Skip to main content

How Does Microsoft Protect Your Data?

Media How Does Microsoft Protect Your Data

Microsoft 365 stores some of the most important information used by modern businesses.

This may include:

  • Email
  • Customer records
  • Contracts
  • Financial documents
  • Microsoft Teams conversations
  • SharePoint libraries
  • OneDrive files
  • Employee information
  • Meeting recordings
  • Business reports
  • Microsoft 365 Copilot interactions

Businesses therefore need to understand how Microsoft protects this information and which security responsibilities remain with them.

Microsoft uses physical security, encryption, access controls, service monitoring, threat detection and resilient infrastructure to protect its cloud services.

However, Microsoft cannot secure an environment that has weak passwords, excessive permissions, unmanaged devices or incorrectly configured sharing settings.

The strongest protection comes from combining Microsoft’s cloud security with properly managed accounts, devices, policies and backups.

Microsoft Uses Several Layers of Protection

Microsoft does not rely on one security product or control.

Microsoft 365 is protected through several connected layers, including:

  • Physical data-centre security
  • Network protection
  • Encryption
  • Identity and access controls
  • Tenant isolation
  • Application security
  • Threat detection
  • Security monitoring
  • Data governance
  • Service resilience
  • Auditing
  • Privacy and compliance controls

This is commonly described as defence in depth.

When one control is bypassed or fails, another layer may prevent an attacker from accessing the information.

Microsoft describes Microsoft 365 as using physical, network, access, application and data-security controls together rather than relying on a single barrier. (Microsoft Learn)

1. Physical Data-Centre Security

Microsoft 365 data is stored within Microsoft’s global network of data centres.

These facilities are designed to restrict physical access to the infrastructure that hosts customer information.

Microsoft’s documented controls include:

  • Perimeter barriers
  • Security officers
  • Controlled entrances
  • Multi-factor physical access
  • Video surveillance
  • Alarm systems
  • Locked server racks
  • Approved access lists
  • Auditing of authorised personnel
  • Restricted maintenance tools

Physical access becomes more restricted as someone moves through the external perimeter, building and data-centre floor.

Only authorised personnel with a valid operational reason should be able to access protected areas. (Microsoft Learn)

Why This Matters

A business hosting its own server may keep it in an office cupboard, server room or shared building.

The organisation then needs to manage:

  • Door access
  • Fire protection
  • Cooling
  • Power
  • Surveillance
  • Hardware maintenance
  • Equipment disposal
  • Environmental monitoring

Microsoft’s data centres are purpose-built for hosting large-scale cloud services and use several layers of physical protection.

This does not remove the customer’s responsibilities, but it can provide stronger physical infrastructure than many smaller organisations could reasonably build themselves.

2. Encryption at Rest

Data at rest is information stored on physical media rather than actively travelling across a network.

This can include:

  • Email stored in Exchange Online
  • Documents in SharePoint
  • Files in OneDrive
  • Microsoft Teams content
  • Backup and service data
  • Stored application information

Microsoft 365 encrypts customer data at rest using several technologies.

For example, SharePoint and OneDrive use encryption that includes AES 256-bit keys, while Exchange mailboxes are protected through service encryption and data-encryption policies. (Microsoft Learn)

Encryption helps make information unreadable without the appropriate keys and authorisation.

If someone obtained unauthorised access to the underlying storage, encryption would provide another layer between them and the usable business information.

3. Encryption in Transit

Data is in transit when it moves between locations.

This may happen when:

  • An employee opens Outlook
  • A document is uploaded to OneDrive
  • Someone joins a Teams meeting
  • SharePoint sends information to a browser
  • Microsoft servers exchange service data
  • Exchange Online sends email to another provider

Microsoft uses encryption technologies including Transport Layer Security and IPsec to protect supported communications.

Microsoft states that customer-facing servers negotiate secure TLS sessions with client devices and that communications between Microsoft data centres use TLS or IPsec. (Microsoft Learn)

Email Has Additional Considerations

Email travelling between two Microsoft 365 organisations can be encrypted during transport.

