← Back to Blog

Microsoft 365 Security Settings Every Small Business Should Fix

If your business runs on Microsoft 365, as most Northwest Arkansas small businesses do, it’s easy to assume Microsoft is handling security. You’re paying a large, reputable company for a mature platform. Surely that’s covered.

Microsoft provides the tools. Configuring them is your responsibility. Out of the box, Microsoft 365 is tuned for ease of adoption, not for defense, and the gap between those two settings is where a great many small business breaches happen.

The encouraging part: most of the fixes below cost nothing beyond the license you already hold.

What Default Microsoft 365 Actually Leaves Open

SettingCommon DefaultWhat It Means
Multi-factor authenticationOff on many plansA stolen password is full access
Legacy authentication protocolsEnabledAttackers bypass MFA entirely
Admin rolesOne or two Global AdminsOne compromised account owns everything
External file sharingAnyone with the linkDocuments leak with no audit trail
Email auto-forwardingAllowedAttackers read your mail for months undetected
Audit loggingOff on some plansNo way to reconstruct what happened
Safe Links / Safe AttachmentsNot configuredMalicious links and files reach inboxes

Most small businesses are running with most of these open right now.

The Fixes, In Priority Order

1. Enforce MFA on Every Account

Non-negotiable, and the single highest-value change on this list. Microsoft’s own data puts the block rate on automated account attacks above 99%.

Use Security Defaults (free, every plan) to enforce MFA tenant-wide. If you have Business Premium, use Conditional Access instead for finer control: require MFA from unfamiliar locations and devices while keeping the experience smooth on your office network.

2. Block Legacy Authentication

Older mail protocols don’t support MFA. An attacker with a valid password can connect through one and never be challenged. This makes every other identity control cosmetic.

Audit for old clients first so you know what will break, then block legacy authentication at the tenant level via Conditional Access or Security Defaults.

3. Disable External Email Auto-Forwarding

Business email compromise usually runs like this: an attacker gets into a mailbox, quietly sets a rule forwarding everything to an outside address, and then reads your quotes, invoices, and payment discussions for weeks before intervening at exactly the right moment with new banking details.

Block auto-forwarding to external addresses with a transport rule. It takes a few minutes in the Exchange admin center and closes one of the most damaging attacks aimed at small businesses.

4. Restrict External Sharing

By default, staff can share files with anyone holding a link: no account required, no expiration, no record. For any business handling client records, pricing, designs, or personal data, that’s a real exposure.

Recommended:

  • Default SharePoint and OneDrive sharing to “existing guests only” or internal-only
  • Require expiration dates on any external links
  • Turn on notifications so someone sees when files go outside
  • If you regularly share with clients or vendors, create one dedicated, monitored site for it instead of loosening everything

5. Turn On the Defender Features You Already Own

Business Premium includes Defender for Office 365, and a surprising number of businesses have never enabled it:

  • Safe Links: rewrites URLs in mail and Teams so they’re checked at the moment of the click, not just at delivery
  • Safe Attachments: opens attachments in an isolated sandbox before they reach the user
  • Anti-phishing policies: detects impersonation of your own leadership and domain

These do nothing until configured. Check whether yours are on.

6. Fix Your Admin Accounts

Many small businesses have one or two Global Administrators, used daily for email and browsing. If either is phished, the attacker can reset passwords, disable MFA, export data, and lock everyone out.

  • Create separate admin accounts used only for administration
  • Apply stricter MFA to them than to regular users
  • Use least-privilege roles; whoever manages email doesn’t need full tenant control
  • Keep one break-glass account with a hardware key, stored physically and alerted on

7. Enable Unified Audit Logging

Audit logs record who signed in, what files were opened, what admin changes were made. Without them, an investigation after an incident has nothing to work with, and you’ll be guessing about what was accessed, which matters enormously if you have notification obligations.

Turn it on in the Microsoft Purview compliance portal. Note the retention period on your plan and extend it if you’re in a regulated field.

A Realistic Sequence

You don’t need a project team. You need a few focused hours.

Week 1: the free wins Enable MFA. Block legacy authentication. Disable external auto-forwarding. Turn on audit logging. These four cost nothing and close the most-exploited gaps.

Weeks 2–4: configuration Tighten external sharing. Configure Safe Links and Safe Attachments. Audit admin roles and strip unnecessary Global Admin rights. Create the break-glass account.

Ongoing: keep it from drifting Set alerts for suspicious activity: impossible-travel logins, mass file downloads, repeated MFA failures. Review those alerts monthly. Run an access review quarterly to catch accounts for people who left.

Are You On the Right Plan?

If you’re on Business Basic or Business Standard, you have meaningful gaps, particularly Defender for Office 365, Intune device management, and the Entra ID features that make Conditional Access possible.

Microsoft 365 Business Premium closes most of them and is priced for organizations under 300 seats. For a lot of small businesses it’s cheaper than buying comparable security tools separately, and it consolidates identity, device management, and endpoint protection into one bill.

Worth checking before you buy anything new: you may already be entitled to tools you’re paying a third party for.

Why This Matters Beyond Security

Two practical pressures are making M365 configuration a business issue rather than an IT preference:

Cyber insurance. Applications now ask directly whether MFA is enforced for all users and whether legacy authentication is blocked. Answering incorrectly, or inaccurately, can raise premiums or void a claim at the worst possible moment.

Customer requirements. Larger clients increasingly push security questionnaires down to their suppliers. Being able to answer them without a scramble is becoming a condition of doing business.

Don’t Set It and Forget It

Microsoft 365 is a moving target. Staff join and leave, sharing settings drift, and Microsoft changes defaults on its own schedule. A configuration that was solid two years ago probably has gaps now.

The fix isn’t complicated, but it does need someone to own it: reviewing alerts, running access reviews, and keeping settings aligned as the platform changes.

If you’d like a clear read on how your tenant is configured, our free Technology & Growth Review covers cybersecurity, technology, and AI readiness in 60 minutes and leaves you with a written action plan.