Cloud Security

Securing Microsoft 365 for a Small Team: The Settings That Matter

Most small organisations run their entire business through Microsoft 365 on default settings. A handful of changes removes the majority of the practical risk.

Small team working on shared cloud systems

If your organisation runs on Microsoft 365, that tenant holds your email, your documents, your identities and most of your institutional memory. It is the highest-value target you own, and it very often runs on defaults.

Start here

Multi-factor authentication for everyone

Administrators first, then everyone. Use an authenticator app rather than SMS. This single change blocks the overwhelming majority of account compromise attempts, and it is free.

Disable legacy authentication

Older protocols bypass modern conditional access and MFA entirely, which makes them the preferred route for credential stuffing. Block them at the tenant level. Check first for anything still using them — usually a multifunction printer or an old line-of-business application.

Separate administrative accounts

Nobody should read email from an account that holds global administrator rights. Separate daily-use accounts from privileged ones, and keep the privileged ones out of mail and browsing entirely.

Email, where the attacks arrive

  • Configure SPF, DKIM and DMARC. Without them anyone can send mail that appears to come from your domain. Move DMARC to enforcement once you have monitored the reports.
  • Alert on inbox forwarding rules. Creating a rule that forwards mail externally and hides it is a standard step after account compromise, and it is trivially detectable.
  • Flag external senders. A visible banner on external mail makes impersonation of internal colleagues noticeably harder.
  • Restrict auto-forwarding to external domains by policy rather than relying on noticing it.

Sharing and data

  • Set default sharing to "specific people" rather than "anyone with the link".
  • Apply expiry to anonymous links where you allow them at all.
  • Review what is currently shared externally — on first inspection this list surprises almost everyone.
  • Restrict which third-party applications users can consent to. Malicious OAuth consent grants persistent mailbox access without ever touching a password.

Make sure you would know

Enable the unified audit log if it is not already on, and confirm the retention period meets your needs. After an incident, the first question is always what the attacker accessed, and that question is answerable only from logs you were already keeping.

Set alerts for a small number of high-value events: new global administrators, mass downloads, forwarding rule creation, and sign-ins from unexpected locations. Keep the list short enough that the alerts still get read.