Product Listing Checklist for noon and Amazon.ae Sellers in the UAE
Everything to check before, during and after you list a product on noon or Amazon.ae, taken from each marketplace's own seller help pages.
Read the articleIT Services
The settings a small UAE company should check in its Microsoft 365 tenant, in order: sign in, admin accounts, email, sharing, devices, audit logs and Secure Score.

This Microsoft 365 security checklist covers seven areas a small business in Dubai or elsewhere in the UAE can work through in order to secure most of its tenant: confirm security defaults or Conditional Access requires multifactor sign in for everyone, lock down admin accounts, apply Microsoft’s preset email protection and stop automatic forwarding to outside addresses, restrict external file sharing, manage the devices that reach company data, switch on audit logging, and use Secure Score to track what is left. Almost all of it is configuration inside licences you already pay for.
The checklist below follows Microsoft’s own documentation for business plans, which Microsoft aims at organisations with up to 300 users, and notes where a setting depends on Business Premium. Microsoft changes defaults from time to time, so each item reflects the documentation as of September 2026.
Key points
Microsoft’s security best practices article for business plans compares Basic, Standard and Premium. The difference matters because several items on this checklist only exist in Premium.
| Capability | Basic and Standard | Business Premium |
|---|---|---|
| Spam, malware and phishing protection for mailboxes | Included | Included |
| Security defaults | Included | Included |
| Conditional Access | Not included | Included |
| Defender for Office 365 Plan 1 (Safe Links, Safe Attachments, impersonation protection) | Not included | Included |
| Basic Mobility and Security for phones | Included | Included |
| Intune Plan 1 and device protection with Defender for Business | Not included | Included |
| Data Loss Prevention, sensitivity labels, message encryption | Not included | Included |
Before changing anything, open the Microsoft 365 admin center, list which licences each user holds, and note who has an admin role. That list is the baseline for everything below, and it is the kind of record our IT support team keeps up to date for clients.
This Microsoft 365 security checklist starts sign in here. Microsoft Entra security defaults are a single switch that applies a fixed set of protections. Microsoft’s documentation lists them as requiring every user to register for multifactor authentication, requiring admins to complete it, prompting other users when Microsoft judges it necessary, blocking legacy authentication protocols, blocking device code flow and requiring multifactor authentication for Azure management tools. Microsoft says security defaults are rolled out to new tenants when they are created.
If you have Business Premium and need exceptions, such as allowing sign in only from managed devices, Conditional Access replaces security defaults. Microsoft’s instruction is that security defaults must be disabled when Conditional Access policies take over, and that equivalent policies should be enabled immediately afterwards so there is no gap.
The next item on this Microsoft 365 security checklist is admin accounts. Whoever signed up for Microsoft 365 became a Global Administrator. In many small UAE companies that person is the founder, an office manager or a supplier who set things up years ago, and the same account is used for daily email. Microsoft’s guidance on admin accounts for business plans recommends a different arrangement.
If a supplier holds your only Global Administrator account, you do not fully control your own tenant.
Email is the third item on this Microsoft 365 security checklist. Every cloud mailbox gets built in protection against spam, malware and spoofing. Microsoft’s preset security policies apply its recommended settings in one step instead of tuning dozens of options by hand. There are Standard and Strict presets, plus a Built-in protection preset that gives basic Safe Links and Safe Attachments coverage in tenants with Defender for Office 365. You find them in the Microsoft Defender portal under Email and collaboration, Policies and rules, Threat policies.
The second email setting deserves particular attention. A common problem we see in UAE companies is payment fraud that starts with a mailbox someone else has quietly taken over, and Microsoft notes that inbox rules forwarding mail to outside recipients can be created as a result of a compromised account. Microsoft’s outbound spam policy has three choices for automatic external forwarding: Automatic, System controlled; On; and Off. Microsoft explains that the automatic setting behaves differently depending on when and how the tenant was set up, and recommends choosing On or Off explicitly.
Sharing is the fourth item on this Microsoft 365 security checklist. SharePoint and OneDrive offer four organisation level sharing levels: Anyone, New and existing guests, Existing guests, and Only people in your organisation. The OneDrive setting can be stricter than SharePoint but never more open, and each site can be stricter than the organisation.
