If your business uses Microsoft 365 for email, documents, Teams and remote working, your security depends on more than a strong password. The right Microsoft 365 security settings help control who can sign in, what they can access and how quickly you can respond when something looks suspicious.
Ensuring your Microsoft 365 security settings are correctly configured is vital for protecting your business data.
This matters even if you have a small team.
Diana runs a 12-person digital marketing agency in Winchester. Her team uses Microsoft 365 every day to manage client campaign data, proposals, CRM information and shared files. Staff work from the office, from home and occasionally from client sites.
Diana is acutely aware of the importance of reviewing her Microsoft 365 security settings regularly to safeguard her team’s work.
One afternoon, Diana receives a realistic-looking message asking her to review a campaign document. She signs in through a convincing fake page. Within minutes, an attacker has access to her mailbox. If the tenant is poorly configured, the attacker could read client conversations, create a hidden forwarding rule and access shared files.
This is not an unusual scenario. It is why Microsoft 365 security for small business should be treated as an ongoing business responsibility, not a one-off setup task.
Use the following checklist to review your environment. Some features depend on your Microsoft 365 licence, tenant configuration or additional Microsoft services. Always check the current Microsoft documentation before making changes.
This checklist focuses on the best practices for your Microsoft 365 security settings to prevent data breaches.
Microsoft 365 security settings: start with the basics
Reviewing Microsoft 365 security settings early helps you close common gaps before they turn into incidents. For most small businesses, these controls are not just technical preferences. They are practical safeguards that reduce the chances of account compromise, data exposure and unnecessary downtime.
Proper management of your Microsoft 365 security settings is essential in today’s digital landscape.
1. Require multifactor authentication for every user
Multifactor authentication (MFA) requires users to prove their identity in more than one way. For example, they may enter a password and approve a notification through an authenticator app.
A stolen password should not be enough to access your business systems.
What to check
-
- Require Microsoft 365 MFA for all users.
- Include administrators and remote workers.
- Prefer an authenticator app or security key over SMS where practical.
- Check that users have registered a backup authentication method.
- Review authentication methods when someone leaves the business.
- Make sure emergency access arrangements are documented and protected.
Regular checks of your Microsoft 365 security settings help maintain a strong security posture.
Microsoft provides guidance on multifactor authentication for Microsoft 365 for business.
For smaller organisations, security defaults may provide a suitable baseline. They are designed to apply essential protections, including MFA requirements and protection against older sign-in methods.
If your business needs more detailed controls, you may use Conditional Access instead. Do not enable overlapping or conflicting policies without testing them carefully.
Utilising the best Microsoft 365 security settings can significantly mitigate risks associated with cyber threats.
Pro tip: Ask each user to report unexpected MFA prompts. Several prompts in a short period could indicate that someone is trying to use a stolen password.
2. Use separate administrator accounts
An administrator account can make high-impact changes. It may be able to reset passwords, alter security policies, create users or access sensitive information.
Using that account for ordinary email and web browsing increases its exposure.
What to check
-
- Give each administrator a separate admin account.
- Use the standard account for email, Teams and everyday work.
Each user’s compliance with the recommended Microsoft 365 security settings is critical for overall protection.
- Protect administrator accounts with MFA.
- Keep the number of Global Administrators as low as possible.
- Review privileged roles regularly.
- Remove access when a person changes responsibility or leaves.
For example, Diana may have one account for managing client campaigns and another for administering Microsoft 365. If her everyday account is compromised, the attacker should not automatically gain administrator privileges.
See Microsoft’s guidance on admin account security in Microsoft 365 for business.
Warning: Never share an administrator password between members of staff. Shared accounts make investigations more difficult and weaken accountability.
3. Disable legacy authentication where applicable
Legacy authentication is an older way of connecting to services such as email. It may not support modern security controls, including MFA.
Old mail apps, devices and protocols can therefore become a route around your stronger sign-in policies.
Transitioning to updated Microsoft 365 security settings strengthens your defence against modern threats.
What to check
- Identify whether POP, IMAP or other legacy connections are still being used.
- Confirm that old mail clients and devices have been replaced or updated.
- Disable legacy authentication where it is no longer required.
- Test the change with staff before applying it widely.
- Document any genuine exception and set a removal date.
Security defaults may block legacy authentication in suitable Microsoft 365 environments. Alternatively, Conditional Access can be used to block older client types where the relevant licensing and configuration support it.
Microsoft explains how to block legacy authentication with Conditional Access.
Utilising Microsoft 365 security settings can block unwanted access and enhance overall security.
