Microsoft 365

Microsoft 365 Security Baseline for Small Businesses

The controls every small team should review before email, files, and identity become business risk.

By Noah Stertzbach, owner of NHM Ohio · Published · Updated · 7 min read

A technician checks a clipboard beside a long table of identical new laptops in a timber-beamed design studio.
AI-generated illustration

Microsoft 365 is often the center of a small business: email, files, calendars, Teams, identity, and access to other apps. That makes it one of the first places to harden.

Start with identity

Require MFA for every user, then apply extra scrutiny to administrators. Admin accounts should be named, limited, and used only when needed. Avoid shared administrator accounts whenever possible.

Review mailbox rules and forwarding

Attackers often create forwarding rules after mailbox compromise. Review external forwarding, suspicious inbox rules, delegated mailbox access, and sign-in activity for unusual patterns.

Control file sharing

Check whether anyone can create anonymous links, whether sensitive folders are overshared, and whether former employees still have access to SharePoint or OneDrive content.

Protect devices

Decide which devices can access company mail and files. At minimum, require screen locks, supported operating systems, encryption where practical, and a process for lost or replaced devices.

Do not confuse sync with backup

OneDrive and SharePoint sync are not the same as an independent backup. Decide how long deleted or encrypted files can be recovered and how a restore would work during a ransomware event.

Document ownership

Microsoft 365 security is not a one-time setup. Assign ownership for new users, terminated users, license changes, admin reviews, mailbox investigations, and backup checks.

Baseline checklist

  • MFA enforced for all users, administrators included.
  • Admin roles reviewed and limited.
  • External forwarding and suspicious mailbox rules reviewed.
  • Guest and external sharing settings documented.
  • Device access expectations defined.
  • Independent backup and restore expectations confirmed.

Need help with IT services or web hosting?

Talk with our team about managed IT support, secure hosting, migration, and day-to-day operations.

About the author

Noah Stertzbach, owner of NHM Ohio

Noah Stertzbach

Owner, NHM Ohio

Noah started NHM Ohio in 2021 and runs it from East Canton, Ohio. Clients work with him directly.

More about Noah and NHM Ohio →

IT Security Tips Newsletter

Weekly insights for Northeast Ohio businesses

Practical security and IT tips for Ohio business owners. No spam, and every email has an unsubscribe link.

DMARC setup guidesPhishing examplesSSL renewal checklistsOhio SMB case studies

Want Microsoft 365 reviewed by a local team?

NHM can assess MFA, admin access, sharing, email security, backups, and risky configuration gaps.

Looking for specific offerings? Managed IT services or web hosting services.