In most medium-sized companies Microsoft 365 is the heart of daily work: e-mail, files, Teams, identities. It is correspondingly popular with attackers. The good news: the most effective protections are already included in the common licences. They are just not always switched on. The following ten points are the ones we find most often in audits – and each of them can be checked in an afternoon.

1. Multi-factor authentication for everyone

Not only for administrators, not only “recommended”, but enforced for every account. Use the Microsoft Authenticator app with number matching instead of SMS. Accounts without MFA are taken over within minutes using stolen passwords.

2. Block legacy authentication

Old protocols such as IMAP, POP3 and SMTP AUTH bypass MFA completely. Check the sign-in logs to see whether they are still in use and block them via Conditional Access. Usually only an old multifunction printer depends on them.

3. Conditional Access instead of all-or-nothing

With Conditional Access you define under which conditions access is allowed: only from managed devices, only from certain countries, only with MFA, for administrators only from the company network. Start with Microsoft's default policies and extend step by step.

4. Separate administrator accounts

Anyone who works daily with an account that has Global Admin rights risks the entire environment with every phishing click. Administrators get a separate account without a mailbox that is used only for administrative tasks. The number of Global Admins should be between two and four.

5. Control external sharing

By default, SharePoint and OneDrive allow sharing with “anyone with the link”. Restrict external sharing to specific domains or authenticated guests, set expiry dates and regularly review which files are visible externally.

6. Monitor forwarding rules

After an account takeover, attackers almost always set up a rule that silently forwards incoming e-mails externally – often for months. Block automatic forwarding to external addresses and get alerted about new mailbox rules.

7. Enable phishing and malware protection

Microsoft Defender for Office 365 offers safe links, safe attachments and protection against impersonation of your own executives. The preset security policies “Standard” or “Strict” are enabled with a few clicks and are considerably better than the baseline.

8. SPF, DKIM and DMARC for your own domain

Without these three DNS records anyone can send e-mails in your name – to your customers and to your own employees. DKIM is enabled in Microsoft 365, SPF and DMARC are set at the domain provider. Start with DMARC in monitoring mode and tighten after a few weeks.

9. Logging and retention

The unified audit log must be switched on, otherwise there is nothing to analyse after an incident. Check the retention period of sign-in and audit logs – by default it is only 30 to 90 days depending on the licence. Attacks are often discovered later.

10. Backup outside Microsoft

Microsoft ensures the availability of the platform, not the protection of your data against deletion, encryption or user error. The recycle bin is not a backup. An independent backup of Exchange, SharePoint, OneDrive and Teams – with regularly tested restores – belongs to every serious Microsoft 365 environment.

How to proceed

The Microsoft Secure Score in the Defender portal shows which of these points are open in your environment and prioritises them. A score below 50 percent is the norm in SMEs and no reason to panic – but a reason to start. We review your configuration in a half-day session, implement the measures with your IT and document the result for audits, insurers and customers.