Microsoft 365 includes several security controls that stay switched off or loosely configured by default: conditional access, tenant-wide MFA enforcement, sensitivity labels, audit log retention, admin role restrictions, and external mail forwarding blocks. None of these require an upgraded plan for most businesses. They need someone to actually turn them on and set them up correctly.

1. Conditional access

Conditional access lets you set rules like “block sign-ins from outside the U.S.” or “require MFA when logging in from an unrecognized device,” without manually managing individual account restrictions. It’s one of the highest-impact security tools most businesses don’t know they have, and it works alongside the protections covered in multi-factor authentication, explained for business owners.

2. MFA enforced tenant-wide, not just enabled

Enabling MFA and enforcing it are different things. A lot of tenants have MFA technically available but not required for every account, which leaves the door open on exactly the accounts an attacker would target first. Enforcing it tenant-wide closes that gap in one setting change.

3. Sensitivity labels

Sensitivity labels let you mark documents as confidential or restricted, controlling who can view, edit, print, or forward them, even after the file leaves your network. For businesses handling client contracts, financial data, or information covered under CMMC and NIST compliance requirements, this closes a real gap most file-sharing setups leave wide open.

4. Audit log retention

By default, many tenants retain audit logs for a short window, sometimes too short to reconstruct what happened during a security incident that isn’t discovered right away. Extending retention costs little and matters a lot the one time you actually need it.

5. Admin role restrictions

Global admin access handed out broadly, because it was easier during setup, is one of the most common findings in a security review. Scoping admin roles down to what each person actually needs limits how much damage a single compromised account can do.

6. Blocking external mail auto-forwarding

Attackers who compromise a mailbox often set up a quiet forwarding rule to siphon email to an outside address. Blocking automatic forwarding to external domains by default closes one of the most common ways a breach stays hidden.

Why these stay off by default

Most tenants get configured during onboarding with a focus on getting people working, not locking things down. Security settings get left for “later,” which quietly turns into never. This is one of the most common gaps found during a Microsoft 365 migration review, and every one of these six is a fast fix once someone flags it.

If you’re not sure which of these six are actually turned on in your tenant, a free IT review covers exactly that.

These settings are part of the cloud and Microsoft 365 support covered in our full managed IT overview.

Frequently asked questions

Do these settings require a plan upgrade?

Most are included in standard Business Standard and Business Premium plans. Sensitivity labels and some advanced conditional access rules may require Business Premium or an add-on, depending on your current plan.

How long does it take to configure all six?

For most small business tenants, a knowledgeable IT provider can review and configure all six in a single focused session, typically under a few hours.