Microsoft 365 Security Checklist for Small Businesses

September 20, 2026

Seven practical steps to secure email, files and accounts.

Cybersecurity · Braintree, MA

Microsoft 365 Security Checklist for Small Businesses

📍 Serving Massachusetts, within 50 miles of Braintree ⏱ 7 min read 🗓 Published September 2026

The short answer: the most useful thing you can do for Microsoft 365 security is turn on multifactor authentication (MFA) for every account and block the old sign-in methods that can get around it. Everything else builds from there.

This guide walks you through seven steps in the order we would tackle them, in plain language, so you can see where your business stands. Most of it can be done inside the Microsoft admin tools you already pay for. None of it makes a business breach-proof, but it closes the doors attackers use most.

7 Steps to Secure Microsoft 365 for Your Small Business

1. Require MFA for Everyone, Starting With Administrators

A stolen password is the easiest way into a business email account. MFA adds a second check, usually a prompt in the Microsoft Authenticator app, so a password alone isn't enough. Microsoft says that MFA can block more than 99.2% of identity-based attacks. That's Microsoft's own finding and your results will vary, but this is the single highest-value setting on the list.

  • Start with administrators and anyone who handles sensitive information, such as billing, HR, or client records. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) gives the same advice in its guidance on requiring multifactor authentication.
  • Not all MFA is equal. Attackers sometimes flood people with approval prompts hoping someone taps "yes" to make them stop. Number matching, where the user types a number shown on the sign-in screen, helps prevent that, and Microsoft's security defaults use it. CISA describes hardware security keys and other phishing-resistant methods as the strongest option, and number matching as a reasonable interim step for smaller businesses. See CISA's guidance on phishing-resistant and number-matching MFA.

2. Protect Your Admin Accounts

Administrator accounts can change settings, reset passwords, and read data across your whole Microsoft 365 setup, so they deserve extra care.

  • Use separate accounts. Microsoft recommends that administrators use one account for daily work like email and a separate account only for administration. This also cuts down on how often admins are prompted for MFA.
  • Keep the number of administrators small. Everyone with admin rights is one more account an attacker could target.
  • Set up emergency access accounts. Microsoft recommends two cloud-only "break glass" accounts with Global Administrator rights, not tied to any one person, for the day normal admins are locked out. Follow Microsoft's emergency access account guidance and store the credentials securely.

3. Block Legacy Sign-In Methods

"Legacy authentication" means older ways of signing in, such as old Office versions or email apps and devices that use IMAP, POP3, or SMTP. Microsoft explains that legacy authentication doesn't support MFA, so even if you require MFA, an attacker who uses an older protocol can sign in without it.

⚠️ Before you flip the switch: some older scanners, multifunction printers, and line-of-business apps still send email through these older methods. List what depends on them first, or you may break scan-to-email. Microsoft has a guide to setting up a multifunction device or application to send email using Microsoft 365.

4. Pick the Right Baseline: Security Defaults or Conditional Access

Microsoft offers two ways to enforce most of the settings above:

  • Security defaults cost nothing extra and are simply on or off. They suit smaller organizations that want a solid baseline with little effort.
  • Conditional Access requires at least Microsoft Entra ID P1 licensing and is fully customizable. It suits organizations that need exceptions or more control.

According to Microsoft, security defaults require all users to register for MFA, require administrators to use MFA, and block legacy authentication, among other protections. Newer Microsoft 365 tenants may have them turned on already, but that isn't guaranteed for older ones, so verify it rather than assume. Microsoft's page on security defaults has the details. If you move to Conditional Access later, disable security defaults first and replace their protections right away, so there's no gap.

5. Watch for Suspicious Inbox Rules and Forwarding

If someone does get into a mailbox, one thing attackers often do is create inbox rules that forward, hide, or delete certain messages, so the real owner doesn't notice. Microsoft's documentation on detecting and remediating Outlook rules attacks explains how to review them.

  • Periodically look for rules you didn't create, especially ones that forward mail to outside addresses.
  • Treat unexpected forwarding as a warning sign, not a curiosity.
  • If you think an account was compromised, follow Microsoft's steps to respond to a compromised email account, and reset the password and sessions as well as removing the rule.

