Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

Microsoft 365 Security Settings Every Small Business Should Turn On

In short

Microsoft 365 comes with strong security tools switched off by default. This guide walks you through the settings that matter most: multi-factor authentication, anti-phishing, Safe Links and Safe Attachments, audit logging, and file-sharing controls. Turn these on and you close the doors most attackers walk through, without needing to be technical.

Powerful protection that’s switched off by default

Here’s something most business owners never hear: Microsoft 365 arrives with some of its best security features turned off. Microsoft builds the tools, but leaves the final decision to you. The result is thousands of UK small businesses running on the digital equivalent of an unlocked front door — not because the lock doesn’t exist, but because nobody ever turned the key.

Microsoft 365 ships with the seatbelts in the glovebox — powerful protections that do nothing until someone decides to fit them.

The good news is that fitting them takes minutes, not days, and you don’t need to be technical. This guide walks through the settings that give you the most protection for the least effort, roughly in order of importance. Work down the list and you’ll have closed the doors that attackers use most often.

1. Turn on multi-factor authentication (the single most important step)

If you do only one thing on this list, do this. Multi-factor authentication, or MFA, means that even if a criminal steals your password, they still can’t get in — because logging in also requires a code or an approval tap on your phone.

The numbers speak for themselves: the overwhelming majority of account takeovers involve accounts that had no MFA. It is the closest thing to a silver bullet that cyber-security offers.

You have two main ways to switch it on:

  • Security Defaults — a single on/off switch in the Microsoft 365 admin centre that enforces MFA for everyone. It’s free on every plan and takes about two minutes. For most small businesses without a dedicated IT person, this is the right choice.
  • Conditional Access — a more flexible approach available on Business Premium and Enterprise plans. It lets you set rules like “require MFA only when someone signs in from outside the UK” or “block sign-ins from countries we never work with”. It’s more powerful but needs a little more setup.

Start with Security Defaults. You can graduate to Conditional Access later as you grow. Either way, note that Cyber Essentials now makes MFA mandatory for cloud services, so this isn’t optional if you’re pursuing certification. Our guide to multi-factor authentication explains the different methods and why an authenticator app beats a text message.

2. Switch on anti-phishing protection

Phishing — fake emails designed to trick your staff into handing over passwords or paying fraudulent invoices — is the way most attacks begin. Microsoft 365 includes anti-phishing policies that spot impersonation attempts, such as an email pretending to come from you or your bank.

Inside the Microsoft Defender portal you can set anti-phishing policies to protect your key people — the owner, the finance manager, anyone who handles money or sensitive data. Defender learns what “normal” looks like and flags messages that try to impersonate them. Combine this with staff who know how to spot a phishing email and you’ve built two layers of defence instead of one.

These two features come with Microsoft 365 Business Premium, and they’re a big part of why that plan is worth the extra cost for many firms.

  • Safe Links checks web links at the moment someone clicks them, not just when the email arrives. This matters because criminals often send a clean link and only make it malicious later. Safe Links re-checks it in real time and blocks the dangerous ones.
  • Safe Attachments opens email attachments in a secure, isolated environment first, to see whether they behave maliciously, before they ever reach your inbox. A booby-trapped invoice gets caught before anyone opens it.

Both run quietly in the background. Your staff barely notice them, but they stop a category of attack that ordinary spam filters miss.

4. Confirm audit logging is on

Audit logging is your security camera. It records who signed in, who deleted or shared a file, who changed a setting, and when. If you ever suspect something has gone wrong, the audit log is the difference between knowing what happened and guessing.

On newer tenants this is switched on automatically, but it’s always worth confirming in the compliance or Defender portal. It costs nothing and it’s the kind of thing you only miss once — usually at the worst possible moment. If you ever need to report an incident to the ICO, this record is invaluable.

5. Tighten your file-sharing controls

By default, Microsoft 365 can be quite generous about letting staff share files and folders with anyone, including people outside your business, sometimes with links that work for absolutely anyone who gets hold of them.

In the SharePoint and OneDrive admin settings you can:

  • Limit external sharing to named guests only, rather than “anyone with the link”.
  • Set shared links to expire after a set number of days.
  • Default new links to “people in your organisation” rather than “anyone”.

This stops the slow leak of company data that happens when a link meant for one supplier quietly gets forwarded around, or when a staff member leaves and their old share links keep working.

6. Review who has admin rights

Administrator accounts can change any setting and access any data. The fewer people who have that power, the smaller your risk. Check your admin list and ask: does everyone on it genuinely need it? A good rule is to have at least two admins (so you’re never locked out) but no more than you truly require — and every one of them must have MFA switched on.

Don’t forget: Microsoft doesn’t back up your data for you

This is the setting that isn’t a setting — and it catches people out constantly. Microsoft keeps the service running, but recovering your emails and files after they’re deleted or encrypted is your responsibility, not theirs. Once the recycle bin empties, that data can be gone for good.

If a staff member deletes the wrong folder, or ransomware sweeps through your files, or an account is compromised and wiped, you need your own independent backup to get your business back. We explain exactly why in why you need Microsoft 365 backup — it’s essential reading before you assume you’re covered.

A sensible order to work through

If this all feels like a lot, here’s the priority order:

  1. Turn on MFA today (Security Defaults).
  2. Confirm audit logging is on.
  3. Tighten external sharing.
  4. Set up anti-phishing policies.
  5. Enable Safe Links and Safe Attachments if you’re on Business Premium.
  6. Review admin accounts.
  7. Put a proper backup in place.

Get the first three done this week and you’ve already dramatically reduced your risk.

We’ll do it for you

Every one of these settings is one we configure as standard for the businesses we look after — correctly, consistently, and checked against the Cyber Essentials requirements. If you’d rather know it’s done properly than wonder whether you’ve missed something, that’s exactly what our managed IT service is for.

Want a second pair of eyes on your Microsoft 365 setup? Get in touch and we’ll tell you honestly where your gaps are — no jargon, no pressure.

Frequently asked questions

Do I need an expensive Microsoft 365 plan to be secure?

No. The most important protections — multi-factor authentication and Security Defaults — are available on every Business plan, including the cheapest ones, at no extra cost. Advanced features like Safe Links and Safe Attachments come with Business Premium, which many small firms find worthwhile, but you can be meaningfully safer today on any plan by turning on MFA.

Will turning on multi-factor authentication annoy my staff?

Far less than you'd think. Most people are prompted only occasionally — often once every 30 days on a trusted device, or when signing in from somewhere new. A few seconds now and then is a small price for stopping the single most common cause of business account breaches: a stolen or guessed password.

Is Microsoft 365 backed up automatically?

No, and this is the biggest misunderstanding we see. Microsoft keeps your service running, but recovering deleted emails or files after the recycle bin empties is your responsibility. If someone deletes data or ransomware encrypts it, you need your own backup. See our guide on why you need Microsoft 365 backup.

What is audit logging and why does it matter?

Audit logging records who did what in your tenant — who signed in, who deleted a file, who changed a setting. If you ever suspect a breach, it's the evidence that tells you what actually happened. Without it, you're guessing. On many plans it's on by default now, but it's always worth confirming.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.