5 Microsoft 365 Security Settings Most Companies Forget to Turn On

When most businesses move to Microsoft 365, they assume the security part is already handled.
After all, it’s Microsoft, so everything must be protected, right?

Not exactly.

Microsoft 365 gives you the tools to protect your environment, but many of the most important security settings are not automatically enabled. They are available, but you have to turn them on, configure them properly, and keep them updated over time.

At Sirius, we have helped countless companies lock down their 365 environments. And almost every time, we find the same security gaps: settings left off, policies half-configured, or protections not fully enforced.

Let’s walk through the top five (plus two bonus) settings most companies forget to enable, and how fixing them can make your Microsoft 365 environment significantly more secure.

1. Multi-Factor Authentication (MFA) for All Accounts

We still see it too often: MFA turned on for only a few users, usually the executives, while everyone else logs in with only a password.

That’s like locking the front door of your office but leaving the side door wide open.

Why it matters:
Passwords get stolen. Every week, attackers target Microsoft 365 accounts with phishing emails, password sprays, and brute-force attacks. MFA adds a critical second layer of protection. Even if someone has your password, they cannot log in without that extra code or app approval.

What to do:

  • Enforce MFA for all users, not just admins.
  • Use Microsoft Authenticator or other approved apps (avoid SMS if possible).
  • Require MFA for privileged roles, external sharing, and new device logins.

Pro tip: In Microsoft 365, MFA can be enforced through Security Defaults or customized Conditional Access policies. The second option gives you more control, especially if your team includes contractors or shared mailboxes.

2. Conditional Access Policies

This is one of the most powerful and underused tools in Microsoft 365 security.

Conditional Access lets you define rules for when and how users can sign in. You can block risky logins automatically based on factors such as location, device type, or user role.

Why it matters:
Attackers often target logins from unusual locations or unknown devices. With Conditional Access, you can automatically block or require MFA for those sessions before they ever reach your data.

Examples:

  • Only allow admin access from company-owned devices.
  • Block sign-ins from outside your region.
  • Require MFA if logging in from a new browser or country.

Think of Conditional Access as your digital security guard. It checks every login at the door and decides who gets in and under what conditions.

3. Mailbox Auditing and Alert Policies

Email is still the number one attack vector for most businesses.
Yet many companies don’t realize that 365’s mailbox auditing is not always fully enabled by default.

Why it matters:
If an attacker compromises a mailbox and starts deleting messages or setting up forwarding rules, you need logs to trace what happened. Without auditing, there is no trail, which makes cleanup and incident response much harder.

What to do:

  • Turn on mailbox auditing for all users, not just admins.
  • Create alert policies in the Microsoft 365 Security Center to notify you of suspicious actions such as mass deletions, login attempts from multiple locations, or forwarding rules to external accounts.

Sirius tip: We have seen small anomalies like one mailbox forwarding to Gmail turn out to be major breaches. Regular auditing catches those before they escalate.

4. Safe Links and Safe Attachments in Defender for Office 365

If you use Microsoft 365 Business Premium or E5 licenses, you already have Defender for Office 365, Microsoft’s built-in email threat protection. But many organizations never finish setting it up.

Why it matters:
Attackers constantly send phishing emails that look real, using the same logos, tone, and urgency. Safe Links and Safe Attachments analyze and rewrite URLs and attachments in real time. If a link is malicious or an attachment is infected, it’s blocked before it reaches your inbox.

What to do:

  • Enable Safe Links for both email and Microsoft Teams messages.
  • Turn on Safe Attachments with dynamic delivery so emails are not delayed.
  • Regularly review quarantined items in the Security & Compliance Center or work with an IT team experienced in email threat protection to make sure nothing slips through.

Pro tip: Pair this with a phishing simulation or employee awareness training so users learn what not to click in the first place.

5. Admin Role Separation and Privileged Access Management

In small teams, it is common to have one or two people with “Global Admin” access. It is also one of the biggest security risks in Microsoft 365.

Why it matters:
If a global admin account is compromised, the attacker has full control: user creation, data export, payment details, and more.

What to do:

  • Limit Global Admin to only those who absolutely need it.
  • Use Role-Based Access Control (RBAC) to delegate smaller roles like Exchange, SharePoint, or Teams admin.
  • Turn on Privileged Access Management (PAM) to require approval before sensitive actions.

We have seen businesses lose entire environments because one over-privileged account got phished. Separating roles is simple but critical.

