When most businesses move to Microsoft 365, they assume the security part is already handled.
After all, it’s Microsoft, so everything must be protected, right?
Not exactly.
Microsoft 365 gives you the tools to protect your environment, but many of the most important security settings are not automatically enabled. They are available, but you have to turn them on, configure them properly, and keep them updated over time.
At Sirius, we have helped countless companies lock down their 365 environments. And almost every time, we find the same security gaps: settings left off, policies half-configured, or protections not fully enforced.
Let’s walk through the top five (plus two bonus) settings most companies forget to enable, and how fixing them can make your Microsoft 365 environment significantly more secure.
1. Multi-Factor Authentication (MFA) for All Accounts
We still see it too often: MFA turned on for only a few users, usually the executives, while everyone else logs in with only a password.
That’s like locking the front door of your office but leaving the side door wide open.
Why it matters:
Passwords get stolen. Every week, attackers target Microsoft 365 accounts with phishing emails, password sprays, and brute-force attacks. MFA adds a critical second layer of protection. Even if someone has your password, they cannot log in without that extra code or app approval.
What to do:
- Enforce MFA for all users, not just admins.
- Use Microsoft Authenticator or other approved apps (avoid SMS if possible).
- Require MFA for privileged roles, external sharing, and new device logins.
Pro tip: In Microsoft 365, MFA can be enforced through Security Defaults or customized Conditional Access policies. The second option gives you more control, especially if your team includes contractors or shared mailboxes.
2. Conditional Access Policies
This is one of the most powerful and underused tools in Microsoft 365 security.
Conditional Access lets you define rules for when and how users can sign in. You can block risky logins automatically based on factors such as location, device type, or user role.
Why it matters:
Attackers often target logins from unusual locations or unknown devices. With Conditional Access, you can automatically block or require MFA for those sessions before they ever reach your data.
Examples:
- Only allow admin access from company-owned devices.
- Block sign-ins from outside your region.
- Require MFA if logging in from a new browser or country.
Think of Conditional Access as your digital security guard. It checks every login at the door and decides who gets in and under what conditions.
3. Mailbox Auditing and Alert Policies
Email is still the number one attack vector for most businesses.
Yet many companies don’t realize that 365’s mailbox auditing is not always fully enabled by default.
Why it matters:
If an attacker compromises a mailbox and starts deleting messages or setting up forwarding rules, you need logs to trace what happened. Without auditing, there is no trail, which makes cleanup and incident response much harder.
What to do:
- Turn on mailbox auditing for all users, not just admins.
- Create alert policies in the Microsoft 365 Security Center to notify you of suspicious actions such as mass deletions, login attempts from multiple locations, or forwarding rules to external accounts.
Sirius tip: We have seen small anomalies like one mailbox forwarding to Gmail turn out to be major breaches. Regular auditing catches those before they escalate.
4. Safe Links and Safe Attachments in Defender for Office 365
If you use Microsoft 365 Business Premium or E5 licenses, you already have Defender for Office 365, Microsoft’s built-in email threat protection. But many organizations never finish setting it up.
Why it matters:
Attackers constantly send phishing emails that look real, using the same logos, tone, and urgency. Safe Links and Safe Attachments analyze and rewrite URLs and attachments in real time. If a link is malicious or an attachment is infected, it’s blocked before it reaches your inbox.
What to do:
- Enable Safe Links for both email and Microsoft Teams messages.
- Turn on Safe Attachments with dynamic delivery so emails are not delayed.
- Regularly review quarantined items in the Security & Compliance Center or work with an IT team experienced in email threat protection to make sure nothing slips through.
Pro tip: Pair this with a phishing simulation or employee awareness training so users learn what not to click in the first place.
5. Admin Role Separation and Privileged Access Management
In small teams, it is common to have one or two people with “Global Admin” access. It is also one of the biggest security risks in Microsoft 365.
Why it matters:
If a global admin account is compromised, the attacker has full control: user creation, data export, payment details, and more.
