Microsoft 365 Tenant Hardening: The Configuration Changes That Matter Most
A hardened Microsoft 365 tenant keeps every account behind multifactor authentication, filters hostile email before anyone opens it, and records a searchable trail of who changed what. Four configuration changes establish that baseline:
- Turn on security defaults in Microsoft Entra ID
- Apply the Standard preset security policy to email
- Confirm the unified audit log is recording
- Trim the admin role list and add break-glass accounts
Verified against the Microsoft Entra admin center, Microsoft Defender portal, and Microsoft Purview portal on 2026-08-03.
Prerequisites
- An account holding at least the Conditional Access Administrator role, for security defaults
- The Audit Logs role in Exchange Online, included in the Organization Management role group, for the auditing change
- Any Microsoft 365 license tier. If you hold Microsoft Entra ID P1 or P2, skip security defaults and use Conditional Access policies instead; Microsoft ships managed policies that cover the same ground with room for exceptions.
These settings are best configured for scale on day one of a new tenant, and every one of them can be applied to a tenant that has been running on defaults for years.
Step 1: Turn On Security Defaults
Security defaults bundle the identity protections that matter most into a single switch: every user registers for multifactor authentication, admin roles confirm it on every sign-in, and legacy authentication protocols and device code flow are blocked outright. Microsoft reports that multifactor authentication combined with blocking legacy authentication stops more than 99.9 percent of common identity attacks.
- Sign in to the Microsoft Entra admin center.
- Go to Entra ID → Overview → Properties.
- Select Manage security defaults.
- Set Security defaults to Enabled, then select Save.
Tenants created on or after October 22, 2019 may already have security defaults enabled. Confirm the toggle rather than assuming.
Step 2: Apply the Standard Preset Security Policy to Email
Standard protection and Strict protection ship turned off, so a new tenant runs on the looser built-in defaults until someone applies a preset. Standard protection is the profile suited to most organizations.
- In the Microsoft Defender portal, go to Email & collaboration → Policies & rules → Threat policies → Preset Security Policies.
- In the Standard protection section, select Manage protection settings to start the configuration wizard.
- On the Apply Exchange Online Protection page, choose All recipients, then select Next.
- If your licensing includes Defender for Office 365, choose All recipients on the Apply Defender for Office 365 protection page as well, then select Next through the impersonation protection pages.
- On the Review and confirm your changes page, select Confirm.
Step 3: Confirm the Unified Audit Log Is Recording
The audit log answers the questions that come up after something odd happens: who forwarded that mailbox, who granted that app permission, who deleted that file. Auditing is not enabled by default on the small business licenses, including Microsoft 365 Business Basic, Business Standard, and Business Premium, so a growing company can easily assume a trail exists that was never being recorded.
- Sign in to the Microsoft Purview portal.
- Select the Audit solution card.
- If auditing is off, a banner prompts you to start recording user and admin activity. Select Start recording user and admin activity.
Enabling can take up to 60 minutes, and recorded activity is retained for 180 days on the standard tier.
Step 4: Trim Admin Roles and Add Break-Glass Accounts
Every account holding Global Administrator is a full-tenant compromise waiting on one successful phish, so the role list deserves the same attention as any setting.
- Keep Global Administrator assignments to the smallest set that can run the tenant, and use scoped roles such as User Administrator or Exchange Administrator for routine work.
- Give admins separate accounts for administration and for daily productivity. Microsoft recommends this split, and it also cuts down how often admins face multifactor prompts during normal work.
- Create two cloud-only emergency access accounts permanently assigned Global Administrator, per Microsoft's recommendation, with credentials stored offline. These are the accounts that get you back in when normal admin sign-in fails.
Verify
- Sign in with a test user and confirm the multifactor registration prompt appears.
- In Exchange Online PowerShell, run Get-AdminAuditLogConfig | Format-List UnifiedAuditLogIngestionEnabled and confirm the value is True.
- On the Preset Security Policies page, confirm Standard protection shows as turned on.
- List every Global Administrator and confirm each assignment is deliberate.
Troubleshooting
The security defaults toggle will not enable: the tenant has Conditional Access policies, and the two cannot run together. Either remove the policies or adopt Conditional Access as your baseline instead.
A printer or scanner stopped sending email: security defaults block the legacy authentication those devices often use. Reconfigure the device using Microsoft's guidance for multifunction devices sending through Microsoft 365.
Audit searches return nothing: newly enabled auditing takes up to 60 minutes to activate, and events can take several hours to become searchable. Re-run the PowerShell check before digging further.
What You Gain From a Hardened Baseline
A tenant configured this way shrugs off the password spray and phishing traffic that every business domain attracts, and it hands you a clean audit trail whenever a question needs answering. ScaleIt applies and maintains this baseline for startups and SMBs as part of managed IT. Book a free call and we will review your tenant against it.
Verified against Microsoft Entra ID security defaults, Microsoft Defender for Office 365 preset security policies, and Microsoft Purview audit on 2026-08-03. Vendor docs: learn.microsoft.com/entra/fundamentals/security-defaults, learn.microsoft.com/defender-office-365/preset-security-policies, learn.microsoft.com/purview/audit-log-enable-disable.