Skip to main content

Our 14 Favourite Microsoft 365 Security Features

Media Our 14 Favourite Microsoft 365 Security Features

Microsoft 365 is often known for applications such as Outlook, Word, Excel, PowerPoint and Microsoft Teams.

However, the platform can also provide a wide range of cybersecurity, identity, device-management and data-protection features.

These tools can help businesses protect employee accounts, detect malicious email, secure laptops, control access to confidential information and investigate suspicious activity.

The important point is that these protections are not necessarily active simply because your organisation uses Microsoft 365.

Features need to be included within the correct licence, configured appropriately and monitored by someone who understands what the alerts mean.

Here are 14 of our favourite Microsoft 365 security features and how they can help protect your business.

1. Multi-Factor Authentication

Multi-factor authentication is one of the most valuable security controls available within Microsoft 365.

A password can be:

  • Stolen through phishing
  • Reused from another website
  • Guessed
  • Shared accidentally
  • Exposed in a data breach
  • Captured by malicious software

Multi-factor authentication requires the user to provide another form of verification when signing in.

This might involve:

  • Microsoft Authenticator
  • A physical security key
  • Windows Hello for Business
  • Biometric verification
  • A temporary code

This means a stolen password may not be enough for a criminal to access the account.

Microsoft recommends using multi-factor authentication as a core security measure for Microsoft 365 business environments. Security defaults can provide baseline protection, while Conditional Access offers more detailed control in suitable licences. (Microsoft Learn)

Why We Like It

A compromised Microsoft 365 account can give an attacker access to email, files, contacts and internal conversations.

Multi-factor authentication places an important additional barrier between the criminal and your business information.

However, employees must also understand multi-factor authentication fatigue attacks.

An attacker who already knows a password may repeatedly send approval requests in the hope that the employee eventually accepts one.

Users should never approve a sign-in request they did not initiate.

Unexpected prompts should be reported to IT immediately.

2. Conditional Access

Conditional Access allows businesses to decide under which circumstances someone may access Microsoft 365.

Instead of treating every sign-in in the same way, Microsoft Entra ID can consider signals such as:

  • User identity
  • Device compliance
  • Location
  • Application
  • Authentication method
  • Sign-in circumstances
  • The resource being accessed

A policy might:

  • Require multi-factor authentication outside trusted locations
  • Block outdated authentication methods
  • Require a managed device
  • Prevent access from selected countries
  • Apply stronger controls to administrators
  • Restrict access to sensitive applications
  • Require an approved application on mobile devices

Microsoft describes Conditional Access as its Zero Trust policy engine. Microsoft 365 Business Premium includes access to Conditional Access through Microsoft Entra ID Plan 1, although some advanced risk and identity-governance capabilities require additional licensing. (Microsoft Learn)

Why We Like It

Conditional Access allows security to reflect the level of risk.

An employee accessing email through a managed office laptop may be treated differently from an administrator attempting to sign in from an unfamiliar device in another country.

This creates stronger protection without forcing every user through the most restrictive process every time they work.

Conditional Access policies should be planned and tested carefully.

A badly configured policy can prevent legitimate employees or administrators from accessing important systems. Emergency access arrangements should also be maintained securely.

3. Microsoft Defender for Business

Microsoft Defender for Business provides centrally managed endpoint security for supported computers, servers and mobile devices.

It is included with Microsoft 365 Business Premium and can also be purchased separately.

Depending on the platform and configuration, it can help identify:

  • Malware
  • Ransomware behaviour
  • Suspicious scripts
  • Credential theft
  • Unusual applications
  • Attempts to disable security tools
  • Potentially compromised devices
  • Known software vulnerabilities

Microsoft 365 Business Premium combines Defender for Business with Microsoft Intune Plan 1, allowing security and device policies to be centrally deployed and managed. (Microsoft Learn)

Why We Like It

Traditional antivirus focuses heavily on known malicious files.

Modern cyberattacks may use legitimate applications, scripts and stolen credentials to avoid looking like a conventional virus.

Defender for Business provides greater visibility into suspicious behaviour and can help an IT provider investigate what happened.

It can also support actions such as isolating an affected device from the network while the incident is investigated.

The licence alone is not enough.

Security alerts need to be monitored and investigated. A warning sitting unseen in a management portal does not protect the business.

4. Microsoft Intune Device Management

Microsoft Intune allows businesses to manage supported computers, tablets and mobile phones centrally.

Policies can be used to:

  • Require device encryption
  • Configure screen locks
  • Deploy applications
  • Apply security settings
  • Check device compliance
  • Manage Windows updates
  • Remove company information
  • Restrict access from unsuitable devices
  • Configure Wi-Fi and email settings
  • Report on managed equipment

Intune can work with Conditional Access so Microsoft 365 access depends on the compliance status of the device. A computer that does not meet the organisation’s security requirements can be blocked or required to complete remediation before access is granted. (Microsoft Learn)

Why We Like It

Employees no longer work from one office computer.

