Microsoft 365 runs the day-to-day work for many Australian small businesses. Email, files, calendars, Teams, invoices, quotes and client documents often all live there.
That makes it a common target for criminals. They are not always trying to hack your computers. Often, they are trying to get into one mailbox, quietly read conversations, and send fake invoices or password reset emails from a real account.
The good news is that a few settings make a big difference. You do not need to be technical to understand what to check. You just need to know what matters and why.
Here are seven Microsoft 365 settings every small business should review.
1. Multi-factor authentication is turned on for everyone
Multi-factor authentication, often called MFA, means a password is not enough on its own. After entering a password, the person also needs to approve the sign-in on their phone or use another second step.
This is one of the most important security settings in Microsoft 365. If a staff member reuses a password, falls for a fake login page, or has their password guessed, MFA can stop the account being taken over.
What to check
- MFA is turned on for every user, not just office staff.
- Admin accounts have MFA without exception.
- Staff are using the Microsoft Authenticator app or another strong method where possible.
- Old or unused phone numbers are removed from user accounts.
SMS codes are better than having no second step, but an authenticator app is usually stronger. For many small businesses, the main goal is simple: no account should be protected by a password alone.
2. Admin accounts are limited and separate
An admin account can make major changes in Microsoft 365. It can add users, reset passwords, change security settings and access sensitive areas.
If a criminal gets into an admin account, the damage can be much worse than a normal mailbox compromise. They may be able to create hidden access, turn off protections, or lock you out.
What to check
- Only the people who truly need admin access have it.
- Day-to-day email accounts are not also used as admin accounts.
- There are at least two trusted admin accounts, so the business is not locked out if one person is unavailable.
- No shared admin logins are being used.
- Former staff, old IT providers and unused accounts have been removed.
A good approach is to use a normal account for everyday work and a separate admin account only when making changes. It is a small inconvenience that can prevent a very large problem.
3. Mailbox forwarding is not sending email outside the business
Mailbox forwarding can automatically send a copy of incoming email to another address. It is useful in some situations, but it is also a common trick used after an account is compromised.
A criminal may set up forwarding so they can keep reading emails even after the password is changed. They may watch for invoices, bank details, legal documents or password reset emails.
What to check
- No mailbox is forwarding to an unknown external email address.
- Forwarding rules created inside Outlook are reviewed.
- External forwarding is blocked unless there is a clear business reason.
- Any approved forwarding is documented and checked regularly.
This check is especially important for accounts used by owners, bookkeepers, finance staff and anyone who receives invoices or client payment details.
4. Sign-in activity is being reviewed
Microsoft 365 records sign-ins to your accounts. This can show where people are logging in from, whether there are repeated failed attempts, and whether something looks unusual.
You do not need to understand every technical detail. You are mainly looking for signs that do not match normal business activity.
What to check
- Sign-ins from countries where your staff do not work.
- Repeated failed login attempts against one account.
- Successful sign-ins at odd hours that do not make sense.
- Users being prompted for MFA over and over.
- Risk warnings, if your Microsoft licence includes them.
Some Microsoft 365 plans provide more detailed alerts than others. Even if your plan is basic, the sign-in logs can still be useful. If something looks wrong, change the password, check MFA, review forwarding rules and get help before assuming it is harmless.
5. File sharing links are not open to anyone
OneDrive and SharePoint make it easy to share files with staff, clients and suppliers. That convenience is valuable, but the wrong sharing settings can expose sensitive information.
The riskiest option is usually an open link that works for anyone who has it. If that link is forwarded, guessed, saved in the wrong place or sent to the wrong person, access can spread beyond your control.
What to check
- The default sharing option is not set to anyone with the link.
- External sharing is limited to what the business actually needs.
- Sensitive folders use specific people links rather than open links.
- Shared links expire after a reasonable time where possible.
- Old sharing links are reviewed and removed when no longer needed.
For many small businesses, a sensible default is to share with specific people, not the whole internet. This still lets you work with clients and suppliers, but it reduces the chance of files being passed around without control.
6. Old sign-in methods are blocked
Some older email apps and devices use outdated sign-in methods. These can be a problem because they may not support modern security checks like MFA.
This is often referred to as legacy authentication, but the plain-English meaning is simple: old ways of logging in can create a gap in your protection.
What to check
- Old email protocols such as POP and IMAP are turned off unless there is a real need.
- SMTP sending is only allowed for approved devices or services that still require it.
- Old phones, scanners, copiers and line-of-business systems are reviewed before changes are made.
- Staff are using current versions of Outlook, Outlook on the web, or supported mobile apps.
Do not switch settings blindly if you rely on older equipment for scanning to email or sending system alerts. Check what is in use first, then replace or reconfigure old setups where needed.
7. Backup and recovery are understood before something goes wrong
Microsoft 365 is a reliable cloud service, but that does not mean every mistake or attack is automatically easy to undo. Deleted files, accidental changes, ransomware, malicious insiders and long-unnoticed mailbox compromise can still cause serious disruption.
Microsoft provides recovery features such as deleted items, version history and retention options, depending on how your environment is set up. Many businesses also choose a separate Microsoft 365 backup service for extra protection and easier restores.
What to check
- You know how long deleted emails and files can be recovered.
- Version history is available for important OneDrive and SharePoint files.
- Critical mailboxes and folders are covered by an agreed backup approach.
- Backups, if used, are separate from the main Microsoft 365 login.
- A test restore has been done, not just assumed.
The key question is not whether you have a product called backup. The key question is whether you can recover the right email, file or folder quickly when the business needs it.
A simple review plan for small businesses
If you are not sure where to start, keep it practical. You do not need a 40-page report before improving your Microsoft 365 security.
Start with these steps:
- List every active user and confirm they still need access.
- Turn on MFA for all users and especially admins.
- Review who has admin rights.
- Check for external mailbox forwarding.
- Look at recent sign-ins for anything unusual.
- Review OneDrive and SharePoint sharing settings.
- Confirm your recovery options for email and files.
After that, set a reminder to review these settings regularly. Quarterly is a good rhythm for many small businesses, and you should also review them whenever staff leave, roles change, or a new supplier needs access.
Why these settings matter
Most small business cyber incidents are not dramatic movie-style hacks. They often start with one password, one fake login page, one forgotten account, or one file shared too widely.
The impact can still be serious: stolen invoices, payment redirection, private client information exposed, business interruption, reputational damage and stressful clean-up work.
These seven settings help reduce that risk. They are not about making technology complicated. They are about putting sensible locks on the systems your business already relies on.
Need help checking your Microsoft 365 setup?
If you are unsure whether your Microsoft 365 settings are safe, JCPIT can help. We work with Australian small businesses and explain the risks in plain English, without the scare tactics or technical waffle.
Book a free security check with JCPIT and we will review the key areas that commonly lead to Microsoft 365 account compromise, including MFA, admin access, forwarding rules, sharing settings and recovery options.
It is a practical way to find the gaps before they become an expensive problem.