Blog · Cybersecurity · July 12, 2026 · By Mike Parker

The Microsoft 365 Security Settings Most SMBs Never Turn On

Your tenant was set up to get everyone working, not to keep attackers out. Six settings — MFA policy, legacy authentication, app consent, mail rules, audit logging, and real backup — separate the tenants that survive an attack from the ones that make the news.

Think back to the day your Microsoft 365 tenant was created. Somebody — a previous IT guy, a vendor, maybe you — spent an afternoon getting mail to flow and files to sync, and then moved on. Nobody has meaningfully revisited the security configuration since. Meanwhile, that tenant has become the front door to everything: email, contracts, financials, customer data.

Out of the box, Microsoft 365 is tuned to minimize friction, not risk. Attackers know the defaults better than most administrators do, and they aim at them every day. The good news: the highest-value fixes aren't expensive add-ons. They're settings — already included in what you pay for — that most small-business tenants have simply never turned on.

First, the shared-responsibility truth

Microsoft secures the platform: the datacenters, the service uptime, the infrastructure. Under the shared responsibility model, what happens inside your tenant — who can sign in and how, which apps get access, what's logged, how data is protected and recovered — is your job, or your IT partner's. "We're in the cloud, so we're covered" is where most tenant horror stories begin. With that settled, here are the six settings that matter most.

1. Enforce MFA with Conditional Access — not the honor system

Microsoft's own research (published 2023) found that multi-factor authentication blocks over 99.2% of account-compromise attacks. There is no other control with that return. But "we have MFA" usually means "we asked people to enroll" — and there's a canyon between offering MFA and enforcing it.

Enforcement is policy. At minimum, turn on security defaults. Better, use Conditional Access to require MFA for everyone, everywhere, and layer in rules that fit how you work: block sign-ins from countries you'll never operate in, require compliant devices for admins, and step up scrutiny on risky logins. Admin accounts come first — every one of them, no exceptions — and for those, prefer phishing-resistant methods like passkeys over push prompts that a tired thumb can approve.

2. Block legacy authentication

Here's the quiet loophole: older protocols — POP, IMAP, SMTP AUTH — support only a username and password. No MFA challenge at all. Attackers running password-spray campaigns deliberately target them, because a tenant with "MFA enabled" but legacy auth alive is a locked front door next to an open window.

Check your sign-in logs for what still uses legacy protocols (it's usually an ancient scanner or a line-of-business relic), fix those, then block legacy authentication tenant-wide with Conditional Access. This is one afternoon of work that removes a whole attack class.

3. Stop rubber-stamping app consent

By default, users can grant third-party apps standing access to their mailbox and files. Attackers exploit this with convincing consent screens — "This app would like to read your email" — and here's the nasty part: the access rides on an authorization grant, not the password, so it survives password resets and even MFA.

Restrict user consent to low-risk permissions from verified publishers (or turn it off entirely), enable the admin consent workflow so requests route to someone qualified to judge them, and audit the apps that already have access. Most tenants find at least one surprise.

Why these settings matter

The math on tenant hardening

The controls are already in your subscription. The losses land on businesses that never switched them on.

99.2%

of account-compromise attacks are blocked by enforced MFA

Microsoft research, 2023

$3.05B

reported U.S. losses to business email compromise in 2025 — the scam that starts in a mailbox

FBI IC3 2025

180

days of audit-log retention by default — quiet compromises can outlast it

Microsoft Purview documentation

4. Audit your mail rules — attackers love them

When criminals compromise a mailbox, their first moves are mail rules: auto-forward copies of invoices and wire instructions to an outside address, and auto-delete the replies so the owner never notices the conversation happening in their name. This is the machinery of business email compromise — a crime that cost U.S. businesses a reported $3.05 billion in 2025, per the FBI's IC3 report.

Disable external auto-forwarding at the tenant level, alert on newly created inbox rules, and review existing rules and transport rules on a schedule. A forwarding rule nobody recognizes is a five-alarm finding, not a curiosity.

5. Turn on auditing — and keep the logs longer

You cannot investigate what you never recorded. Audit logging answers the questions that matter after an incident: who signed in from where, what was read, what was forwarded, what was deleted. Yet plenty of small-business tenants have never verified auditing is enabled for every user and workload.

Retention is the second half: by default, standard audit logs are kept for 180 days, per Microsoft's Purview documentation. Quiet compromises — the kind where someone reads a controller's mailbox for months before striking — can outlast that window. Export or stream logs to longer-term storage so the evidence exists when you need it, and check that alerting is actually pointed at a human who will see it.

6. Stop calling Microsoft 365 a backup

This is the most expensive myth in the small-business cloud. Retention policies, recycle bins, and version history protect against some mistakes for limited windows. They are not a backup: retention can be misconfigured or aged out, an admin (or attacker with admin rights) can purge data, a departed employee's cleanup can take irreplaceable files with it, and ransomware-encrypted documents will happily sync over your clean copies. Microsoft's shared responsibility model says it plainly — the platform is theirs, the data is yours.

Real protection means an independent backup of mailboxes, calendars, contacts, and shared files — separate credentials, separate storage, immutable copies, and restores that get tested instead of assumed.

How your IT partner should help

None of this requires an enterprise budget — it requires somebody actually owning it. If a provider manages your Microsoft 365, this is the standard they should be meeting:

  • Harden the tenant to a written baseline — enforced MFA and Conditional Access, legacy auth blocked, consent restricted, forwarding disabled — and re-verify it after every change
  • Watch it 24/7: sign-in logs, new inbox rules, app consents, and privilege changes monitored by a security operations center that can kill a hijacked session at 2 a.m., not read about it at 9
  • Back up the tenant independently and test the restores
  • Review posture with you quarterly — settings drift, staff change, attackers adapt
  • Work alongside internal IT where you have it, through a co-managed arrangement that adds monitoring depth without turf wars

One honest test: ask whoever manages your tenant to show you your Conditional Access policies. The speed and clarity of the answer tells you nearly everything. Or start from the outside — a free 30-minute assessment will surface the gaps in plain English.

Defaults get you onboarded. They don't keep you safe.

Quick answers

Microsoft 365 security, answered plainly

Doesn't Microsoft already secure Microsoft 365?

Microsoft secures the platform — the datacenters, the service, the infrastructure. Under the shared responsibility model, what happens inside your tenant is yours: who can sign in and how, which apps have access, what gets logged, and how your data is protected and recovered. The security ceiling of Microsoft 365 is high, but the defaults sit well below it.

We turned on MFA. Is our tenant secure now?

It's the single best first step, but not the finish line. Legacy protocols can sidestep MFA, users can be tricked into approving prompts or granting rogue apps mailbox access, attackers who steal a session token skip the login entirely, and none of it gets investigated if audit logging was never turned on. Hardening is a set of settings plus ongoing monitoring, not one toggle.

Does Microsoft 365 back up our data?

Not in the way most owners assume. Retention policies and recycle bins protect against some mistakes for limited windows, but they are not a backup: they can be emptied, misconfigured, or aged out, and ransomware-encrypted files can sync right over clean ones. Microsoft's shared responsibility model puts data responsibility on the customer. An independent backup — separate credentials, separate storage, tested restores — is what actually gets your mail and files back.

Find out what your tenant is missing

A free 30-minute assessment with the owner — a plain-English read on your Microsoft 365 security gaps. No pitch deck, no obligation.

Book a Free 30-Minute IT Assessment