Reviewing security configuration
Microsoft 365 Partner · CSP Reseller

Microsoft 365 Security

Buying Business Premium is not the same as being secure. Almost everything in it is off, or on a permissive default, until somebody configures it.

Identity, devices, data and administration — the baseline that holds, applied deliberately rather than left at whatever Microsoft ships.

Start with two things. Enforce multi-factor authentication for every user and block legacy authentication, which otherwise provides a route straight around it. Those two are available on every Microsoft 365 plan, cost nothing extra, and close the great majority of the exposure we find. Everything else — device management, endpoint protection, data loss prevention — matters, and matters less than those two.

Six areas

What Microsoft 365 security actually covers

Each area notes which plan provides it, because “we should do that” and “we are licensed for that” are different conversations. Plan contents checked 21 September 2026.

badge

Identity

Multi-factor authentication enforced for everyone, legacy authentication blocked, admin accounts separated from everyday accounts, and conditional access rules where the plan supports them. Identity is where almost every real compromise starts.

Basic and Standard include Entra ID free; Premium adds policy-based access

devices

Devices

Company laptops and phones enrolled in Intune with compliance policies, encryption enforced, and the ability to wipe a device that is lost or belongs to someone who has left.

Intune Plan 1 with Business Premium

shield

Endpoints

Defender for Business protecting against ransomware and malware on the devices themselves, rather than relying only on what the mail filter caught.

Included in Business Premium; ₹250 standalone

lock

Data

Purview Information Protection and data loss prevention — labelling sensitive material and stopping it leaving by email or upload, deliberately rather than by hoping.

Purview Information Protection Plan 1 with Business Premium

admin_panel_settings

Administration

Role separation so day-to-day admins cannot do everything, break-glass accounts documented, and a record of who changed what. The controls that matter when something has already gone wrong.

Available on all plans; it is configuration, not licensing

fact_check

Audit and review

Audit logging on, sign-in logs reviewed, and a periodic check that the configuration still matches how the business actually operates. Security posture drifts, quietly.

Purview Audit Standard on all Business plans

Team reviewing security settings together
The non-negotiables

Eight things that should be true of any tenant

Almost all of this is available on every plan. It is configuration rather than spend, which is what makes it frustrating to find missing.

  • check_circle

    Multi-factor authentication enforced for every user, including — especially — the directors

  • check_circle

    Legacy authentication protocols blocked, because they bypass MFA entirely

  • check_circle

    Admin roles separated from daily-use accounts, with a documented break-glass account

  • check_circle

    Conditional access rules for risky sign-ins, where the plan supports them

  • check_circle

    External sharing set deliberately rather than left at the default

  • check_circle

    A documented offboarding process that actually revokes access on the day

  • check_circle

    Audit logging enabled and sign-in logs reviewed periodically

  • check_circle

    SPF, DKIM and DMARC published on the domain

What reviews turn up

The findings that recur

None of these are sophisticated attacks. They are configuration gaps, and every one of them is fixable in an afternoon once somebody has looked.

FindingHow oftenWhy it matters
MFA not enforced for all usersVery commonThe single largest exposure. Usually left optional to avoid complaints, then never revisited.
Departed staff still holding active accountsVery commonAccess continues and the licence keeps billing. Both problems, one cause.
Legacy authentication still permittedCommonProvides a route around MFA, which makes the MFA you did enable considerably less useful.
External sharing wide openCommonFiles shareable with anyone, links that never expire, and no record of what went where.
Global admin rights used day to dayCommonOne phished session compromises the whole tenant rather than one mailbox.
No DMARC record publishedVery commonAnyone can send mail appearing to come from your domain, to your customers.
Defender licensed but unconfiguredCommonPaying for protection that is not switched on, often alongside a third-party product bought to fill the gap.
Four beliefs worth correcting

What people assume, and what is actually true

cloud_off

"It is in the cloud, so Microsoft secures it."

Microsoft secures the platform. Your configuration, your identities and your data are yours. The shared responsibility model is genuinely shared, and the half that gets organisations into trouble is the half they own.

backup

"Microsoft 365 backs up our data."

