How to Secure Your Microsoft 365 Account: A Guide for Business Owners

29th September 2026

Microsoft 365 is the backbone of most modern businesses. Email, files, Teams calls, shared documents: it all runs through one platform. And that makes it a prime target.

Cyber attackers know this. They don’t need to break through your firewall if they can simply log into your Microsoft 365 account with a stolen password. Once they’re in, they have access to everything.

The good news is that Microsoft has built a strong set of security tools directly into the platform, but many of them aren’t switched on by default and most business owners don’t know they exist.

This guide walks you through the security settings that matter most — what they are, why they matter, and how to enable them — without requiring a technical background.

Here’s what we’ll cover:

  • Multi-factor authentication (MFA)
  • Admin account protection
  • Blocking legacy authentication
  • Email security and anti-phishing settings
  • Monitoring for suspicious activity
  • Data loss prevention and backups

Step 1: Enable Multi-Factor Authentication

Multi-factor authentication (MFA) is the single most impactful security change you can make. It requires users to verify their identity with a second method (usually a code on their phone) in addition to their password.

Stolen passwords are extremely common. Phishing emails, data breaches, and weak password habits mean that credentials are compromised far more often than most business owners realise, and MFA stops an attacker in their tracks even if they already have your password.

According to Microsoft’s own data, enabling MFA blocks over 99% of account compromise attacks.

That’s not a marginal improvement — it’s one of the most impactful security changes any business can make.

How to enable MFA in Microsoft 365

The quickest way is through Security Defaults, which Microsoft provides free on every plan:

  1. Sign in to the Microsoft Entra admin centre
  2. Go to Identity > Overview > Properties
  3. Select Manage security defaults
  4. Toggle Security defaults to Enabled
  5. Save your changes

Once enabled, all users will be prompted to register for MFA the next time they sign in. The Microsoft Authenticator app is the recommended method — it’s free, quick to set up, and works on both iOS and Android.

A note on exceptions

Don’t create exemptions for senior staff or directors. Their accounts are the ones attackers want most. If a CEO’s email is compromised, an attacker can impersonate them to authorise fraudulent payments, access sensitive contracts, or instruct staff to hand over credentials.

MFA should apply to everyone in the organisation, without exception.

Step 2: Lock Down Your Admin Accounts

Admin accounts have the keys to everything. Whoever holds Global Administrator access in your Microsoft 365 tenant can reset passwords, read any email, delete users, and change security settings. That level of access demands a higher level of protection.

Most small businesses make the same mistake: the owner or IT contact has one account that they use for both day-to-day work and admin tasks. That’s a significant risk.

What to do instead

  • Create separate admin accounts for admin tasks. Your IT admin (or you) should have a standard user account for email and a separate account used only when making changes to the system.
  • Limit Global Admin assignments. Not everyone who manages the business needs Global Admin access. Microsoft recommends keeping this to the absolute minimum — ideally two people.
  • Remove stale accounts immediately. When a member of staff leaves, disable and then delete their account. Former employees (or the IT suppliers they worked with) retaining access is a surprisingly common source of security incidents.
  • Use dedicated admin credentials. Admin accounts shouldn’t be used for browsing the web or reading emails. They exist solely for administrative actions.

The principle here is simple: the more powerful the account, the more carefully it should be protected. Treat your admin credentials the way you’d treat the master key to your building.

Step 3: Block Legacy Authentication

This step sounds technical, but the concept behind it is simple.

Older email protocols, such as POP3, IMAP, and basic SMTP, were built before modern security methods existed. They can’t handle MFA. That means if an attacker gets hold of a username and password, they can use these old protocols to log in without ever being challenged for a second factor.

Blocking legacy authentication closes this back door entirely, and it’s one of the simplest steps you can take to strengthen your overall security position.

Enabling Security Defaults (covered in Step 1) handles most of this automatically. But it’s worth checking that nothing in your environment still relies on these older protocols before you block them. Usual offenders include:

  • Older multifunction printers that send scanned documents by email
  • Legacy line-of-business applications
  • Older email clients that haven’t been updated

Check your Microsoft Entra sign-in logs for any sign-ins using older protocols before making changes. If something breaks when you enable Security Defaults, it’s almost certainly one of these legacy connections that needs updating.

Once you’re confident nothing depends on the old protocols, leave Security Defaults enabled and move on. The risk of leaving legacy authentication open far outweighs the inconvenience of updating an old printer configuration.

Step 4: Strengthen Your Email Security

Email remains the most common entry point for cyber attacks. Phishing, impersonation, and malicious attachments account for the majority of business security incidents, and they almost always start with an email.

Microsoft 365 includes baseline email protection on all plans. But there are additional settings worth enabling, and some that are switched off by default.

Enable anti-phishing and anti-spoofing policies

Microsoft’s Defender for Office 365 includes impersonation protection that detects emails pretending to be from your CEO, your bank, or a trusted supplier. If you’re on Microsoft 365 Business Premium, this is included. If you’re on Business Standard, the baseline protection still catches most spoofed emails.

To review your anti-phishing settings:

  1. Go to the Microsoft Defender portal
  2. Navigate to Email & Collaboration > Policies & Rules > Threat policies
  3. Select Anti-phishing and review the default policy

Watch for suspicious inbox rules

This is one of the most overlooked threats. Once an attacker gains access to a mailbox, they often create hidden inbox rules — auto-forwarding emails to an external address, or silently deleting replies from banks and suppliers so the real user never sees them.

