Microsoft 365 Security Checklist for UK SMEs

For most of the businesses we support, Microsoft 365 is where the work happens. Email runs through Outlook, files live in OneDrive and SharePoint, and meetings happen in Teams. Staff sign in with a Microsoft account from office laptops, home broadband and their own phones. If someone gets into that account, they get into the business.
Microsoft includes a lot of security in the product, and more again in Business Premium. What it cannot do is decide how your tenant should be set up. Most of the problems we find when we take on a new client come from settings nobody changed, or changed once years ago and forgot about, rather than from a missing product.
This checklist is what we go through when we review a Microsoft 365 tenant for a UK business. It covers 25 checks across identity, email, devices, files, monitoring and recovery, what each one protects, and which licence you need for it. We have checked every claim against Microsoft's current documentation, and the sources are listed at the end.
The Microsoft 365 security checklist at a glance
Work through this table first. The licence column tells you whether you can do it on any Microsoft 365 business plan or whether it needs Business Premium.
Every planBasic, Standard and Premium PremiumBusiness Premium Outside M365DNS or a separate product
| Check | What good looks like | Licence |
|---|---|---|
| Identity and access | ||
| 1. MFA | Every user has to pass MFA to sign in | Every plan |
| 2. Admin accounts | Admins use a separate account for admin work | Every plan |
| 3. Least privilege | People hold the smallest admin role that does the job | Every plan |
| 4. Emergency access | Two protected break glass accounts exist and are monitored | Every plan |
| 5. Legacy authentication | Old sign in methods that skip MFA are blocked | Every plan |
| 6. Conditional Access | Sign in rules take account of user, device and location | Premium |
| 7. Phishing resistant sign in | Admins sign in with a passkey, security key or Windows Hello | Every plan |
| 8. Leavers and movers | Access is removed or changed on the day someone leaves or moves role | Every plan |
| 9. App consent | Staff cannot hand company data to any app they like | Every plan |
| 10. SPF | Your DNS lists every service allowed to send as your domain, and nothing else | Outside M365 |
| 11. DKIM | Outgoing mail from your own domain is signed | Every plan |
| 12. DMARC | A DMARC record is published and someone reads the reports | Outside M365 |
| 13. Anti phishing | Spoofing protection is on; impersonation protection covers senior staff | Premium |
| 14. External forwarding | Automatic forwarding to outside addresses is set to Off | Every plan |
| 15. Safe Links and Attachments | Links and files are checked when they are opened | Premium |
| Devices | ||
| 16. Device management | Company devices are enrolled in Intune | Premium |
| 17. Device compliance | Devices that fall below your standard lose access | Premium |
| 18. Endpoint protection | Defender for Business is running and reporting on every device | Premium |
| 19. Encryption | BitLocker or FileVault is on, and you can prove it | Premium |
| Files and collaboration | ||
| 20. External sharing | SharePoint and OneDrive sharing is limited to what you need | Every plan |
| 21. Guest access | Guest accounts are reviewed and removed when finished with | Every plan |
| 22. Data protection | Sensitive files are labelled and DLP stops the obvious leaks | Premium |
| Monitoring and recovery | ||
| 23. Secure Score | Open recommendations are reviewed every quarter | Every plan |
| 24. Audit logging | The audit log is switched on and someone watches the alerts | Every plan |
| 25. Recovery | Data is backed up and a restore has been tested | Outside M365 |
More than half of the list costs nothing beyond the licence you already have. It is configuration work, and in our experience that is the part most tenants are missing.
| Licence | Share of checklist | Checks |
|---|---|---|
| Any business plan | 14 | |
| Business Premium | 8 | |
| DNS or separate backup | 3 |
Source: the checklist above, against Microsoft's current licensing guidance.
None of this is a one-off job. People join and leave, suppliers get access and never lose it, someone connects a new app, and a policy gets an exception added in a hurry. A tenant that was well set up in January can have real gaps by the summer if nobody looks at it, which is why there is a review schedule further down.
What you are responsible for in Microsoft 365
Microsoft runs the service. It keeps the datacentres, the hardware and the platform secure and available, and it gives you the controls. How those controls are set is up to you, or your IT provider.
| Microsoft looks after | You look after |
|---|---|
| Physical datacentre security | Who has an account and what they can reach |
| The underlying network and servers | MFA, sign in rules and admin roles |
| Keeping the service running | Laptops and phones that access company data |
| Security features and updates to them | Sharing settings, guest users and connected apps |
| Copies of your data for its own resilience | Backups you can restore from, and testing them |
The trouble is that a badly configured tenant looks exactly like a well configured one from the outside. People can sign in, email arrives, Teams works and files open. Meanwhile there can be a director with Global Administrator rights on their everyday account, a laptop nobody has checked in a year, an inbox rule sending copies of invoices to a Gmail address, and a sharing link to the HR folder that anyone on the internet can open. A security review has to look at the settings, because the day to day experience will not tell you.