What to do:
- Limit Global Admin to only those who absolutely need it.
- Use Role-Based Access Control (RBAC) to delegate smaller roles like Exchange, SharePoint, or Teams admin.
- Turn on Privileged Access Management (PAM) to require approval before sensitive actions.
We have seen businesses lose entire environments because one over-privileged account got phished. Separating roles is simple but critical.
6. Data Loss Prevention (DLP) and Sensitivity Labels
This is the setting that protects you from your own people, not in a malicious sense, but from accidental data leaks.
Why it matters:
Employees often share the wrong file, forward client data to the wrong recipient, or store sensitive information in unsecured folders. DLP and sensitivity labels can automatically prevent that.
What to do:
- Turn on Data Loss Prevention policies to detect when sensitive information (such as SSNs, credit cards, or client data) leaves your environment.
- Use Sensitivity Labels to mark documents and emails with classifications like “Confidential,” “Internal,” or “Public.”
- Restrict sharing or downloading based on label type.
Sirius example: We once saw a client unknowingly share payroll files via a Teams channel with external guests. DLP alerts caught it within minutes and prevented a compliance issue.
7. Security Reports and Continuous Monitoring
You cannot protect what you don’t see.
Even with all the right configurations, Microsoft 365 security requires regular review and monitoring.
Why it matters:
Threat actors adapt quickly. A security report from six months ago is not a guarantee of safety today. Continuous monitoring ensures your environment stays aligned with new threats, policies, and user behaviors.
What to do:
- Regularly review reports in the Microsoft 365 Security & Compliance Center.
- Check the Secure Score dashboard for a live snapshot of your environment’s overall protection level.
- Enable alerts for suspicious sign-ins, privilege escalations, and DLP triggers.
- Audit shared files and external access monthly.
At Sirius, we include continuous monitoring in every managed IT plan. Security is not “set it and forget it.” It’s a living process.
Bonus: Review Your Security Defaults
If you are not ready to dive deep into Conditional Access or Defender settings, start with Microsoft’s Security Defaults.
They are a baseline set of protections that enforce MFA, block legacy protocols, and require modern authentication.
While not as flexible as customized policies, they are a huge upgrade from doing nothing.
How Sirius Helps Lock It Down
At Sirius, our job is to make sure your Microsoft 365 setup is not just working but secure.
When we onboard a new client, one of the first things we do is a Microsoft 365 Security Review.
We check:
- Who has admin privileges
- Whether MFA is properly enforced
- If Defender features are configured
- How conditional access and audit policies are set
- If DLP and sensitivity labels are deployed correctly
- And what’s missing from your compliance setup
Then we document everything, remediate the gaps, and monitor changes going forward.
For many businesses, that review is the first time they see how exposed their cloud environment really was. And the peace of mind once it’s fixed is worth it.
Key Takeaway
Microsoft 365 gives you enterprise-level security tools. But tools don’t protect you. Configuration does.
If you are not sure which of these settings are turned on in your tenant, that is your next action step.
Spend 30 minutes with your IT provider (or with us), review your configuration, and close those gaps before someone else finds them.
FAQs
Q: Do I need to pay extra for these security settings?
Most of them, including MFA, Security Defaults, and audit logging, are included in standard Microsoft 365 Business Premium plans. Defender for Office 365 and Conditional Access come with higher tiers (Premium P1/P2), but can be added affordably.
Q: How often should I review these settings?
At least twice a year, or whenever you add new staff, licenses, or integrations. Threats evolve quickly, and your configurations should too.
Q: My IT provider said we’re “covered.” How do I verify that?
Ask for a configuration report showing which settings are enabled. If they cannot provide one, it’s time for a second opinion.
Ready to Secure Your Microsoft 365 Environment?
Let’s make sure your setup is truly protected, not just assumed to be.
Sirius can perform a quick Microsoft 365 security audit and help implement every protection we discussed here.
Schedule a quick call to get started.

