Hardening Microsoft 365 for a 50-seat firm
Most breaches I get called in on don't start with something exotic. They start with a legacy auth protocol nobody remembered to turn off and a shared mailbox with a weak password. This engagement was a textbook case — and a good example of how much risk you can remove with configuration alone.
The starting point
A 50-seat professional services firm had grown into Microsoft 365 organically. The tenant reflected that: no Conditional Access, MFA "encouraged" but not enforced, legacy authentication wide open, and global admin rights handed out like business cards.
What I changed
- Enforced phishing-resistant MFA via Conditional Access, scoped by risk so low-risk sign-ins stayed frictionless.
- Killed legacy authentication (POP, IMAP, basic auth) after two weeks of report-only monitoring to catch anything that would break.
- Tiered admin access — separate, MFA-gated admin identities, and dropped standing global admins from nine to two, with the rest moved to just-in-time roles via Privileged Identity Management.
- Baseline device compliance through Intune before granting access to corporate data.
The result
Sign-in risk detections dropped to near zero within a month, and the firm passed its cyber-insurance assessment on the first attempt. Total downtime for the cutover: under an hour, scheduled on a Friday evening.
The lesson I keep relearning: the highest-leverage security work is rarely a new tool. It's turning off the defaults that should never have been on.
If your Microsoft 365 tenant grew the way this one did, a configuration review is the cheapest security win available to you.
Have a similar challenge?
I help businesses secure and run their IT. Let's talk.
Start a conversation →