1 Microsoft 365 Security Settings for Boston SMBs

A default Microsoft 365 setup is not a secure one. Out of the box, Microsoft leaves most of its strongest security controls turned off or set to a baseline that attackers have learned to bypass.

That matters because 365 is now the front door to most small businesses. Email, files, Teams, SharePoint, and calendars all sit behind the same login. One compromised password can expose everything behind it.

The FBI’s 2025 Internet Crime Report recorded more than $2.7 billion in business email compromise losses in a single year. Most of it started inside a poorly configured inbox.

Here is exactly what to turn on, where to find it in the Microsoft 365 admin center, and why each setting matters for a Boston small business in 2026.

Quick Answer: The Settings You Cannot Skip

  • Multi-factor authentication enforced for every account, no exceptions
  • Conditional access policies that block risky or unexpected sign-ins
  • Mailbox forwarding rules audited and restricted by policy
  • Admin accounts separated from everyday user accounts
  • Data loss prevention policies for sensitive client and financial data
  • Sign-in alerts configured to catch suspicious activity in real time

Why the Default Setup Falls Short

Microsoft designs default settings to minimize friction for new users, not to maximize security. Many of the controls that actually protect your business — conditional access, data loss prevention, forwarding rule restrictions — sit behind menus most users never open.

Cyber insurers have started requiring specific Microsoft 365 configurations as part of the underwriting process. If you cannot document that MFA is enforced and forwarding rules are restricted, some carriers will decline coverage or add exclusions for email-related incidents.

The Six Settings That Matter Most, and How to Turn Them On

  1. Multi-Factor Authentication (MFA)

What it does: Requires a second verification step — like a push notification or a one-time code — before allowing a sign-in. It is the single most effective control against stolen passwords.

Where to find it: Go to the Microsoft 365 Admin Center and select Security in the left menu. Navigate to Authentication methods under the Entra ID settings. If you have not already configured Conditional Access policies, enabling Security Defaults is the fastest way to enforce MFA across your tenant.

Important: Enable MFA for admin accounts first, then roll it out to all users. Shared mailboxes and service accounts should not be left uncovered.

  1. Conditional Access Policies

What it does: Blocks or challenges sign-ins based on location, device health, or risk level. If someone attempts to log in from an unexpected country or an unmanaged device, conditional access can require MFA, block the sign-in entirely, or flag it for review.

Where to find it: Go to the Microsoft Entra admin center at entra.microsoft.com and navigate to Protection, then Conditional Access. Create a policy requiring MFA for all users. Create a second policy blocking legacy authentication protocols, which are older sign-in methods that bypass MFA entirely and remain a common attacker entry point.

Note: Conditional access requires Microsoft 365 Business Premium or an Entra ID P1 license. On Business Basic or Standard, enabling Security Defaults provides a baseline version of this protection.

  1. Mailbox Forwarding Rules

What it does: Prevents attackers from setting up silent forwarding rules that redirect copies of incoming email to an outside address after gaining access to an inbox. This technique often goes undetected for weeks.

Where to find it: Open the Exchange Admin Center at admin.exchange.microsoft.com and navigate to Mail flow, then Rules. Create a rule that blocks automatic forwarding to external addresses or generates an alert when a user attempts to set one up.

To audit existing forwarding rules: go to Recipients, then Mailboxes, select a user, and review Mail flow settings. Any unexpected external forwarding rule is a red flag.

  1. Admin Role Separation

What it does: Limits global admin access to a small number of dedicated accounts used only for administrative tasks, not daily email or browsing. When an admin uses their admin account for routine work, a single phishing click can compromise the entire Microsoft 365 tenant.

Where to find it: Go to the Microsoft 365 Admin Center and select Users, then Active users. Filter by role and review who holds Global Administrator. Anyone using their admin account for daily email should have a separate standard account created for routine work.

A practical rule: global admin accounts should never have email enabled.

