By J. Mesa
Most small businesses run on Microsoft 365. Email, calendars, files, and Teams all sit behind one sign-in. Criminals know that, so a Microsoft 365 account is the most common target in business email compromise. Microsoft supplies strong protections with most plans, and many of them stay switched off until someone turns them on. Work through this list with whoever manages your tenant.
Is Microsoft 365 secure by default?
Partly. Microsoft secures its data centers and the service. You are responsible for how your accounts are set up: who can sign in, how they prove who they are, and what they can share. Microsoft calls this the shared responsibility model. A tenant left on its original settings from years ago has gaps that attackers use every day.
What are the most important Microsoft 365 security settings?
- Require multi-factor authentication for everyone. This single setting blocks the large majority of account takeovers. No exceptions for the owner. If your tenant has no custom policies, turn on Security Defaults in the Microsoft Entra admin center. It requires all users to register for multi-factor authentication and costs nothing.
- Protect administrator accounts. Give each administrator a separate account used only for admin work, with no mailbox and no daily use. Keep the number of Global Administrators between two and four. Require the strongest sign-in method you have on those accounts.
- Block legacy authentication. Old protocols such as POP, IMAP, and basic SMTP authentication can’t perform multi-factor authentication, so attackers use them to get around it. Security Defaults blocks them. Confirm that no old copier, scanner, or app still depends on them, and replace what does.
- Use the authenticator app with number matching. Text message codes are better than nothing, and they can be intercepted. The Microsoft Authenticator app with number matching resists the “approve this prompt” trick.
- Turn on the email protections. In the Microsoft Defender portal, apply the Standard preset security policy. It sets anti-phishing, anti-spam, and anti-malware protection to Microsoft’s recommended levels. With Business Premium or Defender for Office 365, it also enables Safe Links and Safe Attachments, which check links and files when a user opens them.
- Turn on impersonation protection. List your owners, executives, and finance staff as protected users, and your own domain as a protected domain. The filter then flags mail that poses as them.
- Tag external email. Enable the external sender tag in Outlook, so staff can see when a message “from the boss” came from outside the company.
- Block automatic forwarding to outside addresses. After taking over a mailbox, an attacker often creates a rule that forwards a copy of every message to an outside account. Disable external auto-forwarding in the outbound spam policy.
- Confirm that auditing is on. The unified audit log records sign-ins, mailbox access, rule changes, and file activity. You need it to investigate an incident. Verify it is enabled in the Microsoft Purview portal, and know how long your plan retains it.
- Tighten sharing. In the SharePoint admin center, change the default sharing link from “Anyone with the link” to “Specific people.” Set guest links to expire. Review which sites allow outside sharing at all.
- Stop users from approving apps. Attackers trick users into granting a malicious app permission to read their mail, which survives a password change. In Entra, restrict user consent so that an administrator must approve new apps.
- Publish SPF, DKIM, and DMARC for your domain. These DNS records stop others from sending mail that claims to come from your address. Google and Yahoo began requiring them from bulk senders in February of this year.
Which Microsoft 365 plan should a small business buy?
For most businesses under 300 users, Business Premium gives the best security value. Compared with Business Standard, it adds:
- Conditional Access, which lets you set sign-in rules by user, location, and device
- Defender for Office 365, with Safe Links and Safe Attachments
- Defender for Business, an endpoint detection and response tool for your computers
- Intune, to manage and wipe laptops and phones
- Information protection, to label and encrypt sensitive files
Bought separately, those tools cost far more than the price difference between the plans.
What is Conditional Access?
Conditional Access is a rules engine for sign-ins. Each rule says: when this kind of user signs in to this app under these conditions, require this. Useful starting rules:
- Require multi-factor authentication for all users
- Require stronger authentication for administrators
- Block legacy authentication
- Block sign-ins from countries where you have no staff
- Require a managed, compliant device to reach company data
Before you enforce any rule, create one emergency “break glass” administrator account with a long random password stored in a safe, and exclude it from the policies. It keeps you from locking yourself out.
How do I check my Microsoft 365 security?
Open Microsoft Secure Score in the Defender portal. It grades your tenant against Microsoft’s recommendations and lists each improvement with instructions. Treat the score as a to-do list. Work from the top, and check it each quarter.
How do I know whether a mailbox has been hacked?
Look for these signs:
- Inbox rules the user did not create, often ones that move mail to the RSS Feeds or Conversation History folder or mark it as read
- Forwarding to an unknown outside address
- Sign-ins from unfamiliar cities or countries in the sign-in log
- Sent messages the user did not write
- Contacts reporting strange emails from the user
- Multi-factor prompts the user did not start
- A new authentication method or device registered on the account
What should I do if an account is compromised?
- Reset the password.
- Revoke all active sessions, so stolen tokens stop working.
- Review and remove unknown multi-factor methods and devices.
- Delete suspicious inbox rules and forwarding.
- Review app consents and remove any the user does not recognize.
- Search the audit log to learn what the attacker read and sent.
- Warn the contacts who received messages, and your bank if invoices or payments were discussed.
- Ask your attorney whether the mailbox held data that triggers a notification duty.
Do I need to back up Microsoft 365?
Yes. Microsoft keeps the service running. Retention settings and the recycle bin cover short-term mistakes. They do not protect against a deletion nobody notices for months, a malicious insider, or ransomware that syncs encrypted files. A third-party backup for Exchange, OneDrive, and SharePoint costs a few dollars per user each month.
What mistakes do small businesses make?
- Exempting the owner from multi-factor authentication
- Using a Global Administrator account for daily email
- Leaving former employees’ accounts active and licensed
- Sharing one mailbox password among several people in place of a shared mailbox
- Leaving “Anyone” sharing links as the default
- Ignoring Secure Score
- Assuming the IT provider configured everything, with nothing in writing
How does this apply to Google Workspace?
The same principles hold: enforce two-step verification for all users, protect administrator accounts, turn on the advanced phishing and malware settings, restrict third-party app access, limit external sharing, and publish SPF, DKIM, and DMARC.
Your next step
Sign in to the admin center today and answer one question: does every account, including the owner’s, require multi-factor authentication? Then open Secure Score. Cerberus Cybersecurity reviews Microsoft 365 configurations as part of our risk and compliance assessments and writes the access policies behind them. Contact us for a review, or see our training to prepare your staff.