Microsoft 365 & Cloud
Microsoft 365 security settings checklist: 14 settings to check before an attacker does
A numbered Microsoft 365 security checklist for UK SMEs: MFA, legacy authentication, admin accounts, Conditional Access, SPF, DKIM, DMARC, audit logs, Intune.
By Dig IT SolutionsUpdated 8 September 202610 min read
Short answer
Start with the settings attackers exploit most: enforce MFA for every user, block legacy authentication, separate and protect admin accounts, restrict external sharing and automatic forwarding, and confirm audit logging is on. Then use Secure Score, Conditional Access, SPF, DKIM and DMARC, alert policies and Intune device compliance to close the remaining gaps.
Most Microsoft 365 tenants we review were set up correctly for the day they went live and never touched again. The mailboxes migrated, the licences were assigned and the security portals were left on their defaults. This checklist is the list an engineer works through on a tenant they have just inherited, in the order that removes the most risk soonest.
Why the defaults are not enough
Microsoft has to ship settings that work for a two-person consultancy, a school and a global manufacturer at the same time, so it leaves a lot permissive and lets each organisation tighten things to suit its own risk. Some protections are on by default for new tenants, including security defaults, mailbox auditing and the blocking of automatic forwarding. Older tenants, and any tenant where an admin switched something off to make a printer work, cannot be assumed to have them.
The GOV.UK Cyber Security Breaches Survey consistently reports phishing as the most common attack UK businesses experience, and a compromised Microsoft 365 account is the usual outcome. Almost every item below either makes that compromise harder or makes it visible sooner.
The checklist at a glance
| # | Setting | Where to find it | Why it matters |
|---|---|---|---|
| 1 | MFA for every user | Entra admin centre, Protection, Authentication methods | Stops most password-based account takeovers |
| 2 | Block legacy authentication | Entra sign-in logs, Conditional Access, Exchange admin centre | Old protocols bypass MFA entirely |
| 3 | Security defaults or Conditional Access | Entra admin centre, Identity, Overview, Properties | You need one of the two, never neither |
| 4 | Conditional Access policies | Entra admin centre, Protection, Conditional Access | Applies MFA and device rules based on risk rather than blanket prompts |
| 5 | Dedicated, protected admin accounts | Entra admin centre, Roles and administrators | A compromised global admin owns the whole tenant |
| 6 | Microsoft Secure Score | Microsoft Defender portal, Secure Score | A prioritised list of what is still wrong |
| 7 | SPF, DKIM and DMARC | DNS at your registrar, Defender portal email authentication settings | Stops criminals sending mail as your domain |
| 8 | External sharing limits | SharePoint admin centre, Policies, Sharing | Anonymous links leak data silently |
| 9 | Automatic forwarding and inbox rules | Defender portal outbound spam policy, Exchange admin centre | Attackers forward your mail to themselves |
| 10 | Unified audit log and mailbox auditing | Microsoft Purview portal, Audit | Without it you cannot investigate an incident |
| 11 | Alert policies | Defender portal, Policies and rules, Alert policy | Turns suspicious events into notifications someone sees |
| 12 | Defender for Office 365 preset policies | Defender portal, Threat policies, Preset security policies | Safe Links, Safe Attachments and impersonation protection |
| 13 | Device compliance via Intune | Intune admin centre, Devices, Compliance policies | Only healthy, encrypted devices reach company data |
| 14 | Leavers, inactive accounts and permissions | Entra admin centre, Users | Forgotten accounts are the easiest way in |
Microsoft Learn is the authority for the current path.
The checklist in detail
1. Multi-factor authentication for every user
MFA is the single most effective control, and the one most often only half done. The common failure is enforcing it for admins and a few senior staff while ordinary users can still sign in with a password.
Enforce MFA for all users with no exceptions for "trusted" locations. Prefer the Microsoft Authenticator app with number matching, or passkeys, over SMS. Check that everyone has actually registered: a user with MFA required but no method registered is still a password-only account until their next sign-in. Pair MFA with a sensible password policy, which under NCSC guidance means long, unique passwords, a password manager and no forced periodic changes. Read what is multi-factor authentication if you need to explain it to staff.
2. Block legacy authentication
Legacy protocols such as POP, IMAP and older SMTP authentication were designed before MFA existed and do not support it. A tenant that allows them has a side door that ignores everything you did in step 1. Microsoft has retired basic authentication for most Exchange Online protocols, but SMTP AUTH can still be enabled per mailbox, and older tenants may carry exceptions.
Filter the Entra sign-in logs by client app to see what is still using legacy authentication, then block it with a Conditional Access policy (or leave security defaults on, which blocks it too). The usual holdouts are multifunction printers, scan-to-email devices and old line-of-business applications. Move them to a dedicated relay or modern authentication rather than leaving the door open for everyone.
3. Security defaults or Conditional Access, never neither
Security defaults are a free, one-switch baseline: MFA for all users, legacy authentication blocked, extra protection for admin actions. They are the right answer for a tenant on Business Basic or Standard, and Microsoft documents them at Microsoft Learn.
Conditional Access is the flexible version. It needs Entra ID P1, which is included in Business Premium. The two cannot run together, so a tenant moving to Conditional Access must build the equivalent policies before switching security defaults off. Tenants where an admin disabled security defaults to fix a compatibility problem and never built Conditional Access are common and completely exposed.
4. Conditional Access policies
Conditional Access evaluates each sign-in against who the user is, what device they are on, where they are and what they are trying to reach, then requires MFA, blocks, or allows. A sensible starter set for an SME:
- Require MFA for all users on all cloud apps.
- Block legacy authentication.
- Require MFA on every sign-in for admin roles.
- Block sign-ins from countries the business never operates in.
