IT Services

Microsoft 365 security checklist for small businesses in Dubai and the UAE

The settings a small UAE company should check in its Microsoft 365 tenant, in order: sign in, admin accounts, email, sharing, devices, audit logs and Secure Score.

Rows of rack-mounted servers glowing with blue status lights in a data centre
Photo: BalticServers.com, CC BY-SA 3.0, via Wikimedia Commons

This Microsoft 365 security checklist covers seven areas a small business in Dubai or elsewhere in the UAE can work through in order to secure most of its tenant: confirm security defaults or Conditional Access requires multifactor sign in for everyone, lock down admin accounts, apply Microsoft’s preset email protection and stop automatic forwarding to outside addresses, restrict external file sharing, manage the devices that reach company data, switch on audit logging, and use Secure Score to track what is left. Almost all of it is configuration inside licences you already pay for.

The checklist below follows Microsoft’s own documentation for business plans, which Microsoft aims at organisations with up to 300 users, and notes where a setting depends on Business Premium. Microsoft changes defaults from time to time, so each item reflects the documentation as of September 2026.

Key points

  • Security defaults are free, suit most small tenants and block legacy authentication; Conditional Access needs Microsoft Entra ID P1, which Business Premium includes.
  • Microsoft recommends at least two emergency access accounts and least privilege roles for everyone else.
  • Set external forwarding explicitly to off rather than leaving the system controlled default in place.
  • Microsoft states that auditing is not enabled by default for Business Basic, Standard and Premium, so check it.
  • Secure Score shows progress against recommendations; Microsoft says it is not an absolute measure of breach risk.

Microsoft 365 security checklist: know your plan first

Microsoft’s security best practices article for business plans compares Basic, Standard and Premium. The difference matters because several items on this checklist only exist in Premium.

CapabilityBasic and StandardBusiness Premium
Spam, malware and phishing protection for mailboxesIncludedIncluded
Security defaultsIncludedIncluded
Conditional AccessNot includedIncluded
Defender for Office 365 Plan 1 (Safe Links, Safe Attachments, impersonation protection)Not includedIncluded
Basic Mobility and Security for phonesIncludedIncluded
Intune Plan 1 and device protection with Defender for BusinessNot includedIncluded
Data Loss Prevention, sensitivity labels, message encryptionNot includedIncluded

Before changing anything, open the Microsoft 365 admin center, list which licences each user holds, and note who has an admin role. That list is the baseline for everything below, and it is the kind of record our IT support team keeps up to date for clients.

Sign in: security defaults or Conditional Access

This Microsoft 365 security checklist starts sign in here. Microsoft Entra security defaults are a single switch that applies a fixed set of protections. Microsoft’s documentation lists them as requiring every user to register for multifactor authentication, requiring admins to complete it, prompting other users when Microsoft judges it necessary, blocking legacy authentication protocols, blocking device code flow and requiring multifactor authentication for Azure management tools. Microsoft says security defaults are rolled out to new tenants when they are created.

  • Check the switch. In the Microsoft Entra admin center, go to Entra ID, Overview, Properties, then Manage security defaults. If you do not use Conditional Access, it should be enabled.
  • Check for old devices and apps. Legacy authentication covers clients that do not use modern authentication and older mail protocols such as IMAP, SMTP and POP3. Microsoft warns that these cannot use multifactor authentication and are blocked once defaults are on, so find scanners, line of business apps and old mail clients first.
  • Know what changed in 2024 and 2026. Microsoft removed the 14 day grace period for registering multifactor authentication from 29 July 2024. From 1 July 2026, new tenants block device code flow as part of security defaults.
  • Revoke existing sessions. When enabling defaults on an established tenant, Microsoft advises revoking active tokens so users already signed in have to register.

If you have Business Premium and need exceptions, such as allowing sign in only from managed devices, Conditional Access replaces security defaults. Microsoft’s instruction is that security defaults must be disabled when Conditional Access policies take over, and that equivalent policies should be enabled immediately afterwards so there is no gap.

