
The Microsoft 365 security best practices that matter most for a small business: turn on multi-factor authentication for everyone, tighten admin accounts, block legacy sign-ins, alert on new inbox rules, enable Defender for Office 365, add basic data loss prevention, back up the tenant, and confirm audit logging. Most of them cost nothing.
Microsoft 365 hardening is largely the work of switching on protections your subscription already includes but leaves partly disabled. This checklist covers nine settings in the order we configure them for new clients, and flags which ones need a Business Premium license.
Why do attackers target small business Microsoft 365 accounts?
Because email is where the money moves. Invoices, wire instructions, and payroll changes all flow through the mailbox, and business email compromise cost victims $2.77 billion in reported losses in 2024 alone, per the FBI's 2024 Internet Crime Report. Small businesses make appealing targets precisely because so many run their tenant on default settings.
The encouraging part: a 2023 Microsoft study of real-world attack data on Entra ID accounts found that MFA alone cuts the risk of account compromise by 99.2 percent. Most of what follows is configuration, not spending.
Which Microsoft 365 security settings should you lock down first?
1. Turn on MFA for every user, no exceptions
If nobody has touched your tenant's identity settings, start with security defaults: free, preconfigured protections that require every user to register for MFA, force it for admins, and block legacy authentication. Microsoft has been enabling them automatically on new tenants since late 2019, but older tenants may still have them off. Check under Entra ID properties, and don't grant carve-outs for executives; their mailboxes are the ones attackers want most.
2. Clean up admin accounts
Keep Global Administrator assignments to the bare minimum, give admins separate accounts for daily email versus admin work (Microsoft's own recommendation), and remove stale accounts left behind by former staff or IT vendors. Microsoft also recommends two cloud-only emergency access accounts, stored offline, so a bad Conditional Access policy can't lock everyone out.
3. Block legacy authentication everywhere
Legacy protocols such as POP, IMAP, and SMTP can't complete an MFA challenge, which is why password-spray attacks love them. Microsoft began disabling basic authentication across Exchange Online in October 2022 and finished in early 2023; per Microsoft Learn, it can no longer be re-enabled, and retirement of the one remaining exception, SMTP AUTH, has been announced. Security defaults or a Conditional Access policy close whatever is left, but check the sign-in logs first so a scanner or old copier doesn't break silently.
4. Add Conditional Access policies if you have Business Premium
Conditional Access replaces the all-or-nothing security defaults with rules: require MFA everywhere, block sign-ins from countries you don't operate in, and require managed devices for admin roles. It needs at least a Microsoft Entra ID P1 license, per Microsoft Learn, which is one of the pieces bundled into Business Premium.
How do attackers hide inside a compromised mailbox?
5. Alert on new inbox rules and external forwarding
Once inside a mailbox, attackers create rules that auto-forward mail or quietly delete replies from banks and vendors so the real user never sees the conversation. It is the signature move of email compromise: per Huntress's inaugural SMB Threat Report, 64% of identity-focused incidents in Q3 2023 involved malicious forwarding or other malicious inbox rules. Set alert policies for new rule creation, restrict automatic external forwarding, and review existing rules whenever an account behaves oddly.
6. Turn on Defender for Office 365
Business Standard relies on Microsoft's built-in mail filtering. Defender for Office 365 Plan 1, included with Business Premium per Microsoft's service description, adds Safe Links, which re-checks URLs at click time; Safe Attachments, which detonates files in a sandbox before delivery; and impersonation protection that catches look-alike senders pretending to be your CEO or your bank.
What protects your data when prevention fails?
7. Start with basic data loss prevention
Purview DLP, also part of Business Premium, watches outbound email and shared files for sensitive content like Social Security and credit card numbers. Begin with Microsoft's built-in policy templates in audit mode, see what your users actually send, then tighten to warnings and blocks once the noise settles.
8. Back up the tenant
Microsoft keeps the service online; it does not undo your mistakes or an attacker's. Deleted mailboxes age out, retention windows expire, and ransomware syncs happily through OneDrive. Recycle bins are not backup, a distinction we unpack in our post on Microsoft 365 backup and the shared responsibility model. Use a third-party backup that stores copies outside the tenant, and test a restore before you need one.
9. Confirm audit logging and know its window
Purview Audit (Standard) is enabled by default and retains records for 180 days, per Microsoft Learn (the default was 90 days before an October 2023 change). Verify yours is on and returning results now, because after an incident this log is how you answer what the attacker read, forwarded, and touched. If compliance requires more than six months, export logs or move them into a SIEM.
Which Microsoft 365 security features need Business Premium?
Roughly half this checklist is free tenant hygiene. The rest rides on licensing, and the two small-business plans split cleanly; our Business Premium vs Standard comparison puts the list-price gap at roughly $8 per user per month, about $14 versus $22 at this writing. Feature placement below is per Microsoft's plan documentation.
| Security control | Business Standard | Business Premium |
|---|---|---|
| Office apps, business email, Teams | Included | Included |
| MFA and security defaults | Included | Included |
| Conditional Access (Entra ID P1) | Not included | Included |
| Defender for Office 365 Plan 1 (Safe Links, Safe Attachments) | Not included | Included |
| Intune device management | Not included | Included |
| Defender for Business (endpoint detection and response) | Not included | Included |
| Purview data loss prevention | Not included | Included |
Settings only help if someone owns them, reviews the alerts, and re-checks the tenant as Microsoft moves the furniture. That ongoing piece is exactly what The NetSys Group's Microsoft 365 management service handles for small businesses, monitored around the clock on month-to-month terms.
Frequently asked questions
Are security defaults enough for a small business?
They are a strong free baseline: MFA registration for everyone, forced MFA for admins, and blocked legacy authentication. But they are all-or-nothing, with no location rules, device requirements, or exceptions. Once you hold sensitive client data or Business Premium licenses, replace them with Conditional Access policies that keep the same protections and add conditions.
Does Microsoft back up my Microsoft 365 data?
Not in the way most owners assume. Microsoft guarantees the service stays available and provides recycle bins and retention windows, but recovering a mailbox an attacker emptied, or files encrypted through a synced laptop, is your responsibility. A third-party backup keeps independent copies outside the tenant; test restores on a schedule, not during a crisis.
How can I tell if an attacker created inbox rules in a mailbox?
Open the mailbox's rules in Outlook and look for entries that forward externally, delete messages, or carry short nonsense names. Then search the audit log for rule-creation events tied to that account, and review sign-in logs for unfamiliar locations around the same timestamps. Reset the password, revoke sessions, and re-register MFA before cleanup.
Turn insight into action.
Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.