Note: Do not simply disable protocols without checking business dependencies. A forgotten scanner, CRM integration or line-of-business application may still rely on an older connection method.
4. Configure Conditional Access and sign-in risk policies
Conditional Access works like a set of “if this, then that” rules. For example:
If a user signs in from an unfamiliar location, require additional verification or block access.
It can use signals such as the user, application, device, location and sign-in risk.
What to check
- Require MFA for administrator roles.
- Require managed or compliant devices for sensitive applications.
- Block access from locations that your business never uses, where appropriate.
- Block legacy authentication.
- Test policies in report-only mode before enforcing them.
- Keep an emergency access process so administrators are not locked out.
Conditional Access is not available in every Microsoft 365 plan. It commonly requires the appropriate Microsoft Entra licence, and Microsoft 365 Business Premium includes relevant Conditional Access capabilities. Risk-based policies, such as sign-in risk and user risk policies, have additional licensing requirements.
These Microsoft 365 security settings are most effective when they are planned together rather than added one by one without testing.
Integrating the latest features into your Microsoft 365 security settings ensures maximum effectiveness.
Read Microsoft’s Conditional Access overview and verify your current licence position before planning a policy.
For Diana, a sensible policy might require MFA whenever a team member signs in to Microsoft 365 from an unmanaged device. A more advanced risk policy could require a password reset or block a high-risk sign-in, if the necessary services are available.

Review your Microsoft 365 security settings for email and sharing
5. Restrict mailbox forwarding and suspicious inbox rules
Attackers who compromise a mailbox often create rules to hide messages or forward copies to an external address.
They may use those messages to monitor invoices, passwords, contracts or client communications without being noticed.
What to check
Attackers may exploit gaps in your Microsoft 365 security settings if not addressed promptly.
- Block automatic forwarding to external addresses unless there is a clear business need.
- Review Exchange mail flow rules.
- Check user inbox rules for unusual forwarding, deletion or hiding actions.
- Alert administrators when new forwarding rules are created.
- Review forwarding settings after a suspected account compromise.
- Remove forwarding arrangements when they are no longer needed.
In Diana’s agency, an attacker could create a rule that forwards every message containing words such as “invoice”, “password” or “campaign” to an external mailbox. The rule might remain unnoticed for weeks.
Use the Exchange Online mail flow rules documentation as a starting point.
Pro tip: Include mailbox-rule checks in your account compromise response plan. Resetting the password alone may not stop continued data exposure if malicious rules remain active.
6. Tighten SharePoint and OneDrive external sharing
Microsoft 365 makes collaboration easy, but a sharing link can expose information beyond the people you intended to reach.
“Anyone with the link” is particularly risky for confidential material because the link can be forwarded without your knowledge.
Implementing strong Microsoft 365 security settings is essential for protecting sensitive client information.
What to check
- Review the organisation-wide external sharing setting.
- Use the most restrictive setting that still supports your work.
- Prefer named people or authenticated guests over anonymous links.
- Set expiry dates for sharing links where appropriate.
- Review existing external users and remove those who no longer need access.
- Check sensitive client folders separately from general marketing resources.
- Use least privilege: give people only the access they need.
Microsoft’s SharePoint and OneDrive sharing overview explains the available controls.
Diana’s team may need to share a campaign presentation with a client. That does not mean the client should have access to the entire project folder. Create a specific client-sharing location and review it after the project ends.
Always consider your Microsoft 365 security settings when sharing files externally.
7. Enable audit logging and security alerting
Security logs record important activity across your environment. They can show sign-ins, file access, role changes, mailbox activity and other events.
Logging and monitoring in your Microsoft 365 security settings can assist in identifying potential breaches.
Without logs, you may not know what happened during an incident or how much information was accessed.
What to check
- Confirm that audit logging is enabled.
- Review Microsoft Entra sign-in activity.
- Monitor administrator role changes.
- Alert on suspicious sign-ins and impossible travel indicators.
- Monitor unusual mailbox forwarding and mass file downloads.
- Decide who receives alerts and who responds to them.
- Retain logs for a period that suits your operational and compliance needs.
Microsoft provides audit solutions in Microsoft Purview and sign-in logs in Microsoft Entra.
Logging is only useful if somebody reviews it. A small business does not need to watch every event manually, but it should have a clear process for investigating high-priority alerts.
8. Configure Microsoft Defender and email protection
Microsoft 365 includes baseline protection against threats such as spam, malware and spoofing. Depending on your licence, you may also have access to enhanced protections such as Safe Links, Safe Attachments and additional impersonation controls.
These features should be configured rather than assumed.
