Skip to content

Insights

Microsoft 365 Security Checklist for Small Businesses

A practical Microsoft 365 security checklist for Australian small businesses — covering MFA, Conditional Access, email filtering, and backup.

Microsoft 365 is the most widely used business productivity platform in Australia. Most small businesses have it. Most small businesses are not using it securely.

The default Microsoft 365 configuration is designed for ease of use — not security. Out of the box, it leaves significant gaps that attackers regularly exploit. This checklist covers the most important settings every Australian small business should have in place.

1. Multi-Factor Authentication (MFA)

MFA is the single highest-impact security control in Microsoft 365. If you only do one thing on this list, do this.

  • MFA enabled for all users — not just admins
  • Security Defaults or Conditional Access policies enforcing MFA
  • Admin accounts have phishing-resistant MFA (FIDO2 key or Microsoft Authenticator app, not SMS)
  • Per-user MFA (legacy) replaced by Conditional Access (more flexible and more secure)

ACSC Essential Eight context: MFA is the number one mitigation in the ACSC Essential Eight. The ACSC recommends that all internet-facing services — including Microsoft 365 — require MFA.

2. Conditional Access

Conditional Access policies allow you to define rules for who can access Microsoft 365, from where, and under what conditions. This is a significant step up from simply enabling MFA.

  • Block legacy authentication protocols (SMTP, POP3, IMAP) — these bypass MFA
  • Require MFA for all users on all apps
  • Block or limit access from high-risk countries (if your business has no operations there)
  • Require compliant or Azure AD joined devices for access to sensitive data (if using Intune)

Note: Conditional Access requires Microsoft 365 Business Premium or Azure AD P1. It is not available on Microsoft 365 Business Basic or Business Standard without an add-on.

3. Email Security

Email is the primary attack vector for small businesses. Microsoft 365 includes Defender for Office 365 (Plan 1 in Business Premium), but it needs to be configured — it is not enabled by default.

  • Safe Links enabled — checks URLs in emails and Office documents at click time
  • Safe Attachments enabled — sandboxes email attachments before delivery
  • Anti-phishing policy configured with impersonation protection for your domain and key personnel
  • DMARC, DKIM, and SPF configured on your domain
  • Outbound spam filtering to prevent your domain being used to send spam

4. Admin Account Security

Global Administrator accounts in Microsoft 365 have unrestricted access to everything. Compromising a Global Admin account gives an attacker full control of your tenant.

  • Global Admin accounts are separate from everyday user accounts (dedicated admin accounts)
  • Global Admin accounts have no mailbox and are not used for day-to-day email
  • The number of Global Admins is minimised (two or three maximum for most small businesses)
  • Break-glass admin accounts exist and are secured and documented
  • Admin activity is logged and monitored

5. Data Loss Prevention

Data Loss Prevention (DLP) policies prevent sensitive information from being shared accidentally or intentionally in ways that violate your policies.

  • DLP policies configured to detect and block sharing of sensitive information types (tax file numbers, credit card numbers, bank account details)
  • SharePoint and OneDrive external sharing settings reviewed and restricted appropriately
  • Anonymous sharing links reviewed and restricted

6. Backup

Microsoft 365 does not include a backup service. Your emails, SharePoint files, OneDrive data, and Teams messages need a separate backup.

  • Third-party backup solution in place for Exchange Online, SharePoint, and OneDrive
  • Backup retention period appropriate for your record-keeping obligations
  • Restore procedure tested — not just assumed to work

7. Monitoring and Alerting

Knowing when something suspicious is happening in your Microsoft 365 environment requires active monitoring.

  • Audit logging enabled in the Microsoft Purview compliance portal
  • Alert policies configured for high-risk activities (mass file download, suspicious login, forwarding rules created)
  • Microsoft Secure Score reviewed periodically as a benchmark

Where to Start

If you have not started on this list, begin with MFA for all users. It is the highest-return security control in Microsoft 365 and can be enabled in under an hour.

From there, work through blocking legacy authentication and configuring email security — these two items close the most common attack paths.

If you want an independent review of your Microsoft 365 configuration, SouthCore provides Microsoft 365 security assessments for Melbourne businesses. We’ll tell you what’s configured correctly, what’s missing, and what the priorities are.

RELATED READING

Related Resources

Related

IT Support for Professional Services Firms in Melbourne

Managed IT for Melbourne professional services firms — including Microsoft 365 management.

Learn more

Related

Managed IT Services — SouthCore

End-to-end managed IT support for Melbourne businesses with 10–75 staff.

Learn more

Better IT starts with a conversation.

Tell us what you need. Let’s find a way forward.