Microsoft 365 Security: The Settings Every Business Should Review

Microsoft 365 security depends heavily on how the environment is configured. The platform includes strong security controls, but businesses still need to review authentication, administrator access, email protection, file sharing and monitoring.

The exact options available depend on your Microsoft 365 licence. However, every organisation should understand the following settings and confirm who is responsible for managing them.

Microsoft 365 security settings at a glance

  1. Require multi-factor authentication
  2. Protect administrator accounts
  3. Review Security Defaults or Conditional Access
  4. Remove unused accounts and licences
  5. Configure email authentication and anti-phishing protection
  6. Control external forwarding and mailbox rules
  7. Review SharePoint and OneDrive sharing
  8. Control third-party applications and permissions
  9. Monitor sign-ins, alerts and audit activity
  10. Plan for backup, retention and account recovery

1. Require multi-factor authentication

Multi-factor authentication, commonly known as MFA, requires users to provide an additional method of verification alongside their password.

This means that a stolen password alone should not be enough to access the account.

MFA should be required for:

  • All normal user accounts
  • Global administrators and other privileged accounts
  • External administrators and IT suppliers
  • Remote access to company systems
  • Accounts accessing sensitive business information

Microsoft recommends using Security Defaults or Conditional Access to enforce MFA rather than relying on the older per-user MFA configuration.

Where possible, businesses should use stronger authentication methods such as Microsoft Authenticator, passkeys or security keys rather than depending entirely on text messages.

Read Microsoft’s guidance on setting up multi-factor authentication.

2. Protect administrator accounts

Administrator accounts can change security settings, create users, access data and grant permissions. They therefore need stronger protection than ordinary employee accounts.

Everyday user accounts should not have administrator access simply for convenience.

A safer arrangement includes:

  • Separate administrator and everyday accounts
  • MFA on every privileged account
  • The minimum level of permission required for each task
  • No shared administrator usernames
  • Regular reviews of who holds administrative roles
  • Alerts for important administrator changes

Microsoft 365 contains several specialised administrator roles. For example, somebody responsible for user accounts may not need the unrestricted access provided by the Global Administrator role.

The organisation should also maintain an emergency access procedure in case normal administrator accounts become unavailable. Emergency accounts must be carefully protected, monitored and tested rather than used for ordinary administration.

3. Review Security Defaults or Conditional Access

Security Defaults provides a basic collection of identity protections for Microsoft 365 environments. It is designed to give organisations a straightforward security baseline without requiring individually constructed access policies.

Conditional Access provides more granular control. It can apply different requirements according to the user, device, application, location or level of risk.

Conditional Access can be used to:

  • Require MFA for specific users or circumstances
  • Block access from unsupported or non-compliant devices
  • Apply stricter controls to administrator accounts
  • Restrict access from particular countries or locations
  • Control access to sensitive applications
  • Require stronger authentication for higher-risk activity

Security Defaults and Conditional Access are different approaches and should not simply be enabled together without planning. Conditional Access also requires suitable Microsoft licensing.

Policies should be tested carefully before being enforced across the entire organisation. A badly designed policy can lock out legitimate employees or administrators.

4. Remove unused accounts and licences

Unused accounts are often overlooked after employees, contractors or suppliers leave the business.

An account that is no longer needed should not remain active merely because nobody has requested its removal.

A documented offboarding process should include:

  • Blocking the user from signing in
  • Revoking active sessions
  • Resetting or removing authentication methods
  • Transferring ownership of business files
  • Preserving or redirecting important email where appropriate
  • Removing access to Teams, SharePoint and shared mailboxes
  • Removing unnecessary licences
  • Recovering company-owned devices

The business should periodically review inactive accounts, guests, external users and accounts without a clear owner.

Unused accounts create security risk and may also result in unnecessary licensing costs.

5. Configure email authentication and anti-phishing protection

Microsoft 365 email should be supported by properly configured sender-authentication records.

The principal controls are:

  • SPF, which identifies systems authorised to send email for the domain
  • DKIM, which adds a digital signature to outgoing messages
  • DMARC, which checks alignment and tells receiving systems how failed messages should be handled

These controls work together. Having an SPF record alone does not provide the same protection as a properly planned SPF, DKIM and DMARC configuration.

Businesses should also review:

  • Anti-phishing policies
  • Impersonation protection for senior employees and important domains
  • Spam and malware filtering
  • Warnings for external messages
  • Safe Links and Safe Attachments where licensed
  • Procedures for verifying payment and bank-detail changes

Microsoft explains how the three main controls work in its guide to email authentication in Microsoft 365.

6. Control external forwarding and mailbox rules

Attackers who gain access to an email account sometimes create forwarding or inbox rules that silently send business messages elsewhere.

This can allow them to monitor conversations, hide security warnings or intercept correspondence relating to invoices and payments.

Businesses should review:

  • Whether automatic forwarding to external addresses is permitted
  • Existing forwarding addresses
  • Suspicious inbox and deletion rules
  • Alerts relating to unusual forwarding activity
  • Shared mailbox permissions and delegates

External forwarding may have legitimate uses, but it should be explicitly approved rather than available to every employee by default.

Unexpected forwarding rules should be investigated alongside the user’s sign-in activity, authentication methods and other account changes.

7. Review SharePoint and OneDrive external sharing

SharePoint and OneDrive make it easy to collaborate with customers, suppliers and other external users. Without suitable controls, they can also make information easier to share more widely than intended.

Review the organisation-wide sharing level and the settings applied to individual SharePoint sites.