Reviewing your Microsoft 365 security settings ensures your email is adequately protected.
What to check
-
- Review anti-spam and anti-malware policies.
- Configure anti-phishing protection.
- Protect senior staff and finance-related mailboxes against impersonation.
- Enable Safe Links where available.
- Enable Safe Attachments where available.
Always check your Microsoft 365 security settings to ensure protection against impersonation threats.
- Review quarantine notifications and release permissions.
- Make sure staff know how to report suspicious messages.
- Consider preset security policies where they suit your organisation.
Microsoft’s recommended settings for Exchange Online Protection and Microsoft 365 explains the available controls.
The exact feature set depends on your subscription and configuration. Built-in email protection is not the same as every Microsoft Defender for Office 365 capability, so check what your business actually has enabled. Reviewing these Microsoft 365 security settings regularly helps make sure protections still match the way your team works.

Understanding your Microsoft 365 security settings leads to better incident response planning.
Control access from devices and plan for recovery
9. Require secure and compliant devices
A valid user account does not guarantee that the device is safe. A stolen or poorly maintained laptop may expose files, browser sessions and saved credentials.
Ensure that your Microsoft 365 security settings enforce compliance across all devices.
What to check
- Require screen locks and strong device authentication.
- Keep operating systems and applications patched.
- Use encryption on business laptops where supported.
- Protect devices with reputable endpoint security.
- Remove access from lost or stolen devices.
- Review personal-device access and bring-your-own-device arrangements.
- Require compliant devices for sensitive resources where your licensing supports it.
Microsoft 365 plans include different levels of device management. Basic Mobility and Security may be available for some controls, while more advanced management may require Microsoft Intune and the appropriate licence.
See Microsoft’s overview of device security in Microsoft 365 for business.
Do not make device controls so restrictive that staff work around them by moving client data to personal email or unapproved file-sharing services. Apply controls alongside clear guidance and practical support.
10. Review backup and recovery arrangements
Microsoft 365 provides resilience, but it should not automatically be treated as a complete backup strategy for every business need.
Regularly assess your Microsoft 365 security settings to avoid unexpected data loss.
Accidental deletion, malicious deletion, ransomware, retention requirements and recovery times all need consideration.
What to check
- Understand Microsoft’s retention and recovery options.
- Decide which mailboxes, SharePoint sites, OneDrive accounts and Teams data need additional protection.
- Confirm how long deleted data can be recovered.
- Test restoration, not just backup status.
- Document who can authorise recovery.
- Protect backup administration accounts with MFA.
- Keep recovery information available if your main tenant is unavailable.
- Include Microsoft 365 in your wider business continuity plan.
The right approach depends on your data, risks, contractual commitments and recovery objectives. A backup product may be appropriate, but it should be selected after understanding what needs to be restored and how quickly.
Backup strategies must align with your Microsoft 365 security settings to ensure resiliency.
The NCSC’s small organisations guide to cyber security also recommends taking practical steps around backups, accounts, devices and incident recovery.
How should you use this Microsoft 365 security checklist?
Do not try to change everything at once. Use a staged review:
- Document your current setup. Record licences, administrators, devices, integrations and external sharing.
- Fix high-risk gaps first. Prioritise MFA, administrator accounts, legacy authentication and external forwarding.
- Test before enforcing. Use pilot users or report-only policies where available.
- Communicate changes clearly. Explain what staff will see and what they should do if access is blocked.
- Review regularly. Recheck settings after staff changes, new applications, acquisitions or major projects.
- Monitor continuously. Security settings are valuable, but alerts and response processes turn them into protection.
Why aim for failproof cybersecurity? No environment is completely risk-free. The practical goal is to make compromise harder, detect unusual activity earlier and recover with less disruption.
Need help reviewing Microsoft 365 security settings?
Microsoft 365 is powerful, but its security settings can be spread across several administration centres. A small configuration gap may remain hidden until an attacker finds it. If you are unsure whether your Microsoft 365 security settings are doing what you expect, an independent review can quickly highlight the most important priorities.
Consider how your Microsoft 365 security settings can be optimised with expert reviews.
BITSmart Technology Ltd provides proactive IT support in Hampshire, including Microsoft 365 configuration, monitoring, cybersecurity and user support. We work with businesses across Winchester and the wider county, explaining technical decisions in plain English and helping you improve security without creating unnecessary friction for your team.
If you would like a second pair of eyes on your tenant, Book a Call with BITSmart. We can help you understand your current position, identify practical priorities and create a review plan suited to your business.
Contact us to help you evaluate your Microsoft 365 security settings for potential improvements.