Microsoft 365 Business Standard vs Business Premium for security
Licensing decides which of the checks you can carry out, so it is worth looking at before anything else. A lot of businesses pick Business Standard because it has the Office apps they need, then find a year later that they want device management and better email filtering, and start buying separate products to fill the gap.
Business Premium is built for organisations of up to 300 users and bundles the main security products into the licence. Here is what that adds in practice.
| Feature | Basic or Standard | Premium |
|---|---|---|
| Anti-spam, anti-malware and spoofing protection (Exchange Online Protection) | Included | Included |
| Security defaults: MFA for everyone and legacy sign in blocked | Included | Included |
| Conditional Access (Microsoft Entra ID P1) | Not included | Included |
| Device management (Microsoft Intune Plan 1) | Not included | Included |
| Endpoint protection with detection and response (Defender for Business) | Not included | Included |
| Safe Links, Safe Attachments and impersonation protection (Defender for Office 365 Plan 1) | Not included | Included |
| Sensitivity labels and data loss prevention (Purview Information Protection) | Not included | Included |
Source: Microsoft Learn service descriptions for Microsoft 365 Business Premium, Defender for Office 365 and Microsoft Purview.
For a business that runs on Microsoft 365, has staff working from home, and holds client or financial data, Premium is usually the simpler route. You get device management, endpoint protection and proper email filtering from one supplier, all managed in the same place. If you have a handful of staff, no company laptops and nothing especially sensitive, Standard with security defaults switched on may be enough for now.
Microsoft also sells add-ons for Premium, the Microsoft Defender Suite and the Microsoft Purview Suite for Business Premium, which bring in features from the enterprise E5 plans. Most small businesses do not need them to start with. Licensing changes regularly, so check Microsoft's current UK plan comparison before you buy.
Identity and access
Most attacks on Microsoft 365 start with a stolen sign in, usually from a phishing email. That makes identity the first place to spend time. The UK government's latest breaches survey suggests plenty of businesses still have work to do here.
| Control | Share of businesses | Percentage |
|---|---|---|
| Up to date malware protection | 81% | |
| Admin rights restricted to specific users | 73% | |
| Any two-factor authentication | 47% | |
| Security updates applied within 14 days | 34% | |
| Formal incident response plan | 25% |
Source: Cyber Security Breaches Survey 2025/2026, GOV.UK.
Fewer than half of UK businesses use any form of two-factor authentication, up from 40 per cent the year before. In Microsoft 365, MFA is free on every business plan, so there is no licensing reason for this number to be as low as it is.
Turn on Microsoft 365 MFA for every user
Multi-factor authentication asks for something beyond the password, such as an approval in the Microsoft Authenticator app, a passkey, a security key or Windows Hello. It stops most password-based attacks outright, because a stolen password is no longer enough on its own.
Every Microsoft 365 business tenant can use security defaults, a free set of settings that makes all users register for MFA, requires it for admins and blocks legacy authentication. New tenants have them switched on from the start. Older tenants often do not, especially ones that were set up before 2019 or had them turned off to get round a problem.
Microsoft now enforces MFA on its own admin portals, including the Microsoft 365 admin centre and the Entra and Intune admin centres. That protects admin sign ins to those portals. It does nothing for an ordinary member of staff signing in to Outlook.
The question to answer is whether every user is actually required to use MFA, including directors, admins and people who only work remotely. Having the Authenticator app on a phone is not the same thing. In the Entra admin centre, check that:
- every active user is covered by security defaults or a Conditional Access policy that requires MFA
- admins use a phishing resistant method, such as a passkey, a FIDO2 security key or Windows Hello for Business
- former staff are blocked from signing in
- shared mailboxes are not being signed in to directly with a shared password
- any exclusions from MFA are written down, with a reason and an owner
Use Conditional Access when security defaults are not enough
Business Premium includes Microsoft Entra ID P1, which gives you Conditional Access. Instead of one rule for everyone, you set conditions for who can sign in, from what, and from where. Typical policies for a small business are:
- require MFA for all users on all apps
- require a phishing resistant method for admin roles
- allow access to company data only from managed, compliant devices
- block sign ins from countries you never work in
- apply separate rules to guest users
Security defaults and Conditional Access cannot run together. Moving to Conditional Access means turning security defaults off, so build policies that cover everything security defaults did before you switch. New policies can run in report-only mode first, which logs what would have happened without blocking anyone. Leave them in that mode for a week or two and read the results. It is the easiest way to find the old app or the one director whose phone would have been locked out.