Questions to consider include:

  • Are anonymous “Anyone” links permitted?
  • Do shared links expire automatically?
  • Can employees share folders with external users without approval?
  • Are confidential files stored in sites where external sharing is disabled?
  • How frequently are guest users reviewed?
  • Can externally shared information be downloaded?
  • Who owns each SharePoint site and reviews its membership?

Microsoft recommends storing confidential information in sites where external sharing is disabled and using separate sites where external collaboration is required.

The correct level of restriction will depend on how the business works. The goal is controlled collaboration, rather than preventing legitimate sharing entirely.

8. Control third-party applications and permissions

Employees may connect third-party applications to their Microsoft 365 accounts for file storage, scheduling, email management, automation and other business functions.

Some applications request permission to read email, access files, maintain access when the user is offline or act on the user’s behalf.

The organisation should understand:

  • Whether users can approve applications themselves
  • Which applications already have access
  • What data each application can read or modify
  • Who owns and supports the connected application
  • Whether the application is still required
  • How access will be removed if the supplier or employee relationship ends

High-risk permission requests should require administrator review. Applications that are unused, unrecognised or unsupported should have their permissions removed.

9. Monitor sign-ins, alerts and audit activity

Security settings are more effective when somebody monitors the resulting alerts and investigates unusual activity.

Depending on licensing, Microsoft 365 can provide information about:

  • Successful and failed sign-ins
  • Unusual locations and devices
  • Changes to administrator roles
  • Mailbox rules and forwarding
  • File access and sharing activity
  • Security-policy changes
  • Suspicious email and malware detections

The Microsoft Purview audit log can support investigations into compromised accounts, mailbox activity and configuration changes.

However, collecting audit information is not the same as monitoring it. The business should know who receives security alerts, how quickly they are reviewed and what happens when suspicious activity is confirmed.

10. Plan for backup, retention and account recovery

Microsoft 365 contains retention and recovery capabilities, but these should not be confused with a complete business backup and continuity strategy.

Review how the organisation would recover following:

  • Accidental deletion
  • A compromised administrator account
  • Malicious or mass file deletion
  • Ransomware synchronising encrypted files
  • An employee deliberately removing information
  • A retention or configuration mistake

Confirm:

  • Which mailboxes, SharePoint sites, Teams and OneDrive accounts are protected
  • How frequently separate backups run
  • How long backup copies are retained
  • Whether backup administration is separated from Microsoft 365 administration
  • Who monitors failed backups
  • How restoration is tested

The business should also document how administrator access will be recovered if the normal account or authentication device becomes unavailable.

What should businesses prioritise first?

Where Microsoft 365 has not previously received a structured security review, begin with these actions:

  1. Require MFA for every user and administrator
  2. Remove unnecessary Global Administrators
  3. Disable or secure unused accounts
  4. Review external email forwarding
  5. Configure SPF, DKIM and DMARC
  6. Review SharePoint and OneDrive external sharing
  7. Confirm who monitors alerts and audit activity
  8. Test how important Microsoft 365 information would be restored

These measures provide a strong starting point while the remaining settings and licensing requirements are reviewed.

How often should Microsoft 365 security be reviewed?

Microsoft 365 should be reviewed regularly rather than configured once and then left indefinitely.

A review should also take place following:

  • A suspected or confirmed security incident
  • A significant increase in staff numbers
  • A company acquisition or restructuring
  • A change of IT provider
  • The introduction of new applications or suppliers
  • A change to remote or hybrid working arrangements
  • A Microsoft licensing change

Administrator roles, inactive accounts, guest users, connected applications and external sharing should all be reviewed as part of ongoing management.

How Secure IT can help

Secure IT helps businesses administer Microsoft 365, manage users and licences, strengthen account security, protect email and monitor the wider technology environment.

A review can identify where important settings have been left at unsuitable defaults, where permissions have accumulated and where additional protection may be required.

For a broader explanation of ongoing support, read our guide to what managed IT support includes.

Contact the Secure IT team to discuss Microsoft 365 administration, security or support for your business.

Frequently asked questions

Is Microsoft 365 secure by default?

Microsoft 365 provides extensive security capabilities, but the protection a business receives depends on its licence, configuration and ongoing management. Settings such as MFA, administrator roles, file sharing and email authentication still need to be reviewed.

Should every Microsoft 365 user have MFA?

Yes. MFA should be required for ordinary users as well as administrators. Stronger, phishing-resistant authentication methods should be used where practical.

What is the difference between Security Defaults and Conditional Access?

Security Defaults provides a straightforward baseline of identity protection. Conditional Access allows more detailed policies according to factors such as user, device, application, location and risk, but requires suitable licensing and careful configuration.

How many Global Administrators should a business have?

There should be enough properly protected administrator access to avoid dependence on one person, but Global Administrator rights should remain tightly limited. Other administrative work should use less powerful roles wherever possible.

Does Microsoft 365 include backup?

Microsoft 365 includes retention and recovery features, but these may not satisfy every organisation’s backup, retention and recovery requirements. Businesses should assess whether they need a separately managed Microsoft 365 backup service.

Microsoft 365 security requires ongoing management

Microsoft 365 can provide a strong and secure platform for business communication and collaboration, but only when the environment is configured and monitored appropriately.

Start with identity protection, administrator access and email security. Then review file sharing, third-party applications, monitoring and recovery arrangements so that responsibility for each control is clear.

Share this guide

Looking for a better way to manage your IT?

Whether you need day-to-day IT support, stronger cyber security or help with a specific project, tell us what you’re looking to improve. We’ll arrange a straightforward conversation with the right person.