Microsoft 365 security best practices for small businesses
Ten things worth doing, ordered by how much risk each one removes rather than how easy it is to tick off.
Security advice for small businesses tends to arrive as a list of forty items with no indication of which ones matter. This is the shorter version, ordered by how much risk each step actually removes.
The underlying point: at this size of business, attacks are overwhelmingly opportunistic and identity-based. Somebody gets a password, signs in, reads the mail, and either invoices your customers or waits for a payment conversation to interrupt. Almost everything below is aimed at making that harder.
Start with identity, because that is where attacks start
1. Enforce multi-factor authentication for everyone
This is the single highest-value control available and it is included in every Microsoft 365 plan. A stolen password on its own becomes useless.
The common mistake is enabling it for most people but exempting the awkward accounts: the director who finds it annoying, the shared sales mailbox, the account a piece of software uses. Attackers do not need to get through the front door if a side window is open, and those exempted accounts are usually the highest-value ones. If an account genuinely cannot use multi-factor authentication, restrict where it can sign in from instead.
Prefer an authenticator app over SMS codes. SMS is meaningfully better than nothing and meaningfully worse than an app.
2. Reduce the number of administrators
Global administrator rights should be rare and deliberate. Most businesses of twenty people need one or two, not six. Every additional administrator is another account whose compromise means total compromise.
Practical version: name the people who genuinely need it, remove the rest, and give day-to-day tasks a lesser role that covers what they actually do. Keep one break-glass account with a long unique password, stored somewhere physical and safe, not used routinely.
3. Remove accounts for people who have left
Obvious, frequently not done, and easy to check. A leaver's account with a known password and no multi-factor prompt is an open invitation. Build it into whatever process you use when someone leaves, along with removing them from shared mailboxes and revoking their sessions so an already signed-in device stops working.
Close the side doors
4. Disable legacy authentication
Older sign-in protocols were designed before multi-factor authentication existed and cannot enforce it. If they are still enabled, an attacker can use them to sign in with just a password, bypassing the control you carefully switched on. Modern tenants are secure by default here, but tenants created years ago frequently are not.
5. Use conditional access if your licence includes it
Conditional access lets you set rules such as requiring multi-factor authentication from unfamiliar locations, blocking sign-ins from countries you do not operate in, or requiring a managed device for administrative work. This is often the exact case where a business is already paying for a licence tier that includes the feature and has never used it.
Protect email specifically
6. Check for forwarding rules, and keep checking
One of the first things an attacker does after getting into a mailbox is set a rule quietly forwarding mail to an address they control, or moving messages containing words like "invoice" or "payment" into an obscure folder. Blocking automatic external forwarding by default is a sensible tenant-wide setting, and reviewing existing rules is a quick win.
7. Set up SPF, DKIM and DMARC
These three DNS records let receiving mail servers verify that mail claiming to come from your domain really did. Without them, anyone can send email as you, which matters most when the target is one of your own customers being asked to change bank details. They also improve your legitimate mail reaching inboxes.
Introduce DMARC gradually. Going straight to a strict policy without checking what it will reject is how businesses accidentally block their own invoicing system.
Get files and sharing under control
8. Audit external sharing
Find anything shared with "anyone with the link" and decide whether it should still be. These links do not expire unless you tell them to, are not tied to a person, and work for whoever holds them. Setting a default expiry on new anonymous links, and defaulting sharing to named people instead, removes most of the ongoing problem.
While you are there, look at guest accounts. Contractors and partners accumulate access and rarely lose it when a project ends.
This work has become more consequential with AI assistants in the mix. Copilot respects permissions, which sounds reassuring until you remember that the permissions are the problem. If a document is technically readable by everyone, an assistant will find it and quote from it when someone asks a plausible question.
Devices
9. Know which devices hold company data
You do not necessarily need full device management, but you do need a way to remove company data from a lost laptop or a departing employee's phone. At minimum: disk encryption on company laptops, screen locks, and a route to wipe company data remotely.
Recovery, tested
10. Find out whether you can actually restore things
Microsoft protects its infrastructure. It does not protect you from your own mistakes indefinitely. Deleted items and files are recoverable for a limited retention window, and after that they are gone.
The question worth answering is not "do we have backup" but "has anyone ever restored anything". Pick a file and a mailbox item, try to restore them, and time it. That exercise usually reveals either a gap or a reassuring answer, and both are worth having.
The habits that matter more than settings
Configuration is the part you can finish. These are the parts you cannot, and they matter more.
- People. The most effective attacks are convincing rather than technical: an email from a supplier about a changed bank account, sent from a real compromised mailbox. Make it normal to verify payment changes by phone, using a number you already had.
- Patching. Keeping devices and browsers current closes the vulnerabilities that automated attacks rely on.
- Knowing what normal looks like. Audit logging switched on now is what lets you answer questions later.
- Reviewing periodically. Tenants drift. A setup that was tidy two years ago and has had ten joiners since is not tidy now.
What to do first if you only do three things
- Enforce multi-factor authentication on every account, with no exceptions.
- Cut administrator accounts down to the people who genuinely need them, and check no former staff have access.
- Look for mailbox forwarding rules you did not create.
Those three take a fraction of the effort of the full list and remove most of the realistic risk. The rest is worth doing, and it is worth doing in that order.
Questions about this topic
Does Microsoft 365 Business Premium include everything we need?
For most small businesses it covers the important ground: conditional access, device management, and stronger email protection alongside the basics. The gap is usually not the licence but the configuration, since a considerable amount of what Business Premium includes is not switched on by default and needs deliberate setup.
Is Microsoft 365 secure by default?
Newer tenants start in a reasonable position, and Microsoft has improved the defaults substantially. Older tenants are the problem: they were created when the defaults were weaker, and they carry years of accumulated permissions, leftover accounts and settings nobody has revisited. The defaults also cannot know how your business works, so decisions like external sharing still need making.
Do we need Cyber Essentials?
You need it if a customer or contract requires it, and it is a reasonable target even if not, because the controls it asks for are sensible. What it is not is a substitute for reviewing your own environment, since it certifies against a baseline rather than telling you what is specifically wrong with your setup.

Need a clearer picture of your Microsoft 365 setup?
A free Microsoft 365 assessment is usually the most useful first step: an evidence-led look at security, governance and licensing, with clear priorities.
