
Key takeaways
- Multi-factor authentication on every account, with no exceptions for the owner, is the single change that stops most account break-ins.
- Conditional access lets you say who may sign in, from where and on what device; it needs Microsoft 365 Business Premium or an Entra ID P1 add-on.
- Microsoft does not back up your mailboxes and files in the way most owners assume; a separate backup of 365 data is a real need, not an upsell.
- Most breaches I have cleaned up started with a phishing email and an account that had no MFA; both are fixable in an afternoon.
- Admin hygiene matters as much as any product: separate admin accounts, as few global admins as possible, and a written offboarding routine.
Who can manage your Microsoft 365 and security in Dallas?
I can, and it is a large part of what I do. I am Anthony Omini, the owner of Cross River Tech, a small, owner-led managed IT company in Dallas. Microsoft 365 administration and security is included in my managed IT services and is also available as a stand-alone project through Microsoft 365 and Google Workspace support. I set tenants up, migrate businesses into them, harden them, and then look after them month to month. I work with businesses across Dallas–Fort Worth onsite and support Microsoft 365 remotely anywhere in Texas, because almost none of this work needs anyone in your office.
This article is the list of things I turn on and check for every small business tenant I take over. It is written for an owner or office manager, not an administrator, so each item says what it is, what it stops, and what license you need for it. If you already have someone managing your Microsoft 365, you can use it as a checklist to ask them about. If you do not, it tells you what "managing your 365 and security" should actually mean before you hire anyone, including me.
A note on scope. This is about protecting your accounts, your email and your files in Microsoft 365. It is not a complete cybersecurity program; computers, networks, backups of anything outside 365 and staff training are covered in cybersecurity, backup and disaster recovery.
Why is a fresh Microsoft 365 tenant not secure enough on its own?
Microsoft gives every new tenant a decent starting point called security defaults, and the platform itself is well built. The problem is what happens after the tenant is created. Someone sets it up in a hurry, turns off a prompt that annoyed the boss, adds a shared mailbox with a password everyone knows, gives three people global administrator rights because it was easier, and never looks at it again. Two years later the tenant is the way in.
The weak points I find most often when I take over a small business tenant:
- Multi-factor authentication turned off for one or two "important" people, who are exactly the people attackers want.
- Legacy sign-in methods still allowed, which quietly bypass MFA for old apps and scripts.
- Global administrator rights on accounts people use for daily email.
- Mailbox forwarding rules, sometimes created by an attacker months earlier, sending copies of every email to an outside address.
- Accounts of people who left still active, with licenses still being paid for.
- No backup of mailboxes, OneDrive or SharePoint at all, on the assumption that "it is in the cloud."
- Third-party apps that were granted access to everyone's mail and files by a single click years ago.
None of these is exotic. All of them are visible in the admin center to anyone who knows to look, and all of them are fixed with settings rather than new products. That is the good news: a small business tenant can be brought to a solid baseline in a day or two of work, provided someone actually does it and then keeps checking.
What is MFA, and why is it the first thing I fix?
Multi-factor authentication, or MFA, means a password alone is not enough to sign in. After the password, Microsoft asks for a second proof, usually a tap in the Microsoft Authenticator app on the person's phone. If someone in another country has stolen a password through a phishing email, they still cannot get in, because they do not have the phone.
It is the first thing I fix because it stops the most common attack there is. Almost every compromised Microsoft 365 account I have been called in to clean up had one thing in common: no MFA, or MFA with an exception for that person. Stolen passwords are cheap and plentiful. MFA makes them nearly worthless.
How I roll it out so it does not disrupt the office:
- I turn it on for everyone, including the owner and including shared mailboxes that anyone signs into directly. Exceptions are where breaches start.
- I use the Authenticator app with number matching rather than text messages. Text messages work but can be intercepted or socially engineered away from a phone carrier.
- I register two methods per person where possible, so a lost phone does not lock anyone out.
- I block legacy authentication, the old sign-in methods that ignore MFA entirely.
- I do it in one short session per person, usually ten minutes, either onsite or on a call, and I leave a one-page guide.
MFA is available on every Microsoft 365 business plan at no extra cost. There is no license reason to leave it off. If someone tells you MFA is too much hassle for the boss, the honest answer is that the boss's mailbox is the one with the wire instructions and the payroll file in it.
What are conditional access basics, in plain terms?
Conditional access is a set of rules that decide whether a sign-in is allowed, based on who is signing in, from where, on what kind of device and to which application. MFA asks "is this really you?" Conditional access asks "should this sign-in be happening at all?"
The rules I put in place for a typical small business:
- Require MFA for everyone, everywhere. Conditional access is the proper way to enforce it, replacing the older per-user switches.
- Block sign-ins from countries you do not do business in. A Dallas law office does not need staff signing in from overseas. If someone travels, I add their trip for the dates they are away.
