Microsoft 365 security features
Microsoft 365

Microsoft 365 Security Features You Should Be Using

11 min readSearchMyMSP Team
Microsoft 365

Microsoft 365 includes a powerful suite of security tools that most businesses never fully activate. Whether you're on Business Basic or Business Premium, there are critical security features available right now that can dramatically reduce your risk — many at no additional cost. Here is what to enable, how to enable it, and why it matters.

The average Microsoft 365 tenant has a Secure Score below 40% — meaning more than half of Microsoft's recommended security controls are not enabled. Most of these controls are included in your existing subscription and require no additional spending. The four features below represent the highest-impact improvements you can make, in order of priority.

Multi-Factor Authentication (MFA)

All Plans

MFA is the single most effective control for preventing account takeover. Microsoft reports that MFA blocks 99.9% of automated attacks. Yet many businesses still haven't enabled it for all users — often because of concerns about user friction or the complexity of the rollout. Enable Security Defaults in Azure AD to enforce MFA across your entire organisation instantly, with no additional licensing required.

The mechanics of why MFA is so effective are worth understanding. Most credential attacks — password spraying, phishing, credential stuffing from data breaches — rely on stolen username and password combinations. MFA adds a second factor (typically a phone notification or authenticator app code) that the attacker does not have. Even if they have your password, they cannot log in without the second factor. This single control neutralises the vast majority of account takeover attempts.

The most common objection to MFA is user inconvenience. In practice, Microsoft Authenticator's number matching and passwordless sign-in options have made the experience seamless for most users. The initial setup takes 5–10 minutes per user, and the ongoing friction is minimal — a single tap on a phone notification. Compare that to the cost and disruption of a compromised account, and the case for MFA becomes overwhelming.

Quick win: Enable Security Defaults in Azure AD → Properties → Manage Security Defaults. This enforces MFA for all users in under 5 minutes, at no additional cost.

How to enable:

  • Go to Azure Active Directory → Properties
  • Click "Manage Security Defaults"
  • Toggle to Enabled
  • All users will be prompted to register MFA on next sign-in

Microsoft Defender for Office 365

Business Premium+

Defender for Office 365 adds advanced threat protection to Exchange Online, including Safe Links (real-time URL scanning), Safe Attachments (sandboxed attachment analysis), and Anti-Phishing policies. These features stop the majority of email-based attacks before they reach your inbox. Email remains the #1 attack vector for businesses of all sizes — over 90% of cyberattacks begin with a phishing email.

Safe Links works by rewriting every URL in incoming emails and scanning the destination in real time when the user clicks. This catches malicious links that were safe at the time of delivery but were later weaponised — a technique known as time-of-click phishing. Safe Attachments opens every attachment in a sandboxed environment before delivering it to the recipient, catching malware that evades signature-based detection.

The Anti-Phishing policies in Defender for Office 365 include impersonation protection — detecting emails that attempt to impersonate your executives, your domain, or trusted external senders. This is the technical control that catches Business Email Compromise attempts at the email gateway, before they ever reach your finance team. Combined with Attack Simulation Training, which sends realistic phishing simulations to your employees, Defender for Office 365 addresses both the technical and human dimensions of email security.

Configuration priority: Enable Safe Attachments in Dynamic Delivery mode first — this provides the highest protection with the least user disruption.

How to enable:

  • Enable Safe Links policy for all users in the Microsoft 365 Defender portal
  • Configure Safe Attachments in Dynamic Delivery mode to avoid email delays
  • Set up Anti-Phishing with impersonation protection for your executives and domain
  • Enable Attack Simulation Training to measure and improve employee phishing awareness

Conditional Access Policies

Business Premium+

Conditional Access lets you enforce context-aware access controls — requiring MFA from untrusted locations, blocking legacy authentication protocols, and restricting access from non-compliant devices. This is the foundation of a Zero Trust security model: never trust, always verify. Instead of granting access based solely on username and password, Conditional Access evaluates the full context of every sign-in attempt.

Legacy authentication protocols are one of the most overlooked security risks in Microsoft 365 environments. Protocols like SMTP AUTH, POP3, IMAP, and basic authentication do not support MFA — meaning any account that allows legacy authentication can be compromised even if MFA is enabled. Blocking legacy authentication is one of the highest-impact security improvements you can make, and it is often the first thing a security-focused MSP will do when they take over a Microsoft 365 tenant.

Device compliance policies, enforced through Conditional Access and Microsoft Intune, ensure that only managed, up-to-date devices can access your corporate data. This prevents a compromised personal device from being used to access sensitive business information, and ensures that all devices accessing your environment meet your security baseline — current OS patches, antivirus enabled, disk encryption active.

Highest-impact policy: Block legacy authentication protocols. This single Conditional Access policy eliminates a major attack surface that MFA cannot protect.

How to enable:

  • Block legacy authentication protocols (SMTP AUTH, POP3, IMAP, basic auth) via Conditional Access
  • Require MFA for all admin accounts — apply this policy first, before any others
  • Require compliant devices for access to sensitive data using Intune device compliance policies
  • Block access from high-risk sign-in locations and flag risky sign-ins for review

Microsoft Purview (Data Loss Prevention)

Business Premium+

Purview DLP policies automatically detect and protect sensitive information like credit card numbers, Social Security numbers, and health records. Prevent accidental or malicious data exfiltration via email, Teams, SharePoint, and OneDrive. Data loss prevention is particularly important for businesses subject to compliance requirements — HIPAA, PCI-DSS, GDPR — where a single data breach can result in significant regulatory fines in addition to the direct costs of the incident.

The most valuable aspect of Purview DLP is its policy tips feature, which educates users in real time when they attempt to share sensitive information. Instead of silently blocking an action and generating a support ticket, Purview shows the user a notification explaining why the action was blocked and what they should do instead. This turns DLP from a pure enforcement tool into an ongoing security awareness programme.

Purview's sensitivity labels extend data protection beyond your Microsoft 365 environment. Documents labelled as "Confidential" carry their protection with them — even when shared externally or downloaded to a personal device. This is particularly valuable for professional services firms, healthcare organisations, and any business that regularly shares sensitive documents with clients or partners.

Compliance note: Purview DLP reports provide the audit evidence required by HIPAA, PCI-DSS, and SOC 2 for data handling controls. Configure monthly report reviews.

How to enable:

  • Create DLP policies for PII, PCI, and HIPAA data types relevant to your business
  • Configure policy tips to educate users in real time rather than silently blocking actions
  • Set up alerts for policy violations and assign a reviewer to investigate them weekly
  • Review DLP reports monthly and use them as compliance evidence for audits

The Bottom Line

Most M365 security features are already included in your subscription — they just need to be turned on and configured correctly. Enabling MFA alone can block 99.9% of automated attacks. The rest of the stack builds on that foundation to create a comprehensive defence.

If you are unsure where to start, check your Microsoft Secure Score at security.microsoft.com. It will show you exactly which controls are missing and prioritise them by impact. A qualified MSP can implement the full security baseline in a single engagement, typically within a week.

Frequently Asked Questions

Common questions about this topic, answered by the SearchMyMSP team.

Share: Twitter LinkedIn

Get Your M365 Security Configured Properly

Many MSPs offer Microsoft 365 security assessments and configuration services. A properly configured M365 tenant can stop the vast majority of common attacks. Find an MSP with Microsoft certifications in your area.

Find a Microsoft MSP