Microsoft 365 Security Checklist for UK Small Businesses
For most UK small businesses the Microsoft 365 tenant is now the crown jewels. These are the settings that matter, in the order they matter.
What are the most important Microsoft 365 security settings?
Enforce multi-factor authentication on every account including administrators, block legacy authentication protocols so MFA cannot be bypassed, restrict external mailbox forwarding, enable unified audit logging, and add a third-party backup — native retention is not one.
If your business runs on Microsoft 365, that tenant holds your email, your documents,
your customer data and the identities that unlock everything else. It is where business email
compromise happens, and it is the most valuable thing you own.
The good news: nearly every control below is included in licences you already pay for.
Do these first
Enforce multi-factor authentication everywhere
Every user, every administrator, no exceptions. The common failure is exempting "service accounts"
or a director who finds it inconvenient — and attackers specifically look for those exemptions.
Block legacy authentication
This is the step people miss, and it makes the previous one meaningless if skipped. Older protocols
such as IMAP, POP and SMTP AUTH do not support MFA, so an attacker with a valid password can
authenticate through them and bypass it entirely. Block them.
Restrict external auto-forwarding, and alert on new rules
Silent mailbox rules that forward invoices to an attacker are the signature move of business email
compromise. Restrict external forwarding by policy, and alert whenever a rule is created.
Enable unified audit logging
Without it, you cannot investigate. Turn it on now, with the longest retention your licence permits,
because it only records from the moment it is enabled — it does not backfill.
Then these
- Review who holds global administrator: the target is two or three, not everyone in IT
- Use separate administrative accounts, never used for email or browsing
- Configure conditional access policies for location, device and sign-in risk
- Review guest accounts and remove those from finished projects
- Audit anonymous and organisation-wide sharing links in SharePoint and OneDrive
- Review third-party applications with consented access to your tenant
- Configure DKIM and move DMARC to enforcement so your domain cannot be spoofed
- Set a self-service password reset policy so people do not reuse passwords across systems
Back it up properly
Microsoft 365 is not backed up in the way most businesses assume. Retention policies and recycle bins
protect against accidental deletion for a limited window. They do not survive a compromised account
systematically deleting mailboxes, or a ransomware event syncing encrypted files into SharePoint.
Microsoft's service agreement places responsibility for data backup on the customer. A third-party
backup costs a few pounds per user per month and closes what is, for many SMEs, the largest single
gap in their recovery plan.
Watch Secure Score, but do not chase it
Microsoft Secure Score is a useful indicator and a poor target. Some recommendations do not apply to
your business, and some carry operational cost that outweighs the risk they address for an
organisation your size. Read the recommendations, implement the ones that make sense, and record why
you declined the rest — that record is itself useful evidence for an auditor or insurer.
The controls above are not exotic. They are configuration changes, most of them achievable in a
week, and between them they prevent the large majority of incidents we are called about.