Back to Blog
Cybersecurity

9 Microsoft 365 Security Settings Most Small Businesses Never Turn On

Microsoft 365 includes powerful security features, but most small businesses never configure them. Here are 9 specific settings — where to find each one and what it protects against — that you can implement today.

Laurel Fuller — OwnerSeptember 15, 20269 min read

You're Paying for Security Features You're Not Using

If your business uses Microsoft 365, you have access to a suite of security controls that would have cost tens of thousands of dollars a decade ago. Conditional access, multi-factor enforcement, mailbox auditing, safe attachments — they're all included in most business plans.

The problem is that many of these features are not enabled by default. Microsoft gives you the tools but leaves the configuration to you. And most small businesses, lacking a dedicated IT security team, never turn them on. That leaves the door open to the exact attacks these settings are designed to stop.

This guide walks through 9 specific security settings you can configure in your Microsoft 365 tenant today. For each one, you'll see where to find it and what it protects against.

1. Enforce Multi-Factor Authentication (Not Just Enable It)

There's a critical difference between enabling MFA and enforcing it. Enabling means users can turn it on if they want to. Enforcing means they must use it — no exceptions, no opting out.

Where to find it: Microsoft 365 admin center > Users > Active users > Multi-factor authentication. Or better, use Conditional Access policies (see below) to enforce MFA across your entire tenant.

What it protects against: Credential stuffing and phishing attacks. Even if an attacker obtains a user's password, they can't access the account without the second factor. Microsoft reports that MFA blocks over 99.9% of account compromise attacks.

2. Set Up Conditional Access Policies

Conditional access is the most powerful security control in Microsoft 365, and most small businesses have never touched it. It lets you define rules: who can access what, from where, under what conditions.

A practical starter policy: block all sign-ins from non-trusted locations unless MFA is completed. This means an attacker in another country can't log in even with valid credentials, because the sign-in originates from an unfamiliar location.

Where to find it: Microsoft Entra admin center (formerly Azure AD) > Protection > Conditional Access.

What it protects against: Logins from compromised credentials originating from unexpected locations or devices.

3. Disable Legacy Authentication

Legacy authentication protocols — IMAP, POP3, SMTP, ActiveSync — don't support MFA. They're also the primary method attackers use to brute-force Microsoft 365 accounts. Disabling them forces all clients to use modern authentication, which supports MFA and conditional access.

Where to find it: Microsoft Entra admin center > Protection > Authentication methods > Policy. Set legacy authentication to block.

What it protects against: Brute-force attacks and credential stuffing that exploit protocols immune to MFA.

4. Enable Mailbox Auditing

Mailbox auditing records what happens inside a user's mailbox — who logged in, what was read, what was deleted, what was forwarded. Without it, you have no way to investigate if an account is compromised.

Attackers who gain mailbox access often set up hidden forwarding rules to send copies of incoming emails to an external address. Mailbox auditing is how you detect this.

Where to find it: Microsoft Purview compliance portal > Audit. Ensure mailbox auditing is enabled for all users.

What it protects against: Silent data exfiltration and undetected account compromise. It doesn't prevent the attack — it gives you the evidence to detect and respond to it.

5. Block External Email Forwarding Rules

This is the attack method most business owners have never heard of. An attacker gains access to a user's mailbox, creates a hidden inbox rule that automatically forwards all incoming emails to an external address, then deletes the forwarded copy so the user never notices. The attacker receives a copy of every email the compromised account receives — including confidential business communications.

Where to find it: Microsoft 365 admin center > Exchange admin center > Mail flow > Remote domains. Edit the default remote domain and set automatic forwarding to disabled.

What it protects against: Silent exfiltration of business email through attacker-created forwarding rules.

6. Enable Safe Attachments

Safe Attachments scans every email attachment in a sandboxed environment before delivering it to the user. If the attachment behaves maliciously — attempting to execute code, modify system files, or connect to known-bad domains — it's blocked and the user receives a notification.

Where to find it: Microsoft 365 Defender portal > Email & collaboration > Policies & rules > Threat policies > Safe Attachments.

What it protects against: Malware and ransomware delivered via email attachments, including zero-day threats that signature-based antivirus won't catch.

7. Enable Safe Links

Safe Links rewrites every URL in incoming emails and checks the destination in real time when the user clicks. If the link points to a known phishing or malware site, the click is blocked. This protects against phishing emails that pass initial spam filtering but contain malicious links.

Where to find it: Microsoft 365 Defender portal > Email & collaboration > Policies & rules > Threat policies > Safe Links.

What it protects against: Phishing attacks and drive-by malware downloads from malicious links in emails.

8. Separate Admin Accounts from Daily Use Accounts

This isn't a setting in the Microsoft 365 console — it's a practice. Your global admin accounts should be separate from the accounts you use for daily work (email, Teams, file editing). Admin accounts should require MFA, should never be used to browse the web or open email attachments, and should only be logged into when performing administrative tasks.

Why: if an admin's daily-use account is compromised through a phishing email, the attacker doesn't automatically gain administrative access to your entire tenant. The blast radius is contained.

Where to find it: Create separate user accounts in Microsoft 365 admin center. Assign admin roles only to the dedicated admin accounts.

What it protects against: Full tenant compromise through a single phishing attack on an administrator.

9. Implement Backup Beyond Microsoft's Retention

Many businesses assume that because their email is in Microsoft 365, it's backed up. Microsoft provides redundancy — your data is replicated across multiple data centers. But redundancy is not backup. Microsoft's retention policies are limited, and in some plans, deleted items are permanently removed after 14-30 days.

If an attacker with admin access deletes mailboxes, or if ransomware encrypts files in OneDrive/SharePoint, Microsoft's built-in retention may not save you. A third-party backup of your Microsoft 365 data — stored separately from your Microsoft tenant — is the only way to guarantee recovery.

Where to find it: This requires a third-party backup solution. Your IT provider can implement one that backs up Exchange, OneDrive, SharePoint, and Teams data to a separate, secure location.

What it protects against: Permanent data loss from malicious deletion, ransomware, or extended outages that exceed Microsoft's recovery capabilities.

Start With These Three

If configuring all 9 settings at once feels overwhelming, start with the three that provide the most protection for the least effort:

  1. 1Enforce MFA — the single most impactful security control you can implement
  2. 2Block external email forwarding — one policy that closes a major data exfiltration path
  3. 3Disable legacy authentication — closes the backdoor that attackers use to bypass MFA

These three settings take minutes to configure and block the most common attack vectors against Microsoft 365 tenants.

Microsoft 365 includes enterprise-grade security, but only if you actually configure it. Dytech Group helps Central Florida businesses implement and manage Microsoft 365 security controls. Our cybersecurity services include tenant hardening, and our Microsoft cloud managed services provide ongoing monitoring and configuration management to keep your tenant secure as threats evolve.

More articles

Get a Free Consultation

As a family-owned business, we treat every client like a neighbor — not a number. Talk to a real local technician and discover what personalized IT support feels like.