Mon–Sat 10:00–18:00 London · UK
Remote & on-site ☎ 0207 096 0936
← Guides
Security

How to Secure Your Microsoft 365 Tenant

MFA is the floor, not the ceiling. A practical guide to hardening Microsoft 365 beyond multi-factor authentication — conditional access, admin roles, audit logging and Safe Links.

There’s a comfortable assumption we run into a lot: “We’ve switched on multi-factor authentication, so our Microsoft 365 is secure.” Turning on MFA is genuinely one of the best things you can do — it stops the overwhelming majority of password-only attacks. But it’s the floor, not the ceiling. Attackers adapted years ago. They send repeated MFA prompts hoping someone taps “approve” out of habit, they steal session tokens so they never see a prompt at all, and they exploit older sign-in protocols that bypass MFA entirely.

So MFA on its own is not “done”. The good news is that the next layers aren’t exotic. They’re built into Microsoft 365, and a handful of them close most of the gaps. Here’s what actually matters, in plain terms.

Turn on conditional access (and block legacy sign-ins first)

Conditional access is the control that decides when a sign-in is allowed, challenged or refused — based on who’s logging in, from what device, where, and how risky it looks. It’s the biggest single step beyond basic MFA.

The first rule to set is the dullest and the most important: block legacy authentication. Older protocols like IMAP, POP and basic auth were never designed for MFA, and attackers deliberately target them because they slip straight past it. Blocking them shuts a door that a lot of businesses don’t know is open.

From there, a few sensible rules go a long way:

  • Require MFA for every user, with no quiet exceptions.
  • Require a managed or compliant device for anyone with admin rights.
  • Challenge or block sign-ins from countries you never operate in.
  • Flag risky sign-ins for an extra check rather than waving them through.

Conditional access needs the right licensing, so it’s worth confirming what your plan covers before you design the rules. This is exactly the kind of thing we sort out during a proper Microsoft 365 setup rather than leaving to chance.

Cut down admin accounts and stop using them daily

The single most damaging account to lose is a Global Administrator. Yet admin rights have a habit of piling up — someone gets promoted to Global Admin for a one-off task and still holds it three years later. Every one of those accounts is a master key, and every extra key is a bigger target.

Two principles fix most of this. First, least privilege: give each person the smallest role that lets them do their job, not a blanket admin role for convenience. Microsoft 365 has specific roles — for billing, for user management, for helpdesk tasks — so most people never need full control of the tenant.

Second, separate admin accounts from everyday accounts. The person who administers your tenant should have one identity for daily email and browsing, and a separate admin identity used only when they’re actually administering something. That way, a phishing email opened on the normal account can’t hand over the keys to everything. Reviewing who holds privileged roles every quarter — and removing what’s no longer needed — takes half an hour and prevents a genuinely bad day.

Switch on audit logging before you need it

Audit logging is one of those things nobody thinks about until an incident, when the first question is always “what actually happened?” If logging wasn’t on, you can’t answer it — and you can’t tell whether an attacker read one mailbox or all of them.

Make sure unified audit logging is enabled so you have a record of sign-ins, mailbox access, file activity and admin changes. It’s your black box. When something looks off — an odd forwarding rule, a login from nowhere — the logs are what turn guesswork into a clear picture. This kind of visibility is part of the wider cyber security posture we help businesses build, and it costs nothing to have running quietly in the background.

Most incidents still start with email. Safe Links and Safe Attachments (part of Microsoft Defender for Office 365) add a real layer here. Safe Links rewrites and checks URLs at the moment someone clicks — so a link that was clean when the email arrived but weaponised an hour later is still caught. Safe Attachments detonates attachments in an isolated environment before they reach the user.

Pair that with sensible anti-phishing rules and a check for suspicious mailbox forwarding — a classic attacker move is to quietly forward a compromised mailbox to an external address and read everything from the outside. These protections depend on your licence tier, so it’s worth checking what you already own before buying anything extra.

A quick honest note on the basics

None of this replaces the fundamentals: keep devices patched, make sure your data is actually backed up (Microsoft’s own advice is that tenant data is your responsibility, not theirs), and keep an eye on where your files live as you lean further on Microsoft 365 and the cloud. Security is layers. MFA is a strong first one — these are the next few that turn a tenant from “logged-in-protected” into genuinely hardened.

If you’re not sure which of these are already switched on in your tenant, that’s normal — the settings are scattered and the defaults change. We’re happy to run through your Microsoft 365 configuration and tell you plainly what’s solid, what’s missing and what’s worth doing first. No jargon, no scare tactics — just a clear picture of where you stand.

Frequently asked questions

We've turned on MFA — isn't our Microsoft 365 already secure?

MFA is essential, but it's the starting point, not the finish line. Attackers now use MFA-fatigue prompts, token theft and legacy protocols that skip MFA entirely. Real hardening also means conditional access rules, fewer admin accounts, audit logging switched on, and mail protection like Safe Links. MFA alone leaves several of those doors open.

What is conditional access and do we need it?

Conditional access is a set of rules that decides when a sign-in is allowed, challenged or blocked — based on the user, device, location and risk level. It's how you block legacy sign-ins, require a managed device for admins, or challenge logins from unexpected countries. It needs the right licensing, but for most businesses it's the single biggest step up from plain MFA.

How often should we review who has admin access?

At least quarterly, and immediately whenever someone changes role or leaves. Admin rights accumulate quietly — a person gets Global Admin for a one-off task and keeps it for years. A short regular review of who holds privileged roles, and removing anything no longer needed, closes one of the most common weak points we find.

Related services

Free · no obligation

Want a hand with any of this?

Tell us what you're trying to sort out and we'll come back with a clear, no-obligation plan and price.