Skip to content
Cloud & Microsoft 365

Securing Microsoft 365: the 10 settings to get right

MFA, Conditional Access, legacy auth, admin accounts, external forwarding, Defender, SPF, DKIM, DMARC, sharing, audit, backup: the SMB checklist.

By the ALLSAFE SOLUTIONS engineering team30 September 20267 min read
Data centre aisle hosting cloud servers

Your company has moved its email to Microsoft 365, files live in OneDrive and SharePoint, meetings in Teams. But a freshly created tenant is not configured to the security level a business needs, and most of the Microsoft 365 incidents we handle do not come from a Microsoft flaw: they come from a setting that was never made. An account taken over by phishing, a forwarding rule planted by the attacker, a fake invoice sent from the accountant’s real mailbox. The short answer: ten settings cover the essentials, and most require no extra licence. Here they are, in what order, and how to apply them without blocking your teams.

The 10 settings at a glance

No. Setting Where Licence required Priority
1 MFA for all users Entra ID All Immediate
2 Security defaults or Conditional Access Entra ID All / Entra ID P1 Immediate
3 Legacy authentication blocked Entra ID, Exchange All Immediate
4 Separate admin accounts and emergency accounts Entra ID All Immediate
5 External automatic forwarding blocked Defender, Exchange All Quick
6 Defender for Office 365: attachments and links Defender Business Premium or add-on Quick
7 SPF, DKIM and DMARC DNS, Defender All Quick
8 SharePoint and OneDrive sharing policy SharePoint All Planned
9 Audit log enabled and reviewed Purview All Planned
10 External tenant backup Third-party solution Separate service Planned

1. MFA for everyone, no exceptions

A password alone no longer protects a mailbox. Multi-factor authentication must cover every account, administrators first, using the Microsoft Authenticator app rather than SMS. Roll it out in waves, with user support: our MFA rollout guide details the method.

2. Security defaults or Conditional Access

Microsoft offers two mechanisms that cannot be active at the same time. Security defaults are free and enforce a baseline: MFA, legacy authentication blocked, protection of admin actions. Conditional Access, available with Entra ID P1 (included in Business Premium), lets you fine-tune: require a compliant device to reach data, block certain countries, tighten control for administrators. Without P1, at least turn on security defaults. To choose licences, see Business Basic, Standard or Premium.

3. Block legacy authentication

Old protocols (POP, IMAP, authenticated SMTP, older Outlook clients) cannot handle MFA: attackers use them to bypass the second factor. Microsoft has turned off basic authentication for most Exchange Online protocols, but exceptions still need checking: a copier that emails scans over SMTP, an old line-of-business application. Identify them in the sign-in logs, find an alternative, then block the rest with a Conditional Access policy or security defaults.

4. Separate admin accounts, plus emergency accounts

The global administrator should not read their email with the same account. Create dedicated admin accounts without a mailbox, keep the number of global administrators to the strict minimum, and assign narrower roles (Exchange administrator, user administrator) when they are enough. Also set up two emergency “break-glass” accounts: they let you regain control if Conditional Access or the MFA provider locks everyone out. They are protected by a strong method, such as a FIDO2 key kept in a safe place, excluded from rules that could block them, and every sign-in triggers an alert.

5. Block automatic forwarding to external addresses

This is the most discreet technique after a compromise: a mailbox rule that forwards everything to an external address. In Microsoft Defender’s outbound anti-spam policy, turn off external automatic forwarding, then create justified, documented exceptions. Also review existing mailbox rules: an unknown rule that moves or deletes messages is a warning sign. The fraud scenarios that follow are described in the 8 phishing scams targeting SMBs in Morocco.

6. Turn on Defender for Office 365

Every plan includes basic filtering (Exchange Online Protection). Defender for Office 365, included in Business Premium or available as an add-on, adds detonation of attachments in an isolated environment (Safe Attachments) and time-of-click link checking (Safe Links), plus stronger impersonation protection. The simplest approach is to apply Microsoft’s preset policies, standard for everyone and strict for management and accounting, then adjust.

