Security
Microsoft 365 hardening: the seven settings most tenants get wrong
The factory defaults in Microsoft 365 are designed to make adoption easy, not to make tenants secure.
- Disable legacy auth. POP, IMAP, and SMTP basic auth are still on in tenants we audit.
- Enforce MFA via conditional access. Per-user MFA is too easy to bypass.
- Block downloads from unmanaged devices. SharePoint and OneDrive can require browser-only access from devices that are not enrolled.
- Configure anti-phishing impersonation protection. Add the executive team to the impersonated-users list.
- Lock down external sharing. By default, anyone in your tenant can share anything.
- Audit log retention. Crank it up. The default is shorter than most incident investigations need.
- Self-service password reset with strong verification. Convenient and secure if configured.