A Microsoft 365 email security baseline that fits a 40-person firm
You do not need every blade in the portal. You need a short list that stays on.
ITSIGN Administrator · September 24, 2025 · 2 min read
MFA. Safe Links / Safe Attachments if you licence them. External banners. Disable legacy auth. Audit forwarding. Lock down shared mailboxes.
Review quarterly. Drift is the enemy.
Cloud and Microsoft 365 is the ongoing version of that list.
Related reading
Email retention, PIPEDA, and the mailbox you never deleted
Keeping everything forever is not a strategy. It is a larger breach waiting for a number.
2 min read
When the phish comes from a vendor you trust
Their tenant, your payment. Callback still wins. So does knowing who is allowed to change details.
2 min read
Turn off IMAP and POP before someone else uses them
Legacy protocols skip modern MFA. They are still on in tenants that were migrated in a hurry.
2 min read
Want this applied to your environment?
A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.