They may use:

  • Laptops
  • Home-working devices
  • Mobile phones
  • Tablets
  • Replacement computers
  • Devices sent directly from a supplier

Intune gives the business a central method for applying consistent controls, regardless of where the device is located.

This reduces the need to rely on employees configuring their own security settings.

It also supports faster onboarding because approved applications and policies can be delivered automatically.

5. Intune App Protection Policies

Some businesses need to allow employees to access work information from personal or otherwise unmanaged devices.

Managing the entire device may be inappropriate, particularly when it belongs to the employee.

Intune App Protection Policies can protect business information within approved applications, even when the organisation does not manage the complete device.

Policies can help:

  • Require a PIN before opening business information
  • Prevent work data being copied into personal applications
  • Restrict saving to unapproved storage
  • Protect Outlook, Teams and other supported apps
  • Remove business information without wiping personal content
  • Require approved applications
  • Restrict access when the device presents a security risk

Microsoft describes these controls as Mobile Application Management. They can separate organisational data from personal information at the application level and can be enforced using Conditional Access. (Microsoft Learn)

Why We Like It

App Protection Policies can provide a useful balance between productivity and privacy.

The organisation protects its information without necessarily taking full control of the employee’s personal phone.

This is particularly useful for:

  • Mobile email
  • Bring-your-own-device arrangements
  • Contractors
  • Temporary workers
  • Senior employees using personal devices

The organisation still needs a clear mobile-device and acceptable-use policy.

Technology should support the agreed rules rather than replace them.

6. Safe Links

Phishing emails often include a link to a fake Microsoft 365 login page, fraudulent payment portal or malware-hosting website.

The link may appear genuine when the email first arrives.

The criminal can also change the destination after the message has passed through initial security checks.

Safe Links provides additional protection by analysing supported links when users select them.

It works alongside Microsoft’s normal anti-spam and anti-malware protection and can block access when a link is identified as malicious. Safe Links is part of Microsoft Defender for Office 365 Plan 1, which is included in Microsoft 365 Business Premium. (Microsoft Learn)

Safe Links can protect supported links in areas including:

  • Email
  • Microsoft Teams
  • Office applications
  • SharePoint
  • OneDrive

Why We Like It

Employees are frequently told not to click suspicious links.

The problem is that modern phishing messages can be extremely convincing.

Safe Links adds a technical layer of protection at the point when the employee attempts to visit the website.

It does not mean users can click anything without thinking.

No security product will detect every malicious website immediately, and employees should still report messages that appear unusual.

7. Safe Attachments

Malicious attachments may contain ransomware, malware or files designed to steal information.

The attachment might appear to be:

  • An invoice
  • A purchase order
  • A CV
  • A delivery notice
  • A Microsoft document
  • A voicemail
  • A customer enquiry
  • A scanned document

Safe Attachments provides an additional layer of analysis for files received through supported Microsoft 365 services.

Microsoft Defender for Office 365 can analyse attachments in a protected environment before deciding whether they should be delivered, blocked or otherwise handled according to the organisation’s policy. (Microsoft Learn)

Why We Like It

A file can look completely normal to the person receiving it.

Safe Attachments allows Microsoft 365 to examine behaviour that may not be visible from the file name or icon.

Protection can also extend to supported files in SharePoint, OneDrive and Microsoft Teams.

As with every Microsoft 365 security feature, policies need to be reviewed.

The organisation should understand what happens when a file is being analysed, how employees are informed and who investigates detections.

8. Anti-Phishing and Impersonation Protection

Cybercriminals often impersonate trusted people rather than relying on obviously malicious messages.

They may pretend to be:

  • The managing director
  • A finance employee
  • A customer
  • A supplier
  • Microsoft
  • The organisation’s IT provider
  • A colleague
  • A bank

The email address may be spoofed, or the criminal may use a lookalike domain and familiar display name.

Microsoft 365 includes baseline anti-phishing and spoof protection for cloud mailboxes. Microsoft Defender for Office 365 adds more advanced impersonation features, including protection for selected users and domains. (Microsoft Learn)

Policies can help protect:

  • Senior leaders
  • Finance teams
  • Frequently impersonated employees
  • Trusted supplier domains
  • Your own business domain

Why We Like It

Many damaging cyber incidents begin with a message that appears to come from someone the employee trusts.

Impersonation protection can identify subtle warning signs that an employee may miss.

