Microsoft 365 · Practical guide

Microsoft 365 security basics every small business should control

A practical Microsoft 365 security checklist for small businesses covering MFA, administrator roles, staff changes, sharing, email threats and recovery.

Microsoft 365 often contains a business’s email, files, calendars, customer conversations and access to other cloud services. That makes the Microsoft account more important than the laptop used to reach it. A sensible security baseline focuses first on identity, administrator control, staff lifecycle and recoverability.

Require multi-factor authentication

A stolen or reused password should not be enough to enter a business mailbox. Require multi-factor authentication for every user and pay special attention to administrators, finance staff and people with access to sensitive customer information. Review registered authentication methods so that former phone numbers and unknown devices are removed.

Document a secure recovery process. If an employee loses a phone, the business should know who can verify their identity and reset authentication without bypassing basic checks.

Reduce and separate administrator access

Daily email accounts should not hold broad administrator rights without a clear reason. Keep the number of global administrators small, use the least powerful role that completes the task and maintain more than one controlled recovery path so the tenant does not depend on a single person or supplier.

  • Record every administrator, their role and why access is required.
  • Remove unused partner and delegated-administration relationships.
  • Use separate administrator identities where the business risk justifies it.
  • Review privileged access on a recurring schedule.

Control joiners, role changes and leavers

Security problems often come from an incomplete staff process rather than a sophisticated attack. New users may receive too much access, employees keep permissions after changing roles, and departed staff remain signed in on personal devices. Use a short checklist that connects HR or management decisions to account creation, access approval, device return and account closure.

Review sharing, forwarding and suspicious email

Check external sharing on important SharePoint sites and Teams, especially links that allow broad or anonymous access. Review automatic mailbox forwarding and unusual inbox rules, as attackers sometimes use them to quietly copy messages or hide replies. Staff should have a simple way to report suspicious messages without feeling blamed for asking.

Plan for retention, backup and recovery

Microsoft 365 availability does not automatically answer every recovery need. Decide how long important information must be kept, what accidental deletion scenarios matter and whether an independent backup is appropriate. Test the recovery steps for a mailbox, a shared document library and a departed employee’s data before an urgent request exposes gaps.

Wesley Classen
Wesley's AI Assistant Usually replies in ~15 min Ask me anything — if I can't answer, Wesley gets pinged and replies personally.
Hello! I'm Wesley's AI assistant. How can I help you today?