Microsoft 365 runs email, file sharing, and chat for many agencies. However, the default settings leave important gaps. Strong Microsoft 365 security depends on the right licenses and the right configuration, and this guide explains both in plain terms.
Start with the right license
Microsoft offers several business plans, and their security features differ. Basic and Standard plans cover email and Office apps. By contrast, Business Premium adds tools that matter for agencies, such as conditional access, Defender for Office 365, device management, and data loss prevention.
Mixing plans is possible, but it leaves gaps. Therefore, giving every staff member the same security features usually works best.
Licensing alone does nothing, though. Many of these features stay off or loosely set up until someone configures them. So budget time for configuration, not just the subscription.
Lock down sign-ins
Account takeover is one of the most common threats agencies face in Microsoft 365. First, require MFA for every user, with number matching turned on. Then block legacy authentication protocols, because they skip MFA entirely.
Next, use conditional access to set rules for sign-ins. For example, you can block logins from countries where you have no staff, or require a managed device to open client files. Also, keep admin accounts separate from everyday email accounts.
Review risky sign-in reports as well. They flag logins from unusual locations or known malicious addresses, so you can respond before an attacker settles in.
Microsoft 365 security settings for email
Email is where most agency attacks begin. Several settings reduce that risk without affecting daily work.
- Turn on Safe Links and Safe Attachments to scan links and files.
- Block automatic forwarding to outside addresses.
- Publish SPF, DKIM, and DMARC records for your domain.
- Tag external emails so staff can spot outside senders.
- Alert on new inbox rules that hide or forward messages.
- Review who can open shared mailboxes, such as service or claims inboxes.
Shared mailboxes need special care in agencies. Service, claims, and billing inboxes often collect years of client documents. Therefore, grant access only to the staff who work those queues, and review membership whenever roles change.
Control file sharing
SharePoint, OneDrive, and Teams make collaboration easy. Unfortunately, they also make it easy to share client files with the wrong person. So set default sharing links to specific people rather than anyone with the link.
In addition, limit or disable guest access in Teams unless you have a clear need. Review external sharing reports monthly, and remove old links. For sensitive files, sensitivity labels can apply encryption that follows the document.
Teams also creates a SharePoint site behind each new team. As a result, a new team quietly adds a new place for client files, so review new teams and their owners regularly.
Prevent data leaks
Agencies handle Social Security numbers, driver’s license numbers, and bank details every day. Data loss prevention policies can detect these patterns in outgoing email and shared files. Then the policy can warn the user, encrypt the message, or block it.
Pair these policies with clear guidance for staff. When a warning appears, the message should explain the safer option, such as encrypted email or a secure upload link.
Start with warnings, so staff learn the rules without disruption. After a few weeks, tighten the policy based on what you see.
Focus first on the data types agencies handle most. Microsoft includes built-in detectors for Social Security numbers, bank account numbers, and driver’s license numbers from many states.
Monitor, log, and back up
Security settings drift over time. Someone creates a new admin, a vendor adds an app, or a user approves a risky permission. So review Microsoft Secure Score and admin activity regularly.
Also, make sure audit logging stays on and keeps records long enough for an investigation. Finally, remember that Microsoft keeps the service running, while you remain responsible for your data.
A separate Microsoft 365 backup protects against accidental deletion, ransomware, and departing employees. It also lets you restore a single mailbox or folder quickly.
Also, review which third-party apps have permission to read mail or files. Attackers sometimes trick users into approving malicious apps, which then keep access even after a password reset.
How WEBIT helps
WEBIT configures Microsoft 365 security for agencies, from MFA and conditional access to sharing controls and data loss prevention. We baseline every client to the CIS Controls and review your tenant during regular health assessments. Learn more about our cloud infrastructure services.
Our Security Advanced add-on includes Microsoft 365 threat detection and response, email security, and Microsoft 365 backup. Visit our insurance industry page to see how we support agencies.
Key takeaways
- Business Premium includes many of the security tools agencies need.
- Require MFA, block legacy sign-ins, and use conditional access.
- Harden email, restrict file sharing, and add data loss prevention.
- Strong Microsoft 365 security also requires monitoring and separate backup.