
Updated September 16, 2026.
The Microsoft 365 security best practices that matter most for a small business: turn on multi-factor authentication for everyone, tighten admin accounts, block legacy sign-ins, alert on new inbox rules, enable Defender for Office 365, add basic data loss prevention, back up the tenant, and confirm audit logging. Most of them cost nothing.
Microsoft 365 hardening is largely the work of switching on protections your subscription already includes but leaves partly disabled. This checklist covers nine settings in the order we configure them for new clients, and flags which ones need a Business Premium license.
Why do attackers target small business Microsoft 365 accounts?
Because email is where the money moves. Invoices, wire instructions, and payroll changes all flow through the mailbox, and business email compromise cost victims $2.77 billion in reported losses in 2024 alone, per the FBI's 2024 Internet Crime Report. Small businesses make appealing targets precisely because so many run their tenant on default settings.
The encouraging part: a 2023 Microsoft study of real-world attack data on Entra ID accounts found that MFA reduces the risk of compromise by 99.22%. Most of what follows is configuration, not spending.
Which Microsoft 365 security settings should you lock down first?
1. Turn on MFA for every user, no exceptions
If nobody has touched your tenant's identity settings, start with security defaults: free, preconfigured protections that require every user to register for MFA, force it for admins, and block legacy authentication. Microsoft has been enabling them automatically on new tenants since late 2019, but older tenants may still have them off. Check under Entra ID properties, and don't grant carve-outs for executives; their mailboxes are the ones attackers want most.
2. Clean up admin accounts
Keep Global Administrator assignments to the bare minimum, give admins separate accounts for daily email versus admin work (Microsoft's own recommendation), and remove stale accounts left behind by former staff or IT vendors. Microsoft also recommends two cloud-only emergency access accounts, stored offline, so a bad Conditional Access policy can't lock everyone out. Formalizing this discipline — separated admin identities, vaulted credentials, time-limited elevation — is called privileged access management (PAM), and it scales down to small tenants.
3. Block legacy authentication everywhere
Legacy protocols such as POP, IMAP, and SMTP can't complete an MFA challenge, which is why password-spray attacks love them. Microsoft began disabling basic authentication across Exchange Online in October 2022 and finished in early 2023; per Microsoft Learn, it can no longer be re-enabled, and retirement of the one remaining exception, SMTP AUTH, has been announced. Security defaults or a Conditional Access policy close whatever is left, but check the sign-in logs first so a scanner or old copier doesn't break silently.
4. Add Conditional Access policies if you have Business Premium
Conditional Access replaces the all-or-nothing security defaults with rules: require MFA everywhere, block sign-ins from countries you don't operate in, and require managed devices for admin roles. It needs at least a Microsoft Entra ID P1 license, per Microsoft Learn, which is one of the pieces bundled into Business Premium. One rung up that ladder, Entra ID P2 adds privileged identity management (PIM) — admin roles activated just in time instead of held permanently.
Put one date in the calendar here. Microsoft retires the legacy risk policies configured in Entra ID Protection on October 1, 2026, and they have to be rebuilt as Conditional Access policies. Nothing migrates on its own, so a tenant that skips it keeps the license and loses the enforcement. Our guide to Conditional Access for small business walks through the migration.
How do attackers hide inside a compromised mailbox?
5. Alert on new inbox rules and external forwarding
Once inside a mailbox, attackers create rules that auto-forward mail or quietly delete replies from banks and vendors so the real user never sees the conversation. It is the signature move of email compromise: per Huntress's inaugural SMB Threat Report, 64% of identity-focused incidents in Q3 2023 involved malicious forwarding or other malicious inbox rules. Set alert policies for new rule creation, restrict automatic external forwarding, and review existing rules whenever an account behaves oddly.
6. Turn on Defender for Office 365
Business Standard relies on Microsoft's built-in mail filtering. Defender for Office 365 Plan 1, included with Business Premium per Microsoft's service description, adds Safe Links, which re-checks URLs at click time; Safe Attachments, which detonates files in a sandbox before delivery; and impersonation protection that catches look-alike senders pretending to be your CEO or your bank.
What protects your data when prevention fails?
