Skip to content
Checklist·Microsoft 365 & cloud·3 min

Microsoft 365: the security settings to check in your company

Microsoft 365 is secure by design, not by default. Here are the settings that matter, and the backup question that many companies discover too late.

The essentials in 30 seconds

A Microsoft 365 subscription is not secure by default. Four settings cover most of the risk: multi-factor authentication on every account without exception, administrator accounts kept separate from work accounts, legacy authentication protocols disabled, and automatic mail forwarding rules monitored. Finally, Microsoft hosts your data but does not back it up for you.

Account hacking is the top threat reported by companies and associations to Cybermalveillance.gouv.fr (the French government's cyber assistance service). Business email is the most common way in, and Microsoft 365 is by far the most widely used email platform among French SMEs.

Microsoft provides a solid platform. It also provides a starting configuration designed so that everything works straight away, which is not the same thing as a secure configuration.

1. Multi-factor authentication, without exception

This is the measure that makes the biggest difference for the least effort. A stolen password is no longer enough to get in.

  • Enable it on every account, including those of senior management: they are the most targeted, never the least.
  • Do not leave any permanent exception. An exception made "for the duration of the migration" becomes a permanent one.
  • Prefer an authenticator app to SMS, which is more exposed to phone number hijacking.

2. Separate administrator accounts

An administrator who reads email with their privileged account exposes the entire tenant to a single malicious attachment.

  • A named work account for everyday use, and a separate administration account for administrative tasks.
  • The administration account receives no email and is not used for browsing.
  • Limit the number of global administrators: it is the most powerful role and the one least often needed.

3. Disable legacy authentication protocols

Some older protocols cannot handle multi-factor authentication. As long as they remain active, they offer a path that bypasses it entirely. This is the path tested first in automated attacks.

Before disabling them, check that no multifunction copier, business software or old mobile app relies on them to send email. It is the only precaution to take, but it is essential.

4. Monitor automatic forwarding rules

After a compromise, the attacker often creates a rule that quietly forwards a copy of messages to an external address, then deletes them from the folder. The victim notices nothing for months.

List the existing forwarding rules, block the creation of new rules to external addresses, and set up an alert whenever an attempt is made. It is also the best detector of bank transfer fraud you will have.

5. Backup: what Microsoft does not do

Microsoft guarantees the availability of the platform and the replication of its infrastructure. It does not guarantee to give you back a folder deleted eight months ago, or to restore a mailbox emptied by ransomware.

The native recycle bins and retention settings cover limited periods and have to be configured. Beyond that, you need an external backup, tested with a real restore at least once a year.

Frequently asked questions

Does Microsoft 365 back up data automatically?
No. Microsoft ensures the availability of the service and the replication of its infrastructure, which protects against hardware failure, but not against deletion, human error or ransomware encryption beyond the configured retention periods. An external backup is still necessary.
Is multi-factor authentication enough to protect email?
It removes most of the risk linked to password theft, but not all of it. It needs to be combined with disabling legacy protocols, which make it possible to bypass it, and with monitoring of automatic forwarding rules.
Where should I start if nothing has ever been configured?
In this order: enable multi-factor authentication everywhere, separate the administrator accounts, then disable legacy protocols after checking which devices use them. These three steps cover most of the everyday risk.

Next step

Sources

Published 3 September 2026 · Équipe Skill Group, Cybersécurité

Going further

Guide·Cybersecurity

Ransomware: what to do in the first hour

The decisions taken in the first sixty minutes largely determine how long the shutdown lasts. Here is the order of actions, and the three mistakes to avoid.

3 min·
Read the resource
Guide·Business continuity

Food industry: what really stops when IT goes down

On a production site, an IT failure does more than get in the way: it blocks shipping, traceability and sometimes the line itself. Here is how to prioritise.

3 min·
Read the resource