Microsoft Secure Score dashboard showing 60.2% score and security posture analysis for small businesses.

Most small business owners don’t find out their Microsoft 365 setup was wrong until something goes wrong. A hacked email account, a ransomware infection, or a former employee still logging in months after they left; these are the moments that make a Microsoft 365 setup checklist for small business feel a lot less like optional reading. The good news is that the tools to prevent most of these scenarios are already included in what you’re paying for. They just aren’t turned on by default.

This post is for business owners who are managing their own Microsoft 365 environment, or who suspect their current setup might have gaps. We work with small businesses across the greater Atlanta area every day, and the same five issues come up with nearly every new client we onboard. None of them require a technical background to understand, and all of them are worth checking today.

1. Multi-factor authentication (MFA)

Multi-factor authentication means that logging into your Microsoft 365 account requires two things: your password, and a second confirmation, usually a code sent to your phone or generated by an authenticator app. Even if someone steals or guesses your password, they can’t get in without that second factor.
We see this turned off constantly. A business will pay for Microsoft 365 for years and never enable MFA because no one told them it wasn’t on by default, and nothing broke. Until it does.

What bad looks like: a single password is the only thing standing between an attacker and your email, your files, and your entire Microsoft environment. Password breaches are so common that credentials from old data leaks are bought and sold cheaply. Your password being strong isn’t enough on its own.

What good looks like: every user in your organization is required to complete MFA when they sign in, especially from a new device or location. The Microsoft Authenticator app is the most seamless way to do this and takes about five minutes per user to set up.

We’ve seen lack of multi-factor authentication alone lead to scenarios where businesses lose $500,000 or more in the span of a day – that’s when they called TekNation. It’s not conjecture, it’s reality. This is the easiest win to keep your business secure and prevent life-changing losses.

2. Microsoft 365 backup

Here is something Microsoft will tell you in their own documentation if you read closely enough: Microsoft is responsible for keeping their services running, but they are not responsible for recovering your data if it gets deleted, corrupted, or encrypted by ransomware. That responsibility falls on you.

Microsoft 365 has some built-in retention and recycle bin features, but they are not a backup. Retention policies are designed for compliance, not recovery. If a user accidentally deletes a folder, or a bad actor with access to your account wipes your SharePoint, the path to getting that data back is much harder without a dedicated backup solution.

What bad looks like: your business is running entirely out of Exchange Online, SharePoint, and Teams with no third-party backup in place. You assume Microsoft is handling it. They are not.

What good looks like: a dedicated Microsoft 365 backup solution running daily automated backups of your email, SharePoint, OneDrive, and Teams data, stored separately from Microsoft’s own infrastructure. Solutions like Dropsuite, which we use for our managed clients through NinjaOne, make this straightforward and affordable.

Recovery matters as much as backup. Before you trust any backup solution, make sure you have actually tested restoring a file from it.

3. Intune device management and compliance policies

Microsoft Intune is the device management platform built into Microsoft 365 Business Premium. It lets you enforce security requirements on every device that accesses your company data, whether that’s a company-owned laptop or a personal phone an employee uses to check email.

Without Intune, you have no visibility or control over what devices are connecting to your environment. An employee could be accessing company files from an unpatched personal laptop running outdated software, and you would never know. This means users can download all company data to their own personal devices, completely uninhibited, and stakeholders have no way to stop it. Worse yet, device theft could lead to catastrophic breaches without encryption enforced.

What bad looks like: your Microsoft 365 licenses are active, but Intune is untouched. Any device, from anywhere, meeting any security standard (or none at all), can connect to your company data as long as it has valid credentials.

What good looks like: Intune compliance policies require that devices be encrypted, up to date on patches, and free of known threats before they’re allowed access. If a device doesn’t meet those requirements, access is blocked until it does. You can also remotely wipe a device if it’s lost or stolen, which matters a great deal when an employee leaves unexpectedly.

Most business owners are shocked when we show them how device deployment and management – from laptops, desktops, iPhones, and more – looks when Intune is configured properly. Company data is under lock and key to prevent exfiltration, but never gets in the way of workflows. Automation turns hours-long device setups into a few seconds spent logging in and simply letting it configure itself – it’s like magic. No one ever has questions about why things are different between devices, because it’s all standardized and no one has to remember a laundry list of apps to download, sign in to, and configure. This could be your business too!