When email is delivered to an external provider, protection may depend partly on whether the recipient’s email system supports and correctly negotiates TLS.

Businesses sending particularly sensitive information may therefore require additional protection, such as:

  • Microsoft Purview Message Encryption
  • Sensitivity labels
  • Secure file-sharing links
  • A specialist customer portal
  • Contractual encryption requirements

Transport encryption protects the connection.

It does not prevent the intended recipient from forwarding, copying or mishandling the information after they receive it.

4. Separation Between Microsoft 365 Customers

Microsoft 365 is a multi-tenant cloud service.

This means the same overall Microsoft infrastructure supports many different organisations.

Microsoft uses logical isolation and access controls to prevent one customer from accessing another customer’s data.

Exchange, SharePoint and other services use tenant-level authentication, authorisation controls and role-based permissions to separate customer environments.

Microsoft’s cloud architecture is designed on the assumption that each tenant must be isolated from every other tenant. (Microsoft Learn)

What Is a Microsoft 365 Tenant?

A tenant is your organisation’s Microsoft 365 environment.

It contains items such as:

  • User accounts
  • Domains
  • Mailboxes
  • Microsoft Teams
  • SharePoint sites
  • Security policies
  • Devices
  • Applications
  • Administrative settings

Your users authenticate against your organisation’s tenant before gaining access to its services.

However, Microsoft’s tenant isolation does not decide which people within your own organisation should access each document.

Your business remains responsible for configuring its internal permissions correctly.

5. Identity and Access Protection

Microsoft 365 uses Microsoft Entra ID to identify users and control access to cloud services.

An organisation can use Entra ID capabilities to apply controls such as:

  • Multi-factor authentication
  • Conditional Access
  • Role-based permissions
  • Sign-in restrictions
  • Device-compliance requirements
  • Authentication-method policies
  • Administrator-role management
  • Guest-user controls

This is important because many attacks do not attempt to break Microsoft’s data-centre encryption.

Instead, the attacker tries to sign in as a legitimate employee.

They may steal a password through:

  • Phishing
  • Malware
  • Password reuse
  • Fake Microsoft login pages
  • Social engineering
  • Data breaches

Once an attacker successfully signs in, Microsoft 365 may initially treat them as the authorised user.

Strong identity configuration is therefore one of the most important customer responsibilities.

6. Multi-Factor Authentication

Multi-factor authentication requires another form of verification in addition to the password.

This might involve:

  • Microsoft Authenticator
  • Windows Hello for Business
  • A security key
  • A passkey
  • Biometric verification

If an attacker steals an employee’s password, multi-factor authentication may prevent them from accessing the account.

However, not every verification method provides the same level of protection.

Businesses should move towards phishing-resistant authentication methods where practical, particularly for:

  • Administrators
  • Directors
  • Finance teams
  • Employees handling confidential data
  • Remote-access accounts

Employees also need training to reject unexpected authentication prompts.

An unexplained request may mean a criminal already knows the employee’s password.

7. Conditional Access

Conditional Access allows the business to apply access rules using several signals.

A policy might consider:

  • Who is signing in
  • Which application they are accessing
  • Whether the device is managed
  • Whether the device meets security standards
  • The location of the request
  • The authentication method
  • The role held by the user

For example, the organisation could:

  • Require multi-factor authentication outside trusted locations
  • Block access from an unmanaged computer
  • Apply stronger rules to administrators
  • Prevent outdated authentication methods
  • Restrict access from selected countries
  • Require approved mobile applications

Conditional Access does not automatically protect every Microsoft 365 organisation.

The feature must be licensed, designed, tested and enabled correctly.

A badly planned policy could block legitimate users, so suitable emergency access arrangements should also be maintained.

8. Microsoft Defender

Microsoft Defender provides security capabilities across identities, email, applications and devices.

The features available depend on the Microsoft licences held by the organisation.

