Microsoft 365 Security: 7 Things Nottingham Businesses Should Check

Microsoft 365 is used by businesses across Nottingham for email, file sharing, Teams, SharePoint and day-to-day collaboration.

It is a strong platform, but security depends on how it is configured and managed.

Settings can drift over time, especially as staff change, new devices are added and third-party apps are connected.

Here are seven areas worth checking.

1. Is Multi-Factor Authentication Enabled for Everyone?

Passwords on their own are not enough.

Multi-factor authentication, or MFA, adds an extra step when somebody signs in. This could be an approval through Microsoft Authenticator, a code or another verification method.

Check that MFA is being applied properly across the business, especially for:

  • Administrators
  • Directors and senior staff
  • Remote workers
  • New starters
  • Dormant accounts
  • Accounts with access to sensitive information

Administrator accounts need particular attention because they can provide access to a much wider part of your Microsoft 365 environment.

2. Who Has Administrator Access?

It is common for businesses to end up with more Microsoft 365 administrators than they actually need.

Over time, permissions may be given to employees, previous IT providers or temporary users and then never reviewed.

Check:

  • Who has administrator access
  • Whether they still need it
  • Whether Global Administrator rights are necessary
  • Whether previous employees or suppliers still have access
  • Whether administrator accounts are protected with MFA

Where possible, users should only have the level of access they need to do their job.

3. Are Your Email Security Settings Correct?

Email is still one of the main ways attackers target businesses.

Microsoft 365 includes a range of tools to help protect users from phishing, malicious links, dangerous attachments and impersonation attempts.

Depending on your licence, this can include Microsoft Defender for Office 365, Safe Links and Safe Attachments.

It is worth reviewing:

  • Anti-phishing policies
  • Anti-malware settings
  • Spam filtering
  • Safe Links
  • Safe Attachments
  • Quarantine settings
  • Impersonation protection

Having the feature available in your Microsoft 365 licence does not necessarily mean it has been configured correctly.

4. Are SPF, DKIM and DMARC Set Up Properly?

SPF, DKIM and DMARC help protect your email domain from being impersonated.

They are especially important if your business sends email through more than one system, such as:

  • Microsoft 365
  • CRM software
  • Marketing platforms
  • Accounting software
  • Website forms
  • Ticketing systems

Incorrect settings can cause legitimate emails to be marked as spam, while weak settings can make it easier for attackers to spoof your domain.

These records should be reviewed whenever you change email systems or add new services that send email on your behalf.

5. Who Can Access Your SharePoint and OneDrive Data?

Microsoft 365 makes it easy to share files with customers, suppliers and contractors.

The problem is that sharing permissions are often forgotten.

Someone may have been given access to a folder six months ago and still have access today, even though they no longer need it.

Review:

  • SharePoint permissions
  • OneDrive sharing
  • Microsoft Teams guest access
  • External users
  • Anonymous sharing links
  • Old supplier and contractor accounts

External sharing can be useful, but access should be deliberate and regularly reviewed.

6. Are the Devices Accessing Microsoft 365 Secure?

Staff may access Microsoft 365 from office PCs, laptops, mobiles and home devices.

That makes device security an important part of Microsoft 365 security.

Depending on how your business works, you may want to check:

  • Whether devices are fully patched
  • Whether disk encryption is enabled
  • Whether antivirus and endpoint protection are active
  • Whether devices are managed
  • Whether lost devices can be remotely protected
  • Whether unmanaged devices can download company data

Microsoft Intune and Conditional Access can help businesses control which devices are allowed to access company information.

7. When Did You Last Check Microsoft Secure Score?

Microsoft Secure Score gives you an overview of security recommendations across your Microsoft 365 environment.

It can highlight areas relating to:

  • User accounts
  • Devices
  • Applications
  • Data
  • Access controls

It should not be treated as a simple pass or fail score, but it can be useful for spotting gaps that have been missed.

Microsoft 365 environments change all the time. Staff join and leave, devices are replaced, permissions are added and new services are connected.

That is why security settings should be reviewed regularly rather than left alone after the initial setup.

How Secure Is Your Microsoft 365 Environment?

Microsoft 365 gives businesses access to a wide range of security tools, but they still need to be configured and maintained properly.

A sensible review should cover user accounts, administrator permissions, email security, domain protection, file sharing and device access.

For many Nottingham businesses, these settings are rarely reviewed unless there is already a problem.

If you are unsure how your Microsoft 365 environment is currently configured, a security review can help identify gaps and give you a clearer picture of what needs attention.

Looking for Microsoft 365 Support in Nottingham?

We help businesses across Nottingham manage, secure and support their Microsoft 365 environments.

If you want a second opinion on your current setup, or you are reviewing your existing IT support, get in touch with Firaya to discuss your Microsoft 365 environment.

Take A Look At Our Other Blogs