Service targets: 99.9% uptime · 15-min response · 24/7 monitoringVancouver, BC · serving all of Canada · (604) 632-4959
ITIT ExpertsOPERATIONS / CANADA

INSIGHT / MICROSOFT 365

Microsoft 365 Security Baseline: Twelve Settings Every Tenant Should Review

Twelve practical Microsoft 365 configuration areas, from conditional access to external sharing, that reduce risk without slowing staff down.

By Ali Sedighi, MBAReviewed 2026-10-065 min read

Microsoft 365 ships with defaults that prioritise convenience, and many tenants are never revisited after the initial setup. The result is a powerful platform with open external sharing, legacy protocols enabled and administrators using everyday accounts. These twelve review areas give you a pragmatic baseline that most organisations can adopt in a few weeks.

01Multi-factor authentication and conditional access

Require MFA for all users, using the authenticator app or security keys rather than text messages where possible. Use conditional access policies to block sign-ins from unexpected countries, require compliant devices for sensitive apps and prompt for stronger authentication on risky sign-ins. Test policies in report-only mode first and always keep two emergency access accounts excluded and monitored.

02Block legacy authentication

Older protocols such as POP, IMAP and basic SMTP authentication cannot perform MFA and are a favourite route for password-spray attacks. Identify any application that still depends on them, replace or modernise it, and then disable legacy authentication tenant-wide. Monitor sign-in logs for remaining attempts.

03Administrator hygiene

Reduce permanent global administrators to as few as possible, and assign roles on a least-privilege basis. Use separate cloud-only administrator accounts without mailboxes, require phishing-resistant MFA and review role assignments quarterly. Where licensing allows, use just-in-time elevation so privileges exist only when needed.

04Email protection and domain authentication

Enable anti-phishing, safe attachment and safe link policies, tuned for executives and finance staff who are impersonated most often. Publish SPF, DKIM and DMARC, and move DMARC gradually from monitoring to enforcement. Disable automatic external forwarding and alert on suspicious inbox rules, which attackers use to hide replies.

05External sharing and guest access

Set SharePoint and OneDrive sharing to the most restrictive level that still allows real collaboration, prefer named-person links over anonymous links and set expiry on guest access. Review guest accounts every quarter and assign owners to every Team and site so that someone is accountable for membership.

06Device compliance and management

Use Intune to require encryption, supported operating systems, screen locks and endpoint protection before devices can reach company data. For personal phones, app protection policies can contain company data without managing the whole device. Include a remote wipe procedure for lost devices.

07Data retention, labels and loss prevention

Define retention for email and files that reflects legal and business needs, and apply sensitivity labels to the most important content. Start data-loss prevention policies in audit mode for common identifiers such as social insurance numbers and payment-card numbers, then tighten gradually based on what you observe.

08Logging, alerting and secure score

Make sure unified audit logging is on and retained long enough to investigate incidents. Use Microsoft Secure Score as a prioritised to-do list, not a vanity metric. Route high-severity alerts to a monitored mailbox or a managed detection service, and review a monthly summary of sign-in risk and mailbox changes.

09Mistakes that undermine the baseline

The most frequent error is enabling policies without testing, which locks out staff and leads to exceptions that quietly dilute the whole control. Another is creating broad exclusions for convenience, such as excluding entire groups from multi-factor authentication. A third is neglecting emergency access accounts, so that a policy mistake becomes a tenant-wide lockout. Finally, many tenants accumulate licences for features nobody has configured. Use report-only mode, keep a change log, review exclusions regularly and match licences to the controls you actually use.

10A 60-day rollout approach

In the first two weeks, review sign-in logs, identify legacy protocol use and pilot MFA. In weeks three and four, enforce MFA and block legacy authentication. In weeks five and six, tighten external sharing and deploy device compliance for corporate laptops. In weeks seven and eight, enable retention, labelling in audit mode and alerting. Communicate each change in plain language, offer drop-in help and report Secure Score progress. A staged rollout gets the security benefit without a flood of support tickets.

11Differences by organisation type

A law firm will emphasise sensitivity labels and strict external sharing. A construction company will emphasise mobile app protection and simple sign-in for field staff. A clinic will focus on shared workstation sign-in, auditing and encryption. A nonprofit may rely on volunteers with limited-access accounts and nonprofit licensing. The baseline is the same, yet policy details such as session lengths, device requirements and guest access should reflect how people truly work.

12Details that are easy to overlook

Check that guest users cannot invite other guests, that Teams creation is controlled or at least named consistently, and that mailbox auditing is enabled. Review enterprise application consent settings, because attackers use malicious application permissions to maintain access even after passwords change. Confirm that shared mailboxes cannot be signed into interactively, and that former employees' licences and mailboxes follow a documented lifecycle. Look at service accounts and automation identities, which are often exempt from policy and rarely reviewed.

13Questions for your leadership team

Who owns the tenant and has the authority to approve changes? How much external collaboration do we really need, and with whom? Which roles require access to the most sensitive mailboxes and libraries? What is our expectation for personal phones accessing company email? How will we know if an account is compromised, and who will act? Settling these questions turns technical options into policy choices that leadership has endorsed.

Checklist

  • MFA enforced for all users
  • Two monitored emergency access accounts
  • Legacy authentication blocked
  • Global administrators reduced to the minimum
  • DMARC at enforcement
  • External sharing reviewed
  • Intune compliance policy applied
  • Audit logging confirmed and retained

Where this fits in your IT plan

Guidance like this works best when it is part of a coordinated programme rather than a one-off fix. These IT Experts services address the topic directly:

How IT Experts can help

IT Experts is a sub-brand of SAZ.ca, led by Ali Sedighi, MBA, combining senior-partner strategy with hands-on IT delivery. If this topic matches a situation in your organisation, book a free 30-minute consultation: call (604) 632-4959 or email info@SAZ.ca. We will give you a plain-language view of your options and, if useful, a fixed-price scope. We are an IT services and consulting firm, not a reseller, and there is no lock-in.

Frequently asked questions

Do I need Microsoft 365 E5 for good security?

Not necessarily. Business Premium covers many essentials for small and mid-sized organisations, and add-ons can fill gaps.

Will conditional access disrupt my staff?

Properly designed policies are almost invisible day to day. Pilot with a small group and use report-only mode first.

How often should we review the tenant?

A light monthly review and a deeper quarterly review work well for most organisations.

Can you manage our tenant for us?

Yes. Our Microsoft 365 service covers licensing, security configuration and day-to-day administration.

Call (604) 632-4959Email info@SAZ.caBook a consultation