Microsoft 365 arrives configured for adoption, not protection. Out of the box it is built so a business can be sending email within the hour, which is why almost every SME tenancy we audit shares the same profile: excellent platform, factory-default security, and several years of nobody having touched the settings that matter. The capabilities are usually already paid for; they are simply switched off, waiting for the one attack that checks.

This guide covers the settings that actually move the needle for a small business, in priority order, with the honest note on which require a Business Premium licence and which are free on any plan. Work down the list and you will pass most of a Cyber Essentials assessment and most insurer questionnaires as a side effect.

Priority 1 — Identity: where every attack starts

Enforce MFA for every user, no exceptions. The single highest-value change in this guide, and under the current Cyber Essentials question set an auto-fail if missing anywhere. App-based or passwordless methods over SMS where possible; the rollout playbook (including the director who hates prompts) is in our MFA for business guide.

Kill legacy authentication. Older protocols (IMAP, POP, legacy SMTP auth) let attackers bypass MFA entirely, and password-spray attacks specifically hunt them. Blocking legacy auth is a settings change with occasional printer-and-scanner fallout, which is a fine trade.

Conditional access, if you have Premium. Rules like “block sign-ins from countries we never work in” and “require compliant devices for admin roles” convert MFA from a prompt into a policy. This is the headline reason the Business Premium tier exists; on Basic/Standard, “security defaults” gives a blunter version free.

Admin hygiene. Global admin accounts are the tenancy’s crown jewels: separate them from daily-driver accounts, keep the count tiny, protect each with the strongest MFA you have, and maintain one documented break-glass account stored offline. The pattern to eliminate: the MD’s everyday mailbox account also being global admin, which turns one phished password into total compromise.

Priority 2 — Email: where every attack arrives

Turn on the anti-phishing features you own. Premium tenancies include Defender for Office 365 Plan 1: safe attachments (detonated in a sandbox before delivery), safe links (URLs checked at click time, not just at delivery), and impersonation protection that flags lookalike senders. We find these unconfigured in a majority of Premium tenancies: paid for, dormant.

Publish SPF, DKIM and DMARC. Three DNS records that stop criminals sending email *as your domain*: the mechanism behind supplier-invoice fraud in your name. SPF and DKIM first, then a DMARC policy tightened over a few weeks from monitoring to enforcement. Free on every plan, missing from most SME domains.

Add external-sender flagging so mail from outside the business is visibly tagged: cheap friction against the “MD asking for a bank transfer” pattern that staff training drills against.

Review forwarding rules quarterly. Attackers who compromise a mailbox routinely add silent auto-forwarding to an external address and harvest for weeks. Block external auto-forwarding by policy and audit exceptions.

Priority 3 — Data: what a breach actually takes

Tame external sharing. Default SharePoint/OneDrive settings allow generous anyone-with-the-link sharing, and years of it accumulate into exactly the exposure that Copilot deployments later surface at conversational speed. Set organisation defaults to specific-people links, expire guest access, and review the “shared with everyone” list, which every mature tenancy has and no one remembers creating.

Deploy sensitivity labels where Premium allows, at SME scale meaning two or three labels (internal, confidential) with encryption on the top tier, not a forty-label taxonomy nobody uses.

Remember retention is not backup. Recycle bins and retention policies do not protect against sync-through ransomware or late-discovered deletion; independent Microsoft 365 backup remains its own line item on any plan.

Priority 4 — Watch the estate

Use Secure Score as your dashboard. Microsoft grades your tenancy continuously against its own recommendations; treat it as a prioritised to-do list and a progress metric for management, not gospel. Score-chasing has diminishing returns; the first thirty points are the ones that matter.

Switch on audit logging and alerts for the events that signal compromise: new forwarding rules, admin role changes, impossible-travel sign-ins, mass deletions. On managed tenancies these feed our monitoring, which is the difference between a compromised mailbox found in hours and found in months.

Review app consents. Users can grant third-party apps standing access to mail and files with one careless OAuth click, and consent-phishing exploits exactly this. Restrict user consent to verified low-risk permissions and audit what has already been granted; the existing list is usually educational.

The honest meta-point

None of this is exotic, and almost all of it is configuration rather than purchase. The reason most SME tenancies stay at defaults is ownership: security settings belong to nobody, so they belong to the attacker who checks first. Whether the owner ends up being an internal person with this page as a checklist or a managed service with it as a baseline matters less than the settings getting an owner at all.

Frequently asked questions

What are the most important Microsoft 365 security settings?

In order of impact: MFA enforced for all users, legacy authentication blocked, admin accounts separated and minimised, Defender for Office 365 features enabled (on Premium), SPF/DKIM/DMARC published, external auto-forwarding blocked, and external sharing defaults tightened.

Is Microsoft 365 secure by default?

It is secure infrastructure with permissive default configuration: built for fast adoption. “Security defaults” (free) enforces MFA basics; everything beyond that is deliberate configuration, which is where most SME tenancies stop short.

What is Microsoft Secure Score?

A built-in percentage grading your tenancy against Microsoft’s security recommendations, with a prioritised improvement list. Useful as a dashboard and management metric; imperfect as a strategy, since points do not map exactly to your risks.

Do we need Business Premium for good M365 security?

The identity and email protections that define “good” lean on Premium (conditional access, Intune, Defender for Office 365). Basic/Standard tenancies can still enforce MFA, block legacy auth, publish DMARC and tighten sharing free, which is meaningfully better than defaults, but the £6 gap buys the proper toolkit, as the plan comparison shows.

How often should M365 security be reviewed?

Quarterly light reviews (forwarding rules, admin list, app consents, Secure Score trend) and an annual deeper pass, plus immediately after staff changes in admin roles. Configuration drifts; review cadence is what keeps hardening hardened.

Who should manage all this in a small business?

Someone named, with the access and the calendar reminders, or a managed provider for whom it is baseline service. The specific failure to avoid is the default: everyone assuming someone else owns it.

Get your tenancy scored honestly

Thirty minutes inside your Microsoft 365 admin centre tells us (and you) exactly where your tenancy sits against everything above: what is on, what is dormant, and what is wide open. It is a standard part of our free IT health check, with findings in plain English and the fixes priced. Get in touch before someone less friendly runs the same checks.