Start with identity and access
Every person should have an individual account. Shared sign-ins make it difficult to protect information, understand activity or remove access cleanly when responsibilities change. Require multi-factor authentication and apply stronger controls to administrators, finance functions and anyone handling sensitive principal information.
Administrative accounts should be separate from ordinary email accounts and used only when necessary.
Manage the devices that connect
Laptops and phones are part of the Microsoft 365 security boundary. Establish a minimum standard for encryption, supported operating systems, screen locks and security updates. Device management can help apply those controls consistently and remove business information if a device is lost.
Personal devices require an explicit decision: either manage them appropriately or restrict what they can access.
Control sharing and information movement
Review how files are shared through SharePoint, OneDrive and Teams. External links should expire where practical, sensitive material should be limited to named recipients, and broad anonymous sharing should be used sparingly.
Mailbox forwarding rules and third-party applications also deserve attention. Both can move information outside the organisation without being obvious to everyday users.
Prepare for mistakes and incidents
Microsoft provides resilience within its services, but retention and recovery settings still need to match the office’s requirements. Decide how long deleted email and files must remain recoverable and whether an additional backup is appropriate.
Document the first actions for a compromised account, lost device or suspicious payment request. Test contact details and responsibilities before an urgent situation occurs.
A CONSIDERED NEXT STEP
Review the whole environment.
Technology risks rarely sit in isolation. A short review can identify priorities across people, devices, accounts, connectivity and recovery.
Request an introduction