Microsoft 365 Security Checklist for Maryland Small Businesses

Microsoft 365 is the operating system of the modern small business. Email, file storage, video calls, team communication — for most Maryland SMBs, it all runs through M365.

It is also one of the most consistently misconfigured platforms in the small business space.

This is not a knock on Microsoft. M365 is a capable, well-designed platform. But it ships with default settings designed for broad accessibility, not for security. And most small businesses in Maryland set it up, get their email working, and move on — never touching the security settings that matter most.

Attackers know this. They specifically look for the M365 configurations that small businesses routinely skip.

This checklist covers the settings that matter most, why businesses skip them, and what each gap actually costs when it is exploited.

1. Multi-Factor Authentication

The gap: MFA is either not enabled, or it is enabled for some accounts but not enforced across the board. Executive and admin accounts are the most common exception — the people with the most access to sensitive data are often the ones running on password-only authentication.

Why businesses skip it: They think it will slow their team down. They set it up as optional and staff do not adopt it. They do not know the M365 admin center has a setting to enforce it.

What it costs: A stolen password is all an attacker needs to access email, files, and any connected applications. Without MFA, a single compromised credential can give an attacker full access to your business environment for days or weeks before anyone notices.

What to do: Go to the Microsoft Entra admin center. Enable Security Defaults if your plan supports it. If you are on a plan that includes Conditional Access (Microsoft 365 Business Premium or higher), set up a Conditional Access policy that requires MFA for all users on all sign-ins.

2. Legacy Authentication Protocols

The gap: M365 supports older authentication protocols like POP, IMAP, and SMTP AUTH that do not support modern MFA. Many businesses have these enabled by default and do not realize it. Attackers specifically target these protocols because they bypass MFA entirely.

Why businesses skip it: Nobody told them this was a setting they needed to check. It is not visible from the regular M365 interface — you have to go looking for it.

What it costs: If legacy auth is enabled, your MFA enforcement means nothing for accounts being accessed through those protocols. An attacker with a stolen credential and knowledge of which protocol to use bypasses MFA completely.

What to do: In the Microsoft Entra admin center, create a Conditional Access policy that blocks legacy authentication. If you are not on a plan that supports Conditional Access, use Security Defaults, which block legacy auth automatically.

3. Admin Account Hygiene

The gap: Administrators use their regular daily-use accounts to perform admin tasks. These accounts have elevated privileges, receive email, browse the web, and are at full credential risk every day.

Why businesses skip it: It is more convenient to have one account. Nobody explained why dedicated admin accounts matter.

What it costs: If an admin account is compromised through phishing, credential stuffing, or malware, the attacker gains admin-level control over your entire M365 environment. They can create new accounts, disable MFA, access all mailboxes, and lock out the legitimate admin.

What to do: Create dedicated global admin accounts that are never used for daily email or browsing. These accounts should have MFA enforced, no email license attached, and be used only when admin tasks are required. Regular user accounts should not have global admin privileges.

4. Email Authentication (SPF, DKIM, DMARC)

The gap: Email authentication records are missing, broken, or set to permissive values that do not actually stop attackers from spoofing your domain.

Why businesses skip it: These are DNS settings that require going outside of M365 to configure. Many businesses set up their domain, get email working, and never set these records up. Others have them partially configured but not correctly.

What it costs: Without proper email authentication, attackers can send emails that appear to come from your domain. Clients, vendors, or employees receive emails impersonating your business and are more likely to trust them. Business email compromise attacks specifically exploit this gap.

What to do: Add an SPF record to your DNS that lists Microsoft as an authorized sender for your domain. Enable DKIM signing in the M365 Defender portal. Set up a DMARC record with at minimum a policy of p=quarantine and a reporting address.

5. Conditional Access Policies

The gap: For businesses on plans that include Conditional Access, these policies are often never configured. They are a powerful tool for enforcing security requirements based on user, device, location, and application — but they require setup.

Why businesses skip it: Conditional Access requires some technical knowledge to configure correctly and the consequences of a misconfigured policy can lock users out. Many businesses know it exists but treat it as too complex to touch.

What it costs: Without Conditional Access, your security posture relies on individual settings rather than a coherent policy framework. You have no way to enforce different security requirements for high-risk sign-ins versus normal ones.

What to do: Start with Microsoft’s built-in policy templates. The most important ones to enable: Require MFA for all users, Require MFA for admins, and Block legacy authentication. These three templates cover the highest-priority gaps with the lowest risk of misconfiguration.

Why Maryland SMBs Skip All of This

There are two reasons most Maryland small businesses are running M365 with these gaps in place.

First, these settings are not visible during normal daily use of M365. You have to go looking for them in admin panels that most business owners and staff never open.

Second, there is no one in the business whose job it is to check. Small businesses do not have a security team. The person who set up M365 is usually not a security professional — they got email working and moved on.

That is what NexSecure addresses. We audit M365 environments for small businesses in Bowie and across Prince George’s County, Maryland and fix what we find. You get a written findings report, a remediation plan with prioritized steps, and implementation support to close the gaps.

Most M365 audits are completed in five to ten business days. The remediation work for most small businesses is done within two to four weeks. The result is a significantly more secure environment and, for businesses applying for cyber insurance, documentation that supports the application.

If you are running M365 for your Maryland business and you have not had a security review, schedule a free discovery call with NexSecure.

Book a Free Discovery Call

NexSecure Solutions helps small businesses review and harden Microsoft 365 with practical priorities, clear costs, and evidence of what changed.

Categories: