All resources

4 May 2026 · Guide · CyberSec360 Australia

Microsoft 365 Security: The Settings Every Small Business Should Turn On

Business email compromise is the costliest attack on Australian SMBs, and most of it lands in Microsoft 365. The uncomfortable, useful truth: the majority of victims already owned the defences that would have stopped the attack — inside licences they were already paying for.

The must-do five

  • Enforce MFA for every user — via Security Defaults or Conditional Access. Non-negotiable.
  • Block legacy authentication (old protocols like IMAP/POP basic auth) — it’s the side door attackers use to dodge MFA.
  • Turn on mailbox auditing and alerts for suspicious inbox rules — attackers’ first move after taking over a mailbox is a rule that hides their tracks.
  • Enable anti-phishing and impersonation protection so lookalikes of your own executives and suppliers get flagged.
  • Review admin accounts: as few as possible, each with MFA, none used for day-to-day email.

Worth the small upgrade

Microsoft 365 Business Premium adds Defender for Office 365 (safe links and attachment detonation), Intune device management, and Conditional Access. For most SMBs it’s the best-value security spend available — cheaper than a single third-party point product, covering half the Essential Eight in one licence.

Check your score, then keep it

Microsoft Secure Score (in the Defender portal) grades your tenant and lists exactly what to fix, in order. Screenshot it before and after — that’s free evidence for insurers and tenders. Then put a quarterly reminder in the calendar: tenants drift, staff change, new features appear. Configuration is a habit, not a project.

Want help with this in your business?

Book a free security check with our Sydney team — plain-English advice, no obligation.

Get a Free Security Check