How to secure Microsoft 365: the small-business hardening checklist
"Microsoft 365 does not arrive secure. Several of the settings that stop real attacks ship switched off, and turning them on is left to you. This is the checklist we work through in order: the three that matter most in week one, then everything after."
It is easy to assume a fresh Microsoft 365 tenant arrives locked down. It does not. Security defaults give a new tenant basic MFA, but they stop well short of a hardened configuration[1] - several of the settings that stop real attacks are switched off by default, and switching them on is left to you. Most of the highest-impact ones are free and quick, so the order below starts there.
This checklist is not our house opinion. It tracks two published, independently maintained standards: the CIS Microsoft 365 Foundations Benchmark, which specifies each setting and its recommended value[2], and CISA's Microsoft 365 Secure Configuration Baselines (the SCuBA project), which is the configuration US federal agencies are required to meet[3]. Where we deviate from either - usually to keep a small team workable - we say so.
Start with the critical three
If you get to nothing else this month, get to these. A week is enough, and they shut the doors attackers lean on first.
1Turn on MFA for everyone. Microsoft's own measurement study of Entra accounts put the effect at a 99.22% reduction in compromise risk, and 98.56% even for accounts whose password had already leaked[4]; Microsoft now states the figure as blocking more than 99.2% of account-compromise attacks and has made MFA mandatory for Azure sign-ins on that basis[5]. On Business Premium it costs nothing extra. There is no case for leaving it off, admins included.
Reduction in account compromise risk with MFA enabled
Reduction in compromise risk
All accounts studied
Accounts whose password had leaked
Measured across Microsoft Entra accounts rather than modelled. The second bar is the one that matters most: MFA still removes almost all of the risk after the password is already in someone else's hands.
Show the data
Horizontal bar chart showing MFA reduced account compromise risk by 99.22% across all accounts studied and by 98.56% for accounts whose password had already leaked.
2Block legacy authentication. Old sign-in methods such as basic POP, IMAP and SMTP cannot use MFA, which is exactly why attackers reach for them[6]. Blocking them is free and shuts the gap.
3Set up email authentication. Configure SPF, DKIM and DMARC, with DMARC set to reject, so nobody can send mail that appears to come from your domain to your own staff and customers.
Identity and access
Most breaches start with a login, so identity is where the bulk of the work sits. Beyond the critical three:
Add Conditional Access, so a risky sign-in from an unfamiliar place or device gets challenged or blocked on its own.
Move admins onto phishing-resistant MFA, whether that is the Authenticator app or a FIDO2 security key.
Give the admin accounts extra protection, and keep one break-glass account aside for the day you are locked out.
Email protection beyond authentication
Email is the most common way in, so it is worth hardening past SPF and DKIM:
Turn on Safe Links and Safe Attachments, which check links and files the moment someone clicks or opens them.
Switch on anti-phishing and impersonation protection, which has to be configured explicitly for your own domain and named executives[7].
Raise an alert on any new mailbox forwarding rule. Mail quietly forwarding to an outside address is a familiar sign of an account that has been taken over.
Protecting the data itself
With identity and email in hand, turn to the files:
Data Loss Prevention policies stop sensitive details, such as ID numbers or card data, leaving by email or link.
Sensitivity labels attach encryption and access rules to the file itself, so it stays protected even after it is forwarded on.
Devices and monitoring
Last, the machines and the ongoing view:
Enrol devices in Intune, enforce encryption, and keep company data off devices that are out of compliance.
Turn on Defender for Business, so threats are caught by how they behave rather than only by known signatures.
Set a Secure Score baseline and review it monthly, so the protection you set up does not slip over time.
What each starting point actually covers
Capability grid comparing Microsoft security defaults, this checklist and the CIS Microsoft 365 benchmark across six controls. Security defaults cover MFA only; the checklist adds impersonation protection, audit logging and device compliance.
Capability
Security defaults
This checklist
CIS benchmark
MFA on every account
Covered
Covered
Covered
Legacy authentication blockedSecurity defaults block most legacy protocols but leave no room for exceptions or staged rollout.
Partly covered
Covered
Covered
Impersonation protection for your domain and named users
Not covered
Covered
Covered
Audit logging and alert policies reviewed
Not covered
Covered
Covered
Device compliance enforced before access
Not covered
Covered
Covered
Setting-level hardening across the whole tenantThe full benchmark runs to hundreds of settings - useful as a target, heavy as a starting point.
Not covered
Partly covered
Covered
Covered
Partly covered
Not covered
Security defaults are a floor, not a baseline. This checklist is the working middle: everything that changes your exposure, without the several hundred settings a full benchmark asks for.
TechSuit comparison of Microsoft security defaults, this checklist and the CIS Microsoft 365 Foundations Benchmark.
The licence you need for this
Most of these tools sit in Microsoft 365 Business Premium, or E3 for larger teams. Basic and Standard leave them out. When security is the point, Premium is the floor, and that is usually where we start.
A realistic timeline
The critical three take about a week. Fuller hardening, with Conditional Access, data protection and device policies, tends to run four to eight weeks for a small business, plus some tuning after that. It does not all have to happen at once, as long as the three that matter most come first.
Questions we get asked
Sources
Every figure in this article traces back to a named source. Where we quote our own numbers, they come from work we have done with small businesses in Israel and across Europe, and we say so.
Want to know where Microsoft 365 is leaving you exposed?
Book a free 30-minute call. We'll run your Secure Score, show you the gaps, and give you a prioritised list - what to fix this week, and what can wait.