
Microsoft has made significant security improvements to Microsoft 365 over the past several years. The challenge for many small businesses is that these improvements often apply only to newly created Microsoft 365 environments.
If your Microsoft 365 tenant was set up several years ago, configured by a previous IT provider, or simply hasn't been reviewed recently, you may still be operating with legacy settings that could expose your business to unnecessary security risks.
The good news? A few simple reviews can help ensure your small business is getting the maximum protection from Microsoft 365.
Here are five Microsoft 365 settings every small business should check.
1. File Sharing Settings in SharePoint and OneDrive
File sharing is one of the most common ways employees collaborate, but it's also one of the most overlooked security settings in Microsoft 365.
Many older Microsoft 365 environments still allow users to create sharing links that work for "Anyone with the link." That means files can potentially be accessed without requiring a sign-in, and links can be forwarded to people outside your organization.
For small businesses, this can create risks involving:
- Customer information
- Financial documents
- Contracts
- Proposals
- Internal business records
What to Check
Review the default sharing settings in SharePoint and OneDrive.
Whenever possible, configure sharing links to require authentication and limit access to specific users.
You should also review whether anonymous sharing links are permitted and whether those links have expiration dates.
Why It Matters
Many small businesses discover that files shared years ago are still accessible through old links that nobody remembers creating.
2. External Email Forwarding Rules
Microsoft has strengthened protections against automatic email forwarding because cybercriminals frequently use forwarding rules to steal sensitive information.
However, older forwarding rules may still exist within your organization.
For example, a former employee may have created a rule that automatically forwards company email to a personal Gmail account years ago.
What to Check
Verify that automatic external email forwarding is disabled at the tenant level.
Also review mailbox rules to identify any existing forwarding configurations that send company emails outside the organization.
Why It Matters
For small businesses, unauthorized email forwarding can lead to:
- Data leaks
- Privacy concerns
- Compliance issues
- Business email compromise risks
Many organizations have no idea these rules exist until they conduct an audit.
3. Third-Party Applications Connected to Microsoft 365
Over time, employees often connect third-party applications to Microsoft 365 to improve productivity or solve a temporary business problem.
The issue is that those applications may retain access long after they're no longer being used.
Some apps can access:
- Calendars
- OneDrive files
- SharePoint documents
- User profile information
What to Check
Review the list of connected applications in Microsoft Entra ID.
Look for applications that:
- Are no longer used
- Were installed for one-time projects
- Cannot be identified
- Have excessive permissions
Why It Matters
Many small businesses discover dozens of unused applications with ongoing access to corporate data.
Removing unnecessary access helps reduce risk and improves overall security.
4. Audit Log Retention
Audit logs track important activity throughout your Microsoft 365 environment.
These logs can show:
- User sign-ins
- File access
- Permission changes
- Configuration changes
- Security events
While Microsoft increased standard audit log retention periods in recent years, your business needs may require longer retention.
What to Check
Review your current audit retention settings and compare them to your business requirements.
This is particularly important for small businesses operating in:
- Healthcare
- Legal services
- Financial services
- Professional services
- Regulated industries
Why It Matters
If a security incident occurs, audit logs can provide critical information for investigations.
Without sufficient retention, important evidence may no longer be available when you need it.
5. Multifactor Authentication (MFA) Enforcement
If there's one Microsoft 365 setting every small business should verify immediately, it's MFA.
Microsoft now encourages and increasingly requires MFA for many administrative functions. However, older Microsoft 365 environments can still contain gaps.
It's not uncommon to find:
- Some employees protected by MFA
- Others excluded by mistake
- Legacy administrator accounts without MFA
- Incomplete Conditional Access policies
What to Check
Review:
- Security Defaults settings
- Conditional Access policies
- Administrator accounts
- Emergency access accounts
- User MFA enrollment status
Make sure all users, especially administrators, are adequately protected.
Why It Matters
For small businesses, compromised credentials remain one of the leading causes of ransomware incidents, data breaches, and cyber insurance claims.
MFA is one of the simplest and most effective ways to reduce that risk.
A Smart Order for Small Businesses
Not every change needs to happen at once.
A practical order is:
First
Review third-party application access and audit log retention.
These changes typically have little or no impact on employees.
Second
Check external email forwarding settings.
Most small businesses can make these changes with minimal disruption.
Third
Review SharePoint and OneDrive sharing settings.
Communicate planned changes to employees beforehand to avoid confusion.
Finally
Review MFA and Conditional Access policies.
These controls provide significant security benefits but should be implemented carefully to avoid locking users out of business-critical systems.
Final Thoughts
Microsoft has done an excellent job improving Microsoft 365 security over the years, but many small businesses assume those improvements automatically apply to older environments.
They often don't.
If your Microsoft 365 tenant hasn't been reviewed recently, now is the perfect time to verify these five settings. A short audit today could help your small business prevent security issues, improve compliance, and better protect valuable company data.
For many small businesses, these five checks represent some of the highest-value security improvements you can make without purchasing any new software.