Our article How Do I Know If My Business Was Hacked? 10 Warning Signs to Watch For covers the wider signs to look for.

6. Plan for Recovery, Not Just Prevention

Security settings lower the odds of a problem. They don't guarantee you'll never have one, so ask a second question: if a file, mailbox, or site were deleted or damaged, how would you get it back, and how quickly? Microsoft runs the service, but you're responsible for your data, and built-in recovery options like recycle bins have time limits and don't cover every situation. Check what your current settings retain, and ask whether you need a separate backup of email, OneDrive, and SharePoint. A backup you've never tested is a hope, not a plan.

7. Clean Up Access When People Join, Change Roles, or Leave

Many security problems come from access nobody remembered to remove. Build a short routine and keep it in writing so it doesn't depend on who remembers:

  • New hire: create the account, register MFA on day one, and give access only to what the role needs.
  • Role change: review shared mailboxes, groups, and folders they no longer need.
  • Departure: disable the account the same day, reset sessions, forward or archive mail as your policy says, and reclaim the license.

Our 10 Practical Tips for Keeping Your Business' Data Secure is a good companion piece.

Quick Self-Check: Where Does Your Business Stand?

  1. MFA: can you see a list showing that every user has registered an MFA method?
  2. Admins: who has admin rights today, and does each of them actually need it?
  3. Legacy sign-in: which scanners, copiers, or older apps send email, and are they on your list?
  4. Baseline: is security defaults or Conditional Access turned on in your tenant?
  5. Mailboxes: when did someone last review inbox rules and forwarding?
  6. Recovery: have you ever tested restoring a file or mailbox?
  7. Offboarding: is there a written checklist for when someone leaves?

Common Questions

Is MFA really necessary if we have strong passwords?

Yes. Strong passwords can still be guessed, reused, or stolen through phishing. MFA means a stolen password alone isn't enough to get in.

Will MFA slow my team down?

Slightly, at sign-in. Microsoft decides when to prompt users based on things like location, device, and task, so people usually aren't prompted constantly. Registering everyone in one planned session avoids most of the frustration.

We're a small business. Are we really a target?

Attackers often automate their attempts and don't need to know who you are. Small businesses often lack a dedicated IT person, which is why these basics matter.

Can we do this ourselves?

Many of these steps are within reach if you have someone comfortable with the Microsoft admin centers. The riskier parts, such as blocking legacy sign-in without breaking a scanner, or moving to Conditional Access, are where a second opinion is worth having. See what IT support actually covers.

How Bridge IT Services Helps Massachusetts Businesses

Bridge IT Services, based in Braintree, MA, supports Massachusetts businesses within about 50 miles of our office with managed IT, network, and security support. If you would like to talk through your Microsoft 365 setup with a local team, we're glad to help.

Want a second set of eyes on your Microsoft 365 setup?

Book a free consultation by phone at (857) 344-0222 or in person at 400 Franklin St, Suite 203, Braintree.

Book a Free Consultation →

This article is general guidance, not a guarantee of security or compliance for any organization. Microsoft settings and licensing change, so confirm current details in Microsoft's documentation.

Warning signs your business was hacked — blog illustration
By site-1fJuLQ April 22, 2026
Worried your business was hacked? Here are 10 warning signs of a cyberattack and what to do next. Bridge IT Services helps South Shore MA businesses stay secure.
Evolution of cybersecurity roles and responsibilities — blog featured image
February 23, 2023
How cybersecurity roles are changing, and the twelve security functions to consider as you build or restructure your team. From Bridge IT Services.
Infographic: 10 practical tips for keeping business data secure
By site-1fJuLQ February 23, 2023
Ten practical ways to protect business data, from passwords and software updates to Wi-Fi security and employee training. From Bridge IT Services in Braintree, MA.
By site-1fJuLQ February 13, 2023
What IT support is, how Level 1 and Level 2 help desk tiers work, and why small businesses need it. From Bridge IT Services in Braintree, MA.
February 9, 2023
Cloud providers secure their data centers, but your business still has security work to do. An introduction to cloud security from Bridge IT Services.