Relevant services can include:

  • Microsoft Defender for Business
  • Microsoft Defender for Endpoint
  • Microsoft Defender for Office 365
  • Microsoft Defender for Identity
  • Microsoft Defender for Cloud Apps
  • Microsoft Defender XDR

These services can help detect threats such as:

  • Malware
  • Ransomware
  • Phishing
  • Malicious attachments
  • Dangerous links
  • Credential theft
  • Suspicious applications
  • Unusual sign-ins
  • Compromised devices
  • Attempts to evade security controls

Microsoft can supply the security platform, but alerts still need to be reviewed.

A critical detection that remains unseen in a portal provides little practical protection.

The business or its managed IT provider should know:

  • Who monitors alerts
  • When monitoring takes place
  • How incidents are prioritised
  • Who can isolate a device
  • Who can disable an account
  • How the business is notified

9. Email Filtering and Anti-Phishing Protection

Exchange Online Protection provides baseline filtering for Microsoft 365 email.

Depending on licensing, Microsoft Defender for Office 365 can add capabilities including:

  • Safe Links
  • Safe Attachments
  • Advanced anti-phishing policies
  • User impersonation protection
  • Domain impersonation protection
  • Threat investigation
  • Automated response
  • Attack simulation training

Safe Links can analyse supported links when employees select them.

Safe Attachments can examine files within a protected environment before deciding how the message should be handled.

These features reduce risk, but they cannot guarantee that every malicious email will be stopped.

Businesses still need:

  • Employee security awareness
  • Payment-verification processes
  • Multi-factor authentication
  • DMARC, SPF and DKIM
  • A clear method for reporting suspicious email
  • Monitoring for compromised mailboxes

10. Microsoft Purview Information Protection

Microsoft Purview provides tools for classifying, governing and protecting business information.

Sensitivity labels can be used to identify the importance of a document or email.

An organisation might create labels such as:

  • Public
  • Internal
  • Confidential
  • Customer Confidential
  • Highly Confidential

Depending on configuration and licensing, a label may apply:

  • Encryption
  • Access restrictions
  • Visual markings
  • Sharing limitations
  • Protection that travels with the file

Microsoft states that sensitivity labels can classify and protect information while allowing employees to continue collaborating. (Microsoft Learn)

Why Labels Matter

Folder permissions protect information while it remains within that location.

A sensitivity label can help continue protecting a supported file after it is:

  • Downloaded
  • Emailed
  • Copied
  • Moved to another location
  • Shared with an approved external user

The label structure must be designed carefully.

Too many confusing options may result in employees choosing the wrong classification or ignoring the process.

11. Data Loss Prevention

Microsoft Purview Data Loss Prevention can identify sensitive information and help prevent it from being shared inappropriately.

Policies can operate across supported locations such as:

  • Exchange
  • SharePoint
  • OneDrive
  • Microsoft Teams
  • Managed devices
  • Approved cloud applications

DLP may detect information including:

  • Payment-card details
  • Bank information
  • Passport numbers
  • National Insurance numbers
  • Health information
  • Customer identifiers
  • Confidential business terms

Depending on the policy, Microsoft 365 may:

  • Warn the employee
  • Provide guidance
  • Request a business justification
  • Block the action
  • Generate an alert
  • Record the incident

Microsoft Purview DLP supports policies that use sensitive-information types, labels and other classification methods across Microsoft 365 services. (Microsoft Learn)

DLP should normally be introduced in stages.

An overly restrictive rule could interrupt legitimate work and encourage employees to use unapproved workarounds.

12. Audit Logging

Microsoft 365 records many user and administrator activities in audit logs.

Depending on the service, licence and configuration, records may include:

  • Sign-ins
  • File access
  • External sharing
  • Mailbox activity
  • Administrator changes
  • Security events
  • Application consent
  • Microsoft Teams actions
  • SharePoint activity
  • OneDrive activity
  • Customer Lockbox requests
  • Microsoft Defender actions

Audit information can help answer questions such as:

  • Who accessed a confidential file?
  • Was a document shared externally?
  • Who changed an administrator role?
  • When was a forwarding rule created?
  • Which user deleted the information?
  • What action did the security team take?

