Microsoft 365's defaults have improved substantially, but tenants provisioned years ago still carry configurations that a modern review would tighten. The following settings deliver most of the risk reduction available without buying additional licenses.
Identity
- MFA enforced for every account, including service and shared mailboxes wherever possible.
- Legacy authentication protocols blocked at the tenant level.
- Admin accounts separated from day-to-day mail-enabled accounts.
- Conditional access policies covering unmanaged devices and impossible-travel patterns.
Mail flow
- SPF, DKIM, and DMARC configured for every sending domain, with DMARC at least in monitoring mode.
- Anti-phishing policies enabled with impersonation protection for executives and finance.
- Safe Links and Safe Attachments active for the licenses that include them.
- External-sender warnings enabled in Outlook.
Sharing and collaboration
- Default OneDrive/SharePoint sharing scoped to 'specific people' or 'people in your organization'.
- Guest access reviewed and expired on a schedule.
- External sharing links set to expire by default.
Audit and logging
- Unified audit log enabled and mailbox auditing turned on.
- Alert policies for risky sign-ins, mailbox rule creation, and mass downloads.
- Log retention aligned with insurance and regulatory requirements.
Do this in order
Identity first, then mail flow, then sharing, then logging. Each layer depends on the ones before it.