Here's how it usually goes. An accountant gets an email that looks exactly like a shared invoice. She enters her password on a convincing sign-in page. A moment later her phone asks her to approve a sign-in, and because she just signed in, she taps Approve. By the afternoon, a hidden mailbox rule is quietly forwarding every message with the word "invoice" to an outside address, and a client is about to wire a payment to the wrong account.
Nothing in that story required breaking Microsoft's security. Every step used a setting that was left at its default or never turned on. This checklist closes those gaps, in the order we'd fix them.
Still choosing a platform? Start with Microsoft 365 vs. Google Workspace, then come back to this list.
1. Multifactor authentication for everyone
- Turn on MFA for every account, not just executives. Attackers target whoever has the weakest protection. (Identity protection is the core of our cyber security work.)
- Start with security defaults if you have nothing today. They're free in every Microsoft 365 business plan and turn on MFA and block legacy sign-in methods.
- Move to Conditional Access if you have Business Premium. It's included through Microsoft Entra ID P1 and lets you require MFA based on user, device and location.
- Prefer the Authenticator app with number matching over text messages, and teach staff one rule: if you didn't just sign in, never approve a prompt.
2. Administrator accounts
- Separate admin accounts from daily accounts. The account you read email with should not be a Global Administrator.
- Keep Global Administrators to a minimum, with at least two so you're never locked out, and use narrower admin roles for everything else.
- Protect admin accounts with the strongest MFA you have and review who holds admin roles every quarter.
- Keep two emergency-access ("break-glass") accounts, as Microsoft recommends: cloud-only, not tied to any one person, protected with phishing-resistant sign-in such as a FIDO2 security key or certificate-based authentication, excluded from Conditional Access policies that could lock them out, and monitored so every sign-in raises an alert. Document where the keys are and who may use them.
3. Email protection
- Turn on the preset security policies. With Defender for Office 365 Plan 1, included in Business Premium, you also get Safe Links and Safe Attachments, which check links and files before users open them.
- Block automatic forwarding to outside addresses. It's one of the most common ways stolen mailboxes leak data.
- Set up SPF, DKIM and DMARC for your domain so others can't easily send mail pretending to be you.
- Tag external emails so staff can see at a glance when a message comes from outside the company.
- Check for suspicious inbox rules regularly, especially after any password-reset or phishing report.
4. Device security
- Manage company devices with Intune (we do this as part of managed desktop). Business Premium includes Intune Plan 1 for managing Windows, Mac, iOS and Android devices, including personal phones through app protection.
- Encrypt laptops (BitLocker on Windows, FileVault on Mac) so a lost laptop isn't a data breach.
- Keep systems patched automatically, and protect endpoints with Defender for Business, also included in Business Premium.
- Require a compliant device for access to company data once Conditional Access is in place.
5. Recovery planning
- Decide how you'll restore data if a mailbox, SharePoint site or OneDrive is deleted or encrypted. Many businesses add a dedicated Microsoft 365 backup so they control the recovery. See data backup and recovery.
- Write down the first hour. Who resets passwords, who revokes sessions, who calls the bank if a payment was redirected, who talks to clients.
- Test a restore at least once a year. An untested backup is a hope, not a plan.
Which plan gets you what
If you're not sure which plan you have, or want help moving to Business Premium, that's routine Microsoft 365 administration.
| Control | Business Basic / Standard | Business Premium |
|---|---|---|
| Security defaults (MFA baseline) | Yes | Yes |
| Conditional Access (Entra ID P1) | No | Yes |
| Defender for Office 365 Plan 1 | No | Yes |
| Intune Plan 1 device management | Basic Mobility and Security only | Yes |
| Defender for Business (endpoints) | No | Yes |
Where to start this week
- Confirm MFA is on for every account.
- Separate admin accounts and trim the Global Administrator list.
- Block external auto-forwarding and review inbox rules.
- Check SPF, DKIM and DMARC.
- Decide on backup and write down the first-hour plan.
Sources
- Microsoft 365 for business security overview (Microsoft Learn)
- Microsoft 365 Business Premium security FAQ (Microsoft Learn)
- Manage emergency access admin accounts (Microsoft Learn)
- Security defaults in Microsoft Entra ID (Microsoft Learn)
- Microsoft 365 Business Premium (Microsoft)
Vendor details checked September 2026. Licensing and product features change; confirm current terms with the vendor before you buy.