Microsoft 365 security checklist: admin accounts, fewer and protected

The next item on this Microsoft 365 security checklist is admin accounts. Whoever signed up for Microsoft 365 became a Global Administrator. In many small UAE companies that person is the founder, an office manager or a supplier who set things up years ago, and the same account is used for daily email. Microsoft’s guidance on admin accounts for business plans recommends a different arrangement.

  1. Two emergency access accounts. Not assigned to a specific person, used only in emergencies, excluded from multifactor requirements and therefore protected by long, complex passwords of 16 or more characters stored securely.
  2. Least privilege for everyone else. Someone who only creates users should hold the User Administrator role, not Global Administrator. Microsoft warns that too many admin accounts give attackers more opportunities.
  3. Separate daily and admin identities. Admins sign in to email and documents with an ordinary account and use the admin account only when needed, in a private browser window, signing out afterwards. Admin only accounts do not need a licence.
  4. Names that do not advertise privilege. Avoid labels such as “admin” in the account name.
  5. Passwordless sign in for admins using the Authenticator app, passkeys or Windows Hello for Business, which Microsoft lists as available even on Basic and Standard.
If a supplier holds your only Global Administrator account, you do not fully control your own tenant.

Email: preset policies and outside forwarding

Email is the third item on this Microsoft 365 security checklist. Every cloud mailbox gets built in protection against spam, malware and spoofing. Microsoft’s preset security policies apply its recommended settings in one step instead of tuning dozens of options by hand. There are Standard and Strict presets, plus a Built-in protection preset that gives basic Safe Links and Safe Attachments coverage in tenants with Defender for Office 365. You find them in the Microsoft Defender portal under Email and collaboration, Policies and rules, Threat policies.

The second email setting deserves particular attention. A common problem we see in UAE companies is payment fraud that starts with a mailbox someone else has quietly taken over, and Microsoft notes that inbox rules forwarding mail to outside recipients can be created as a result of a compromised account. Microsoft’s outbound spam policy has three choices for automatic external forwarding: Automatic, System controlled; On; and Off. Microsoft explains that the automatic setting behaves differently depending on when and how the tenant was set up, and recommends choosing On or Off explicitly.

  • Set automatic external forwarding to Off in the default outbound spam policy.
  • If a team genuinely needs to forward to a partner, allow it only for that domain through remote domain settings.
  • Review the Auto forwarded messages report monthly for users who are forwarding outside the company.
  • Confirm SPF, DKIM and DMARC are in place for your domain, as described on our cyber security page.

Files and sharing in SharePoint and OneDrive

Sharing is the fourth item on this Microsoft 365 security checklist. SharePoint and OneDrive offer four organisation level sharing levels: Anyone, New and existing guests, Existing guests, and Only people in your organisation. The OneDrive setting can be stricter than SharePoint but never more open, and each site can be stricter than the organisation.

  • Choose New and existing guests unless there is a clear need for links that work without signing in.
  • If Anyone links are allowed, make them expire and limit them to view only.
  • Set the default link type to Specific people or Only people in your organisation.
  • Set guest access to expire automatically after a period that suits your projects.
  • Where external sharing is only needed with known partners, limit it by domain.

Microsoft notes that if external sharing is restricted, guests typically lose access within an hour, so warn project teams before changing the setting. For where company data should live in the first place, see our cloud services.

Devices that reach company data

Devices are the fifth item on this Microsoft 365 security checklist. Staff in Dubai offices often read company email on personal phones. Every business plan includes Basic Mobility and Security, a free subset of Intune that can require a device password before company apps open, and can remove company data from a device or reset it to factory settings. Business Premium adds Microsoft Intune Plan 1 for managing both devices and apps, and device protection policies with Microsoft Defender for Business for laptops and desktops.

  • Require a device password on any phone that syncs company email.
  • Know who can remove company data from a lost or stolen device, and test the process once.
  • On Business Premium, enrol company laptops in Intune and turn on Defender for Business protection.
  • Keep a register of which device belongs to which person, and update it when people leave.

