Skip to main content
Dig IT Solutions logo

Microsoft 365 & Cloud

Microsoft 365 security settings checklist: 14 settings to check before an attacker does

A numbered Microsoft 365 security checklist for UK SMEs: MFA, legacy authentication, admin accounts, Conditional Access, SPF, DKIM, DMARC, audit logs, Intune.

By Dig IT SolutionsUpdated 8 September 202610 min read

Short answer

Start with the settings attackers exploit most: enforce MFA for every user, block legacy authentication, separate and protect admin accounts, restrict external sharing and automatic forwarding, and confirm audit logging is on. Then use Secure Score, Conditional Access, SPF, DKIM and DMARC, alert policies and Intune device compliance to close the remaining gaps.

Most Microsoft 365 tenants we review were set up correctly for the day they went live and never touched again. The mailboxes migrated, the licences were assigned and the security portals were left on their defaults. This checklist is the list an engineer works through on a tenant they have just inherited, in the order that removes the most risk soonest.

Why the defaults are not enough

Microsoft has to ship settings that work for a two-person consultancy, a school and a global manufacturer at the same time, so it leaves a lot permissive and lets each organisation tighten things to suit its own risk. Some protections are on by default for new tenants, including security defaults, mailbox auditing and the blocking of automatic forwarding. Older tenants, and any tenant where an admin switched something off to make a printer work, cannot be assumed to have them.

The GOV.UK Cyber Security Breaches Survey consistently reports phishing as the most common attack UK businesses experience, and a compromised Microsoft 365 account is the usual outcome. Almost every item below either makes that compromise harder or makes it visible sooner.

The checklist at a glance

#SettingWhere to find itWhy it matters
1MFA for every userEntra admin centre, Protection, Authentication methodsStops most password-based account takeovers
2Block legacy authenticationEntra sign-in logs, Conditional Access, Exchange admin centreOld protocols bypass MFA entirely
3Security defaults or Conditional AccessEntra admin centre, Identity, Overview, PropertiesYou need one of the two, never neither
4Conditional Access policiesEntra admin centre, Protection, Conditional AccessApplies MFA and device rules based on risk rather than blanket prompts
5Dedicated, protected admin accountsEntra admin centre, Roles and administratorsA compromised global admin owns the whole tenant
6Microsoft Secure ScoreMicrosoft Defender portal, Secure ScoreA prioritised list of what is still wrong
7SPF, DKIM and DMARCDNS at your registrar, Defender portal email authentication settingsStops criminals sending mail as your domain
8External sharing limitsSharePoint admin centre, Policies, SharingAnonymous links leak data silently
9Automatic forwarding and inbox rulesDefender portal outbound spam policy, Exchange admin centreAttackers forward your mail to themselves
10Unified audit log and mailbox auditingMicrosoft Purview portal, AuditWithout it you cannot investigate an incident
11Alert policiesDefender portal, Policies and rules, Alert policyTurns suspicious events into notifications someone sees
12Defender for Office 365 preset policiesDefender portal, Threat policies, Preset security policiesSafe Links, Safe Attachments and impersonation protection
13Device compliance via IntuneIntune admin centre, Devices, Compliance policiesOnly healthy, encrypted devices reach company data
14Leavers, inactive accounts and permissionsEntra admin centre, UsersForgotten accounts are the easiest way in

Microsoft Learn is the authority for the current path.

The checklist in detail

1. Multi-factor authentication for every user

MFA is the single most effective control, and the one most often only half done. The common failure is enforcing it for admins and a few senior staff while ordinary users can still sign in with a password.

Enforce MFA for all users with no exceptions for "trusted" locations. Prefer the Microsoft Authenticator app with number matching, or passkeys, over SMS. Check that everyone has actually registered: a user with MFA required but no method registered is still a password-only account until their next sign-in. Pair MFA with a sensible password policy, which under NCSC guidance means long, unique passwords, a password manager and no forced periodic changes. Read what is multi-factor authentication if you need to explain it to staff.

2. Block legacy authentication

Legacy protocols such as POP, IMAP and older SMTP authentication were designed before MFA existed and do not support it. A tenant that allows them has a side door that ignores everything you did in step 1. Microsoft has retired basic authentication for most Exchange Online protocols, but SMTP AUTH can still be enabled per mailbox, and older tenants may carry exceptions.

Filter the Entra sign-in logs by client app to see what is still using legacy authentication, then block it with a Conditional Access policy (or leave security defaults on, which blocks it too). The usual holdouts are multifunction printers, scan-to-email devices and old line-of-business applications. Move them to a dedicated relay or modern authentication rather than leaving the door open for everyone.

