
Microsoft 365 Security
Buying Business Premium is not the same as being secure. Almost everything in it is off, or on a permissive default, until somebody configures it.
Identity, devices, data and administration — the baseline that holds, applied deliberately rather than left at whatever Microsoft ships.
Start with two things. Enforce multi-factor authentication for every user and block legacy authentication, which otherwise provides a route straight around it. Those two are available on every Microsoft 365 plan, cost nothing extra, and close the great majority of the exposure we find. Everything else — device management, endpoint protection, data loss prevention — matters, and matters less than those two.
What Microsoft 365 security actually covers
Each area notes which plan provides it, because “we should do that” and “we are licensed for that” are different conversations. Plan contents checked 21 September 2026.
Identity
Multi-factor authentication enforced for everyone, legacy authentication blocked, admin accounts separated from everyday accounts, and conditional access rules where the plan supports them. Identity is where almost every real compromise starts.
Basic and Standard include Entra ID free; Premium adds policy-based access
Devices
Company laptops and phones enrolled in Intune with compliance policies, encryption enforced, and the ability to wipe a device that is lost or belongs to someone who has left.
Intune Plan 1 with Business Premium
Endpoints
Defender for Business protecting against ransomware and malware on the devices themselves, rather than relying only on what the mail filter caught.
Included in Business Premium; ₹250 standalone
Data
Purview Information Protection and data loss prevention — labelling sensitive material and stopping it leaving by email or upload, deliberately rather than by hoping.
Purview Information Protection Plan 1 with Business Premium
Administration
Role separation so day-to-day admins cannot do everything, break-glass accounts documented, and a record of who changed what. The controls that matter when something has already gone wrong.
Available on all plans; it is configuration, not licensing
Audit and review
Audit logging on, sign-in logs reviewed, and a periodic check that the configuration still matches how the business actually operates. Security posture drifts, quietly.
Purview Audit Standard on all Business plans

Eight things that should be true of any tenant
Almost all of this is available on every plan. It is configuration rather than spend, which is what makes it frustrating to find missing.
- check_circle
Multi-factor authentication enforced for every user, including — especially — the directors
- check_circle
Legacy authentication protocols blocked, because they bypass MFA entirely
- check_circle
Admin roles separated from daily-use accounts, with a documented break-glass account
- check_circle
Conditional access rules for risky sign-ins, where the plan supports them
- check_circle
External sharing set deliberately rather than left at the default
- check_circle
A documented offboarding process that actually revokes access on the day
- check_circle
Audit logging enabled and sign-in logs reviewed periodically
- check_circle
SPF, DKIM and DMARC published on the domain
The findings that recur
None of these are sophisticated attacks. They are configuration gaps, and every one of them is fixable in an afternoon once somebody has looked.
| Finding | How often | Why it matters |
|---|---|---|
| MFA not enforced for all users | Very common | The single largest exposure. Usually left optional to avoid complaints, then never revisited. |
| Departed staff still holding active accounts | Very common | Access continues and the licence keeps billing. Both problems, one cause. |
| Legacy authentication still permitted | Common | Provides a route around MFA, which makes the MFA you did enable considerably less useful. |
| External sharing wide open | Common | Files shareable with anyone, links that never expire, and no record of what went where. |
| Global admin rights used day to day | Common | One phished session compromises the whole tenant rather than one mailbox. |
| No DMARC record published | Very common | Anyone can send mail appearing to come from your domain, to your customers. |
| Defender licensed but unconfigured | Common | Paying for protection that is not switched on, often alongside a third-party product bought to fill the gap. |
What people assume, and what is actually true
"It is in the cloud, so Microsoft secures it."
Microsoft secures the platform. Your configuration, your identities and your data are yours. The shared responsibility model is genuinely shared, and the half that gets organisations into trouble is the half they own.
"Microsoft 365 backs up our data."
It does not, in the sense you mean. Retention policies, versioning and the recycle bin are not a backup you control. A deletion or corruption found four months later is generally gone. Third-party backup is a separate product and a separate cost.
"We bought Business Premium, so we are secure."
Premium gives you the tools. Almost everything in it is off, or on a permissive default, until someone configures it. The most common finding in our reviews is a fully licensed tenant with almost none of it switched on.
