
Microsoft 365 is the backbone of how most small businesses communicate, collaborate, and store information. Email, Teams, SharePoint, OneDrive — it all runs through a single platform. That is exactly why it is also one of the most targeted environments by cybercriminals.
The uncomfortable truth? Most small businesses are running Microsoft 365 with major security gaps and have no idea. Not because they are careless, but because the platform looks secure on the surface. Subscriptions are active, passwords are set, files are saving to the cloud. What else is there to do?
Quite a bit, actually.
A Microsoft 365 security assessment is the process of reviewing your tenant settings, user configurations, and security policies against current best practices. Think of it as a health check for your entire Microsoft environment. This guide walks you through what that process covers, what warning signs to look for, and why more Indianapolis-area businesses working with managed IT services are getting this done before a problem forces their hand.
Why Small Businesses Get Microsoft 365 Wrong
Here is the most common mistake: assuming Microsoft handles your security for you.
Microsoft operates on what is called a Shared Responsibility Model. That means Microsoft is responsible for keeping the infrastructure running, securing the physical data centers, and maintaining platform availability. What they are NOT responsible for is securing your accounts, your data configurations, your user permissions, or your email policies.
That responsibility sits with you.
Microsoft’s own security intelligence data shows that the overwhelming majority of Microsoft 365 account compromises involve stolen credentials and phishing attacks, not failures on Microsoft’s infrastructure side. These attacks succeed because the customer’s side of the equation is left unsecured.
Business Email Compromise (BEC) is a good example. A hacker gains access to one email account, often through a phishing link or a reused password, and quietly monitors conversations for weeks. Then they step in at exactly the right moment, impersonating a vendor or executive, and redirect a payment. The FBI’s Internet Crime Complaint Center consistently reports BEC as the highest-dollar cybercrime category in the country.
Microsoft 365 accounts are a primary target. Default settings alone will not protect you.
What a Microsoft 365 Security Assessment Actually Covers
A proper assessment reviews your Microsoft 365 tenant against documented best practices. Here are the key areas any thorough review should include.
Multi-Factor Authentication (MFA). This is the single biggest lever for reducing account compromise risk. When MFA is enforced, a stolen password alone is not enough to access an account. Microsoft reports that MFA blocks more than 99% of credential-based attacks. Yet many small businesses still have it turned off for some or all users, often because no one prioritized enabling it after initial setup.
Admin Roles and Permissions. Every Microsoft 365 tenant has at least one Global Administrator account. Many small businesses have several, which creates unnecessary risk. If one of those accounts is compromised, the attacker has complete control over your entire environment. A proper review checks how many admin roles exist, who has them, and whether the principle of least privilege is being followed.
Email Security Settings. This covers your DMARC, DKIM, and SPF records, which authenticate your outbound email and prevent spoofing. It also includes the anti-phishing, anti-spam, and Safe Links policies inside Microsoft Defender. Many businesses have these tools available in their subscription but have never configured them.
Conditional Access Policies. These policies control who can access your Microsoft 365 environment, from where, and on what devices. Without them, a staff member’s compromised account could be accessed from anywhere in the world with no alerts triggered. This connects directly to broader IT security and network protection practices that keep your entire environment safe.
Legacy Authentication Protocols. Older authentication methods like Basic Authentication bypass MFA entirely and are a known attack vector. Microsoft has been disabling them by default in newer tenants, but older environments may still have them active. An assessment catches this.
Data Loss Prevention (DLP) Policies. DLP policies prevent sensitive information like Social Security numbers, credit card numbers, or HIPAA-covered data from being shared outside the organization accidentally. Without them, a well-meaning employee can inadvertently expose customer or patient data with a single email.
Audit Logging. If something goes wrong, you need to be able to trace it. Unified audit logging must be turned on in your tenant to retain records of user activity. Without this, forensic investigation after a breach becomes nearly impossible and compliance requirements may not be met.
Microsoft Secure Score. Microsoft provides a built-in benchmarking tool that scores your tenant’s security posture out of a possible total. Most unreviewed small business environments score well below 50%. An assessment uses this score as a baseline and maps specific actions to improve it.
Red Flags That Suggest Your M365 Needs Attention
You do not need an IT background to recognize these warning signs. If any of the following describe your environment, your Microsoft 365 setup likely has gaps that need addressing.
