Microsoft 365 includes strong security features, but many SMEs only use part of what they already pay for. The risk is not the platform itself; it is weak configuration, unmanaged access and assumptions about recovery.
1. Administrator accounts
Privileged accounts should be limited, protected with MFA and used only where needed. Shared admin accounts and old supplier access create unnecessary risk.
2. MFA and conditional access
MFA should be enforced consistently. Conditional access can add sensible rules around location, device state and risky sign-ins where licensing and business needs allow.
3. Email protection
Review SPF, DKIM, DMARC, impersonation protection, malware filtering and how suspicious messages are reported by staff.
4. Teams, SharePoint and OneDrive sharing
External sharing should be deliberate. Review who can create links, what data can leave the organisation and whether sensitive areas need tighter controls.
5. Recovery and retention
Microsoft 365 retention and recycle bins are not a full backup strategy. Decide what needs independent recovery and how quickly it must be restored.
Start with the Microsoft 365 security review, the Cyber Essentials readiness page, or the IT Risk Scorecard.
