Microsoft 365 allows you to access emails and files from anywhere, on any device. Unfortunately, this also means attackers can gain access to your data with just a username and password.
Due to the significant increase in phishing and identity compromise attacks, we have defined a set of best practice security recommendations and made our minimum Baseline Security standard mandatory.
Strongly recommended for organisations handling sensitive, confidential, or regulated data.

Enhanced security options include:
Baseline Security
Our Baseline Security standard defines the minimum controls we implement and support to protect Microsoft 365 environments against common attack methods. It is mandatory that these elements are in place (or that there is an agreed plan for their implementation) in order for to ensure your business data and systems are secure.
Third-party Cloud Backup
Microsoft SharePoint and OneDrive for Business protect files using a combination of versioning and retention. A third-party cloud backup that provides additional protection should be utilised to guard against ransomware and other data loss.
Managed Antivirus
An antivirus (EDR/XDR) that is centrally managed and can report on the status of individual PCs or laptops. Our preferred anti-virus technology is Microsoft Defender for Business/Endpoint, an advanced next-generation version of the standard Windows 10/11 Defender.
Enhanced Email Filtering/Protection Service
We require an enhanced email filtering/protection service that scans URLs and attachments within emails for malicious links and looks for the common signs of impersonation. This can be from Microsoft – Microsoft Defender for Office 365 or from a third-party such as Mimecast or Barracuda.
Multi-factor Authentication (MFA)
Multi-factor Authentication requires you to type a code from your phone or accept a notification to get access to Microsoft 365. This can prevent hackers from taking over if they know your password.
Further granular settings for MFA can be achieved using Conditional Access (an element of Baseline+ Security).
Baseline+ Security
Our recommended minimum provision for organisations with increased compliance, cyber insurance, or audit requirements.
This is our recommended minimum provision, it is a combination of Baseline Security, plus:
Conditional Access
Conditional Access allows granular access to corporate resources based on ‘If/Then’ statements which can be based on user/device/location, or application. Depending on the result of the conditions, only enrolled users/devices/locations can be allowed access Microsoft 365 accounts without an MFA challenge.
Encryption
Laptop and desktop hard/solid state disks can be encrypted so that if a device is lost and even if the disk was removed it would not be possible to read/copy the contents. The deployment and management of the encryption keys can be centrally managed using BitLocker and Intune.
DMARC
DMARC (Domain-based Message Authentication, Reporting & Conformance) is an email authentication, policy, and reporting protocol. It helps prevent hackers and other attackers from spoofing your organisation and domain.
DMARC is increasingly a mandatory requirement for cyber insurance and compliance.
Enhanced Security
There are a number of enhanced security options that are strongly recommended for organisations that handle sensitive, confidential information, or have regulatory compliance requirements, these include:
Extend Audit Log Duration
As standard Microsoft 365 only log activity to the audit logs for a rolling 180-day period. In the case of an investigation this could be very limiting.
We strongly recommend extending the logging duration with Microsoft Log Analytics, which extends the logging to 24-months with the ability to further archive these logs indefinitely.
Single Sign-on (SSO)
Single Sign-on allows users to sign in once with one account to access company resources, software as a service (SaaS) applications (such as Salesforce, accounting systems, etc.), and web applications.
After signing in, the user can launch the applications whilst securely authenticated with Microsoft 365.
Document Protection
It is possible to configure additional security to protect files and documents regardless of where they reside. For example, if you shared a sensitive file with a prospective investor and the deal did not progress, you could revoke access regardless of whether they kept a local copy of the file.
It is possible to discover and automatically categorise your sensitive information such as PII or banking information across a variety of locations including devices, apps, cloud services, and on-premises.
We can implement a service to apply sensitivity labels manually or automatically to files. Allowing data security actions such as encryption, digital rights management (DRM), and visual markings (such as ‘Confidential’) to be applied.
Cloud Access Security Broker (CASB)
Cloud Access Security Brokers (CASBs) are cloud-based security solutions that provide a new layer of security to enable oversight and control of activities and information across cloud SaaS apps – not just Microsoft 365, but other services such as Dropbox, Salesforce, etc. that may be used in an official or unofficial manner (known as ‘Shadow IT’).
