Knowledge base · cloud identity

Microsoft 365 security for small businesses

Microsoft 365 contains email, files and identities that unlock much of an organisation. A practical baseline therefore starts with strong sign-in, separated administration, secure email and enough visibility into changes.

Updated: 4 September 2026

Start with identity and MFA

Enable multifactor authentication for every user, with particular attention to administrators and accounts that access financial or sensitive data. Microsoft Security Defaults can provide a useful baseline for smaller, straightforward environments. Appropriately licensed organisations can use Conditional Access for more granular policies.

MFA greatly reduces password-only risk but is not infallible. Train users to reject unexpected prompts and report them immediately. Prefer phishing-resistant methods where possible and prevent legacy authentication protocols from bypassing modern sign-in controls.

Limit administrator privileges

Use separate accounts for everyday work and administration. Assign only the role required for a task and periodically review who holds each privilege. Maintain emergency accounts under a documented procedure, monitor their use and protect their credentials carefully.

Administrators should not routinely read email, browse websites or open Office documents with privileged accounts. This separation reduces the chance that ordinary phishing immediately gains tenant-wide impact.

Protect email and collaboration

Configure SPF, DKIM and DMARC for every legitimate sending route. Review anti-phishing policy, external forwarding and alerts for suspicious inbox rules. SharePoint, OneDrive and Teams also require deliberate sharing settings so files do not quietly become more widely available.

Review guest users and old application integrations. Forgotten OAuth consent or external accounts can retain access after a project ends. Remove what is no longer needed and record who approves exceptions.

Logging, recovery and periodic review

Ensure someone can review alerts and sign-in logs. Microsoft Secure Score can identify improvements but does not replace risk assessment: understand what a measure changes and whether critical processes continue to work.

Document who can block an account, revoke sessions and investigate mailbox rules. Test recovery of important files and retain administrative contact information outside the tenant. A short, rehearsed procedure saves valuable time during a real compromise.

Technical sources

Would you like your Microsoft 365 baseline reviewed?

The Security Baseline Review translates identity, email, endpoints and recovery into practical priorities.