Microsoft 365 Security — MFA, Passwords & Account Protection

Securing your Microsoft 365 accounts is one of the most important things you can do to protect your business. The majority of account compromises are caused by weak passwords and the absence of multi-factor authentication (MFA). This guide covers enabling MFA, setting password policies, and recommended security steps for all Microsoft 365 organisations.

Need help setting this up?

If you'd rather not deal with the technical side, we can fully set up and manage your Microsoft 365 for you — including email, DNS, and ongoing support.

See how we can help →


Enable Multi-Factor Authentication (MFA)

MFA requires users to verify their identity with a second factor (such as a phone app) in addition to their password. Enabling MFA blocks over 99% of account compromise attacks.

Option 1 — Enable Security Defaults (Recommended for most organisations)

Security Defaults enable MFA for all users and admins automatically. This is the quickest way to protect your organisation.

  1. Sign in to admin.microsoft.com.
  2. Go to Azure Active Directory (or search for it in the admin centre search bar).
  3. In the left panel, click Properties.
  4. At the bottom, click Manage security defaults.
  5. Toggle Security defaults to Enabled.
  6. Click Save.

After enabling, users will be prompted to set up MFA on their next sign-in. They can use the Microsoft Authenticator app (recommended) or a phone number for SMS verification.

Option 2 — Enable MFA per user (for manual control)

  1. Go to admin.microsoft.comUsers → Active users.
  2. Click Multi-factor authentication in the top toolbar.
  3. A new page opens. Tick the checkboxes next to the users you want to enable MFA for.
  4. Click Enable in the right-hand panel, then confirm.
  5. Users will be prompted to set up MFA on their next sign-in.

Setting Up the Microsoft Authenticator App (Users)

Share these steps with your users when MFA is enabled:

  1. Download Microsoft Authenticator from the App Store (iPhone) or Google Play (Android).
  2. When prompted to set up MFA during sign-in, choose Mobile app as the method.
  3. Open the Authenticator app, tap + (Add account) → Work or school account.
  4. Scan the QR code displayed on screen or enter the setup code manually.
  5. The app will generate a 6-digit code. Enter it to verify setup.
  6. MFA is now active. On future sign-ins, users approve a notification in the app.

Password Policies

Set passwords to expire (or never expire)

Microsoft's current recommendation is to not force regular password expiry if MFA is enabled — frequent forced changes encourage weak passwords. However, if your organisation requires expiry for compliance reasons, you can configure it.

  1. Go to Settings → Org settings → Security & privacy → Password expiration policy.
  2. To set passwords to never expire: tick Set user passwords to never expire.
  3. To enforce expiry: untick the box and set the number of days (minimum 14, maximum 730).
  4. Click Save.

Note: This setting applies at the organisation level. Individual user password expiry can also be configured via PowerShell if needed.

Self-Service Password Reset (SSPR)

SSPR allows users to reset their own passwords without contacting an admin — reducing support burden.

  1. Go to the Microsoft Entra admin centre (formerly Azure AD).
  2. Go to Protection → Password reset.
  3. Under Properties, set Self service password reset enabled to All.
  4. Under Authentication methods, choose how users verify their identity (e.g. email, mobile app, phone call).
  5. Click Save.

Users reset their password at aka.ms/sspr.


Protect Admin Accounts

Admin accounts are high-value targets. Apply these protections to all admin accounts:

  • Enable MFA — mandatory for all admin accounts, no exceptions.
  • Use dedicated admin accounts — do not use your admin account for day-to-day email. Create a separate admin-only account with no mailbox.
  • Limit Global Admins — have no more than 4 Global Admins. Use specific roles (User Admin, Exchange Admin, etc.) for everyone else.
  • Monitor sign-in activity — go to Reports → Usage in the admin centre, or use Microsoft Entra → Sign-in logs to review suspicious sign-ins.
  • Set up admin alerts — go to Settings → Org settings → Organization profile and ensure admin notification emails are correctly set.

Review Sign-In Activity & Blocked Accounts

Check recent sign-in activity

  1. Go to entra.microsoft.com.
  2. Click Users → Sign-in logs.
  3. Filter by user, date, or status to investigate suspicious activity.

Block a compromised account immediately

  1. Go to Users → Active users in the admin centre.
  2. Click the affected user → click Block sign-in.
  3. Confirm. The user is immediately prevented from signing in.
  4. Reset their password before unblocking.

Recommended Security Checklist

  • ☑ Enable MFA for all users and admins
  • ☑ Enable Security Defaults (or Conditional Access if on E3/E5)
  • ☑ Enable Self-Service Password Reset
  • ☑ Set a password expiry policy appropriate for your compliance needs
  • ☑ Review and reduce Global Admin accounts to 4 or fewer
  • ☑ Ensure all admins use dedicated admin-only accounts
  • ☑ Review sign-in logs monthly for anomalies
  • ☑ Enable audit logging: Compliance → Audit in the Microsoft Purview portal

Troubleshooting

A user is locked out after too many failed MFA attempts

  • Go to Users → Active users, click the user → Reset password.
  • If the MFA method is lost (e.g. new phone), an admin can reset MFA: in the per-user MFA page, select the user and click Manage user settings → Require selected users to provide contact methods again. The user will be prompted to re-enrol MFA on next sign-in.

User forgot their password and SSPR is not set up

  • An admin must reset it manually: Users → Active users → tick the user → Reset password.
  • Enable SSPR to prevent this in future.

MFA prompts appearing too frequently

  • Users should tick Don't ask again for 14 days on trusted devices when completing MFA.
  • If using Conditional Access, check that trusted locations are correctly configured in Microsoft Entra.

Security Defaults cannot be enabled — greyed out

  • Security Defaults cannot be enabled if Conditional Access policies are already configured. If your organisation is on Microsoft 365 E3 or E5, use Conditional Access instead.

Related Guides

Prefer us to handle this?

We provide fully managed Microsoft 365 setup and support — so you can focus on running your business.

Get started with Microsoft 365 →


Need Help?

Need help setting this up? We can manage your Microsoft 365 for you — from setup to ongoing support.

Find out more about our Microsoft 365 managed service →

Bu cevap yeterince yardımcı oldu mu? 0 Bu dökümanı faydalı bulan kullanıcılar: (0 Oy)