addressed by: /services/helpdesk-support/#scope \u2192

  • Without these, anyone can send mail that appears to come from your domain, and your customers have no way to tell. DMARC at p=none publishes the problem without fixing it.

    Microsoft 365: DKIM is enabled per-domain in the Defender portal; SPF and DMARC are DNS records.

    Google Workspace: Admin console - Apps - Google Workspace - Gmail - Authenticate email, plus DNS records.

    Our Email Health Scanner checks all three in a few seconds.

    Addressed by: /tools/email-health-scanner/ \u2192

  • Incidents get discovered weeks after they start. If your logs only go back thirty days, the investigation ends where the evidence does - and carriers commonly ask for ninety.

    Microsoft 365: Purview - Audit. Confirm auditing is on and check the retention period for your license.

    Google Workspace: Admin console - Reporting - Audit and investigation. Retention varies by edition.

    Addressed by: /services/cyber-risk-management/#maturity-checklist \u2192

  • Users grant applications access to mail and files without a password ever changing hands. Those grants survive password resets and MFA, and almost nobody reviews them.

    Microsoft 365: Entra admin center - Enterprise applications - review consented permissions and restrict user consent.

    Google Workspace: Admin console - Security - API controls - review third-party app access and mark unconfigured apps as blocked.

    Addressed by: /services/third-party-assessments/ \u2192

  • Retention is not backup. Both vendors are explicit that keeping your data recoverable is your responsibility, and ransomware that encrypts a synced folder syncs the encryption.

    Microsoft 365: Retention policies and the recycle bin are not a backup. Confirm a third-party backup covers Exchange, SharePoint, OneDrive, and Teams.

    Google Workspace: Vault is for retention and legal hold, not recovery. Confirm a third-party backup covers Gmail and Drive.

    Addressed by: /resources/saas-shared-responsibility/ \u2192

You checked 0 of 12.

FAQ

Common questions

Do I need to enter my email to see my results?

No. Your results appear on this page as you check items. Email is only for sending yourself a copy, and that option appears after your results - never before.

Does Microsoft 365 or Google Workspace make me HIPAA compliant?

Neither one, on its own. Both will sign a Business Associate Agreement, and both publish a list of which services that agreement covers - but the agreement covers the vendor's obligations, not your configuration. HIPAA holds you responsible for how the platform is set up and who can reach what. That's what this checklist looks at.

Which license do I actually need?

There is no compliance license. Neither vendor gates the BAA by edition. What the tiers change is which controls you get - conditional access, device management, data loss prevention, audit retention - and which controls you need depends on which frameworks apply to you. The Compliance Finder answers that half.

We have an IT provider. Shouldn't they have done this?

Often they have. This checklist is how you find out, and every item names the exact console screen where the answer lives, so the conversation starts with a specific setting rather than a general worry.

The information provided here is for educational purposes only and should not be considered legal advice. Requirements change and applicability depends on your specific circumstances - for specific compliance concerns, consult a qualified legal professional.