- Require a compliant or managed device for company data. Email on a personal phone is fine through the Outlook app with protections applied; downloading the whole client folder to an unmanaged home computer is not.
- Require MFA every time for administrators, with no "remember this device" convenience.
- Block legacy authentication as a rule rather than a setting that can be flipped back.
- Treat risky sign-ins differently. If Microsoft flags a sign-in as unusual, require a fresh MFA or block it outright.
The catch is licensing. Conditional access needs Entra ID P1, which is included in Microsoft 365 Business Premium and not in Business Basic or Business Standard. For most offices I work with, moving to Business Premium is the right decision, because it also brings device management and the better anti-phishing tools described below. If the budget does not allow it, security defaults still give you MFA and legacy authentication blocking, and I make sure those are on. I do not turn on conditional access rules without a "break-glass" admin account excluded from every rule, so a mistake cannot lock the whole company out.
How do you stop phishing in Microsoft 365?
Phishing is email that pretends to be someone you trust in order to get a password, a payment or a click. It is how most small business breaches begin, and no setting stops all of it, so the answer is layers.
Layer one: make it harder for fake email to arrive. Exchange Online Protection is included with every plan and filters the obvious junk. On Business Premium, Defender for Office 365 adds Safe Links, which checks a link at the moment someone clicks it rather than when the email arrived, and Safe Attachments, which opens attachments in a sandbox first. I also turn on impersonation protection, so an email from "the owner" using a look-alike address gets flagged.
Layer two: make it harder for people to fake you. SPF, DKIM and DMARC are three records in your domain's DNS that tell the world which servers are allowed to send email as your company. Without them, anyone can send an invoice to your clients that appears to come from you. Setting them up is an hour of work and most small business domains I inspect are missing at least one.
Layer three: make fakes visible. I tag every email from outside the company with a short "External" label in the subject or a banner. It costs nothing and it is remarkably effective at making people pause before they act on an email that looks like it came from a colleague.
Layer four: make reporting easy. The Report Phishing button in Outlook sends a suspicious email to me and to Microsoft with one click. People report more when it is easy and nobody makes them feel foolish for asking.
Layer five: the people. A short conversation twice a year about what current phishing looks like, and a simple rule that any change of bank details or any urgent payment request is confirmed by phone, on a number you already had, before anything moves.
Does Microsoft back up your 365 data? Not the way you think
This is the misunderstanding that costs businesses the most. Microsoft keeps your data highly available, meaning it is stored in more than one place and the service stays up. That is not the same as a backup you control. If someone deletes a folder, if a departed employee emptied their mailbox on the way out, if a synced laptop with ransomware encrypts a shared library, or if an account is compromised and used to delete files, you are relying on retention windows and recycle bins that have time limits and gaps.
What Microsoft gives you by default is useful but limited: a recycle bin for files with a fixed window, a recoverable-items folder for email, and version history in SharePoint and OneDrive. What it does not give you is a copy you hold, outside the tenant, that you can restore from at a point in time of your choosing, months later, in bulk.
What I set up for the businesses I manage:
- A third-party backup of Exchange mailboxes, OneDrive, SharePoint and Teams, running daily, stored outside Microsoft's tenant.
- Retention policies inside 365 so that deleted mail and files are kept for a defined period even if a user or an attacker tries to remove them.
- Litigation hold or retention for mailboxes of departed staff, instead of deleting the account and losing the history.
- A test restore every quarter, because a backup nobody has restored from is a hope, not a plan.
Backup of Microsoft 365 is a modest monthly cost per user and it is included in the way I quote managed plans. If your current provider has not mentioned it, ask them where your mailbox backup is and how far back it goes. If the answer is "Microsoft handles that," the honest reply is: partly.
What does good admin hygiene look like?
Admin hygiene is the unglamorous routine that keeps a tenant safe between projects. It is not a product, it is habits, and it is where a small, owner-led IT company that knows your setup earns its fee. My routine for every tenant:
- Separate admin accounts. Nobody administers the tenant from the account they read email on. Admin accounts have no mailbox, no license and MFA on every sign-in.
- As few global administrators as possible. Usually two: mine and a break-glass account whose credentials are sealed and stored offline. Everyone else who needs some admin ability gets a narrower role.
- A break-glass account excluded from conditional access, with a very long password kept where the owner can reach it if I am unavailable.
- Audit logging turned on and reviewed. It is how I find that forwarding rule an attacker created, or the sign-in from a country nobody visited.
- App consent restricted. Users cannot grant a random third-party app access to company mail and files; requests come to me.
- Shared mailboxes with sign-in disabled. A shared mailbox should be accessed through permissions, not by a shared password.
- A written offboarding routine. When someone leaves: sign-in blocked, sessions revoked, MFA methods removed, mailbox converted or held, files reassigned, license released, devices wiped. Done the same day.
- A monthly review of new accounts, admin roles, forwarding rules, external sharing links and the licenses being paid for.
