Microsoft 365 is the backbone of most mid-size businesses: email, files, Teams and identity all live there. It includes a strong set of security controls, but several of the most valuable ones are either off by default, depend on your licensing, or were set up once years ago and never revisited. These are the seven we check first in almost every environment we assess.
1. MFA for every account, enforced with Conditional Access
Multi-factor authentication is the single most effective control against account takeover. Security defaults are a good start, but organizations with Entra ID P1 licensing (included in Microsoft 365 Business Premium) should use Conditional Access policies so MFA is enforced consistently, with clear, documented exceptions.
2. Separate, protected admin accounts
Global administrators should not read email or browse the web with the same account they use to administer the tenant. Use dedicated admin accounts, keep the number of Global Admins small, and require phishing-resistant MFA for them where possible.
3. Automatic external forwarding blocked
Attackers who compromise a mailbox often set up a rule that quietly forwards mail outside the company. Block automatic external forwarding through the outbound spam policy, and allow it only for specific, approved cases.
4. Audit logging turned on and reviewed
Unified audit logging is what lets you answer “what happened?” after an incident. Confirm it is enabled, know how long your license retains the logs, and make sure someone is actually reviewing alerts rather than letting them pile up.
5. Guest and external sharing reviewed
SharePoint, OneDrive and Teams make it easy to share with people outside the company, which is exactly the point, and exactly the risk. Set sensible defaults (for example, links that expire and require sign-in), and review guest accounts periodically so former vendors don’t keep access indefinitely.
6. Email authentication: SPF, DKIM and DMARC
These DNS records help receiving servers confirm that mail claiming to come from your domain really did. Many companies have SPF but never enabled DKIM signing or moved DMARC beyond monitoring. Getting to an enforced DMARC policy makes it much harder for attackers to impersonate you to your customers and vendors.
7. Secure Score treated as a to-do list
Microsoft Secure Score lists recommended improvements specific to your tenant and licensing. It isn’t a grade to chase for its own sake, but it is a useful, prioritized backlog. Review it monthly and record why you have chosen not to implement any recommendation you skip.
Where to start
None of these settings is exotic, but each one needs to be configured with your users and workflows in mind, or it will either break something or get quietly turned off. If you’d like a second set of eyes, our cybersecurity team can review your tenant and give you a prioritized list. Start the conversation here.