7. Start with basic data loss prevention
Purview DLP, also part of Business Premium, watches outbound email and shared files for sensitive content like Social Security and credit card numbers. Begin with Microsoft's built-in policy templates in audit mode, see what your users actually send, then tighten to warnings and blocks once the noise settles. DLP flags sensitive content on its way out; keeping that content unreadable once it leaves is a separate layer, covered in our guide to business email encryption.
8. Back up the tenant
Microsoft keeps the service online; it does not undo your mistakes or an attacker's. Deleted mailboxes age out, retention windows expire, and ransomware syncs happily through OneDrive. Recycle bins are not backup, a distinction we unpack in our post on Microsoft 365 backup and the shared responsibility model. Use a third-party backup that stores copies outside the tenant, and test a restore before you need one.
9. Confirm audit logging and know its window
Purview Audit (Standard) is enabled by default and retains records for 180 days, per Microsoft Learn (the default was 90 days before an October 2023 change). Verify yours is on and returning results now, because after an incident this log is how you answer what the attacker read, forwarded, and touched. If compliance requires more than six months, export logs or move them into a SIEM.
Which Microsoft 365 security features need Business Premium?
Roughly half this checklist is free tenant hygiene. The rest rides on licensing, and the two small-business plans split cleanly; our Business Premium vs Standard comparison puts the list-price gap at roughly $8 per user per month, about $14 versus $22 at this writing. Feature placement below is per Microsoft's plan documentation.
| Security control | Business Standard | Business Premium |
|---|---|---|
| Office apps, business email, Teams | Included | Included |
| MFA and security defaults | Included | Included |
| Conditional Access (Entra ID P1) | Not included | Included |
| Defender for Office 365 Plan 1 (Safe Links, Safe Attachments) | Not included | Included |
| Intune device management | Not included | Included |
| Defender for Business (endpoint detection and response) | Not included | Included |
| Purview data loss prevention | Not included | Included |
Settings only help if someone owns them, reviews the alerts, and re-checks the tenant as Microsoft moves the furniture. That ongoing piece is exactly what The NetSys Group's Microsoft 365 management service handles for small businesses, monitored around the clock on month-to-month terms.
Want to know where your tenant actually stands against this list? Book a complimentary security assessment and we'll walk the nine points with you.
Frequently asked questions
Are security defaults enough for a small business?
They are a strong free baseline: MFA registration for everyone, forced MFA for admins, and blocked legacy authentication. But they are all-or-nothing, with no location rules, device requirements, or exceptions. Once you hold sensitive client data or Business Premium licenses, replace them with Conditional Access policies that keep the same protections and add conditions.
Does Microsoft back up my Microsoft 365 data?
Not in the way most owners assume. Microsoft guarantees the service stays available and provides recycle bins and retention windows, but recovering a mailbox an attacker emptied, or files encrypted through a synced laptop, is your responsibility. A third-party backup keeps independent copies outside the tenant; test restores on a schedule, not during a crisis.
How can I tell if an attacker created inbox rules in a mailbox?
Open the mailbox's rules in Outlook and look for entries that forward externally, delete messages, or carry short nonsense names. Then search the audit log for rule-creation events tied to that account, and review sign-in logs for unfamiliar locations around the same timestamps. Reset the password, revoke sessions, and re-register MFA before cleanup.
Sources and further reading
- FBI IC3 — 2024 Internet Crime Report — business email compromise losses of $2,770,151,146 in 2024. Accessed September 2026.
- Microsoft Research (2023) — How effective is multifactor authentication at deterring cyberattacks? — MFA reduces the risk of compromise by 99.22% across the studied population. Accessed September 2026.
- Huntress — Inaugural SMB Threat Report — 64% of identity-focused incidents in Q3 2023 involved malicious forwarding or other malicious inbox rules. Accessed September 2026.
- Microsoft Learn — Configure risk policies in Entra ID Protection — the October 1, 2026 retirement of legacy risk policies. Accessed September 2026.
- Microsoft Learn — Deprecation of basic authentication in Exchange Online — basic auth cannot be re-enabled, and SMTP AUTH retirement is announced. Accessed September 2026.
By Latoya Reed, who leads cloud and Microsoft 365 services at The NetSys Group. NetSys has delivered managed IT, cybersecurity, and cloud services since 1998 to businesses across NY, NJ, CT, PA, and Southwest Florida.
Discuss microsoft 365 security hardening for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.



