954-539-5678Free audit
Menu

Cybersecurity · Microsoft 365

The Microsoft 365 security settings that actually stop attacks

Ten settings, where to find them in the 2026 admin centers, and the order to change them in, written for owners and office managers.

Ten settings ranked by impact

Security Defaults vs Conditional Access explained

Current admin center paths for 2026

Get your free Technology Health Assessment

30 minutes of data collection, your report the next day, yours to keep with no obligation. Or pick a time now. Or call 954-539-5678.

The settings that matter most

If you only change ten Microsoft 365 security settings, make it these. They close the gaps attackers use most against small businesses: stolen passwords, old sign-in methods, quiet email forwarding and too many admins.

  1. Require MFA for everyone, with Security Defaults or Conditional Access.
  2. Block legacy authentication (old protocols that skip MFA).
  3. Keep two to four Global Administrators, use separate admin accounts, and set up two emergency access accounts.
  4. Turn off automatic forwarding to outside addresses.
  5. Confirm mailbox auditing and the audit log are on.
  6. Apply the Standard or Strict preset email protection policies.
  7. Publish SPF, DKIM and DMARC for your domain.
  8. Stop users from approving risky third-party apps.
  9. Limit “Anyone” sharing links in SharePoint and OneDrive.
  10. Require compliant, encrypted devices (Business Premium with Intune).

The rest of this guide explains each one, where to find it as of 2026, and the order to do them in.

Where the settings live in 2026

Microsoft has split administration across several portals, and the names have changed more than once. As of 2026 these are the ones you need:

  • Microsoft 365 admin center (admin.microsoft.com): users, licenses, billing, org settings.
  • Microsoft Entra admin center (entra.microsoft.com): sign-in, MFA, Security Defaults, Conditional Access, admin roles, app consent. Entra ID was formerly Azure Active Directory.
  • Microsoft Defender portal (security.microsoft.com): email threat policies, Secure Score, device security.
  • Microsoft Purview portal (purview.microsoft.com): audit log search, retention, data loss prevention.
  • Exchange admin center, SharePoint admin center and Microsoft Intune admin center (intune.microsoft.com) for mail flow, sharing and devices.

Note that Microsoft now enforces MFA for sign-in to the Microsoft 365 admin center, Entra admin center, Intune admin center and Azure portal. According to Microsoft Learn, enforcement for the Microsoft 365 admin center began rolling out in February 2025, and there is no opt-out.

Security Defaults vs Conditional Access

This is the first decision, because it controls how MFA works for everyone.

Security Defaults

Free and on or off, with no customization. It requires all users to register for MFA, requires MFA for admins every time, prompts users when Microsoft judges it necessary, blocks legacy authentication and blocks device code flow. New tenants get it by default.

Conditional Access

Requires Microsoft Entra ID P1, which is included in Microsoft 365 Business Premium. You write policies by user, app, location, device state and risk, and you can make exceptions such as a scanner account that cannot do MFA.

Decision rule: if you are on Business Basic or Standard and have no Entra ID P1 licenses, turn on Security Defaults and leave it on. If you have Business Premium, switch to Conditional Access. Microsoft’s guidance is to recreate the Security Defaults protections first, using the Microsoft-managed policies or the “secure foundations” templates, then disable Security Defaults. Never leave a tenant with neither.

To check, go to the Entra admin center, then Entra ID > Overview > Properties > Manage security defaults.

MFA done properly

  • Use the Authenticator app, not text messages, wherever possible. Security Defaults uses number matching in Microsoft Authenticator, which helps stop “MFA fatigue” attacks where people approve prompts they did not start.
  • Give admins phishing-resistant methods such as passkeys or FIDO2 security keys. With Conditional Access you can require this using authentication strength.
  • Revoke old sessions after you turn MFA on so everyone has to sign in again and register.
  • Check registration. In the Entra admin center, the authentication methods activity report shows who has not registered.

Block legacy authentication

Old protocols such as POP, IMAP and basic-auth SMTP cannot do MFA, so an attacker with a password can walk around it. Security Defaults blocks them. With Conditional Access, apply the “Block legacy authentication” template. Before you do, find what still uses them, usually a copier that scans to email or an old line-of-business app, and move it to a supported method such as SMTP relay through a connector.

Lock down admin accounts

  • Keep Global Administrators to a small number. Microsoft recommends fewer than five, and at least two so you are never locked out.
  • Give admins a separate admin account they use only for admin work, with no mailbox if possible.
  • Use narrower roles such as User Administrator, Exchange Administrator or Helpdesk Administrator instead of Global Administrator.
  • Create two cloud-only emergency access accounts with long passwords and passkeys, stored securely and monitored for any sign-in.
  • Review the role list each quarter. Former staff and old vendors holding admin rights is one of the most common findings in our reviews.

