The Microsoft 365 Security Settings Small Businesses Never Turn On

Microsoft 365 defaults are usable, not safe. Here's how to check where your tenant stands in five minutes, the settings most small businesses never enable, and a prioritized action plan.

Here is an uncomfortable truth about Microsoft 365: the day you signed up, Microsoft handed you a powerful security toolbox and then quietly left most of the tools in the drawer. Not because Microsoft is careless, but because a brand-new tenant has to work for everybody, from the one-person accounting shop to the sales team still using a 2011 email app. So the defaults are tuned to "everyone can log in and get their mail," not "nobody can break in."

Attackers know this better than you do. They are not sitting in a dark room writing custom code to defeat your firewall. They are logging in with a password they bought for a few dollars, through a door you never bothered to lock. And email is the door, the number one attack surface for small businesses, because your inbox is where the money conversations happen.

Below are the settings that separate a hardened Microsoft 365 tenant from a sitting duck. A small business owner, or whoever helps with your IT, can turn them on. Most are free. Most take minutes. And unless someone has checked, you can't assume they're on.

Check where you stand in five minutes

Before changing anything, look at what you have. You'll need an account with admin rights.

  1. Is MFA enforced? In the Microsoft Entra admin center, go to Entra ID > Overview > Properties and scroll to Security defaults. "Your organization is protected by security defaults" means MFA and the legacy-sign-in block are on. If it says you're using Conditional Access policies instead, ask whoever set them up to confirm every user is covered. If it says you're not protected by either, start with Setting 1 below. (Microsoft's instructions)
  2. What does Microsoft think you're missing? Sign in to the Microsoft Defender portal and go straight to security.microsoft.com/securescore (Microsoft's guide). The Recommended actions tab is a ranked to-do list for your tenant. More on it in Setting 7.
  3. Is anyone's mail being forwarded outside? Ask each person to open Outlook on the web, then Settings > Mail > Rules and Forwarding, and check for anything they didn't set up. A rule that forwards mail to an outside address is the classic sign of a compromised mailbox.

Why identity is the whole ballgame

Before we get into knobs and switches, understand what you are actually defending. You are not really defending "email." You are defending identity: the username and password that proves you are you. Once an attacker has your identity, your email, your files, your shared calendars, and your ability to send messages that look legitimate all belong to them.

Here is why that matters. Verizon's Data Breach Investigations Report finds year after year that stolen credentials are one of the most common ways attackers get in, and that the human element (someone getting phished, reusing a password, clicking the wrong link) shows up in the majority of breaches. Attackers do not need to be geniuses. They need one working login.

And they very often have one, because passwords leak constantly. This is the mechanism behind credential stuffing, where attackers take username-and-password pairs stolen from some unrelated breach and try them against your Microsoft 365 login, betting that your employee reused the same password. That bet pays off far too often.

So the single most important thing you can do is make a stolen password not enough. That is what most of the settings below accomplish.

Setting 1: Multi-factor authentication for every single user

Multi-factor authentication (MFA) means requiring a second proof of identity in addition to the password, usually a tap on an approval in an app on your phone or a one-time code. The idea is simple: even if a criminal has your password, they do not have your phone.

How effective is it? Microsoft has said publicly that enabling MFA blocks more than 99.9 percent of account compromise attacks. Read that again. One setting stops the overwhelming majority of account takeovers. In that same research, Microsoft noted it was fending off hundreds of millions of fraudulent sign-in attempts every single day. MFA is the closest thing to a silver bullet that exists in this business.

There are two ways to turn MFA on in Microsoft 365, and the difference matters.

Security Defaults is a single on-off switch Microsoft provides for smaller organizations. Flip it on and Microsoft enforces a sensible baseline: MFA required for all users, MFA always required for administrators, and old insecure sign-in methods blocked. Microsoft has switched it on automatically for new tenants since late 2019, but plenty of businesses turned it off during setup and never turned it back on. It is free, fast, and for a small business with no full-time IT staff, often the right answer. Microsoft explains Security Defaults here.

Conditional Access is the grown-up version: a rules engine that says "if this condition is true, then require that." For example, "if someone signs in from outside our country, require MFA and block legacy apps," or "if the sign-in looks risky, force a password reset." It gives you far more control, but it requires a higher-tier license (typically Microsoft Entra ID P1, often included in Microsoft 365 Business Premium) and someone who knows how to configure it.

The rule of thumb: if you are tiny and want protection today, turn on Security Defaults. If you have Business Premium and an IT partner, use Conditional Access so you can add smarter rules. Either way, the non-negotiable is that MFA is on for everyone, especially the owner and anyone who touches money.