Microsoft documents a wide range of activities that can be captured within the Microsoft 365 audit log. (Microsoft Learn)

Logs Must Be Retained and Reviewed

Audit logs are most useful when:

  • The required activity is enabled
  • Suitable retention is available
  • Administrators know how to search them
  • Alerts are monitored
  • The organisation responds quickly

The business should not wait until after an incident to discover that it lacks the licensing, permissions or retention period required for its investigation.

13. Controlled Access by Microsoft Engineers

Microsoft engineers do not normally have permanent unrestricted access to customer data.

Microsoft describes its Microsoft 365 production-access model as Zero Standing Access.

Where privileged access is required, engineers must request time-limited access and provide a legitimate business justification.

Microsoft uses Just-In-Time and Just-Enough-Access controls to limit what an authorised engineer can access and for how long.

Requests and actions are logged. (Microsoft Learn)

Customer Lockbox

Eligible organisations can use Customer Lockbox for additional control.

When a Microsoft engineer needs to access supported customer information during a support investigation, Customer Lockbox can require an administrator within the customer’s organisation to approve or reject the request.

Supported services include:

  • Exchange Online
  • SharePoint Online
  • OneDrive for Business
  • Microsoft Teams
  • Windows 365

Microsoft 365 Copilot support interactions are also covered through the relevant support arrangements. (Microsoft Learn)

Customer Lockbox is not included with every Microsoft 365 licence and must be configured where required.

14. Encryption-Key Management

By default, Microsoft manages the encryption keys used by Microsoft 365 services.

Some organisations have legal, regulatory or contractual requirements for greater control.

Microsoft Purview Customer Key allows eligible customers to control root encryption keys for supported Microsoft 365 data.

Customer Key complements Microsoft’s existing disk and service encryption and can support organisations with advanced compliance or sovereignty requirements. (Microsoft Learn)

Customer-managed keys introduce additional responsibility.

The organisation must carefully manage:

  • Azure Key Vault
  • Key permissions
  • Key rotation
  • Recovery processes
  • Administrator access
  • Business-continuity implications

Customer Key is normally appropriate for organisations with defined compliance needs rather than every small business.

15. Resilient and Redundant Infrastructure

Microsoft 365 is designed to remain available when individual hardware, software or data-centre components fail.

Microsoft uses technologies and processes including:

  • Redundant hardware
  • Multiple service instances
  • Data replication
  • Automated integrity checking
  • Monitoring
  • Preventive maintenance
  • Failover processes
  • Geographically separated infrastructure

Microsoft states that Microsoft 365 customer data is stored within a redundant environment and that multiple levels of redundancy are used to support availability and recovery. (Microsoft Learn)

Exchange Online, for example, uses database availability groups and keeps multiple copies of mailbox databases across separate data centres within the relevant territory. (Microsoft Learn)

Availability Is Not the Same as Backup

Resilient infrastructure helps keep Microsoft services available when Microsoft experiences a hardware or platform failure.

It does not automatically protect the business from every possible data-loss scenario.

Examples include:

  • An employee permanently deleting information
  • A malicious administrator removing data
  • Incorrect retention settings
  • A compromised account changing documents
  • Ransomware synchronising damaged files
  • A business needing a recovery point from several months earlier

Microsoft’s shared-responsibility guidance confirms that customers retain responsibility for their information and should understand the available recovery and backup options. (Microsoft Learn)

16. Retention and Recovery Features

Microsoft 365 provides built-in recovery and retention capabilities across services such as Exchange, SharePoint and OneDrive.

Depending on the service and configuration, these may include:

  • Recycle bins
  • Version history
  • Deleted-item recovery
  • Retention policies
  • Litigation or legal holds
  • File restoration
  • Mailbox recovery features

These controls can help recover from some accidental changes or deletions.

