Skip to content
Trivane TECH

A practical security baseline for Microsoft 365 and Entra ID

For most businesses, Microsoft 365 holds the keys to everything: email, files, Teams, and often the sign-in for other applications. That makes the accounts in your tenant the most valuable target for attackers, and the most common way in is not a sophisticated hack. It is a stolen or guessed password on an account without multi-factor authentication.

This guide covers a practical baseline that protects most tenants. It uses Microsoft's current names: Microsoft Entra ID is the identity service formerly called Azure Active Directory.

1. Turn on multi-factor authentication for everyone

Multi-factor authentication (MFA) is the single most effective control you can add. Microsoft has also been making it mandatory for administrative access: since October 2024 it has been required for signing in to the Azure portal, Microsoft Entra admin center and Intune admin center, with enforcement for the Microsoft 365 admin center beginning in February 2025.

There are two main ways to require MFA for all users:

  • Security defaults. A free, preconfigured set of protections that requires everyone to register for MFA, protects admin accounts and blocks older sign-in methods that cannot do MFA. If you do not have Entra ID P1 licences, turn this on.
  • Conditional Access. Available with Entra ID P1 or higher (included in Microsoft 365 Business Premium and many enterprise plans). It lets you write precise rules, such as requiring MFA for all users, stricter checks for admins, and blocking sign-ins from countries you never operate in.

Use one or the other, not neither. Where possible, encourage the Microsoft Authenticator app or passkeys rather than text-message codes.

2. Protect admin accounts

  • Keep admin roles to a minimum. Most people should have no admin rights at all. Give admins only the specific role they need (for example Exchange or user administrator) rather than Global Administrator.
  • Use separate admin accounts. Admins should use an everyday account for email and browsing, and a separate account for admin work.
  • Require strong MFA for admins, ideally phishing-resistant methods such as passkeys or security keys.
  • Have two emergency ("break-glass") accounts, with very strong credentials stored securely, excluded only from rules that could lock everyone out, and monitored for any use.

3. Block legacy authentication

Older protocols such as basic authentication for some mail clients cannot use MFA, which makes them a favourite route for password-spraying attacks. Security defaults block them; with Conditional Access, create a rule to block legacy authentication for everyone.

4. Get the user lifecycle right

Most real-world exposure comes from accounts that should not exist:

  • Onboarding: create users from a template with the right licences, groups and access, nothing more.
  • Offboarding: disable sign-in and sign out of all sessions on the last day, reset the password, convert or delegate the mailbox if needed, transfer file ownership and remove licences.
  • Regular review: check for accounts of people who have left, shared accounts nobody owns, and guests who no longer need access.

5. Secure email

  • Make sure SPF, DKIM and DMARC are set up for your domain so others cannot easily send email pretending to be you.
  • Review the anti-phishing and anti-malware policies in Microsoft Defender for Office 365 (or the built-in protection, depending on your plan).
  • Warn users about external senders and train them to report suspicious messages.
  • Turn off automatic forwarding of email to external addresses unless there is a business reason, as attackers often use it to quietly copy a mailbox.

6. Control sharing in SharePoint and OneDrive

Decide how files can be shared outside the company. A sensible default is to allow sharing with specific people who must sign in, and to limit or disable "anyone with the link" sharing. Set expiry on external links where your plan allows.

7. Manage devices

If staff use company laptops, enrol them in Intune (or your device management tool) so you can require disk encryption, updates, a screen lock and endpoint protection, and wipe a lost device. For personal phones, app protection policies can protect company data in Outlook and Teams without managing the whole device.

8. Watch what is happening

  • Check Microsoft Secure Score in the Defender portal for a prioritised list of recommendations specific to your tenant.
  • Make sure audit logging is on, and review sign-in logs for unusual activity, especially for admin accounts.
  • Set up alerts for risky events such as new inbox forwarding rules or admin role changes.

A short checklist

  • MFA required for all users (security defaults or Conditional Access)
  • Admin roles minimised and separate admin accounts in use
  • Two monitored break-glass accounts
  • Legacy authentication blocked
  • Offboarding checklist used for every leaver
  • SPF, DKIM and DMARC configured
  • External sharing defaults reviewed
  • Devices managed and encrypted
  • Secure Score reviewed regularly

Where to start

If you are not sure whether MFA is enforced for every account, start there today. If you would like a review of your Microsoft 365 setup, help moving from security defaults to Conditional Access, or ongoing administration, book a free consultation.

Want help with your cloud or IT?

Book a free 30-minute consultation.

Book a free consultation