Skip to content
Article

Microsoft 365 Security Settings Every Business Should Review

A concise review of the most impactful Microsoft 365 settings for identity, mail flow, sharing, and audit logging.

North Shield EditorialJune 15, 2026 8 min read
Microsoft 365Cybersecurity

Microsoft 365's defaults have improved substantially, but tenants provisioned years ago still carry configurations that a modern review would tighten. The following settings deliver most of the risk reduction available without buying additional licenses.

Identity

  • MFA enforced for every account, including service and shared mailboxes wherever possible.
  • Legacy authentication protocols blocked at the tenant level.
  • Admin accounts separated from day-to-day mail-enabled accounts.
  • Conditional access policies covering unmanaged devices and impossible-travel patterns.

Mail flow

  • SPF, DKIM, and DMARC configured for every sending domain, with DMARC at least in monitoring mode.
  • Anti-phishing policies enabled with impersonation protection for executives and finance.
  • Safe Links and Safe Attachments active for the licenses that include them.
  • External-sender warnings enabled in Outlook.

Sharing and collaboration

  • Default OneDrive/SharePoint sharing scoped to 'specific people' or 'people in your organization'.
  • Guest access reviewed and expired on a schedule.
  • External sharing links set to expire by default.

Audit and logging

  • Unified audit log enabled and mailbox auditing turned on.
  • Alert policies for risky sign-ins, mailbox rule creation, and mass downloads.
  • Log retention aligned with insurance and regulatory requirements.

Do this in order

Identity first, then mail flow, then sharing, then logging. Each layer depends on the ones before it.

Related resources

Checklist
7 min readMay 11, 2026
Read
Guide
18 min readJun 1, 2026
Read
Security Advisory
5 min readJun 22, 2026
Read

Related services

Microsoft 365

Design, harden, and operate the Microsoft 365 platform your business runs on.

Cybersecurity

Managed detection & response, EDR, SIEM, and continuous compliance monitoring.

Stay informed about important IT and security developments.

Receive practical technology guidance, educational security updates and new North Shield resources by email.

Frontend preview — subscription delivery is not yet connected.

By subscribing you agree to receive occasional updates from North Shield. See our privacy notice (placeholder). You can unsubscribe at any time.

Need help applying this?

Turn guidance into a concrete plan.

North Shield can help assess your environment, identify gaps, and build a practical roadmap.