A Microsoft 365 account can provide access to email, documents, contacts and shared business information. The controls available depend on the Microsoft 365 and Microsoft Entra licences in use, so check the tenant and licence before promising a feature.
1. Require multi-factor authentication
Multi-factor authentication asks for more than a password when a user signs in.
Microsoft 365 organisations can use security defaults as a baseline. Organisations with the required Microsoft Entra licence can use Conditional Access for more detailed sign-in policies. Legacy per-user MFA is not the preferred method for a new deployment.
MFA should cover normal users and day-to-day administrator accounts. Emergency-access accounts need a separate, tightly controlled design, monitoring and review.
2. Use stronger authentication where possible
Not every MFA method provides the same protection. Microsoft recommends phishing-resistant methods such as passkeys, FIDO2 security keys and Windows Hello for Business.
These methods use cryptographic credentials tied to the correct service. They are harder for a fake sign-in page to capture and reuse.
The right rollout depends on the devices, applications and support process. Plan enrolment and account recovery before requiring a new method.
3. Separate administrator work from everyday work
Administrators should use a normal account for email, web browsing and everyday work. A separate administrator account should be used only when an administrative task requires it.
Give each administrator only the role needed for the job. Avoid making every IT user a Global Administrator. Review privileged roles and remove access that is no longer needed.
4. Block old authentication methods
Legacy authentication methods may not support modern sign-in controls such as MFA. Old mail applications, devices and scripts can keep them in use without the business realising it.
Identify dependencies before blocking legacy authentication. Replace or reconfigure affected applications, then confirm that the block is effective.
5. Protect account recovery
An MFA rollout is incomplete when the recovery process is weak.
- Keep authentication methods current
- Define how identity is verified during a reset
- Protect helpdesk and administrator reset processes
- Remove old phone numbers and devices
- Review registrations after staff or role changes
- Avoid giving one person unchecked power to reset privileged accounts
6. Manage joiners, movers and leavers
Account security changes when a person joins, changes role or leaves.
The process should cover licences, group membership, application access, mailbox and file ownership, shared accounts, company devices, active sessions and authentication methods. Leaver actions should be agreed with management because business data may need to be retained or transferred before access is removed.
7. Review suspicious sign-ins and mailbox rules
Unfamiliar sign-ins, unexpected MFA prompts, new forwarding rules and messages sent without the user’s knowledge may indicate compromise.
Monitoring options depend on the licence and configured services. Alerts only help when someone receives them, understands them and owns the response.
8. Prepare for a compromised account
A basic response process should include:
- Verify the report using a trusted channel.
- Restrict or disable access when necessary.
- Revoke active sessions and tokens.
- Reset credentials and review authentication methods.
- Check forwarding, inbox rules, delegated access and recent changes.
- Review relevant sign-in and audit information.
- Determine what data and other people may be affected.
- Preserve evidence and follow the organisation’s legal, insurance and notification process.
Do not assume that changing the password ends every active session or removes a malicious mailbox rule.
9. Understand what DMARC adds
DMARC protects the use of the business domain in the visible From address. It does not protect a mailbox that has already been compromised, stop a lookalike domain or prove that an authenticated message is safe.
It is useful alongside Microsoft 365 account security, not instead of it. Read about Managed DMARC.
A sensible starting order
For many small businesses, the first priorities are to confirm administrator ownership, require MFA, remove unnecessary privilege, identify legacy authentication, protect recovery, and establish joiner and leaver processes.
The exact order should follow the tenant’s current state and the business risk. Explore Microsoft 365 support.
A sensible next step
Talk to Kwik Support
Tell us about the current setup, the problem you are trying to solve and the outcome your business needs.
Talk to Kwik Support