Out of the box, Microsoft 365 is convenient — not secure. These baseline settings close the most common gaps without getting in your team's way.
Microsoft 365 ships optimised for easy adoption, not maximum security. That's a sensible default for Microsoft — but it leaves gaps that every business should close. Here's the baseline I apply to new and inherited tenants.
Turn on MFA and disable legacy auth
The overwhelming majority of account compromises would be stopped by MFA. Enforce it for everyone via conditional access, and block legacy authentication protocols that quietly bypass it.
Protect against phishing and malware
Configure Microsoft Defender for Office 365 anti-phishing, Safe Links and Safe Attachments. Email remains the number-one attack vector, and these controls dramatically reduce what reaches the inbox.
Tighten sharing and external access
Review SharePoint and OneDrive sharing defaults so files aren't accidentally exposed to the whole internet, and govern guest access in Teams deliberately rather than by accident.
Enable audit logging and alerts
You can't investigate what you didn't record. Ensure unified audit logging is on and set alert policies for risky activity like mass downloads or mailbox forwarding rules.
A secure baseline isn't a project with an end date — it's a standard you hold the tenant to, continuously.
Emmanuel A.
Azure Administrator & Cloud Consultant at EA IT Consult. Helping businesses run secure, cost-efficient Azure & Microsoft 365.


