MICROSOFT 365 SECURITY EXPLAINED

Microsoft 365 security is more than switching on MFA.

Microsoft 365 brings email, identities, files, collaboration and business applications together in one cloud environment.

Securing it requires coordinated controls across users, administrators, devices, email, data, sharing, monitoring and recovery.

Microsoft 365 Security Areas

01

Identity & Authentication

02

Administrator Security

03

Email Protection

04

Device Security

05

Data Protection

06

Backup & Recovery

07

Monitoring & Response

08

Governance & Lifecycle

Shared Responsibility

Microsoft operates the cloud. Your business still controls its users, access and data.

Microsoft protects the underlying cloud service, but your organisation remains responsible for how accounts, permissions, devices and business information are configured and managed.

A secure tenant depends on both technical settings and repeatable business processes.

Your organisation is responsible for

User identities and authentication
Administrator roles and permissions
Device access and compliance
External sharing and guest users
Business data and recovery requirements
Security alerts and incident response
Onboarding and offboarding
Core Security Areas

Eight areas working together.

Microsoft 365 security is strongest when identity, devices, email, data and operational processes are managed together.

01

Identity & Authentication

Protect every Microsoft 365 account with strong authentication, controlled sign-in policies and secure password-reset processes.

Why it matters

Most Microsoft 365 incidents begin with a compromised user account. Strong identity controls reduce the chance that a stolen password results in business access.

02

Administrator Security

Restrict privileged roles, separate administrator accounts from daily-use accounts and review elevated access regularly.

Why it matters

Administrator accounts can change security settings, access data and control the tenant. Limiting privileged access reduces the potential impact of compromise.

03

Email Protection

Use anti-phishing, anti-spam, impersonation protection, safe-link and attachment controls appropriate to your Microsoft 365 licensing.

Why it matters

Email remains one of the most common ways attackers steal credentials, deliver malware and attempt payment fraud.

04

Device Security

Protect computers and mobile devices through endpoint security, encryption, updates, device management and compliance controls.

Why it matters

A secure cloud account can still be exposed when users access it from an unmanaged, outdated or compromised device.

05

Data Protection

Control access to SharePoint, OneDrive, Teams and email using appropriate permissions, sharing restrictions and information-protection controls.

Why it matters

Microsoft 365 contains customer, employee, financial and operational information that must remain accessible only to authorised people.

06

Backup & Recovery

Define how Exchange Online, OneDrive and SharePoint data will be protected and recovered following deletion, compromise or operational disruption.

Why it matters

Cloud availability does not remove the organisation's responsibility for its identities and data. Recovery requirements should be documented and tested.

07

Monitoring & Response

Review security alerts, audit activity, risky users, unusual sign-ins and important administrative changes.

Why it matters

Security controls are more effective when suspicious activity is identified, investigated and acted on quickly.

08

Governance & Lifecycle

Maintain clear onboarding, offboarding, guest-user, access-review, licence-management and security-governance processes.

Why it matters

Microsoft 365 security weakens over time when old accounts, excessive permissions and unmanaged external access are not reviewed.

Identity First

Protect accounts before attackers use them.

Microsoft Entra Conditional Access can evaluate signals such as users, devices, locations and risk before granting access.

Smaller organisations without the required licensing may use Security Defaults as a simpler starting point for identity protection.

Identity controls to review

MFA enforced for users and administrators
Conditional Access or Security Defaults configured
Legacy authentication restricted
Separate privileged administrator accounts
Emergency-access accounts protected
Self-service password reset configured appropriately
Risky sign-ins and risky users reviewed
Inactive and former-user accounts removed
Email Security

Protect your people from phishing and impersonation.

Email security should combine Microsoft 365 protection policies, domain authentication and employee awareness.

No single control stops every malicious message, so prevention, reporting, monitoring and response must work together.

Email controls to review

SPF configured correctly
DKIM enabled for business domains
DMARC implemented and monitored
Anti-phishing policies configured
Impersonation protection reviewed
External forwarding restricted
Mailbox rules and alerts monitored
Suspicious-email reporting available to users

Data and sharing controls

SharePoint external sharing reviewed
OneDrive sharing restrictions defined
Guest-user access reviewed
Shared mailboxes assigned correctly
Sensitive information access limited
Retention requirements documented
Data export and recovery requirements defined
Business ownership of important sites documented
Data Protection

Collaboration should not mean uncontrolled access.

SharePoint, OneDrive and Teams make collaboration easier, but external sharing, guest users and inherited permissions require regular review.

Important business data should have a clear owner, an approved storage location and appropriate recovery requirements.

Microsoft Secure Score

Use Secure Score as a guide, not a finish line.

Microsoft Secure Score measures the extent to which recommended security actions have been completed across areas such as identity, devices, applications and data.

Prioritise

Start with relevant high-impact recommendations rather than focusing only on the overall percentage.

Validate

Confirm that settings genuinely protect the intended users, devices and scenarios.

Review

Reassess regularly as Microsoft 365, licensing, users and business risks change.

Secure Score does not mean

The tenant cannot be compromised
Every policy is correctly targeted
All business risks have been addressed
Security Improvement Path

Improve Microsoft 365 one controlled step at a time.

01

Basic Protection

Establish MFA, administrator controls, email protection, supported devices and reliable recovery.

02

Managed Security

Introduce Conditional Access, device management, structured sharing controls and regular access reviews.

03

Monitored Security

Review Secure Score, audit events, security alerts, risky sign-ins and device health consistently.

04

Governed Security

Maintain documented ownership, policies, lifecycle processes, incident response and regular security reassessment.

Common Mistakes

Where Microsoft 365 security often breaks down.

Assuming MFA is enabled for everyone

Having an MFA policy does not always mean every user and access scenario is properly protected.

Using Global Administrator accounts daily

Highly privileged accounts should be limited and separated from ordinary email and browsing activity.

Leaving former users active

Old accounts, sessions, guest access and application permissions may remain available after a person leaves.

Allowing unrestricted external sharing

SharePoint, OneDrive and Teams links can expose business information when sharing settings are too broad.

Treating Secure Score as a guarantee

Secure Score helps prioritise recommended actions, but it is not an absolute measure of breach likelihood.

Assuming cloud data needs no recovery plan

The organisation remains responsible for its identities and data and should define suitable retention, backup and recovery controls.

How ArchZen Helps

Practical Microsoft 365 security for growing businesses.

ArchZen can review identities, administrator access, email security, SharePoint and OneDrive sharing, devices, backups, audit activity and Secure Score recommendations.

We then create a prioritised improvement plan aligned with your licensing, users, operating model and business risk.

Tenant security review
MFA and Conditional Access
Administrator-role review
Email-security configuration
SPF, DKIM and DMARC
SharePoint and OneDrive sharing
Guest-user review
Device and Intune review
Backup and recovery review
Secure Score improvement plan

ArchZen is not Microsoft and is not affiliated with or endorsed by Microsoft. Microsoft 365, Microsoft Entra, Microsoft Defender, Microsoft Intune and related product names are trademarks of their respective owner. Available controls depend on your licences, configuration and Microsoft service updates.

How secure is your Microsoft 365 tenant?

ArchZen can review your tenant, identify security gaps and create a practical improvement roadmap.