According to research from Huntress, 64% of identity-focused incidents in SMBs involved malicious inbox rules or external email forwarding. That’s a staggering figure.

You can set up alert policies to notify you whenever a new inbox rule is created. Do this under Security & Compliance > Alerts > Alert policies in your Microsoft 365 admin centre.

Set up email authentication records

SPF, DKIM, and DMARC are DNS records that tell the world which servers are allowed to send email on your behalf. They make it much harder for attackers to spoof your domain and send phishing emails that appear to come from your business.

Your IT provider or domain registrar can help you set these up. They’re not visible to end users, but they’re critical for protecting your brand and your customers.

Step 5: Control File Sharing and Data Access

SharePoint and OneDrive make it easy to share files, which is exactly the problem. The default sharing settings in Microsoft 365 are relatively permissive — and many businesses have no idea what’s been shared externally over the years.

Oversharing is a genuine risk. A link shared with “anyone with the link” can be forwarded, indexed, or accessed long after the first recipient has moved on, and most businesses have no visibility over how widely those links have spread.

Tighten your sharing defaults

In the SharePoint admin centre:

  1. Go to Policies > Sharing
  2. Change the external sharing setting from Anyone to New and existing guests (or Only people in your organisation if you rarely share externally)
  3. Set link expiry dates so shared links don’t remain active indefinitely

Apply the principle of least privilege

Not every member of staff needs access to every file. Review who has access to sensitive folders and restrict permissions where they’re not needed. This limits the damage if any one account is compromised.

  • Finance documents should be accessible only to finance staff
  • HR files should be restricted to HR and senior management
  • Client data should be accessible on a need-to-know basis

It’s a straightforward principle, but in practice most businesses have never applied it consistently across their Microsoft 365 environment.

Step 6: Back Up Your Microsoft 365 Data

This is the most common misconception we encounter: business owners who assume that because their data is in Microsoft’s cloud, it’s automatically backed up.

That assumption is incorrect, and it’s one of the most consequential misconceptions we encounter.

Microsoft is responsible for keeping the platform running. It is not responsible for recovering your data if you accidentally delete files, a ransomware attack encrypts your OneDrive, or a disgruntled employee wipes a shared folder. Recycle bins have limited retention windows, and once those expire, the data is gone.

Microsoft’s own shared responsibility model makes this clear: data protection is the customer’s responsibility.

What you need to do

Use a third-party backup solution that stores copies of your Microsoft 365 data outside the tenant itself. A good backup solution should cover:

  • Exchange Online (email and calendars)
  • SharePoint (document libraries and site content)
  • OneDrive (individual user files)
  • Microsoft Teams (chat history and channel files)

Critically, test your backups. Knowing that a backup exists is not the same as knowing it works. Schedule a test restore at least once a year to confirm you can actually recover your data when you need to.

Step 7: Review Your Microsoft Secure Score

Microsoft provides a free tool called Secure Score that evaluates your current security configuration and scores it out of 100. It then gives you a prioritised list of recommended actions to improve your score.

It’s one of the most useful tools available to business owners because it translates complex security settings into plain-language recommendations with clear guidance.

Think of it as a health evaluation of your Microsoft 365 environment. It won’t catch everything, but it will flag the most common gaps and tell you exactly how to address them.

To access it, sign in to the Microsoft Defender portal and select Secure Score from the left-hand menu. Aim to work through the recommendations in order of impact, starting with those that are marked as high priority.

One important caveat: a high Secure Score doesn’t mean your business is fully protected. It measures configuration against Microsoft’s baseline recommendations. It doesn’t account for your specific industry, the sensitivity of your data, or threats that fall outside Microsoft’s detection scope. Use it as a starting point, not a finish line.

Security Is Not a One-Off Task

Working through this guide will put you significantly ahead of most small businesses. But security isn’t something you configure once and forget.

Microsoft routinely updates its default settings. New threats emerge. Staff leave and join. Devices change. What’s secure today may have gaps tomorrow.

The most resilient businesses treat Microsoft 365 security as an ongoing process, not a project. That means reviewing your Secure Score periodically, auditing user access when staff move on, and keeping up to date with new threats.

If you’d rather not manage this yourself, that’s exactly what a managed IT provider is for. At ECL, we help businesses across Essex and the wider UK set up, monitor, and maintain their Microsoft 365 environments so that nothing is missed.

Get in touch with the ECL team to find out how we can help secure your Microsoft 365 environment. Whether you need a one-off security audit or ongoing managed support, we’re here to help.

Get in touch

Can't find what you're looking for or have further questions, please give ECL a call on 01268 575300 or fill out the form below and we will get back in touch as soon as possible...

Please enter your name.
Please enter a valid email address.
Please type your message.

Please check the captcha to verify you are not a robot.

IT Support

ECL recognises that every client is different, and every client has a different IT support requirement. Whatever the size of your business, we can offer a support scenario to suit your needs.

Cloud Services

Whether your business already uses Cloud services or you’re considering the Cloud as a possible way forward, talk to us first. We can provide anything from fully hosted IT infrastructures on our own ECL Private Cloud, to simple on-line backups. We can also give expert advice on Microsoft 365 and other Cloud platforms.

Disaster Recovery

How would losing access to your IT systems and data for days, or even weeks, affect your business? For many if not most companies this would be a nightmare scenario, with potentially very serious consequences.

Microsoft 365

Cloud services could potentially lower your overall costs and gives your employees all the tools they need alongside the correct layers of security and compliance. We are an IT company in Essex who are here to help.

Client reviews