Microsoft 365 Security Best Practices for SMEs and Charities
Many organisations across Bradford, Leeds, Halifax and the wider West Yorkshire region rely on Microsoft 365 as their primary business platform.
A compromised Microsoft 365 account is rarely just an IT problem. It can mean a fake invoice sent from a familiar address, confidential files shared outside the organisation, or a charity’s donor records put at risk. This guide to Microsoft 365 security best practices focuses on the controls that make the biggest practical difference for small organisations, without turning every colleague into a cyber security specialist.
The right setup depends on your licences, the sensitivity of your information and how your team works. A five-person office with shared machines has different needs from a growing business with remote staff, volunteers and personal phones. The aim is sensible protection that supports people’s work rather than getting in their way.
Whether you’re a professional services firm in Leeds, a charity in Bradford or a growing business in Halifax, securing Microsoft 365 should be a core part of your cyber security strategy.
While Microsoft provides a strong security platform, effective protection depends on how those controls are configured, monitored and maintained. As a Managed Security Service Provider (MSSP), we regularly help organisations across West Yorkshire identify avoidable security gaps that expose businesses and charities to phishing, account compromise and data loss.
Microsoft 365 Security Checklist
If you’re reviewing your Microsoft 365 security, make sure you:
- Enable MFA for all users
- Separate administrator and user accounts
- Configure Security Defaults or Conditional Access
- Enable SPF, DKIM and DMARC
- Enable external email warnings
- Apply device security policies
- Review SharePoint and OneDrive sharing
- Configure Teams guest access
- Enable audit logging
- Review backup and retention policies
Protect User Accounts with MFA and Conditional Access
Most successful Microsoft 365 attacks begin with a stolen password. That is why account security comes before email filtering, device controls or clever software. If an attacker can sign in as a trusted colleague, they may be able to read mail, reset passwords and persuade others to act.
Turn on multi-factor authentication (MFA) for every user, including administrators. The Microsoft Authenticator app is generally a better choice than text messages because SMS codes can be targeted through number-porting scams. Where possible, encourage number matching in the app, which helps reduce accidental approval of fraudulent prompts.
Be careful not to treat MFA as a one-off task. Review the authentication methods available to users and remove old phone numbers, former staff details and methods that are no longer needed. Staff should also know one simple rule: never approve a sign-in prompt they did not initiate. A quick call to the IT team is far cheaper than dealing with a breached account.
Not sure whether MFA is properly enforced across your organisation? A Microsoft 365 security review can quickly identify gaps before they become incidents.
Security Defaults are a sensible baseline for many smaller organisations. They encourage MFA and protect against older sign-in methods that are easier for criminals to exploit. Organisations with Microsoft Entra ID Premium licensing may instead use Conditional Access policies, which allow more tailored rules, such as requiring MFA when someone signs in from an unfamiliar location or blocking access from high-risk countries.
Conditional Access is powerful, but it needs careful testing. A rule that is too strict can prevent a director from accessing email while travelling or stop a vital third-party application from working. Start in report-only mode where available, check the results, and apply policies in stages.
Protect administrator accounts separately
Global Administrator accounts can change almost everything in a Microsoft 365 tenant. Keep the number of people with this role to an absolute minimum and give staff only the permissions they actually require. Day-to-day work should be completed with a normal user account, not an administrator account.
Maintain at least two emergency access accounts with long, unique passwords and appropriate monitoring. These accounts should be cloud-only, stored securely and used only if normal sign-in controls fail. It may feel like extra housekeeping, but it prevents a security policy error from locking everyone out at once.
Strengthen Email Security
Email remains the preferred route for phishing, invoice fraud and malware. Microsoft 365 has useful protections, but the default settings are not always enough for an organisation handling financial information, personal data or sensitive community work.
Set up SPF, DKIM and DMARC for every domain that sends email on your behalf. These records help receiving mail systems check that messages genuinely came from your organisation. DMARC should usually begin in monitoring mode while you identify legitimate services, such as newsletter platforms or website forms, that send using your domain. Once those are included, move towards a quarantine or reject policy.
Microsoft 365 includes baseline email protection, but organisations with higher security requirements may benefit from an additional security layer such as Heimdal. Features including advanced email security, ransomware protection, DNS filtering, privileged access management and threat prevention can help reduce the risk of phishing, malware and business email compromise. The right solution will depend on your organisation’s risk profile, compliance requirements and existing Microsoft 365 licensing.
External sender tagging is a small setting with a useful human benefit. When colleagues can clearly see that an email came from outside the organisation, they are more likely to pause before acting on an unexpected payment request. It does not replace awareness training, but it gives people a helpful prompt at the right moment.
Many organisations discover SPF, DKIM and DMARC are only partially configured. A quick assessment can verify that your domains are fully protected against email impersonation.
Secure the devices that access your files
A well-protected account can still be exposed through an unattended laptop, an unpatched PC or a lost mobile phone. Make sure Windows, Microsoft 365 Apps, browsers and security software receive updates promptly. Delaying updates indefinitely because they might interrupt work creates a much bigger problem later.
For company-owned devices, Microsoft Intune can apply security settings consistently. This may include BitLocker encryption, screen lock timeouts, antivirus protection, firewall settings and minimum operating system versions. It also gives the organisation options to remove company data from a lost or departing employee’s device.
Personal devices need a more measured approach. Many charities and SMEs rely on bring-your-own-device arrangements, particularly for trustees, volunteers and occasional remote workers. Rather than trying to manage someone’s entire phone, consider app protection policies that protect Microsoft 365 data within Outlook, Teams and other work apps. This can require a suitable licence, but it offers a sensible balance between security and privacy.
