Cybersecurity
Microsoft 365 Security
The settings nobody turned on.
Microsoft 365 security means configuring the protections your subscription already includes: a second check on every sign-in, conditional access rules, legacy sign-in methods switched off, audit logging retained, mailbox forwarding watched, and guest access kept tidy. happier IT reviews and hardens Microsoft 365 tenancies for Canadian organizations of roughly 15 to 200 people. Most of the work is settings rather than purchases.
Who it's for
Nearly every tenancy we look at has the same four gaps.
They are not the result of carelessness. They are the result of a migration project whose success criteria was that email kept arriving.
The tenancy was configured to work, not to be secure. Whoever moved your email had one brief: make mail arrive on day one. Defaults were left as defaults. That was the right priority at the time and nobody went back afterwards.
You are paying for protections you have never switched on. Business Premium and the E3 and E5 plans include security features many organizations never enable. The cheapest security available to you is already on the invoice.
Nobody can tell you who has access to what. Guest accounts from a project two years ago, sharing links set to "anyone with the link", and rather more global administrators than anyone intended.
An email went out from a real mailbox. Not forged, sent. That is an account problem rather than a filtering problem, and the tenancy usually holds the evidence, provided logging was switched on before it happened.
The forwarding rule
One of the most reliable early signals that an account is being used by someone else is a new inbox rule: mail forwarded to an outside address, or messages containing the word "invoice" filed straight into a folder nobody opens.
Alerting when a rule like that is created costs nothing, takes minutes to configure, and is off by default in most tenancies we are shown.
What's included
What gets reviewed and changed.
Ordered by risk removed per hour of work. The first four are usually a single evening between them.
-
Multi-factor authentication on everyone, administrators first
A second check before a login is accepted, applied to every account rather than to the ones that did not object. Administrator accounts get a stronger method than a text message, because a text message can be redirected.
-
Conditional access rules
Policies that weigh who is signing in, from what device and from where, and ask for more proof only when something is unusual. Conditional access needs Entra ID P1, which is included in Microsoft 365 Business Premium, so most organizations of this size already own it.
-
Legacy sign-in methods closed off
Older protocols that cannot present a second factor at all. Microsoft has retired basic authentication for most services, but leftover app passwords, SMTP submission accounts, scan-to-email devices and old handsets still get through. We find them and replace them properly.
-
Administrator accounts separated
A global administrator account that is not also somebody’s daily mailbox: no licence, no mail flow, its own strong second factor, used deliberately. And fewer of them, two or three named people, not seven historical ones.
-
Audit logging on, and retained
Default retention is short, and it is the difference between answering "what did they read" within a day and never answering it. We will tell you the actual retention on your plan and what extending it costs.
-
Alerting on mailbox rules and forwarding
New forwarding rules, external forwarding at the tenancy level, and unusual sign-in locations raised as alerts to people who will act on them, rather than sitting in a portal.
-
Guest access and sharing brought back under control
External sharing links given an expiry date, guest accounts reviewed on a schedule and removed when a project ends, and Teams nobody has posted in for two years archived rather than left standing with their files inside.
-
Defender and Purview features you already pay for
Safe Links and Safe Attachments, anti-phishing impersonation protection configured with the names of your actual executives and finance staff, and simple rules that flag obvious sensitive data leaving by email.
How it works
Look first, change in a window, then stop it drifting.
Nothing changes in your tenancy until you have seen the list and agreed what is on it.
-
A read-only review
We examine the tenancy configuration and produce a written list of findings ranked by risk and by how disruptive the fix is. Microsoft Secure Score is one input rather than the answer. Nothing is changed at this stage, and the document is yours whatever happens next.
-
Change the safe things, then the sensitive ones
Administrator separation, logging, alerting and legacy sign-in first, because nobody notices those. Conditional access and any change to how people sign in goes into an announced window with a pilot group first and a rollback ready.
