How to Configure Microsoft 365 Email Security

How to Configure Microsoft 365 Email Security

A convincing invoice email can reach a busy accounts team at 9:02 am, look like it came from a regular supplier and be actioned before anyone notices one changed letter in the sender address. That is why organisations need to configure Microsoft 365 email security as a connected set of controls, not simply turn on a spam filter and hope for the best.

For small and medium-sized businesses, email protection needs to be strong without becoming a daily productivity problem. The right configuration reduces phishing, malware and account takeover risk while ensuring legitimate customer, supplier and cloud-service emails still arrive where they should.

Start with the account, not the inbox

Most serious email incidents begin with a compromised user account. If an attacker signs in as a staff member, they can read mail, reset passwords for other services, send believable internal requests and create forwarding rules that quietly copy messages outside the business.

Multi-factor authentication should therefore be enabled for every account, particularly administrators, finance staff and users with access to sensitive client information. Microsoft Authenticator is generally a better option than SMS because text messages can be intercepted through number-porting scams. Where possible, use number matching or phishing-resistant methods such as security keys for privileged accounts.

Avoid relying on broad exceptions. A director travelling frequently or a legacy scanner that cannot use modern authentication may need a different solution, but exclusions should be documented, reviewed and kept to a minimum. Conditional Access policies can add another layer by requiring stronger sign-in checks for risky logins, unfamiliar locations or administration portals. The best approach depends on the Microsoft 365 licence in use and how staff work between office, site and home.

Administrator accounts deserve separate treatment. Do not use a day-to-day mailbox as a global administrator account. Create dedicated admin identities, protect them with strong multi-factor authentication and keep at least two emergency access accounts secured under a documented process. This limits the chance that one compromised mailbox gives an attacker control of the whole tenant.

Configure Microsoft 365 email security in layers

Microsoft 365 includes useful baseline protections, but the available features vary between Business Basic, Business Standard, Business Premium and enterprise licensing. Microsoft Defender for Office 365 adds advanced phishing, link and attachment protection. Before applying policies, confirm what the organisation owns so settings match the available capability.

Security Defaults can provide a quick starting point for a small organisation without complex access requirements. Businesses with more detailed needs should normally use Conditional Access and carefully designed policies instead. Running both approaches without planning can create confusion and lock out users at the wrong time.

The email layer should address four common problems: unwanted bulk mail, malicious attachments, unsafe web links and impersonation. Anti-spam policies should be reviewed so quarantined messages are visible to the right people and genuine business mail is not silently discarded. Be cautious with allow lists. Adding an entire external domain or a wide IP range to a bypass list can create a permanent path around your protections.

Anti-phishing policies should be configured to detect impersonation of key people and domains. Add executives, accounts staff, payroll contacts and commonly impersonated external suppliers where appropriate. Enable mailbox intelligence and spoof protection so Microsoft 365 can identify messages that appear to come from your own domain or a trusted partner but fail authentication checks.

For organisations with Defender for Office 365, Safe Links checks web addresses at the time a user clicks them. Safe Attachments opens attachments in a controlled environment before delivery. These controls are particularly valuable because attackers often use previously legitimate websites and newly created files to evade basic filtering.

Authenticate your domain properly

A business can make it much harder for criminals to impersonate its email domain by setting up SPF, DKIM and DMARC. These records work together, but they are not interchangeable.

SPF identifies which mail servers are permitted to send on behalf of your domain. DKIM adds a digital signature to outgoing mail so recipients can verify it has not been altered. DMARC tells receiving systems what to do when a message fails those checks and sends reporting data that exposes unauthorised use of your domain.

This is an area where rushed changes can interrupt legitimate email. Before enforcing a strict DMARC policy, identify every platform that sends as your business: Microsoft 365, website forms, accounting software, marketing platforms, ticketing systems, multifunction printers and cloud applications. Start DMARC in monitoring mode, review the reports, correct any missed senders, then progress towards quarantine or reject. A properly implemented policy improves trust in your outgoing email as well as reducing fraud attempts against your customers.

Stop risky forwarding and outdated sign-in methods

Attackers who gain mailbox access commonly set automatic forwarding rules to an external address. They may then monitor invoices, supplier conversations and password reset emails without raising obvious alarms. External automatic forwarding should be blocked by default, with exceptions approved only where there is a clear operational reason.

Also review inbox rules, delegated mailbox permissions and connected applications. A rule that moves messages to RSS folders, marks them as read or forwards them to unfamiliar addresses is worth investigating. Regular checks are far easier than trying to reconstruct several months of compromised correspondence.

Legacy authentication protocols are another unnecessary exposure. Older protocols often cannot enforce multi-factor authentication and are regularly targeted in password-spraying attacks. Disable legacy authentication unless a specific, tested business requirement remains. If a device or application needs to send email, configure it using a supported, authenticated method rather than leaving a broad legacy exception in place.

Make quarantine useful, not confusing

Strong filters sometimes catch legitimate messages. If staff cannot see or release safe mail through an approved process, they will pressure administrators to weaken policies. If everyone can release anything without oversight, one malicious email can bypass the protection you just configured.

Set clear quarantine permissions based on risk. Users may be able to review low-risk bulk email, while high-confidence phishing and malware detections should remain with IT or authorised administrators. Configure notifications at a sensible frequency and show staff how to report suspicious messages rather than simply deleting them. Reported messages provide useful intelligence and help tune protections over time.

Protect the people who use it

Technology filters many attacks, but users still make decisions at the point of payment, login and document sharing. Short, practical awareness training is more effective than a once-a-year presentation full of technical jargon. Staff should know how to pause and verify an unexpected payment change, a Microsoft 365 sign-in prompt, an urgent gift-card request or a shared-file notification.

Create a simple verification process for financial changes. For example, a supplier banking update should be confirmed using a known phone number from company records, not the number in the email. This one control can prevent a costly business email compromise even when a fraudulent message looks convincing.

Monitor, test and keep improving

Email security is not a set-and-forget task. Review Microsoft 365 security alerts, risky sign-ins, mailbox forwarding events and failed authentication trends. A sudden spike in blocked mail from a supplier may show that their domain has been compromised. Repeated failed logins could indicate a password-spraying campaign before an account is successfully accessed.

Configuration should also be checked after business changes, such as introducing a new website provider, acquiring another business, moving phone systems, onboarding a new cloud application or changing staff responsibilities. These changes often create new sending sources, access requirements and permission risks.

For many businesses, an independent security review is useful because small misconfigurations are easy to miss in a busy environment. EHW Technology can assess Microsoft 365 settings alongside devices, backups, networks and user access, so email security supports the wider continuity plan rather than operating in isolation.

The practical goal is not to make email difficult to use. It is to make a fraudulent message, stolen password or unsafe attachment far less likely to become a costly interruption to your business.

Scroll to Top