Microsoft 365 security matters more than most NZ small businesses realise, because default settings are built for convenience, not protection. Out of the box, a Microsoft 365 tenant leaves several doors wider open than most business owners would choose.
This guide walks through the practical steps that make up proper Microsoft 365 security hardening, without requiring a background in IT. If your business runs on Microsoft 365 and hasn’t reviewed its settings recently, Mi-IT can carry out a full security review for you.
1. Why Microsoft 365 Security Needs Extra Attention
Microsoft 365 is one of the most common targets for cybercriminals, simply because so many businesses run on it. A single compromised account can expose email, files, calendars and Teams conversations all at once, giving an attacker a remarkably complete picture of your business.
Default Microsoft 365 security settings prioritise ease of setup over protection. That means most tenants are running with gaps that Microsoft itself recommends closing, but few small businesses ever get around to it, often because nobody has explicitly taken ownership of the task.
The good news is that most of the fixes are quick, don’t require specialist tools, and make a meaningful difference almost immediately.

2. Enable Multi-Factor Authentication for Every User
Multi-factor authentication is the single most important step in Microsoft 365 security. Without it, a stolen password is often all an attacker needs to access your entire business.
Enable MFA for every user, including admin accounts, which should always carry the strongest protection available. Microsoft’s own security reporting shows accounts with MFA enabled are dramatically less likely to be compromised than those without it.
Use the Microsoft Authenticator app rather than SMS-based codes where possible, since text messages can be intercepted more easily than app-based approvals. Rolling MFA out in stages, starting with admin and finance accounts, helps avoid overwhelming staff all at once.
By contrast, a minor internal mix-up with no real risk of harm, like an email briefly sent to the wrong internal team member and immediately recalled, usually won’t meet the threshold. When in doubt, it’s safer to assess formally rather than assume it doesn’t count.
3. Turn On Conditional Access Policies
Conditional access lets you control exactly when and how users can sign in, adding a smarter layer on top of basic MFA. This feature is available on most Microsoft 365 Business Premium and above plans.
Common policies include blocking sign-ins from unexpected countries, requiring a managed device for access to sensitive data, and forcing MFA whenever a login looks unusual. Microsoft’s own documentation provides templates that make setup far easier than configuring policies from scratch.
4. Configure Anti-Phishing and Anti-Spam Protection
Phishing remains the most common way attackers gain access to Microsoft 365 accounts. Default spam filtering catches some threats, but not all of the more convincing, targeted attempts that are specifically crafted to bypass basic filters.
Phishing remains the most common way attackers gain access to Microsoft 365 accounts. Default spam filtering catches some threats, but not all of the more convincing, targeted attempts that are specifically crafted to bypass basic filters.
Enable Microsoft Defender’s anti-phishing policies, which flag impersonation attempts and suspicious sender behaviour that basic spam filters often miss. Pay particular attention to policies that detect domain and display name impersonation, since these are commonly used to mimic trusted suppliers or executives.
Combine this with clear staff guidance on reporting suspicious emails, so genuine threats get flagged quickly rather than quietly ignored or forwarded on to colleagues.
5. Restrict Legacy Authentication Protocols
Legacy authentication methods don’t support modern security features like MFA, which makes them a favourite target for automated attacks. Many businesses still have them enabled without realising it.
Disable legacy authentication across your Microsoft 365 tenant wherever possible. This single change closes off one of the most commonly exploited weaknesses in poorly configured tenants, often with no noticeable impact on day-to-day staff use.
Are you looking for a reliable Managed IT Support and Services Provider in Auckland?
Mi-IT is a leading, New Zealand owned Managed IT Support and Services provider. We support our clients in their business goals through reliable and scalable solutions.
6. Set Up Data Loss Prevention (DLP) Policies
Data loss prevention policies help stop sensitive information, like financial details or customer records, from being accidentally shared outside the business. This matters as much for compliance as it does for security, and it’s often overlooked entirely by small business tenants.
Set up basic DLP rules to flag or block emails containing sensitive data patterns, such as credit card numbers or IRD numbers, before they leave your organisation. Start with a small number of high-value rules rather than trying to cover every possible scenario at once.
