Skip to main content
Microsoft 365 security best practices to protect business data and users

1. We have Microsoft 365 Business Basic, is it worth adding security controls at that tier?

Yes, several high-impact controls like audit logging, MFA enforcement, and phishing filters are available across all tiers and should be configured regardless of license level.

2. How do we know if legacy authentication is still enabled in our tenant?

Sign-in logs in Azure Active Directory will show authentication protocol details, filter for “Legacy Auth” clients to see active usage before disabling.

3. Our IT team says our Microsoft 365 is already secured. What should we actually verify?

Ask them to pull the Microsoft Secure Score and show you the Conditional Access policies in place, those two items reveal most of the significant gaps quickly.

4. Can we set up automatic alerts for suspicious activity in Microsoft 365?

Yes, Microsoft Defender for Office 365 and Microsoft Sentinel both support alert rules for high-risk events like mass file downloads, new mail forwarding rules, and impossible travel sign-ins.

5. How often should we review our Microsoft 365 security configuration?

At minimum quarterly, and any time there’s a significant change, new admin roles assigned, new third-party apps connected, or a major organizational shift like an acquisition or departure of a senior employee.

Roger Michelson

Roger Michelson is CEO and co-owner of BNMC (Bredy Network Management Corporation), a leading Managed IT Support Services Provider serving businesses across the Northeast. With over 30 years in IT and an MBA from Northeastern University, he combines deep technical expertise with sharp business acumen to help organizations build resilient, high-performing IT environments. BNMC's 2024 MSP Titan of the Industry award reflects his commitment to excellence.