Lock down Microsoft 365 admin accounts
A Global Administrator can change anything in the tenant, including turning off the security settings on this list. If an attacker gets hold of one, they own your Microsoft 365 environment rather than a single mailbox.
In small businesses the usual story is that the founder got admin rights on day one because someone had to have them. Then the office manager needed to reset a password, so they got Global Administrator too, and then the finance director, and then the outgoing IT contractor. A few years on, nobody is sure who can change what. Here is what Microsoft recommends, and what we set up for clients.
| Check | What to set up |
|---|---|
| Separate accounts | Admins have a second account used only for admin work, with no mailbox for everyday email and browsing |
| Fewer Global Admins | Keep it to a small number of named people. Microsoft suggests fewer than five |
| Narrower roles | Use roles like User Administrator, Helpdesk Administrator or Exchange Administrator for day to day tasks |
| Emergency access | At least two cloud-only break glass accounts on your onmicrosoft.com domain, protected with a passkey or FIDO2 key |
| Monitoring | An alert fires whenever an emergency account signs in, and the accounts are tested every 90 days |
| Clean-up | Former admins and old IT suppliers have had their roles removed |
Emergency access accounts sound like overkill for a 20-person business until the day a Conditional Access policy locks every admin out, or the one person with admin rights leaves on bad terms. Keep their credentials somewhere physically separate from the people who use the normal admin accounts.
Block legacy authentication
Legacy authentication covers older protocols such as POP, IMAP and basic SMTP sign in. They cannot handle MFA, so an attacker with a password can use them to walk straight past it. Microsoft switched off basic authentication for most Exchange Online protocols in October 2022. SMTP AUTH, which many printers, scanners and line of business apps use to send email, is the main exception still around. Microsoft plans to disable it by default for existing tenants at the end of December 2026, and to announce a final removal date in the second half of 2027.
So if your scanner emails PDFs to staff, check how it signs in now rather than finding out when it stops working. The process we follow is:
- Find itCheck the Entra sign in logs for legacy authentication in use.
- Trace itWork out which device, app or mailbox is behind each sign in.
- Replace itUpdate the firmware, switch the device to OAuth or a relay, or retire the system.
- Block itTurn on security defaults or a Conditional Access policy that blocks legacy authentication.
- Watch itKeep an eye on the logs for a few weeks for anything you missed.
Control which apps can reach your data
Staff connect all sorts of tools to Microsoft 365: e-signature services, CRMs, project boards, accounting software, AI note takers and meeting schedulers. When someone clicks Accept on a consent prompt, that app may get ongoing access to their mailbox or files, and in some cases to data belonging to the whole organisation.
Tenants created recently default to a setting where Microsoft manages user consent and blocks users from granting the riskiest permissions, such as reading all files. Older tenants may still let anyone consent to anything. In the Entra admin centre, limit user consent to apps from verified publishers asking for low risk permissions, and turn on the admin consent workflow so staff can request anything else. Then go through the list of enterprise applications that already have access and remove what nobody uses.
Remove access when people leave or change role
Leavers are one of the most common gaps we find. An account stays active for weeks after someone has gone, still syncing email to a personal phone. Role changes are quieter but just as risky: someone moves from finance to sales and keeps access to the payroll folder. Agree a leaver process with HR that blocks sign in and revokes sessions on the last day, converts the mailbox if it needs keeping, and removes admin roles, group memberships and devices. Then check the list of active users against the payroll every quarter.
Microsoft 365 email security
Email is still how most attacks reach a business. Phishing is by some distance the most common type of breach or attack UK businesses report, and impersonation of the business or its staff comes a clear second.
| Type of attack | Share of businesses | Percentage |
|---|---|---|
| Phishing | 38% | |
| Impersonation by email or online | 12% | |
| Malware | 7% | |
| Online bank account hacking | 3% | |
| Account takeover | 2% | |
| Ransomware | 1% |
Source: Cyber Security Breaches Survey 2025/2026, GOV.UK. Among businesses that identified any breach, 88 per cent had been phished.
SPF, DKIM and DMARC
These three DNS records let receiving mail servers check whether an email that claims to come from your domain really did. Without them, anyone can send email that appears to come from your accounts team. Microsoft recommends all three for every custom domain, including domains you own but do not send from.
| Record | What it does | What to check |
|---|---|---|
| SPF | Lists the servers and services allowed to send email as your domain | It includes Microsoft 365 and every other service that sends for you, and nothing you have stopped using |
| DKIM | Adds a digital signature so the receiver can tell the message has not been altered | It is switched on for each custom domain in the Defender portal. Only the onmicrosoft.com domain is signed automatically |
| DMARC | Tells receivers what to do with mail that fails SPF and DKIM, and sends you reports | A record exists, the reports go to a mailbox someone reads, and the policy moves from none to quarantine or reject over time |
Be careful with SPF. It is tempting to add every marketing platform and invoicing tool anyone has ever used, but a long record is harder to trust and can break the lookup limit. Keep it to what actually sends email today. A DMARC record set to none with nobody reading the reports gives you almost nothing, so plan to tighten it once the reports show your legitimate mail passing.
