· security · 2 min read

Microsoft 365 security basics every SME should have in place

Most breaches we see at small firms exploit missing basics, not sophisticated attacks. Ten settings and habits that close the common doors.

Most breaches we see at small firms exploit missing basics, not sophisticated attacks. Ten settings and habits that close the common doors.

When a small business gets breached, the story is rarely sophisticated. It is usually a phished password, no multi-factor authentication, and a mailbox rule quietly forwarding invoices to an attacker. The good news: the defences are mostly settings you already pay for.

Here is the baseline we put in place for every Microsoft 365 client.

Identity first

1. Multi-factor authentication for everyone. Not just admins. MFA blocks the overwhelming majority of account-compromise attacks. If you do one thing from this list, do this.

2. Ditch legacy authentication. Older protocols like IMAP and SMTP basic auth bypass MFA entirely. Block them.

3. Separate admin accounts. Day-to-day work and administration should never share an account. Admin accounts get the strictest protection and no mailbox.

Email, the front door

4. Anti-phishing policies. Turn on Defender’s impersonation protection so mail pretending to be your directors gets flagged.

5. External email tagging. A simple banner on external mail defeats a surprising number of impersonation attempts.

6. Review forwarding rules regularly. Attackers who get into a mailbox almost always add a forwarding rule. Audit them, and alert on new ones.

Data and devices

7. Turn on device management basics. Require a PIN and encryption on any device that touches company data, and keep the ability to wipe company data from lost phones.

8. Limit sharing defaults. SharePoint and OneDrive links should default to people you choose, not “anyone with the link”.

Resilience

9. Back up Microsoft 365 data. Retention policies are not backup. Deleted or encrypted data needs an independent copy.

10. Practise the bad day. Once a year, walk through what you would do if the MD’s account were compromised this morning. Thirty minutes of rehearsal changes how a real incident goes.

The honest summary

None of this requires new products or a security team. It requires a few focused days of configuration and a habit of review. As a Microsoft Cloud partner, we run this hardening as a fixed-price package for SMEs, and it is some of the best-value work we do.

Back to Blog