Microsoft 365 ships with a genuinely strong set of security tools — and most of them are off by default, so the businesses paying for them often never find out. We regularly audit M365 tenants for new clients and find the same powerful controls sitting unused, not because anyone decided against them, but because nobody knew they were there. Here are the settings that make the biggest difference for a small business, roughly in order of impact. Most take minutes to enable; a few need a specific license tier, which we’ll flag.
If MFA isn’t enforced, nothing else here matters as much. A password alone is the most common way business email accounts get taken over, and once an attacker is in your mailbox, invoice fraud, data theft, and spread to others follow quickly. At minimum, enable Security Defaults, which turns on MFA for everyone. If your license includes it, Conditional Access is better — it can require MFA intelligently (always from outside the office, or only when a sign-in looks risky) without nagging people on every trusted login. Either way, no account gets in on a password alone.
This is the quiet killer. Older email protocols can bypass MFA entirely, so you can have MFA perfectly configured and still be wide open — an attacker just connects over one of these old protocols and the second factor is never checked. Blocking legacy authentication closes that back door. It’s one of the highest-impact changes you can make and invisible to almost everyone once done; only genuinely outdated apps are affected, and those should be replaced anyway.
By default you may not be logging who did what in your tenant. If an account is ever compromised, the audit log is how you find out what the attacker touched — which files they opened, which rules they created, whether they exported data. Without it, you’re investigating a break-in with the cameras switched off. Enable it now, before you need it; logs only help if they were already running when the incident happened.
A favorite move in email compromise: the attacker sets a rule to auto-forward incoming mail to an outside address, then quietly reads everything. Blocking automatic forwarding to external domains at the tenant level shuts this down across every mailbox at once. There’s rarely a legitimate reason for it, and the risk it removes is significant.
Microsoft Defender for Office 365 can detect the display-name spoofing and lookalike domains that target your executives and finance staff — the “urgent request from the CEO” emails that drive so much fraud. These policies aren’t fully configured out of the box; setting them so impersonation attempts get flagged or quarantined is one of the more valuable things you can do, and it directly counters business email compromise.
A simple, high-value setting: mark every email that originates outside your organization with a visible warning. When a message claiming to be from a coworker or the owner arrives carrying an EXTERNAL banner, the impersonation exposes itself instantly. It costs nothing and quietly trains your whole team to spot spoofing.
Beyond the general audit log, you can enable mailbox-level auditing and alerts for suspicious activity — a rule created that deletes incoming mail, or a sign-in from an unusual location. These alerts are often the first sign an account has been compromised, and getting them in near-real time is the difference between catching it in hours versus after the damage is done.
Less about stopping attackers, more about closing a support gap that becomes a security gap. When people can’t reset their own passwords, they reuse weak ones, write them down, or wait days for help. Self-service password reset with proper verification lets users recover access securely on their own, cutting both risk and frustration.
A few of the strongest controls — advanced Conditional Access and the full Defender for Office 365 protections — require Microsoft 365 Business Premium or equivalent. For a small business, Business Premium is very often worth the step up precisely because it unlocks these features; if you’re on a basic plan, that’s worth a conversation, because what you’d gain frequently justifies the difference on its own.
None of these are exotic. Every one is a setting Microsoft already built and you’re likely already paying for. They’re off not because they’re risky, but because turning them on requires someone to go looking — and in most small businesses, no one has. That’s the whole opportunity: real security improvement, no new purchase, mostly switches waiting to be flipped by someone who knows where they are.
Want to know which of these are already on in your tenant? Book a free 30-minute consult and we’ll run through your Microsoft 365 security posture and show you exactly what’s switched off.