This directly supports Privacy Act 2020 compliance by reducing the risk of accidental disclosure, which is one of the more common causes of notifiable privacy breaches.
7. Manage Admin Roles and Privileged Access
Admin accounts carry far more risk than standard user accounts, since a compromised admin account can affect the entire business, not just one person.
Limit the number of Global Administrator accounts to as few as genuinely necessary, and use role-based access for anything beyond that. Most staff who need elevated permissions only need access to a specific area, like Exchange or SharePoint, rather than full administrative control over everything.
Review who holds admin access at least twice a year, removing it promptly whenever a role changes or someone leaves the business. Consider using dedicated admin accounts, separate from everyday email accounts, so admin access isn’t exposed every time someone checks their inbox.
8. Enable Mailbox Auditing and Alerts
Without auditing enabled, it’s difficult to know exactly what happened during a security incident, or even to confirm one occurred at all. This makes response and recovery far slower.
Turn on mailbox auditing to track sign-ins, forwarding rule changes, and file access. Set up alerts for suspicious activity, like a sudden spike in failed logins or a new forwarding rule appearing on an executive’s inbox, both common signs of a compromised account.
This is a commonly missed requirement, and one regulators are paying closer attention to as more small businesses adopt overseas software by default.
9. Train Staff on Microsoft 365-Specific Threats
Even strong Microsoft 365 security settings can be undone by a single staff member falling for a convincing phishing email. Technology alone can’t close every gap, especially when attackers specifically design their tactics around Microsoft 365 workflows.
Show staff what a genuine Microsoft 365 login prompt looks like compared to a fake one, since credential-harvesting pages are often near-identical copies of the real thing. Cover common tactics like fake shared-document notifications and urgent password-reset requests, both frequently used to trick users into entering credentials on a fraudulent page.
CERT NZ publishes current examples of Microsoft 365 phishing attempts specifically targeting New Zealand businesses, which makes excellent, locally relevant training material.
Frequently asked questions
1. Are the default Microsoft 365 security settings good enough?
No. Default settings are designed for ease of use, not maximum protection. Most small businesses need to actively enable several additional security features to reach a safe baseline.
2. Do I need Microsoft 365 Business Premium for proper security?
Business Premium unlocks features like conditional access and advanced threat protection that lower-tier plans don’t include. For businesses handling sensitive customer data, it’s generally worth the upgrade.
3. How long does Microsoft 365 security hardening take?
Most of the core steps in this guide can be completed within a day for a small business tenant. Ongoing monitoring and periodic review, however, should continue indefinitely.
4. Can Microsoft 365 security hardening affect staff productivity?
Done well, it shouldn’t. Most changes, like MFA and conditional access, add only minor friction for legitimate sign-ins while significantly reducing risk from compromised accounts.
5. What’s the biggest Microsoft 365 security mistake small businesses make?
Leaving legacy authentication enabled and skipping MFA on admin accounts are two of the most common and damaging oversights. Both are quick to fix once identified.
6. Does Microsoft 365 security hardening help with Privacy Act 2020 compliance?
Yes. Features like data loss prevention and mailbox auditing directly support the reasonable security expectations set out in the Privacy Act 2020.
7. How often should we review our Microsoft 365 security settings?
At least twice a year, and immediately after any significant staff or role changes. Microsoft also regularly updates available security features, so periodic reviews help you take advantage of new protections.
8. Can Mi-IT handle Microsoft 365 security hardening for us?
Yes. Mi-IT reviews and hardens Microsoft 365 tenants for NZ small businesses, covering every step in this guide. Get in touch for a free Microsoft 365 security review.
Final Thoughts: Making Microsoft 365 Security a Standard, Not an Afterthought
Microsoft 365 security hardening isn’t a one-time project. New threats and features both emerge regularly, and your settings should evolve alongside them.
Pair this guide with your broader cybersecurity basics playbook for a complete view of where your business stands.
Mi-IT helps NZ small businesses harden Microsoft 365 and keep it that way. Visit www.miit.co.nz or our contact page to book a free Microsoft 365 security review.


