Most SMEs already have useful security capability in Microsoft 365, especially with Business Premium, but many tenants are simply not configured properly. They are paying for locks they never turned. A secure Microsoft 365 tenant does not require enterprise complexity or a security operations centre. It does require the basics to be done properly, consistently, by someone who knows where the settings are.
This is the checklist we use when we review a tenant. The highest value controls for most SMEs are identity protection, mail security, device management, sensible sharing controls and clear admin processes. Get those right and you are ahead of most.
1. Identity and access
| Check | Why it matters | Evidence / decision required | Status |
|---|---|---|---|
| MFA for all users | Compromised passwords remain a common route into Microsoft 365. | MFA registration and enforcement report. | |
| Conditional Access | Controls access based on user, location, device and risk. | Policy export and exclusions review. | |
| Admin separation | Admin accounts should be protected and used deliberately. | Role assignments and admin account list. | |
| Break-glass account | Provides emergency access if normal sign-in controls fail. | Documented emergency account and monitoring. |
MFA for everyone, no exceptions for the MD. We still hear "but the boss finds it annoying". The boss finding it annoying is cheaper than the boss's mailbox being used to redirect supplier payments.
2. Email and collaboration security
- Enable and review SPF, DKIM and DMARC.
- Review Defender for Office 365 policies where licensed.
- Check anti-phishing, Safe Links and Safe Attachments configuration.
- Restrict external forwarding unless there is a clear business reason.
- Review transport rules and mailbox forwarding.
- Train users on phishing reporting and suspicious requests.
3. Device and data protection
| Area | Minimum sensible control | Why it matters |
|---|---|---|
| Devices | Use Intune for managed devices where possible. | Lost or unmanaged devices can expose company data. |
| Mobile access | Require approved apps and app protection policies. | Protects data on personal mobile devices. |
| Sharing | Set default link types carefully and review external sharing. | Reduces accidental exposure. |
| Sensitivity | Apply simple labels for sensitive content. | Helps users recognise and protect confidential information. |
| Backups | Understand retention, recycle bin and backup requirements. | Microsoft 365 is resilient, but accidental deletion and ransomware planning still matter. |
4. Monthly security review checklist
Security is not a project you finish. Half an hour a month keeps a tenant honest:
- Review risky users and sign-in logs.
- Review admin role assignments.
- Check new guest users and external sharing activity.
- Review Secure Score recommendations, but do not blindly implement without business context.
- Check inactive accounts and leavers.
- Review mail flow rules and forwarding.
Practical recommendation: start with a small number of high-value controls rather than a giant security programme. MFA, Conditional Access, admin role cleanup, mail protection and sharing governance will usually reduce risk quickly. A 60-page security policy nobody implements is worth less than five controls that are actually switched on.
If you are on Microsoft 365 Business Premium, you already own most of what you need, including Defender for Business and Intune. Microsoft detail the security features included on their site. The gap is rarely the licence. It is the configuration, which is exactly what our Microsoft 365 consultancy covers.
Book a Microsoft 365 Optimisation Assessment
Want Microsoft 365 secured properly? We can run a security review and give you a prioritised remediation plan you can actually act on.
Book a Microsoft 365 Optimisation Assessment