The offboarding routine deserves emphasis. The most common avoidable exposure I see is a former employee whose account still works months after they left, often with a license still being billed. Closing that the day someone leaves is basic, and it only happens reliably when somebody owns it.
What is the small business Microsoft 365 security checklist?
Here is the whole list in one place, with what each control protects against and what plan it needs. Use it to check your own tenant or to ask whoever manages it.
| Control | What it stops | Plan needed |
|---|---|---|
| MFA for every account | Sign-ins with a stolen password | Any business plan |
| Block legacy authentication | Old protocols bypassing MFA | Any business plan |
| Conditional access rules | Sign-ins from wrong countries, unmanaged devices, risky sessions | Business Premium or Entra ID P1 |
| SPF, DKIM and DMARC records | Others sending email as your company | Any plan; DNS change |
| Safe Links and Safe Attachments | Malicious links and attachments | Business Premium (Defender for Office 365) |
| External sender tagging | Impersonation of colleagues | Any business plan |
| Report Phishing button | Slow reporting of suspicious mail | Any business plan |
| Third-party 365 backup | Deletion, ransomware, account compromise | Separate product |
| Retention policies and holds | Loss of mail and files from departed staff | Business Standard and above |
| Separate admin accounts, minimal global admins | One phished mailbox becoming a full takeover | Any business plan |
| Audit log review | Silent forwarding rules, unusual sign-ins | Any business plan |
| Device management with Intune | Company data on lost or unmanaged devices | Business Premium |
| Written offboarding routine | Former staff keeping access | None; discipline |
If most of the "any business plan" rows are not done in your tenant, that is the place to start, and it costs nothing but time. The Business Premium rows are worth the upgrade for any office that handles client money, client records or anything a regulator cares about, which is most of the industries I work with in Dallas.
What does having me manage Microsoft 365 look like month to month?
Two ways to work with me. The first is a one-time hardening project: I review the tenant against the checklist above, fix what can be fixed without disruption, roll out MFA and conditional access with your staff, set up backup and DMARC, write down what was done, and hand you a short report of what remains. Most small tenants take a day or two of my time, billed hourly.
The second is ongoing management as part of a managed IT plan, quoted per user or per device after a short conversation, month-to-month and cancel anytime. In that case the checklist is not a project but a state I keep the tenant in. New hires are set up correctly on day one, leavers are closed out the day they go, alerts from Defender come to me and get acted on, the backup is tested, licenses are reviewed so you are not paying for ghosts, and you have one number to call, mine, about anything Microsoft. If you are weighing that against a bigger provider, a small IT company vs a big MSP lays out the honest trade-offs.
Either way, the first step is the same. Get in touch, tell me roughly how many people you have and which plan you are on, and I will tell you what I would look at first. If your office is in Dallas, Plano, Fort Worth or anywhere in Texas, the work is almost entirely remote, so distance does not change the answer.
Questions people ask
Who can manage our Microsoft 365 and security in Dallas?
I can. Cross River Tech is a small, owner-led managed IT company in Dallas, and Microsoft 365 setup, security hardening and month-to-month administration are core parts of what I do. It is included in managed IT plans or available as a one-time hourly project, and because the work is almost entirely remote I support tenants for businesses anywhere in Texas, not just Dallas–Fort Worth.
Is Microsoft 365 secure enough out of the box for a small business?
It is a good starting point, not a finished one. Security defaults give you MFA prompts and block old sign-in methods, but the tenant still needs MFA enforced with no exceptions, forwarding rules checked, admin roles trimmed, SPF, DKIM and DMARC set on your domain, external email tagged, and a real backup. All of that is configuration, and most of it costs nothing but a day of attention.
Do I need Microsoft 365 Business Premium for security?
Not for the basics. MFA, blocking legacy authentication, external tagging and admin hygiene work on any business plan. Business Premium adds conditional access, Defender for Office 365 with Safe Links and Safe Attachments, and Intune device management. For an office that handles client money or client records, I usually recommend the upgrade; for a very small office on a tight budget, the basics done properly still go a long way.
Does Microsoft back up my email and files?
Microsoft keeps your data available, but that is not a backup you control. Recycle bins and recoverable items have time limits, and a compromised account or a synced ransomware infection can delete or encrypt what is there. I set up a separate daily backup of mailboxes, OneDrive, SharePoint and Teams stored outside the tenant, plus retention policies inside it, and I test a restore every quarter.
Will turning on MFA and conditional access disrupt my staff?
Briefly, and then not at all. I set each person up in about ten minutes with the Authenticator app and a backup method, and I always keep a break-glass admin account outside the rules so a mistake cannot lock the company out. After the first day, most people see a prompt only when they sign in on a new device or from an unusual place, which is exactly when you want a check.
Sources and further reading
Market price ranges in this article are my own observation of quotes in the Dallas market, not a published survey. Where I state a rule or a standard, the source is linked above.
