12 Best Microsoft 365 Security Settings for SMBs

12 Best Microsoft 365 Security Settings for SMBs

A compromised Microsoft 365 account can do more than send a few suspicious emails. It can expose payroll files, redirect invoices, give an attacker access to shared documents, and disrupt daily operations. The best Microsoft 365 security settings reduce those risks without making your team jump through unnecessary hoops every time they sign in.

For small and medium-sized businesses, the goal is not to turn Microsoft 365 into a complicated security project. It is to make sensible controls standard, verify that they are working, and adjust them as your staff, devices, and compliance needs change. Here are the settings that deserve attention first.

Best Microsoft 365 Security Settings to Prioritize

1. Require multifactor authentication for every user

Multifactor authentication, or MFA, should be non-negotiable for employees, administrators, contractors, and shared administrative accounts. A stolen password is still one of the simplest ways into a business environment. MFA adds a second check, such as an authenticator app prompt or number match, that makes a password alone far less useful to an attacker.

Use the Microsoft Authenticator app or a security key where practical. Text-message codes are better than no MFA, but they are more vulnerable to SIM-swap attacks and social engineering. Also make sure users register more than one recovery method. A lost phone should create a manageable support request, not lock an employee out for a day.

2. Block legacy authentication

Older email and productivity protocols can bypass modern sign-in protections, including MFA. Attackers know this, which is why password-spray attacks often target legacy authentication first.

Disable legacy authentication across the tenant unless a verified business requirement remains. If an older copier, scanner, line-of-business application, or email relay still depends on it, do not simply leave the door open for everyone. Identify the device, isolate the exception, use the least-privileged method available, and set a deadline to replace or modernize it.

3. Use Conditional Access to control risky sign-ins

Conditional Access lets you decide when a sign-in should be allowed, blocked, or challenged for additional verification. For many businesses, a sound starting point is to require MFA for all users, block sign-ins from locations where the company has no legitimate business activity, and require compliant devices for access to sensitive resources.

This is one area where licensing and configuration matter. Microsoft 365 Business Premium and certain enterprise plans provide stronger Conditional Access capabilities than basic plans. Avoid broad geographic blocks if your staff travels, works internationally, or relies on third-party services that may originate from other regions. The setting should reflect how your business actually operates, not just a generic security checklist.

4. Separate admin accounts from daily work accounts

No employee should use a global administrator account to read email, browse the web, or open attachments. Administrators are high-value targets because a single compromised admin account can change security policies, create new users, or access large amounts of company data.

Give each administrator a separate account used only for administrative work. Assign the lowest role that gets the job done, rather than making everyone a global administrator for convenience. Review privileged roles regularly, remove former employees promptly, and maintain at least two secured emergency access accounts for a true lockout scenario. Those accounts should be monitored carefully and never used for routine work.

5. Turn on anti-phishing, Safe Links, and Safe Attachments

Email remains the most common delivery method for business fraud and malware. Microsoft Defender protections can identify impersonation attempts, scan attachments, and check web links at the time a user clicks them.

Configure anti-phishing policies to protect executives, finance staff, HR, and anyone authorized to change bank information or approve payments. Enable mailbox intelligence and impersonation protection, then send suspicious messages to quarantine instead of deleting them immediately. Quarantine gives your IT team a chance to review a false positive without training employees to ignore security warnings.

Safe Links and Safe Attachments are especially valuable because malicious content can change after an email has been delivered. These protections may require Microsoft Defender for Office 365 licensing, so confirm what your plan includes rather than assuming every feature is active.

6. Stop automatic external email forwarding

Attackers who gain access to a mailbox often create hidden forwarding rules to copy messages outside the company. This gives them ongoing visibility into conversations, invoices, customer requests, and password-reset emails even after the initial suspicious sign-in is noticed.

Block automatic forwarding to external domains by default. If a department has a legitimate need to forward mail to a trusted partner or service, create a documented exception and review it periodically. Pair this control with alerts for newly created inbox rules, unusual forwarding behavior, and sign-ins from unfamiliar locations.

7. Set practical external sharing rules for OneDrive and SharePoint

File sharing is productive until a sensitive folder is accessible to the wrong person. Review external sharing settings for SharePoint, OneDrive, and Teams, then decide what level of access your business truly needs.

For most organizations, authenticated guest access is safer than anonymous “anyone with the link” sharing. Set link expiration dates, limit downloads where appropriate, and prevent employees from sharing with unmanaged personal accounts when that creates a compliance or confidentiality issue. Finance, HR, legal, and executive folders often need stricter rules than general project collaboration spaces.

Security should not force staff back to emailing attachments. The better approach is to provide a secure sharing process that is easier than the workaround.

8. Manage devices with Intune and require encryption

Microsoft 365 security is only as strong as the laptops and mobile devices connecting to it. A lost, unpatched, or personally shared computer can expose data even when the user has a strong password.

Use Microsoft Intune or another managed device platform to enforce screen locks, operating system updates, antivirus protection, disk encryption, and the ability to remove company data from a lost device. Require BitLocker encryption on Windows devices and establish clear rules for mobile access.

Bring-your-own-device policies need a balanced approach. Some businesses should require full device management before granting access to company email. Others may use app-level protection that secures Outlook, Teams, and OneDrive data without taking control of an employee’s personal phone. The right answer depends on the sensitivity of your data and the expectations you set with staff.

9. Enable auditing and review security alerts

A security setting has limited value if no one knows when it is triggered. Confirm that audit logging is enabled and retained for a period that supports your operational and compliance needs. Review alerts for impossible travel, repeated failed sign-ins, risky users, unusual mailbox activity, and privileged role changes.

Small businesses do not need someone staring at a dashboard all day. They do need clear ownership. Assign alerts to an internal leader or an outsourced IT partner that can investigate quickly, document the event, and act before a suspicious sign-in turns into a business interruption.

10. Apply data loss prevention where it matters most

Data loss prevention, or DLP, can identify sensitive information such as Social Security numbers, payment card data, health information, or financial records before it is emailed or shared inappropriately. Start with the data categories that create the greatest legal, financial, or reputational exposure for your organization.

Begin in test mode where possible. A policy that blocks every spreadsheet or customer email will frustrate employees and encourage workarounds. Tune the rules, add justified exceptions, and make the warning messages clear enough that users understand what they need to do next.

11. Protect against ransomware with backup outside Microsoft 365

Microsoft 365 includes retention, version history, and recycle bins, but those features are not the same as a complete backup strategy. Accidental deletion, malicious mass deletion, retention gaps, and account compromise can still create difficult recovery situations.

Back up Exchange Online, OneDrive, SharePoint, and Teams data to a separate protected platform. Test restoration regularly. The question is not whether a backup report says “successful” – it is whether you can restore a specific mailbox, file set, or SharePoint site within the time your business can tolerate.

12. Review settings after every business change

New hires, acquisitions, office moves, new vendors, and changes in remote-work practices all affect your security posture. Security settings should be reviewed at least quarterly and whenever a meaningful operational change occurs.

At Proactive Data, we see the best results when Microsoft 365 security is managed as part of day-to-day IT operations, not treated as a one-time setup. A well-configured tenant still needs account reviews, patching, user education, alert response, and tested recovery procedures.

The right settings give your people room to work while making it much harder for a stolen password, deceptive email, or lost device to become a costly incident. Start with identity protection and email security, then build outward from there with controls your team can consistently support.