Why this matters
Microsoft 365 is secure when configured well, but many tenants still run on defaults. Business email compromise, invoice fraud and data theft often succeed because of a missing setting. This checklist covers the highest-impact changes first.
What you'll need
- Global administrator access
- A separate admin account
- A list of users and their roles
Step-by-step instructions
Step 1
Require MFA for everyone
Enable Security defaults, or if you have Microsoft 365 Business Premium, create Conditional Access policies that require MFA for all users and stronger methods for admins.
Step 2
Block legacy authentication
Older protocols such as POP, IMAP and basic SMTP authentication bypass MFA. Security defaults block them; with Conditional Access, create a policy to block legacy clients.
Step 3
Separate and limit admin accounts
Admins should use a dedicated admin account (with no mailbox) only for admin tasks. Keep the number of Global administrators to between two and four.
Step 4
Turn on Microsoft Defender preset policies
In the Microsoft Defender portal (security.microsoft.com), apply the Standard or Strict preset security policies for anti-phishing, Safe Links and Safe Attachments where licensed.
Step 5
Block automatic forwarding to external addresses
In Defender, edit the outbound spam filter policy and set automatic forwarding to "Off". This stops a common data theft technique.
Step 6
Confirm audit logging is on
In the Microsoft Purview portal, check that Audit is enabled so you can investigate incidents.
Step 7
Review your Secure Score
In the Defender portal, open Secure Score to see recommended improvements, ranked by impact.
Summary
MFA, blocking legacy authentication, limited admin accounts, Defender policies and audit logging form a strong Microsoft 365 baseline. Secure Score helps you keep improving.
Still Need Help?
Some IT problems are easier to solve with a professional. If you've followed the guide and still need help, the Omnicron team can assist.