Microsoft 365 accounts are one of the most common targets for attackers. A compromised account can give someone access to email, OneDrive files, SharePoint data, Teams messages, contacts, invoices and sensitive business conversations.
The damage is not always obvious straight away. An attacker may read emails silently, create forwarding rules, impersonate the user, send phishing messages to customers or wait for the right payment conversation before intervening.
This guide explains practical steps businesses can take to secure a Microsoft 365 account before it is compromised.
Start with multi-factor authentication
Multi-factor authentication, often shortened to MFA, is one of the most important protections for Microsoft 365 accounts. It requires a second verification method when a user signs in, rather than relying on a password alone.
Microsoft explains that MFA improves account security and can be set up using security defaults, Conditional Access policies, or legacy per-user MFA. Microsoft also notes that security defaults are available in all Microsoft 365 organisations through Microsoft Entra ID Free, while Conditional Access requires Microsoft Entra ID P1 or P2 licensing. Microsoft’s MFA guidance explains the available setup options.
For most businesses, every user should have MFA enabled. Administrator accounts should be treated with even more care, because they can change settings, create users, reset passwords and access sensitive areas of Microsoft 365.
Use security defaults or Conditional Access
Security defaults are a useful starting point for smaller businesses that do not have complex security requirements. They help strengthen the tenant with preconfigured protections, including MFA requirements and legacy authentication protection. Microsoft describes security defaults as a way to strengthen an organisation’s security posture.
For businesses with Microsoft Entra ID P1 or P2 licensing, Conditional Access gives more control. It can be used to create policies based on user, location, device, risk level and application.
Conditional Access can help with policies such as:
- Require MFA for all users
- Require MFA for administrator accounts
- Block legacy authentication
- Restrict access from risky locations
- Require compliant or managed devices
- Apply stronger controls to high-risk sign-ins
Microsoft also provides guidance for requiring MFA for all users and for administrator accounts using Conditional Access. Microsoft’s Conditional Access guidance covers MFA for all users.
Protect administrator accounts first
Administrator accounts need stronger protection than standard user accounts. If an attacker compromises an admin account, the impact can be much wider than a single mailbox.
Businesses should check:
- Who has Global Administrator rights
- Whether admin accounts are used for day-to-day email
- Whether admin accounts have MFA enabled
- Whether old supplier or leaver admin accounts still exist
- Whether separate named admin accounts are needed
- Whether emergency access accounts are documented and protected
As a rule, admin rights should be limited to the people who genuinely need them. Day-to-day users should not have elevated permissions unless there is a clear reason.
Check for risky sign-ins and unusual access
Microsoft 365 account compromise is often visible in the sign-in history before anyone reports a problem. Suspicious sign-ins, unfamiliar countries, repeated failures, impossible travel events or unusual devices can all indicate that an account needs attention.
Businesses should regularly check for:
- Sign-ins from unexpected countries or regions
- Repeated failed sign-in attempts
- Unusual browser or device activity
- Sign-ins outside normal working patterns
- Risky users or risky sign-ins, where licensing supports this
For managed clients, this is one of the reasons KES includes identity and sign-in monitoring as part of a wider Microsoft 365 security approach.
Review mailbox forwarding rules
One of the most common signs of Microsoft 365 email compromise is an unexpected forwarding rule. Attackers may create rules that send a copy of incoming email to an external address, hide certain messages, delete warnings or move emails into unusual folders.
Check for:
- External forwarding rules
- Inbox rules that delete or move emails
- Rules containing words such as invoice, payment, statement or password
- Forwarding to unknown Gmail, Outlook or other external accounts
- Delegates or mailbox permissions that are no longer required
This is especially important for accounts used by finance, directors, sales teams and anyone involved in supplier payments.
Strengthen email phishing protection
Many Microsoft 365 compromises start with phishing. A user receives a convincing email, clicks a fake Microsoft login page and enters their password. MFA helps, but phishing protection and user awareness are still important.
Microsoft Defender for Office 365 includes protections such as Safe Links and Safe Attachments. Safe Links helps protect against phishing and other attacks that use malicious URLs, while Safe Attachments provides an additional layer of protection by checking attachments in a virtual environment before delivery. Microsoft explains Safe Links protection here, and Microsoft explains Safe Attachments here.
Businesses should also make sure users know how to spot suspicious emails and report them quickly.
Use Microsoft Secure Score as a guide
Microsoft Secure Score can help businesses understand the current security posture of their Microsoft 365 environment. Microsoft describes Secure Score as a central dashboard in the Defender portal that helps organisations monitor and improve the security of Microsoft 365 identities, apps and devices. Microsoft’s Secure Score documentation explains how it works.
Secure Score should not be treated as a perfect measurement, but it is a useful starting point. It can highlight missing controls, weak settings and recommended actions.
Areas to review include:
- Identity and sign-in controls
- Admin account protection
- Email security settings
- SharePoint and OneDrive sharing settings
- Device security
- Data protection recommendations
Remove or secure old accounts
Old accounts create unnecessary risk. If a user has left the business but the account remains active, it may still be used to access email, files or Teams data.
Businesses should have a clear leaver process that covers:
- Blocking sign-in
- Resetting the password
- Removing or reassigning licences
- Preserving mailbox data where needed
- Transferring OneDrive files where appropriate
- Removing admin roles
- Removing old MFA methods
- Checking mailbox forwarding and delegation
This is a simple area where many businesses can reduce risk quickly.
Make sure Microsoft 365 data is backed up
Securing an account is not only about stopping attackers from getting in. It is also about reducing the damage if something goes wrong.
If an account is compromised, data may be deleted, altered, moved or encrypted through synchronised files. Microsoft 365 includes useful recovery and retention features, but businesses should still make a deliberate decision about backup.
We explain this in more detail in our guide: Why Microsoft 365 Still Needs Backup and Monitoring.
Use the right Microsoft 365 licence
The licence a user has affects what security and management features are available. For example, Microsoft 365 Business Premium includes stronger security and management capabilities than Business Basic or Business Standard.
Business Premium can be especially useful for businesses that need better identity controls, device management and security features.
You can read more in our guide: Microsoft 365 Business Basic vs Standard vs Premium.
KES also has a dedicated page explaining Microsoft 365 Business Premium for business users.
Practical Microsoft 365 account security checklist
As a starting point, check the following:
- All users have MFA enabled
- Administrator accounts have stronger protection
- Legacy authentication is blocked
- Security defaults or Conditional Access policies are in place
- Old users and leaver accounts are disabled or removed
- Mailbox forwarding rules are reviewed
- External sharing is checked
- Users know how to report phishing emails
- Microsoft Secure Score is reviewed
- Microsoft 365 data is backed up
- Sign-ins and account activity are monitored
Need help securing Microsoft 365?
KES helps businesses secure and manage Microsoft 365. We can review users, licences, admin accounts, MFA, Conditional Access, mailbox rules, backup, monitoring and common Microsoft 365 security risks.
For businesses that want Microsoft 365, security and support handled together, our Business User Pack provides a more complete managed service wrapper.
Want KES to check your Microsoft 365 accounts?
KES can review your Microsoft 365 users, sign-in security, MFA, mailbox rules, backup and monitoring to help identify risks before they become problems.
Sources
- Microsoft Learn: Set up multifactor authentication for Microsoft 365
- Microsoft Learn: Configure security defaults for Microsoft Entra ID
- Microsoft Learn: Require MFA for all users with Conditional Access
- Microsoft Learn: Safe Links in Microsoft Defender for Office 365
- Microsoft Learn: Safe Attachments in Microsoft Defender for Office 365
- Microsoft Learn: Microsoft Secure Score