The checklist recommends strong MFA for privileged roles, reducing standing privilege, and removing shared admin accounts. It also says organizations should inventory AI usage, control access and logging, and review workflows for prompt injection and sensitive data leakage.
Microsoft 365 and enterprise AI adoption are pushing security and access controls higher on the agenda