Resources

Microsoft 365 Business Security Configuration Guide

A practical Microsoft 365 business security guide covering common weaknesses, MFA, Conditional Access, Defender, email security, admin roles, app consent, sharing, logging and recovery.

The Microsoft 365 problems we worry about most are usually not dramatic. They are gaps in coverage: one administrator outside the policy, an old forwarding rule, an application with more access than it needs, or a device that can reach company data without meeting the intended security standard.

What we look for

What we see most often is not a missing product. It is incomplete coverage or configuration drift. A company can own the right Microsoft licenses and still have a few users, administrators, applications or unmanaged devices outside the intended policy. We verify who and what is actually protected instead of relying on a setting that simply says enabled.

Microsoft 365 can contain a company's email, identities, files, Teams conversations, SharePoint sites, OneDrive data and access to other business applications. A subscription alone does not mean every recommended security control is configured. Security depends on licensing, tenant configuration, identities, devices, applications, policies and ongoing administration.

Note: Microsoft changes portals, product names, licensing and configuration options regularly. Verify menu paths against current Microsoft documentation before production changes. Test authentication and Conditional Access changes carefully to avoid lockouts.

20 Common Microsoft 365 Security Issues to Look For

  1. Users without the intended MFA protection
  2. Weak or inconsistent authentication policies
  3. Legacy authentication exposure
  4. Too many Global Administrators
  5. Privileged accounts used for routine work
  6. No protected emergency-access strategy
  7. Weak or incomplete Conditional Access
  8. Unmanaged devices accessing sensitive information
  9. Inadequate anti-phishing protection
  10. Safe Links or Safe Attachments not appropriately deployed
  11. Executive/domain impersonation protections not fully configured
  12. Weak SPF, DKIM or DMARC implementation
  13. Unnecessary external email forwarding
  14. Suspicious inbox or forwarding rules
  15. Excessive OAuth/application permissions
  16. Uncontrolled application consent
  17. Excessive SharePoint/OneDrive external sharing
  18. Security and audit logs not adequately reviewed
  19. Departed users not fully offboarded
  20. No documented Microsoft 365 recovery strategy

1. Multi-Factor Authentication

Passwords can be phished, reused or stolen. MFA adds another authentication requirement and is one of the most important cloud identity controls.

Verify coverage for normal users, administrators, remote access, sensitive applications and other identities according to their supported authentication model. Do not simply record "MFA enabled." Verify who and what is actually protected.

For organizations with appropriate Microsoft Entra licensing, Conditional Access provides more granular authentication controls. Smaller tenants should evaluate Microsoft's Security Defaults where appropriate.

2. Conditional Access

Conditional Access can make access decisions using signals such as user, application, device, location and risk, depending on licensing.

Common objectives include requiring MFA, blocking legacy authentication, strengthening administrator authentication, controlling unmanaged-device access and applying stronger controls to sensitive applications.

Build policies deliberately and test them before enforcement. Microsoft provides report-only mode for evaluating Conditional Access policies before broad enforcement. Maintain emergency access according to Microsoft's current guidance.

3. Legacy Authentication

Older authentication protocols can create security exposure because they may not support modern authentication controls.

Identify legacy-authentication sign-ins and legitimate dependencies, migrate or replace those dependencies, and block unnecessary legacy authentication.

4. Privileged Administrator Roles

Global Administrator is highly privileged. Microsoft recommends least privilege.

Inventory privileged roles and use the least-privileged role capable of performing the required task. Review privileged assignments regularly and remove unnecessary access.

Where practical, separate highly privileged administrative activity from routine email and browsing.

5. Emergency Access

Authentication or Conditional Access mistakes can create tenant-wide lockout risk. Maintain carefully protected and monitored emergency-access capability following Microsoft's current guidance.

6. Defender Preset Security Policies

Microsoft recommends Standard or Strict preset security configurations for Defender for Office 365.

Standard is designed to balance protection and usability. Strict applies more aggressive settings and can be appropriate for higher-risk users such as executives, finance personnel and administrators.

In the Microsoft Defender portal review: Email & collaboration > Policies & rules > Threat policies > Preset Security Policies.

Microsoft's Configuration Analyzer can compare existing settings with Standard and Strict recommendations.

7. Anti-Phishing and Impersonation

Business email compromise frequently relies on impersonation.

Review spoof intelligence, user impersonation protection, domain impersonation protection, mailbox intelligence, phishing thresholds, quarantine actions and safety tips.

Preset policies configure many recommended protections, but administrators should still review specific users and domains that require impersonation protection.

8. Safe Links

Defender for Office 365 Safe Links can evaluate URLs during mail flow and at time of click in supported workloads.

Verify that intended licensed users are covered. Microsoft generally recommends Standard and/or Strict preset policies instead of unnecessary custom Safe Links policies.

9. Safe Attachments

Safe Attachments helps detect malicious files. Confirm that intended eligible users and workloads receive the expected protection. Purchasing a license does not itself prove every intended policy assignment is complete.

