Comserv Connect
← Back to Blog
Cybersecurity

Microsoft 365 Security Settings Every NYC Small Business Should Turn On

By Comserv Connect TeamReviewed by Chris Ferrera

Almost every small business we walk into around New York runs on Microsoft 365, and almost every one of them assumes that because it came from Microsoft, it came secure. It did not. It came configurable.

The default tenant has to work for a two-person insurance office and a hospital system at the same time, so Microsoft ships it in the middle. A lot of the protection you are already paying for sits switched off until somebody deliberately turns it on. The settings below are included in most business plans, take an afternoon of focused work, and close the gaps that actually get used against businesses in the NYC metro.

Start With MFA, and Mean It

Multi-factor authentication is the single highest-value switch in the entire tenant. A stolen password is worth almost nothing to an attacker if the login still needs a second factor.

Two things go wrong in practice. The first is partial coverage: MFA gets rolled out to the office staff but not the owner, the bookkeeper, or the service account nobody remembers. This is most common in older tenants, and in ones where somebody once switched Microsoft's default protections off to accommodate an old device and never switched anything back on. Attackers do not need all your accounts. They need one. The second is method quality: text-message codes are far better than nothing, but an authenticator app with number matching is meaningfully harder to defeat than a code someone can be talked into reading aloud.

If you have Microsoft Entra ID P1 (included in Microsoft 365 Business Premium), Conditional Access is where this gets real. Instead of a blanket on-off switch, you can require MFA when someone signs in from an unmanaged device, block logins from countries you never do business in, and require a compliant, company-managed device for access to email. Policies that react to Microsoft's real-time risk scoring are a step up from there, and those need Entra ID P2, which is a paid add-on to Business Premium rather than part of it.

For a Staten Island firm whose entire staff logs in from the tri-state area, blocking sign-ins from outside the US is a five-minute change worth making. Treat it as a speed bump rather than a wall: a determined attacker simply routes through a US address, and Conditional Access is only evaluated after the password has already been checked. But it is five minutes, and it costs you nothing.

Close the Last Legacy Authentication Door Before December

Legacy authentication means older protocols that were built before MFA existed and therefore cannot enforce it. While they are enabled, an attacker with a valid password can walk straight past the MFA you just deployed by using an old protocol instead.

The good news is that Microsoft has already finished most of this cleanup for you. Basic authentication for POP, IMAP, ActiveSync, Exchange Web Services, and Outlook was permanently removed from every Exchange Online tenant back in 2022, and nobody, including Microsoft support, can turn it back on.

One exception is still open, and it now has a deadline. Authenticated SMTP is the protocol your copier uses to scan to email and your line-of-business application uses to send notifications, and it can still send with nothing but a stored username and password. Microsoft disables it by default for existing tenants at the end of December 2026 and removes it entirely after that. Anything in your office still sending mail that way will simply stop working.

Finding those devices is the hard part. The fix is easy once you know what you are looking for. Start the inventory now rather than in December, and block legacy authentication outright in Conditional Access while you are there, since that also catches older non-Microsoft mail clients.

Switch On the Anti-Phishing Tools You Already Own

Microsoft Defender for Office 365 Plan 1, included in Business Premium, has protections that do nothing until you configure a policy.

Safe Links rewrites URLs in email so they are checked at the moment someone clicks, not just at the moment the mail arrived. This matters because a common attack sends a clean link, waits for it to pass filtering, and then weaponizes the destination page hours later.

Safe Attachments detonates attachments in an isolated environment before delivery instead of relying on signatures alone.

Impersonation protection in the anti-phishing policy is the one most businesses skip and most need. You explicitly list your high-value people (the owner, the controller, whoever can move money) and your own domain, and Microsoft flags mail that mimics them. That is the exact shape of the fake-boss payment request that costs small businesses real money, and it is a setting, not a purchase.

Tag External Mail and Block Auto-Forwarding

Two small changes with outsized returns.

External sender identification puts a visible tag on email originating outside your organization. When an employee sees "External" sitting next to a message signed by the owner, the illusion breaks on its own, without any training required.

Automatic external forwarding is the quietest persistence trick there is. An attacker gets into a mailbox and creates a rule that silently copies incoming mail to an address they control. They may lose the password later, but they keep reading your email for months.

Microsoft now blocks external auto-forwarding by default in the outbound spam filter policy, so this one is probably already closed. The work is confirming that rather than assuming it, and then doing the part Microsoft does not do for you: reviewing the auto-forwarded messages report and auditing mailboxes for suspicious inbox rules, including rules that forward to an internal address or quietly file away replies. Those still work, and they are what a real compromise tends to look like.

Turn On Auditing Before You Need It

Auditing is worthless the day you turn it on and priceless six months later. If something goes wrong (a suspected mailbox compromise, a departing employee, an insurance carrier asking what happened), the first question is always what the logs show.

Here is the part most owners do not know, and it is the single most important line in this article. Microsoft turns unified audit logging on by default for its enterprise plans, but not for the small-business plans, and that includes Microsoft 365 Business Premium. If you are on Business Premium, somebody has to switch it on manually, and until they do there is nothing to look at.

Mailbox auditing itself is already on by default, so this is one thing to confirm and one switch to flip. It costs nothing, it keeps 180 days of history, and it is often the difference between a contained incident and an expensive guess. Reconstructing exactly which messages an intruder opened requires Microsoft's premium audit tier, which is an upgrade, but seeing what was configured, forwarded, and deleted does not.

Then Lock Down Who Can Install Apps

By default, users in many tenants can grant third-party applications permission to their Microsoft 365 data. That means an employee clicking "allow" on a convincing consent screen can hand a stranger persistent read access to company email, no password required and no MFA prompt triggered.

Restricting user consent so that new app permissions require admin approval takes one setting change. It occasionally creates a small amount of friction with legitimate tools, which is the point.

Check Your Work

Microsoft Secure Score, in the Microsoft Defender portal, scores your tenant against these controls and shows what is still open. It is not a compliance certificate, and chasing a number for its own sake is a mistake, but as a running checklist of what you have and have not enabled, it is genuinely useful. Look at it once a quarter.

The pattern in all of this is the same: the protection was already in the license. Somebody just has to go turn it on, verify it held, and check again when Microsoft changes the defaults.

How Comserv Helps

None of the settings above are exotic, but they are easy to half-finish, and a half-finished MFA rollout is the one that gets exploited. The businesses that get hurt are rarely careless. They just never had anyone whose job it was to own the configuration.

At Comserv Connect, our cybersecurity services and managed IT services cover exactly this work for small and mid-sized businesses across Staten Island, New York City, and New Jersey: MFA and Conditional Access, legacy auth cleanup, Defender for Office 365 policies, audit logging, and 24/7 MXDR/SOC monitoring behind it so a bad sign-in at 2 AM is not discovered at 9.

Want to know which of these are already on in your tenant? Book a free strategy call or call (347) 273-1200, and we will walk through your configuration with you.

Want the Checklist We Actually Use?

The same checks we run for the businesses we protect, in plain language. Free PDF, no vendor pitch.