Support Area

Best Microsoft 365 Security Settings for SMEs

Set the best Microsoft 365 security settings for your organisation, reducing account compromise, data loss and disruption without hindering daily work.

Microsoft 365 security and productivity platform logo representing cloud services, cyber security, collaboration tools, and business solutions for SMEs.
Microsoft 365 security and productivity platform logo representing cloud services, cyber security, collaboration tools, and business solutions for SMEs.

A compromised Microsoft 365 account is rarely just an email problem. It can expose finance records, pupil or employee data, shared files and supplier conversations in minutes. The best Microsoft 365 security settings reduce that risk at the point where most attacks begin: identity, email and unmanaged access.

For SMEs, schools and Multi-Academy Trusts, the aim is not to turn every security control to its highest setting and hope for the best. It is to build a practical security baseline that protects sensitive information while allowing staff to teach, communicate and work without unnecessary friction. The right configuration depends on your licences, the devices in use and how information moves around the organisation, but several controls should be treated as non-negotiable.

Best Microsoft 365 security settings to prioritise

Require multi-factor authentication for every user

Multi-factor authentication, or MFA, remains one of the strongest defences against stolen passwords. It should be required for all users, not only administrators or remote workers. Email credentials are routinely targeted through phishing pages, password spraying and reused passwords from unrelated breaches. MFA prevents a password alone from becoming the key to your tenant.

Use Microsoft Authenticator or FIDO2 security keys where possible. Text-message verification is better than no MFA, but it is more vulnerable to SIM-swap fraud and social engineering. For organisations with a mixture of office-based staff, mobile workers and shared devices, conditional access policies can require MFA according to risk, location, application or device status.

Avoid a blanket policy that challenges users constantly. Repeated prompts lead to fatigue and, in some cases, approval of fraudulent sign-in requests. Use number matching in Authenticator and establish sensible sign-in frequency rules. Emergency access accounts should be excluded from normal conditional access policies, protected with long unique passwords and closely monitored. These accounts are for genuine recovery only, not day-to-day administration.

Block legacy authentication and control risky sign-ins

Older mail protocols can bypass modern authentication and MFA. Unless there is a documented business reason to retain them, block legacy authentication across Exchange Online and other Microsoft 365 services. Before making the change, identify scanners, multifunction printers, line-of-business applications and older email clients that may still rely on it. Replace outdated methods rather than leaving a permanent exception.

Conditional access should also prevent access from countries where your organisation has no legitimate operations, where appropriate. Location-based blocking is not a complete defence – attackers can use UK-based infrastructure – but it reduces unnecessary exposure. More valuable still are policies that require compliant or hybrid-joined devices for access to sensitive systems, and that respond to high-risk sign-ins identified by Microsoft Entra ID.

A school or Trust may need a different approach for staff travelling on educational visits or accessing services from home. The policy should support legitimate work while ensuring that an unfamiliar sign-in, impossible travel alert or compromised credential triggers an appropriate response.

Protect administrator accounts with least privilege

Global Administrator should be rare, not a standard job title. Every permanent administrative role increases the potential impact of a compromised account. Assign the lowest role that permits the task, review role assignments regularly and use separate accounts for administrative work.

Where licensing allows, Privileged Identity Management provides time-limited, approved access to elevated roles. This is particularly useful for internal IT teams and co-managed environments, where responsibilities are shared. It creates a clearer record of who had privileged access, when they used it and why.

At a minimum, protect administrator accounts with phishing-resistant MFA, restrict them from routine email and web browsing, and alert on changes to privileged roles. An attacker who gains Global Administrator access can alter security policies, create forwarding rules and register their own authentication methods. That is why identity protection must come before almost every other control.

Strengthen phishing and malware protection

Microsoft Defender for Office 365 provides useful protections against impersonation, malicious attachments and dangerous links, but the policies need to be checked rather than assumed. Anti-phishing policies should protect senior leaders, finance personnel and anyone whose identity is likely to be impersonated. Add trusted domains and key suppliers carefully, but do not create broad allow lists that weaken filtering.