3. Security defaults or Conditional Access, never neither

Security defaults are a free, one-switch baseline: MFA for all users, legacy authentication blocked, extra protection for admin actions. They are the right answer for a tenant on Business Basic or Standard, and Microsoft documents them at Microsoft Learn.

Conditional Access is the flexible version. It needs Entra ID P1, which is included in Business Premium. The two cannot run together, so a tenant moving to Conditional Access must build the equivalent policies before switching security defaults off. Tenants where an admin disabled security defaults to fix a compatibility problem and never built Conditional Access are common and completely exposed.

4. Conditional Access policies

Conditional Access evaluates each sign-in against who the user is, what device they are on, where they are and what they are trying to reach, then requires MFA, blocks, or allows. A sensible starter set for an SME:

  • Require MFA for all users on all cloud apps.
  • Block legacy authentication.
  • Require MFA on every sign-in for admin roles.
  • Block sign-ins from countries the business never operates in.
  • Require a compliant or hybrid-joined device for access to SharePoint and Exchange.

Build each policy in report-only mode first, review the sign-in log impact for a week, then enforce. Our guide to Conditional Access explained walks through the policies in detail.

5. Dedicated, protected admin accounts

Global admin is the key to everything: it can disable security controls, create users, read any mailbox and remove retention on data held in the tenant. Microsoft recommends fewer than five global admins and that they use separate, cloud-only accounts with no mailbox and no daily use. The person who administers the tenant should have an ordinary account for email and a separate admin account for admin work.

Give lesser roles where they fit (Exchange administrator, User administrator, Helpdesk administrator) rather than global admin for convenience. Create one emergency access account with a long random password stored offline, excluded from Conditional Access and monitored for any sign-in.

6. Microsoft Secure Score

Secure Score, in the Microsoft Defender portal, compares your tenant against Microsoft's recommended configuration and produces a percentage with a prioritised list of actions. It is not a compliance certificate and a high score does not mean you are safe, but it is the fastest way to see what has been missed and to track progress month on month.

Work through the identity and apps recommendations first.

7. SPF, DKIM and DMARC

These three DNS records tell the world which servers may send email as your domain and what to do with mail that fails the check. Without them, anyone can send invoices as your finance team and the recipient's mail system has no way to tell.

SPF and DMARC are records at your domain registrar or DNS host. DKIM for a custom domain is switched on in the Defender portal under email authentication settings, which gives you two CNAME records to publish. Start DMARC at p=none with reporting, review the reports for a few weeks to catch legitimate third-party senders (accounting software, CRM, newsletter tools), then move to quarantine and finally reject. Our email security service covers this along with filtering and impersonation protection.

8. External sharing limits

SharePoint and OneDrive can allow "Anyone" links, which need no sign-in and can be forwarded indefinitely. In the SharePoint admin centre, set the organisation-wide level to "New and existing guests" so external people must authenticate, set anonymous links to expire if you keep them at all, default new links to "specific people", and restrict who can invite guests.

9. Automatic forwarding and inbox rules

The first thing an attacker does with a compromised mailbox is create a rule that forwards or redirects mail to an external address, often hiding copies in an RSS or Archive folder. They then sit and read, waiting for an invoice to alter. Set the outbound spam policy in the Defender portal so automatic forwarding to external addresses is off, and allow exceptions per mailbox only where a real business need exists. Periodically list inbox rules across all mailboxes with PowerShell and query any that forward, redirect or delete.

10. Unified audit log and mailbox auditing

The unified audit log records user and admin activity across Exchange, SharePoint, OneDrive, Teams and Entra. Mailbox auditing records who accessed a mailbox and what they did. Both are on by default for most current tenants, but verify in the Microsoft Purview portal because a tenant created years ago, or one where auditing was switched off, will have gaps.

Retention on the standard audit tier is 180 days at the time of writing, with longer retention needing higher-tier licensing or an add-on. If a compromise is discovered six months after it began, the early evidence is already gone. For businesses with regulatory obligations, export the log periodically or feed it to a monitoring platform.

11. Alert policies

Logging is only useful if someone is told. Microsoft provides default alert policies for events such as a forwarding rule being created, suspicious sending patterns, a user being granted an admin role and malware being detected. Confirm they are enabled, confirm they send to a monitored mailbox rather than the mailbox of someone who left, and add custom alerts for impossible travel sign-ins and mass file downloads if your licence supports them. Test one: create a forwarding rule on a test mailbox and check the alert arrives.