- Require a compliant or hybrid-joined device for access to SharePoint and Exchange.
Build each policy in report-only mode first, review the sign-in log impact for a week, then enforce. Our guide to Conditional Access explained walks through the policies in detail.
5. Dedicated, protected admin accounts
Global admin is the key to everything: it can disable security controls, create users, read any mailbox and remove retention on data held in the tenant. Microsoft recommends fewer than five global admins and that they use separate, cloud-only accounts with no mailbox and no daily use. The person who administers the tenant should have an ordinary account for email and a separate admin account for admin work.
Give lesser roles where they fit (Exchange administrator, User administrator, Helpdesk administrator) rather than global admin for convenience. Create one emergency access account with a long random password stored offline, excluded from Conditional Access and monitored for any sign-in.
6. Microsoft Secure Score
Secure Score, in the Microsoft Defender portal, compares your tenant against Microsoft's recommended configuration and produces a percentage with a prioritised list of actions. It is not a compliance certificate and a high score does not mean you are safe, but it is the fastest way to see what has been missed and to track progress month on month.
Work through the identity and apps recommendations first.
7. SPF, DKIM and DMARC
These three DNS records tell the world which servers may send email as your domain and what to do with mail that fails the check. Without them, anyone can send invoices as your finance team and the recipient's mail system has no way to tell.
SPF and DMARC are records at your domain registrar or DNS host. DKIM for a custom domain is switched on in the Defender portal under email authentication settings, which gives you two CNAME records to publish. Start DMARC at p=none with reporting, review the reports for a few weeks to catch legitimate third-party senders (accounting software, CRM, newsletter tools), then move to quarantine and finally reject. Our email security service covers this along with filtering and impersonation protection.
8. External sharing limits
SharePoint and OneDrive can allow "Anyone" links, which need no sign-in and can be forwarded indefinitely. In the SharePoint admin centre, set the organisation-wide level to "New and existing guests" so external people must authenticate, set anonymous links to expire if you keep them at all, default new links to "specific people", and restrict who can invite guests.
9. Automatic forwarding and inbox rules
The first thing an attacker does with a compromised mailbox is create a rule that forwards or redirects mail to an external address, often hiding copies in an RSS or Archive folder. They then sit and read, waiting for an invoice to alter. Set the outbound spam policy in the Defender portal so automatic forwarding to external addresses is off, and allow exceptions per mailbox only where a real business need exists. Periodically list inbox rules across all mailboxes with PowerShell and query any that forward, redirect or delete.
10. Unified audit log and mailbox auditing
The unified audit log records user and admin activity across Exchange, SharePoint, OneDrive, Teams and Entra. Mailbox auditing records who accessed a mailbox and what they did. Both are on by default for most current tenants, but verify in the Microsoft Purview portal because a tenant created years ago, or one where auditing was switched off, will have gaps.
Retention on the standard audit tier is 180 days at the time of writing, with longer retention needing higher-tier licensing or an add-on. If a compromise is discovered six months after it began, the early evidence is already gone. For businesses with regulatory obligations, export the log periodically or feed it to a monitoring platform.
11. Alert policies
Logging is only useful if someone is told. Microsoft provides default alert policies for events such as a forwarding rule being created, suspicious sending patterns, a user being granted an admin role and malware being detected. Confirm they are enabled, confirm they send to a monitored mailbox rather than the mailbox of someone who left, and add custom alerts for impossible travel sign-ins and mass file downloads if your licence supports them. Test one: create a forwarding rule on a test mailbox and check the alert arrives.
12. Defender for Office 365 preset policies
Business Premium includes Defender for Office 365 Plan 1, which adds Safe Links (URL rewriting and time-of-click checking), Safe Attachments (opening attachments in a sandbox before delivery) and anti-phishing impersonation protection. Many tenants that pay for it have never applied it. In the Defender portal, apply the Standard preset security policy to all users, then add the names of your directors and finance staff to the impersonation protection list so a lookalike sender is flagged. Defender for Business, also in Premium, covers endpoints and should be deployed alongside your endpoint detection and response.
13. Device compliance via Intune
Remote working means company mail and files on laptops and phones you may never have seen. Intune, included in Business Premium, lets you define what a healthy device looks like: BitLocker encryption on, a minimum operating system version, Defender antivirus active, a PIN or password on mobiles. A Conditional Access policy then requires devices to be compliant before they can reach SharePoint or Exchange. Start with company-owned Windows laptops, then bring in mobiles with app protection policies so personal phones can read email without the business owning the device.
14. Leavers, inactive accounts and permissions
Every leaver should trigger the same steps on the day they go: block sign-in, revoke sessions, remove MFA devices, convert the mailbox to shared or apply retention, transfer OneDrive ownership, remove licences. Accounts that stay active for months after someone leaves are a standing invitation. Run a quarterly review of users with no sign-in in 60 days and of who holds owner rights on SharePoint sites and Teams. Our onboarding and offboarding process turns this into a standard form rather than a memory test.
Backup, and reviewing this regularly
None of the above brings deleted or encrypted data back. Microsoft's retention windows and recycle bins are not a backup, and the platform does not protect you from ransomware that encrypts files through a synced OneDrive or an admin error that purges a mailbox. Independent Microsoft 365 backup belongs alongside this checklist, and does Microsoft 365 include backup explains why.
Treat the checklist as a cycle rather than a project. A tenant review at least annually, with Secure Score checked monthly, is a reasonable rhythm for most SMEs. Our Microsoft 365 security service does exactly this on a schedule.
What to do next
If you cannot say with confidence that every item above is in place, the honest next step is to check rather than assume. An IT health check reviews your tenant against this list, reports what is exposed in plain English, and gives you a prioritised fix list you can act on with us or with your own team.