Microsoft 365 phishing protection
Every Microsoft 365 mailbox gets Exchange Online Protection, which filters spam and malware and includes spoof protection. Defender for Office 365 Plan 1, which comes with Business Premium, adds impersonation protection for named people and domains, Safe Links, which checks a link when it is clicked rather than only when the email arrives, and Safe Attachments, which opens files in a sandbox before delivery and also covers SharePoint, OneDrive and Teams.
When reviewing these policies, look at:
- whether impersonation protection lists your directors, finance staff and your own domains
- whether Safe Links and Safe Attachments are applied to all users rather than a small pilot group
- how staff report suspicious messages, and who sees those reports
- allow list entries
The allow list is where we find the most trouble. Someone adds a supplier's whole domain to stop an invoice going to junk, and three years later every email from that domain skips filtering, including the one from the supplier's compromised mailbox. Use the Tenant Allow/Block List for specific, time-limited exceptions and remove old ones.
External email forwarding
One of the first things an attacker does inside a mailbox is set up a rule that forwards copies of incoming email to an address outside the business. It lets them keep watching after the password is changed and gives them what they need for invoice fraud.
The outbound spam policy in Microsoft 365 controls automatic external forwarding. The default setting, Automatic, blocks it for most tenants, but some older tenants still behave as if it is on, and Microsoft advises setting it explicitly. Set it to Off in the default policy and create a separate policy for any named mailbox that has a real business need to forward. Then check mailbox forwarding settings, inbox rules and mail flow rules for anything forwarding outside the organisation. This matters most in finance, legal, recruitment and consultancy firms, where email carries contracts, client data and payment details.
Device security
A secure account on an unmanaged, unpatched laptop is still a risk. Cloud settings only cover half the picture if the device holding a synced copy of your SharePoint library is someone's old home PC.
Microsoft Defender for Business
Defender for Business comes with Business Premium and is designed for organisations of up to 300 users. It protects Windows, macOS, iOS and Android devices with next-generation antivirus, endpoint detection and response, vulnerability management, and automated investigation that can clean up common threats without anyone stepping in. It also includes attack surface reduction rules and controlled folder access, which Microsoft positions as its ransomware mitigations. Servers need a separate licence.
What we check is whether it is doing its job on the devices that matter. The portal will happily show a green dashboard while half the laptops have never onboarded. Look at:
- device coverage against your actual device list
- onboarding status and last seen dates
- antivirus mode, since passive mode means another product is in charge
- security intelligence update status
- open vulnerabilities and the devices they affect
- antivirus exclusions, which tend to pile up and rarely get removed
- alerts, and who receives them
Retire devices that have not checked in for months. A device list full of old laptops makes it hard to see the ones that are really unprotected.
Microsoft Intune and device compliance
Intune is Microsoft's device management service, included in Business Premium as Intune Plan 1. It lets you push settings to company devices and define what a healthy device looks like. For a small business, sensible compliance rules include a minimum operating system version, BitLocker or FileVault encryption, a screen lock PIN or password, Defender running and up to date, and the firewall switched on.
Compliance becomes useful when you pair it with Conditional Access. A policy that requires a compliant device means a laptop that falls behind on updates, or a personal PC nobody has enrolled, cannot open company data until it is fixed. Build the compliance policies first and give devices time to report, or you will lock people out.
Operating system support matters here too. Windows 10 reached end of support on 14 October 2025. Any Windows 10 device still in use needs to be on Microsoft's paid Extended Security Updates or replaced, and an unsupported device will also cost you a Cyber Essentials pass.
Personal devices need a decision rather than a default. Many businesses let staff use their own phones for email, which is reasonable if the Outlook app is protected by an app protection policy that stops company data being copied into personal apps, and full device enrolment is not needed for that.
Files, Teams and sensitive data
Many businesses put real effort into sign in security and never look at file sharing. A strong login does nothing to protect a document that has already been shared with the wrong person.
SharePoint and OneDrive sharing
SharePoint and OneDrive make it very easy to share files, which is the point of them. The organisation-level sharing settings decide how easy. The one we look at first is whether Anyone links are allowed. These are links that work for whoever has them, with no sign in. They are convenient for sending a brochure to a prospect and a problem when they point at a folder of payslips.