One honest caveat: MFA that relies on tapping Approve or typing a texted code can still be beaten by phishing pages that sit between you and the real Microsoft login and steal your signed-in session after you approve. That's why phishing-resistant sign-in, such as passkeys, is now the recommendation for admins and anyone who handles money. We cover how to set it up in MFA fatigue attacks and passkeys.

Setting 2: Block legacy authentication

This one is invisible and it is exactly what attackers pray you overlook.

Legacy authentication (or "legacy auth") refers to old sign-in methods used by older email protocols like IMAP, POP, and SMTP AUTH, the plumbing that lets a mail app connect to a server. The problem is that these old protocols were built before MFA existed, and they cannot present that second factor. So when a login comes in over legacy auth, it checks the password and that is it. No MFA prompt. No second door.

Think about what that means. You can turn MFA on for your whole company, feel protected, and an attacker can stroll right past it through an ancient protocol that never asks for the second factor. It is a bypass hiding in plain sight.

How much do attackers rely on this? According to Microsoft's official guidance on blocking legacy authentication, more than 97 percent of credential stuffing attacks and more than 99 percent of password spray attacks use legacy authentication protocols. The good news is that Microsoft has already switched off basic authentication for most Exchange Online connections (POP, IMAP, ActiveSync and the rest). The main holdout is SMTP AUTH, which older copiers, scanners and business apps use to send email, and Microsoft plans to turn it off by default for existing tenants at the end of December 2026. Turning on Security Defaults blocks legacy sign-ins entirely; with Conditional Access you create a specific policy to block them. Either way, check first whether your copier or accounting software sends email through Microsoft 365, because it may need to be set up again.

Setting 3: Disable automatic external email forwarding

Now we get to a favorite trick of the people running business email compromise (BEC), the scam where a criminal uses a compromised or spoofed email account to trick a company into sending money or sensitive data to the wrong place. BEC is not a small problem. The FBI's Internet Crime Complaint Center logged about $3 billion in reported BEC losses in 2025, second only to investment fraud among the crimes it tracks. (We go deeper on how it works in our piece on business email compromise.)

Here is the specific move. When an attacker gets into a mailbox, one of the first things they do is set up a hidden rule that automatically forwards incoming mail to an outside address they control. Now they can read your invoices, contracts, and payment threads quietly, from the outside, even if you change the password later. They watch, they wait for a real invoice, and they pounce.

Microsoft has blocked automatic forwarding to outside addresses by default for new tenants since 2021, but older tenants can still allow it, and the default setting (labeled "Automatic - System-controlled") behaves differently depending on your tenant. Don't leave it to chance. In the Microsoft Defender portal, go to Email & collaboration > Policies & rules > Threat policies > Anti-spam, open the outbound policy and set automatic forwarding to Off. If a specific person genuinely needs external forwarding, allow it as a deliberate exception, not as a default that applies to everyone.

Setting 4: Turn on Microsoft Defender for Office 365 protections

If your plan includes Microsoft Defender for Office 365 (Business Premium does), two features are worth enabling deliberately.

Safe Links rewrites the web links inside incoming emails so that when someone clicks, Microsoft checks the destination in real time, at the moment of the click, and blocks it if it has turned malicious. This matters because attackers often send a clean link first and weaponize it later, after the email has already sailed past your filters.

Safe Attachments opens suspicious attachments in an isolated sandbox, a safe throwaway environment, to watch what they do before they ever reach your inbox. If the file tries something nasty, it never gets delivered.

Together they cover the two things people actually click: links and attachments. The quickest way to set them up properly is Microsoft's preset security policies (Standard or Strict), which apply its recommended settings for you instead of you tuning each policy by hand.

Setting 5: Anti-phishing and impersonation protection

Microsoft 365 includes anti-phishing policies that do something clever: they watch for impersonation. Attackers love to send email that looks like it came from the boss ("Hey, can you grab some gift cards for a client, I'm in a meeting") or from a trusted vendor. Impersonation protection lets you tell Microsoft, "these are our important people and our real domains," so it can flag messages that mimic them but come from somewhere else.

You configure it by adding the names and addresses of your most-impersonated users (the owner, the finance lead) and your own domain to the protected list. It is one of the few defenses aimed squarely at the human trickery that makes BEC work.

Setting 6: Turn on audit logging so you can investigate later

Prevention fails sometimes. When it does, the difference between "we contained it in an hour" and "we have no idea what happened" comes down to logs.

The Unified Audit Log records activity across Microsoft 365: who signed in, who changed a mailbox rule, who accessed which files. Mailbox auditing records actions inside individual mailboxes. Microsoft's own guidance for responding to a compromised email account leans heavily on these logs to figure out what an attacker did, including hunting down those hidden forwarding rules.

The good news is that Microsoft now turns mailbox auditing on by default for every organization. The catch is that it can be switched off, and logs are only kept for a limited time, so confirm it's working today rather than finding out on the worst day. Open Audit in the Microsoft Purview portal: if you see a prompt to start recording user and admin activity, turn it on.

