KA
Cybersecurity

Microsoft 365 Security — 7 Settings Every Company Needs

Corporate email is the most common target. MFA, disabling legacy authentication, admin accounts, mail forwarding and backup — what to check.

Microsoft 365 — email, Teams, OneDrive, SharePoint — often holds all of a company’s important information. A single compromised account can lead to phishing aimed at your customers or a fake invoice. Here are the key settings every company should check.

1. MFA for every user

Turn on multi-factor authentication for every account, not just management. The Microsoft Authenticator app is better than SMS.

2. Disable legacy authentication

Legacy mail protocols bypass MFA. If you don’t need them, turn them off — otherwise MFA doesn’t fully protect you.

3. Separate admin accounts

  • Don’t use an admin account for daily work — use a separate, regular account for email and browsing;
  • Give admin rights to as few people as possible;
  • Protect admin accounts with the strongest MFA.

4. Conditional Access (if your license includes it)

If your license includes Conditional Access, you can restrict sign-ins by country, device or risk level. Start with simple rules and test them so employees aren’t locked out.

5. Control automatic mail forwarding

Attackers often create a hidden rule that forwards mail to an outside address. Block or control automatic forwarding to external addresses and get alerts about new rules.

6. Phishing protection

Enable the available protection against phishing, spam and malicious attachments, and tag messages from external senders. Back up the technical controls with employee awareness about phishing.

7. Backup — the cloud is not a backup

Microsoft is responsible for keeping the service running, but protecting your data is partly your responsibility (shared responsibility). A deleted file, a OneDrive encrypted by ransomware, a departed employee’s mailbox — for these cases you need a separate Microsoft 365 backup.

💡 Tip: When an employee leaves, don’t delete the account the same day — first block sign-in, preserve the mail and files, and only then deal with the license.

Quick checklist

  • MFA on every account;
  • Legacy authentication disabled;
  • Admin accounts separate and few;
  • External forwarding under control;
  • Microsoft 365 backup enabled and tested.

Contact us

Information

Leave us a message or contact us using the details below.

© 2026 ICOMP LLC. All rights reserved.