6. Data Loss Prevention (DLP) and Sensitivity Labels

This is the setting that protects you from your own people, not in a malicious sense, but from accidental data leaks.

Why it matters:
Employees often share the wrong file, forward client data to the wrong recipient, or store sensitive information in unsecured folders. DLP and sensitivity labels can automatically prevent that.

What to do:

  • Turn on Data Loss Prevention policies to detect when sensitive information (such as SSNs, credit cards, or client data) leaves your environment.
  • Use Sensitivity Labels to mark documents and emails with classifications like “Confidential,” “Internal,” or “Public.”
  • Restrict sharing or downloading based on label type.

Sirius example: We once saw a client unknowingly share payroll files via a Teams channel with external guests. DLP alerts caught it within minutes and prevented a compliance issue.

7. Security Reports and Continuous Monitoring

You cannot protect what you don’t see.
Even with all the right configurations, Microsoft 365 security requires regular review and monitoring.

Why it matters:
Threat actors adapt quickly. A security report from six months ago is not a guarantee of safety today. Continuous monitoring ensures your environment stays aligned with new threats, policies, and user behaviors.

What to do:

  • Regularly review reports in the Microsoft 365 Security & Compliance Center.
  • Check the Secure Score dashboard for a live snapshot of your environment’s overall protection level.
  • Enable alerts for suspicious sign-ins, privilege escalations, and DLP triggers.
  • Audit shared files and external access monthly.

At Sirius, we include continuous monitoring in every managed IT plan. Security is not “set it and forget it.” It’s a living process.

Bonus: Review Your Security Defaults

If you are not ready to dive deep into Conditional Access or Defender settings, start with Microsoft’s Security Defaults.

They are a baseline set of protections that enforce MFA, block legacy protocols, and require modern authentication.
While not as flexible as customized policies, they are a huge upgrade from doing nothing.

How Sirius Helps Lock It Down

At Sirius, our job is to make sure your Microsoft 365 setup is not just working but secure.
When we onboard a new client, one of the first things we do is a Microsoft 365 Security Review.

We check:

  • Who has admin privileges
  • Whether MFA is properly enforced
  • If Defender features are configured
  • How conditional access and audit policies are set
  • If DLP and sensitivity labels are deployed correctly
  • And what’s missing from your compliance setup

Then we document everything, remediate the gaps, and monitor changes going forward.

For many businesses, that review is the first time they see how exposed their cloud environment really was. And the peace of mind once it’s fixed is worth it.

Key Takeaway

Microsoft 365 gives you enterprise-level security tools. But tools don’t protect you. Configuration does.

If you are not sure which of these settings are turned on in your tenant, that is your next action step.
Spend 30 minutes with your IT provider (or with us), review your configuration, and close those gaps before someone else finds them.

FAQs

Q: Do I need to pay extra for these security settings?
Most of them, including MFA, Security Defaults, and audit logging, are included in standard Microsoft 365 Business Premium plans. Defender for Office 365 and Conditional Access come with higher tiers (Premium P1/P2), but can be added affordably.

Q: How often should I review these settings?
At least twice a year, or whenever you add new staff, licenses, or integrations. Threats evolve quickly, and your configurations should too.

Q: My IT provider said we’re “covered.” How do I verify that?
Ask for a configuration report showing which settings are enabled. If they cannot provide one, it’s time for a second opinion.

Ready to Secure Your Microsoft 365 Environment?

Let’s make sure your setup is truly protected, not just assumed to be.
Sirius can perform a quick Microsoft 365 security audit and help implement every protection we discussed here.

Schedule a quick call to get started.

Got value from this post? Share the insight:

Table of Contents

Send Us A Message

Related articles

Let's Chat

Book a Free 15-Minute
IT Consultation

Not sure where to start with IT? In just 15 minutes, we’ll review your setup, answer your questions, and point you in the right direction. No pressure, no sales pitch.

Why Book With Us?
What Happens After You Book?
1

We schedule a quick call that fits your calendar

2

We talk through your top IT challenges

3

You get expert guidance and make sure we’re a good fit

Talk to an IT Consultant

Sirius Office Systems is a company that goes out of its way to provide excellent customer service! I was hoping my organization would be happy brining on Sirius (since I had recommended their proposal). We were not only pleased with them but were blown away at their commitment to excellence. I can sincerely and confidently recommend Sirius.

Tamara A