A Microsoft 365 breach rarely starts with a dramatic technical failure. More often, it starts with a convincing email, a reused password or a staff member approving an unexpected sign-in prompt. Knowing how to harden Microsoft 365 means reducing those opportunities before they become an invoice fraud event, data loss incident or business interruption.
For Australian organisations, Microsoft 365 is usually where email, documents, meetings, client information and day-to-day approvals live. Securing it is not a one-off project or a set of default settings. It is an operating discipline: establish sensible controls, monitor what changes, and keep improving as your people, devices and risks change.
Microsoft 365 hardening is the process of configuring identities, devices, collaboration tools and data protection settings so that an attacker has fewer ways in and less freedom if they get past one control. The aim is not to make work difficult. It is to ensure staff can work securely from the office, home, site or on the road without every exception becoming a security gap.
The strongest environments use layered controls. Multifactor authentication protects a password, device compliance gives access decisions context, email security stops common threats, and backup and recovery provide a way back when prevention fails. No single setting is enough on its own.
The right level of control depends on your organisation. A healthcare practice handling sensitive records will need tighter data and device controls than a small business with a handful of shared, low-risk documents. However, identity protection, managed endpoints, secure administration and recoverable data are baseline requirements for almost every Microsoft 365 tenant.
Identity is the front door to Microsoft 365. If an attacker takes over an account with broad access, they can read mail, impersonate staff, reset passwords, create inbox rules and access SharePoint or OneDrive files. Start by making sign-ins harder to compromise and easier to assess.
Turn on multifactor authentication for every user, including executives, contractors and administrators. Avoid treating SMS as the end state. It is better than a password alone, but authenticator apps with number matching, passkeys or hardware security keys offer stronger protection against common phishing methods.
Conditional Access policies can require MFA based on risk, location, device status and application. These policies need careful testing. An overly broad rule can lock out legitimate workers, particularly field teams using mobile devices or contractors who need limited access. Roll out in report-only mode where available, review the impact, then enforce progressively.
Do not forget non-human accounts. Shared mailboxes should not be used as shared user accounts, and service accounts should have a documented purpose, tightly limited permissions and regular review.
Administrators should have separate accounts for privileged work. A global administrator account must not be used to read email, join Teams meetings or browse the web. This reduces the chance that a routine phishing event becomes a tenant-wide compromise.
Keep the number of Global Administrators low. Assign more limited roles where possible, such as Exchange Administrator, Helpdesk Administrator or SharePoint Administrator. Review privileged role assignments regularly and remove access that is no longer needed.
Maintain at least two emergency access accounts, often called break-glass accounts. These accounts should be protected, monitored and stored under a documented process for use only when normal access controls fail. Test that process rather than assuming it will work during an outage.
A secure Microsoft 365 account on an unmanaged laptop is still a risk. Devices can hold cached email, synced files and active browser sessions. Endpoint management gives your business a practical way to enforce basic security without relying on individual staff choices.
Use Microsoft Intune or an equivalent managed endpoint platform to enrol corporate devices and assess compliance. At a minimum, require supported operating systems, full-disk encryption, screen lock, anti-malware protection and timely security updates. A lost laptop should be protected by encryption and capable of being remotely wiped where appropriate.
Bring-your-own-device arrangements need a deliberate policy. You may choose to allow mobile access through app protection policies that keep work data within managed apps and prevent simple copy-and-paste into personal services. For higher-risk roles or sensitive data, requiring a managed device is often the clearer choice.
Endpoint controls also support Essential Eight-aligned practices, including patching applications and operating systems, restricting administrative privileges and using application controls where the business case warrants them. The priority is consistency. A policy that applies to 90 per cent of devices but ignores the remaining 10 per cent can leave a useful opening for an attacker.
Email remains the main delivery mechanism for credential theft, malware and payment redirection scams. Microsoft 365 Defender policies should be configured to filter known malicious content and give users a safe process for reporting suspicious messages.
Review anti-phishing policies, impersonation protection, safe links and safe attachments settings. Apply stronger protection to users who are regularly impersonated, such as directors, finance staff and payroll teams. External email tagging can also help staff recognise messages originating outside the organisation, although it should support – not replace – security awareness.
Domain protection matters as well. Configure SPF, DKIM and DMARC to reduce the chance of others spoofing your domain. Start DMARC in monitoring mode if needed, investigate legitimate senders, then move towards a quarantine or reject policy. This is a technical change with direct business value: it makes fraudulent emails using your organisation’s name harder to deliver.
SharePoint, OneDrive and Teams make collaboration easy. They can also expose information when external sharing is left too open, old guest accounts remain active or permissions grow without review.
Set a clear external sharing position. Some organisations need to share documents with clients, suppliers or project partners. Others should limit external sharing to approved teams or named domains. Avoid blanket settings that allow anonymous links to sensitive content unless there is a specific and managed reason to use them.
Use sensitivity labels where they genuinely improve handling of information. Labels can guide staff and apply controls such as encryption or limits on forwarding. Start with understandable categories, such as Public, Internal and Confidential, rather than creating a complex taxonomy nobody can apply correctly.
Data loss prevention policies can help stop accidental sharing of information such as tax file numbers, bank details or health data. Tune these policies first. If alerts are too frequent or block ordinary work without context, staff will find workarounds and confidence in the control will drop.
Retention settings and deleted-item recovery are useful, but they are not the same as an independent backup strategy. They may not provide the recovery point, retention period or restoration flexibility your organisation needs after ransomware, accidental deletion or a faulty bulk change.
Define what must be recoverable across Exchange Online, OneDrive, SharePoint and Teams. Then test restoring a mailbox, a file library and a meaningful set of data. A backup report that says successful is not proof that your team can recover critical information within the time the business can tolerate.
Recovery planning should also cover the people side. Document who can authorise a restore, how staff communicate during an outage and which services must return first. A clear, tested plan reduces pressure when time matters most.
Hardening drifts when new users are added, licences change, teams create new workspaces or an urgent exception becomes permanent. Regular reviews keep the baseline intact.
A practical monthly or quarterly review should cover sign-in risk, MFA coverage, privileged roles, device compliance, external guests, forwarding rules, security alerts and backup results. Review Microsoft Secure Score as a prompt for improvement, not as a score to chase blindly. Some recommendations may not suit your workflows, licensing or risk profile.
Keep reporting useful for decision-makers. Business leaders need to see whether devices are compliant, whether high-risk access is controlled, what incidents occurred and what actions remain outstanding. They do not need an unexplained stream of technical alerts.
For organisations without an internal Microsoft security team, a managed service can provide the discipline that is otherwise difficult to maintain: policy management, 24/7 monitoring, endpoint oversight, user support and clear accountability under one operating model. The value is not simply switching on features. It is knowing someone is watching the environment and acting before a small issue becomes downtime.
Microsoft 365 hardening works best when it becomes part of normal operations, not an annual scramble after an audit or security scare. Start with identity and devices, make sharing intentional, test recovery, and keep the controls under review as the business changes.