Microsoft 365 Security

How to Harden Your Microsoft 365 Tenant: Complete Guide

Microsoft 365 is not secure by default. Default settings prioritise ease of access over security — allowing legacy authentication, permitting any device to access email, and leaving many security features disabled. Hardening your M365 tenant means changing these defaults to close the gaps attackers routinely exploit.

Overview

Microsoft 365 default settings prioritise ease of access over security. Hardening your M365 tenant means configuring Conditional Access, blocking legacy authentication, deploying Defender for Business correctly, applying anti-phishing policies, and securing admin accounts with PIM. Microsoft Secure Score tracks progress against recommended settings.

Learn about M365 security

Why is Microsoft 365 not secure by default?

Microsoft 365 ships for ease of deployment and broad compatibility, so the out-of-the-box settings favour access over security. Legacy authentication is enabled, any device with valid credentials can reach email, the most powerful admin roles are permanently assigned, and audit logging often is not retained long enough for a forensic investigation.

That default posture matters because 43% of UK businesses experienced a cybersecurity breach or attack in 2025 (gov.uk Cyber Security Breaches Survey 2025). The most common Microsoft 365 attacks — password spray, legacy-protocol credential stuffing, OAuth app abuse — all exploit these defaults. Hardening, guided by AMVIA's Microsoft 365 security audit, turns those defaults off.

How do you harden identity with Conditional Access?

Identity is the highest-priority hardening domain because 85% of businesses that suffered a breach identified phishing as the attack vector (gov.uk Cyber Security Breaches Survey 2025), and most Microsoft 365 compromises start with a stolen credential. Conditional Access is the policy engine in Microsoft Entra ID that decides who gets in, from which device, under what conditions.

AMVIA deploys a baseline policy set for every managed client:

  • Require MFA for all users across all applications
  • Block legacy authentication protocols entirely
  • Require device compliance for SharePoint, Exchange Online and Teams
  • Apply phishing-resistant MFA to admin accounts

Security Defaults vs Conditional Access

Lower licence tiers include Security Defaults — pre-configured policies that enforce MFA and block legacy authentication. Full Conditional Access, available with Business Premium, adds the granular control most businesses need. See Microsoft's Conditional Access documentation for the policy detail.

CapabilitySecurity DefaultsConditional Access
Enforce MFAYesYes
Block legacy authYesYes
Device compliance rulesNoYes
Location / risk-based accessNoYes
Per-app and per-group controlNoYes
LicenceBasic / StandardBusiness Premium

How do you protect admin accounts with PIM?

Permanent Global Administrator access means a single compromised admin hands an attacker the whole tenant. Privileged Identity Management (PIM) replaces standing access with just-in-time elevation: an admin requests a role, gives a justification, sets a duration, and the role expires automatically — every activation logged.

Standing admin rights are dangerous because only 14% of UK businesses held a formal incident response plan (DSIT Cyber Security Breaches Survey 2024), leaving most unable to contain a takeover quickly. AMVIA configures PIM for all admin accounts as standard, so day-to-day work runs on least privilege and elevation is the exception, not the rule.

How should MFA be enforced across the tenant?

MFA is the single highest-impact control: Microsoft reports MFA blocks over 99% of account compromise attacks (Microsoft Security). The detail that matters is *how* it is enforced. Legacy per-user MFA can be bypassed through old protocols; enforcing MFA through Conditional Access and a proper MFA setup makes it consistent across every access point.

  • Microsoft Authenticator with number matching — the baseline for business users, resistant to MFA-fatigue attacks
  • FIDO2 hardware keys or Windows Hello for Business — phishing-resistant MFA for admin accounts
  • No exceptions — every application, every user, enforced at policy level

How do you harden email security in Exchange Online?

Exchange Online Protection filters mail, but default policies are not tuned for targeted threats. Hardening means enabling impersonation protection for commonly-spoofed executives, switching on Safe Links and Safe Attachments, and authenticating your own domain so attackers cannot spoof it against your clients.

  • Anti-phishing policy with impersonation protection for key people and domains
  • Safe Links and Safe Attachments (Defender for Office 365, Business Premium) enabled, not left at defaults
  • DKIM signing enabled; DMARC published and advanced to `p=reject`; SPF reviewed
  • Outbound spam policies to catch a compromised account before takeover completes

How do you harden endpoints with Defender for Business?

Microsoft Defender for Business, included in Business Premium, provides endpoint detection and response — but its default configuration leaves much switched off. Hardening means turning protections on deliberately, because licensing Defender does not activate them.

  • Attack surface reduction (ASR) rules moved from audit-only to enforcement
  • Controlled folder access to blunt ransomware
  • Network protection to block known-malicious domains and IPs
  • Web content filtering for high-risk categories

How do you control data sharing and audit logging?

SharePoint external sharing defaults are usually too permissive, allowing anyone-with-the-link access. AMVIA restricts sharing to authenticated users, reviews Teams guest access, and layers Microsoft Purview Data Loss Prevention (DLP) over email, Teams, SharePoint and OneDrive. For UK businesses handling personal data, DLP is a technical control that supports UK GDPR obligations (ICO).

Audit logging is essential for investigating an incident. AMVIA enables Microsoft 365 audit logs with appropriate retention and monitors security-relevant events — unusual sign-ins, admin actions, external sharing, and mailbox forwarding-rule creation — through its in-house 24/7 SOC.

How do you track hardening progress with Secure Score?

Microsoft Secure Score measures your configuration against Microsoft's recommendations in real time and lists improvement actions by impact, making prioritisation straightforward. The reported industry average sits around 50% (2025 benchmarks). AMVIA captures a baseline before hardening and tracks the score at quarterly reviews, following NCSC guidance alongside Microsoft's recommendations.

M365 hardening checklist

  • Conditional Access — MFA required for all users, legacy authentication blocked
  • Admin accounts protected with PIM — just-in-time elevation, no permanent Global Admin
  • Anti-phishing policy — impersonation protection for key executives and domains
  • Safe Links and Safe Attachments enabled with appropriate policies
  • DKIM and DMARC configured, DMARC in enforcement
  • SharePoint external sharing restricted — no anonymous links without justification
  • Defender for Business — ASR rules enforced, not audit-only
  • Audit logging enabled with appropriate retention

Key Points

What M365 hardening covers for UK businesses.

Default Settings Create Risk

Legacy authentication is enabled by default. Basic MFA can be bypassed. Admin accounts have permanent elevated permissions. All of these are commonly exploited.

Hardening Is Configuration, Not Cost

Most M365 hardening changes require no additional licensing — just deliberate configuration of settings already available in your existing licence.

Secure Score Measures Progress

Microsoft Secure Score provides a numerical score and an ordered list of improvement actions — making it easy to prioritise and track hardening progress.

Supports

Correctly hardened M365 configuration satisfies several security controls — access control, secure settings, malware protection — making security certification more straightforward.

M365 Hardening Checklist

Conditional Access — MFA required for all users, legacy authentication blocked

Admin accounts protected with PIM — just-in-time elevation, no permanent Global Admin

Anti-phishing policy — impersonation protection for key executives and domains

Safe Links and Safe Attachments enabled with appropriate policies

DKIM and DMARC configured and DMARC in enforcement mode

SharePoint external sharing restricted — no anonymous link sharing without business justification

Defender for Business — ASR rules enabled, not in audit-only mode

Audit logging enabled with appropriate retention period

Frequently Asked Questions

Harden Your Microsoft 365 Tenant

AMVIA reviews your M365 configuration, implements Microsoft's recommended security baseline, and maintains your tenant against new recommendations on an ongoing basis.