Skip to main content

5 Microsoft 365 Settings Every Small Business Should Review

Microsoft 365 Small Business

Microsoft has made significant security improvements to Microsoft 365 over the past several years. The challenge for many small businesses is that these improvements often apply only to newly created Microsoft 365 environments.

If your Microsoft 365 tenant was set up several years ago, configured by a previous IT provider, or simply hasn't been reviewed recently, you may still be operating with legacy settings that could expose your business to unnecessary security risks.

The good news? A few simple reviews can help ensure your small business is getting the maximum protection from Microsoft 365.

Here are five Microsoft 365 settings every small business should check.


1. File Sharing Settings in SharePoint and OneDrive

File sharing is one of the most common ways employees collaborate, but it's also one of the most overlooked security settings in Microsoft 365.

Many older Microsoft 365 environments still allow users to create sharing links that work for "Anyone with the link." That means files can potentially be accessed without requiring a sign-in, and links can be forwarded to people outside your organization.

For small businesses, this can create risks involving:

  • Customer information
  • Financial documents
  • Contracts
  • Proposals
  • Internal business records

What to Check

Review the default sharing settings in SharePoint and OneDrive.

Whenever possible, configure sharing links to require authentication and limit access to specific users.

You should also review whether anonymous sharing links are permitted and whether those links have expiration dates.

Why It Matters

Many small businesses discover that files shared years ago are still accessible through old links that nobody remembers creating.


2. External Email Forwarding Rules

Microsoft has strengthened protections against automatic email forwarding because cybercriminals frequently use forwarding rules to steal sensitive information.

However, older forwarding rules may still exist within your organization.

For example, a former employee may have created a rule that automatically forwards company email to a personal Gmail account years ago.

What to Check

Verify that automatic external email forwarding is disabled at the tenant level.

Also review mailbox rules to identify any existing forwarding configurations that send company emails outside the organization.

Why It Matters

For small businesses, unauthorized email forwarding can lead to:

  • Data leaks
  • Privacy concerns
  • Compliance issues
  • Business email compromise risks

Many organizations have no idea these rules exist until they conduct an audit.


3. Third-Party Applications Connected to Microsoft 365

Over time, employees often connect third-party applications to Microsoft 365 to improve productivity or solve a temporary business problem.

The issue is that those applications may retain access long after they're no longer being used.

Some apps can access:

  • Email
  • Calendars
  • OneDrive files
  • SharePoint documents
  • User profile information

What to Check

Review the list of connected applications in Microsoft Entra ID.

Look for applications that:

  • Are no longer used
  • Were installed for one-time projects
  • Cannot be identified
  • Have excessive permissions

Why It Matters

Many small businesses discover dozens of unused applications with ongoing access to corporate data.

Removing unnecessary access helps reduce risk and improves overall security.


4. Audit Log Retention

Audit logs track important activity throughout your Microsoft 365 environment.

These logs can show:

  • User sign-ins
  • File access
  • Permission changes
  • Configuration changes
  • Security events

While Microsoft increased standard audit log retention periods in recent years, your business needs may require longer retention.

What to Check

Review your current audit retention settings and compare them to your business requirements.

This is particularly important for small businesses operating in:

  • Healthcare
  • Legal services
  • Financial services
  • Professional services
  • Regulated industries

Why It Matters

If a security incident occurs, audit logs can provide critical information for investigations.

Without sufficient retention, important evidence may no longer be available when you need it.


5. Multifactor Authentication (MFA) Enforcement

If there's one Microsoft 365 setting every small business should verify immediately, it's MFA.

Microsoft now encourages and increasingly requires MFA for many administrative functions. However, older Microsoft 365 environments can still contain gaps.

It's not uncommon to find:

  • Some employees protected by MFA
  • Others excluded by mistake
  • Legacy administrator accounts without MFA
  • Incomplete Conditional Access policies

What to Check

Review:

  • Security Defaults settings
  • Conditional Access policies
  • Administrator accounts
  • Emergency access accounts
  • User MFA enrollment status

Make sure all users, especially administrators, are adequately protected.

Why It Matters

For small businesses, compromised credentials remain one of the leading causes of ransomware incidents, data breaches, and cyber insurance claims.

MFA is one of the simplest and most effective ways to reduce that risk.


A Smart Order for Small Businesses

Not every change needs to happen at once.

A practical order is:

First

Review third-party application access and audit log retention.

These changes typically have little or no impact on employees.

Second

Check external email forwarding settings.

Most small businesses can make these changes with minimal disruption.

Third

Review SharePoint and OneDrive sharing settings.

Communicate planned changes to employees beforehand to avoid confusion.

Finally

Review MFA and Conditional Access policies.

These controls provide significant security benefits but should be implemented carefully to avoid locking users out of business-critical systems.


Final Thoughts

Microsoft has done an excellent job improving Microsoft 365 security over the years, but many small businesses assume those improvements automatically apply to older environments.

They often don't.

If your Microsoft 365 tenant hasn't been reviewed recently, now is the perfect time to verify these five settings. A short audit today could help your small business prevent security issues, improve compliance, and better protect valuable company data.

For many small businesses, these five checks represent some of the highest-value security improvements you can make without purchasing any new software.

How Small Businesses Can Answer Cyber Insurance Qu...