A sensible setup for most SMEs is to allow sharing with named external people who have to verify their email address, turn Anyone links off or give them an expiry date, set the default link type to people in your organisation, and restrict sharing on your most sensitive sites further still. Then look at what has already been shared. The SharePoint admin centre can show externally shared content, and an old link to a finance or HR folder is a common find.
Microsoft Teams security
Teams sits on top of SharePoint, OneDrive and Entra ID, so most of its security comes from getting those right. There are a few Teams settings of its own worth checking: whether guests can be added to teams and by whom, whether staff can chat with people in any external organisation or only with named partner domains, and which apps can be added to Teams. Every team should have at least two owners who are still with the business, and inactive teams should be archived so their files and guest members are not forgotten.
Sensitivity labels and data loss prevention
Business Premium includes Microsoft Purview Information Protection, which gives you sensitivity labels that you can apply to files and emails, plus data loss prevention policies for Exchange, SharePoint and OneDrive. Labels can encrypt a document so it stays protected after it leaves the business. DLP can warn a user, or block them, when they try to email a spreadsheet full of National Insurance numbers to an outside address. Automatic labelling needs a higher licence, such as the Purview Suite add-on.
Start by listing the types of information you hold that would cause real harm if they leaked: customer personal data, financial records, employee files, contracts, and passwords or keys that have ended up in documents. Then create three or four labels with plain names, such as Public, Internal, Confidential and Restricted, that people can apply without thinking. A scheme with twelve labels that nobody uses protects nothing. Run DLP policies in test mode first so you can see what they would catch before they start blocking email.
Monitoring Microsoft 365 security
If something goes wrong, you need to be able to see it and work out what happened. That depends on two things: Secure Score for how your settings compare with Microsoft's recommendations, and the audit log and alerts for what is happening day to day.
Microsoft Secure Score
Secure Score, in the Defender portal, measures how many of Microsoft's recommended security settings you have in place. It lists recommended actions, shows how each one would change your score, and tracks the score over time. Used properly, it is a good to-do list.
Microsoft is clear that the score is not a measure of how likely you are to be breached. It shows how much of the available security you are using. A high score can still sit alongside a gap that matters a great deal to your business, and a low score can include points you are losing for features you have deliberately chosen not to use.
| Secure Score tells you | Secure Score does not tell you |
|---|---|
| Which recommended settings are on or off | How likely you are to be attacked |
| How your score has changed over time | Whether a setting is right for your business |
| Which actions carry the most points | Whether your backups can be restored |
| Which products each action affects | Who would notice an alert at 7pm on a Friday |
Rather than chasing a number, go through the open recommendations each quarter, deal with the high-impact ones that apply to you, and mark the rest as accepted risk with a note explaining why.
Audit logs and alerts
Mailbox auditing is on by default for every organisation and records what owners, delegates and admins do in each mailbox. The wider Microsoft 365 audit log covers sign ins, admin changes, sharing and much more. Microsoft switches it on by default for enterprise plans, but on business plans it is worth confirming in the Audit section of the Purview portal, because it is easy to miss on a tenant that was set up years ago. Standard audit records are kept for 180 days, and longer retention needs an add-on.
The events worth watching in a small business are:
- unusual sign ins, such as new countries or impossible travel
- new admin role assignments
- new inbox rules or forwarding
- new app consents
- large amounts of external sharing or file deletion
- Defender alerts for devices and email
Collecting logs is the easy part. What most small businesses lack is a person who looks at the alerts and knows which ones need action tonight. If you do not have that in-house, it is one of the areas where a managed IT provider earns its fee.
Backup, recovery and ransomware
Microsoft keeps your data available, but a user who deletes a folder, an attacker who wipes a mailbox, or a retention policy set up wrong can all remove data that Microsoft will not bring back for you after a certain point.
Microsoft 365 backup and recovery
SharePoint and OneDrive keep deleted items in a two-stage recycle bin for 93 days in total. Mailboxes have their own recoverable items period, and retention policies can hold data for longer. Microsoft also sells Microsoft 365 Backup, charged by the amount of data protected, and there are third party products that do the same job. Our Microsoft 365 backup guide covers the retention limits and the options in detail, so we will not repeat it here.
