Microsoft 365 security is more than a password
For many businesses, Microsoft 365 contains email, files, identities, collaboration tools, and access to other business systems. Protecting the Microsoft 365 tenant is therefore an important part of protecting the business.
Require multi-factor authentication
Multi-factor authentication should be a baseline for user accounts, particularly administrators and people with access to sensitive business information.
Limit administrative privileges
Global Administrator and other powerful roles should be assigned only when necessary. Administrative work should be separated from ordinary email and browsing where practical.
Review sign-ins and old accounts
Unused accounts, stale guest users, old forwarding rules, suspicious sign-ins, and unnecessary application access should be reviewed periodically.
Improve email protection
Phishing, malicious attachments, impersonation, and fraudulent payment requests are common business risks. Configure the available email protections and train employees on how to report suspicious messages.
Plan for recovery
Understand what Microsoft protects as part of the service and what your organization is responsible for. Decide whether additional backup and recovery capabilities are appropriate for your business.
Treat identity as part of the network
Cloud identity is now a core security boundary. Those Computer Guys can help with Microsoft 365 administration, identity security, email protection, migrations, and related cloud planning.