Skip to main content
Cyber Resilience9 min read

How to secure Microsoft 365: the small-business hardening checklist

"Microsoft 365 does not arrive secure. Several of the settings that stop real attacks ship switched off, and turning them on is left to you. This is the checklist we work through in order: the three that matter most in week one, then everything after."

Author

Lior Refael

Published

Jul 12, 2026

Back to Articles

Microsoft 365 is not secure out of the box

It is easy to assume a fresh Microsoft 365 tenant arrives locked down. It does not. Security defaults give a new tenant basic MFA, but they stop well short of a hardened configuration[1] - several of the settings that stop real attacks are switched off by default, and switching them on is left to you. Most of the highest-impact ones are free and quick, so the order below starts there.

This checklist is not our house opinion. It tracks two published, independently maintained standards: the CIS Microsoft 365 Foundations Benchmark, which specifies each setting and its recommended value[2], and CISA's Microsoft 365 Secure Configuration Baselines (the SCuBA project), which is the configuration US federal agencies are required to meet[3]. Where we deviate from either - usually to keep a small team workable - we say so.

Start with the critical three

If you get to nothing else this month, get to these. A week is enough, and they shut the doors attackers lean on first.

  1. Turn on MFA for everyone. Microsoft's own measurement study of Entra accounts put the effect at a 99.22% reduction in compromise risk, and 98.56% even for accounts whose password had already leaked[4]; Microsoft now states the figure as blocking more than 99.2% of account-compromise attacks and has made MFA mandatory for Azure sign-ins on that basis[5]. On Business Premium it costs nothing extra. There is no case for leaving it off, admins included.

Reduction in account compromise risk with MFA enabled

Reduction in compromise risk

All accounts studied
Accounts whose password had leaked

Measured across Microsoft Entra accounts rather than modelled. The second bar is the one that matters most: MFA still removes almost all of the risk after the password is already in someone else's hands.

Show the data
Horizontal bar chart showing MFA reduced account compromise risk by 99.22% across all accounts studied and by 98.56% for accounts whose password had already leaked.
Reduction in compromise riskRisk reduction
All accounts studied99.22%
Accounts whose password had leaked98.56%

Source: Microsoft, How effective is multifactor authentication at deterring cyberattacks? (2023)

  1. Block legacy authentication. Old sign-in methods such as basic POP, IMAP and SMTP cannot use MFA, which is exactly why attackers reach for them[6]. Blocking them is free and shuts the gap.
  2. Set up email authentication. Configure SPF, DKIM and DMARC, with DMARC set to reject, so nobody can send mail that appears to come from your domain to your own staff and customers.

Identity and access

Most breaches start with a login, so identity is where the bulk of the work sits. Beyond the critical three:

  • Add Conditional Access, so a risky sign-in from an unfamiliar place or device gets challenged or blocked on its own.
  • Move admins onto phishing-resistant MFA, whether that is the Authenticator app or a FIDO2 security key.
  • Give the admin accounts extra protection, and keep one break-glass account aside for the day you are locked out.

Email protection beyond authentication

Email is the most common way in, so it is worth hardening past SPF and DKIM:

  • Turn on Safe Links and Safe Attachments, which check links and files the moment someone clicks or opens them.
  • Switch on anti-phishing and impersonation protection, which has to be configured explicitly for your own domain and named executives[7].
  • Raise an alert on any new mailbox forwarding rule. Mail quietly forwarding to an outside address is a familiar sign of an account that has been taken over.

Protecting the data itself

With identity and email in hand, turn to the files:

  • Data Loss Prevention policies stop sensitive details, such as ID numbers or card data, leaving by email or link.
  • Sensitivity labels attach encryption and access rules to the file itself, so it stays protected even after it is forwarded on.

Devices and monitoring

Last, the machines and the ongoing view:

  • Enrol devices in Intune, enforce encryption, and keep company data off devices that are out of compliance.
  • Turn on Defender for Business, so threats are caught by how they behave rather than only by known signatures.
  • Set a Secure Score baseline and review it monthly, so the protection you set up does not slip over time.

What each starting point actually covers

Capability grid comparing Microsoft security defaults, this checklist and the CIS Microsoft 365 benchmark across six controls. Security defaults cover MFA only; the checklist adds impersonation protection, audit logging and device compliance.
CapabilitySecurity defaultsThis checklistCIS benchmark
MFA on every accountCoveredCoveredCovered
Legacy authentication blockedSecurity defaults block most legacy protocols but leave no room for exceptions or staged rollout.Partly coveredCoveredCovered
Impersonation protection for your domain and named usersNot coveredCoveredCovered
Audit logging and alert policies reviewedNot coveredCoveredCovered
Device compliance enforced before accessNot coveredCoveredCovered
Setting-level hardening across the whole tenantThe full benchmark runs to hundreds of settings - useful as a target, heavy as a starting point.Not coveredPartly coveredCovered
  • Covered
  • Partly covered
  • Not covered

Security defaults are a floor, not a baseline. This checklist is the working middle: everything that changes your exposure, without the several hundred settings a full benchmark asks for.

TechSuit comparison of Microsoft security defaults, this checklist and the CIS Microsoft 365 Foundations Benchmark.

The licence you need for this

Most of these tools sit in Microsoft 365 Business Premium, or E3 for larger teams. Basic and Standard leave them out. When security is the point, Premium is the floor, and that is usually where we start.

A realistic timeline

The critical three take about a week. Fuller hardening, with Conditional Access, data protection and device policies, tends to run four to eight weeks for a small business, plus some tuning after that. It does not all have to happen at once, as long as the three that matter most come first.

Questions we get asked

Sources

Every figure in this article traces back to a named source. Where we quote our own numbers, they come from work we have done with small businesses in Israel and across Europe, and we say so.

  1. Security defaults in Microsoft Entra IDMicrosoft Learn · 2026What security defaults do and do not enable, and where they stop being sufficient. (opens in a new tab)
  2. CIS Microsoft 365 Foundations BenchmarkCenter for Internet Security · 2026An independent, setting-level hardening baseline to check your tenant against. (opens in a new tab)
  3. Secure Cloud Business Applications (SCuBA) - Microsoft 365 Secure Configuration BaselinesCISA · 2025US federal baseline configuration for Microsoft 365, used as the independent standard behind this checklist. (opens in a new tab)
  4. How effective is multifactor authentication at deterring cyberattacks?Microsoft · 202399.22% reduction in compromise risk overall and 98.56% for accounts with a leaked password. (opens in a new tab)
  5. Plan for mandatory Microsoft Entra multifactor authenticationMicrosoft Learn · 2026Microsoft's own position that MFA blocks more than 99.2% of account compromise attacks, and the enforcement timeline. (opens in a new tab)
  6. Block legacy authentication with Conditional AccessMicrosoft Learn · 2026Why legacy authentication bypasses MFA, and how to block it without breaking clients. (opens in a new tab)
  7. Anti-phishing policies in Microsoft 365Microsoft Learn · 2026Impersonation protection for your own domain and named users has to be configured explicitly - it is not on by default. (opens in a new tab)
  8. Microsoft Secure ScoreMicrosoft Learn · 2026The in-tenant measure of configuration posture and which improvement actions move it. (opens in a new tab)

Figures last checked 28 July 2026

Want to know where Microsoft 365 is leaving you exposed?

Book a free 30-minute call. We'll run your Secure Score, show you the gaps, and give you a prioritised list - what to fix this week, and what can wait.