Skip to main content
Microsoft 365ChecklistBeginner2 min readUpdated

Email Security Settings Every Microsoft 365 Admin Should Check

Six settings inside Microsoft 365 that quietly reduce your exposure to phishing and account takeover — most take minutes to enable.

Written by

Zach Swartz, Business Technology Advisor

Zach Swartz

Business Technology Advisor · Great Falls, Montana

Most email compromise starts with a setting that was never configured, not a sophisticated attack. Work through this list.

Inbound emailAnti-phishing policiesExternal-sender labelingSafe Links & Safe AttachmentsMFA enforced, legacy auth blockedStaff inbox
Each setting is an independent layer. Any one of them can be the one that catches a message the others let through — which is why the list is worth finishing.
  1. Multifactor authentication is enforced, not optional. A conditional access policy that requires it, rather than a recommendation staff can ignore.
  2. Anti-phishing policies are turned on. Microsoft Defender's impersonation protection catches lookalike domains and display-name spoofing that basic filtering misses.
  3. External email is labeled. A banner marking messages from outside your organization makes spoofed internal emails easier for staff to spot.
  4. Mail forwarding rules are reviewed. Auto-forwarding to external addresses is a common sign of a compromised mailbox — and one attackers rely on to stay hidden.
  5. Safe Links and Safe Attachments are enabled, if your licensing includes them, so malicious links and files are checked before they reach an inbox.
  6. Legacy authentication protocols are blocked. Older sign-in methods don't support modern MFA and are a common way stolen passwords are still exploited.

None of these require new software — they're switches inside the tenant you're already paying for.

Not sure where your organization stands?

The Business Success Assessment covers this topic and more, with results in about 7–10 minutes.