It does not, in the sense you mean. Retention policies, versioning and the recycle bin are not a backup you control. A deletion or corruption found four months later is generally gone. Third-party backup is a separate product and a separate cost.

verified

"We bought Business Premium, so we are secure."

Premium gives you the tools. Almost everything in it is off, or on a permissive default, until someone configures it. The most common finding in our reviews is a fully licensed tenant with almost none of it switched on.

person_off

"We are too small to be a target."

Credential attacks and invoice fraud are automated and indiscriminate — nobody picked you. Smaller organisations are targeted more successfully precisely because MFA is off and nobody reviews sign-in logs.

Microsoft 365 security — common questions

help

What is a Microsoft 365 security baseline?

expand_more

The set of controls that should be on before anything else is considered: multi-factor authentication for everyone, legacy authentication blocked, admin roles separated from daily accounts, external sharing set deliberately, audit logging on, a documented offboarding process, and SPF, DKIM and DMARC on your domain. None of it is exotic and most of it is available on every plan. It is configuration, not spend.

help

Does Business Premium make us secure?

expand_more

It gives you the tools — Intune, Defender for Business, Entra ID P1, Purview Information Protection Plan 1. Nearly all of it needs configuring before it does anything, and the defaults are permissive. The most common finding in our reviews is an organisation paying for Premium with almost none of it enabled, which is the worst of both outcomes: the cost without the protection.

help

Do we really need multi-factor authentication for everyone?

expand_more

Yes, and the exceptions people ask for are usually the accounts that matter most. A director's mailbox is the one worth compromising, because it is the one whose instructions get followed. MFA is inconvenient for about a week; a compromised mailbox running invoice fraud against your customers is inconvenient for considerably longer.

help

Is Microsoft 365 backed up?

expand_more

Not in the way most people mean. Microsoft protects its own infrastructure and provides retention, versioning and a recycle bin. That is not a backup you control, and it will not help with a deletion or corruption discovered months later. If the business could not tolerate losing a year-old file, you need third-party backup as a separate product and line item.

help

What does a security review involve?

expand_more

We look at the tenant as configured: MFA coverage, whether legacy authentication is blocked, admin role assignment, external sharing settings, device compliance, leaver accounts still active, audit logging, and your domain's authentication records. You get a written finding list ordered by risk with what it would take to fix each one — yours to act on with us or anyone else.

help

Will tightening security make things harder for staff?

expand_more

A little, briefly, and most of that is the first week of MFA. Controls that genuinely obstruct people get worked around or switched off, so the aim is a baseline that holds rather than the strictest possible configuration. Where a control would cause real friction we will say so and discuss the trade-off rather than applying it and leaving you to discover why everyone is annoyed.

help

How is this different from your email security page?

expand_more

This page covers identity, devices, data and administration — who can sign in, from what, and what they can do once inside. Email security covers what arrives in inboxes and who can pretend to be you. Both matter. If you are choosing where to start, MFA and DMARC are the two highest-value things on either page.

help

Do you provide ongoing security management?

expand_more

Yes. A baseline applied once drifts as people join, leave and ask for exceptions. Ongoing work covers periodic review of MFA coverage and admin rights, leaver offboarding, sign-in log review, and keeping configuration aligned with how the business has changed. It is quoted separately from a one-off review.

Book a Microsoft 365 security review

We look at the tenant as it is actually configured and give you a written finding list ordered by risk, with what each fix involves. Yours to act on with us or with anyone.

  • check_circle

    MFA coverage, legacy authentication and admin role assignment

  • check_circle

    Leaver accounts, external sharing and device compliance

  • check_circle

    A finding list ordered by risk, not by what we would like to sell

For finance teams whose records live in Excel, the gap between a password and real protection is set out on our page for Microsoft 365 partner in Thrissur.

If you think you have a live compromise, call rather than emailing: +91 99467 89916. Otherwise admin@techgeum.com.

call