Microsoft 365 includes strong security features, but many must be configured. A checklist covering identity, administrators, email, sharing, devices, and monitoring closes the most common gaps.
Key takeaways
What to know before you act
- Microsoft 365 security depends heavily on configuration, especially for identity and administrator accounts.
- Security defaults provide a strong baseline; conditional access offers more control where licensing allows.
- Secure Score is a useful way to track improvements, but prioritize by your own risk.
Why it matters
What business leaders should understand
Compromised Microsoft 365 accounts are a frequent starting point for business email compromise and data theft. Default settings and older tenants may not reflect current recommendations.
The right response should reflect your environment, data, vendors, risk, and operational priorities. Use this guide as a practical starting point, then validate important decisions with the people responsible for your technology, cybersecurity, legal obligations, and insurance coverage.
Learn how Meta IT Pro can help with microsoft 365 services, cloud services, and managed email security.
Related reading: Phishing-resistant MFA and passkeys and Does Microsoft 365 need a backup?.
Identity and administrators
Most Microsoft 365 compromises begin with an account. Security defaults, available at no extra cost, require MFA registration and block legacy authentication protocols that cannot use MFA. Organizations with Entra ID P1 or higher can use conditional access for more precise policies.
- Require MFA for all users, with phishing-resistant methods for administrators.
- Block legacy authentication.
- Limit global administrators to a small number of dedicated accounts.
- Use separate admin accounts that are not used for email or browsing.
- Keep a documented emergency-access account protected and monitored.
Email, sharing, and applications
After identity, review the settings attackers commonly abuse once they gain access.
- Block or alert on automatic forwarding to external addresses.
- Review anti-phishing, anti-spam, and safe-link and attachment policies.
- Configure SPF, DKIM, and DMARC for your domains.
- Restrict anyone-with-the-link sharing for sensitive sites.
- Limit user consent to third-party applications and review existing consents.
- Enable audit logging and review sign-in alerts.
Devices, monitoring, and recovery
Use Intune or another device-management tool to require encryption and updates on devices that access company data. Track progress with Microsoft Secure Score, review recommendations against your risk, and decide on a backup approach for mailboxes, OneDrive, SharePoint, and Teams.
Practical action plan
Steps your business can take
Enable MFA for all users through security defaults or conditional access.
Use separate, protected accounts for administrators and limit their number.
Review external sharing, mailbox forwarding, and third-party app consents.
Use Microsoft Secure Score to track and prioritize improvements.
Recommended next steps
Continue from this article.
These pages expand the specific risks and decisions covered in this guide. Use them to move from general understanding to the service, tool, or related topic that best matches your next question.
Related guide
Phishing-resistant MFA and passkeys
Choose stronger MFA methods for administrators and staff.
Explore nextRelated guide
Does Microsoft 365 need a backup?
Plan recovery for mailboxes, OneDrive, SharePoint, and Teams.
Explore nextRelated guide
What is business email compromise?
See how compromised Microsoft 365 accounts are used for fraud.
Explore nextPlanning tool
Domain health check
Review SPF, DKIM, and DMARC for your Microsoft 365 domains.
Explore nextWarning signs
Do not ignore these indicators
- Legacy authentication is still allowed
- Several everyday user accounts hold global administrator rights
- Mail is automatically forwarded to external addresses
How Meta IT Pro can help
Related services and practical next steps
Explore the services connected to this topic. These links provide more detail about scope, safeguards, support, and how to start a conversation with our team.
Authoritative references
Sources and further reading
These primary sources support the guidance in this article and provide additional technical or consumer information.
Microsoft Learn
Security defaults in Microsoft Entra ID
Microsoft's baseline identity protections, including MFA registration and blocking legacy authentication.
Microsoft Learn
Microsoft Secure Score
How Microsoft measures an organization's security posture and recommends improvement actions.
Cybersecurity and Infrastructure Security Agency
Implementing Phishing-Resistant MFA
CISA's fact sheet on MFA attacks, FIDO/WebAuthn authenticators, and phased rollout of phishing-resistant MFA.
Need help with your IT solution?
Get practical guidance from a local IT and cybersecurity team.
Meta IT Pro helps Massachusetts and Rhode Island businesses improve support, security, Microsoft 365, Google Workspace, networks, backup, recovery, and compliance readiness. Tell us what is not working - or what you want to improve - and we will help identify a sensible next step.