7. SPF, DKIM and DMARC

These three DNS records prove that messages sent in your name really come from you. SPF lists the servers allowed to send, DKIM signs each message, DMARC says what to do with messages that fail. Start DMARC in monitoring mode (p=none) with reports, list every service that sends on your behalf (website, invoicing software, mailing tool), then move gradually to quarantine and then reject. Without this, anyone can send a fake invoice using your domain name.

8. Control SharePoint and OneDrive sharing

By default, users can often share files externally through links open to anyone who has them. Choose a suitable level: sharing limited to identified guests, “anyone” links disabled or given an expiry date, default link restricted to people in the organisation. For sensitive sites (finance, HR), restrict further.

9. Enable and review the audit log

The unified audit log records sign-ins, rule creation, sharing and permission changes. Check that it is enabled on your tenant and, above all, review it: alerts on sign-ins from unusual countries, on forwarding rule creation and on new administrators. Microsoft Secure Score, in the Defender portal, also gives a list of recommendations and lets you track progress.

10. Back up the tenant outside Microsoft

Microsoft ensures service availability, not the protection of your data against deletion, ransomware or a contentious departure. The recycle bin and retention periods do not replace a backup. A third-party solution that copies Exchange, OneDrive, SharePoint and Teams outside the tenant, with regular restore tests, completes the setup. Details are in Microsoft 365 backup and shared responsibility.

The most common mistakes

  • A single global administrator, who is also the managing director’s email account.
  • “Temporary” MFA exceptions that become permanent.
  • DMARC published at p=none and never tightened, or not published at all.
  • No emergency account, and a locked tenant the day MFA misbehaves.
  • Business Premium licences paid for without Conditional Access or Defender being configured.
  • An audit log nobody reads.

Microsoft 365 checklist

  • MFA active on every account, report of accounts without MFA checked monthly.
  • Security defaults or Conditional Access in place.
  • Legacy authentication blocked, exceptions identified and documented.
  • Dedicated admin accounts, two emergency accounts tested.
  • External automatic forwarding blocked, mailbox rules reviewed.
  • Defender policies applied where the licence allows.
  • SPF, DKIM and DMARC published, DMARC being tightened.
  • External sharing limited, open links expiring or disabled.
  • Audit log active and alerts configured.
  • External tenant backup, restore tested.

How we do it

We start with a tenant audit: accounts and roles, MFA status, access rules, legacy protocols, email, sharing, logs and Secure Score. We then apply the settings in order of priority, warning users before every visible change and testing exceptions (copiers, business applications) before blocking. Once in place, the tenant is looked after as part of our managed cloud Microsoft 365 and Azure offering, with 24/7 monitoring of alerts and critical incidents handled in under 15 minutes. Learn more about our Microsoft partnership and our case studies. To take the approach further, see Zero Trust for SMBs: where to start.

Take action

Not sure how many of these ten settings are in place on your tenant? The initial audit is free and gives you a clear answer, setting by setting. Contact us: we reply within 24 business hours.

Frequently asked questions

Are security defaults enough for an SMB?

They are a good baseline, free and available on every plan: MFA for everyone, legacy authentication blocked, stronger protection for administrators. But they allow no nuance. Once you have Entra ID P1, included in Business Premium, Conditional Access gives finer control. The two cannot be active at the same time.

Why block automatic forwarding to external addresses?

After taking over a mailbox, an attacker often creates a rule that quietly forwards every message to an external address. They keep reading the conversation, even after a password change. Blocking this forwarding by default, with justified exceptions, shuts down the technique.

Does Microsoft back up my Microsoft 365 data?

Microsoft ensures service availability and keeps deleted items for a limited time, but protecting your data against deletion, ransomware or error remains your responsibility. A third-party backup stored outside the tenant is recommended.

Do I need Business Premium to apply these settings?

No, most apply on every plan: MFA, forwarding block, SPF, DKIM, DMARC, sharing, audit. Business Premium adds Conditional Access, Defender for Office 365 and Intune, which make protection finer-grained. A per-user mix of licences is often the right compromise.

About the editorial team

ALLSAFE SOLUTIONS

Network, security and cloud engineers

Written by the engineering team at ALLSAFE SOLUTIONS, a managed IT provider founded in Casablanca by network, security and cloud engineers. Our articles draw on the projects we deliver for clients in Morocco and abroad.

LinkedIn
← All articles
CallWhatsAppFree audit