Microsoft 365: the security settings to check in your company
Microsoft 365 is secure by design, not by default. Here are the settings that matter, and the backup question that many companies discover too late.
A Microsoft 365 subscription is not secure by default. Four settings cover most of the risk: multi-factor authentication on every account without exception, administrator accounts kept separate from work accounts, legacy authentication protocols disabled, and automatic mail forwarding rules monitored. Finally, Microsoft hosts your data but does not back it up for you.
Account hacking is the top threat reported by companies and associations to Cybermalveillance.gouv.fr (the French government's cyber assistance service). Business email is the most common way in, and Microsoft 365 is by far the most widely used email platform among French SMEs.
Microsoft provides a solid platform. It also provides a starting configuration designed so that everything works straight away, which is not the same thing as a secure configuration.
1. Multi-factor authentication, without exception
This is the measure that makes the biggest difference for the least effort. A stolen password is no longer enough to get in.
- Enable it on every account, including those of senior management: they are the most targeted, never the least.
- Do not leave any permanent exception. An exception made "for the duration of the migration" becomes a permanent one.
- Prefer an authenticator app to SMS, which is more exposed to phone number hijacking.
2. Separate administrator accounts
An administrator who reads email with their privileged account exposes the entire tenant to a single malicious attachment.
- A named work account for everyday use, and a separate administration account for administrative tasks.
- The administration account receives no email and is not used for browsing.
- Limit the number of global administrators: it is the most powerful role and the one least often needed.
3. Disable legacy authentication protocols
Some older protocols cannot handle multi-factor authentication. As long as they remain active, they offer a path that bypasses it entirely. This is the path tested first in automated attacks.
Before disabling them, check that no multifunction copier, business software or old mobile app relies on them to send email. It is the only precaution to take, but it is essential.
4. Monitor automatic forwarding rules
After a compromise, the attacker often creates a rule that quietly forwards a copy of messages to an external address, then deletes them from the folder. The victim notices nothing for months.
List the existing forwarding rules, block the creation of new rules to external addresses, and set up an alert whenever an attempt is made. It is also the best detector of bank transfer fraud you will have.
5. Backup: what Microsoft does not do
Microsoft guarantees the availability of the platform and the replication of its infrastructure. It does not guarantee to give you back a folder deleted eight months ago, or to restore a mailbox emptied by ransomware.
The native recycle bins and retention settings cover limited periods and have to be configured. Beyond that, you need an external backup, tested with a real restore at least once a year.
Frequently asked questions
- Does Microsoft 365 back up data automatically?
- No. Microsoft ensures the availability of the service and the replication of its infrastructure, which protects against hardware failure, but not against deletion, human error or ransomware encryption beyond the configured retention periods. An external backup is still necessary.
- Is multi-factor authentication enough to protect email?
- It removes most of the risk linked to password theft, but not all of it. It needs to be combined with disabling legacy protocols, which make it possible to bypass it, and with monitoring of automatic forwarding rules.
- Where should I start if nothing has ever been configured?
- In this order: enable multi-factor authentication everywhere, separate the administrator accounts, then disable legacy protocols after checking which devices use them. These three steps cover most of the everyday risk.
Next step
Sources
Published 3 September 2026 · Équipe Skill Group, Cybersécurité
Going further
Ransomware: what to do in the first hour
The decisions taken in the first sixty minutes largely determine how long the shutdown lasts. Here is the order of actions, and the three mistakes to avoid.
Internet keeps dropping at your company: how to find the real cause
Repeated outages almost always have an identifiable cause. Here is the method to find it, and why a second router usually fixes nothing.
Food industry: what really stops when IT goes down
On a production site, an IT failure does more than get in the way: it blocks shipping, traceability and sometimes the line itself. Here is how to prioritise.