Five Microsoft 365 security settings every business should turn on
Most Microsoft 365 breaches start with a stolen password. These settings stop most of them.
Microsoft 365 is secure by design, but many tenants still run with settings that make attackers’ work easy. Here are the five changes we make first.
- Multi-factor authentication for every user, starting with administrators
- Conditional Access to block sign-ins from risky locations or unmanaged devices
- Legacy authentication turned off, since old protocols cannot use MFA
- Separate, protected administrator accounts with only the roles they need
- Alerts for suspicious sign-ins, mailbox forwarding rules and mass deletions
Roll out without disruption
Start with administrators, then a pilot group, then everyone. Tell users in advance and keep a break-glass account excluded from Conditional Access, stored safely, in case of lockout.
We review and harden Microsoft 365 tenants as part of our Microsoft 365 and IT security services.