Commteck
Guide

Microsoft 365 security settings every practice should turn on

5 min read · last reviewed 2026-10-06

Microsoft 365 is where a small practice's email, files and identity live, which makes it the most valuable account an attacker can reach and the easiest place to make a real security improvement. These are the settings we turn on for every client, in the order that matters.

Multi-factor authentication, for everyone — including the owner

Most mailbox compromises start with a password someone was tricked into typing. MFA is what turns that from a breach into a failed login, and it has to cover every account: the senior partner who considers themselves too busy, the shared front-desk account (which should not be shared at all), and the admin accounts most of all. App-based codes or a hardware key; SMS only as a fallback.

Close the doors that do not need a password

Legacy authentication protocols — the older mail settings used by ancient scanners, apps and scripts — can bypass MFA entirely, and they are still enabled by default on many tenants. Block them, then replace anything still using them rather than living with the hole.

Then look at what can reach your data from outside: no mailbox forwarding to external addresses, no auto-forwarding rules to personal accounts, and conditional access that refuses sign-ins from countries your practice does not work in.

  • Block legacy authentication and legacy protocols
  • Disable external mailbox forwarding to personal accounts
  • Require MFA for administrators and for remote access
  • Restrict sign-ins to the countries and networks you actually use

Make sure someone can see what is happening

Turn on the audit log, keep it, and actually read the alerts you get. The two signals worth watching first are failed sign-ins followed by a success, and new mailbox rules that forward or hide mail — those two catch most of the attacks that have already got in.

Add phishing and spoofing protection for your own domain (SPF, DKIM and DMARC) so the internet can tell real mail from yours from fake. DMARC starts as monitoring and moves to enforcement once the reports look clean.

Train the one behaviour that stops most of it

Technical controls stop attacks; people stop the ones the controls miss. Short, regular training works better than one annual session, and the single habit worth building is the check that takes four seconds: verify a payment or credential request by phone, on a number you look up yourself. Then make reporting easy and blameless — a staff member who reports a mistake in five minutes saves a practice a breach.

This is general guidance for practices in Utah — it is not legal, medical, compliance or tax advice, and it is not a substitute for advice on your own systems and obligations. Reviewed 2026-10-06; tell us if something in it has changed.