Microsoft 365

A practical Microsoft 365 security baseline for a small business

How to prioritise identity, administration, email, devices and recovery without copying an enterprise checklist blindly.

Begin with identity and administrator control, because compromised credentials can affect email, files, applications and payments at once. Then establish supported devices, safer email settings, recoverability, logging and a repeatable joiner-leaver process. The exact controls depend on licences and risk, so record both implementation and evidence.

Design choices that matter

  • Multi-factor authentication (MFA) should protect all users, with stronger and separately managed controls for administrators.
  • Every tenant needs controlled emergency-access arrangements instead of shared administrator accounts.
  • A baseline needs named responsibility, test results and review dates as well as configuration.

How to approach the work

  1. 01

    Secure administrators

    Identify privileged roles, remove daily-use privilege, protect administrator sign-in and document emergency access.

  2. 02

    Protect users

    Implement appropriate MFA, block legacy access paths where safe and review risky sign-ins and consent.

  3. 03

    Control devices and sharing

    Define which devices may access data, how guests are reviewed and how external sharing is approved.

  4. 04

    Prepare response and recovery

    Confirm logs, contacts, retention, backup decisions and the account-compromise runbook.

  5. 05

    Review evidence

    Capture configuration, exceptions, licence dependencies and a scheduled reassessment.

What to test before handover

  • Privilege separated
  • MFA coverage confirmed
  • Emergency access tested
  • Legacy access reviewed
  • Guest access reviewed
  • Device decision recorded
  • Recovery path tested
  • Exceptions approved

Problems to catch early

  • Using shared administrator credentials
  • Enabling a control without testing business-critical applications
  • Assuming Microsoft defaults equal the organisation's approved risk position

Useful technical references

  1. Australian Signals Directorate, Australian Cyber Security Centre — Small business cloud security guides
  2. Australian Signals Directorate, Australian Cyber Security Centre — Implementing multi-factor authentication
  3. Microsoft Learn — Microsoft 365 security solutions

Links and technical details checked 2 September 2026. Corrections can be sent to info@turnstoneai.com.

A practical next step

Apply the guidance to the real environment.

Share what is not working, what is changing or what decision needs to be made. Technical answers can come after the business context is clear.