Setting 7: Use Microsoft Secure Score as your roadmap

You do not have to guess whether you have done enough, because Microsoft grades you. Microsoft Secure Score is a built-in scorecard, found in the Microsoft Defender portal, that measures your security posture as a percentage and lists specific improvement actions ranked by impact. Microsoft describes it as a measurement of your security posture, where a higher number means you have taken more of the recommended actions.

Think of it as a to-do list written by the people who built the product. It tells you exactly which settings to change and how many points each is worth, so you can knock out the high-impact items first. It is the single best place to start, because it turns "am I secure?" into a concrete, prioritized checklist.

Setting 8: Least-privilege admin and separate admin accounts

Administrator accounts are the master keys, and they should be treated that way. Three habits matter here.

First, least privilege: give each person only the access they actually need, not blanket admin rights "just in case." Second, keep the number of Global Admins small; Microsoft recommends limiting these all-powerful accounts to a handful of people. Fewer master keys means fewer keys to steal. Third, admins should use a separate account for admin work, distinct from the everyday account they use to read email and browse the web. That way, if their daily account gets phished, the attacker lands on a low-privilege account, not one that can rewrite your entire tenant.

Setting 9: Self-service password reset and banned-password lists

Two smaller settings round this out. Self-service password reset lets users securely reset their own passwords after verifying their identity. That sounds like a convenience feature, but it is also a security one: resets do not have to route through a help desk that a social engineer can fool. It's included with Microsoft 365 Business Standard and Premium, not Business Basic. And banned-password lists reject weak or common passwords before they are ever set. Microsoft blocks the most common ones for everyone; adding your own list (your company name, your street, "Company2026!") needs Business Premium or Microsoft Entra ID P1.

A real scenario: the invoice that quietly changed

Picture a small design studio. The office manager reuses her email password on a few other sites. One of those sites gets breached. Months later, an attacker tries the leaked password against the studio's Microsoft 365 login, and it works, because MFA was never turned on.

The attacker does not send a single flashy email. Instead, they create a hidden inbox rule that forwards all of her incoming mail to an outside address. For two weeks they read everything. When a real invoice arrives from a genuine vendor, they wait for the reply thread, then jump in with a near-identical email: "We've updated our banking details, please send payment to the new account." The client pays. The money is gone before anyone notices, and because nobody had checked that auditing was still on, reconstructing what happened is a nightmare.

Every single step of that attack is stopped by settings in this article. MFA blocks the initial login. Disabling external forwarding kills the silent surveillance. Impersonation protection flags the fake reply. Audit logging lets you see it all. None of it required a bigger budget.

Your prioritized action plan

If you do nothing else this month, do these, in this order:

  1. Turn on MFA for every user. For most small businesses, enabling Security Defaults does this and blocks legacy auth in one move. This is the single highest-value step, full stop.
  2. Block legacy authentication if it is not already handled by Security Defaults, and find out which copiers, scanners or apps still send email with SMTP AUTH before Microsoft switches it off at the end of 2026.
  3. Disable automatic external email forwarding with an outbound spam policy, allowing exceptions only where genuinely needed.
  4. Open Microsoft Secure Score in the Defender portal and work the top recommendations. It is your customized roadmap.
  5. Confirm audit logging and mailbox auditing are on, today, so you can investigate if something ever goes wrong.
  6. Turn on Microsoft's preset security policies (Standard or Strict) under Email & collaboration > Policies & rules > Threat policies in the Defender portal. They apply Microsoft's recommended anti-spam, anti-malware and anti-phishing settings in one step, including Safe Links and Safe Attachments if your plan has Defender for Office 365. Then add your owner and finance lead to impersonation protection.
  7. Clean up admin accounts: limit Global Admins, apply least privilege, and give admins separate accounts for privileged work.
  8. Enable self-service password reset and banned-password protection so weak and reused passwords stop being an option.

Microsoft 365 gave you a strong lock the day you signed up. You just have to turn the key. Almost everything above is free, and together it defeats the attacks that most often hit small businesses. The same email protections matter on the outside of your domain too: our SPF, DKIM and DMARC guide covers stopping people from faking your address.

When to call someone

  • Security Defaults is off, Conditional Access isn't set up, and nobody is sure why.
  • You find a forwarding rule or a sign-in you can't explain.
  • You want to block SMTP AUTH but a copier, scanner or line-of-business app still depends on it.

If you'd rather have someone handle the hardening and keep an eye on it, that's what our cybersecurity service does. If you already have an IT person, our co-managed Microsoft 365 hardening and monitoring takes on these settings and watches for drift while they keep the day-to-day.

Related reading