Buyer guide

A Microsoft 365 security baseline for small and mid-sized organisations

A sound Microsoft 365 baseline starts with identity: multi-factor authentication for everyone, legacy sign-in blocked and administrator access tightly controlled. Then add email protection, managed devices, a backup that sits outside normal retention and someone watching the alerts.

The short answer

For most small and mid-sized organisations, a Microsoft 365 security baseline covers six areas:

  1. Identity: multi-factor authentication (MFA) for every user, legacy authentication blocked.
  2. Administrator access: separate admin accounts, few Global Administrators, two emergency access accounts.
  3. Email: Microsoft's preset protection policies, plus sender authentication for your domain.
  4. Devices: managed, encrypted and protected endpoints.
  5. Data and backup: sensible sharing settings and a backup that can restore after deletion or ransomware.
  6. Monitoring: someone reviewing sign-in risk, alerts and configuration drift.

Which tools you can use depends on your licences. Check your current plan before designing the rollout.

1. Identity: MFA and blocking legacy sign-in

Microsoft offers two ways to enforce MFA:

  • Security defaults are free and switched on or off as a whole. They require all users to register for MFA, require MFA for administrators, prompt users for MFA when needed, block legacy authentication protocols, block device code flow and protect access to Azure management tools (Microsoft Learn).
  • Conditional Access requires at least Microsoft Entra ID P1 and lets you build policies based on user, device, location, application and risk. Microsoft notes that organisations with P1 or P2 licences are probably better served by Conditional Access than by security defaults, and that security defaults must be turned off when Conditional Access policies replace them.

Legacy authentication matters because it does not support MFA, so an attacker using an older protocol such as IMAP or POP3 can bypass your MFA policy. Before blocking it, check for printers, scanners and line-of-business applications that still send mail or sign in the old way.

When choosing MFA methods, remember that mobile networks in some locations are unreliable, so SMS codes may arrive late or not at all. An authenticator app, which works offline for code generation, or a security key is a more dependable choice for staff who travel or work from branch offices. SMS is also weaker against SIM-swap fraud.

A typical Conditional Access starting set:

  • Require MFA for all users.
  • Require phishing-resistant MFA (such as passkeys or security keys) for administrators.
  • Block legacy authentication.
  • Require compliant or managed devices for access to sensitive data.
  • Restrict sign-ins from countries where you have no staff, if that fits your business.

2. Administrator access

Microsoft's guidance for Entra roles is specific (Microsoft Learn):

  • Apply least privilege: use roles such as User Administrator or Exchange Administrator instead of Global Administrator for everyday work.
  • Assign the Global Administrator role to fewer than five people.
  • Require MFA for all administrator accounts.
  • Use Privileged Identity Management for just-in-time elevation where licensed (it requires Entra ID P2 or Entra ID Governance).
  • Run recurring access reviews to remove roles people no longer need.
  • Use cloud-only accounts for administrative roles, not accounts synchronised from on-premises Active Directory.

Microsoft also recommends two or more emergency access ("break glass") accounts: cloud-only accounts on the onmicrosoft.com domain, protected with a phishing-resistant method such as a FIDO2 passkey that is different from your normal admin method, excluded from Conditional Access policies that could block them, monitored with alerts on every sign-in, and tested at least every 90 days (Microsoft Learn).

Give administrators a separate account for admin work so their everyday mailbox and browsing are not privileged.

3. Email protection

Email is the most common route for phishing and malware. Microsoft's preset security policies (Standard and Strict) apply Microsoft's recommended settings for anti-spam, anti-malware and anti-phishing, and, where you have Defender for Office 365, Safe Links and Safe Attachments (Microsoft Learn). Using a preset keeps settings aligned as Microsoft updates its recommendations, instead of relying on custom policies nobody reviews.