Microsoft notes that if external sharing is restricted, guests typically lose access within an hour, so warn project teams before changing the setting. For where company data should live in the first place, see our cloud services.
Devices are the fifth item on this Microsoft 365 security checklist. Staff in Dubai offices often read company email on personal phones. Every business plan includes Basic Mobility and Security, a free subset of Intune that can require a device password before company apps open, and can remove company data from a device or reset it to factory settings. Business Premium adds Microsoft Intune Plan 1 for managing both devices and apps, and device protection policies with Microsoft Defender for Business for laptops and desktops.
Audit logging is the item most small tenants miss on this Microsoft 365 security checklist. Microsoft’s Purview documentation says audit logging is on by default for Microsoft 365 organisations in general, but not for small and medium business licences including Business Basic, Standard and Premium, which must turn it on manually. Once enabled, the audit log records user and admin activity and retains it for 180 days by default. Without it, there may be little record to show what an attacker did after taking over a mailbox.
To turn it on, open the Microsoft Purview portal, select the Audit solution, and choose the banner to start recording user and admin activity. Microsoft says this can take up to 60 minutes to take effect.
Microsoft Secure Score, at security.microsoft.com/securescore, then gives you a running list of recommended actions. Each action is worth up to ten points, and some award partial points, such as protecting half your users. Turning on security defaults earns full points for the multifactor and legacy authentication recommendations. Microsoft is careful to say that Secure Score reflects how far you use recommended controls, not an absolute measure of whether you could be breached, and that security has to be balanced with usability. Review it monthly and record any recommendation you decide not to follow, with the reason.
The UAE Cyber Security Council publishes guidance for businesses that lines up with this Microsoft 365 security checklist. It advises companies to review threat updates regularly, prepare and test response plans for suspicious activity, train staff regularly, audit systems periodically for vulnerabilities, and work with cyber security professionals to assess their defences.
For reporting, the Council’s website points Dubai users to the Dubai Police eCrime website, Abu Dhabi users to the Aman service, and everyone to the Ministry of Interior’s eCrimes platform, the nearest police station or 999. If a compromised account exposed customer information, your obligations under UAE data protection law are a question for a legal adviser; our article on email marketing consent under the UAE data protection law introduces that law in a marketing context. This section is general information, not legal advice.
We review a tenant against this Microsoft 365 security checklist, make the changes with you, and document every setting in a register you keep. The work is part of our IT services, with day to day administration through IT support and email authentication and staff awareness through cyber security. We are not a security operations centre, we do not hold security certifications, and no configuration can promise that an attack will never succeed. What you get is a tenant set up the way Microsoft documents it, and a written fixed price proposal within 45 minutes during business hours.
Straight answers
Basic includes email protection against spam, malware and phishing, security defaults and basic mobile device management, which covers the essentials in this checklist. Business Premium adds Conditional Access, Defender for Office 365 Plan 1, Intune and Defender for Business, which matter more as the team, devices and data grow.
Removing multifactor authentication for one user reopens exactly the gap that security defaults are designed to close. With security defaults, Microsoft decides when to prompt based on factors such as location, device and role, and separate admin accounts reduce prompts for admins. Explain the reason and help the person set up the app properly instead.
No. Microsoft describes Secure Score as a measure of how many recommended controls you use, not an absolute measure of how likely a breach is, and says no online service is immune. Use it to track progress, alongside the other checks here.
Security defaults block legacy authentication, and older devices that send email with basic sign in are affected. Microsoft publishes guidance on setting up multifunction devices and applications to send email through Microsoft 365, so reconfigure the device rather than switching protection off.
The UAE Cyber Security Council lists official reporting channels, including Dubai Police's eCrime website for Dubai. If money or customer personal data is involved, speak to your bank and your legal adviser as well. This is general information, not legal advice.
Sources
Fixed price, in writing
Got it. Your quote is being written now.
In business hours you will have it within 45 minutes. Check your inbox for the confirmation.
Keep reading

Everything to check before, during and after you list a product on noon or Amazon.ae, taken from each marketplace's own seller help pages.
Read the article
How a UAE business decides between noon and Amazon.ae, using the marketplaces' own rules on eligibility, reach, catalogue, language and ads.
Read the article
When Arabic marketing copy should follow the English closely, when it should be recreated, and how to brief and check both.
Read the article