1
A default Microsoft 365 setup is not a secure one. Out of the box, Microsoft leaves most of its strongest security controls turned off or set to a baseline that attackers have learned to bypass.
That matters because 365 is now the front door to most small businesses. Email, files, Teams, SharePoint, and calendars all sit behind the same login. One compromised password can expose everything behind it.
The FBI’s 2025 Internet Crime Report recorded more than $2.7 billion in business email compromise losses in a single year. Most of it started inside a poorly configured inbox.
Here is exactly what to turn on, where to find it in the Microsoft 365 admin center, and why each setting matters for a Boston small business in 2026.
Quick Answer: The Settings You Cannot Skip
Microsoft designs default settings to minimize friction for new users, not to maximize security. Many of the controls that actually protect your business — conditional access, data loss prevention, forwarding rule restrictions — sit behind menus most users never open.
Cyber insurers have started requiring specific Microsoft 365 configurations as part of the underwriting process. If you cannot document that MFA is enforced and forwarding rules are restricted, some carriers will decline coverage or add exclusions for email-related incidents.
What it does: Requires a second verification step — like a push notification or a one-time code — before allowing a sign-in. It is the single most effective control against stolen passwords.
Where to find it: Go to the Microsoft 365 Admin Center and select Security in the left menu. Navigate to Authentication methods under the Entra ID settings. If you have not already configured Conditional Access policies, enabling Security Defaults is the fastest way to enforce MFA across your tenant.
Important: Enable MFA for admin accounts first, then roll it out to all users. Shared mailboxes and service accounts should not be left uncovered.
What it does: Blocks or challenges sign-ins based on location, device health, or risk level. If someone attempts to log in from an unexpected country or an unmanaged device, conditional access can require MFA, block the sign-in entirely, or flag it for review.
Where to find it: Go to the Microsoft Entra admin center at entra.microsoft.com and navigate to Protection, then Conditional Access. Create a policy requiring MFA for all users. Create a second policy blocking legacy authentication protocols, which are older sign-in methods that bypass MFA entirely and remain a common attacker entry point.
Note: Conditional access requires Microsoft 365 Business Premium or an Entra ID P1 license. On Business Basic or Standard, enabling Security Defaults provides a baseline version of this protection.
What it does: Prevents attackers from setting up silent forwarding rules that redirect copies of incoming email to an outside address after gaining access to an inbox. This technique often goes undetected for weeks.
Where to find it: Open the Exchange Admin Center at admin.exchange.microsoft.com and navigate to Mail flow, then Rules. Create a rule that blocks automatic forwarding to external addresses or generates an alert when a user attempts to set one up.
To audit existing forwarding rules: go to Recipients, then Mailboxes, select a user, and review Mail flow settings. Any unexpected external forwarding rule is a red flag.
What it does: Limits global admin access to a small number of dedicated accounts used only for administrative tasks, not daily email or browsing. When an admin uses their admin account for routine work, a single phishing click can compromise the entire Microsoft 365 tenant.
Where to find it: Go to the Microsoft 365 Admin Center and select Users, then Active users. Filter by role and review who holds Global Administrator. Anyone using their admin account for daily email should have a separate standard account created for routine work.
A practical rule: global admin accounts should never have email enabled.
What it does: Flags or blocks sensitive information — like Social Security numbers, credit card numbers, or client financial data — from leaving your organization over email or SharePoint.
Where to find it: Open Microsoft Purview at compliance.microsoft.com and navigate to Data loss prevention, then Policies. Microsoft provides built-in templates for common regulatory requirements, including HIPAA and financial services. Start with a policy set to notify before moving to block, so you can see what is being flagged without disrupting workflows.
What it does: Surfaces unusual sign-in activity — logins from unexpected locations, unusual hours, or new devices — before it leads to a breach.
Where to find it: In the Entra admin center, navigate to Monitoring and health, then Sign-in logs. Filter by user, location, or risk level to spot anomalies. To automate alerts, go to Protection, then Identity Protection, and configure Risky sign-in notifications. Full risk detection requires an Entra ID P2 license, but basic alerts are available in Business Premium.
Enabling MFA, DLP, and sign-in alerts costs nothing beyond your existing Microsoft 365 license on Business Standard or higher. Conditional access and identity protection require Business Premium. For most Boston SMBs, that upgrade costs less per month than the deductible on a single business email compromise claim.
Healthcare Boston healthcare practices need DLP configured to flag protected health information in email and SharePoint. HIPAA requires documented evidence that controls are active, not just enabled. Your IT provider should be able to produce that documentation on request.
Finance and Professional Services Financial firms need conditional access and audit logging configured to satisfy recordkeeping requirements. Boston firms holding personal information of Massachusetts residents also fall under 201 CMR 17.00, which requires a documented written information security plan.
Legal Privileged client communications carried over email need forwarding rule restrictions and tight mailbox security. A compromised law firm inbox is a breach of professional obligation, not just an IT incident.
Biotech and Life Sciences Cambridge and Seaport biotech companies routinely share proprietary research data over email and SharePoint. DLP policies that cover SharePoint and Teams, not just email, are essential for protecting that data before it leaves your environment.
Is Microsoft 365’s built-in security enough on its own? The built-in tools are strong. The problem is they are not turned on by default. A default setup leaves significant gaps that need to be configured deliberately.
How long does it take to secure a Microsoft 365 tenant? A full configuration and rollout typically takes one to two weeks, depending on user count and your current license tier.
Will MFA slow down my team? Modern MFA options, including the Microsoft Authenticator app’s push notifications, add a few seconds to sign-in. Most users adapt within a day or two.
Do I need Business Premium for all of these settings? MFA, DLP, and forwarding rule restrictions work on Business Standard and above. Conditional access and advanced identity protection require Business Premium.
How often should we review these settings? At minimum twice a year, and immediately after any significant staffing change or new compliance requirement.
What is the first thing to turn on today? Multi-factor authentication for every account, starting with anyone who has admin access. It is the fastest control to implement and the one attackers count on being missing.
Microsoft 365 gives Boston small businesses enterprise-grade security tools. The gap is not the platform. It is the configuration.
Turning on MFA, conditional access, DLP, and forwarding rule restrictions closes the doors attackers rely on most without adding new software or significant cost.
If you are not sure what is turned on in your Microsoft 365 tenant right now, request a Microsoft 365 security assessment from BHD and find out before an attacker does.