Do not overlook local administrator rights. Users who can install any application may unintentionally introduce risky software or make changes that leave devices vulnerable. Some teams need elevated access for specialist tools, but that should be the exception, not the standard setting.
If managing multiple devices has become difficult, Microsoft Intune can help standardise security settings without increasing administrative workload.
Control sharing in Teams, SharePoint and OneDrive
Microsoft 365 makes collaboration easy, which is excellent until a confidential folder is shared with “Anyone with the link”. Review the sharing settings for SharePoint and OneDrive at tenant level, then check the sites holding finance, HR, client or beneficiary information.
For many organisations, authenticated sharing with named people is the safest practical default. If external sharing is necessary, set link expiry dates and use view-only permissions where editing is not required. Limit who can create sharing links and make sure former partners, staff and volunteers lose access when their relationship with the organisation ends.
Teams deserves the same attention. Review guest access, external chat and who can create new teams. Open collaboration can be useful for project work, but it should be a deliberate choice. A community group working with several partner agencies may need guest access, while a business discussing payroll or commercial plans may need much tighter boundaries.
Why We Recommend a Layered Security Approach
Microsoft 365 provides a strong foundation for security, but no single platform can protect against every threat. At Bees Knees IT, we regularly help organisations across Bradford, Leeds, Halifax and the wider West Yorkshire area strengthen security controls that have been overlooked, misconfigured or simply never reviewed.
Common issues include weak email authentication, excessive administrator privileges, unmanaged devices and phishing attacks that bypass user awareness training. In many cases, the technology is already available, but it has not been configured to provide the level of protection the organisation expects.
As a Managed Security Service Provider (MSSP), we typically recommend a layered approach that combines Microsoft 365 security features with additional protection such as Heimdal. This can provide enhanced threat prevention, DNS security, privileged access management, endpoint protection and ransomware defences, helping organisations reduce cyber risk without making day-to-day work more complicated.
The right security strategy should reflect your organisation’s size, risk profile and compliance requirements. Whether you’re a charity managing donor information or a growing business handling sensitive client data, layered security can help improve resilience against evolving threats.
Unsure whether your Microsoft 365 security is configured correctly?
Bees Knees IT provides Microsoft 365 security reviews for organisations across Bradford, Leeds, Halifax and West Yorkshire. We can assess your current setup, identify weaknesses and recommend practical improvements to help protect your users, data and reputation.
Contact us to arrange a Microsoft 365 security assessment.
Prepare for mistakes, leavers and incidents
Security settings are only useful if somebody checks that they continue to work. Turn on audit logging and agree who will review alerts for suspicious sign-ins, mailbox forwarding rules and unusual file activity. Mailbox forwarding is especially worth watching because attackers often create hidden rules to copy messages outside the organisation.
Have a clear leaver process. On a person’s final day, block sign-in, remove licences where appropriate, revoke sessions, check shared mailbox access and transfer ownership of files or Teams work. Do not simply delete the account immediately if email, records or legal retention requirements still need to be handled.
Microsoft provides strong infrastructure, but it does not remove your responsibility for your data, permissions and recovery plan. Check retention policies for email and documents, and decide whether a separate Microsoft 365 backup service is appropriate. Retention can help recover accidental deletions, while backup can provide an additional recovery option after a major mistake or attack. The best choice depends on how long you need to retain information and how quickly you must restore it.
A useful monthly review need not take all day. Check that MFA is still enforced, look for new admin accounts, review risky sign-ins, confirm devices are compliant and make sure email authentication is passing. Keep a short record of what was checked and any action taken. This is valuable evidence for Cyber Essentials, insurers and trustees, but more importantly, it catches small issues before they become a stressful call on a Monday morning.
Security should make your organisation more confident, not more cautious about using technology. If your team in Bradford, Leeds or Halifax needs help turning these settings into a manageable routine, Bees Knees IT can take the sting out of the technical detail and leave you free to focus on the people you support.
Frequently Asked Questions
What are the most important Microsoft 365 security settings?
The most important settings include MFA, Conditional Access, administrator account protection, SPF/DKIM/DMARC email authentication, audit logging and secure sharing controls.
Is Microsoft 365 secure enough on its own?
Microsoft provides a secure platform, but organisations remain responsible for configuring security settings, managing permissions and protecting data.
Is Microsoft 365 email security enough on its own?
Microsoft 365 includes built-in email security controls, but many organisations choose to supplement these with additional protection such as Heimdal. This can provide enhanced threat prevention, email security, privileged access management and endpoint protection, helping reduce cyber security risk without significantly increasing complexity.
What’s the difference between Microsoft 365 retention and backup?
Retention policies help preserve and recover content within Microsoft 365, while backups provide a separate copy of data for additional recovery options.
Do I need Microsoft 365 backup if Microsoft already stores my data?
Microsoft provides resilient infrastructure and retention capabilities, but organisations remain responsible for meeting their own recovery and retention requirements. A dedicated Microsoft 365 backup solution provides an essential, additional layer of protection against accidental deletion, ransomware and long-term recovery needs.
How often should Microsoft 365 security settings be reviewed?
At minimum, organisations should review key settings monthly and conduct a more detailed security audit annually.
About Bees Knees IT
Bees Knees IT provides managed IT support, cybersecurity, backup and disaster recovery services to businesses, charities and professional organisations across Bradford, Leeds, Halifax and the wider West Yorkshire region. Our team helps organisations improve resilience, protect critical data and recover quickly from unexpected disruptions.
About the Author
Craig Hawes is the Managing Director of Bees Knees IT and has spent years helping organisations across West Yorkshire improve their IT security, cyber resilience and compliance. Working closely with charities, SMEs and community groups, Craig focuses on practical solutions that reduce risk, strengthen data protection and make technology easier to manage without unnecessary complexity.
Leave A Comment