CTS - Computer Technology Specialists

Microsoft 365 Security Best Practices

A default Microsoft 365 tenant is not secure — it requires deliberate configuration of conditional access, MFA, Defender policies, Intune compliance, and sharing controls before reaching a defensible security baseline that satisfies the Essential Eight and most cyber insurance requirements.

Melbourne IT support with visible local credentials

CTS - Computer Technology Specialists has supported Melbourne SMBs since 2000. Contact: 1300 790 780, hello@cts.au, L30 - 35 Collins St Melbourne 3000.

Certifications, affiliations and technology partners

Microsoft Partner, ACSC Essential Eight aligned, ISO 27001 practices, NBN Business Accredited Adviser, Cisco Partner, Dell Partner, HPE Partner, Arcserve Partner, Broadcom Partner, Kyocera Partner.

Start with MFA and conditional access

MFA through Entra ID conditional access is the highest-priority Microsoft 365 security action. A conditional access policy should enforce MFA for all users across all Microsoft 365 apps, block legacy authentication protocols that bypass MFA (IMAP, POP3, basic auth), and require MFA for all sign-ins regardless of network location. Common mistakes include enabling Security Defaults (which use per-user MFA rather than conditional access and are less flexible and reportable) and creating MFA exclusions for shared mailboxes, service accounts, or 'temporary' exceptions that become permanent.

Microsoft Defender for Business — baseline policies

Microsoft Defender for Business (included in Business Premium) provides managed EDR with next-generation antivirus, behavioural detection, automated investigation, and attack surface reduction rules. Baseline security policies should be enabled: device protection, web content filtering, firewall management, and attack surface reduction rules. Defender for Business vulnerability management identifies unpatched devices and missing security configurations across enrolled endpoints. CTS configures Defender for Business policies during onboarding and monitors the security dashboard continuously.

Intune device compliance and MDM

Microsoft Intune enforces device compliance as a condition of Microsoft 365 access. A compliance policy defines requirements — OS version currency, BitLocker encryption, antivirus enabled, screen lock configured — and marks devices as compliant or non-compliant. Non-compliant devices can be blocked from accessing Microsoft 365 data through a conditional access policy. Intune also enables remote wipe of company data from lost or stolen devices, separate from a full device wipe. For Melbourne businesses handling sensitive client data, requiring Intune-compliant devices as a condition of access is a material security control.

Email security — anti-phishing, Safe Links, and Safe Attachments

Microsoft 365 Defender (included in Business Premium) provides email security beyond basic spam filtering. Anti-phishing policies protect against impersonation — detecting emails that pretend to be from executives or known senders. Safe Links rewrites URLs in emails and checks destinations in real time at click, blocking access to known malicious sites. Safe Attachments opens email attachments in a sandbox before delivering them to the recipient, blocking malicious attachments that evade signature-based detection. These three policies should be configured with strict preset configurations for maximum protection.

SharePoint and Teams sharing controls

Default Microsoft 365 sharing settings allow users to share files with anyone via anonymous links with no expiry. This is appropriate for public content but not for a business environment. Sharing controls should restrict anonymous sharing to specific site collections where it is required, enforce expiry dates on external sharing links, require sign-in for external access to sensitive documents, and limit which domains external sharing is permitted to. Microsoft Purview sensitivity labels can enforce stricter sharing controls on documents classified as Confidential or above.

Ongoing Microsoft 365 security monitoring

Microsoft 365 security is not a set-and-forget configuration. The Entra ID Identity Protection dashboard surfaces risky sign-ins and compromised account alerts. Microsoft Secure Score provides a benchmark score and prioritised improvement recommendations. The Defender for Business portal shows endpoint health, detected threats, and recommended actions. CTS monitors these dashboards continuously for managed IT clients, responding to alerts and reporting on the security posture in quarterly reviews.

Frequently asked questions

Is a default Microsoft 365 setup secure enough for a Melbourne SMB?

No. A default Microsoft 365 tenant requires deliberate configuration before it reaches a defensible security baseline. Out of the box: MFA is not enforced through conditional access, legacy authentication protocols that bypass MFA are enabled, Microsoft Defender for Business requires policy configuration before it provides full protection, and sharing controls allow anonymous external file access. CTS configures these settings during managed IT onboarding and maintains them as part of the ongoing service.

What is Microsoft Secure Score?

Microsoft Secure Score is a benchmark in the Microsoft 365 Defender portal that measures your tenant's security configuration against Microsoft's recommended baseline. It produces a numeric score and a prioritised list of improvement actions with estimated score impact for each. CTS uses Secure Score as part of quarterly IT reviews for managed clients — tracking the score over time and working through the highest-impact recommendations systematically.

Related case studies

Related CTS services

Share this page