Want a second set of eyes on your tenant?

Our free Technology Health Assessment takes about 30 minutes of data collection and gives you a plain-language report the next day, rating cybersecurity, IT operations and more as controlled, needs attention, significant exposure or unknown, with next steps in order. No obligation. Book your free assessment.

Stop automatic external forwarding

When attackers take over a mailbox, one of the first things they do is set a rule that quietly forwards mail outside the company. Microsoft’s default setting, “Automatic – System-controlled,” behaves differently depending on when your tenant was created, so Microsoft advises setting it explicitly.

In the Defender portal, go to Email & collaboration > Policies & rules > Threat policies > Anti-spam, open the outbound spam filter policy, and set automatic forwarding to Off – Forwarding is disabled. If a few people genuinely need to forward to a partner, create a separate policy for just them. Then check the Auto forwarded messages report in the Exchange admin center for anyone already forwarding.

Confirm auditing is on

According to Microsoft Learn, mailbox audit logging is on by default for user, shared and Microsoft 365 Group mailboxes, and it records actions such as inbox rule changes, deletions and mail access. Do not assume. In Exchange Online PowerShell, Get-OrganizationConfig | Format-List AuditDisabled should return False. Then open the Audit area of the Purview portal and run a test search. If an incident happens, these logs are what your insurer and investigators will ask for, and how long they are kept depends on your license.

Email protection and your domain

  • Preset security policies: in the Defender portal under Threat policies, apply the Standard or Strict preset. It sets anti-spam, anti-phishing and anti-malware to Microsoft’s recommended values, plus Safe Links and Safe Attachments if your license includes Defender for Office 365, as Business Premium does.
  • SPF, DKIM and DMARC: publish all three for every domain that sends mail, enable DKIM signing in the Defender portal, and move DMARC from monitoring toward quarantine once you know every service that sends as you.
  • External sender tags: turn on the “External” tag in Outlook so staff can spot outside mail pretending to be internal.

Apps, sharing and devices

  • App consent: in the Entra admin center under Enterprise apps, consent and permissions, stop users from granting third-party apps access to company data, or allow it only for low-risk permissions from verified publishers. Set up an admin consent request workflow instead.
  • Sharing: in the SharePoint admin center, set external sharing to “New and existing guests” rather than “Anyone,” or give “Anyone” links an expiry date.
  • Devices: with Business Premium, enroll devices in Intune, require BitLocker or FileVault encryption, set compliance policies, and use Conditional Access to block non-compliant devices from company data.
  • Secure Score: in the Defender portal, Secure Score lists improvement actions for your tenant. Use it as a to-do list, not a grade.

Order of operations

  1. Week one: admin accounts, emergency access accounts, MFA, legacy authentication, external forwarding.
  2. Week two: auditing check, preset email policies, SPF/DKIM/DMARC.
  3. Week three: app consent, sharing limits, device enrollment and compliance.
  4. Every quarter: review admin roles, guest accounts, Secure Score and leavers.

JLB USA sets up and maintains these controls as part of our managed IT and cybersecurity services, including help with cyber-insurance questionnaires that ask about MFA and email security. Call 954-539-5678 or start with the free assessment.

Book it now

Pick a time for your 30 minutes

Choose a slot that suits you. We’ll confirm by email, collect the data with you on the call, and send your report the next day. It’s free, and the report is yours to keep with no obligation.

Prefer to talk first? Call 954-539-5678, or send the form and we’ll contact you.

Questions we hear

Should I use Security Defaults or Conditional Access?

If you have no Microsoft Entra ID P1 licenses (Business Basic or Standard only), use Security Defaults. If you have Business Premium, which includes Entra ID P1, move to Conditional Access after recreating the same protections. Never run with neither.

Is MFA turned on by default in Microsoft 365?

New tenants have Security Defaults on, which requires MFA registration. Older tenants may not. Microsoft also enforces MFA for its admin portals. Check Entra ID > Overview > Properties to see your current state.

How do I stop email from being forwarded outside my company?

In the Microsoft Defender portal, edit the outbound spam filter policy under Threat policies > Anti-spam and set automatic forwarding to Off. Create a separate policy for anyone with a genuine business need.

Is mailbox auditing on by default?

According to Microsoft Learn, yes, for user, shared and Microsoft 365 Group mailboxes. Confirm with Get-OrganizationConfig in Exchange Online PowerShell and run a test search in the Purview audit tool.

What is Microsoft Secure Score?

A score in the Microsoft Defender portal that lists recommended security improvements for your tenant and tracks progress. It is useful as a checklist; a high score does not mean you are safe.

Related services

Want to know where your business stands?

Pick a time for my free assessmentCall 954-539-5678