-
Keep it from drifting
Quarterly review of guests, administrators, sharing links and policies, alerting on the changes that matter, and a check that the rules still match how people actually work, because a policy people are working around is worse than no policy.
What it costs
A fixed-price review, or inside managed IT.
Almost everything above uses licences you already hold. Where it genuinely does not, we will show you Microsoft’s list price and let you decide.
You keep the written findings whether or not we do the remediation, and there is no obligation attached to that.
If happier IT runs your managed IT
The two changes that sometimes need a licence upgrade are conditional access, which requires Business Premium or above, and extended audit log retention. Both are Microsoft list-price decisions, and we make no margin on describing them accurately.
Secure Score is a compass, not a target
Microsoft Secure Score is a useful prompt and a poor goal. Some of its recommendations do not fit how your organization works, and chasing the number produces policies staff quietly route around.
We will tell you which recommendations we skipped and why, in writing, so the gap between your score and 100 is a decision rather than an oversight.
Why us for this
The tenancy is where most of the useful evidence lives.
Identity is where nearly every question about an incident gets answered: who signed in, from where, what they opened, what rules they created. That evidence is kept for a limited period by default, which is why the logging settings matter more than they sound.
happier IT feeds Microsoft 365 sign-in and audit data into our own security operations centre in Canada, staffed by our own employees, alongside endpoint and network data, so an unusual sign-in and an unusual process on a laptop can be recognised as the same event rather than two unrelated ones. Staffed hours: 24/7, with the Surrey office on Monday to Friday, 8:00 am to 5:00 pm Pacific.
Where a Microsoft service stores data outside Canada, we will name it rather than implying we control it. See also our Microsoft 365 services for the administration side.
Go deeper
- Microsoft 365 services Licensing, migration and day-to-day administration.
- Identity and access management The joiners and leavers process behind the settings.
- Backup and disaster recovery Why a tenancy still needs its own backup.
Questions
What people ask before they sign anything.
Is Microsoft 365 secure by default?
Partly, and the split matters. Microsoft secures the platform: the data centres, the service, the updates. The settings inside your tenancy are yours: who has administrator rights, whether a second sign-in check is required, what guests can reach, how long logs are kept. Newer tenancies get security defaults switched on, which is a genuine improvement, but they are a floor rather than a configuration, and many older tenancies never had them.
What is conditional access?
Conditional access is a set of rules that decide what a sign-in has to satisfy based on its circumstances. A known user on a managed device inside normal hours signs in normally. The same account from an unfamiliar country, or from a device that is not enrolled, gets challenged or blocked. It is the mechanism that lets you add security without adding a prompt to every login, which is why staff usually prefer it to blanket rules.
Do we need Business Premium or E5?
For most organizations of 15 to 200 people, Business Premium covers the security features on this page, including conditional access and endpoint management, and it is the usual right answer. E3 with security add-ons and E5 become worth considering above 300 seats, where Business Premium is no longer available, or where you need advanced compliance and data-governance tooling. We will show the comparison on your actual user count rather than in the abstract.
How would we know if someone had been reading a mailbox?
From the audit log, provided it was enabled and retained long enough to still cover the period in question. That is the whole reason logging appears on this page rather than in a compliance appendix. The log shows sign-ins, what was accessed, what rules were created and what was shared. Once the retention window has passed, the answer is gone, and no amount of investigation afterwards brings it back.
Will hardening the tenancy annoy our staff?
Less than people expect, if it is designed properly. Configured well, conditional access reduces prompts for people on known devices, because the system stops asking questions it can already answer. What does irritate people is a blanket rule that challenges everyone constantly regardless of context, and that is usually what "we turned on MFA" means when nobody tuned it afterwards.
What does a Microsoft 365 security review cost?
For managed IT clients it is part of onboarding at no separate cost. Remediation is quoted separately once you have seen the list, so you can do some of it yourself if you would rather.
Related
Where to go next.
Related services
Worth reading
Want to know what this would look like for you?
A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.