Hardening Microsoft 365
email, step by step.
Microsoft 365's defaults are built for compatibility, not maximum security — which means a new tenant leaves several of the settings that stop phishing and account takeover switched off. This checklist walks through the changes that matter most, in rough order of impact, with the actual policy and portal names, in plain language for the person who administers the tenant.
The highest-impact Microsoft 365 email hardening steps are: enforce multi-factor authentication for every account, block legacy authentication, and turn off external auto-forwarding. Then apply a Defender preset security policy, publish SPF, DKIM, and DMARC for your domain, and confirm unified audit logging is on so you can investigate later. Most account takeovers start with a stolen password on an account without MFA — close that door first, then work down the list.
Why the defaults aren't enough
Microsoft 365 ships to work smoothly for the widest range of customers, and some of its strongest protections are optional or need configuration. Every mailbox includes Exchange Online Protection, which filters spam and known malware — but out of the box a tenant does not necessarily enforce multi-factor login, block older insecure protocols, scan links at click-time, or stop a compromised account from quietly forwarding mail out of the organization. Those are the gaps attackers rely on, and the checklist below closes them.
The reassuring part: the two changes that matter most are free and fast. Microsoft has stated that requiring MFA and blocking legacy authentication together stop more than 99.9% of identity-based attacks, and that the large majority of password-spray attempts ride in over legacy protocols. You do not need the most expensive license to shut those down — you need to turn them on.
Know your four admin portals
Almost everything here lives in one of four places. Knowing which is which saves most of the hunting:
- Microsoft 365 admin center (admin.microsoft.com) — users, licenses, domains.
- Microsoft Entra admin center (entra.microsoft.com) — identity: MFA, Conditional Access, Security Defaults. (Entra ID is the current name for what used to be Azure AD.)
- Microsoft Defender portal (security.microsoft.com) — anti-phishing, Safe Links, Safe Attachments, preset policies, DKIM, Secure Score.
- Microsoft Purview (purview.microsoft.com) — the unified audit log and alerting.
The essentials (do these first)
- Enforce multi-factor authentication for everyone. Use a Conditional Access policy in Entra (or Security Defaults on smaller plans) so every user, especially admins, must confirm sign-in with a second factor. This is the single biggest barrier to account takeover. Note that Security Defaults and Conditional Access are mutually exclusive — turning on CA policies switches Security Defaults off — so pick one path deliberately.
- Create break-glass admin accounts. Before you tighten Conditional Access, set up two emergency-access accounts excluded from the policies, so a misconfiguration can't lock every admin out of the tenant.
- Block legacy authentication. Protocols like IMAP, POP, and older Office and Exchange clients can't enforce MFA, so attackers target them to slip past it. Block them with a Conditional Access policy (Security Defaults also does this), exempting only an app that genuinely needs it.
- Disable POP, IMAP, and SMTP AUTH. Turn these legacy mail protocols off tenant-wide unless a specific mailbox requires one. SMTP AUTH in particular is a common way for a stolen password to send mail without ever facing MFA.
- Protect and separate admin accounts. Use dedicated admin accounts that don't send or receive normal mail, grant only the roles each person needs, and require phishing-resistant MFA (a FIDO2 security key or passkey) on them — ordinary app or text-message codes can be relayed in real time by modern phishing kits.
- Turn on unified audit logging. In Purview, confirm audit log search is enabled. If it isn't recording, you can't investigate a compromise after the fact. Do it now, before you need it.
Anti-phishing and malicious content
Shortcut for small teams: rather than build each policy by hand, apply a preset security policy (Standard or Strict) in the Defender portal. It switches on anti-phishing impersonation protection, Safe Links, and Safe Attachments together, with Microsoft-maintained settings — the fastest way to a strong baseline.
- Configure a Defender anti-phishing policy with mailbox intelligence, impersonation protection for your key people (executives, finance) and for your own and partner domains, and spoof intelligence. Turn on the first-contact safety tip so mail from a brand-new sender is visibly flagged. Advanced impersonation protection needs Defender for Office 365; spoof intelligence and the first-contact tip are included in Exchange Online Protection.