  1. Data Loss Prevention (DLP)

What it does: Flags or blocks sensitive information — like Social Security numbers, credit card numbers, or client financial data — from leaving your organization over email or SharePoint.

Where to find it: Open Microsoft Purview at compliance.microsoft.com and navigate to Data loss prevention, then Policies. Microsoft provides built-in templates for common regulatory requirements, including HIPAA and financial services. Start with a policy set to notify before moving to block, so you can see what is being flagged without disrupting workflows.

  1. Sign-In Log Monitoring and Alerts

What it does: Surfaces unusual sign-in activity — logins from unexpected locations, unusual hours, or new devices — before it leads to a breach.

Where to find it: In the Entra admin center, navigate to Monitoring and health, then Sign-in logs. Filter by user, location, or risk level to spot anomalies. To automate alerts, go to Protection, then Identity Protection, and configure Risky sign-in notifications. Full risk detection requires an Entra ID P2 license, but basic alerts are available in Business Premium.

What These Settings Cost to Implement

Enabling MFA, DLP, and sign-in alerts costs nothing beyond your existing Microsoft 365 license on Business Standard or higher. Conditional access and identity protection require Business Premium. For most Boston SMBs, that upgrade costs less per month than the deductible on a single business email compromise claim.

Industry Considerations for Boston Businesses

Healthcare Boston healthcare practices need DLP configured to flag protected health information in email and SharePoint. HIPAA requires documented evidence that controls are active, not just enabled. Your IT provider should be able to produce that documentation on request.

Finance and Professional Services Financial firms need conditional access and audit logging configured to satisfy recordkeeping requirements. Boston firms holding personal information of Massachusetts residents also fall under 201 CMR 17.00, which requires a documented written information security plan.

Legal Privileged client communications carried over email need forwarding rule restrictions and tight mailbox security. A compromised law firm inbox is a breach of professional obligation, not just an IT incident.

Biotech and Life Sciences Cambridge and Seaport biotech companies routinely share proprietary research data over email and SharePoint. DLP policies that cover SharePoint and Teams, not just email, are essential for protecting that data before it leaves your environment.

Frequently Asked Questions

Is Microsoft 365’s built-in security enough on its own? The built-in tools are strong. The problem is they are not turned on by default. A default setup leaves significant gaps that need to be configured deliberately.

How long does it take to secure a Microsoft 365 tenant? A full configuration and rollout typically takes one to two weeks, depending on user count and your current license tier.

Will MFA slow down my team? Modern MFA options, including the Microsoft Authenticator app’s push notifications, add a few seconds to sign-in. Most users adapt within a day or two.

Do I need Business Premium for all of these settings? MFA, DLP, and forwarding rule restrictions work on Business Standard and above. Conditional access and advanced identity protection require Business Premium.

How often should we review these settings? At minimum twice a year, and immediately after any significant staffing change or new compliance requirement.

What is the first thing to turn on today? Multi-factor authentication for every account, starting with anyone who has admin access. It is the fastest control to implement and the one attackers count on being missing.

Conclusion

Microsoft 365 gives Boston small businesses enterprise-grade security tools. The gap is not the platform. It is the configuration.

Turning on MFA, conditional access, DLP, and forwarding rule restrictions closes the doors attackers rely on most without adding new software or significant cost.

If you are not sure what is turned on in your Microsoft 365 tenant right now, request a Microsoft 365 security assessment from BHD and find out before an attacker does.

Albert Najimy

Albert Najimy

When it comes to technology services and solutions, it's vital to have a knowledgeable and enthusiastic partner who can help clients achieve long-lasting growth using proven IT solutions. Our CEO, Albert, is fully dedicated to assisting clients in improving their technology to gain a competitive edge in their industries. At Boston Helpdesk, Albert Najimy leads a team of dedicated professionals who are focused on delivering exceptional IT services and solutions. With his extensive expertise and practical experience, Albert ensures that clients receive top-quality support and guidance for their IT projects. You can count on Boston Helpdesk to enhance your business systems and stay ahead in today's fiercely competitive business environment.