Table of contents
- 01What Does Microsoft 365 Configuration Mean?
- 02Buying a Microsoft 365 Licence Is Only the Beginning
- 03Identity and Multi-Factor Authentication
- 04Email Security Configuration
- 05Device Management and Compliance
- 06Microsoft Defender Configuration
- 07SharePoint and OneDrive Permissions
- 08Teams and Guest Access
- 09Audit Logs, Alerts and Security Monitoring
- 10Employee Onboarding and Offboarding
- 11Microsoft 365 Backup and Data Recovery
- 12Common Microsoft 365 Configuration Mistakes
- 13Microsoft 365 Business Premium and Security
- 14Microsoft 365 Security Checklist
What Does Microsoft 365 Configuration Mean?
Microsoft 365 configuration is the set of choices that decide how the platform behaves for your users, devices and data. It covers who can sign in and from where, how email is filtered, which files can be shared externally, how administrator access is granted, which devices can access company data and how security events are recorded and reviewed. Configuration is separate from licensing. Two businesses on the same licence tier can have very different security postures depending on what has been turned on, tuned or left at default.
Buying a Microsoft 365 Licence Is Only the Beginning
A licence unlocks capabilities. It does not implement them. Business Basic and Business Standard include email, Teams, SharePoint, OneDrive and core protections. Business Premium adds identity protection, Intune device management and Microsoft Defender for Business. In every tier, the settings that convert these capabilities into working controls need to be configured, documented and reviewed. Doing nothing after purchase is a common and understandable choice, and also the source of most Microsoft 365 risk we see in Sydney SMEs.
Identity and Multi-Factor Authentication
Identity is the primary control plane. Most attacks in Microsoft 365 begin with a sign-in that should not have happened. Getting identity right addresses more risk than any other single area.
- MFA enabled and enforced for every user, including executives and shared accounts wherever possible.
- Security Defaults are a reasonable starting point for smaller tenants, but they do not replace Conditional Access.
- Conditional Access rules based on user, device state, location and risk level.
- Legacy authentication disabled to prevent bypass attempts.
- Administrator roles separated from day-to-day accounts, with just-in-time elevation where possible.
- Break-glass accounts documented, monitored and stored securely for emergency access.
Email Security Configuration
Email remains the most common initial attack vector for Sydney SMEs. Exchange Online Protection catches a large volume of noise, but the higher-value phishing and business email compromise attempts benefit from additional controls.
- Anti-phishing policies tuned for your organisation and executives.
- Safe Links to rewrite URLs and inspect them at click time.
- Safe Attachments to detonate suspicious attachments in a sandbox.
- Spam and outbound spam policies aligned with normal sending patterns.
- Impersonation protection for common executive and finance addresses.
- SPF, DKIM and DMARC published for every sending domain, with DMARC eventually moved to enforcement.
Device Management and Compliance
Devices that access business data need to meet a defined standard. Microsoft Intune, included in Business Premium, allows a business to enrol Windows, macOS, iOS and Android devices, apply security baselines, require disk encryption and separate work data from personal data on mobile devices. For businesses without Intune, App Protection Policies still provide meaningful control over Microsoft 365 mobile apps.
The most common issue we see is inconsistent enrolment. Half the laptops are managed, half are not, and no one is sure which is which. A short project to enrol every business device and set a baseline is one of the highest-value pieces of work in a typical Microsoft 365 environment.
Microsoft Defender Configuration
Microsoft Defender is a family of products, not a single toggle. Defender for Business is included in Business Premium and provides endpoint protection, attack surface reduction rules and basic threat investigation. Defender for Office 365 provides Safe Links, Safe Attachments and anti-phishing features on top of Exchange Online Protection. Not every capability is included in every licence, so it is important to verify what is available before assuming coverage.
Teams and Guest Access
Teams guest access lets external partners collaborate inside your tenant. That is useful and, uncontrolled, risky. Over time, guest accounts accumulate. They stay after projects finish. They receive access to channels and files that were meant to be temporary. A quarterly guest review and a clear naming convention for external-facing teams keeps this manageable.
Audit Logs, Alerts and Security Monitoring
Microsoft 365 records a large volume of security telemetry. The value only appears when someone reviews it. Common priorities are impossible-travel sign-ins, mailbox rules that forward externally, unusual privileged operations, mass file downloads and consent grants to third-party applications. Alerts should have a clear owner and a documented triage process. Without one, alerts become noise and important events are missed.
Employee Onboarding and Offboarding
The account lifecycle is where governance meets everyday operations. A tidy joiner and leaver process reduces both risk and licensing waste. Standardised group memberships, documented licence assignments, mailbox conversion on departure and prompt removal of MFA methods for former staff belong in a written procedure, not in someone's head.
Microsoft 365 Backup and Data Recovery
Microsoft is responsible for platform availability and service resilience. You are responsible for the data you create in that platform. Retention settings, recycle bins and preservation holds are useful, but they are not a substitute for an independent backup. If a mailbox is deleted, a SharePoint site is corrupted, or ransomware encrypts synced files, an independent backup is often the only reliable recovery option.
For the underlying model and testing approach, see Business continuity and the 3-2-1 backup model explained.
Common Microsoft 365 Configuration Mistakes
| Configuration issue | Business risk | Recommended action |
|---|---|---|
| MFA not enforced for every user | Stolen passwords lead to direct account takeover | Enable MFA for every user and disable legacy authentication |
| Global administrator used for daily work | A single phishing event compromises the whole tenant | Separate admin accounts from day-to-day accounts and apply just-in-time roles |
| External sharing left at default | Sensitive files reachable by anyone with a link | Reduce sharing scope and enforce link expiry |
| No independent backup of Microsoft 365 data | Limited recovery options after accidental or malicious deletion | Deploy an independent backup and test restores |
| Alerts arrive but no one reviews them | Real incidents are missed inside routine noise | Assign ownership and a triage schedule for alerts |
| Guest users accumulate over time | External access persists after projects end | Quarterly guest review and named team owners |
Microsoft 365 Security Checklist
Practical Microsoft 365 baseline
- MFA enforced for every user and legacy authentication disabled.
- Conditional Access rules aligned with normal work locations and devices.
- Administrator accounts separated from daily use and reviewed.
- Safe Links, Safe Attachments and anti-phishing policies enabled.
- SPF, DKIM and DMARC published for every sending domain.
- External sharing scoped and anonymous links restricted.
- Devices enrolled in Intune or covered by App Protection Policies.
- Independent backup for Microsoft 365 data and periodic restore tests.
- Alert triage assigned to a named owner with a documented process.
- Quarterly guest and administrator access review.
Talk to us
Not sure where your business stands?
Book a free 30-minute conversation with our team. We will listen, ask questions and point you at the practical next steps for your environment.
Frequently Asked Questions
Is Microsoft 365 secure by default?+
What is the difference between Microsoft 365 licensing and configuration?+
Does every Microsoft 365 user need MFA?+
What is Microsoft 365 Business Premium?+
Does Microsoft 365 need a separate backup?+
How often should Microsoft 365 security settings be reviewed?+
Official Resources and Further Reading
- Microsoft 365 Business Premium documentation - Microsoft Learn
- Zero Trust guidance - Microsoft Security
- Multi-factor authentication - Australian Cyber Security Centre
- Small business cyber security guide - Australian Cyber Security Centre