10. Protect Higher-Risk Users

Executives, finance, HR, administrators and users authorized to change banking information may justify stronger controls.

Consider stronger authentication, Strict Defender policies, tighter device requirements and enhanced monitoring based on risk.

11. SPF

SPF identifies systems authorized to send mail for a domain.

Review for missing or multiple SPF records, obsolete vendors, excessive authorization and DNS lookup problems. Maintain an inventory of legitimate services sending as the business domain.

12. DKIM

DKIM cryptographically signs outgoing messages so receiving systems can verify domain authorization and message integrity. Enable it for appropriate custom domains and validate operation.

13. DMARC

DMARC builds on SPF and DKIM and provides domain owners with policy and reporting capabilities.

A controlled rollout can begin with visibility and reporting, correction of legitimate senders, and movement toward an appropriate enforcement policy. Do not move to restrictive enforcement without understanding legitimate mail sources.

14. External Automatic Forwarding

External forwarding can create data-loss and attacker-persistence risk.

Review outbound spam policy, mail-flow rules, mailbox forwarding and inbox rules. Disable unnecessary automatic external forwarding and document legitimate exceptions.

15. Suspicious Inbox Rules

Compromised mailboxes can contain rules designed to hide replies, delete messages, move conversations or forward mail. Security investigations should review mailbox rules, and monitoring should identify suspicious changes where capabilities allow.

16. OAuth and Enterprise Applications

Third-party applications can receive access to Microsoft 365 data.

Review Microsoft Entra enterprise applications, app registrations, permissions, consent, owners and service principals. Remove unnecessary applications and investigate applications with powerful permissions.

17. Application Consent

Define whether users can independently consent to applications and which permission levels are acceptable. A controlled consent process can reduce malicious or unnecessary application access.

18. SharePoint and OneDrive Sharing

Review tenant and site-level sharing, anonymous links, guests, link expiration, default sharing types and sensitive sites. Apply tighter restrictions to sensitive data when appropriate.

19. Teams External and Guest Access

Teams guest access and external access are separate capabilities. Configure each according to actual collaboration requirements rather than enabling broad external access by default.

20. Device-Based Access

A valid username, password and MFA response do not automatically prove the device is trusted.

Organizations with appropriate licensing can combine Intune and Conditional Access to require managed or compliant devices for selected resources.

Device controls can include encryption, supported operating systems, endpoint protection, screen-lock requirements and configuration standards.

21. Microsoft Intune

Intune can centrally manage supported endpoints and mobile devices using configuration policies, compliance policies, application deployment, security baselines, encryption management, inventory and access integration.

Capabilities vary by license and platform.

22. Security and Audit Logging

Logs are critical during an incident.

Verify that the organization can investigate user sign-ins, administrative changes, mailbox activity, application consent, sharing, security alerts, email threats and device activity.

Available telemetry and retention depend on licensing and configuration.

23. Microsoft Purview Audit

Microsoft Purview auditing can provide records of user and administrator activity across Microsoft 365 services. Verify that required audit data is available and retained long enough for security, legal, insurance and compliance needs.

24. Microsoft Secure Score

Secure Score can identify Microsoft security improvement opportunities. Use it as one input rather than treating it as a complete security audit. A higher score does not guarantee security.

25. User Offboarding

Document offboarding.

Consider blocking sign-in, revoking sessions, handling authentication methods, removing privileged roles, reviewing forwarding and inbox rules, transferring business data, recovering company devices and removing third-party access.

Disabling one account does not necessarily complete offboarding across the business.

26. Shared Accounts

Avoid shared user credentials when individual identities can be used. Individual identities improve MFA, accountability, logging and offboarding. Use supported shared-resource models such as shared mailboxes where appropriate.

27. Microsoft 365 Backup and Recovery

Define recovery requirements for accidental deletion, malicious deletion, ransomware, compromised administrators and retention needs.

Evaluate Microsoft-native recovery and retention capabilities against business requirements and determine whether an additional backup service is appropriate.

28. Security Alert Ownership

Security products provide little value if important alerts are not investigated.

Document who receives alerts, who investigates, escalation requirements, response expectations and after-hours responsibility.

29. Recurring Security Reviews

Microsoft 365 changes continuously.

Periodically review privileged accounts, MFA coverage, Conditional Access, enterprise applications, guest users, sharing, forwarding, Defender policies, security alerts, device compliance, Secure Score and audit capabilities.

A working Microsoft 365 security baseline

Identity

MFA, privileged-account protection, least privilege, controlled authentication and emergency access.

Email

Microsoft-recommended Defender policies, anti-phishing, Safe Links/Safe Attachments where licensed, impersonation protection and forwarding controls.

Domain

SPF, DKIM and DMARC.

Applications

Controlled app consent, enterprise-application inventory and OAuth permission review.

Data

Controlled SharePoint/OneDrive sharing, guest access and recovery planning.

Devices

Central management, encryption, endpoint security and compliance controls where appropriate.

