Microsoft 365, Email and Cloud Security Basics for Small Businesses

The essential controls small businesses should use to protect Microsoft 365, email and other cloud services from account takeover and impersonation.

Cyber Security Basics · Lesson 8 of 10

Quick answer: The essential controls small businesses should use to protect Microsoft 365, email and other cloud services from account takeover and impersonation.

For many small businesses, Microsoft 365 or another cloud platform is now the centre of day-to-day operations. Email, files, Teams, calendars and identity are all connected, which makes cloud-account security a business priority.

Start with strong sign-in protection

Enable MFA for users and especially administrators. Review legacy sign-in methods and make sure recovery information is controlled by the organisation rather than tied to old personal details.

Separate administration from everyday use

Administrator accounts should not be used for routine email and browsing. Keep privileged accounts separate and limit the number of people with high-level roles.

Watch for suspicious mailbox rules

Attackers who gain access to a mailbox may create forwarding or inbox rules that hide messages or copy them elsewhere. Unexpected rules, new authentication methods or unfamiliar sign-ins should be investigated.

Protect the email domain

SPF, DKIM and DMARC help receiving systems verify legitimate mail and reduce opportunities for domain spoofing. They should be configured carefully so legitimate services such as CRM, marketing platforms and website forms are included.

Use anti-phishing and impersonation controls

Email protection can help detect malicious links, attachments and impersonation attempts, but it should be combined with staff awareness and finance verification procedures.

Understand cloud backup

Review how email, OneDrive, SharePoint and Teams data would be recovered following accidental deletion, ransomware, compromised administration or retention limits. An independent Microsoft 365 backup may form part of the recovery design.

Monitor changes and sign-ins

Important signals include unexpected countries, impossible travel, new MFA registrations, administrator role changes, mailbox forwarding and unusual application consent. Logging only helps if somebody reviews the alerts that matter.

What to do after this lesson

Review your Microsoft 365 administrator accounts, MFA status and mailbox forwarding rules. Then confirm how your business would recover a deleted mailbox or SharePoint file.

Frequently asked questions

Is Microsoft 365 secure by default?

Microsoft 365 includes strong security capabilities, but protection depends on configuration, licensing, identity controls, monitoring and business processes.

Do we need DMARC if we use Microsoft 365?

DMARC is a domain-level email authentication control and can be useful regardless of the mailbox platform, provided SPF and DKIM alignment are configured correctly.

Should Microsoft 365 be backed up separately?

Businesses should assess their recovery requirements and decide whether native retention and recovery features are sufficient or whether an independent backup is needed.

Useful UK guidance

Put the lesson into practice

39Security helps small businesses turn cyber security guidance into practical controls and owned actions.

Course overview ← Previous lesson Next lesson →