Microsoft 365 Security Checklist for UK Small Businesses

For most UK small businesses the Microsoft 365 tenant is now the crown jewels. These are the settings that matter, in the order they matter.

In short

What are the most important Microsoft 365 security settings?

Enforce multi-factor authentication on every account including administrators, block legacy authentication protocols so MFA cannot be bypassed, restrict external mailbox forwarding, enable unified audit logging, and add a third-party backup — native retention is not one.

If your business runs on Microsoft 365, that tenant holds your email, your documents,

your customer data and the identities that unlock everything else. It is where business email

compromise happens, and it is the most valuable thing you own.

The good news: nearly every control below is included in licences you already pay for.

Do these first

Enforce multi-factor authentication everywhere

Every user, every administrator, no exceptions. The common failure is exempting "service accounts"

or a director who finds it inconvenient — and attackers specifically look for those exemptions.

Block legacy authentication

This is the step people miss, and it makes the previous one meaningless if skipped. Older protocols

such as IMAP, POP and SMTP AUTH do not support MFA, so an attacker with a valid password can

authenticate through them and bypass it entirely. Block them.

Restrict external auto-forwarding, and alert on new rules

Silent mailbox rules that forward invoices to an attacker are the signature move of business email

compromise. Restrict external forwarding by policy, and alert whenever a rule is created.

Enable unified audit logging

Without it, you cannot investigate. Turn it on now, with the longest retention your licence permits,

because it only records from the moment it is enabled — it does not backfill.

Then these

  • Review who holds global administrator: the target is two or three, not everyone in IT
  • Use separate administrative accounts, never used for email or browsing
  • Configure conditional access policies for location, device and sign-in risk
  • Review guest accounts and remove those from finished projects
  • Audit anonymous and organisation-wide sharing links in SharePoint and OneDrive
  • Review third-party applications with consented access to your tenant
  • Configure DKIM and move DMARC to enforcement so your domain cannot be spoofed
  • Set a self-service password reset policy so people do not reuse passwords across systems

Back it up properly

Microsoft 365 is not backed up in the way most businesses assume. Retention policies and recycle bins

protect against accidental deletion for a limited window. They do not survive a compromised account

systematically deleting mailboxes, or a ransomware event syncing encrypted files into SharePoint.

Microsoft's service agreement places responsibility for data backup on the customer. A third-party

backup costs a few pounds per user per month and closes what is, for many SMEs, the largest single

gap in their recovery plan.

Watch Secure Score, but do not chase it

Microsoft Secure Score is a useful indicator and a poor target. Some recommendations do not apply to

your business, and some carry operational cost that outweighs the risk they address for an

organisation your size. Read the recommendations, implement the ones that make sense, and record why

you declined the rest — that record is itself useful evidence for an auditor or insurer.

The controls above are not exotic. They are configuration changes, most of them achievable in a
week, and between them they prevent the large majority of incidents we are called about.
Written by Cipher Knights Security Team , Security Consultant at CIPHER KNIGHTS LTD (company number 16141995), Leicester, United Kingdom. General guidance rather than advice for your specific circumstances — call +44 7424 967568 to discuss your own situation.