IT & SupportIT SupportMicrosoft 365Server SolutionsVirtualisationCyber SecurityCyber SecuritySavvy SecureEmail SolutionsAccess ControlCCTVConnectivity & CommsBusiness Phone SystemsProfessional CommunicationNetwork & WiFiMobile ConnectivityBroadband CheckerWeb & DigitalWeb DesignAll servicesResource CentreKnowledge HubGuidesMicrosoft 365Cyber SecurityIT SupportPhones & BroadbandCCTV & Security SystemsPlanning & ProductivityAll resources by topicCompanyLocationsFAQsAboutContactGet a Quote
Cyber Security

How to secure Microsoft 365 properly

Small business owner reviewing Microsoft 365 security settings on a laptop

Microsoft 365 is a good starting point for email and files, but its default settings are not a finished security plan. This guide is for small businesses that already use it and want a sensible order of work. Follow the steps below to protect the accounts, mail and documents you rely on, without turning everyday work into a nuisance.

Start with a short security inventory

Before changing settings, record licences, administrator accounts, shared mailboxes and important file locations. Check the Microsoft 365 admin centre and keep the list secure. You cannot judge whether a setting is missing if you do not know what is in use.

Also list services that sign in with a Microsoft account, such as payroll, quoting software or backup tools. A change to conditional access can affect them. If you are unsure which licence includes a control, check it before planning around it; some stronger protections need Microsoft Entra ID P1 or a Microsoft 365 Business Premium-type licence. A Microsoft 365 review should cover licences as well as settings.

Turn on MFA for every account

Step 1: protect ordinary user accounts

Multi-factor authentication, usually shortened to MFA, asks for a second proof after the password. Turn it on for every user, including part-time staff and directors. An authenticator app is normally easier and safer than a text message, and a passkey is better still where it is offered. Microsoft is making passkeys the default sign-in method in Microsoft Entra ID and retires its own SMS and voice delivery on 1 February 2027, so work through our Microsoft 365 passkey rollout guide rather than leaving people on text-message codes. Give people a short setup session, ask them to register a second method where appropriate, and explain that no colleague or supplier should ever ask them to approve an unexpected sign-in prompt.

Do not leave MFA as a task people can finish later. Set a completion date, chase the exceptions and document the reason for any temporary exemption. MFA is one part of the wider approach explained in our plain-English MFA guide; it does not make a weak password, a risky attachment or an over-privileged account safe on its own.

Step 2: deal with admin accounts separately

Administrators are more valuable to an attacker because they can create accounts, read settings and change access. Each person who needs administration should use a separate admin account, not the account used for day-to-day email. Protect those accounts with MFA from the start. Keep the number of Global Administrators very small and use narrower roles, such as Exchange Administrator or SharePoint Administrator, where that is enough.

Create a break-glass account and store it safely

A break-glass account is an emergency administrator account for the rare moment when a policy or outage locks out normal administrators. Keep it separate from named users, protect its long unique password in a secure emergency record and monitor its use. It is not for routine jobs.

Use conditional access to set sensible sign-in rules

Conditional access is simply a set of "if this, then that" sign-in rules. For example: if someone is signing in from outside your normal locations, require MFA; if an administrator signs in, apply tighter rules; if a device is not managed, limit access. It can reduce risk without blocking all remote work, but a badly planned rule can stop genuine users from doing their jobs.

Start in report-only mode if it is available with your licence. Watch who would be affected, exclude the emergency account deliberately, then roll out one policy at a time. Avoid broad country blocks as your only defence: staff travel, cloud services and attackers can all make location look misleading. Security Defaults may be a useful baseline for a smaller firm, though it offers less control.

Make email harder to misuse

Check mailbox forwarding rules. An attacker who gains access may create a hidden rule that sends invoices, password resets or replies to an outside address. Review user mailboxes and shared mailboxes for automatic forwarding, inbox rules with unusual names and redirects to addresses you do not recognise. Investigate the account, not just the rule, when you find one.

Enable clear external sender warnings so people can see when an email came from outside your organisation. They will not catch every impersonation attempt, so pair the warning with a simple reporting route and regular reminders. Our guide to spotting phishing emails gives staff a practical list of warning signs. Review anti-phishing and anti-spam policies before changing them, as the available controls vary by licence.

Set safe sharing rules for documents

SharePoint and OneDrive make it easy to collaborate, which is useful until a sensitive folder is shared more widely than intended. Set a default link type that makes sense for your work, preferably named people or people in your organisation rather than anyone with the link. Put an expiry on guest links where possible. Allow external sharing only where there is a business reason, and remove guest access once a project ends.

Ask the people who own departments which folders contain HR, finance, customer or commercial material. Check the members and permissions on those sites rather than assuming everyone needs access. Use separate project spaces for external work. If files are business-critical, make sure they are included in your business data backup plan; retention settings are not automatically the same as a recoverable backup.

Turn on visibility and review it monthly

Make sure audit logging is on and understand how long records are kept under your licence. Audit data helps answer basic questions after an incident: who signed in, who changed a rule, which file was shared and when. It is most useful when you know where to look before you need it. Set alerts for new administrator roles, risky forwarding and other meaningful changes if your licence supports them.

Once a month, review Global Administrators, other privileged roles, external guests, forwarding settings and recent sign-in alerts. Every quarter, remove dormant accounts and licences, then compare the account list with your current staff list. This work fits alongside the checks in a small-business cyber security plan, not instead of them.

What to do next

Work through MFA and administrator roles first, then plan sharing, mail and conditional access changes with a test group. Keep a short record of what you changed and why. If you want an independent set of eyes on your tenant, TSS can talk through a practical Microsoft 365 security review for businesses in Bury, Greater Manchester and Lancashire.

Want a second pair of eyes on Microsoft 365?

Book a free, no-obligation chat and we will help you prioritise the security changes that matter.

Call us Get a quote