Skip to content
Cybersecurity · · 4 min read

Securing Microsoft 365: the basic checklist for small businesses

Microsoft 365 does not set itself up securely. Six points to go through with your IT partner, from MFA and admin accounts to a backup that really is a backup.

By Limburg Cyber Group

In most offices, nearly everything runs on Microsoft 365: your email, your calendar, your files in OneDrive and SharePoint, and your meetings in Teams. That also makes it the account an attacker most wants to get into. Microsoft provides a solid platform, but how secure it is depends largely on how it has been set up. Go through the points below with your IT partner. Most of it is a matter of settings, not new purchases.

1. MFA for everyone, with no exceptions

Multi-factor authentication (MFA) is the most important measure: a stolen password on its own is then no longer enough to sign in. See our article on MFA for how it works and how to roll it out.

MFA must be enforced, not optional for each employee. There are two ways to do that:

  • Security defaults. A basic package from Microsoft itself, which includes MFA for all users and blocks legacy sign-in methods. Simple, and a good start for many small businesses.
  • Conditional access, depending on your licence. This lets you set your own rules, such as stricter checks for administrators or access only from company devices.

You use one or the other. Avoid having neither, with MFA only switched on for the people who asked for it.

2. Separate accounts for admin work

Manage Microsoft 365 with a separate admin account that you use only for admin tasks. Your everyday account, the one you email with and click links from, then has no admin rights. If someone falls for a phishing email, the damage stays limited to one ordinary account.

Give full admin rights to as few people as possible, but to more than one, so you cannot lock yourself out. Protect admin accounts with the strongest form of MFA you have.

3. Block legacy sign-in methods

Older ways of signing in, such as those used by old email programs, do not support MFA. As long as they are open, an attacker with only a password can still get in. Microsoft has already switched much of this off, but check that nothing is still allowed. Watch out for a scanner or printer that sends email: it may still rely on an old method.

4. Alerts for suspicious sign-ins and forwarding rules

A well-known pattern after a mailbox has been taken over: the attacker quietly creates a rule that forwards mail to an outside address, or that moves replies into a folder nobody looks at. That way they can read along, for example to fake an invoice later.

So agree that:

  • automatic forwarding to external addresses is blocked by default;
  • alerts are raised for new forwarding rules and for suspicious sign-ins, such as from an unexpected country, as far as your licence allows;
  • someone actually reads those alerts and knows what to do.

5. External sharing in OneDrive and SharePoint

Staff can often create links that let anyone who has the link open a file. Convenient, but such a link can be passed on and keeps working. Decide in the admin centre what suits your business: for example sharing only with specific people, an expiry date on links that anyone can open, or external sharing only for certain sites. Also check which files are already shared externally.

6. Retention is not the same as a backup

Microsoft makes sure the service keeps running and that data is not lost through a failure on its side. What you, a colleague or an attacker deletes or encrypts is your responsibility. The recycle bin and version history only reach back for a limited time, and retention policies are meant to preserve data, not to restore everything quickly after ransomware, a deleted account or a mistake. A separate backup of email, OneDrive, SharePoint and Teams, from Microsoft itself or another provider, is therefore no luxury. More on that in backups that really work.

And your email domain?

Once Microsoft 365 is in order, also check whether others can send email that appears to come from your domain. That is handled with SPF, DKIM and DMARC, explained in this article. Our free email spoofing check shows you straight away where your domain stands.

Go through the list together

Not sure how yours is set up? Discuss it with your IT partner, or with us. We review your Microsoft 365 environment and help close the gaps without getting in your team’s way. See our cybersecurity service or book a conversation.

Read more

Shall we meet?

No sales pitch. Just a conversation about where you stand and what makes sense for your business.