- Enable Safe Links so URLs are checked at the moment of click, not just at delivery — attackers commonly send a clean link and weaponize it afterward.
- Enable Safe Attachments to detonate unknown attachments in a sandbox before delivery.
- Confirm Zero-hour Auto Purge (ZAP) is on. It removes mail from inboxes after delivery if it is later reclassified as phishing or malware. It's on by default — verify nobody has disabled it.
- Add an external-sender tag so a message pretending to be internal is easier to spot at a glance.
- Review the anti-spam and quarantine policies so genuinely dangerous mail is quarantined and users have a clear, safe way to review it.
Authenticate your own domain (SPF, DKIM, DMARC)
These three records don't protect your inbox — they stop criminals from spoofing your domain to everyone else, which protects your customers, donors, and contacts as much as you. Set them up in order: SPF, then DKIM, then DMARC.
- Confirm SPF lists every service allowed to send as your domain, and nothing more (for a Microsoft-only domain,
v=spf1 include:spf.protection.outlook.com -all). - Enable DKIM signing per custom domain in the Defender portal. This is the step most often missed: Microsoft signs with a default key automatically, but that is not DKIM for your domain. Publish the two CNAME selector records for each domain, then switch DKIM signing on for it.
- Publish DMARC with an
ruareporting address, and move it from none to quarantine to reject over time — watching the reports so you don't block a legitimate sender (a newsletter platform, an invoicing tool) you'd forgotten sends as you. A DMARC record with no reporting address leaves you flying blind, which is why so many organizations stall at none.
Close the persistence gaps attackers use
When an account is taken over, the attacker's next move is almost always to set up a quiet way to keep reading or redirecting mail. Shut those down in advance:
- Turn off automatic external forwarding. In the outbound spam filter policy, set automatic forwarding to Off. A hidden rule that forwards mail out of the organization is a classic sign of compromise and a common data-theft path — and it's an explicit control in both the CIS Microsoft 365 Benchmark and CISA's baselines.
- Alert on new inbox rules and forwarding. A rule that hides or redirects replies is the actual fingerprint of a compromised mailbox. Create an alert policy so one is caught quickly.
- Restrict who can consent to third-party apps. Require admin approval for app permissions, so an attacker can't trick a user into granting a malicious app standing access to their mailbox — a route that survives a password reset.
- Review mailbox delegate and forwarding settings periodically as part of routine hygiene.
Watch your posture over time
- Use Microsoft Secure Score (in the Defender portal) as your running scorecard. Action the highest-value recommendations it surfaces, and check that the score doesn't quietly drift down as settings change.
- Set alert policies for mass mail, unusual forwarding-rule creation, impossible-travel sign-ins, and mailbox-permission changes.
- Know your audit-log retention. Business Premium and E3 retain the unified audit log for 180 days; longer retention needs E5 or the Audit (Premium) add-on. Plan around what you actually have before an incident, not during one.
The one-afternoon priority order
If you only have a few hours, do them in this sequence — each one blunts a larger share of real attacks than the last is expensive:
- Enforce MFA for all users (Conditional Access or Security Defaults), and create two break-glass accounts.
- Block legacy authentication, and disable POP, IMAP, and SMTP AUTH tenant-wide.
- Set the outbound spam policy to turn off external auto-forwarding.
- Confirm SPF, enable DKIM per domain, and publish DMARC at quarantine (or none with reporting if you're unsure of all your senders).
- Apply the Standard preset security policy to bundle anti-phishing, Safe Links, and Safe Attachments.
- Turn on unified audit log search in Purview.
- Open Secure Score and action the top three remaining recommendations.
What license do you actually need?
Exchange Online Protection — anti-spam, anti-malware, spoof intelligence, the first-contact safety tip, and support for SPF, DKIM, and DMARC — is included in every Microsoft 365 plan. The advanced pieces (Safe Links, Safe Attachments, impersonation protection) come with Defender for Office 365 Plan 1, which is bundled into Microsoft 365 Business Premium and E5, or available as an add-on. For most small organizations, Business Premium covers essentially this entire checklist. Qualifying nonprofits can get Business Premium at a steep discount through Microsoft's nonprofit program — a reason not to skip these controls on budget grounds.
