Seven Microsoft 365 security settings mid-size companies often miss

Data center aisle with illuminated server racks

Microsoft 365 is the backbone of most mid-size businesses: email, files, Teams and identity all live there. It includes a strong set of security controls, but several of the most valuable ones are either off by default, depend on your licensing, or were set up once years ago and never revisited. These are the seven we check first in almost every environment we assess.

1. MFA for every account, enforced with Conditional Access

Multi-factor authentication is the single most effective control against account takeover. Security defaults are a good start, but organizations with Entra ID P1 licensing (included in Microsoft 365 Business Premium) should use Conditional Access policies so MFA is enforced consistently, with clear, documented exceptions.

2. Separate, protected admin accounts

Global administrators should not read email or browse the web with the same account they use to administer the tenant. Use dedicated admin accounts, keep the number of Global Admins small, and require phishing-resistant MFA for them where possible.

3. Automatic external forwarding blocked

Attackers who compromise a mailbox often set up a rule that quietly forwards mail outside the company. Block automatic external forwarding through the outbound spam policy, and allow it only for specific, approved cases.

4. Audit logging turned on and reviewed

Unified audit logging is what lets you answer “what happened?” after an incident. Confirm it is enabled, know how long your license retains the logs, and make sure someone is actually reviewing alerts rather than letting them pile up.

5. Guest and external sharing reviewed

SharePoint, OneDrive and Teams make it easy to share with people outside the company, which is exactly the point, and exactly the risk. Set sensible defaults (for example, links that expire and require sign-in), and review guest accounts periodically so former vendors don’t keep access indefinitely.

6. Email authentication: SPF, DKIM and DMARC

These DNS records help receiving servers confirm that mail claiming to come from your domain really did. Many companies have SPF but never enabled DKIM signing or moved DMARC beyond monitoring. Getting to an enforced DMARC policy makes it much harder for attackers to impersonate you to your customers and vendors.

7. Secure Score treated as a to-do list

Microsoft Secure Score lists recommended improvements specific to your tenant and licensing. It isn’t a grade to chase for its own sake, but it is a useful, prioritized backlog. Review it monthly and record why you have chosen not to implement any recommendation you skip.

Where to start

None of these settings is exotic, but each one needs to be configured with your users and workflows in mind, or it will either break something or get quietly turned off. If you’d like a second set of eyes, our cybersecurity team can review your tenant and give you a prioritized list. Start the conversation here.

More from the blog

Start the partnership

Let’s align your infrastructure with your business objectives

Whether you need a full managed IT takeover or one specific problem solved, start with a conversation and a clear-eyed assessment.