Reliable Networks | Managed IT and Cyber Security Experts

Microsoft 365 Is Not Secure by Default: 10 Settings Every SME Should Review Today

Microsoft 365 Security: 10 Settings SMEs Must Review
Assigning Microsoft 365 licences across an organisation gives staff immediate access to powerful productivity tools. However, many business leaders operate under the dangerous assumption that moving to the cloud automatically provides complete protection against modern cyber threats.
 
In reality, Microsoft delivers an environment configured for maximum usability and convenience out of the box, not maximum security. While Microsoft builds enterprise-grade security tools into the platform, ensuring those tools are properly configured, enforced, and monitored remains the sole responsibility of your business.
 
Achieving a strong Microsoft 365 security posture requires moving beyond default settings to ensure your tenant matches established SME cyber security standards.

The Myth: “Microsoft Takes Care of Security”

A critical concept every SME leadership team must understand is the Shared Responsibility Model.
Microsoft guarantees the physical security of their data centres, server hardware uptime, and global cloud infrastructure resilience. However, you remain entirely responsible for:
 
  • User identity and credentials
  • Device compliance and endpoint health
  • Data governance and access permissions
  • Tenant-level configurations
     
The vast majority of business email compromises and cloud data breaches do not happen because a hacker cracked Microsoft’s underlying infrastructure. They occur because attackers exploited configuration gaps, unmonitored guest access, or weak login policies within an individual business’s tenant.

The 10 Microsoft 365 Settings Every SME Should Review

To align your environment with Microsoft 365 best practice, review these ten critical configuration areas immediately.

1. Multi-Factor Authentication (MFA) Enforcement

Optional MFA leaves your business exposed. If even a single user account is left without mandatory MFA, attackers can use basic password spraying to gain a foothold. MFA must be enforced universally for all accounts, preferably using authenticator apps rather than vulnerable SMS push notifications.

2. Conditional Access Policies

Conditional Access acts as the intelligent gatekeeper for your tenant. Rather than allowing logins from anywhere at any time, Conditional Access evaluates context in real time. It allows you to restrict access based on user risk, geographical location, and whether the connecting device meets corporate security compliance standards.

3. Legacy Authentication Blocking

Older email protocols like POP3, IMAP, and older versions of SMTP do not support modern authentication protocols. Crucially, they cannot enforce Multi-Factor Authentication. Attackers routinely target legacy auth protocols specifically to bypass MFA enforcement on protected accounts. Blocking legacy authentication tenant-wide is one of the quickest ways to stop automated credential attacks.

4. Privileged Access Controls

Over-privileging staff accounts creates catastrophic blast radius potential if credentials are compromised. As a strict rule, SMEs should maintain no more than two to four Global Administrator accounts. Furthermore, administrators should use separate, dedicated accounts for admin tasks rather than running their daily email and web browsing from an administrative profile.

5. External Sharing Settings

By default, SharePoint Online and OneDrive allow users to generate “Anyone with the link” anonymous access links. This makes oversharing sensitive commercial data incredibly easy. Review your external sharing controls to require authenticated logins for external partners and apply mandatory expiration dates on shared files.

6. Secure Defaults for SharePoint and Teams

Prevent staff from creating unmonitored, public Microsoft Teams or SharePoint sites. Setting strict defaults for team creation prevents shadow IT and ensures guest access permissions are scoped appropriately across all collaborative channels.

7. Defender for Office 365 Configuration

If your licensing includes Defender for Office 365, relying on basic spam filtering is not enough. You must actively configure and tune:
  • Safe Links: Scans URLs in real time when clicked inside emails or Teams chats.
  • Safe Attachments: Detonates incoming files in a virtual sandbox before delivering them to inboxes.
  • Anti-Phishing Policies: Protects against domain spoofing and executive impersonation.

8. Email Authentication (SPF, DKIM, DMARC)

Properly configuring Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication (DMARC) prevents cybercriminals from sending spoofed emails that look like they originated directly from your company domain. Setting DMARC to a strict “quarantine” or “reject” policy protects both your brand reputation and your supply chain.

9. Data Retention and Recovery

A common misconception is that Microsoft 365 provides full data backup. Microsoft maintains short-term recycle bins, but they do not offer long-term point-in-time recovery against ransomware encryption, malicious deletion, or retention policy errors. Implementing dedicated cloud-to-cloud Backup & Disaster Recovery ensures your commercial data remains recoverable in any scenario.

10. Audit Logging and Alerting

The Microsoft 365 Unified Audit Log must be explicitly enabled and monitored. Without audit logging, investigating a potential security incident or proving data compliance becomes impossible. Ensure automated alerting is configured for high-risk activities, such as inbox forwarding rules created immediately after a login or mass file downloads.

Common M365 Security Mistakes We See in the Field

During our technical audits, we regularly identify recurring configuration errors that leave organisations vulnerable:
  • Shared Admin Credentials: Multiple IT staff or external vendors logging into a single, shared Global Admin account, destroying audit accountability.
  • Active Ex-Staff Accounts: Former employees retaining active licenses and valid credentials weeks or months after leaving the business.
  • No Geo-Blocking: Allowing login attempts from countries where the business has no employees, partners, or operations.
  • Unmanaged Teams Guests: External contractors added to internal Teams channels years ago who still retain full access to sensitive documents.
  • No Active Alerting: Having audit logs turned on, but with zero real-time alerts configured for suspicious administrative changes or inbox rule creation.

Is Your Microsoft 365 Tenant Secure?

Leaving your tenant configured with default settings puts your sensitive operational data, financial assets, and client trust at risk.
If you have not conducted a formal Microsoft 365 security review in the past 12 months, our team can help you uncover hidden configuration gaps before attackers do.
Through our structured Microsoft 365 Security Assessment Packages, we provide:
  1. A Comprehensive Tenant Audit: Measuring your configuration against established Microsoft Security Baselines and CIS Benchmarks.
  2. Configuration Gap Analysis: Identifying risky sharing rules, identity vulnerabilities, and licensing misconfigurations.
  3. A Prioritised Remediation Roadmap: Clear, actionable steps to secure your environment without disrupting daily productivity.
  4. An Executive Summary: C-level reporting detailing your current risk profile and strategic recommendations.
     
Take control of your cloud environment today. Contact Reliable Networks to schedule your comprehensive Microsoft 365 audit.

Is Your Microsoft 365 Tenant Secure?

Uncover hidden configuration gaps, unmonitored guest access, and licensing risks before cybercriminals exploit them.

Picture of Gregory Olczyk

Gregory Olczyk

Latest articles

Microsoft 365 Is Not Secure by Default: 10 Settings Every SME Should Review Today

The Club Manager’s Guide to IT: In-House vs Outsourced Partners

Navigating WiFi Constraints in Listed Heritage Buildings

Free IT Health Check

Fill in the form below to claim your check.