Skip to main content

Microsoft 365

Microsoft 365 security

Microsoft 365 security configured properly: MFA everywhere, Conditional Access, Intune compliance, Defender for Business, Secure Score and audit logging.

In short

Microsoft 365 security is about configuring what you already pay for: MFA on every account, Conditional Access policies that block risky sign-ins, Intune device compliance, Defender for Business, separated admin roles, legacy authentication disabled and audit logging turned on. Dig IT Solutions hardens tenants against a documented baseline and tracks progress with Microsoft Secure Score.

When you need this

Signs this is the right conversation

  • We set up Microsoft 365 years ago and never touched the security settings.
  • Some staff have MFA and some don't.
  • People sign in from personal devices we know nothing about.
  • We're not sure who has global admin rights.
  • If an account was compromised, we wouldn't be able to tell what was accessed.

Scope

What we deliver

  • 01

    MFA and identity baseline

    Multi-factor authentication enforced for all users and admins, with number matching, no shared accounts and break-glass admin accounts documented.

  • 02

    Conditional Access policies

    Rules that require compliant devices, block legacy protocols, restrict sign-ins from unexpected countries and challenge risky logins.

  • 03

    Intune device management

    Windows, macOS, iOS and Android devices enrolled, encrypted, patched and checked against compliance policies before they can access company data.

  • 04

    Defender for Business

    Endpoint, email and identity protection from the Business Premium licence configured and monitored, rather than left on defaults.

  • 05

    Admin role hygiene

    Global admin limited to a few named accounts, role-based admin for everything else, and privileged tasks done from separate accounts.

  • 06

    Logging and alerts

    Unified audit log enabled and retained, alerts for suspicious inbox rules, mass downloads and impossible-travel sign-ins.

  • 07

    Secure Score reporting

    Your tenant's Secure Score tracked over time with a plan for the recommendations worth doing.

Outcomes

What you get out of it

  • Stolen passwords stop being enough to get in.
  • Only known, healthy devices reach company data.
  • Clear visibility of admin access and account activity.
  • Progress measured against a Microsoft benchmark.

FAQ

Questions we are asked

Straight answers. If yours is not here, call 020 8482 4020 or 01992 939 365 and ask an engineer.
What are the most important Microsoft 365 security settings?
Enforce MFA for everyone, block legacy authentication, use Conditional Access to require compliant devices, limit global admins, disable external mail forwarding, turn on the unified audit log, enable Defender's Safe Links and Safe Attachments, and enrol devices in Intune. Those steps close the routes behind most account compromises. A full checklist is in our Microsoft 365 security settings article.
What is Conditional Access?
Conditional Access is the Microsoft 365 policy engine that decides whether a sign-in is allowed, and on what terms, based on who is signing in, from where, on which device and how risky it looks. Examples: require MFA for everyone, block sign-ins from countries you don't operate in, allow email only from managed devices. It requires Entra ID P1, which is included in Business Premium.
Do we need Microsoft 365 Business Premium?
For most organisations of 10 to 300 people, yes. Business Premium adds Intune, Conditional Access, Defender for Business and Defender for Office 365 to the standard apps and email. Buying those separately or leaving them out usually costs more or leaves gaps. If you're on Business Standard we'll show you exactly what you'd gain and what the licence uplift costs.
What is Microsoft Secure Score?
Secure Score is a dashboard in Microsoft 365 that rates your tenant's security configuration against Microsoft's recommendations and gives a percentage score. It's a useful benchmark and improvement tracker, though not every recommendation suits every business. We use it to prioritise changes and to show management measurable progress, rather than chasing a perfect score for its own sake.
Can you secure our tenant if another provider set it up?
Yes. We regularly take over tenants built by previous providers or set up in-house. The first step is an audit of identities, admin roles, policies, licences and logs, then a prioritised hardening plan. Changes are staged so staff aren't locked out, with MFA rolled out in groups and Conditional Access run in report-only mode before enforcement.

Next step

Talk to an engineer, not a sales script

Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

WhatsApp us