Microsoft 365 security baseline for small businesses
Microsoft 365 is where most businesses keep email, files, calendars and day-to-day work. That makes it worth protecting properly. You do not need every advanced security product on day one, but you do need a sensible baseline: strong sign-in protection, controlled access, protected email, managed devices, backups and a plan for when something goes wrong.
Last updated
The short answer
For most small businesses, start by requiring multi-factor authentication for every account, removing unused accounts and old admin access, securing email, keeping devices updated, limiting who can access sensitive files, and making sure important data can be restored. The exact settings depend on your Microsoft licence and how your team works, so the baseline should be reviewed before it is applied.
What a Microsoft 365 security baseline means
A security baseline is the minimum set of practical controls that protect the Microsoft 365 tenant before more specialised tools are considered. It is not one magic switch. It is a documented set of decisions about identities, email, devices, sharing, backups and response responsibilities that are checked over time.
The controls to check first
Protect every sign-in
Require multi-factor authentication, especially for administrators and remote workers. Review legacy sign-in methods and exceptions so a weak old setting does not undermine the rest.
Keep administrator access tight
Know who has administrator permissions, remove access that is no longer needed, and avoid using an all-powerful account for ordinary day-to-day work.
Harden business email
Review spam, phishing and impersonation protection; make sure suspicious messages have a clear reporting path; and train people to pause before entering credentials or paying an unexpected invoice.
Manage the devices that touch business data
Keep supported devices patched, encrypted and protected by screen locks. Decide which personally owned devices may access business email and files, and under what conditions.
Control sharing and sensitive information
Set sensible rules for external sharing, particularly for finance, HR and customer information. Make it easy for staff to collaborate without making every file public by accident.
Test recovery, not just backup
Document what must be recovered first, who can act during an incident, and how long recovery can realistically take. A backup is only useful when the business can restore what it needs.
Who this is for
- Small businesses using Microsoft 365 for email, files and collaboration.
- Business owners who are unsure whether their Microsoft tenant was configured securely when it was first set up.
- Teams that have grown quickly and now have old accounts, shared access or unmanaged devices.
- Businesses preparing for a cyber-security review, insurance conversation or a move to managed IT.
How to approach the baseline
- Map the tenant first. List users, administrator accounts, licences, shared mailboxes, devices, external access and the systems connected to Microsoft 365.
- Fix the highest-risk gaps. Prioritise exposed administrator accounts, missing MFA, unused accounts, unsupported devices and obvious email-security weaknesses.
- Set policies that fit the business. Security settings need to reflect who works remotely, who handles sensitive data and what support the team can realistically follow.
- Document the decisions. Record the baseline, exceptions, account owners and recovery responsibilities so the setup does not become tribal knowledge.
- Review it regularly. New staff, new devices, new suppliers and licence changes can all introduce gaps. Revisit the baseline after material changes and on a regular schedule.
How WaTo can help
- We start with the accounts, devices and work patterns you actually have, rather than a generic enterprise checklist.
- We explain what each control does and what trade-off it creates before switching it on.
- We can connect the Microsoft 365 setup to your wider device, backup, email and incident-response arrangements.
- We document the baseline so it is useful to your business after the initial work is finished.
- We are Adelaide-owned and support businesses locally and remotely across Australia.
Microsoft 365 security questions
Is multi-factor authentication enough on its own?
It is an important first control, but it does not replace secure administrator access, email protection, device management, sensible sharing rules or recovery planning. Think of it as one layer in a practical baseline.
Do small businesses need advanced Microsoft security licences?
Not automatically. Start by using the security controls already available in your current licence properly, then assess whether an upgrade solves a real gap in your risk or operating model.
Can staff use personal phones and laptops?
Possibly, but the business should decide what data can be accessed, which protections are required, and how access is removed when a person leaves. The answer should be documented rather than assumed.
How often should the setup be reviewed?
Review it after meaningful changes such as staff turnover, a new device rollout, a new supplier or an incident; also schedule a broader review at least annually.
Sources & references
WaTo Consulting. Last reviewed 2026-10-04. Review after Microsoft licensing or security-policy changes.
Want a clear view of your Microsoft 365 risks?
We can review the practical baseline, explain what matters for your business and help you prioritise the fixes.
Mon to Fri, 8:30am to 5pm