Monitoring

Audit logging, security alerts, investigation processes and appropriate retention.

Recovery

Documented Microsoft 365 recovery requirements and tested recovery processes.

A sensible order of operations

Phase 1 - Identity

Inventory administrators, verify MFA, review legacy authentication, protect privileged accounts, establish emergency access and review inactive/former users.

Phase 2 - Email

Review Defender preset policies, configure Standard/Strict assignments where appropriate, review impersonation protection, verify Safe Links/Safe Attachments coverage, control forwarding and validate SPF/DKIM/DMARC.

Phase 3 - Applications And Data

Review OAuth applications, application consent, SharePoint/OneDrive sharing and Teams guest/external access.

Phase 4 - Devices

Inventory devices, deploy centralized endpoint management where appropriate, establish compliance requirements and integrate device trust with Conditional Access where justified.

Phase 5 - Detection And Recovery

Review audit logging, establish alert ownership, implement monitoring, document recovery requirements and test recovery.

Microsoft 365 Security and CIS Controls

Microsoft 365 configuration can support multiple CIS Critical Security Controls:

Control 3 - Data Protection Control 4 - Secure Configuration Control 5 - Account Management Control 6 - Access Control Management Control 8 - Audit Log Management Control 9 - Email and Web Browser Protections Control 13 - Network Monitoring and Defense Control 17 - Incident Response Management

Purchasing Microsoft licenses does not automatically satisfy CIS safeguards. Controls must be appropriately configured, operated and evidenced.

Microsoft 365 Security Assessment Checklist

  • ☐ Are all intended users protected by MFA?
  • ☐ Are administrators subject to stronger controls?
  • ☐ How many Global Administrators exist?
  • ☐ Are privileged roles reviewed?
  • ☐ Are emergency-access accounts properly protected and monitored?
  • ☐ Is unnecessary legacy authentication blocked?
  • ☐ Are Conditional Access policies documented and tested?
  • ☐ Are Standard or Strict Defender preset policies deployed where appropriate?
  • ☐ Are executives and finance users protected against impersonation?
  • ☐ Are Safe Links and Safe Attachments applied to intended licensed users?
  • ☐ Is external automatic forwarding controlled?
  • ☐ Is SPF valid?
  • ☐ Is DKIM enabled for appropriate custom domains?
  • ☐ Is DMARC deployed and monitored?
  • ☐ Are enterprise applications reviewed?
  • ☐ Is application consent controlled?
  • ☐ Are SharePoint and OneDrive external-sharing settings reviewed?
  • ☐ Are guest users reviewed?
  • ☐ Are company devices centrally managed where required?
  • ☐ Can unmanaged devices access sensitive information?
  • ☐ Are audit logs available for investigations?
  • ☐ Is someone responsible for security alerts?
  • ☐ Is offboarding documented?
  • ☐ Is there a Microsoft 365 recovery strategy?

Common questions

Is Microsoft 365 secure by default?

Microsoft provides significant built-in security plus additional capabilities depending on licensing. Organizations remain responsible for configuring identities, policies, applications, sharing and other tenant settings according to their needs.

Should every business use Conditional Access?

Organizations with appropriate licensing should evaluate Conditional Access as part of identity security. Policies should be designed for actual business requirements and tested carefully.

Standard or Strict Defender protection?

Microsoft recommends Standard or Strict preset security configurations. Standard balances security and usability. Strict is more aggressive and can be appropriate for higher-risk users or organizations.

Does MFA completely stop account compromise?

No. MFA substantially improves security but does not eliminate session theft, malicious OAuth applications, compromised endpoints, social engineering or configuration mistakes.

Is DMARC still important with Microsoft 365?

Yes. SPF, DKIM and DMARC address domain email authentication and spoofing risks that remain relevant when using Microsoft 365.

Is Secure Score a security audit?

No. It is a useful Microsoft measurement and recommendation tool, but not a complete cybersecurity assessment.

Where Huff Data fits

Huff Data Systems can help businesses assess and manage Microsoft 365 security, including Microsoft Entra identity, MFA, Conditional Access, administrator security, Defender configuration, email security, SPF/DKIM/DMARC, OAuth/application reviews, sharing controls, endpoint management, monitoring, backup planning, CIS Controls alignment and cyber-insurance readiness.

The goal of a Microsoft 365 security review should be a prioritized, risk-based improvement plan rather than simply enabling every available feature.

Victoria: 361-570-7240 Houston: 713-493-2051

Related Resources

Microsoft 365 Managed Services Microsoft 365 Security Guide Cybersecurity Services CIS Controls Business Guide Business Cyber Insurance & CIS IG2/IG3 Guide Business Cybersecurity Assessment Guide Zero Trust Security Guide

Sources and further reading

This guide references current primary-source material. Requirements and product capabilities can change, so verify current source guidance before implementation.

Ready to move forward?

Want help applying this to your business?

We can look at your current environment and tell you which parts of this guide matter most for you.

Talk With Huff Data