Skip to main content
Security

Microsoft 365 Security Checklist for Small Businesses

Most small-business breaches don't start with hackers breaking encryption. They start with one password, one approved sign-in prompt, and one mailbox rule nobody noticed.

Here's how it usually goes. An accountant gets an email that looks exactly like a shared invoice. She enters her password on a convincing sign-in page. A moment later her phone asks her to approve a sign-in, and because she just signed in, she taps Approve. By the afternoon, a hidden mailbox rule is quietly forwarding every message with the word "invoice" to an outside address, and a client is about to wire a payment to the wrong account.

Nothing in that story required breaking Microsoft's security. Every step used a setting that was left at its default or never turned on. This checklist closes those gaps, in the order we'd fix them.

Still choosing a platform? Start with Microsoft 365 vs. Google Workspace, then come back to this list.

1. Multifactor authentication for everyone

  • Turn on MFA for every account, not just executives. Attackers target whoever has the weakest protection. (Identity protection is the core of our cyber security work.)
  • Start with security defaults if you have nothing today. They're free in every Microsoft 365 business plan and turn on MFA and block legacy sign-in methods.
  • Move to Conditional Access if you have Business Premium. It's included through Microsoft Entra ID P1 and lets you require MFA based on user, device and location.
  • Prefer the Authenticator app with number matching over text messages, and teach staff one rule: if you didn't just sign in, never approve a prompt.

2. Administrator accounts

  • Separate admin accounts from daily accounts. The account you read email with should not be a Global Administrator.
  • Keep Global Administrators to a minimum, with at least two so you're never locked out, and use narrower admin roles for everything else.
  • Protect admin accounts with the strongest MFA you have and review who holds admin roles every quarter.
  • Keep two emergency-access ("break-glass") accounts, as Microsoft recommends: cloud-only, not tied to any one person, protected with phishing-resistant sign-in such as a FIDO2 security key or certificate-based authentication, excluded from Conditional Access policies that could lock them out, and monitored so every sign-in raises an alert. Document where the keys are and who may use them.

3. Email protection

  • Turn on the preset security policies. With Defender for Office 365 Plan 1, included in Business Premium, you also get Safe Links and Safe Attachments, which check links and files before users open them.
  • Block automatic forwarding to outside addresses. It's one of the most common ways stolen mailboxes leak data.
  • Set up SPF, DKIM and DMARC for your domain so others can't easily send mail pretending to be you.
  • Tag external emails so staff can see at a glance when a message comes from outside the company.
  • Check for suspicious inbox rules regularly, especially after any password-reset or phishing report.

4. Device security

  • Manage company devices with Intune (we do this as part of managed desktop). Business Premium includes Intune Plan 1 for managing Windows, Mac, iOS and Android devices, including personal phones through app protection.
  • Encrypt laptops (BitLocker on Windows, FileVault on Mac) so a lost laptop isn't a data breach.
  • Keep systems patched automatically, and protect endpoints with Defender for Business, also included in Business Premium.
  • Require a compliant device for access to company data once Conditional Access is in place.

5. Recovery planning

  • Decide how you'll restore data if a mailbox, SharePoint site or OneDrive is deleted or encrypted. Many businesses add a dedicated Microsoft 365 backup so they control the recovery. See data backup and recovery.
  • Write down the first hour. Who resets passwords, who revokes sessions, who calls the bank if a payment was redirected, who talks to clients.
  • Test a restore at least once a year. An untested backup is a hope, not a plan.

Which plan gets you what

If you're not sure which plan you have, or want help moving to Business Premium, that's routine Microsoft 365 administration.

ControlBusiness Basic / StandardBusiness Premium
Security defaults (MFA baseline)YesYes
Conditional Access (Entra ID P1)NoYes
Defender for Office 365 Plan 1NoYes
Intune Plan 1 device managementBasic Mobility and Security onlyYes
Defender for Business (endpoints)NoYes

Where to start this week

  1. Confirm MFA is on for every account.
  2. Separate admin accounts and trim the Global Administrator list.
  3. Block external auto-forwarding and review inbox rules.
  4. Check SPF, DKIM and DMARC.
  5. Decide on backup and write down the first-hour plan.

Sources

Vendor details checked September 2026. Licensing and product features change; confirm current terms with the vendor before you buy.

FAQ

Frequently Asked Questions

MFA is the most important single step, but not the only one. Admin accounts, email protection, device security and backups still need attention.

Security defaults are a free, one-switch baseline that turns on MFA and blocks legacy sign-ins. Conditional Access, included in Business Premium through Entra ID P1, lets you write your own rules based on user, device and location.

If you want Conditional Access, full Intune device management, Defender for Business and Defender for Office 365, Business Premium is the business plan that includes them. Business Basic and Standard include baseline protections only.

Microsoft keeps the service running and offers retention features, but many businesses add a separate backup so they can restore deleted or encrypted data on their own schedule. Decide this deliberately.

Keep Reading

More from our blog

Talk to an Engineer about Microsoft 365 security

We'll review your tenant against this checklist and tell you what to fix first.

Direct Lines

Call your local office

Each service area has its own direct line — your call goes straight to the team that covers your neighborhood.

NEW YORK
212-920-9466
Financial District, Midtown, SoHo
NEW YORK
917-268-4940
LIC, Astoria, Flushing
NEW YORK
917-268-4940
DUMBO, Williamsburg, Park Slope
NEW YORK
516-717-0404
Nassau & Suffolk counties
NEW JERSEY
201-374-0092
Bergen, Hudson, Essex
Insights

Latest from the Blog

Certified Partners & Technology Stack

Cisco HP, Hewlett-Packard Microsoft