Microsoft Solutions Partner

Free self-check · about 30 minutes · no tools to install

You're paying for 20 security controls. Find out how many are on.

The Business Premium activation check walks you through the 20 identity, device, email, sharing, and data protections included in Microsoft 365 Business Premium. Where each one lives. What “on” looks like. A score at the end. For IT leads and executives at organizations of 25 to 300 staff.

  • Microsoft Solutions Partner, five solution-area designations
  • CIS-certified baseline platform
  • Working with organizations on Microsoft since 2014

Get the activation check

It opens on this page as soon as you submit. A copy goes to your inbox.

This field is required
Valid email required
This field is required

We use this only to respond to you. See our privacy policy.

No sales call unless you ask for one. We guarantee 100% privacy. Your information will not be shared.

Here's your activation check.

Open it now. A copy is on its way to your inbox from Chris.

Open the activation check (PDF)

Want it run on your tenant, with every control mapped and the fix order written down? That is the $1,950 Readiness Assessment, credited in full against a Module 1 Launch within 30 days. Ongoing management after Launch is optional.

Book a 15-minute fit call

The first five, no form needed

Identity: five controls, five places to look.

  1. MFA is required for every user.

    Where: Entra admin center → Protection → Conditional Access → Policies. On looks like a policy for all users and all resources, with only the emergency-access account excluded.

  2. Legacy authentication is blocked.

    Where: the “Block legacy authentication” policy is On, not report-only, and the sign-in logs show zero legacy protocols.

  3. Admin accounts are few, cloud-only, and protected.

    Where: Entra → Roles & admins → Global Administrator. Two to four, separate from daily mailboxes, MFA required, one documented emergency-access account.

  4. Access requires a compliant device, or MFA on an unmanaged one.

    Where: Conditional Access → “Require device to be marked as compliant”, backed by the Intune compliance policies in control 7.

  5. Self-service password reset and banned passwords are on.

    Where: Entra → Protection → Password reset, and → Authentication methods → Password protection, with your own organization's names on the banned list.

Fifteen more cover devices, email, sharing, data, and the one control that keeps the other nineteen on.

What's in the other fifteen

The controls most tenants never turn on.

  • The two email controls that flag a message from a free mailbox carrying your executive director's name, and why one of them is a DNS record, not a setting.
  • The default that lets any staff member share a file with anyone on the internet, and where the switch is.
  • What “compliant device” actually means, and the one Conditional Access policy that makes Intune matter.
  • The two Purview foundations Microsoft 365 Copilot inherits on day one.
  • A one-page scoresheet, 0 to 20, with what each band usually means.

Send me the activation check

Why this exists

You didn't under-buy. It shipped switched off.

Microsoft 365 Business Premium already includes the identity, device, email, and data protection that larger organizations buy separately. Most of it ships off, and it stays off. Turning it on means working through six admin centers and your DNS registrar. Microsoft shipped more than 50 changes to Entra, Intune, and Defender last year, and none of them switch themselves on. Nobody's job is “operate the tenant,” so nobody does.

We run this check by hand at the start of every engagement. In our experience, a tenant only scores 20 when someone's job is to keep it there. This is that check, written down so you can run it yourself.

It matters more now than it did. Everyone wants to get to Copilot and agents, and those inherit whatever the tenant already allows. The organizations that get there safely put this foundation in place first, then move up the stack.

Who made it

Written by the people who run these checks for a living.

Chris Grecsek, founder of Centered Networks

Microsoft Solutions Partner with five solution-area designations. Working mostly with nonprofits, foundations, and rural hospitals on Microsoft 365 and Azure since 2014. The check is the first thing we run on a new tenant. The M365 InstantOn service is what keeps the score at 20.

Questions

Before you submit.

Is this a sales call in disguise?

No. The check opens on this page the moment you submit, and a copy lands in your inbox. If you want us to run it on your tenant, that is a 15-minute call, and you would have to ask for it.

Do I need admin rights?

Global Reader is enough to look, or Security Reader plus the SharePoint and Teams admin roles. Nothing in the check changes a setting.

We're under 25 staff. Still worth it?

Yes. The 20 controls are the same; the fix is smaller.

Does a high score mean we're secure?

It means the controls are on. Whether they fit your organization's exceptions, service accounts, and sharing needs is the next conversation.

What happens after I submit?

The check opens here and a copy arrives by email within a few minutes. After that, occasional notes from Chris on operating Microsoft 365, unsubscribe any time.

Thirty minutes, six admin centers, one number.

Find out what you're paying for and not using, before someone else does.

Send me the activation check