Guide

Microsoft 365 security baseline for small business: the 10 settings we always change

Fractional I.T. services from DASTech ConsultingRelated serviceFractional I.T.See the service

The Microsoft 365 security baseline every small business should set is: turn on multi-factor authentication for all users, block legacy authentication, stop external email auto-forwarding, turn on unified audit logging, enable Safe Links and Safe Attachments, tighten anti-phishing and spoof protection, restrict third-party app consent, reduce the number of global admins, publish SPF, DKIM, and DMARC records, and add sign-in and session controls. These ten changes close the gaps attackers use most, and most of them are free or already included in the plan you are paying for. Here is each one, why it matters, and where to find it.

A note on the admin locations below. Microsoft renames and moves these menus often (Azure AD became Microsoft Entra, and portals shift regularly), so we name the general area rather than an exact click path. Search the admin centre by the name of the setting, and confirm against your own tenant on the day you do the work.

The 10 settings, at a glance

# Setting Why it matters General location
1 MFA for all users Blocks the large majority of account takeovers Microsoft Entra admin centre
2 Block legacy authentication Old protocols skip MFA entirely Entra Conditional Access or Security Defaults
3 Stop external auto-forwarding Cuts off silent mailbox data theft Exchange / Defender outbound policy
4 Unified audit logging Lets you investigate an incident later Microsoft Purview
5 Safe Links and Safe Attachments Catches malicious links and files Microsoft Defender portal
6 Anti-phishing and spoof protection Stops owner and partner impersonation Defender anti-phishing policy
7 Restrict app consent Blocks OAuth consent phishing Entra enterprise applications
8 Fewer global admins Limits the blast radius of one breach Entra roles and administrators
9 SPF, DKIM, DMARC Stops others spoofing your domain Your DNS host plus Defender
10 Sign-in and session controls Protects unmanaged and idle sessions Entra Conditional Access / SSPR

1. Turn on multi-factor authentication for every account

This is the single highest-value change you can make. Passwords get phished, guessed, and reused, and MFA stops the attacker even when they have the password. Turn it on for every user, including yourself and any shared or service accounts you can. On basic plans you can enable Security Defaults, which switches MFA on tenant-wide. If you have Entra ID P1 or P2 (included with Business Premium), use Conditional Access for finer control. Find it in the Microsoft Entra admin centre.

2. Block legacy authentication

Older protocols like POP, IMAP, and SMTP AUTH, along with legacy Office clients, cannot present an MFA prompt. Attackers know this and aim password-spray attacks straight at them, sailing right past the MFA you just enabled. Blocking legacy auth closes that side door. Security Defaults handles this for you, or you can create a dedicated Conditional Access policy in the Entra admin centre. Check for older devices or scanners that still use these protocols before you flip it.

3. Stop external email auto-forwarding

When someone breaks into a mailbox, one of the first things they do is quietly set a rule that forwards a copy of every message to an outside address. Months of invoices, contracts, and password resets leak without anyone noticing. Blocking automatic external forwarding at the tenant level removes that option. Set it in the Exchange admin centre or in the Defender outbound spam policy, depending on which of the two your tenant surfaces it in.

4. Turn on unified audit logging

If you ever have to answer “what did the attacker touch,” you need a record, and you cannot create that record after the fact. Unified audit logging captures sign-ins, file access, rule changes, and admin actions so an incident can actually be investigated. On most tenants it is on by default now, but confirm it rather than assume. Check it in the Microsoft Purview portal.

5. Enable Safe Links and Safe Attachments

Safe Links rewrites and rechecks URLs at the moment a user clicks, and Safe Attachments opens files in a sandbox before delivery. Together they catch phishing pages and malware that get past basic filtering, including links that were harmless when the email arrived and weaponised later. These require Defender for Office 365, which is included in Microsoft 365 Business Premium. Configure them under the threat policies area of the Microsoft Defender portal.

6. Tighten anti-phishing and spoof protection

Business email compromise usually starts with someone pretending to be the owner, the bookkeeper, or a known supplier. Defender’s anti-phishing policy lets you name the people worth protecting and turn on impersonation and spoof detection for them. For a small firm, protecting the owners and anyone who touches money is a quick, high-value step. Set it in the anti-phishing policy in the Defender portal.

7. Restrict who can consent to third-party apps

Consent phishing skips the password entirely. A user is tricked into approving a legitimate-looking app, and that app is then handed standing access to their mailbox and files. By default users can approve many apps on their own. Change the setting so consent for anything sensitive routes to an admin for review. Find it under the enterprise applications and consent settings in the Entra admin centre.

8. Reduce the number of global admins

Global admin is the master key to your whole tenant, and every extra one is another account an attacker can aim for. Keep it to two or fewer, and do not use a global admin account to read daily email or browse the web. Give each admin a normal account for everyday work and a separate account for admin tasks. Review the assignments under roles and administrators in the Entra admin centre.

9. Publish SPF, DKIM, and DMARC records

These three DNS records tell the rest of the internet which servers are allowed to send mail as your domain. Without them, anyone can spoof your address to phish your clients, and your legitimate mail is more likely to land in junk. Set SPF and DMARC at your DNS host and enable DKIM signing through Defender or Exchange. Start DMARC in monitoring mode, then tighten it once you confirm nothing legitimate breaks.

10. Add sign-in and session controls

Finally, decide how sessions behave on devices you do not manage. Shorter idle timeouts, re-authentication on unmanaged devices, and blocking of risky sign-ins all reduce the window an attacker has with a stolen session. Self-service password reset also helps, since it lets users recover securely without a risky help-desk workaround. Configure these through the Conditional Access and self-service password reset settings in the Entra admin centre.

Getting this done without breaking anything

None of these settings is exotic, but the order matters and each one can lock out a legitimate user if you rush it. We apply this baseline for clients as part of our fractional IT service, test it against real devices and workflows first, and document exactly what changed. For law firms, this baseline is the floor rather than the ceiling, since client confidentiality and Clio integrations raise the bar. That work sits under our legal IT services. If you want a second set of eyes on your tenant, get in touch and we will walk through it with you.

FAQ

Common questions.

What is the single most important Microsoft 365 security setting to change first?

Multi-factor authentication for every user. It stops the overwhelming majority of account-takeover attacks on its own, it is free on every plan, and it takes minutes to enable with Security Defaults.

Does Microsoft 365 Business Basic include these security features?

Partly. MFA, Security Defaults, blocking legacy auth, audit logging, and email authentication records are available on the basic plans. Safe Links, Safe Attachments, and the stronger anti-phishing controls require Defender for Office 365, which comes with Microsoft 365 Business Premium.

Is Security Defaults enough for a small business?

For a very small team with no unusual devices, Security Defaults is a solid start because it enforces MFA and blocks legacy auth automatically. As you grow, add regulated clients, or need per-group rules, Conditional Access (included with Business Premium) gives you the control Security Defaults cannot.

How long does it take to apply this baseline?

For a typical small tenant, the technical changes take a few hours. The care goes into testing for older devices, service accounts, and mail flow so nothing legitimate gets blocked, and into rolling out MFA to staff smoothly.

Do law firms need more than this baseline?

Yes. This baseline is the starting point. Firms handling client confidences should layer on tighter data controls, device management, and safeguards around tools like Clio, which is the focus of our legal IT services.