The short answer: the most useful thing you can do for Microsoft 365 security is turn on multifactor authentication (MFA) for every account and block the old sign-in methods that can get around it. Everything else builds from there.
This guide walks you through seven steps in the order we would tackle them, in plain language, so you can see where your business stands. Most of it can be done inside the Microsoft admin tools you already pay for. None of it makes a business breach-proof, but it closes the doors attackers use most.
7 Steps to Secure Microsoft 365 for Your Small Business
1. Require MFA for Everyone, Starting With Administrators
A stolen password is the easiest way into a business email account. MFA adds a second check, usually a prompt in the Microsoft Authenticator app, so a password alone isn't enough. Microsoft says that MFA can block more than 99.2% of identity-based attacks. That's Microsoft's own finding and your results will vary, but this is the single highest-value setting on the list.
- Start with administrators and anyone who handles sensitive information, such as billing, HR, or client records. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) gives the same advice in its guidance on requiring multifactor authentication.
- Not all MFA is equal. Attackers sometimes flood people with approval prompts hoping someone taps "yes" to make them stop. Number matching, where the user types a number shown on the sign-in screen, helps prevent that, and Microsoft's security defaults use it. CISA describes hardware security keys and other phishing-resistant methods as the strongest option, and number matching as a reasonable interim step for smaller businesses. See CISA's guidance on phishing-resistant and number-matching MFA.
2. Protect Your Admin Accounts
Administrator accounts can change settings, reset passwords, and read data across your whole Microsoft 365 setup, so they deserve extra care.
- Use separate accounts. Microsoft recommends that administrators use one account for daily work like email and a separate account only for administration. This also cuts down on how often admins are prompted for MFA.
- Keep the number of administrators small. Everyone with admin rights is one more account an attacker could target.
- Set up emergency access accounts. Microsoft recommends two cloud-only "break glass" accounts with Global Administrator rights, not tied to any one person, for the day normal admins are locked out. Follow Microsoft's emergency access account guidance and store the credentials securely.
3. Block Legacy Sign-In Methods
"Legacy authentication" means older ways of signing in, such as old Office versions or email apps and devices that use IMAP, POP3, or SMTP. Microsoft explains that legacy authentication doesn't support MFA, so even if you require MFA, an attacker who uses an older protocol can sign in without it.
⚠️ Before you flip the switch: some older scanners, multifunction printers, and line-of-business apps still send email through these older methods. List what depends on them first, or you may break scan-to-email. Microsoft has a guide to setting up a multifunction device or application to send email using Microsoft 365.
4. Pick the Right Baseline: Security Defaults or Conditional Access
Microsoft offers two ways to enforce most of the settings above:
- Security defaults cost nothing extra and are simply on or off. They suit smaller organizations that want a solid baseline with little effort.
- Conditional Access requires at least Microsoft Entra ID P1 licensing and is fully customizable. It suits organizations that need exceptions or more control.
According to Microsoft, security defaults require all users to register for MFA, require administrators to use MFA, and block legacy authentication, among other protections. Newer Microsoft 365 tenants may have them turned on already, but that isn't guaranteed for older ones, so verify it rather than assume. Microsoft's page on security defaults has the details. If you move to Conditional Access later, disable security defaults first and replace their protections right away, so there's no gap.
5. Watch for Suspicious Inbox Rules and Forwarding
If someone does get into a mailbox, one thing attackers often do is create inbox rules that forward, hide, or delete certain messages, so the real owner doesn't notice. Microsoft's documentation on detecting and remediating Outlook rules attacks explains how to review them.
- Periodically look for rules you didn't create, especially ones that forward mail to outside addresses.
- Treat unexpected forwarding as a warning sign, not a curiosity.
- If you think an account was compromised, follow Microsoft's steps to respond to a compromised email account, and reset the password and sessions as well as removing the rule.
Our article How Do I Know If My Business Was Hacked? 10 Warning Signs to Watch For covers the wider signs to look for.
6. Plan for Recovery, Not Just Prevention
Security settings lower the odds of a problem. They don't guarantee you'll never have one, so ask a second question: if a file, mailbox, or site were deleted or damaged, how would you get it back, and how quickly? Microsoft runs the service, but you're responsible for your data, and built-in recovery options like recycle bins have time limits and don't cover every situation. Check what your current settings retain, and ask whether you need a separate backup of email, OneDrive, and SharePoint. A backup you've never tested is a hope, not a plan.
7. Clean Up Access When People Join, Change Roles, or Leave
Many security problems come from access nobody remembered to remove. Build a short routine and keep it in writing so it doesn't depend on who remembers:
- New hire: create the account, register MFA on day one, and give access only to what the role needs.
- Role change: review shared mailboxes, groups, and folders they no longer need.
- Departure: disable the account the same day, reset sessions, forward or archive mail as your policy says, and reclaim the license.
Our 10 Practical Tips for Keeping Your Business' Data Secure is a good companion piece.
Quick Self-Check: Where Does Your Business Stand?
- MFA: can you see a list showing that every user has registered an MFA method?
- Admins: who has admin rights today, and does each of them actually need it?
- Legacy sign-in: which scanners, copiers, or older apps send email, and are they on your list?
- Baseline: is security defaults or Conditional Access turned on in your tenant?
- Mailboxes: when did someone last review inbox rules and forwarding?
- Recovery: have you ever tested restoring a file or mailbox?
- Offboarding: is there a written checklist for when someone leaves?
Common Questions
Is MFA really necessary if we have strong passwords?
Yes. Strong passwords can still be guessed, reused, or stolen through phishing. MFA means a stolen password alone isn't enough to get in.
Will MFA slow my team down?
Slightly, at sign-in. Microsoft decides when to prompt users based on things like location, device, and task, so people usually aren't prompted constantly. Registering everyone in one planned session avoids most of the frustration.
We're a small business. Are we really a target?
Attackers often automate their attempts and don't need to know who you are. Small businesses often lack a dedicated IT person, which is why these basics matter.
Can we do this ourselves?
Many of these steps are within reach if you have someone comfortable with the Microsoft admin centers. The riskier parts, such as blocking legacy sign-in without breaking a scanner, or moving to Conditional Access, are where a second opinion is worth having. See what IT support actually covers.
How Bridge IT Services Helps Massachusetts Businesses
Bridge IT Services, based in Braintree, MA, supports Massachusetts businesses within about 50 miles of our office with managed IT, network, and security support. If you would like to talk through your Microsoft 365 setup with a local team, we're glad to help.
Want a second set of eyes on your Microsoft 365 setup?
Book a free consultation by phone at (857) 344-0222 or in person at 400 Franklin St, Suite 203, Braintree.





