Why This Matters
80% of data breaches involve stolen or weak passwords. Microsoft 365 has powerful security tools built in — most companies just never turn them on. Here are 10 things you can do this week, ranked by impact.
The Checklist
- Enable MFA for all users — Multi-Factor Authentication blocks 99.9% of automated attacks. Go to Entra ID → Security → MFA. This is the single most impactful thing you can do.
- Disable legacy authentication — Older protocols (POP3, IMAP, SMTP) bypass MFA. Block them via Conditional Access policy.
- Set up Conditional Access — Require MFA from untrusted locations, block sign-ins from high-risk countries, require compliant devices for admin access.
- Enable Security Defaults — If you don't have Azure AD P1 licenses, Security Defaults gives you baseline MFA and blocks legacy auth for free.
- Review admin accounts — Do you really need 8 Global Admins? Reduce to 2-3. Create separate admin accounts (not the same as daily-use accounts).
- Turn on audit logging — Go to Microsoft Purview → Audit. Enable unified audit log so you can investigate incidents. Logs are retained for 90 days on standard plans.
- Create a DLP policy for sensitive data — Prevent accidental sharing of credit card numbers, Aadhaar numbers, or PAN details via email or Teams. Microsoft Purview DLP has built-in templates for Indian regulations.
- Enable Safe Attachments & Safe Links — Microsoft Defender for Office 365 scans email attachments in a sandbox and checks URLs in real-time. Worth every rupee.
- Set up alerts for suspicious activity — Go to Microsoft Defender → Alert policies. Enable alerts for: impossible travel, mass file downloads, forwarding rules created, and privilege escalation.
- Run Microsoft Secure Score — Go to security.microsoft.com → Secure Score. It gives you a percentage score and ranks recommendations by impact. Aim for 70%+ within 30 days.
Start Here: If you do only ONE thing from this list, enable MFA. It takes 15 minutes and prevents the vast majority of account compromise attacks. Everything else is a bonus. Need help implementing these? Our free M365 Health Check includes a security assessment.