This is particularly useful for payment-diversion fraud, where a criminal impersonates a director or supplier and requests an urgent transfer.

Technical controls should be supported by clear verification procedures.

Bank-detail changes and unusual payment instructions should always be confirmed through an independently verified contact method.

9. Preset Security Policies

Microsoft 365 contains a large number of email-security settings.

Configuring every individual option manually can be complicated, and important protections may be missed.

Preset Security Policies provide Microsoft-recommended groups of settings that can be applied to users.

The main options include:

  • Standard protection
  • Strict protection
  • Built-in protection

Depending on licensing, these policies can configure areas such as:

  • Anti-malware
  • Anti-spam
  • Anti-phishing
  • Safe Links
  • Safe Attachments

Microsoft recommends preset policies as a way to apply a consistent security baseline without relying entirely on individually created policies. (Microsoft Learn)

Why We Like It

Microsoft 365 security portals can be complicated.

Preset policies provide a practical starting point and help reduce the risk of important settings being left disabled.

Strict protection may be appropriate for higher-risk users such as:

  • Administrators
  • Directors
  • Finance employees
  • Employees with access to confidential information

Policies should still be reviewed for the organisation’s needs.

A standard template cannot understand every legitimate sender, business application or operational requirement.

10. Sensitivity Labels

Sensitivity labels allow businesses to classify information according to its importance or confidentiality.

An organisation might create labels such as:

  • Public
  • Internal
  • Confidential
  • Customer Confidential
  • Highly Confidential

Depending on configuration and licensing, a sensitivity label can apply controls such as:

  • Encryption
  • Access restrictions
  • Visual markings
  • Sharing limitations
  • Content protection
  • Rules for Microsoft Teams and SharePoint sites

Microsoft Purview sensitivity labels can continue protecting supported documents and emails as they move between services and devices. They can also work with SharePoint, OneDrive, eDiscovery and data-loss prevention. (Microsoft Learn)

Why We Like It

Not every document needs the same level of protection.

A public brochure should not be handled like employee records, financial information or a confidential customer contract.

Sensitivity labels allow the protection to follow the information rather than depending entirely on the folder in which it was originally stored.

The label structure should remain simple.

If employees are given too many confusing choices, they may select the wrong label or avoid using the system properly.

11. Data Loss Prevention

Data Loss Prevention, commonly known as DLP, can help identify when sensitive information is being shared or handled inappropriately.

Microsoft Purview DLP can recognise supported types of information, such as:

  • Bank details
  • Credit-card information
  • Passport numbers
  • National Insurance numbers
  • Health information
  • Employee information
  • Other defined confidential data

Depending on the policy, Microsoft 365 can:

  • Warn the employee
  • Provide guidance
  • Request a justification
  • Block the activity
  • Generate an alert
  • Record the event for investigation

DLP can operate across supported Microsoft 365 locations, including Exchange, SharePoint, OneDrive and Microsoft Teams, depending on the organisation’s licensing and configuration. (Microsoft Learn)

Why We Like It

Many data breaches are accidental.

An employee may:

  • Email information to the wrong recipient
  • Share an unrestricted link
  • Upload data to an unsuitable location
  • Copy business information into a personal service
  • Send an attachment outside the organisation

DLP can intervene at the point where the risky activity occurs.

Policies need to be tested carefully.

A policy that blocks too much legitimate work will frustrate employees and may encourage them to look for unofficial workarounds.

12. Microsoft Purview Message Encryption

Businesses sometimes need to send confidential information outside the organisation.

This may include:

  • Contracts
  • Financial information
  • Employee records
  • Customer documents
  • Legal information
  • Personal data

Microsoft Purview Message Encryption allows supported users to send encrypted messages to people inside or outside the organisation.

The recipient can access the protected message using the appropriate verification process, even when they do not use Microsoft 365. Encryption can be applied manually or automatically through mail-flow rules and information-protection policies. (Microsoft Learn)

Microsoft Purview Message Encryption is included in Microsoft 365 Business Premium and several enterprise subscriptions. (Microsoft Learn)

Why We Like It

Email is convenient, but standard messages can be forwarded, copied or delivered to the wrong person.

Message encryption provides an additional method for protecting sensitive content.

It can also be combined with restrictions such as preventing forwarding or limiting what the recipient can do with the content.

Encryption should not create false confidence.

The sender still needs to check the recipient, attachment and contents before sending the message.

13. Microsoft Purview Audit

Audit records can help an organisation understand what happened within Microsoft 365.

Depending on the available licence, permissions and retention period, audit searches may show events relating to:

  • User sign-ins
  • File access
  • Document sharing
  • Mailbox activity
  • Administrative changes
  • Microsoft Teams activity
  • SharePoint and OneDrive actions
  • Security events
  • Application consent
  • Policy changes

Microsoft Purview provides audit-search capabilities, while related audit searches can also be accessed through the Microsoft Defender portal. (Microsoft Learn)

Why We Like It

When a suspicious event occurs, businesses need evidence.