"We are too small to be a target."
Credential attacks and invoice fraud are automated and indiscriminate — nobody picked you. Smaller organisations are targeted more successfully precisely because MFA is off and nobody reviews sign-in logs.
Microsoft 365 security — common questions
helpWhat is a Microsoft 365 security baseline?
expand_more
The set of controls that should be on before anything else is considered: multi-factor authentication for everyone, legacy authentication blocked, admin roles separated from daily accounts, external sharing set deliberately, audit logging on, a documented offboarding process, and SPF, DKIM and DMARC on your domain. None of it is exotic and most of it is available on every plan. It is configuration, not spend.
helpDoes Business Premium make us secure?
expand_more
It gives you the tools — Intune, Defender for Business, Entra ID P1, Purview Information Protection Plan 1. Nearly all of it needs configuring before it does anything, and the defaults are permissive. The most common finding in our reviews is an organisation paying for Premium with almost none of it enabled, which is the worst of both outcomes: the cost without the protection.
helpDo we really need multi-factor authentication for everyone?
expand_more
Yes, and the exceptions people ask for are usually the accounts that matter most. A director's mailbox is the one worth compromising, because it is the one whose instructions get followed. MFA is inconvenient for about a week; a compromised mailbox running invoice fraud against your customers is inconvenient for considerably longer.
helpIs Microsoft 365 backed up?
expand_more
Not in the way most people mean. Microsoft protects its own infrastructure and provides retention, versioning and a recycle bin. That is not a backup you control, and it will not help with a deletion or corruption discovered months later. If the business could not tolerate losing a year-old file, you need third-party backup as a separate product and line item.
helpWhat does a security review involve?
expand_more
We look at the tenant as configured: MFA coverage, whether legacy authentication is blocked, admin role assignment, external sharing settings, device compliance, leaver accounts still active, audit logging, and your domain's authentication records. You get a written finding list ordered by risk with what it would take to fix each one — yours to act on with us or anyone else.
helpWill tightening security make things harder for staff?
expand_more
A little, briefly, and most of that is the first week of MFA. Controls that genuinely obstruct people get worked around or switched off, so the aim is a baseline that holds rather than the strictest possible configuration. Where a control would cause real friction we will say so and discuss the trade-off rather than applying it and leaving you to discover why everyone is annoyed.
helpHow is this different from your email security page?
expand_more
This page covers identity, devices, data and administration — who can sign in, from what, and what they can do once inside. Email security covers what arrives in inboxes and who can pretend to be you. Both matter. If you are choosing where to start, MFA and DMARC are the two highest-value things on either page.
helpDo you provide ongoing security management?
expand_more
Yes. A baseline applied once drifts as people join, leave and ask for exceptions. Ongoing work covers periodic review of MFA coverage and admin rights, leaver offboarding, sign-in log review, and keeping configuration aligned with how the business has changed. It is quoted separately from a one-off review.
Related pages
Microsoft 365 Email Security
Phishing, impersonation and domain authentication — the mail half.
Microsoft 365 Implementation
Where the security baseline is applied in the first place.
Microsoft 365 Licensing Explained
Which security capabilities your plan already includes.
Microsoft 365 Consulting
Tenant assessment and governance, if the question is broader.
Microsoft 365 Pricing in India
What Business Premium and the security add-ons cost in INR.
Microsoft 365 Services
Licensing, implementation, migration, security and support.
Google Workspace Security
The equivalent controls on the Google side.
Book a security review
A written finding list ordered by risk, yours to act on.
Book a Microsoft 365 security review
We look at the tenant as it is actually configured and give you a written finding list ordered by risk, with what each fix involves. Yours to act on with us or with anyone.
- check_circle
MFA coverage, legacy authentication and admin role assignment
- check_circle
Leaver accounts, external sharing and device compliance
- check_circle
A finding list ordered by risk, not by what we would like to sell
For finance teams whose records live in Excel, the gap between a password and real protection is set out on our page for Microsoft 365 partner in Thrissur.
If you think you have a live compromise, call rather than emailing: +91 99467 89916. Otherwise admin@techgeum.com.