However, they are not necessarily a complete replacement for a separate backup strategy.

Retention is primarily designed to keep or remove information according to policy.

Backup is designed to provide recoverable copies and restore points.

The organisation should decide:

  • Which Microsoft 365 data requires backup
  • How long recovery points are needed
  • How quickly information must be restored
  • Who can delete backup data
  • Whether backups are protected from compromised administrators
  • When recovery was last tested

Microsoft now offers Microsoft 365 Backup for Exchange, SharePoint and OneDrive, while third-party Microsoft 365 backup platforms are also available. (Microsoft Learn)

17. Data Residency

Data residency refers to the geographic location where customer data is stored at rest.

Microsoft operates data centres in several regions and provides data-residency commitments based on the service, tenant location, contract and available licensing.

For qualifying Office 365 environments provisioned in the United Kingdom, Microsoft documents commitments covering core customer data such as Exchange mailbox content, SharePoint content and OneDrive files. (Microsoft Learn)

Some organisations may require additional controls through options such as Advanced Data Residency.

This can be relevant to:

  • Regulated businesses
  • Government suppliers
  • Legal firms
  • Financial organisations
  • Healthcare providers
  • Businesses with contractual location requirements

Data residency does not necessarily mean that no information is ever processed or transferred elsewhere.

Businesses should review the Microsoft Product Terms, Data Protection Addendum and service-specific documentation for their exact requirements.

18. Privacy Commitments

Microsoft states that commercial customers control their data and that its privacy approach includes:

  • Transparency about where data is located
  • Protection of data at rest and in transit
  • Limits on third-party access
  • Retention and deletion controls
  • Compliance with applicable privacy obligations

Microsoft also states that it does not provide governments with direct or unrestricted access to customer data and only discloses data where authorised by the customer or required by applicable law. (Microsoft Learn)

Microsoft’s contractual privacy and security commitments are described through resources including:

  • Microsoft Product Terms
  • Data Protection Addendum
  • Microsoft Trust Center
  • Service Trust Portal
  • Privacy documentation

Your organisation remains responsible for deciding whether Microsoft’s terms and controls meet its legal and regulatory requirements.

19. Independent Audits and Compliance

Microsoft cloud services are assessed against a wide range of industry and regulatory standards.

The exact certifications available depend on the service and region.

Examples can include frameworks relating to:

  • Information-security management
  • Privacy management
  • Financial controls
  • Government requirements
  • Healthcare
  • Payment information
  • Data protection

Microsoft makes security, privacy and compliance documentation available through the Service Trust Portal.

This includes audit reports and other material that can help organisations complete supplier assessments and compliance reviews. (Service Trust Portal)

A Microsoft compliance certification does not automatically make your business compliant.

Your organisation still needs to configure the platform properly, train employees and operate its own processes in accordance with the relevant rules.

What Microsoft Does Not Automatically Protect You From

Microsoft provides a highly secure cloud platform, but it cannot prevent every incident.

Microsoft may not be able to protect your business when:

  • An employee approves a fraudulent multi-factor authentication request
  • A user shares a confidential document with the wrong person
  • Administrator access is granted too widely
  • A criminal signs in using a genuine compromised account
  • External sharing is left unrestricted
  • Security alerts are not monitored
  • A third-party application receives excessive access
  • Former employee accounts remain active
  • Retention policies are incorrectly configured
  • Employees use unapproved applications
  • The organisation has no suitable backup strategy

A secure cloud platform can still be used insecurely.

The Shared-Responsibility Model

Microsoft is responsible for securing and operating the underlying cloud infrastructure.

The customer remains responsible for how its environment is configured and used.

Your responsibilities can include:

  • User identities
  • Multi-factor authentication
  • Permissions
  • Administrator access
  • Device security
  • Data classification
  • External sharing
  • Security policies
  • Alert monitoring
  • Backup requirements
  • Employee training
  • Incident response
  • Compliance decisions

The balance of responsibility varies depending on the service.