4. Admin account separation and least privilege

Every Microsoft 365 tenant has at least one Global Administrator account. That account has the keys to everything: user management, billing, security settings, mail flow, the works. Most small businesses set this up once and then use it as their everyday account, often for years.

This is one of the highest risk habits we see in small business Microsoft 365 environments. A Global Admin account that gets compromised doesn’t just expose email. It gives an attacker the ability to lock you out of your own environment, create new accounts, change security settings, and exfiltrate everything before you even notice.

What bad looks like: the business owner has one account that is both their daily email and a Global Admin. They use it to send invoices, approve expense reports, and occasionally add a new user. It has no extra protections beyond a password.

What good looks like: Global Admin accounts are separate from daily-use accounts, have their own dedicated credentials, and are protected with MFA and strong password requirements. Daily work happens from a standard user account with only the permissions needed for that person’s role. This is called least privilege, and it is one of the most effective and underutilized protections in Microsoft 365.

You should also audit who has admin roles in your tenant right now. We routinely find old employees, former IT vendors, or misconfigured accounts still holding admin rights on tenants we’re brought in to review. There is a litany of ways this could be implemented – partner relationships, Global Admin accounts, or even guest accounts with administrative privileges.

5. Security defaults vs. custom Conditional Access

Microsoft 365 includes a feature called Security Defaults, which is a set of baseline security policies Microsoft turns on automatically for newer tenants. It enforces MFA, blocks legacy authentication protocols, and adds some basic protections. For a business that has done nothing else on this list, Security Defaults is better than nothing.

Conditional Access is the next level up. Think of it as a set of rules that decide whether someone gets into your Microsoft 365 environment based on context, not just a correct password. Who is signing in? From what device? From what location? At what time? Conditional Access lets you define exactly what “allowed” looks like and block everything that doesn’t meet that standard.

Security Defaults can’t do any of that. It’s a single switch with no flexibility. You cannot exclude a specific user, allow access from a trusted office location without an extra prompt, or apply different rules to different roles in your organization.

What bad looks like: Security Defaults is on and the business assumes their security configuration is complete. They don’t realize it offers no granular control, and they don’t know it can conflict with other settings as their environment grows.

What good looks like: Conditional Access policies, available in Microsoft Entra ID (included with Microsoft 365 Business Premium), replace Security Defaults with a purpose-built policy set tailored to how your business operates. Require MFA for all users, block sign-ins from high-risk locations, enforce compliant device requirements, and apply different rules to different groups. This is the right Microsoft 365 security settings small business foundation for any organization that takes security seriously.

The transition from Security Defaults to Conditional Access requires care. If it’s done wrong, you can accidentally lock users out of their accounts. This is one of the areas where working with someone who configures these regularly makes a real difference.

Where does your setup stand?

These five items represent the foundation of a secure M365 Business Premium setup. They are not the finish line, but they are the starting point we use when evaluating every new client environment.

Run through them honestly:

  • Is MFA enforced for every user in your organization?
  • Do you have a third-party backup solution running daily?
  • Is Intune deployed with active compliance policies?
  • Do your admin accounts exist separately from daily-use accounts? Do you know who all has admin privileges to your business?
  • Have you moved beyond Security Defaults to a real Conditional Access policy set?

 

If you answered no to any of these, your environment has gaps that attackers actively look for. Most of the businesses we work with had at least three of these unchecked when we first met them. That’s not a failure on their part. Microsoft doesn’t make these easy to find or set up without context.

Ready to know where you actually stand?

If you’re a small business in the Douglasville area and you’re not sure how your Microsoft 365 environment measures up, TekNation offers a free security and best practices review. Here’s what that looks like: we connect to your tenant read-only, spend about 30 minutes reviewing your configuration against this checklist, and send you a plain-English summary of what’s configured correctly, what’s missing, and what’s worth prioritizing. No sales pressure, no access retained after the review, and no obligation to become a client.

If something we find is a quick fix, we’ll tell you how to address it yourself. If it’s more involved and you want help, we’re here for that too.

Contact TekNation to schedule your free review.