Microsoft 365 Business Premium Security Settings You Should Enable

by Tomasz Szulczewski | Aug 13, 2026 | Cybersecurity | 0 comments

in roughly 90 percent of the Microsoft 365 tenants I audit, the same five settings are switched off or misconfigured.

Not exotic ones. Not settings that need a consultant and a six-week project. These are Microsoft 365 Business Premium security settings that ship with the license you are already paying for, that take between two and fifteen minutes each, and that nobody switched on because nobody knew where to look.

Most of them work on Business Basic and Standard too - I will flag the two that genuinely need Premium. You can work through the complete list in an afternoon.

Microsoft 365 Business Premium Security Settings You Should Enable
Microsoft 365 Business Premium Security Settings You Should Enable

The five Microsoft 365 Business Premium security settings, in order

Two of these - Conditional Access in settings 1 and 2 - require Business Premium or higher. If you are on Basic or Standard, Security Defaults covers both, and I explain how below. Everything else on this list works on any licence.

1. Enforce MFA for every user

Time to implement: 10 minutes

A password alone stops almost nothing. Credentials leak from services you forgot you registered with, and attackers replay them automatically against every major platform. Multi-factor authentication is the single control that breaks that chain.

You have two ways to do it.

Security Defaults (Entra ID → Properties) is the blunt instrument. One toggle, MFA enforced for everyone, legacy authentication blocked as a side effect. If you have no dedicated admin, turn this on and move on with your life. It is not sophisticated and it is dramatically better than nothing.

Conditional Access (Entra ID → Security → Conditional Access) is the right answer if you are on Business Premium. It lets you require MFA based on circumstances - unmanaged device, unfamiliar location, risky sign-in - rather than blanket-prompting everyone all day. Personally, I think that Conditional Access is the key solution to keep the tenant secure, not another vendor or another procedure that  no-one follows.

The trap most people hit: service accounts and your break-glass admin account. Before you flip anything, create one emergency access account excluded from your policies with a long, stored password. Otherwise the day a policy misfires, you lock yourself out of your own tenant.

2. Block legacy authentication protocols

Time to implement: 15 minutes, after you check the logs

Legacy authentication means the old ways of connecting to mail - IMAP, POP3, Basic Auth, old Outlook clients.

Here is why it matters: MFA does not apply to them. An attacker with a valid username and password can connect over legacy auth and walk straight past the second factor you just spent an afternoon deploying. It is the most common way MFA deployments get quietly defeated.

Before you block it, check who is still using it. Go to Entra ID → Sign-in logs, filter on client app, and look for legacy clients. You are usually looking at one ancient multifunction printer, a scanner that emails PDFs, or a line-of-business app somebody configured in 2016.

Then block it with a Conditional Access policy targeting legacy authentication clients. Handle the printer separately with an app password or a modern connector.

3. Disable automatic external mail forwarding

Time to implement: 5 minutes

This is the one that actually costs companies money.

The scenario runs like this. An attacker gets into a mailbox - usually through a phishing page, usually with no MFA in the way. They send nothing, delete nothing, do not do a single thing you would notice. They set a quiet forwarding rule: everything arriving here also goes to my address.

Then they wait. For weeks. Reading which invoices arrive, from which suppliers, in what amounts, in what tone.

When the timing is right, they send one message from a lookalike domain with changed bank details, at the exact moment a real payment is expected. That is Business Email Compromise, and it is the single most expensive email attack for small and mid-sized companies.

Go to the Exchange admin centre → anti-spam → outbound spam policy and set automatic external forwarding to Off. Then check whether anyone already has it configured - review existing transport rules and mailbox forwarding. If you find external forwarding nobody can explain, that is an incident, not a configuration quirk.

4. Turn on audit logging

Time to implement: 2 minutes

Microsoft 365 can record who signed in, who opened which file, who changed which setting, who created which rule. For that to exist, audit logging has to be enabled.

