Almost every Microsoft 365 compromise we have been called in to investigate walked through a gap that a free setting would have closed. Not a clever exploit. A password that was reused, a legacy protocol nobody disabled, a forwarding rule that ran for four months.

Here are ten settings worth an afternoon of somebody's time. Most are available on every plan. Where a setting needs Business Premium, it is marked.

1. Multi-factor authentication on every account

Non-negotiable and free. Every user, every administrator, every service account that can be given one.

The exceptions people carve out are exactly the accounts that get compromised: the director who finds it inconvenient, the shared mailbox everybody signs into, the old account left active for a system integration. Close the exceptions and use conditional access to make the experience painless for trusted devices rather than turning the requirement off.

Prefer an authenticator app with number matching over SMS, which is interceptable.

2. Block legacy authentication

Older protocols cannot present a second factor. That means an account with MFA enabled can still be signed into over legacy protocols with a password alone, which quietly undoes setting one.

Microsoft has been retiring these protocols, but tenancies vary and exceptions get made for a scanner or an old line-of-business application. Check the sign-in logs for legacy authentication, deal with whatever is still using it and then block it.

3. Turn off external automatic forwarding

When an attacker gets into a mailbox, the first thing they do is create a rule that forwards everything to an address they control. That way, changing the password later does not end their access to your correspondence.

An outbound spam policy that blocks automatic external forwarding removes the technique entirely. If a genuine business process needs forwarding, allow that one address specifically rather than leaving the door open.

4. Verify mailbox auditing

Auditing is on by default in most tenancies, but the retention window is limited and settings can have been changed.

This is the one that matters after the fact. Without audit data, the answer to what did they read, and did they download the client list is a shrug, and a shrug is not something you can put in a breach notification to the ICO.

By default, users in many tenancies can grant an application access to their mailbox and files. Consent phishing exploits this: a convincing prompt, one click, and an attacker has persistent access that survives a password change.

Change it so that applications require administrator approval, and enable the admin consent workflow so people can request rather than being blocked with no route forward.

Consent phishing is the technique that most often defeats multi-factor authentication, because the user is not being asked for a password. They are being asked to say yes.

6. Control external sharing in SharePoint and OneDrive

Default sharing settings are frequently more open than businesses realise. Two changes are worth making immediately: turn off anonymous anyone with the link sharing, or at minimum set links to expire; and default new links to specific people rather than anyone.

Then run a sharing report and look at what is already out there. This is also the prerequisite for any Copilot rollout, for the reasons set out in this article.

7. Set a sensible password policy

Modern guidance from the National Cyber Security Centre is clear: stop forcing regular expiry, because it produces predictable variations rather than better passwords. Use long passphrases, ban common and breached passwords and rely on MFA as the real control.

If your tenancy still expires passwords every 90 days, that is a setting to change rather than a habit to keep.

Defender for Office 365 opens attachments in isolation and checks links at the moment they are clicked, rather than only when the message arrives. Since attackers routinely make a link malicious after delivery specifically to defeat scanning at arrival, click-time checking is the part that matters.

9. Configure conditional access (Business Premium)

The rule engine that turns blunt security into proportionate security. Sensible starting rules: require MFA for all users, block sign-in from countries you do not operate in, require a compliant device for administrative access and block access from unmanaged devices to anything sensitive.

Always exclude one break-glass administrator account from conditional access, store its credentials somewhere physical and monitor its use. Locking yourself out of your own tenancy is an unforgettable afternoon.

10. Alert on the things that matter

Set alert policies for new mailbox forwarding rules, elevation of administrative privilege, unusual volumes of file deletion or download and sign-ins from unexpected locations.

Then decide who reads them. An alert going to an unmonitored inbox is worse than no alert, because it creates a false sense that somebody is watching.

What this closes and what it does not

These ten settings close the routes that the majority of small-business compromises actually use. What they do not do is remove the need for backup, for staff who can recognise a phishing attempt or for a plan for the day something gets through.

If you would like this configured and then kept configured — because settings drift, tenancies change and Microsoft moves things — that is what our security solutions service does. Ask us for a tenancy review and we will tell you which of these ten are currently off.