Safe Links should scan links at the point of click, including links that appeared harmless when an email arrived but were later weaponised. Safe Attachments should detonate suspicious attachments before they reach users. These controls can occasionally delay delivery or quarantine legitimate mail, so establish a clear release process and review false positives. Convenience is not a reason to bypass the protection altogether.

External email tagging is another practical measure. A clear marker for messages originating outside the organisation helps staff spot impersonation attempts, particularly where a supplier name or executive’s writing style has been copied. It should support awareness training, not replace it.

Secure Microsoft 365 data without stopping collaboration

Set clear rules for OneDrive, SharePoint and Teams sharing

Most data exposure is caused by sharing settings, not a dramatic hack. Review tenant-wide sharing first, then apply tighter controls to sites that contain HR records, safeguarding information, finance data or confidential commercial documents.

Anonymous “Anyone” links are convenient, but they cannot identify who accessed the file and can be forwarded beyond the intended recipient. For most organisations, “Specific people” links with expiry dates are a better default. Limit external sharing to approved domains where that reflects normal business activity, and give site owners clear responsibility for reviewing access.

Teams deserves the same attention. Guest access can be necessary for governors, contractors, project partners or external IT specialists, but it must be controlled. Decide who can invite guests, what they can do, and whether they should be able to access shared channels or download files. Regularly remove inactive guests and review external collaboration in high-risk teams.

Apply sensitivity labels and data loss prevention thoughtfully

Sensitivity labels help users classify information and apply consistent handling rules, such as encryption, visual markings or restrictions on external sharing. Start with a small, understandable set of labels. For example: Public, Internal, Confidential and Highly Confidential. A long list of near-identical choices will be ignored or misused.

Data loss prevention policies can then identify sensitive information such as payment card data, National Insurance numbers, pupil records or health-related information. Begin in audit mode. This shows how policies would affect real work before they block activity, allowing rules and exceptions to be refined. A rushed deployment can prevent legitimate finance processes or secure information-sharing with appropriate external professionals.

For education organisations, the data categories and retention expectations should reflect safeguarding duties, the age of users and the systems connected to Microsoft 365. Technical settings should reinforce established governance, not attempt to replace it.

Make devices and monitoring part of the security baseline

A secure cloud account can still be accessed from an unpatched, infected or lost device. Use Microsoft Intune or an equivalent management platform to require supported operating systems, device encryption, screen locks and current security updates. Conditional access can then limit access from devices that do not meet those requirements.

Endpoint protection should be centrally managed, with alerts investigated rather than simply collected. Microsoft Defender for Business or Defender for Endpoint can provide visibility into suspicious activity across laptops and desktops, depending on your licence level. For smaller organisations, this monitoring is often where a proactive managed IT partner adds the most value: alerts need ownership outside normal office hours, not just a dashboard.

Enable unified audit logging and ensure logs are retained for a period that supports your incident-response and compliance needs. Review high-value alerts, including unusual mailbox forwarding rules, mass downloads, changes to MFA methods, creation of new admin accounts and suspicious sign-ins. A good configuration is only effective if someone notices when it is challenged.

Do not rely on Microsoft 365 as your only backup

Microsoft 365 includes resilience features, but that is not the same as a complete backup strategy. Accidental deletion, malicious encryption, retention gaps and intentional removal by a compromised account can all create recovery problems. Back up Exchange Online, OneDrive, SharePoint and Teams data to meet your organisation’s recovery objectives.

Test restoration as well. The useful question is not whether a backup exists, but whether the organisation can recover a specific mailbox, a folder of confidential files or a deleted Team quickly enough to avoid operational disruption.

The strongest Microsoft 365 configuration is reviewed as the organisation changes. New staff, new devices, third-party applications and changing collaboration needs all create risk. A scheduled security review keeps policies aligned with how people actually work, so protection remains practical rather than becoming a barrier to the services your organisation depends on.