In older tenants it frequently is not.

Check the status in Microsoft Purview. If it is off, turn it on, and understand what you have been living without: when something goes wrong, you have no timeline, no evidence, and no way to answer the only question that matters - what did they actually access?

Retention depends on your licensing. Business Premium gives you considerably less than E5. Know your number before you need it, not during an incident.

Two minutes of work for the difference between "we know exactly what happened" and "we have no idea".

5. Read your Secure Score and fix the top three items

Time to implement: 15 minutes to review

Open the Microsoft Defender portal and look at Secure Score. It is a number from 0 to 100 describing how well your tenant's security is configured.

The point is not to chase 100. Hitting 100 usually requires licensing you do not have and controls you do not need. The point is to know where you stand and what matters most.

Sort the recommendations by impact and pick the top three. Microsoft tells you which changes give the biggest security gain for the least effort, which is exactly the list a small company needs.

One caution: optimise for real protection, not for the score. There are recommendations that add points and little else, and there are unglamorous fixes that move your actual risk considerably.

Microsoft 365 Business Premium security settings and what each one costs you

If you only have an hour this week, work in this sequence.

Start with the audit log. Two minutes, no user impact, no risk of breaking anything, and it is the setting whose absence you only discover when you desperately need it. Turn it on before anything else so that the changes you make next are themselves recorded.

Then mail forwarding. Five minutes, and it closes the most financially damaging attack path on this list. The only thing to check first is whether any legitimate business process depends on external forwarding - occasionally a shared mailbox or an old workflow does. Deal with those individually rather than leaving the door open for everyone.

Then MFA. Ten minutes to configure, and this is the one that generates user reaction. Announce it before you enable it, create the break-glass account first, and expect a week of support questions. Every organisation that has done it says the same thing afterwards: it was less painful than expected.

Then legacy authentication. Fifteen minutes, and the only step that genuinely requires homework. Check the sign-in logs before you block anything, because this is where you break the scanner that emails PDFs to the accounts team. Find those devices first, then block.

Then Secure Score. Fifteen minutes of reading, and however long the top three fixes take. This is the one you repeat monthly rather than complete once. Fixing Secure score is my most common project on Upwork.

Total: under an hour of configuration, spread across a week so you can watch for side effects.

Who should actually do this

If you have an internal IT person, hand them this list and ask for a status on each item. The conversation takes ten minutes and tells you a lot about how your environment has been managed.

If you do not have internal IT and your provider handles Microsoft 365 for you, these five items are a fair thing to ask about. Any competent provider will already have done most of them, and if they have not, that is worth knowing.

And if you are the owner doing this yourself at eleven at night, work down the list in the order above and stop after each one. There is no prize for finishing tonight, and there is an actual cost to locking yourself out of your own tenant at midnight.

What this looks like when it goes wrong

I had a client with 40 employees. Ordinary company, nothing that would appear on anyone's target list.

The audit showed that for three months, every email arriving for the CEO had been automatically forwarded to an external address. Three months of contracts, negotiations, supplier terms and payment details, quietly copied to someone else.

Nobody noticed. Nothing broke. Nothing looked unusual.

That was setting number 3. Five minutes of work, never done.

Bottom line

Microsoft 365 security in a small company is not an IT project with a budget and a steering committee. It is five settings, most of which take under fifteen minutes, using licensing you already pay for.

Start with the audit log today and work down the list this week. If you have just taken over an environment and want the full picture before you change anything, use the Microsoft 365 tenant handover checklist first. And

📧 I write weekly about M365 security for SMBs - join the newsletter on LinkedIn → https://www.linkedin.com/in/tomasz-szulczewski/

Written by Tomasz Szulczewski

Hi, my name is Tomasz Szulczewski, and I have been in love with information technology for over 25 years, but I still have an IT passion and feel like a geek. I am a person who is problem solver who thinks that not all people must be experts in IT.

Related Posts

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *