90% of successful cyberattacks start with a compromised account. In Microsoft 365, the default configuration is not secure. It is designed for ease of adoption — not to protect your organization. The result: thousands of Microsoft 365 tenants are running today with gaping vulnerabilities, and their administrators have no idea. Here are the 10 settings to enable today — most of them at no additional cost.
The 10 Configurations to Enable Right Now
1. MFA for Every Account, No Exceptions
Multi-factor authentication — verifying your identity through a second device in addition to your password — reduces the risk of account compromise by 99.9% (a Microsoft figure, measured across billions of sign-ins). An attacker who steals your password cannot log in without your phone. Enabling it takes 30 minutes for 100 users via Entra ID > Security > Authentication methods. It is the fastest return on investment of your entire security policy.
2. Security Defaults: Your First Free Line of Defense
If your organization has not yet migrated to Conditional Access, Security Defaults are a basic security package included for free with all Microsoft 365 subscriptions. They automatically enable MFA, block legacy authentication protocols, and enforce stronger protection on administrator accounts. Enable them with a single click in the Entra ID portal.
3. Conditional Access: Block Sign-Ins from Outside Your Geography
Conditional Access is a rules engine that decides whether a sign-in is allowed based on its context: location, device, time, detected risk level. If your teams work in France, why allow connections from Nigeria or Russia? A simple rule: block all sign-ins from outside France (and outside any declared travel countries). This configuration requires an Entra ID P1 license, included in Microsoft 365 Business Premium.
4. Disable Legacy Authentication Protocols
IMAP, POP3, basic SMTP — these older protocols allow access to email without going through MFA. They simply do not support it. 40% of password spray attacks — a technique where the same password is tested against thousands of accounts — exploit these protocols to bypass modern protections. If no one in your organization uses an older mail client, disabling them changes nothing for your users. But it closes a major entry point for attackers.
5. Secure Administrator Accounts Specifically
A Microsoft 365 Global Admin has rights over your entire tenant: email, files, users, billing. Using that account day-to-day to read emails means exposing the keys to your organization with every click. Minimum rules: create dedicated admin accounts used only for administrative tasks, protect Global Admins with a hardware token (FIDO2 physical key), and audit admin permissions every 90 days.
6. Enable Microsoft Defender for Office 365 Plan 1
Included in Microsoft 365 Business Premium, Defender for Office 365 Plan 1 adds four critical protections. Advanced anti-phishing, which detects identity spoofing attempts even without a malicious link. Safe Links — every URL in an email is analyzed at the moment of click. Safe Attachments — every attachment is opened in an isolated environment before reaching your inbox. The concrete result: 97% of malware transmitted by attachment is blocked before the user ever opens it.
7. Configure DLP Policies for Sensitive Data
DLP — Data Loss Prevention — is a system that analyzes the content of outbound emails and shared files to detect sensitive information. IBAN numbers, credit card numbers, HR data, social security numbers: a DLP rule can automatically block the unauthorized transmission of this information. Configuration takes two hours via the Microsoft Purview portal. Essential for meeting GDPR obligations around the protection of personal data.
8. Enable Suspicious Sign-In Alerts
If an account signs in from Paris at 9:00 AM and from São Paulo at 10:30 AM, that is physically impossible. Microsoft Defender automatically detects these situations — known as "impossible travel" — and can send an immediate alert to your IT team or even block the suspicious session automatically. The average time to detection without an alert system is 197 days according to IBM. By then, the attacker has had plenty of time to cause damage.
9. Set an Email Retention Policy
Retaining emails for five to seven years is a legal obligation for many French companies. Microsoft Purview lets you configure automatic retention policies: emails are preserved in an immutable archive, even if the user deletes them. It is also protection in the event of litigation. Configuration takes two hours and applies to the entire tenant with no action required from users.
10. Audit SharePoint Access and Sharing
SharePoint often accumulates open sharing links that no one is aware of. A user shared a folder as "Anyone with the link" six months ago for an urgent project. The project is done. The link is still active. In our audits, this type of forgotten anonymous sharing is present in nearly every unmonitored tenant. A SharePoint access audit every six months allows you to identify and close these uncontrolled access points before they become an incident.
What These Configurations Actually Protect Against
These 10 settings are not theoretical. They address documented, measured, and recurring attacks against French SMBs.
- BEC — Business Email Compromise: the wire transfer fraud or CEO impersonation scam. An attacker gains access to an email account, monitors financial conversations, and injects a fraudulent bank account at the right moment. MFA, Conditional Access, and suspicious sign-in alerts block the initial access.
- Ransomware via attachment: a booby-trapped PDF invoice opens a backdoor on a workstation, then encrypts all accessible files — including SharePoint. Safe Attachments analyzes every attachment in a sandbox before delivery. Retention policies enable recovery without paying the ransom.
- Data breach: an uninformed employee sends an HR file by email to an external address. DLP policies intercept that transmission before it leaves your organization. You avoid a GDPR notification to the data protection authority and the associated penalties.
What an Audit Typically Reveals
At SMBs we work with before any intervention, the finding is consistent: between 3 and 5 critical configurations missing from these 10 points. This is not negligence. It is the result of a fast Microsoft 365 deployment with no specialized security guidance.
The most common gaps our team identifies during a Microsoft 365 security audit:
- Administrator accounts used daily, without specific MFA
- Legacy authentication protocols still active on recent tenants
- Anonymous SharePoint sharing links open on confidential documents
- No DLP policy configured, despite the presence of HR or financial data
- No suspicious sign-in alerts active
A Microsoft 365 security audit takes one day. It produces a detailed report with every gap documented, a security maturity score, and a remediation plan prioritized by risk level.
To go further on securing your cloud infrastructure, see our Azure Cloud Security page. And if you want to know your current security posture, request a free security audit — our team will get back to you within 48 hours.

