Microsoft 365 is the most widely used business productivity suite in the world, and most businesses that use it are paying for a security arsenal they have never opened. The platform ships with a significant range of security features included in the subscription, but they are not enabled by default, and many organisations are running Microsoft 365 with roughly the same security posture they would have had using basic email a decade ago.
The good news is that most of these settings can be configured without any specialist technical expertise, and switching them on represents one of the highest-impact, lowest-cost security improvements available to any Microsoft 365 business.
1. Multi-factor authentication: if you have not done this yet, start here
Multi-factor authentication should be the first security setting enabled in any Microsoft 365 environment, and it should be mandatory for every user without exception. Microsoft’s own research indicates that MFA blocks over 99% of account compromise attacks, making it the single most impactful security control available at essentially no additional cost to existing subscribers.
To enable it across your organisation, navigate to the Microsoft 365 Admin Centre, select Users, then Active Users, and choose Multi-Factor Authentication from the menu. For stronger protection, configure Conditional Access policies through Azure Active Directory, which give you granular control over when and how MFA is enforced.
2. Security defaults: the baseline most businesses skip
Microsoft 365 offers a feature called Security Defaults that activates a set of pre-configured baseline security policies in a single toggle, including requiring MFA for all users, blocking legacy authentication protocols that are frequently exploited by attackers, and protecting privileged administrator accounts with additional controls.
Security Defaults are designed for organisations that do not have a dedicated security team to configure individual policies, and they represent a significant security improvement over an unconfigured environment. To enable them, navigate to the Azure Active Directory portal, select Properties, then Manage Security Defaults, and toggle the setting on.
Note: if your organisation already uses Conditional Access policies, Security Defaults will be unavailable, as the two features are mutually exclusive. In that case, ensure your Conditional Access policies cover the same ground.
3. Safe links and safe attachments: your defence against phishing
Safe Links and Safe Attachments are features within Microsoft Defender for Office 365 that significantly reduce the risk of phishing and malware delivered through email. Safe Links rewrites URLs in emails and scans them at the moment of click rather than at delivery, catching links that were safe when the email arrived but have since been weaponised. Safe Attachments detonates email attachments in a sandbox environment before delivering them to the recipient, catching malicious files that would otherwise bypass standard antivirus scanning.
Both features are available in Microsoft 365 Business Premium and higher plans. To configure them, navigate to the Microsoft 365 Defender portal, select Policies and Rules, then Threat Policies, where you will find both Safe Links and Safe Attachments under the Defender for Office 365 section.
4. Anti-phishing policies: going beyond basic spam filtering
Microsoft 365 includes anti-phishing policies that go significantly further than basic spam filtering, offering impersonation protection for your key users and domains, mailbox intelligence that learns normal communication patterns to identify anomalies, and spoof intelligence to detect when attackers are impersonating your own domain to target your staff or customers.
To configure anti-phishing policies, navigate to the Microsoft 365 Defender portal, select Policies and Rules, then Threat Policies, and choose Anti-Phishing. Create or edit a policy to add the domains and key users you want to protect against impersonation attacks.
5. Microsoft secure score: your ongoing security benchmark
Microsoft Secure Score is a dashboard within the Microsoft 365 Defender portal that assesses your current security configuration across your entire Microsoft 365 environment, gives you a score relative to similar organisations, and provides a prioritised list of recommended actions to improve your posture.
It is one of the most useful tools available to any Microsoft 365 administrator because it translates abstract security concepts into concrete, actionable improvements with an estimated impact score for each one. Checking your Secure Score monthly and working through the top recommendations is a structured, manageable way to continuously improve your security posture without needing to know where to start.
6. Audit logging: the visibility most businesses are missing
Audit logging in Microsoft 365 records user and administrator activity across the platform, including who accessed what files, when sign-ins occurred and from where, what changes were made to permissions, and when emails were deleted or forwarded. This visibility is invaluable both for detecting suspicious activity early and for investigating an incident after the fact.
Audit logging is not enabled by default in all Microsoft 365 plans. To check and enable it, navigate to the Microsoft Purview compliance portal, select Audit, and ensure that auditing is turned on. Retention periods vary by plan, so review what is included in your subscription and consider whether extended retention is appropriate for your compliance requirements.
A note on licensing
Not all of the features described above are available on every Microsoft 365 plan. Microsoft Defender for Office 365, which includes Safe Links, Safe Attachments, and advanced anti-phishing, requires Microsoft 365 Business Premium or a standalone Defender add-on. If your organisation is on a lower-tier plan, reviewing whether an upgrade is warranted based on the security capabilities it unlocks is a worthwhile conversation.
Not sure which Microsoft 365 security features your business has enabled or which plan you are on? Siyaxhuma can audit your Microsoft 365 environment, identify the gaps, and configure the settings that matter most. Get in touch today.