Most small and medium businesses in Greater Manchester run their entire operation through Microsoft 365 — email, files, Teams calls, the lot. It's reliable and easy to use, which is exactly why so few business owners stop to check whether it's actually secure. The uncomfortable truth is that out of the box, Microsoft 365 is set up for convenience, not protection. Attackers know this, and stolen or guessed passwords into 365 accounts are one of the most common ways criminals get a foothold in SME networks. The good news is that closing most of the obvious gaps doesn't take much time or money — it just takes knowing where to look.
Why Microsoft 365 is a target
Microsoft 365 accounts are valuable to criminals because one login often unlocks everything: email, invoices, customer data, and access to other connected systems. A compromised account can be used to send convincing phishing emails to your customers, redirect bank payments, or quietly sit and read your mail for weeks before doing anything. Because so many businesses use the same platform, attackers have well-tested playbooks for breaking in — and they're constantly scanning for accounts without basic protections switched on.
Turn on multi-factor authentication
If you do nothing else, do this. Multi-factor authentication (MFA) means a stolen password alone isn't enough to get into an account — the attacker also needs a code from the user's phone or authenticator app. Microsoft's own data shows MFA blocks the vast majority of automated account takeover attempts. Despite this, it's still common to find SME tenants where MFA is optional or only applied to a handful of users. It should be mandatory for everyone, including the owner and any part-time or seasonal staff.
Review who has admin access
Global admin rights in Microsoft 365 are powerful — they can reset passwords, change security settings, and access any mailbox. Over time, businesses tend to accumulate more admin accounts than they need, often because it was quicker to grant full access than to work out the right permission level. Every extra admin account is another door for an attacker to try. Review the list regularly, remove anyone who doesn't need it, and use standard user accounts for day-to-day work even if someone technically has admin rights.
Set up conditional access and device policies
Conditional access lets you set rules around how and where accounts can be used — for example, blocking sign-ins from countries you don't operate in, or requiring a managed, up-to-date device before someone can access company email. This is available in Business Premium licensing and is one of the most underused features in SME tenants. Combined with mobile device management, it stops company data being accessed from a personal phone that's never had a security update.
Train staff to spot phishing
Technical controls only go so far if someone is tricked into handing over their password on a convincing fake login page. Phishing emails targeting Microsoft 365 users have become far more sophisticated, often mimicking real Microsoft notifications down to the branding and formatting. Short, regular training — even just a few minutes a month — makes a measurable difference to how many staff report suspicious emails rather than clicking them.
Keep an eye on sign-in logs
Microsoft 365 keeps a record of every sign-in, including the location and device used. Reviewing these logs — or better, setting up automated alerts for unusual activity like a sign-in from an unexpected country — means you can catch a compromised account within minutes rather than discovering it weeks later when a customer calls asking why they've been invoiced twice.
Back up your data separately
It's a common misconception that Microsoft backs up your 365 data for you. In reality, Microsoft's responsibility ends at keeping the service running — if a user deletes a file, an account gets encrypted by ransomware, or an email gets removed by mistake, recovery is down to you. A proper third-party backup for mail, files and Teams data is essential, not optional.
Locking down Microsoft 365 properly means working through licensing options, configuring policies correctly, and keeping on top of them as the business changes — which is exactly the kind of ongoing work that's easy to let slip when you're busy running a business. Valetech Solutions manages Microsoft 365 security for SMEs across Greater Manchester as part of our cybersecurity and IT support services, making sure the basics are done properly and staying on top of new threats as they emerge. Get in touch with Valetech Solutions to have your Microsoft 365 setup reviewed.