Cybersecurity · Microsoft 365
Ten settings, where to find them in the 2026 admin centers, and the order to change them in, written for owners and office managers.
Ten settings ranked by impact
Security Defaults vs Conditional Access explained
Current admin center paths for 2026
30 minutes of data collection, your report the next day, yours to keep with no obligation. Or pick a time now. Or call 954-539-5678.
If you only change ten Microsoft 365 security settings, make it these. They close the gaps attackers use most against small businesses: stolen passwords, old sign-in methods, quiet email forwarding and too many admins.
The rest of this guide explains each one, where to find it as of 2026, and the order to do them in.
Microsoft has split administration across several portals, and the names have changed more than once. As of 2026 these are the ones you need:
Note that Microsoft now enforces MFA for sign-in to the Microsoft 365 admin center, Entra admin center, Intune admin center and Azure portal. According to Microsoft Learn, enforcement for the Microsoft 365 admin center began rolling out in February 2025, and there is no opt-out.
This is the first decision, because it controls how MFA works for everyone.
Free and on or off, with no customization. It requires all users to register for MFA, requires MFA for admins every time, prompts users when Microsoft judges it necessary, blocks legacy authentication and blocks device code flow. New tenants get it by default.
Requires Microsoft Entra ID P1, which is included in Microsoft 365 Business Premium. You write policies by user, app, location, device state and risk, and you can make exceptions such as a scanner account that cannot do MFA.
Decision rule: if you are on Business Basic or Standard and have no Entra ID P1 licenses, turn on Security Defaults and leave it on. If you have Business Premium, switch to Conditional Access. Microsoft’s guidance is to recreate the Security Defaults protections first, using the Microsoft-managed policies or the “secure foundations” templates, then disable Security Defaults. Never leave a tenant with neither.
To check, go to the Entra admin center, then Entra ID > Overview > Properties > Manage security defaults.
Old protocols such as POP, IMAP and basic-auth SMTP cannot do MFA, so an attacker with a password can walk around it. Security Defaults blocks them. With Conditional Access, apply the “Block legacy authentication” template. Before you do, find what still uses them, usually a copier that scans to email or an old line-of-business app, and move it to a supported method such as SMTP relay through a connector.
Our free Technology Health Assessment takes about 30 minutes of data collection and gives you a plain-language report the next day, rating cybersecurity, IT operations and more as controlled, needs attention, significant exposure or unknown, with next steps in order. No obligation. Book your free assessment.
When attackers take over a mailbox, one of the first things they do is set a rule that quietly forwards mail outside the company. Microsoft’s default setting, “Automatic – System-controlled,” behaves differently depending on when your tenant was created, so Microsoft advises setting it explicitly.
In the Defender portal, go to Email & collaboration > Policies & rules > Threat policies > Anti-spam, open the outbound spam filter policy, and set automatic forwarding to Off – Forwarding is disabled. If a few people genuinely need to forward to a partner, create a separate policy for just them. Then check the Auto forwarded messages report in the Exchange admin center for anyone already forwarding.
According to Microsoft Learn, mailbox audit logging is on by default for user, shared and Microsoft 365 Group mailboxes, and it records actions such as inbox rule changes, deletions and mail access. Do not assume. In Exchange Online PowerShell, Get-OrganizationConfig | Format-List AuditDisabled should return False. Then open the Audit area of the Purview portal and run a test search. If an incident happens, these logs are what your insurer and investigators will ask for, and how long they are kept depends on your license.
JLB USA sets up and maintains these controls as part of our managed IT and cybersecurity services, including help with cyber-insurance questionnaires that ask about MFA and email security. Call 954-539-5678 or start with the free assessment.
Book it now
Choose a slot that suits you. We’ll confirm by email, collect the data with you on the call, and send your report the next day. It’s free, and the report is yours to keep with no obligation.
Prefer to talk first? Call 954-539-5678, or send the form and we’ll contact you.
If you have no Microsoft Entra ID P1 licenses (Business Basic or Standard only), use Security Defaults. If you have Business Premium, which includes Entra ID P1, move to Conditional Access after recreating the same protections. Never run with neither.
New tenants have Security Defaults on, which requires MFA registration. Older tenants may not. Microsoft also enforces MFA for its admin portals. Check Entra ID > Overview > Properties to see your current state.
In the Microsoft Defender portal, edit the outbound spam filter policy under Threat policies > Anti-spam and set automatic forwarding to Off. Create a separate policy for anyone with a genuine business need.
According to Microsoft Learn, yes, for user, shared and Microsoft 365 Group mailboxes. Confirm with Get-OrganizationConfig in Exchange Online PowerShell and run a test search in the Purview audit tool.
A score in the Microsoft Defender portal that lists recommended security improvements for your tenant and tracks progress. It is useful as a checklist; a high score does not mean you are safe.