For example:

  • Who created an email-forwarding rule?
  • Who downloaded a confidential file?
  • When was an account changed?
  • Which administrator modified a policy?
  • Was a document shared externally?
  • Which application received access?

Audit logs can support cybersecurity investigations, compliance work and internal reviews.

The organisation should understand how long audit data is retained under its licence.

It should not wait until after an incident to discover that the required records are unavailable or that nobody has permission to search them.

14. Microsoft Secure Score

Microsoft Secure Score provides a central view of recommended security improvements across supported Microsoft identities, devices and applications.

It can highlight actions such as:

  • Enabling stronger authentication
  • Improving email policies
  • Restricting administrator access
  • Securing devices
  • Reviewing applications
  • Strengthening data protection
  • Correcting configuration weaknesses

Microsoft Secure Score is available through the Microsoft Defender portal and is intended to help organisations assess and improve their security posture. (Microsoft Learn)

Why We Like It

Microsoft 365 contains many separate security portals, settings and policies.

Secure Score can help bring important recommendations into one place.

It also gives the IT provider and business leaders a way to track whether the environment is improving.

However, the objective should not be to achieve the highest possible number without considering the consequences.

Some recommendations may not be suitable for every organisation.

A change should be assessed against:

  • Business requirements
  • User experience
  • Application compatibility
  • Security risk
  • Available licensing
  • Existing controls

Secure Score should guide security improvements rather than replace professional judgement.

Microsoft 365 Security Features Still Need Management

Microsoft 365 can provide powerful security capabilities, but the platform does not manage itself.

Businesses can still be exposed when:

  • Multi-factor authentication is not enforced
  • Conditional Access policies are missing
  • Security alerts are ignored
  • Former employee accounts remain active
  • Devices are not enrolled
  • Excessive administrator access exists
  • External sharing is unrestricted
  • DLP policies have not been tested
  • Safe Links and Safe Attachments are poorly configured
  • Audit records are never reviewed

Microsoft provides the technology.

The organisation and its IT provider remain responsible for configuring and operating the environment correctly.

Do You Have the Right Microsoft 365 Licence?

Not every Microsoft 365 subscription includes every feature discussed in this article.

Microsoft 365 Business Premium is commonly selected by small and medium-sized organisations because it combines productivity applications with services including:

  • Microsoft Entra ID Plan 1
  • Conditional Access
  • Microsoft Intune Plan 1
  • Microsoft Defender for Business
  • Microsoft Defender for Office 365 Plan 1
  • Information-protection capabilities

Microsoft’s Business plans are intended for organisations with up to 300 users. Larger organisations or those requiring more advanced identity, threat-detection and compliance features may need enterprise subscriptions or additional add-ons. (Microsoft Learn)

Licences should be selected according to the required security controls rather than only the applications employees want to use.

Which Features Should You Implement First?

Every organisation has different risks, but a strong starting point normally includes:

  • Multi-factor authentication
  • Conditional Access
  • Managed endpoint protection
  • Intune device management
  • Safe Links
  • Safe Attachments
  • Anti-phishing protection
  • Reliable audit logging

Information-protection features such as sensitivity labels and DLP can then be introduced through a planned project.

These controls need employee communication and testing because they can directly affect how people share and manage information.

How Hamilton Group Can Help

Hamilton Group helps businesses configure, secure and manage Microsoft 365.

We can review your current licences, security settings, users and devices before creating a practical improvement plan.

Our services can include:

  • Microsoft 365 security reviews
  • Multi-factor authentication
  • Conditional Access
  • Microsoft Defender for Business
  • Microsoft Defender for Office 365
  • Microsoft Intune
  • App Protection Policies
  • Safe Links and Safe Attachments
  • Anti-phishing protection
  • Sensitivity labels
  • Data Loss Prevention
  • Microsoft Purview Message Encryption
  • Audit-log reviews
  • Microsoft Secure Score improvements
  • Ongoing security monitoring
  • Managed IT support

At Hamilton Group, we aim to make first contact on IT support requests within 15 minutes, helping employees receive assistance quickly when a technology or security problem affects their work.

We can also help make sure the Microsoft 365 security features you already pay for are properly configured, monitored and delivering value.

Call Hamilton Group today on 0330 043 0069 to arrange a Microsoft 365 security review and discover whether your organisation is getting the protection included within its licences.

Microsoft 365 products, licensing and features can change. The controls available to your organisation will depend on its subscriptions, configuration and technical requirements.