- No multi-factor authentication is enforced for any users
- Multiple staff members have Global Admin access
- Files in SharePoint or OneDrive can be shared externally via “anyone with a link”
- Former employees still have active user accounts
- No security alerts or unusual login notifications are configured
- Staff have never gone through a phishing simulation or security awareness training
- Your Microsoft Secure Score is below 40%, or you have never checked it
- Your business has grown or added staff but the original account setup has never been revisited
Even one of these is worth investigating. Several together represent a pattern of risk that is one well-crafted phishing email away from a serious incident.
The Business Cost of Skipping a Security Assessment
Security assessments can feel like a “nice to have” until a breach makes them feel like something you wish you had done six months ago.
IBM’s Cost of a Data Breach Report consistently places the average breach cost for small and mid-sized businesses in the range of several hundred thousand dollars when you factor in downtime, recovery costs, regulatory notifications, and reputational damage. For many small businesses, that number is not survivable.
There are also secondary costs that business owners rarely factor in. Cyber liability insurance underwriters are increasingly requiring documented security controls, including MFA and audit logging, as baseline requirements before issuing or renewing a policy. If you experience a breach and your insurer determines that basic controls were not in place, your claim can be denied.
Compliance is another pressure point. Businesses in legal, medical, dental, financial, and insurance sectors face regulatory requirements around data protection. A Microsoft 365 environment that has never been reviewed for HIPAA or PCI-relevant settings is a compliance liability, not just a security one.
And then there is the operational reality: studies tracking breach timelines have found that attackers often remain inside a network for months before being detected, especially without proper audit logging in place.
| Not sure where your Microsoft 365 environment stands? OnTrack IT offers a free IT assessment for Central Indiana businesses. There is no obligation, and you will come away with a clear picture of where your risks are. Request Your Free IT Assessment |
How OnTrack IT Helps Indianapolis Businesses Secure Microsoft 365
OnTrack IT Partners has been supporting small and mid-sized businesses across Indianapolis, Carmel, Fishers, and the surrounding area for more than 35 years. Over that time, the team has reviewed hundreds of Microsoft environments and seen the same patterns repeatedly: organizations that set up Microsoft 365, got to work, and never revisited the security settings.
An OnTrack IT Microsoft 365 security assessment is a systematic review of your tenant settings against current Microsoft best practices and Secure Score benchmarks. The process is remote-friendly and does not disrupt your team’s daily work.
What you get at the end is not a 40-page document full of technical language. It is a prioritized findings report that tells you what is misconfigured, what the risk is, and what to do about it in order of importance. From there, OnTrack can implement the fixes, train your staff, or hand the report off to your internal IT person. No long-term contracts, no pressure.
The goal is to give you a clear, honest picture of where you stand, and the practical steps to get where you need to be.
Frequently Asked Questions
How long does a Microsoft 365 security assessment take?
The review itself typically takes one to three hours and is conducted remotely, so there is no disruption to your team. You receive a written findings report shortly after.
Do I need Microsoft 365 Business Premium to be secure?
No. Business Basic and Business Standard can be significantly hardened through proper configuration. An assessment covers what you have and recommends cost-effective upgrades only where genuinely needed.
We already have an internal IT person. Do we still need an assessment?
Often, yes. Internal IT staff manage day-to-day operations and may not have reviewed tenant configurations since the original setup. A fresh external review tends to surface gaps that have been overlooked simply because they were never in scope.
What happens after the assessment?
You receive a prioritized findings report. You decide what to act on. OnTrack can implement the recommended changes, run security awareness training for staff, or hand off the report to your team. There is no obligation to continue. You can also browse our security resources and guides for additional context on keeping your environment protected.
Is a Microsoft 365 security assessment a one-time thing?
It is a starting point. Settings drift over time as staff changes, new features roll out, and threat tactics evolve. A review every 12 months is best practice for most small businesses.
| OnTrack IT is trusted by businesses across Central Indiana, including Indianapolis, Carmel, Fishers, Noblesville, and Westfield. If you want to know where your Microsoft 365 environment actually stands, a free IT assessment is the right place to start.Schedule your free assessment at ontrack-it.com/contact-us. |