Microsoft 365IT-beheerKMO

Microsoft 365 in your SME: 8 security settings that are often still switched off

Most SMEs run Microsoft 365 with the default settings from the day it was set up. Eight settings we almost always find still switched off, what they do, which licence you need and how to roll them out without disrupting your team.

Ian

Ian

Co-Founder & CEO

28 September 20266 min read
Illustration of toggle switches and a shield, Microsoft 365 security theme

Almost every SME we visit works with Microsoft 365. And almost every time, the environment is still exactly as it was set up, with the default settings of that day. Understandable, because it works. But Microsoft leaves a large part of the security switched off by default, or only half on. These are the eight settings we still find switched off at most SMEs, what they do and why they matter.

Why the default settings are not enough

Microsoft 365 is built for everyone, from a sole trader to a multinational. The defaults therefore favour convenience: everything is allowed, until you restrict it. A leaked password is enough to sign in, email can be forwarded unnoticed and files can be shared with the whole world with a single link.

  • Most break-ins at SMEs start with a stolen password, not with a technical attack on your server.
  • An attacker sitting in one mailbox can read along unnoticed for months and manipulate invoices from there.
  • The basic settings below do not cost an extra licence, only a few hours of work and some coordination.

The eight settings

In the order we tackle them ourselves: first what removes the most risk, then the fine-tuning.

1. MFA for everyone

Multi-factor authentication, or MFA, is the setting with the biggest impact: a stolen password alone is no longer enough to sign in. In Microsoft 365 you switch this on via the 'security defaults' (simple, all-or-nothing) or via conditional access (finer, for example only outside the office). How to roll it out without a grumbling team is explained in our step-by-step plan for MFA.

2. Separate administrator accounts

At many SMEs the owner's account is also the administrator account. One phishing email then gives access to the whole environment. Create a separate administrator account without a mailbox, used only to change settings. It takes half an hour and it closes the biggest door.

3. Disable outdated sign-in protocols

Old protocols such as POP, IMAP and SMTP with basic authentication do not support MFA. As long as they are open, a password alone gets an attacker in. Microsoft has closed most of them, but SMTP basic authentication is often still enabled per mailbox. Explicitly disable 'legacy authentication', after checking what still uses it, such as a scanner that sends emails.

4. Block automatic forwarding to external addresses

A classic trick after a break-in: a rule that quietly forwards all email to an external address. The attacker reads along for months, even after the password is changed. Block automatic forwarding to external addresses for your whole organisation. Whoever really needs it gets an exception.

5. Enable audit logging and keep it longer

When something happens, you want to know who did what and when. That needs an audit log that is on and kept long enough. Check the retention period: by default only a few months, while a break-in is often discovered later. For longer, export the logs periodically or take an additional licence.

6. Restrict external sharing

By default anyone in SharePoint and OneDrive can share files with 'anyone with the link', without an expiry date. Restrict external sharing to known domains of customers and partners, set an expiry date on links and allow 'anyone' links only where really needed.

7. Scan safe links and attachments

Defender for Office 365 checks links and attachments at the moment someone clicks on them, not only on receipt. That catches phishing that gets past the basic filters. To be honest: this is not included in every licence. Business Basic and Business Standard do not have it, Business Premium does.

8. Manage devices

Company data belongs only on devices you know and manage. With Intune, a laptop or phone only gets access to email and files if it is encrypted, up to date and has a screen lock. Lost phone? You wipe the company data remotely. This too requires Business Premium.

Which licence do you need for this?

Without prices, because they change and depend on your supplier, it comes down to this:

  • Business Basic and Business Standard: MFA via security defaults, separate administrators, legacy authentication off, blocking forwarding, the basic audit log and restricting sharing can all be configured with these. Standard adds the Office programs on your PC.
  • Business Premium: everything in Standard, plus Defender for Office 365, Intune and conditional access for finer MFA rules. For an SME that takes security seriously, this is the logical choice.
  • Mixing is possible: whoever works with customer data or invoices gets Premium; an account for the workshop can stay on Basic.

How do you approach this without disrupting your team?

The technology is the easy part. The hard part is that people want to keep working in the meantime. This is how we keep it calm:

  1. Start with the settings nobody notices: separate administrator accounts, audit logging, blocking forwarding. That can be done in an afternoon, without any communication.
  2. Take stock of what still uses legacy authentication, and fix that first. Otherwise the scanner or the accounting package suddenly stops working after you switch it off.
  3. Announce MFA and the sharing restrictions a week in advance, with a short explanation of why and what changes.
  4. Test with two or three colleagues, preferably people who share a lot externally or work on the road. They find the snags.
  5. Then roll out to the rest, and agree who is reachable for questions during the first days. Count on a few days of adjustment, no more.

Which of these eight settings are still switched off at your company? Our free cyber scan maps your Microsoft 365 environment, together with the rest of your IT, and tells you what to prioritise.