Securing Microsoft 365: the 10 settings to get right
MFA, Conditional Access, legacy auth, admin accounts, external forwarding, Defender, SPF, DKIM, DMARC, sharing, audit, backup: the SMB checklist.

Your company has moved its email to Microsoft 365, files live in OneDrive and SharePoint, meetings in Teams. But a freshly created tenant is not configured to the security level a business needs, and most of the Microsoft 365 incidents we handle do not come from a Microsoft flaw: they come from a setting that was never made. An account taken over by phishing, a forwarding rule planted by the attacker, a fake invoice sent from the accountant’s real mailbox. The short answer: ten settings cover the essentials, and most require no extra licence. Here they are, in what order, and how to apply them without blocking your teams.
The 10 settings at a glance
| No. | Setting | Where | Licence required | Priority |
|---|---|---|---|---|
| 1 | MFA for all users | Entra ID | All | Immediate |
| 2 | Security defaults or Conditional Access | Entra ID | All / Entra ID P1 | Immediate |
| 3 | Legacy authentication blocked | Entra ID, Exchange | All | Immediate |
| 4 | Separate admin accounts and emergency accounts | Entra ID | All | Immediate |
| 5 | External automatic forwarding blocked | Defender, Exchange | All | Quick |
| 6 | Defender for Office 365: attachments and links | Defender | Business Premium or add-on | Quick |
| 7 | SPF, DKIM and DMARC | DNS, Defender | All | Quick |
| 8 | SharePoint and OneDrive sharing policy | SharePoint | All | Planned |
| 9 | Audit log enabled and reviewed | Purview | All | Planned |
| 10 | External tenant backup | Third-party solution | Separate service | Planned |
1. MFA for everyone, no exceptions
A password alone no longer protects a mailbox. Multi-factor authentication must cover every account, administrators first, using the Microsoft Authenticator app rather than SMS. Roll it out in waves, with user support: our MFA rollout guide details the method.
2. Security defaults or Conditional Access
Microsoft offers two mechanisms that cannot be active at the same time. Security defaults are free and enforce a baseline: MFA, legacy authentication blocked, protection of admin actions. Conditional Access, available with Entra ID P1 (included in Business Premium), lets you fine-tune: require a compliant device to reach data, block certain countries, tighten control for administrators. Without P1, at least turn on security defaults. To choose licences, see Business Basic, Standard or Premium.
3. Block legacy authentication
Old protocols (POP, IMAP, authenticated SMTP, older Outlook clients) cannot handle MFA: attackers use them to bypass the second factor. Microsoft has turned off basic authentication for most Exchange Online protocols, but exceptions still need checking: a copier that emails scans over SMTP, an old line-of-business application. Identify them in the sign-in logs, find an alternative, then block the rest with a Conditional Access policy or security defaults.
4. Separate admin accounts, plus emergency accounts
The global administrator should not read their email with the same account. Create dedicated admin accounts without a mailbox, keep the number of global administrators to the strict minimum, and assign narrower roles (Exchange administrator, user administrator) when they are enough. Also set up two emergency “break-glass” accounts: they let you regain control if Conditional Access or the MFA provider locks everyone out. They are protected by a strong method, such as a FIDO2 key kept in a safe place, excluded from rules that could block them, and every sign-in triggers an alert.
5. Block automatic forwarding to external addresses
This is the most discreet technique after a compromise: a mailbox rule that forwards everything to an external address. In Microsoft Defender’s outbound anti-spam policy, turn off external automatic forwarding, then create justified, documented exceptions. Also review existing mailbox rules: an unknown rule that moves or deletes messages is a warning sign. The fraud scenarios that follow are described in the 8 phishing scams targeting SMBs in Morocco.
6. Turn on Defender for Office 365
Every plan includes basic filtering (Exchange Online Protection). Defender for Office 365, included in Business Premium or available as an add-on, adds detonation of attachments in an isolated environment (Safe Attachments) and time-of-click link checking (Safe Links), plus stronger impersonation protection. The simplest approach is to apply Microsoft’s preset policies, standard for everyone and strict for management and accounting, then adjust.
