Microsoft 365 Tenant Hardening: The Configuration Changes That Matter Most

A hardened Microsoft 365 tenant keeps every account behind multifactor authentication, filters hostile email before anyone opens it, and records a searchable trail of who changed what. Four configuration changes establish that baseline:

Verified against the Microsoft Entra admin center, Microsoft Defender portal, and Microsoft Purview portal on 2026-08-03.

Prerequisites

These settings are best configured for scale on day one of a new tenant, and every one of them can be applied to a tenant that has been running on defaults for years.

Step 1: Turn On Security Defaults

Security defaults bundle the identity protections that matter most into a single switch: every user registers for multifactor authentication, admin roles confirm it on every sign-in, and legacy authentication protocols and device code flow are blocked outright. Microsoft reports that multifactor authentication combined with blocking legacy authentication stops more than 99.9 percent of common identity attacks.

  1. Sign in to the Microsoft Entra admin center.
  2. Go to Entra ID → Overview → Properties.
  3. Select Manage security defaults.
  4. Set Security defaults to Enabled, then select Save.

Tenants created on or after October 22, 2019 may already have security defaults enabled. Confirm the toggle rather than assuming.

Step 2: Apply the Standard Preset Security Policy to Email

Standard protection and Strict protection ship turned off, so a new tenant runs on the looser built-in defaults until someone applies a preset. Standard protection is the profile suited to most organizations.

  1. In the Microsoft Defender portal, go to Email & collaboration → Policies & rules → Threat policies → Preset Security Policies.
  2. In the Standard protection section, select Manage protection settings to start the configuration wizard.
  3. On the Apply Exchange Online Protection page, choose All recipients, then select Next.
  4. If your licensing includes Defender for Office 365, choose All recipients on the Apply Defender for Office 365 protection page as well, then select Next through the impersonation protection pages.
  5. On the Review and confirm your changes page, select Confirm.

Step 3: Confirm the Unified Audit Log Is Recording

The audit log answers the questions that come up after something odd happens: who forwarded that mailbox, who granted that app permission, who deleted that file. Auditing is not enabled by default on the small business licenses, including Microsoft 365 Business Basic, Business Standard, and Business Premium, so a growing company can easily assume a trail exists that was never being recorded.

  1. Sign in to the Microsoft Purview portal.
  2. Select the Audit solution card.
  3. If auditing is off, a banner prompts you to start recording user and admin activity. Select Start recording user and admin activity.

Enabling can take up to 60 minutes, and recorded activity is retained for 180 days on the standard tier.

Step 4: Trim Admin Roles and Add Break-Glass Accounts

Every account holding Global Administrator is a full-tenant compromise waiting on one successful phish, so the role list deserves the same attention as any setting.

Verify

Troubleshooting

The security defaults toggle will not enable: the tenant has Conditional Access policies, and the two cannot run together. Either remove the policies or adopt Conditional Access as your baseline instead.

A printer or scanner stopped sending email: security defaults block the legacy authentication those devices often use. Reconfigure the device using Microsoft's guidance for multifunction devices sending through Microsoft 365.

Audit searches return nothing: newly enabled auditing takes up to 60 minutes to activate, and events can take several hours to become searchable. Re-run the PowerShell check before digging further.

What You Gain From a Hardened Baseline

A tenant configured this way shrugs off the password spray and phishing traffic that every business domain attracts, and it hands you a clean audit trail whenever a question needs answering. ScaleIt applies and maintains this baseline for startups and SMBs as part of managed IT. Book a free call and we will review your tenant against it.

Verified against Microsoft Entra ID security defaults, Microsoft Defender for Office 365 preset security policies, and Microsoft Purview audit on 2026-08-03. Vendor docs: learn.microsoft.com/entra/fundamentals/security-defaults, learn.microsoft.com/defender-office-365/preset-security-policies, learn.microsoft.com/purview/audit-log-enable-disable.