Microsoft 365 Settings Contractors Often Miss

Microsoft 365 is the center of many contractors' operations, yet key security defaults are often untouched. Review these settings with your IT provider.

3 min readBy Ironfield Cyber Team

For many contractors, Microsoft 365 is the center of daily operations: email, calendars, Teams, SharePoint, OneDrive, and often the sign-in for other tools. It is also where most account takeover and payment fraud incidents begin. The platform has strong security features, but many are not turned on by default or need deliberate configuration.

The names and locations of settings change as Microsoft updates its products, and available features depend on the license you hold. Use this list as a conversation guide with your IT provider.

Sign-in protection

Require multi-factor authentication for everyone

This is the single most important setting. Apply it to all users, including executives and shared or service accounts where possible. Prefer authenticator apps or hardware keys over text messages. Review how exceptions are handled, because a single unprotected account can be enough for an attacker.

Block legacy authentication

Older protocols that cannot support MFA allow attackers to bypass it. Confirm that legacy authentication is blocked unless a specific, reviewed need exists.

Use conditional access where licensed

Conditional access policies can require MFA from untrusted locations, block sign-ins from countries where you do not operate, and require compliant devices for sensitive data.

Email protection

Filtering

Make sure anti-phishing and malicious attachment protections are configured, not only left at the baseline. Higher license tiers add safe links and safe attachments.

Domain protection

Set up SPF, DKIM, and DMARC for your domain to make it harder for criminals to impersonate you to your vendors and customers. Begin DMARC in monitoring mode and move toward enforcement once you understand your legitimate senders.

Forwarding rules

Review automatic forwarding. Attackers often create hidden rules that copy mail to an outside address or delete security alerts. Disable external auto-forwarding unless there is a defined business need, and alert on new inbox rules.

External sender warnings

Tag messages from outside the company so staff notice when a message that looks internal is not.

Administrator accounts

  • Keep the number of global administrators small, usually a few named people.
  • Give administrators a separate account for admin tasks, not the one they use to read email.
  • Protect admin accounts with the strongest MFA available.
  • Review admin role assignments regularly.

Data sharing and storage

SharePoint, OneDrive, and Teams

Check default sharing settings. Anyone-with-the-link sharing is convenient and risky. For project folders holding contracts or sensitive drawings, restrict sharing to named people and set expirations on external links.

Guest access

Review guest users in Teams and SharePoint. Remove outside parties whose projects have ended.

Retention and backup

Microsoft provides availability, but you remain responsible for protecting against accidental deletion, malicious changes, and long-undetected compromise. Consider a third-party backup and review retention settings.

Devices and apps

Use device management to require encryption, passcodes, and updates on laptops and phones that access company data. Control which third-party apps may be granted access to company data. Approving a malicious app with broad permissions is a known technique, so limit user consent and review enterprise applications.

Monitoring

Turn on audit logging and review alerts for risky sign-ins, unusual file downloads, and new administrator assignments. Know how long logs are retained, because investigation depends on them.

A quick quarterly review

  1. Confirm MFA coverage.
  2. Review admin roles and guests.
  3. Check forwarding and inbox rules.
  4. Review secure score or similar recommendations.
  5. Check licenses assigned to departed users.

Common mistakes to avoid

  • Leaving a former employee's mailbox active and unmonitored for months.
  • Granting administrator rights to staff for convenience and never removing them.
  • Relying on security defaults without checking what they actually cover for your license level.
  • Allowing shared mailboxes to be signed into directly with a shared password.
  • Skipping a review after a staff change in accounting or executive roles, where fraud attempts concentrate.

A short, regular review catches most of these before they become incidents.

Working with Ironfield Cyber

Ironfield Cyber configures and supports Microsoft 365 for contractors and energy firms, from MFA rollout to email authentication and data-sharing controls. If you are not sure how your tenant is configured, we can review it and give you a prioritized list of changes.