7. SPF, DKIM and DMARC
These three DNS records prove that messages sent in your name really come from you. SPF lists the servers allowed to send, DKIM signs each message, DMARC says what to do with messages that fail. Start DMARC in monitoring mode (p=none) with reports, list every service that sends on your behalf (website, invoicing software, mailing tool), then move gradually to quarantine and then reject. Without this, anyone can send a fake invoice using your domain name.
8. Control SharePoint and OneDrive sharing
By default, users can often share files externally through links open to anyone who has them. Choose a suitable level: sharing limited to identified guests, “anyone” links disabled or given an expiry date, default link restricted to people in the organisation. For sensitive sites (finance, HR), restrict further.
9. Enable and review the audit log
The unified audit log records sign-ins, rule creation, sharing and permission changes. Check that it is enabled on your tenant and, above all, review it: alerts on sign-ins from unusual countries, on forwarding rule creation and on new administrators. Microsoft Secure Score, in the Defender portal, also gives a list of recommendations and lets you track progress.
10. Back up the tenant outside Microsoft
Microsoft ensures service availability, not the protection of your data against deletion, ransomware or a contentious departure. The recycle bin and retention periods do not replace a backup. A third-party solution that copies Exchange, OneDrive, SharePoint and Teams outside the tenant, with regular restore tests, completes the setup. Details are in Microsoft 365 backup and shared responsibility.
The most common mistakes
- A single global administrator, who is also the managing director’s email account.
- “Temporary” MFA exceptions that become permanent.
- DMARC published at
p=noneand never tightened, or not published at all. - No emergency account, and a locked tenant the day MFA misbehaves.
- Business Premium licences paid for without Conditional Access or Defender being configured.
- An audit log nobody reads.
Microsoft 365 checklist
- MFA active on every account, report of accounts without MFA checked monthly.
- Security defaults or Conditional Access in place.
- Legacy authentication blocked, exceptions identified and documented.
- Dedicated admin accounts, two emergency accounts tested.
- External automatic forwarding blocked, mailbox rules reviewed.
- Defender policies applied where the licence allows.
- SPF, DKIM and DMARC published, DMARC being tightened.
- External sharing limited, open links expiring or disabled.
- Audit log active and alerts configured.
- External tenant backup, restore tested.
How we do it
We start with a tenant audit: accounts and roles, MFA status, access rules, legacy protocols, email, sharing, logs and Secure Score. We then apply the settings in order of priority, warning users before every visible change and testing exceptions (copiers, business applications) before blocking. Once in place, the tenant is looked after as part of our managed cloud Microsoft 365 and Azure offering, with 24/7 monitoring of alerts and critical incidents handled in under 15 minutes. Learn more about our Microsoft partnership and our case studies. To take the approach further, see Zero Trust for SMBs: where to start.
Take action
Not sure how many of these ten settings are in place on your tenant? The initial audit is free and gives you a clear answer, setting by setting. Contact us: we reply within 24 business hours.
Frequently asked questions
Are security defaults enough for an SMB?
They are a good baseline, free and available on every plan: MFA for everyone, legacy authentication blocked, stronger protection for administrators. But they allow no nuance. Once you have Entra ID P1, included in Business Premium, Conditional Access gives finer control. The two cannot be active at the same time.
Why block automatic forwarding to external addresses?
After taking over a mailbox, an attacker often creates a rule that quietly forwards every message to an external address. They keep reading the conversation, even after a password change. Blocking this forwarding by default, with justified exceptions, shuts down the technique.
Does Microsoft back up my Microsoft 365 data?
Microsoft ensures service availability and keeps deleted items for a limited time, but protecting your data against deletion, ransomware or error remains your responsibility. A third-party backup stored outside the tenant is recommended.
Do I need Business Premium to apply these settings?
No, most apply on every plan: MFA, forwarding block, SPF, DKIM, DMARC, sharing, audit. Business Premium adds Conditional Access, Defender for Office 365 and Intune, which make protection finer-grained. A per-user mix of licences is often the right compromise.
About the editorial team
ALLSAFE SOLUTIONS
Network, security and cloud engineers
Written by the engineering team at ALLSAFE SOLUTIONS, a managed IT provider founded in Casablanca by network, security and cloud engineers. Our articles draw on the projects we deliver for clients in Morocco and abroad.
LinkedIn









