Also:

  • Publish SPF, DKIM and DMARC records for every domain that sends mail, and move DMARC towards enforcement once reports show legitimate mail passes. This also helps protect your staff and customers from fraudsters who impersonate your domain to request payments.
  • Tag external email so staff can see when a message comes from outside.
  • Block automatic forwarding to external addresses unless there is an approved business reason.
  • Give users a simple way to report suspicious messages.

4. Devices

  • Enrol devices in Intune (or an equivalent tool) and set compliance policies: supported operating system, encryption, screen lock, security software running.
  • Deploy endpoint protection with EDR, such as Defender for Business or Defender for Endpoint, depending on licence. See EDR vs antivirus.
  • Patch automatically for Windows, macOS, Office apps and browsers. Allow for devices that spend long periods offline during power or connectivity problems, and check that they catch up on updates when they reconnect.
  • For personal phones, use app protection policies to keep work data inside managed apps without taking over the whole device.

5. Data sharing and backup

  • Review SharePoint and OneDrive external sharing settings. Limit "anyone" links, set link expiry and restrict sharing on sensitive sites.
  • Use sensitivity labels and data loss prevention where licensed and where you have clear rules to enforce.
  • Understand that retention is not backup. Retention policies preserve content for compliance; they are not designed to roll a whole mailbox or site back to a point in time after ransomware or mass deletion.

Microsoft now offers Microsoft 365 Backup, a pay-as-you-go service that backs up SharePoint sites, OneDrive accounts and Exchange mailboxes, with restore points and configurable recovery windows (Microsoft Learn). Third-party backup products that store copies outside Microsoft's service are another option. Whichever you choose, test restores. See why a backup is not the same as a recovery plan.

6. Monitoring and review

  • Review Microsoft Secure Score recommendations regularly and record decisions on those you do not adopt.
  • Turn on and retain audit logging. If you hold personal data, these logs also help you establish what happened if you need to assess a breach under the Nigeria Data Protection Act 2023.
  • Alert on risky sign-ins, new mailbox forwarding rules, new admin role assignments and emergency account use.
  • Assign an owner to review alerts, including after hours if you need that coverage.
  • Re-check the baseline after licence changes, mergers and major Microsoft feature changes.

Baseline checklist

Identity

  • MFA enforced for all users (security defaults or Conditional Access)
  • Legacy authentication blocked; exceptions identified and fixed
  • Phishing-resistant MFA for administrators

Administration

  • Fewer than five Global Administrators
  • Separate, cloud-only admin accounts
  • Two emergency access accounts, monitored and tested at least every 90 days
  • Access reviews scheduled

Email

  • Standard or Strict preset security policy applied
  • SPF, DKIM and DMARC published for every sending domain
  • External auto-forwarding blocked or controlled

Devices

  • Devices enrolled with compliance policies
  • Endpoint protection with EDR deployed
  • Automatic patching in place

Data

  • External sharing settings reviewed
  • Backup covering Exchange, OneDrive and SharePoint, with a tested restore

Monitoring

  • Secure Score reviewed on a schedule
  • Alerts assigned to a named owner

Limitations

Microsoft changes features, names and licence contents often; confirm details against current Microsoft documentation before making changes, and test in a pilot group first. A baseline is a starting point, not a full security programme: it does not replace training, incident response planning or backups outside Microsoft 365. This is general information, not legal advice. If you would like the baseline assessed or implemented, see our Microsoft 365 and modern workplace service.

Sources and further reading

Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.

  1. Security defaults in Microsoft Entra ID, Microsoft Learn
  2. Best practices for Microsoft Entra roles, Microsoft Learn
  3. Manage emergency access admin accounts, Microsoft Learn
  4. Preset security policies, Microsoft Learn
  5. Overview of Microsoft 365 Backup, Microsoft Learn

This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.

Talk to Promatics

Get a straight answer for your situation

General advice only goes so far. Tell us about your environment and we will tell you what we would do, what it would cost and what to watch out for.

  • A named specialist who owns the outcome, not a chat window
  • Advice checked against your actual systems, contracts and risks
  • Written scope and costs in NGN before any work starts