Skip to content

← Resources

Any small firm on Microsoft 365

Five Microsoft 365 settings most small firms are missing

February 18, 2026

Most small firms we look at are on Microsoft 365 Business, and most of them have never changed the security settings from the day the account was created. That is not negligence — the settings are buried, the language is dense, and nothing breaks if you leave them alone. But a few of them matter a great deal.

Here are five we check first. None of them cost extra on a Business Premium plan.

1. Multi-factor authentication is not actually enforced

Turning on “Security Defaults” is a start, but many firms have it switched off because it once blocked a scanner or a shared mailbox. The result is that a stolen password — from a data breach, a phishing email, a reused login — is enough to get into email. Enforced MFA for every user, with a small number of documented exceptions handled properly, is the single highest-value change.

2. Legacy authentication is still allowed

Older mail protocols (POP, IMAP, basic-auth SMTP) do not support MFA. As long as they are enabled, an attacker can skip your MFA entirely by using one of them. These should be blocked with a Conditional Access policy, with any real device that needs them moved to a modern method first.

3. There is no backup of Microsoft 365 data

Microsoft keeps your service running. It does not guarantee to get your data back if a user deletes a year of email, or ransomware encrypts a shared drive, or an account is compromised and mailboxes are wiped. That is your responsibility under Microsoft’s own shared-responsibility model. A proper third-party backup of mail, OneDrive, SharePoint, and Teams — with a restore that has actually been tested — closes that gap.

4. Anti-phishing protection is on the default setting

The default anti-phishing policy does not protect against impersonation of your own people. Adding your partners and finance staff to impersonation protection, turning on mailbox intelligence, and enabling Safe Links and Safe Attachments stops a large share of the “the boss needs a wire transfer” emails before they land.

5. Everyone can grant apps access to company data

By default, any user can approve a third-party app’s request for access to their mailbox and files. Attackers use this — a convincing prompt, one click, and they have a token that survives a password reset. Restricting app consent to verified, low-risk publishers removes that path.


If you want to know which of these apply to your firm, we run a free 20-minute Microsoft 365 security check: we score your current setup and send you a one-page summary. Book one here.

Get started

Tell us what you need. We’ll tell you exactly how it works.

Book a short consultation. We walk through the service, what we need from you, the price and the timeline — with no obligation.