12. Defender for Office 365 preset policies

Business Premium includes Defender for Office 365 Plan 1, which adds Safe Links (URL rewriting and time-of-click checking), Safe Attachments (opening attachments in a sandbox before delivery) and anti-phishing impersonation protection. Many tenants that pay for it have never applied it. In the Defender portal, apply the Standard preset security policy to all users, then add the names of your directors and finance staff to the impersonation protection list so a lookalike sender is flagged. Defender for Business, also in Premium, covers endpoints and should be deployed alongside your endpoint detection and response.

13. Device compliance via Intune

Remote working means company mail and files on laptops and phones you may never have seen. Intune, included in Business Premium, lets you define what a healthy device looks like: BitLocker encryption on, a minimum operating system version, Defender antivirus active, a PIN or password on mobiles. A Conditional Access policy then requires devices to be compliant before they can reach SharePoint or Exchange. Start with company-owned Windows laptops, then bring in mobiles with app protection policies so personal phones can read email without the business owning the device.

14. Leavers, inactive accounts and permissions

Every leaver should trigger the same steps on the day they go: block sign-in, revoke sessions, remove MFA devices, convert the mailbox to shared or apply retention, transfer OneDrive ownership, remove licences. Accounts that stay active for months after someone leaves are a standing invitation. Run a quarterly review of users with no sign-in in 60 days and of who holds owner rights on SharePoint sites and Teams. Our onboarding and offboarding process turns this into a standard form rather than a memory test.

Backup, and reviewing this regularly

None of the above brings deleted or encrypted data back. Microsoft's retention windows and recycle bins are not a backup, and the platform does not protect you from ransomware that encrypts files through a synced OneDrive or an admin error that purges a mailbox. Independent Microsoft 365 backup belongs alongside this checklist, and does Microsoft 365 include backup explains why.

Treat the checklist as a cycle rather than a project. A tenant review at least annually, with Secure Score checked monthly, is a reasonable rhythm for most SMEs. Our Microsoft 365 security service does exactly this on a schedule.

What to do next

If you cannot say with confidence that every item above is in place, the honest next step is to check rather than assume. An IT health check reviews your tenant against this list, reports what is exposed in plain English, and gives you a prioritised fix list you can act on with us or with your own team.

Frequently asked questions

What is the most commonly missed Microsoft 365 security setting?
Multi-factor authentication that is only partly enforced. Many tenants require it for administrators and a few senior staff while ordinary users can still sign in with a password alone, or have MFA set to required but never registered a method. Attackers target ordinary accounts precisely because nobody watches them, so MFA has to cover every user with no location exceptions.
What is the difference between security defaults and Conditional Access?
Security defaults are a free, single switch that enforces MFA for all users, blocks legacy authentication and protects admin actions. Conditional Access is a policy engine that applies MFA, device and location rules selectively and needs Entra ID P1, which Business Premium includes. They cannot run together, so build Conditional Access policies first, then turn security defaults off. Never leave both disabled.
Do I need Business Premium to secure Microsoft 365?
Not for the basics. MFA, security defaults, blocking legacy authentication, SPF, DKIM, DMARC, sharing limits, forwarding controls, audit logging and alert policies are available on Business Basic and Standard. Conditional Access, Intune device compliance, Defender for Office 365 and Defender for Business need Business Premium or the equivalent add-ons. For any business handling client data, Premium is usually worth the difference.
How often should Microsoft 365 security settings be reviewed?
Check Secure Score monthly and run a full configuration review at least once a year. Also review after any significant change, such as a new office, a merger, a change of IT provider or a security incident. Microsoft renames and adds features every quarter, and someone will eventually switch a policy off to fix a printer, so a one-off setup does not stay secure on its own.
Does a high Microsoft Secure Score mean we are secure?
No. Secure Score compares your configuration against Microsoft's recommendations and is useful for finding gaps and tracking progress, but it is not a certificate. A tenant can score well and still have an unmonitored admin account, no backup and staff who click phishing links. Treat it as a prioritised to-do list, work through the identity items first, and pair it with awareness training and independent backup.
Will blocking legacy authentication break anything?
Sometimes. The usual casualties are multifunction printers that scan to email, older line-of-business software that sends mail with a username and password, and very old mail clients. Check the Entra sign-in logs filtered by client app before you block, move those devices to a modern authentication method or a dedicated relay, then enforce. Leaving legacy authentication open for one printer exposes every account.
Does this checklist replace Microsoft 365 backup?
No. Every item here makes an account compromise less likely or easier to detect, but none of them recovers data that has been deleted or encrypted. Microsoft's recycle bins, version history and retention windows are time-limited and are not a backup. A third-party backup that keeps independent copies of Exchange, OneDrive, SharePoint and Teams belongs alongside the checklist, not instead of it.

Next step

Talk to an engineer, not a sales script

Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

WhatsApp us