Microsoft 365 is genuinely brilliant. Email, calendar, Teams, Word, Excel, SharePoint, Intune, Defender, Copilot, all in one bundle. But out of the box, it’s also wide open. Microsoft prioritises ease of setup over secure-by-default. The first time most SMBs realise this is when they fail their first cyber insurance renewal questionnaire.
Here are the 12 settings every UK SMB should configure on day one of using Microsoft 365. Some take 30 seconds. None take more than 10 minutes. Together they’re the difference between a tenant that’s a liability and one that’s actually secure.
In short: a default Microsoft 365 setup is not a secure one, and about a dozen settings make most of the difference. Here are the twelve every UK SMB should turn on, and why each matters.
Key takeaways
- Microsoft 365 ships with most protection features disabled or set to weak defaults.
- Enabling MFA, conditional access, anti-phishing and audit logging takes about 90 minutes total.
- You’ll need at least Microsoft 365 Business Premium for most of these (Standard is not enough).
- The same 12 settings cover the bulk of what cyber insurers and Cyber Essentials assessors want to see.

1. Enforce multi-factor authentication for every team member
Settings: Entra ID admin centre, Security, Authentication methods, Conditional Access. Create a policy that requires MFA for all staff on all cloud apps, with no exceptions for admins.
This single setting blocks roughly 99.9% of credential-based attacks. It’s the most important security control on the entire Microsoft 365 platform. Don’t rely on per-person MFA settings (the legacy approach), use Conditional Access policies (the modern approach).
2. Block legacy authentication protocols
Old protocols like POP3, IMAP, SMTP-Auth and Exchange ActiveSync don’t support MFA. Attackers love them. Block them via Conditional Access. If a few staff still rely on them, migrate those staff to modern Outlook or the Outlook mobile app first.
3. Turn on Conditional Access “Block sign-ins from outside the UK”
Most UK SMBs only have legitimate logins from the UK and a handful of EU countries (when staff travel). Block everywhere else. If you have international clients or remote workers in specific countries, allowlist those countries. The number of attacks blocked by this single rule is staggering.
4. Enable mailbox auditing for every mailbox
Settings: Microsoft Purview compliance portal, Audit, then ensure mailbox auditing is on for all mailboxes. Without this, if you ever have a breach, you won’t be able to tell what the attacker accessed. With it, you have a forensic trail.
5. Configure anti-phishing and Safe Links
Defender for Office 365 (included in Business Premium) has anti-phishing policies that detect impersonation attempts targeting your domain and your VIPs. Set the impersonation protection to cover at least your top 5 senior staff. Safe Links rewrites URLs in inbound email so they’re scanned at click-time, not just at delivery.
6. Set up DKIM, SPF and DMARC for your domain
These three DNS records prevent attackers from spoofing your domain to send phishing emails to your customers and suppliers. SPF says which servers are allowed to send mail as your domain. DKIM cryptographically signs outbound mail. DMARC tells receiving servers what to do with mail that fails SPF or DKIM (typically: quarantine or reject).
Recommended starting DMARC policy
Start with p=none in monitor mode, watch the reports for two weeks to confirm legitimate senders are aligned, then progress to p=quarantine, then eventually p=reject. This staged rollout prevents accidentally blocking your own newsletter sender or invoicing tool.
7. Restrict external sharing in SharePoint and OneDrive
By default, anyone with a Microsoft 365 account can share any document with anyone, anywhere, with no expiry. Tighten this. SharePoint admin centre, Sharing. Set “External sharing” to “Existing guests” or “New and existing guests” with expiry dates required, and require sign-in for shared links.
8. Configure data loss prevention (DLP) policies for sensitive data
Out of the box, DLP doesn’t fire. Create policies that detect UK financial info (sort codes, IBANs, payment card numbers), NHS numbers if relevant, and any custom patterns that match your business (client matter numbers, contract IDs). At minimum, alert on attempts to email these externally; ideally, block.
9. Lock down OAuth app consent
By default, any team member can grant any third-party app access to their Microsoft 365 data, often the first thing a phishing attack tries. Restrict app consent to admins only. Settings: Entra admin centre, Enterprise applications, Consent and permissions.
10. Enrol every device in Intune (or block non-compliant devices)
Microsoft Intune (included with Business Premium) lets you require devices accessing your data to be encrypted, have a screen lock, run an up-to-date OS and have your security software installed. Combined with Conditional Access, you can simply block non-compliant devices.
11. Require sensitivity labels for confidential content
Microsoft Purview Information Protection lets you label documents as “Internal,” “Confidential,” “Highly Confidential,” etc. Labels can enforce encryption, prevent forwarding, and (critically) tell Microsoft Copilot what content not to summarise into open chats.
12. Set up immutable backups for Microsoft 365 data
Important: Microsoft does not back up your Microsoft 365 data in the way you might assume. Their retention policies cover their disasters; they don’t cover yours. If a team member (or attacker) deletes a SharePoint site or empties a mailbox, after 90 days it’s gone. Use a third-party immutable backup tool (Datto, Veeam, Barracuda) that can restore mailboxes, OneDrive, SharePoint and Teams data even after Microsoft’s retention has expired.
Frequently asked questions
Which Microsoft 365 plan do I need for all this?
Microsoft 365 Business Premium gives you all of these. Business Standard does not include Defender for Office 365, Conditional Access, Intune or sensitivity labels. The price difference (about £6/person/month) is almost always worth it.
How long does it take to configure all 12?
For a small tenant (under 25 staff), about 90 minutes if you know what you’re doing. Allow a half-day for testing the Conditional Access rollout (always test on a pilot team member before applying tenant-wide).
Do these settings break anything?
Conditional Access can lock people out if applied without a “break-glass” admin account excluded. Always create a break-glass admin (with a long random password stored offline) before enforcing Conditional Access. The other settings are non-breaking but the email-related ones (DMARC) need to be staged carefully.
What about Copilot?
If you use Microsoft Copilot, items 7, 11 and 12 become twice as important, Copilot honours your sharing permissions, sensitivity labels and DLP policies. Misconfigure any of those and Copilot will surface confidential content to the wrong people.
Will my insurer accept “we’ve configured all 12”?
Most UK cyber insurers will, especially if backed up by Cyber Essentials certification (which these settings satisfy). Some specialist insurers want additional controls; we can scope based on your specific renewal questionnaire.
We deploy and manage Microsoft 365 environments for businesses across Lichfield, Staffordshire and the wider West Midlands. The 12 settings above are the baseline we apply to every new client tenant.
