Microsoft 365 Security Checklist for Small Businesses
By Jamie Hamilton · Published · Updated
Most small businesses I work with in Brisbane run Microsoft 365, and very few have it configured the way they assume it is. That is not carelessness. The tenant was set up quickly by whoever was available, it worked, and nothing since has forced anybody to look at it again.
This is the list I work through, in the order that buys the most safety per hour spent. Each item says which licence it needs, because half the advice written about Microsoft 365 security quietly assumes an enterprise plan.
1. Enforce multi-factor authentication for everyone
The single highest value change available, and the one most often reported as done when it is partly done.
The word to distrust is enabled. What matters is enforced, for every account, with the exceptions written down. The usual gaps are a user who never completed registration, an account excluded from a policy years ago to solve an urgent problem, and a shared login for an application that could not handle a prompt.
Prefer the Microsoft Authenticator app over SMS codes. SMS can be intercepted by porting a number, which is not exotic and does happen. Included in every plan.
2. Block legacy authentication
This belongs immediately after MFA because it is what makes MFA true.
Legacy authentication protocols predate modern sign-in and cannot present a second factor, so they do not prompt: they go around MFA rather than through it. A tenant with MFA enforced and legacy authentication still permitted has a locked front door beside an open window, and the reporting will tell you the door is locked.
Tenants created before roughly 2019 are the ones to check, because they predate the modern defaults and were never migrated onto them. Available in every plan through security defaults, or with more control through Conditional Access.
3. Set up Conditional Access
Conditional Access decides who can sign in, from where, on what, and under which conditions. Requiring MFA from outside Australia, blocking sign-ins from countries you have no presence in, or refusing access from unmanaged devices are all a policy each.
It needs Entra ID P1, which is included in Microsoft 365 Business Premium. If you are on Business Standard, security defaults cover the basics and this is one of the better reasons to look at the difference between the two plans.
The thing to check on an existing setup is not whether policies exist. It is what the exclusion groups contain. Almost every tenant with Conditional Access has a policy with an exception in it and almost nobody can say who is in it or why.
4. Fix email authentication: SPF, DKIM and DMARC
Without these anybody can send email that appears to come from your domain, and your customers have no way to tell.
SPF lists the servers allowed to send for you and needs to include every service that sends in your name, not just Microsoft. DKIM signs your outgoing mail and on Microsoft 365 is two DNS records and a switch, which makes it the fastest of the three to fix. DMARC decides what receivers do when the other two fail, and it is the only one of the three that protects anybody.
Aim for a DMARC policy of reject. Get there by publishing a record with a reporting address, reading the reports for several weeks until you recognise every sender, and only then stepping the policy up. Included in every plan, because it is all DNS.
Reading your own three records takes seconds and needs no sign-in. The free checker on this site reads DMARC, SPF and DKIM in one pass and says what a receiver would currently do with a forged message claiming to be from you.
Free DMARC record checker →5. Review administrative accounts
Global Administrator is the top of the tree, and an attacker holding one owns everything: every mailbox, every file, and the ability to turn off the logging that would have shown what they did.
- •Keep the number small and make them dedicated accounts, not somebody’s daily email login
- •Confirm every one has MFA registered, since an administrative account without it is the worst possible exception
- •Maintain a break glass account that is excluded from Conditional Access, has a long stored credential, and is monitored for use, so a policy mistake cannot lock you out of your own tenant
- •Check for administrative access held by IT providers you no longer work with, which lives under partner relationships rather than in the user list
The last one surprises people most. Changing providers does not revoke the previous provider’s delegated access.
6. Turn on audit logging, before you need it
Unified audit logging records who did what and when. It is frequently a compliance requirement and it is always the thing you wish had been on.
The reason it goes on the list now rather than later is that it is not retrospective. Switching it on after an incident tells you nothing about the incident. Retention is finite and varies by licence, so the question you can answer this week may be unanswerable next quarter.
7. Tighten sharing, and check what is already shared
Many tenants have SharePoint and OneDrive external sharing set so that anyone with a link can open a file, with no sign-in and no expiry. Those links get pasted into emails, forwarded, and occasionally indexed.
Change the default to specific people or existing guests. Then separately review the links that already exist, because changing the setting does not retract them.
8. Configure anti-phishing properly
Microsoft Defender for Office 365 is included in Business Premium and its impersonation protection is the part that is aimed at the attack that actually costs Australian businesses money.
It has to be told who to protect. Add your directors and your finance staff as protected users by name, and add your own domain as a protected domain. Out of the box it does not know which of your people are worth impersonating, and an unconfigured policy protects nobody in particular.
The one that is not a setting
Write down that any request to change bank details, or to make a payment outside the normal process, is verified by voice on a number you already had. Not a number from the email.
It costs nothing, it defeats the most expensive attack in this category, and unlike everything above it does not depend on anybody spotting that a message is fake. It only works if it applies to the directors too, and saying so in advance is what gives the person in accounts permission to ring and check.
Frequently asked questions
What is the most important Microsoft 365 security setting?
Enforcing multi-factor authentication for every account, immediately followed by blocking legacy authentication. They are a pair rather than two items: legacy protocols cannot present a second factor, so they bypass MFA rather than prompting for it, and a tenant with MFA enforced and legacy authentication still permitted is a locked front door beside an open window that reports itself as secure.
Do I need Business Premium for Microsoft 365 security?
Not for all of it. MFA, blocking legacy authentication, email authentication with SPF, DKIM and DMARC, audit logging and sharing settings are all available on every plan. Conditional Access needs Entra ID P1, and Defender for Office 365 with its impersonation protection needs Business Premium. Those two are the substantive difference and they are the better reason to compare the plans.
What is a break glass account?
An administrative account deliberately excluded from Conditional Access, with a long credential stored securely offline and an alert configured on any use. It exists so a mistake in a Conditional Access policy cannot lock every administrator out of your own tenant, which is a real and recoverable-only-through-support scenario. Every tenant using Conditional Access should have one and nobody should use it day to day.
Should I use SMS or an authenticator app for MFA?
The Microsoft Authenticator app. SMS codes can be intercepted by an attacker porting the number to a device they control, which is not exotic and does happen in Australia. The app is free, works offline for code generation, and supports number matching, which defeats the fatigue attack where somebody approves a prompt just to make it stop.
How do I check if my Microsoft 365 sharing settings are too open?
Look at the SharePoint and OneDrive external sharing default. Many tenants are set so anyone with a link can open a file, with no sign-in and no expiry, which means the link works for whoever it was forwarded to. Change the default to specific people or existing guests, then review the links that already exist separately, because changing the setting does not retract links already issued.
Does our old IT provider still have access to our tenant?
Quite possibly, and it will not appear in your user list. Providers usually work through a delegated administration relationship granting their staff administrative access from their own tenant, and changing providers does not revoke it. Check partner relationships in the Microsoft 365 admin centre, which is a different screen entirely, and remove anybody you no longer work with.
Is audit logging worth turning on if nothing has gone wrong?
Yes, because it is not retrospective. Enabling it after an incident tells you nothing about the incident, and the moment you want it is always the moment it should already have been running. Retention is finite and varies by licence, so even with it enabled, a question you can answer easily this week may be unanswerable next quarter.
Related Articles
Want these checked against your actual tenant rather than in general?
Health Check, $599or call 0403 401 250