Retention and backup are different jobs. Retention decides how long information must be kept. Backup is about getting a usable copy back after something has gone wrong, quickly and to a point in time you choose. Your recovery plan should be able to answer these questions.
| Question | What it sets |
|---|---|
| What data is critical? | What you back up and restore first |
| How long can we work without it? | Your recovery time objective |
| How much recent work could we lose? | Your recovery point objective, and so how often you back up |
| Have we tested a restore? | Whether any of the above is real |
Microsoft 365 ransomware protection
No single setting stops ransomware. It takes several layers, each answering a different question about how an attack would unfold. Most of them are items already on this checklist.
| Question | Controls that answer it |
|---|---|
| Can an attacker get in? | MFA, Conditional Access, phishing protection, blocking legacy authentication |
| Can they move around? | Limited admin roles, separate admin accounts, device compliance |
| Can they reach important data? | Least privilege, sharing controls, sensitivity labels |
| Can they damage it? | Defender for Business, attack surface reduction rules, controlled folder access |
| Would we notice? | Audit logging, Defender alerts, someone watching them |
| Can we recover? | Tested backups held separately from the account that was compromised |
Microsoft 365, Cyber Essentials and UK GDPR
Cyber Essentials
The NCSC describes Cyber Essentials as the minimum standard of cyber security the government recommends for organisations of all sizes. The current requirements, version 3.3 with the Danzell question set, came into force on 27 April 2026. The five technical controls are the same as before, but two things changed that matter for Microsoft 365. Cloud services can no longer be left out of scope, and MFA must be turned on for every cloud service that offers it. Not having it is now an automatic fail. Applying high and critical security updates within 14 days is also an automatic fail if you miss it.
Much of the evidence for Cyber Essentials comes straight out of a well set up tenant.
| Cyber Essentials control | Where it lands in Microsoft 365 |
|---|---|
| Firewalls | Windows and macOS firewalls switched on and enforced through Intune |
| Secure configuration | Intune configuration profiles, unused accounts removed, MFA on every cloud service |
| Security update management | Windows Update rings and app updates managed through Intune, inside 14 days |
| User access control | Separate admin accounts, least privilege, a working leaver process |
| Malware protection | Microsoft Defender Antivirus running and managed through Defender for Business |
Certification is a baseline. It does not cover external sharing, app consent, email forwarding, audit logging or backup, all of which are on this checklist. Our Cyber Essentials guide covers the scheme and the April 2026 changes in more depth.
UK GDPR
Microsoft 365 almost always holds personal data, so how it is secured is part of your UK GDPR obligations. The ICO expects appropriate technical measures that protect the confidentiality, integrity and availability of personal data, and the ability to restore access in a timely way after an incident. A tenant with no MFA and no tested backup will be hard to defend on either count.
Security, IT, data protection and business continuity are often handled by different people, but one incident can land on all of them. A single compromised account can play out like this:
- An IT problemA member of staff reports odd emails going out from their account.
- A security incidentSomeone has signed in from abroad and set up a forwarding rule.
- A personal data breachThe mailbox held client personal data, which has now been seen by an outsider.
- A continuity problemThe account is locked while you investigate, and invoices and client work stop.
If a personal data breach is likely to put people's rights and freedoms at risk, you must report it to the ICO without undue delay and within 72 hours of becoming aware of it. That is very hard to do well without audit logs, clear ownership and an agreed response process.
Common Microsoft 365 security mistakes
These are the problems we find most often when we take over a Microsoft 365 tenant from another provider or from someone in-house.
| Mistake | What to do instead |
|---|---|
| Assuming Microsoft handles security | Microsoft secures the service. Your users, devices, sharing, apps and recovery are yours to set up |
| Stopping at MFA | Treat MFA as the first item on the list and keep going through admin roles, devices, email and sharing |
| Everyone is a Global Admin | Give people the narrowest role that does the job, and keep Global Admin for a few named accounts |
| Ignoring external sharing | Restrict Anyone links and review what has already been shared outside the business |
| Leaving external forwarding on | Set automatic forwarding to Off and allow named exceptions only |
| Installing Defender and not checking it | Compare onboarded devices against your real device list every month |
| Looking at Secure Score once a year | Review it every quarter as part of a regular check |
| Treating retention as backup | Back up separately and test a restore |
| Letting staff approve any app | Limit user consent and turn on the admin consent workflow |
| Switching on Conditional Access untested | Run policies in report-only mode first and write down every exclusion |
How often to review Microsoft 365 security
This is the rhythm we use for clients. The monthly checks are short once the tenant is set up properly, and the longer reviews are where most of the clean-up happens.
Every month
- Security alerts
- Unusual sign ins
- Admin role changes
- New app consents
- New forwarding rules
- Devices missing Defender
Every quarter
- Admin roles
- Inactive and guest users
- External sharing
- Secure Score actions
- Device compliance
- MFA and Conditional Access exclusions
Every 6 to 12 months
- The full baseline
- Licensing
- Backup and a test restore
- Incident response plan
- Cyber Essentials readiness
- Supplier access
Some changes should trigger a review straight away: an acquisition, a burst of hiring, a new office, a Microsoft 365 migration, rolling out Copilot or another AI tool, a new CRM or finance system, a change of IT provider, or any security incident.
