A practical Microsoft 365 security baseline for business
Microsoft 365 often becomes the centre of business operations before the organization starts treating it as part of the security perimeter.
Employees store email, files, Teams conversations, SharePoint documents, contacts and calendars there. Microsoft 365 identities may also provide access to third-party applications, devices and confidential information.
A compromised password is therefore no longer only an email problem. It can become access to a large part of the business.
A useful baseline does not mean enabling every available control. It means reducing the most likely risks without making daily work needlessly difficult.
01Protect every account with strong authentication
Multifactor authentication reduces the usefulness of a stolen password, but only when coverage is real.
Verify:
- users are enrolled;
- administrators use strong methods;
- legacy authentication cannot bypass protection;
- associated phones and devices are current;
- exceptions are documented and temporary;
- service accounts are handled deliberately rather than simply excluded.
The goal is not only to see “MFA enabled” in a report. Confirm that real sign-ins follow the intended policy.
02Reduce the number of administrator accounts
Administrative privilege should be granted according to the task, not seniority or convenience.
An organization should know:
- who has an administrator role;
- why that person needs it;
- whether a separate account is used for administration;
- when roles were last reviewed;
- how emergency access is preserved;
- which outside providers still have rights.
The account used every day for email does not necessarily need to be the account used to change tenant security.
03Preserve an emergency-access path
An overly aggressive access policy can lock the organization out of its own environment.
Properly protected emergency accounts help when a policy mistake, authentication outage or lost device prevents normal administrators from signing in.
They should be:
- very limited in number;
- protected by unique credentials;
- monitored;
- documented;
- tested in a controlled way;
- excluded only from policies that would make them unusable during an emergency.
An invisible emergency account that is never verified is not a plan.
04Deploy Conditional Access progressively
Conditional Access can apply rules based on the user, device, location, risk or application.
A poorly designed policy can also block employees, shared devices, older applications or administrators.
A cautious approach is to:
1. inventory users and applications; 2. identify real exceptions; 3. begin in report-only mode where available; 4. review results; 5. test with a small group; 6. expand gradually; 7. retain a rollback procedure.
The goal is to reduce risky sign-ins rather than create a permanent collection of exceptions.
05Know which devices reach business data
Microsoft 365 data is commonly accessed from:
- company computers;
- personal computers;
- phones;
- tablets;
- shared browsers;
- devices that no longer receive security updates.
The organization must decide what it accepts.
Depending on licensing and requirements, controls may include:
- device enrolment and inventory;
- encryption;
- screen locking;
- minimum operating-system versions;
- malware protection;
- compliance requirements;
- download or copy restrictions;
- selective removal of business data.
Every device does not need identical management, but the rules should not be accidental.
06Give higher-risk users additional protection
Some accounts warrant additional attention:
- executives;
- finance;
- human resources;
- administrators;
- reception or highly visible accounts;
- users with sensitive data;
- employees who approve payments.
They are common targets for phishing, business-email compromise and session theft.
Additional measures may include:
- more phishing-resistant authentication;
- separation of roles;
- stronger access policies;
- monitoring of mail forwarding;
- OAuth application controls;
- role-specific training;
- verification procedures for unusual financial requests.
07Review mailbox and forwarding rules
After compromising a mailbox, an attacker may create rules to hide replies, forward messages or monitor a financial conversation.
Monitor:
- unusual mailbox rules;
- external forwarding;
- unexpected delegation;
- newly authorized applications;
- sign-ins from unusual contexts;
- changes to MFA methods;
- mass sending or abnormal behaviour.
An alert without an owner and follow-through is not complete protection.
08Understand sharing in Teams, SharePoint and OneDrive
External sharing is useful, but becomes difficult to manage when it is based on links created case by case over several years.
A review should establish:
- which sites permit external sharing;
- whether anonymous links are necessary;
- how long links remain active;
- who may invite guests;
- which guests are still active;
- whether permissions come from understandable groups;
- how data is transferred when an employee leaves.
The objective is not to prohibit all outside collaboration. It is to know what is shared, with whom and for how long.
09Make onboarding and departures repeatable
An onboarding process should define:
- licence;
- groups;
- mailbox;
- Teams and SharePoint;
- devices;
- MFA;
- application access;
- basic training;
- approving manager.
A departure process should define:
- access-revocation time;
- session termination;
- device recovery;
- email retention or transfer;
- OneDrive transfer;
- group removal;
- third-party application handling;
- retention period;
- data owner.
A checkbox saying “account blocked” does not cover the complete process.
10Plan independent data recovery
Microsoft 365 retention and recovery mechanisms are useful, but may not replace an independent backup strategy designed around the organization’s actual requirements.
The review should determine:
- which workloads are protected;
- retention duration;
- ability to recover a specific item;
- ability to restore to an alternate location;
- handling of former employees;
- separation of administrative access;
- testing frequency.
Our backup and recovery service treats restoration as an outcome to verify rather than simply a feature to enable.
Signs that the tenant has become difficult to manage
A review is particularly useful when:
- several providers have modified the tenant;
- policy names no longer make sense;
- nobody understands the exceptions;
- administrators use everyday accounts;
- departures take several days;
- personal devices reach data without clear rules;
- licences have accumulated without review;
- alerts are received but rarely investigated;
- Microsoft 365 backup is unknown or untested;
- a migration, acquisition or business separation is planned.
A reasonable baseline must remain workable
Security that prevents employees from working will be bypassed. Security that is too permissive will not reduce enough risk.
A practical approach is to:
- begin with inventory;
- address the largest risks;
- test policies;
- document exceptions;
- measure impact;
- reduce unnecessary access gradually;
- assign an owner to alerts and corrections.
UNITECH can manage this baseline through Microsoft 365 and cybersecurity services or as part of a managed and co-managed IT relationship.
Begin with a focused review
An organization does not need to replace its entire environment to begin.
A first review can focus on administrators, MFA, access methods, devices, sharing and backup. The result should be a short list of corrections ordered by risk and effort.
Request a technical Microsoft 365 security assessment
Our Microsoft 365 security assessment — supporting Quebec Law 25 obligations turns these controls into prioritized findings. It is a technical configuration and security review, not legal advice, legal certification or a guarantee of compliance. Available controls depend on the organization’s licensing, configuration and operating processes.