Microsoft 365 security checklist: audit logging and Secure Score

Audit logging is the item most small tenants miss on this Microsoft 365 security checklist. Microsoft’s Purview documentation says audit logging is on by default for Microsoft 365 organisations in general, but not for small and medium business licences including Business Basic, Standard and Premium, which must turn it on manually. Once enabled, the audit log records user and admin activity and retains it for 180 days by default. Without it, there may be little record to show what an attacker did after taking over a mailbox.

To turn it on, open the Microsoft Purview portal, select the Audit solution, and choose the banner to start recording user and admin activity. Microsoft says this can take up to 60 minutes to take effect.

Microsoft Secure Score, at security.microsoft.com/securescore, then gives you a running list of recommended actions. Each action is worth up to ten points, and some award partial points, such as protecting half your users. Turning on security defaults earns full points for the multifactor and legacy authentication recommendations. Microsoft is careful to say that Secure Score reflects how far you use recommended controls, not an absolute measure of whether you could be breached, and that security has to be balanced with usability. Review it monthly and record any recommendation you decide not to follow, with the reason.

The UAE context: official guidance and where to report

The UAE Cyber Security Council publishes guidance for businesses that lines up with this Microsoft 365 security checklist. It advises companies to review threat updates regularly, prepare and test response plans for suspicious activity, train staff regularly, audit systems periodically for vulnerabilities, and work with cyber security professionals to assess their defences.

For reporting, the Council’s website points Dubai users to the Dubai Police eCrime website, Abu Dhabi users to the Aman service, and everyone to the Ministry of Interior’s eCrimes platform, the nearest police station or 999. If a compromised account exposed customer information, your obligations under UAE data protection law are a question for a legal adviser; our article on email marketing consent under the UAE data protection law introduces that law in a marketing context. This section is general information, not legal advice.

How Digital Marketing Dubai can help

We review a tenant against this Microsoft 365 security checklist, make the changes with you, and document every setting in a register you keep. The work is part of our IT services, with day to day administration through IT support and email authentication and staff awareness through cyber security. We are not a security operations centre, we do not hold security certifications, and no configuration can promise that an attack will never succeed. What you get is a tenant set up the way Microsoft documents it, and a written fixed price proposal within 45 minutes during business hours.

Straight answers

Frequently asked questions

We have Microsoft 365 Business Basic. Is that secure enough?

Basic includes email protection against spam, malware and phishing, security defaults and basic mobile device management, which covers the essentials in this checklist. Business Premium adds Conditional Access, Defender for Office 365 Plan 1, Intune and Defender for Business, which matter more as the team, devices and data grow.

A staff member says the Authenticator prompts are annoying. Can we switch MFA off for them?

Removing multifactor authentication for one user reopens exactly the gap that security defaults are designed to close. With security defaults, Microsoft decides when to prompt based on factors such as location, device and role, and separate admin accounts reduce prompts for admins. Explain the reason and help the person set up the app properly instead.

Does a high Secure Score mean we are protected?

No. Microsoft describes Secure Score as a measure of how many recommended controls you use, not an absolute measure of how likely a breach is, and says no online service is immune. Use it to track progress, alongside the other checks here.

Our office printer stopped sending scans by email after we turned on security defaults. Why?

Security defaults block legacy authentication, and older devices that send email with basic sign in are affected. Microsoft publishes guidance on setting up multifunction devices and applications to send email through Microsoft 365, so reconfigure the device rather than switching protection off.

Should we report a compromised mailbox to anyone in the UAE?

The UAE Cyber Security Council lists official reporting channels, including Dubai Police's eCrime website for Dubai. If money or customer personal data is involved, speak to your bank and your legal adviser as well. This is general information, not legal advice.

Fixed price, in writing

Send your brief. Get a scope and a price within 45 minutes.

  • One fixed number, agreed in writing before work starts
  • No obligation, and no pressure to sign
  • English and Arabic work, with proper right to left layout
  • One team for design, marketing, web, media and copy

Get your fixed price quote

Written scope and price within 45 minutes in business hours. No obligation.

By sending this you agree to be contacted about your enquiry. Privacy policy

Keep reading

More articles for UAE businesses

All articles
Call WhatsApp Get a quote