A 30, 60 and 90 day plan
Trying to fix everything at once usually means half-finished changes and people locked out. We work in three stages, starting with the checks that stop the most common attacks.
Days 1 to 30
Foundations
Identity, email, visibility
Days 31 to 60
Stronger controls
Devices, access, sharing
Days 61 to 90
Resilience
Data, recovery, governance
| Area | Actions |
|---|---|
| Days 1 to 30 | |
| Identity | Enforce MFA, review Global Admins, create separate admin accounts, set up two emergency access accounts, remove former staff, review guests |
| Check SPF, enable DKIM, publish DMARC, set external forwarding to Off, review phishing policies and allow lists | |
| Visibility | Confirm the audit log is on, check who receives security alerts, note your starting Secure Score |
| Days 31 to 60 | |
| Devices | Enrol company devices in Intune, set compliance policies, check Defender coverage, turn on encryption, deal with unsupported operating systems |
| Access | Build Conditional Access in report-only mode, block legacy authentication, restrict access from unmanaged devices, tighten admin sign in |
| Sharing | Review SharePoint and OneDrive sharing settings, remove unneeded guests, check permissions on sensitive sites |
| Days 61 to 90 | |
| Data | List your sensitive information, create a small set of labels, test DLP policies, review retention |
| Recovery | Confirm backup covers mail, OneDrive, SharePoint and Teams, test a restore, agree recovery times and owners |
| Governance | Check against Cyber Essentials, record UK GDPR security measures, document exceptions, book the next review |
By the end you should have a written Microsoft 365 security baseline: a record of how the tenant is set up, why, and who owns each part. It is what you will be asked for by a Cyber Essentials assessor, an insurer or a client's security questionnaire.
A minimum standard for UK SMEs
For most small and medium-sized businesses, this is the position to aim for. Anything short of it is worth a conversation.
- Every user has MFA, and admins use a phishing resistant method.
- Admins work from separate accounts with the narrowest role they need.
- Two emergency access accounts exist and are monitored.
- Legacy authentication is blocked, or there is a dated plan to block it.
- Conditional Access is in use where the licence allows it.
- Company devices are managed, encrypted and running Defender.
- SPF, DKIM and DMARC are set up for every domain.
- Automatic external forwarding is off.
- SharePoint and OneDrive sharing is restricted and reviewed.
- Third party app access is controlled and reviewed.
- The audit log is on and someone acts on alerts.
- Secure Score recommendations are reviewed every quarter.
- Important data is backed up and a restore has been tested.
- Cyber Essentials requirements are met where you need certification.
- Your security measures support your UK GDPR obligations.
Microsoft 365 security FAQs
Is Microsoft 365 secure for small businesses?
Microsoft 365 has strong security features for email, identities and devices, but how well protected you are depends on your licence and, above all, on how the tenant is set up. Business Premium includes far more security than Business Basic or Standard. Either way, settings such as MFA, admin roles, sharing and forwarding need configuring by you or your IT provider.
Does Microsoft 365 include MFA?
Yes. Every Microsoft 365 business plan includes Microsoft Entra ID and security defaults, which require all users to register for MFA and block legacy sign in methods. Business Premium adds Conditional Access through Entra ID P1, which lets you set more detailed rules based on the user, device and location.
Is Microsoft 365 Business Premium more secure than Business Standard?
Business Premium includes Defender for Business, Defender for Office 365 Plan 1, Intune Plan 1, Entra ID P1 and Purview Information Protection, none of which come with Business Standard. Whether you need them depends on your devices, your data and how your staff work, but for most businesses with company laptops and remote staff, Premium is the better fit.
Do I need SPF, DKIM and DMARC with Microsoft 365?
Yes, if you send email from your own domain. Microsoft recommends configuring all three for every custom domain, including domains you do not send email from, so that nobody else can send mail that appears to come from you.
Should I disable external email forwarding in Microsoft 365?
For most businesses, yes. Attackers use forwarding rules to keep reading a mailbox after they have been locked out. Set automatic external forwarding to Off in the outbound spam policy, and allow it only for named mailboxes with a business reason.
What is Microsoft Secure Score?
Secure Score measures how many of Microsoft's recommended security settings your organisation has in place and suggests actions to improve it. Microsoft says it is not a measure of how likely you are to be breached, so use it as a to-do list rather than a grade.
Does Microsoft 365 protect against ransomware?
It helps at several points. MFA and email filtering make it harder to get in, and Defender for Business in Business Premium includes attack surface reduction rules and controlled folder access to limit damage on devices. Recovery is still your responsibility, so you need backups that are kept separately and have been tested.
