Microsoft 365 ships with serious security tooling. The problem? Most of it stays switched off until someone deliberately turns it on. You're paying for protection you're not using, and attackers know it.
1. Multi-factor authentication (MFA), no exceptions
A stolen password is still the number one way into business systems. A phishing page that looks like the Microsoft sign-in, an employee in a hurry, and the password is gone. MFA means the password alone is no longer enough: without the confirmation on the phone, the attacker stays at the door. Microsoft's own data has shown the same thing for years, MFA stops the vast majority of account attacks. If you enable just one thing from this list, make it this one. And yes, "no exceptions" includes the CEO. Especially the CEO.
2. Conditional access
Why would anyone sign in to your system at 3 a.m. from another continent? Conditional Access sets the rules: sign-ins from unexpected countries, unknown devices or "impossible travel" patterns get blocked automatically or challenged for extra verification.
3. Anti-phishing protection
A standard spam filter is not the same as protection against targeted phishing. Settings like impersonation protection (someone posing as your CEO from an address that differs by a single letter) and time-of-click link scanning drastically reduce the odds of a scam ever reaching an employee.
4. External forwarding rules
A classic trick after a mailbox breach: the attacker sets a silent rule that copies every message to their own address, then reads your correspondence for months, waiting for the right moment for an invoice fraud. Automatic external forwarding should be banned at the organisation level, and existing rules reviewed regularly.
5. Monitoring and alerts
Everything above means little if nobody reads the alerts. Define who receives security notifications and what happens with them. A suspicious sign-in that sat unreviewed for three weeks. That's an incident that could have been prevented.
The good news: none of this requires a new licence or new hardware. It's about configuring what you already pay for. An hour or two of expert work, and your level of protection multiplies.