Home / Blog

Best Microsoft 365 Security Settings for Business

A compromised Microsoft 365 account can do more than expose email. It can redirect invoices, distribute convincing phishing messages from a trusted address, access SharePoint files and disrupt a team’s daily work. The best Microsoft 365 security settings reduce that risk without making staff jump through unnecessary hoops every time they open Outlook or Teams.

For small to mid-sized organisations, the goal is not to turn every employee into a security specialist. It is to put sensible controls around identities, devices, email and data, then monitor them consistently. The settings below form a practical baseline for Australian businesses that need stronger protection, clearer accountability and less reactive IT work.

Best Microsoft 365 Security Settings Start With Identity

Most Microsoft 365 incidents begin with a stolen password or a user approving a fraudulent sign-in request. Identity protection should therefore be the first priority.

Require multi-factor authentication for every user

Multi-factor authentication, or MFA, should be mandatory for all users, including executives, contractors and administrators. A password alone is not an adequate control, even if it is long and unique.

Authenticator app number matching is a better default than SMS or repeated push notifications, which are more vulnerable to social engineering and SIM-swap attacks. Where the role and licence support it, use phishing-resistant methods such as passkeys or security keys for administrators and users with access to financial, HR or sensitive operational data.

There will be exceptions. Field workers without reliable mobile coverage, shared devices and some legacy applications may need a different approach. Treat each exception as a documented risk decision with a review date, not a permanent workaround.

Apply Conditional Access policies carefully

Conditional Access allows Microsoft 365 to assess the context of a sign-in before granting access. A well-designed policy can require MFA, block high-risk logins, restrict access from unmanaged devices, or prevent access from countries where your organisation has no legitimate business activity.

Start with a small number of clear policies. For example, require MFA for all users, require stronger controls for administrators, and block legacy authentication. Test policies in report-only mode and exclude emergency access accounts that are securely stored and regularly tested. A rushed policy can lock out staff at the worst possible time, so staged rollout matters.

Disable legacy authentication

Older email protocols do not support modern MFA and are commonly targeted by password-spraying attacks. Disable legacy authentication unless there is a verified business requirement to retain it. If an older scanner, application or device needs to send email, use a supported and tightly controlled alternative rather than leaving a broad opening in your tenant.

Secure Email, Teams and Shared Files

Email remains the main delivery method for phishing, malware and business email compromise. Microsoft 365 can provide strong protection, but the policies need to be configured and reviewed rather than left at their defaults.

Set sensible anti-phishing and anti-malware policies

Use Microsoft Defender for Office 365 features available in your licence to identify impersonation attempts, suspicious links and unsafe attachments. Protect high-value users by adding their names and key supplier domains to impersonation protection. Finance teams are frequent targets, particularly where payment details or invoice approvals are involved.

Safe Links and Safe Attachments can add meaningful protection, but they are not a substitute for staff awareness or approval controls. A malicious email may still rely on a legitimate-looking request, such as a change of bank account details. Your finance process should require independent verification for these changes.

Block automatic external forwarding by default. Attackers who gain access to an inbox often create forwarding rules so they can monitor conversations after the password is reset. Allow exceptions only where there is a clear business need, and review them regularly.

Control external sharing in SharePoint and OneDrive

External sharing supports real work with clients, subcontractors and advisers. It also creates a path for sensitive information to leave the business. Set sharing to the least permissive level that still supports your operating model.

For many organisations, named external guests with expiry dates are a safer option than anonymous links that can be forwarded indefinitely. Review existing sharing links, especially in sites used by finance, management, HR and project teams. Ensure owners know they are responsible for access to the content they share.

Protect the Devices That Access Microsoft 365

Microsoft 365 security is only as strong as the laptops and mobiles connected to it. A device without encryption, updates or endpoint protection can expose data even when the user’s sign-in is well protected.

Use Microsoft Intune, where available, to apply baseline security settings consistently. These should include full-disk encryption with BitLocker, supported operating system versions, screen lock requirements, endpoint protection, firewall settings and timely security updates. Device compliance policies can then prevent non-compliant devices from accessing company data.

For personally owned mobiles, consider app protection policies rather than full device management. This approach protects Microsoft 365 data inside approved apps without giving the business unnecessary control over an employee’s personal photos, messages or settings. It is often the more workable option for bring-your-own-device arrangements.

Endpoint security should also align with the Essential Eight principles. Patch applications promptly, limit administrative privileges, use MFA, and maintain recoverable backups. The precise controls depend on your risk profile, but unmanaged endpoints should not become the weak link in an otherwise well-configured tenant.

Limit Privilege and Protect Sensitive Data

Not every user needs the ability to install software, create new Microsoft 365 services or access all company files. Excess privilege increases the damage a compromised account or simple mistake can cause.

Reduce standing administrator access

Give users the lowest level of access needed to do their job. Global Administrator should be reserved for a very small number of trusted accounts and never used for normal email, Teams or web browsing.

Use separate administrator accounts for privileged tasks. Where supported by your licensing, privileged identity management can provide time-limited, approved access rather than permanent high-level permissions. This adds a control point around the accounts attackers value most.

Review administrator roles, shared mailboxes, distribution groups and application permissions at least quarterly. Departed staff, old contractors and forgotten third-party applications are common sources of unnecessary access.

Use sensitivity labels and data loss prevention where they fit

Sensitivity labels can classify documents and emails as internal, confidential or highly confidential, then apply encryption or sharing restrictions based on the label. They are particularly useful for HR records, legal documents, commercial proposals and client information.

Data loss prevention policies can identify patterns such as tax file numbers, credit card details or health information before they are emailed or shared externally. Begin in audit mode so you can understand normal work patterns and reduce false positives. A policy that blocks legitimate work without a clear path to resolution will quickly be bypassed or ignored.

Monitor What Matters and Plan for Recovery

Security settings do not deliver much value if nobody reviews the alerts, sign-in activity and policy changes they generate. Assign responsibility for monitoring Microsoft 365, including what happens after hours and how a suspected compromise is escalated.

Enable unified audit logging and retain logs for a period that supports your compliance and investigation needs. Configure alerts for high-risk events such as new inbox forwarding rules, administrator role changes, impossible travel sign-ins, mass file deletion and suspicious consent granted to applications.

Retention policies are useful, but they are not the same as an independent backup. Microsoft 365 protects platform availability; your organisation still needs a clear approach to recovering data after deletion, ransomware, retention changes or user error. Test restoration before an incident, including mailboxes, SharePoint libraries and Teams-related files.

Keep a short incident response procedure that names the people responsible for isolating an account, resetting credentials, reviewing sign-in logs, preserving evidence and communicating with affected clients or staff. During a real incident, clear ownership is more valuable than a lengthy document no one can find.

A Practical Rollout Order for Microsoft 365 Security

Trying to configure everything at once creates gaps and confusion. A staged approach keeps disruption manageable while addressing the highest risks first:

  • Require MFA, secure administrator accounts and disable legacy authentication.
  • Deploy Conditional Access in report-only mode, then enforce tested policies.
  • Strengthen email protections and block unauthorised external forwarding.
  • Bring company devices under endpoint management and compliance controls.
  • Review sharing, privileges, audit logs, recovery arrangements and alert ownership.

Review this baseline after material business changes, such as a merger, new finance system, major workforce growth or a move to mobile field operations. Security settings should reflect how your people actually work, not how the organisation operated three years ago.

The right Microsoft 365 configuration is not the most restrictive one. It is the one that makes unsafe activity difficult, legitimate work dependable and accountability clear. That is how security becomes part of stable operations rather than another source of disruption.

← Back to all posts Book a free assessment