For a fully managed cloud service, Microsoft handles more of the infrastructure.

For Azure virtual machines or custom cloud applications, the customer may be responsible for operating systems, applications, network configuration and additional security controls.

Common Microsoft 365 Security Mistakes

Businesses may assume Microsoft is protecting everything while leaving important controls unconfigured.

Common mistakes include:

  • Not enforcing multi-factor authentication
  • Giving several employees Global Administrator access
  • Using administrator accounts for everyday work
  • Allowing unrestricted anonymous sharing
  • Failing to review guest users
  • Ignoring Microsoft Defender alerts
  • Leaving former employee accounts enabled
  • Using unmanaged personal devices
  • Assuming OneDrive is a complete backup
  • Not reviewing application permissions
  • Failing to protect email domains with DMARC
  • Never testing data recovery
  • Purchasing Business Premium without configuring its security features
  • Introducing Copilot before reviewing document permissions

These problems should be identified through regular security and governance reviews.

How Can Your Business Improve Microsoft 365 Protection?

A strong Microsoft 365 security plan should include the following areas.

Secure Every Identity

Enforce multi-factor authentication and introduce phishing-resistant methods where practical.

Use separate administrator accounts and minimise the number of privileged users.

Apply Conditional Access

Use access rules appropriate to the employee, device, location and sensitivity of the application.

Manage Every Device

Business computers should be:

  • Centrally managed
  • Encrypted
  • Patched
  • Protected by managed endpoint security
  • Checked for compliance
  • Remotely removable when necessary

Review Permissions

Regularly review:

  • SharePoint sites
  • Microsoft Teams
  • OneDrive sharing
  • Shared mailboxes
  • Guest users
  • Administrator roles
  • Third-party applications

Monitor Security Alerts

Assign clear responsibility for reviewing Microsoft Defender and Microsoft Entra alerts.

Critical events should trigger an agreed response.

Protect Sensitive Information

Consider sensitivity labels, Data Loss Prevention, retention and encryption for confidential information.

Maintain Tested Backups

Understand Microsoft’s built-in recovery options and decide whether Microsoft 365 Backup or a third-party backup service is required.

Test recovery rather than assuming it will work.

Train Employees

Employees should know how to identify and report:

  • Phishing
  • Unexpected authentication requests
  • Payment fraud
  • Accidental sharing
  • Lost devices
  • Suspicious applications
  • Unusual account activity

Create an Incident-Response Plan

The plan should explain:

  • Who disables compromised accounts
  • Who isolates affected devices
  • Who reviews audit logs
  • Who contacts Microsoft
  • How data is recovered
  • Who communicates with customers
  • Whether the insurer or regulator must be informed

How Hamilton Group Can Help

Hamilton Group helps businesses configure, secure and manage their Microsoft 365 environments.

We can review how Microsoft currently protects your data and identify areas where your own settings, permissions or processes may be creating unnecessary risk.

Our services can include:

  • Microsoft 365 security reviews
  • Multi-factor authentication
  • Conditional Access
  • Microsoft Intune
  • Managed endpoint protection
  • Microsoft Defender
  • Email security
  • DMARC, SPF and DKIM
  • SharePoint and OneDrive permission reviews
  • Microsoft Teams governance
  • Sensitivity labels
  • Data Loss Prevention
  • Microsoft Purview
  • Audit-log reviews
  • Microsoft 365 backups
  • Recovery testing
  • Cybersecurity awareness training
  • Incident-response planning
  • Ongoing managed IT support

At Hamilton Group, we aim to make first contact on IT support requests within 15 minutes, helping employees receive assistance quickly when a technology or security problem affects their work.

Microsoft provides a secure and resilient cloud platform, but the protection your business receives depends heavily on how that platform is configured and managed.

Call Hamilton Group today on 0330 043 0069 to arrange a Microsoft 365 security review and make sure your business data is properly protected.

Microsoft products, security features and licensing can change. This article provides general information and should not be treated as legal, regulatory or data-protection advice.