The short answer
For most small and mid-sized organizations, a Microsoft 365 security baseline covers six areas:
- Identity: multi-factor authentication (MFA) for every user, legacy authentication blocked.
- Administrator access: separate admin accounts, few Global Administrators, two emergency access accounts.
- Email: Microsoft's preset protection policies, plus sender authentication for your domain.
- Devices: managed, encrypted and protected endpoints.
- Data and backup: sensible sharing settings and a backup that can restore after deletion or ransomware.
- Monitoring: someone reviewing sign-in risk, alerts and configuration drift.
Which tools you can use depends on your licenses. Check your current plan before designing the rollout.
1. Identity: MFA and blocking legacy sign-in
Microsoft offers two ways to enforce MFA:
- Security defaults are free and switched on or off as a whole. They require all users to register for MFA, require MFA for administrators, prompt users for MFA when needed, block legacy authentication protocols, block device code flow and protect access to Azure management tools (Microsoft Learn).
- Conditional Access requires at least Microsoft Entra ID P1 and lets you build policies based on user, device, location, application and risk. Microsoft notes that organizations with P1 or P2 licenses are probably better served by Conditional Access than by security defaults, and that security defaults must be turned off when Conditional Access policies replace them.
Legacy authentication matters because it does not support MFA, so an attacker using an older protocol such as IMAP or POP3 can bypass your MFA policy. Before blocking it, check for printers, scanners and line-of-business applications that still send mail or sign in the old way.
A typical Conditional Access starting set:
- Require MFA for all users.
- Require phishing-resistant MFA (such as passkeys or security keys) for administrators.
- Block legacy authentication.
- Require compliant or managed devices for access to sensitive data.
- Restrict sign-ins from countries where you have no staff, if that fits your business.
2. Administrator access
Microsoft's guidance for Entra roles is specific (Microsoft Learn):
- Apply least privilege: use roles such as User Administrator or Exchange Administrator instead of Global Administrator for everyday work.
- Assign the Global Administrator role to fewer than five people.
- Require MFA for all administrator accounts.
- Use Privileged Identity Management for just-in-time elevation where licensed (it requires Entra ID P2 or Entra ID Governance).
- Run recurring access reviews to remove roles people no longer need.
- Use cloud-only accounts for administrative roles, not accounts synchronized from on-premises Active Directory.
Microsoft also recommends two or more emergency access ("break glass") accounts: cloud-only accounts on the onmicrosoft.com domain, protected with a phishing-resistant method such as a FIDO2 passkey that is different from your normal admin method, excluded from Conditional Access policies that could block them, monitored with alerts on every sign-in, and tested at least every 90 days (Microsoft Learn).
Give administrators a separate account for admin work so their everyday mailbox and browsing are not privileged.
3. Email protection
Email is the most common route for phishing and malware. Microsoft's preset security policies (Standard and Strict) apply Microsoft's recommended settings for anti-spam, anti-malware and anti-phishing, and, where you have Defender for Office 365, Safe Links and Safe Attachments (Microsoft Learn). Using a preset keeps settings aligned as Microsoft updates its recommendations, instead of relying on custom policies nobody reviews.
Also:
- Publish SPF, DKIM and DMARC records for every domain that sends mail, and move DMARC towards enforcement once reports show legitimate mail passes.
- Tag external email so staff can see when a message comes from outside.
- Block automatic forwarding to external addresses unless there is an approved business reason.
- Give users a simple way to report suspicious messages.
4. Devices
- Enroll devices in Intune (or an equivalent tool) and set compliance policies: supported operating system, encryption, screen lock, security software running.
- Deploy endpoint protection with EDR, such as Defender for Business or Defender for Endpoint, depending on license. See EDR vs antivirus.
- Patch automatically for Windows, macOS, Office apps and browsers.
- For personal phones, use app protection policies to keep work data inside managed apps without taking over the whole device.
5. Data sharing and backup
- Review SharePoint and OneDrive external sharing settings. Limit "anyone" links, set link expiry and restrict sharing on sensitive sites.
- Use sensitivity labels and data loss prevention where licensed and where you have clear rules to enforce.
- Understand that retention is not backup. Retention policies preserve content for compliance; they are not designed to roll a whole mailbox or site back to a point in time after ransomware or mass deletion.
Microsoft now offers Microsoft 365 Backup, a pay-as-you-go service that backs up SharePoint sites, OneDrive accounts and Exchange mailboxes, with restore points and configurable recovery windows (Microsoft Learn). Third-party backup products that store copies outside Microsoft's service are another option. Whichever you choose, test restores. See why a backup is not the same as a recovery plan.
6. Monitoring and review
- Review Microsoft Secure Score recommendations regularly and record decisions on those you do not adopt.
- Turn on and retain audit logging.
- Alert on risky sign-ins, new mailbox forwarding rules, new admin role assignments and emergency account use.
- Assign an owner to review alerts, including after hours if you need that coverage.
- Re-check the baseline after license changes, mergers and major Microsoft feature changes.
Baseline checklist
Identity
- MFA enforced for all users (security defaults or Conditional Access)
- Legacy authentication blocked; exceptions identified and fixed
- Phishing-resistant MFA for administrators
Administration
- Fewer than five Global Administrators
- Separate, cloud-only admin accounts
- Two emergency access accounts, monitored and tested at least every 90 days
- Access reviews scheduled
- Standard or Strict preset security policy applied
- SPF, DKIM and DMARC published for every sending domain
- External auto-forwarding blocked or controlled
Devices
- Devices enrolled with compliance policies
- Endpoint protection with EDR deployed
- Automatic patching in place
Data
- External sharing settings reviewed
- Backup covering Exchange, OneDrive and SharePoint, with a tested restore
Monitoring
- Secure Score reviewed on a schedule
- Alerts assigned to a named owner
Limitations
Microsoft changes features, names and license contents often; confirm details against current Microsoft documentation before making changes, and test in a pilot group first. A baseline is a starting point, not a full security program: it does not replace training, incident response planning or backups outside Microsoft 365. If you would like the baseline assessed or implemented, see our Microsoft 365 and modern workplace service.
Sources and further reading
Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.
- Security defaults in Microsoft Entra ID, Microsoft Learn
- Best practices for Microsoft Entra roles, Microsoft Learn
- Manage emergency access admin accounts, Microsoft Learn
- Preset security policies, Microsoft Learn
- Overview of Microsoft 365 Backup, Microsoft Learn
This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.