Skip to content

Microsoft 365 security checklist for small businesses

Short answer. If you do one thing, turn on multi-factor authentication for everyone. After that: block legacy authentication, restrict who can create forwarding rules to outside addresses, review administrator accounts, and check your audit log is on. Nearly all of this is included in the licence you already have.

Multi-factor authentication, everywhere

Most small-business email compromises start with one stolen password. Multi-factor stops that attack even when the password is already gone, which is why it is worth more than everything else on this list combined.

  1. 1Enable it for administrators first, because those accounts do the most damage if taken.
  2. 2Roll it out to everyone else in stages, not all at once on a Friday afternoon.
  3. 3Have each person register a second method, so a lost phone is not an outage.
  4. 4Brief the team before it takes effect. Unannounced MFA generates a wave of support calls and quiet workarounds.

Block legacy authentication

Older mail protocols cannot do multi-factor. If they remain enabled, an attacker simply uses one of them and walks straight past the MFA you just turned on. Leaving legacy authentication on undoes the previous step.

  1. 1Check whether anything still uses it before switching it off, usually an old scanner, printer or line-of-business app.
  2. 2Move those devices to a modern method, or give them their own tightly scoped account.
  3. 3Then block legacy authentication for everyone else.

Forwarding rules, the quiet one

When an account is compromised, a common first move is to create a rule that forwards mail to an outside address. The attacker then keeps reading everything even after the password is changed, and nobody notices because the mail still arrives normally.

  1. 1Restrict automatic forwarding to external addresses at the organisation level.
  2. 2Review existing rules across mailboxes, especially any that forward outside the business.
  3. 3Check for rules that move mail straight to a rarely used folder, which is how an attacker hides replies.

Administrator accounts and the audit log

  1. 1Count your Global Administrators. Most small businesses need two, and often have five.
  2. 2Make sure day-to-day work happens on a normal account, not an administrator one.
  3. 3Ensure at least two people can administer the tenant, so a holiday or a departure is not a lockout.
  4. 4Confirm the audit log is switched on. It records nothing retrospectively, so turning it on after an incident tells you nothing about the incident.
Check that your recovery email and phone number on the tenant are current and are not the mailbox of somebody who left. This is a small detail that becomes the whole problem during a lockout.

When to stop and call someone

  • You want MFA rolled out across a team without locking people out
  • Something still uses legacy authentication and you are not sure what
  • You found a forwarding rule nobody created
  • Nobody is certain who currently holds administrator access
  • You are being asked about your security posture by a customer or insurer

Want this handled for you?

A technician can look at it directly. First session is $49, up to 45 minutes, and we confirm the scope and price before any work starts.