Knowledge base · cloud identity
Microsoft 365 security for small businesses
Microsoft 365 contains email, files and identities that unlock much of an organisation. A practical baseline therefore starts with strong sign-in, separated administration, secure email and enough visibility into changes.
Updated: 4 September 2026
Start with identity and MFA
Enable multifactor authentication for every user, with particular attention to administrators and accounts that access financial or sensitive data. Microsoft Security Defaults can provide a useful baseline for smaller, straightforward environments. Appropriately licensed organisations can use Conditional Access for more granular policies.
MFA greatly reduces password-only risk but is not infallible. Train users to reject unexpected prompts and report them immediately. Prefer phishing-resistant methods where possible and prevent legacy authentication protocols from bypassing modern sign-in controls.
Limit administrator privileges
Use separate accounts for everyday work and administration. Assign only the role required for a task and periodically review who holds each privilege. Maintain emergency accounts under a documented procedure, monitor their use and protect their credentials carefully.
Administrators should not routinely read email, browse websites or open Office documents with privileged accounts. This separation reduces the chance that ordinary phishing immediately gains tenant-wide impact.
Protect email and collaboration
Configure SPF, DKIM and DMARC for every legitimate sending route. Review anti-phishing policy, external forwarding and alerts for suspicious inbox rules. SharePoint, OneDrive and Teams also require deliberate sharing settings so files do not quietly become more widely available.
Review guest users and old application integrations. Forgotten OAuth consent or external accounts can retain access after a project ends. Remove what is no longer needed and record who approves exceptions.
Logging, recovery and periodic review
Ensure someone can review alerts and sign-in logs. Microsoft Secure Score can identify improvements but does not replace risk assessment: understand what a measure changes and whether critical processes continue to work.
Document who can block an account, revoke sessions and investigate mailbox rules. Test recovery of important files and retain administrative contact information outside the tenant. A short, rehearsed procedure saves valuable time during a real compromise.
Technical sources
Would you like your Microsoft 365 baseline reviewed?
The Security Baseline Review translates identity, email, endpoints and recovery into practical priorities.