CASBs have four key capability areas 1) Shadow IT discovery, 2) information protection, 3) threat protection, and 4) compliance. They provide a central control plane for governance and policy enforcement across all your cloud apps and services.
We can determine the elements you may wish to implement and the most appropriate configuration/reporting settings. This can be undertaken in a phased approach, we initially recommend a basic implementation of Microsoft Defender for Cloud Apps (MDCA) to capture a detailed audit trail of all user and admin activities for forensic investigations.
Other potential uses include:
– Discovering all cloud apps and services used in your organisation, both official and shadow (unofficial).
– Restrict access to specified applications from any managed device.
– Detect when data is being exfiltrated from your corporate apps, this can alert you on suspicious usage that indicate a potential attempt to misappropriate information.
– Protect your data when downloaded to unmanaged devices, it can be configured with granular controls to either prevent the download of sensitive files altogether, or apply a protection label.
Terms of Use
It is possible to require users (internal or external) to agree to accept your terms of use before gaining access.
This can be granularly applied, for example present specific terms of use when accessing high business impact applications, such as an accounting system.
Threat Detection and Incident Response
Syntax are developing an advanced Threat Detection and Incident Response service that combines a 24×7 Security Operations Centre (SOC) with access to security experts and Extended Detection and Response (XDR).
This will include:
– 24×7 incident response and management
– Quarterly security posture review and recommendations
– Incident reporting
– Incident details and timeline
– Threat overview
– Guidance and prevention
– Remediation
Enhanced Management
We are also able to offer a range of Enhanced Management services, building upon the functionality of Enhanced Security.
We would wish to further discuss your requirements and tailor the provision to meet your specific requirements. This can include elements such as:
– Automatic Software Deployment and Management
– Inventory and Asset Management
– Mobile Device Management
– Advanced Security Monitoring and Threat Prevention
To speak to an IT Expert about our Security Recommendations
Call today on 020 7307 5008
Ready to improve your Microsoft 365 Security?
We are working closely with Microsoft to identify new ways to help you stay secure, and we are developing a roadmap of recommendations which we will be sharing with you regularly to ensure that you are kept abreast of best practice as the security landscape evolves.
Ready to improve your Microsoft 365 security? Speak to an expert to discuss your current Microsoft 365 security posture and next steps.
Frequently Asked Questions
What is a Microsoft 365 security audit?
A Microsoft 365 security audit reviews your tenant against current security best practices. It checks MFA enforcement, email protection, admin permissions, audit logging, data sharing, and backup.
The outcome is a clear list of risks and a prioritised remediation plan to strengthen your Microsoft 365 security posture.
How important is a Microsoft 365 backup?
Microsoft provides availability, not full backup, so this is very important.
A dedicated Microsoft 365 backup solution protects against ransomware, malicious deletion, and long-term data loss. It gives you independent, point-in-time recovery across Exchange, SharePoint, OneDrive, and Teams.
For most businesses, third-party backup is a baseline control.
What are the essential Microsoft 365 security solutions for SMEs?
At a minimum:
– Enforced MFA – Mobile App Protection
– Enhanced email filtering
– Managed endpoint protection
– Third-party Microsoft 365 backup
– Admin role controls
These controls address phishing, identity compromise, and ransomware, which remain the most common threats.
What should be included in a Microsoft 365 security checklist?
A typical checklist covers:
– MFA enabled for all users
– Legacy authentication disabled
– Conditional Access configured
– Secure email protection active
– Backup in place
– Audit logs reviewed
It should be reviewed regularly, not treated as a one-off task.
How are Microsoft 365 security services different from standard IT support?
IT support resolves day-to-day issues. Microsoft 365 security services focus on hardening configuration, enforcing policy, reducing risk, and aligning with compliance or cyber insurance requirements.
It is proactive security management, not reactive troubleshooting.
IT support resolves day-to-day issues. Microsoft 365 security services focus on hardening configuration, enforcing policy, reducing risk, and aligning with compliance or cyber insurance requirements. It is proactive security management, not reactive troubleshooting.