24/7 Support Available
Skip to main content
Intermediate
1 to 2 weeks

Microsoft 365 Security Hardening

The changes that make the biggest difference to a Microsoft 365 tenant: multi factor authentication, removing legacy sign in, anti phishing rules, and keeping an eye on the audit log.

Prerequisites

  • Global Administrator access to the Microsoft 365 tenant, ideally from a dedicated admin account.
  • A short pilot group of willing users so you can test changes before they reach everyone.
  • A maintenance window agreed with the business, since removing legacy sign in can disrupt older apps.
  • Microsoft Entra ID P1 or P2 for Conditional Access, or Security Defaults if you are on the free tier.

Step-by-Step Instructions

Turn on multi factor authentication for everyone

Account takeover almost always starts with a stolen password, and MFA stops the great majority of it. Enforce MFA for all users, not just administrators, using Conditional Access if you have it or Security Defaults if you do not. Prefer an authenticator app or a hardware key over text messages, which can be intercepted.

Tip

Roll out to a pilot group first, then the rest of the business. Keep two break glass admin accounts excluded from Conditional Access and stored securely, so a policy mistake cannot lock you out.

Block legacy authentication

Older protocols such as IMAP, POP and basic authentication cannot enforce MFA, so attackers target them directly. Check the sign in logs to see what still relies on legacy authentication, move those apps onto modern authentication, then block the legacy protocols. This single change closes a door that a lot of attacks walk straight through.

Tighten anti phishing and anti spam policies

Microsoft Defender for Office 365 lets you raise the default protection. Switch on mailbox intelligence, impersonation protection for your senior people and your own domains, and safe links and safe attachments if your licence includes them. Set the policies to quarantine rather than deliver anything judged to be phishing.

Review admin roles and sharing

Count your Global Administrators and reduce the number to the few who genuinely need it, giving everyone else the least privileged role that fits their work. Review external sharing settings in SharePoint and OneDrive so files are not shared more widely than intended, and turn off automatic forwarding of email to outside addresses.

Switch on unified audit logging

You cannot investigate what you did not record. Confirm the unified audit log is on so sign ins, file access and admin changes are captured. Set alerts for the events that matter, such as a new mailbox forwarding rule or a change to MFA settings, and decide how long you need to keep the logs.

Check your Secure Score and set a review date

Microsoft Secure Score turns all of this into a single figure with prioritised actions and an estimate of the effort each one takes. Use it to plan the next round of improvements, then put a recurring date in the diary to review it, because tenants drift as staff and apps change.

Every organisation is different, and a playbook can only take you so far. If you would like a second pair of eyes, or you would rather we handled the work, our security posture improvement team is here to help. Talk to us about your requirements.