Free tools Windows power users keep installed
One-click scans. No signup required.
To secure Microsoft 365, require multifactor authentication (MFA) for users, keep emergency access accounts available, protect email deliberately, and use device and identity signals to control access to sensitive data. For a simple baseline, Microsoft Entra security defaults require no license; for customized rules such as requiring a compliant device, use Conditional Access, which requires at least Microsoft Entra ID P1. Neither choice alone makes a tenant secure: configure controls for your accounts and dependencies, then review them regularly.
This guide follows Microsoft’s product and security guidance available on October 3, 2026. Licensing and tenant behavior can change, so verify current requirements before making policy changes.
Start with MFA, but choose methods that fit the risk
Microsoft recommends requiring MFA for all users. MFA reduces the risk of an account being compromised through a stolen or reused password, but it is not a guarantee against compromise. Microsoft guidance quotes Alex Weinert, its Director of Identity Security, saying that an account is “more than 99.9% less likely to be compromised if you use MFA,” based on Microsoft’s studies. The guidance does not give a study year, and the figure is Microsoft’s attributed statement, not an independent estimate for a particular tenant.
Microsoft Entra’s built-in authentication strengths offer three broad levels:
#1 Best Overall
- Multifactor authentication: the standard MFA strength.
- Passwordless MFA: MFA that does not rely on a password as the sign-in method.
- Phishing-resistant MFA: the most restrictive of the three built-in strengths. Microsoft lists FIDO2 security keys, Windows Hello for Business or platform credentials, and multifactor certificate-based authentication among the combinations that can satisfy it.
Use stronger, phishing-resistant methods for higher-risk accounts or sensitive access when your devices, enrollment process, and tenant configuration support them. A FIDO2 security key is one option, not a complete security solution: administrators still need to enable and scope authentication methods and policies, and using Conditional Access requires the relevant license.
Choose security defaults or Conditional Access
Security defaults and Conditional Access are alternative approaches to the baseline, not settings to enable together. Microsoft says they cannot both be turned on at the same time. Defaults are simpler and require no license, while Conditional Access requires at least Microsoft Entra ID P1 and allows customized policies. Microsoft 365 Business Premium and E3 are examples of plans that include P1; E5 includes P2. Check the tenant’s actual plan and add-ons rather than assuming a particular feature is included.
| Decision | Security defaults | Conditional Access |
|---|---|---|
| License prerequisite | None, according to Microsoft | At least Microsoft Entra ID P1 |
| Customization | No customization; on or off | Policies can be customized and targeted |
| Operational effort | Simpler baseline | Requires policy planning, exclusions, testing, and maintenance |
| Typical fit | Organizations that want Microsoft’s basic protections with minimal policy design | Organizations that need differentiated controls, such as device-compliance conditions or stronger access rules |
These fit descriptions reflect the documented differences in customization and operational complexity; the right choice depends on the tenant’s needs, dependencies, and license.
Rank #2
If you use security defaults
Defaults are an on/off baseline rather than a policy set to tune. Before enabling them, check for applications or devices that still rely on older authentication protocols. Microsoft’s guidance also states that, starting July 1, 2026, security defaults block device-code flow in new Entra tenants. Applications or devices that depend on that flow cannot sign in while defaults are enabled. Validate these dependencies against the current Microsoft documentation and your own sign-in requirements.
If you move to Conditional Access
Do not turn security defaults off until replacement Conditional Access policies are ready to preserve the baseline protections. Microsoft’s documented policy templates include MFA for all users, MFA for administrators, blocking legacy authentication, and MFA for Azure management. Plan policy scope and exclusions, test the policies, and then add custom rules that address the tenant’s needs. Exclusions should be deliberate and limited; a policy that accidentally omits users can leave them outside the intended protection.
Keep emergency access available
Strong sign-in policies can lock administrators out if an exclusion, authentication method, or recovery path fails. Microsoft recommends at least two cloud-only emergency access accounts. Its Microsoft 365 admin guidance says these accounts should not be assigned to specific individuals.
- Keep the emergency accounts separate from everyday administrator accounts.
- Exclude emergency access accounts from MFA Conditional Access policies where applicable, as Microsoft’s guidance advises.
- Test the recovery process so administrators know how access can be restored if normal sign-in fails.
Before enabling or replacing policies, confirm that the account types in scope are understood, that any service-account exclusions are appropriate, and that the emergency access path works. Do not use an exclusion as a substitute for a tested recovery plan.
Use device and identity context for sensitive access
For organizations that need more than a basic sign-in baseline, Conditional Access can use identity and device context to control access. For example, a policy can require a compliant device before allowing access to sensitive Microsoft 365 data. Intune evaluates device compliance and provides that signal to Entra ID; Conditional Access can then use the signal in its access decision.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsMicrosoft’s Zero Trust guidance covers cloud-only and hybrid enterprise environments and includes measures such as MFA, Entra groups, device enrollment, identity-risk protections, self-service password reset, password protection, and Intune. These controls do not all share one license requirement. Microsoft lists Microsoft 365 E5, Microsoft 365 E3 with the E5 Security add-on, EMS E5, or Entra ID P2 for some risk-based capabilities, while other features have different requirements. Check licensing for each capability you plan to use rather than treating the full set as included in one general Microsoft 365 plan.
Rank #4
Configure email protections and keep them under review
Microsoft says cloud-mailbox organizations have built-in security features and identifies Defender for Office 365 as its primary email and collaboration security solution for Microsoft 365. Its guidance recommends Standard and Strict filtering levels and suggests using preset security policies to apply them. Select a level appropriate to the organization’s needs and review how it affects legitimate mail as well as threats.
Authenticate outbound sending domains before tuning email policies. SPF identifies the services permitted to send mail for a domain; DKIM lets recipients verify that a message is authorized by the domain and has not changed since it was signed. Microsoft says threat policies work best when sending domains are correctly authenticated.
For ongoing operations, Microsoft recommends monthly Secure Score reviews, enabling the Outlook Report button and routing user reports for review, and reviewing or preventing external mailbox forwarding rules. Investigation tools can help teams find false positives and false negatives. These are maintenance practices, not assurances that phishing or malicious messages will be eliminated.
Use Secure Score as a prioritized checklist, not a security verdict
Microsoft Secure Score brings together security recommendations across identities, apps, and devices. It can help report current posture, guide improvements, and compare with benchmarks. Recommendations may receive partial points when a control covers only some users or devices, and the score can recognize some alternate mitigations, including non-Microsoft solutions.
Microsoft explicitly cautions that Secure Score is not an absolute measure of breach likelihood and is not a guarantee against a breach. Its recommendations do not cover every attack surface. Review each recommendation against the organization’s threat model and operating needs, investigate what a proposed change would affect, and record accepted risks or alternate controls. A higher score can indicate progress on the measured recommendations; it cannot prove that the tenant is safe.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