What hardening does not solve
Every step above reduces the odds of an account being taken over, and that is worth a great deal. But it does not, on its own, stop business email compromise — the plain, link-free request for a wire transfer or a change of bank details that arrives from a real, compromised account and passes every check. That gap is closed by a payment-verification process, user awareness, and a layer that reads the intent of a message rather than just scanning it for malicious code. Treat hardening as the foundation, not the whole building.
Sources & further reading: Microsoft Learn — preset security policies, anti-phishing policies, DKIM and DMARC setup, and blocking legacy authentication · CISA SCuBA Exchange Online baseline · CIS Microsoft 365 Foundations Benchmark. Setting names and locations change; always confirm in your current admin center. Educational only, not a substitute for a professional configuration review.
Common questions
What is the single most important Microsoft 365 email security setting?
Multi-factor authentication for every account, enforced through a Conditional Access policy or the built-in Security Defaults. Microsoft has said that MFA combined with blocking legacy authentication stops the overwhelming majority of identity-based attacks. Most Microsoft 365 account takeovers begin with a stolen or guessed password, and MFA closes that door. Turn it on before anything else.
Does Microsoft 365 stop business email compromise on its own?
No. Exchange Online Protection and Defender for Office 365 catch malicious links, malicious attachments, and known spam, but business email compromise usually carries none of those. When an attacker sends a plain-text request from a compromised but genuine account, it passes every built-in check. Hardening reduces account takeover; stopping the fraud itself also needs a payment-verification process and a layer that reads the intent of a message.
Should I turn off legacy authentication?
Yes. Legacy authentication protocols such as IMAP, POP, and older Office and Exchange clients cannot enforce multi-factor authentication, so attackers target them specifically to bypass MFA — the vast majority of password-spray attacks abuse legacy auth. Block it with a Conditional Access policy (or Security Defaults), and migrate any application that still requires it.
Do I need Defender for Office 365, or is the built-in protection enough?
Every Microsoft 365 mailbox includes Exchange Online Protection, which handles spam, known malware, spoof intelligence, and the first-contact safety tip. Defender for Office 365 Plan 1 adds Safe Links, Safe Attachments, and impersonation protection, and is included with Microsoft 365 Business Premium and E5. For most small organizations the upgrade is worth it — but you must configure the policies, because turning on the license alone does little. The easiest path is to apply the Standard preset security policy.
How do I know DKIM is really protecting my domain?
Microsoft signs outbound mail with a default key even if you never configure anything, but that is not the same as DKIM for your own domain. Proper DKIM requires publishing the two CNAME selector records for each custom domain and then switching DKIM signing on for that domain in the Defender portal. Until you do that per domain, your mail is not carrying a signature that others can verify as yours.
What DMARC policy should I use, and will it break my newsletters?
Aim for p=reject, but get there in stages. Start at p=none with an rua reporting address so you can see every service that sends as your domain, fix SPF and DKIM for the legitimate ones (including newsletter and marketing platforms), then move to p=quarantine and finally p=reject. If you jump straight to reject without watching the reports, you can block your own legitimate mail — which is why the reporting address matters as much as the policy.
Do I need Microsoft 365 E5 to be well protected?
No. For a small organization, Microsoft 365 Business Premium includes Defender for Office 365 Plan 1 and Entra ID Conditional Access, which cover almost everything on this checklist. E5 adds deeper investigation and hunting tools that larger or higher-risk organizations value, but the controls that stop the most common attacks are available well below that tier. Qualifying nonprofits can obtain Business Premium at a steep discount through Microsoft's nonprofit program.
Want a second opinion on your configuration?
Family Sentinel's Org Guard reviews your Microsoft 365 email posture, watches for the account-takeover signals that hardening is meant to prevent, and reads the intent of messages that pass every built-in check. Read-only, and never able to send or delete.