Microsoft 365 security checklist for small businesses
Multi-factor authentication, everywhere
Most small-business email compromises start with one stolen password. Multi-factor stops that attack even when the password is already gone, which is why it is worth more than everything else on this list combined.
- 1Enable it for administrators first, because those accounts do the most damage if taken.
- 2Roll it out to everyone else in stages, not all at once on a Friday afternoon.
- 3Have each person register a second method, so a lost phone is not an outage.
- 4Brief the team before it takes effect. Unannounced MFA generates a wave of support calls and quiet workarounds.
Block legacy authentication
Older mail protocols cannot do multi-factor. If they remain enabled, an attacker simply uses one of them and walks straight past the MFA you just turned on. Leaving legacy authentication on undoes the previous step.
- 1Check whether anything still uses it before switching it off, usually an old scanner, printer or line-of-business app.
- 2Move those devices to a modern method, or give them their own tightly scoped account.
- 3Then block legacy authentication for everyone else.
Forwarding rules, the quiet one
When an account is compromised, a common first move is to create a rule that forwards mail to an outside address. The attacker then keeps reading everything even after the password is changed, and nobody notices because the mail still arrives normally.
- 1Restrict automatic forwarding to external addresses at the organisation level.
- 2Review existing rules across mailboxes, especially any that forward outside the business.
- 3Check for rules that move mail straight to a rarely used folder, which is how an attacker hides replies.
Administrator accounts and the audit log
- 1Count your Global Administrators. Most small businesses need two, and often have five.
- 2Make sure day-to-day work happens on a normal account, not an administrator one.
- 3Ensure at least two people can administer the tenant, so a holiday or a departure is not a lockout.
- 4Confirm the audit log is switched on. It records nothing retrospectively, so turning it on after an incident tells you nothing about the incident.
When to stop and call someone
- You want MFA rolled out across a team without locking people out
- Something still uses legacy authentication and you are not sure what
- You found a forwarding rule nobody created
- Nobody is certain who currently holds administrator access
- You are being asked about your security posture by a customer or insurer
Want this handled for you?
A technician can look at it directly. First session is $49, up to 45 minutes, and we confirm the scope and price before any work starts.