Is Microsoft 365 enough for Cyber Essentials?
Microsoft 365 can provide much of the evidence, but Cyber Essentials covers your whole IT estate, including devices, firewalls and routers. Under version 3.3, in force since 27 April 2026, MFA must be on for every cloud service that offers it, and missing it is an automatic fail.
Is Microsoft 365 GDPR compliant?
Microsoft 365 provides security and compliance features that support your obligations, but compliance belongs to your organisation, not the software. The ICO expects appropriate measures that protect the confidentiality, integrity and availability of personal data, and that let you restore access after an incident.
How often should Microsoft 365 security be reviewed?
Check alerts, sign ins and admin changes monthly, review roles, guests, sharing and Secure Score quarterly, and carry out a full tenant review every six to twelve months. Review straight away after a major change such as a migration, an acquisition, a new IT provider or a security incident.
The bottom line
Microsoft 365 gives a UK business a good set of security tools, and most of them are already paid for. The work is in switching them on in the right order, checking they stay on, and making sure somebody notices when something changes. For businesses of ten to a few hundred people, the answer is rarely another security product. It is usually a tenant that has grown for years without anyone owning it.
A good review should leave you knowing what you are protecting, which controls are in place, where the gaps are, and who is fixing each one.
AIS Technology manages Microsoft 365, cloud, cyber security and day to day IT support for businesses across London and Essex. If your tenant has grown over time and you are not sure what is switched on, get in touch and we will go through it with you.
Sources
- Microsoft Learn, Microsoft 365 Business Premium security overview and Defender Suite for Business Premium, https://learn.microsoft.com/en-us/microsoft-365/admin/security-and-compliance/add-defender-suite-business-premium
- Microsoft Learn, Security defaults in Microsoft Entra ID, https://learn.microsoft.com/en-us/entra/fundamentals/security-defaults
- Microsoft Learn, Mandatory Microsoft Entra multifactor authentication, https://learn.microsoft.com/en-us/entra/identity/authentication/concept-mandatory-multifactor-authentication
- Microsoft Learn, Manage emergency access accounts in Microsoft Entra ID, https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/security-emergency-access
- Microsoft Learn, Conditional Access report-only mode, https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-conditional-access-report-only
- Microsoft Tech Community, Updated Exchange Online SMTP AUTH basic authentication deprecation timeline, January 2026, https://techcommunity.microsoft.com/blog/exchange/updated-exchange-online-smtp-auth-basic-authentication-deprecation-timeline/4489835
- Microsoft Learn, Configure how users consent to applications, https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/configure-user-consent
- Microsoft Learn, Set up DKIM to sign mail from your cloud domain, https://learn.microsoft.com/en-us/defender-office-365/email-authentication-dkim-configure
- Microsoft Learn, Microsoft Defender for Office 365 overview, https://learn.microsoft.com/en-us/defender-office-365/mdo-about
- Microsoft Learn, Control automatic external email forwarding, https://learn.microsoft.com/en-us/defender-office-365/outbound-spam-policies-external-email-forwarding
- Microsoft Learn, Microsoft Defender for Business overview, https://learn.microsoft.com/en-us/defender-business/mdb-overview
- Microsoft Learn, Require device compliance with Conditional Access, https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-all-users-device-compliance
- Microsoft Learn, Windows 10 Home and Pro lifecycle, https://learn.microsoft.com/en-us/lifecycle/products/windows-10-home-and-pro
- Microsoft Learn, Microsoft Purview service description, https://learn.microsoft.com/en-us/office365/servicedescriptions/microsoft-365-service-descriptions/microsoft-365-tenantlevel-services-licensing-guidance/microsoft-purview-service-description
- Microsoft Learn, Microsoft Secure Score, https://learn.microsoft.com/en-us/defender-xdr/microsoft-secure-score
- Microsoft Learn, Manage mailbox auditing and Turn auditing on or off, https://learn.microsoft.com/en-us/purview/audit-mailboxes
- Microsoft Learn, SharePoint and OneDrive data deletion, https://learn.microsoft.com/en-us/sharepoint/sharepoint-data-deletion
- National Cyber Security Centre, Cyber Essentials overview, https://www.ncsc.gov.uk/cyberessentials/overview
- IASME, Important update: changes to Cyber Essentials for April 2026, https://iasme.co.uk/articles/important-update-changes-to-cyber-essentials-for-april-2026/
- Information Commissioner's Office, A guide to data security, https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/a-guide-to-data-security/
- Information Commissioner's Office, Personal data breaches: a guide, https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/
- GOV.UK, Cyber security breaches survey 2025/2026, https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026

