0333 335 5020letstalk@networklondon.co.ukRemote supportClient portal

Network London

Microsoft 365 security: what to switch on, and what we switch on for you

Most firms of 20 to 250 people run on Microsoft 365, and much of the security in the licence is off by default. Network London reviews your tenant, switches on what matters and keeps it that way: multi-factor authentication, conditional access, email protection, device management and the audit logs your clients ask about.

  • A review of your tenant against what your licence already includes
  • The settings that stop most account takeovers, switched on and documented
  • Evidence for questionnaires: who has access, what's enforced, what's logged
An engineer at two monitors reviewing security settings
Call 0333 335 5020Get in touch
Two office workers looking at something concerning on their laptop screen

Your Microsoft 365 licence includes security you're not using

Does any of this sound familiar?

  • Multi-factor authentication is “on”, but a few partners and shared mailboxes are exempt.
  • Anyone can forward email outside the firm, share a file with the world or sign in from any country.
  • A questionnaire asks what you log and for how long, and nobody knows.

Most of the Microsoft 365 breaches we see needed nothing clever. A setting was off. We switch them on.

An IT engineer working together with staff members to solve a problem

The Microsoft 365 settings that matter, in order

First, multi-factor authentication for every account with no exceptions, and legacy sign-in methods blocked so it can't be bypassed. Then conditional access: sign-ins allowed only from managed devices and expected countries, with admin accounts held to a stricter standard. Email protection next: SPF, DKIM and DMARC so your domain can't be spoofed, plus anti-phishing, safe links and safe attachments. Sharing limits so files can't be shared with anyone on the internet by default. Devices enrolled in Intune, encrypted and checked for compliance before they can reach company data. And the audit log switched on and kept, so when a questionnaire asks what you log, there is an answer.

We do this as part of looking after your IT, document what is set and why, and review it when Microsoft changes things, which is often. What can be switched on depends on your licence. One thing no licence includes is a backup of your data: Microsoft keeps the service running, but deleted or encrypted files are your problem. We add a separate backup, charged per user per month. Our security work is led by Ian Welch, a certified ethical hacker and CISSP, and Network London holds Cyber Essentials Plus.

Tell us which licence you're on and we'll tell you what it already includes that you're not using.

Tell us what you need

Why have Network London secure your Microsoft 365

  • What you already pay for

    Business Premium includes most of what a firm of your size needs: Intune, Defender for Business and conditional access. We make sure you're using it before anyone sells you more.

  • Set once, kept on

    Settings drift as people join, leave and ask for exceptions. We review the tenant on a schedule and keep the exceptions list short and written down.

  • Evidence on hand

    Who has access, what is enforced, what is logged and for how long, documented in the form a client questionnaire or an insurer asks for.

  • 20years looking after business IT
  • 100+businesses across the world trust us with their IT
  • 24/7support, with a real person on the phone

Who we work with

Three of the 100+ businesses we look after, and what we do for them.

Rossair

IT support, the phone system and a website that brings in enquiries, all looked after by one team.

Read the story

LAMDA

Everyday support for 180 people, with access reviews and backup testing built into how they work.

Read the story

A private equity firm

A small team with serious duties to investors. We shaped their IT and cyber security policy and look after it day to day.

Read the story

How a Microsoft 365 security review works

  1. A look at your tenant

    Jessica, our Operations Director, replies the same day. We agree access and review your tenant's identity, email, sharing, device and logging settings against what your licence includes.

  2. A written list, in priority order

    What is on, what is off, what is risky and what it would take to fix, in plain English, with the quick wins first.

  3. Switch on, test, document

    We make the changes in stages so nobody is locked out, test them with your team, and document the result for your records and your next questionnaire.

What's included in our Microsoft 365 security service

  • Multi-factor authentication for everyone

    Every user and every admin, with legacy sign-in blocked so it can't be bypassed. Shared mailboxes and service accounts handled properly rather than exempted.

  • Conditional access

    Sign-ins allowed from managed devices and expected locations, risky sign-ins challenged or blocked, admin accounts held to a stricter standard.

  • Email protection

    SPF, DKIM and DMARC set in your domain's DNS, with anti-phishing, safe links and safe attachments switched on and tuned. Ongoing DMARC monitoring and management is an add-on through Hornetsecurity or Sendmarc.

  • Sharing and data controls

    External sharing limited to what you intend, links that expire, and sensitive data labelled so it can't leave by accident.

  • Device management with Intune

    Laptops and phones enrolled, encrypted, kept up to date and checked for compliance before they can reach company data.

  • Admin roles and break-glass accounts

    The fewest admins possible, each with their own account, and an emergency account kept offline for the day something goes wrong.

  • Audit logging and alerts

    The unified audit log switched on and retained. With our managed security package, the signs of an account takeover (new forwarding rules, impossible travel, mass downloads) are monitored, alerted on and dealt with.

  • Backup for Microsoft 365

    Mail, OneDrive, SharePoint and Teams backed up separately from Microsoft, and tested, so a deleted or encrypted file is a restore rather than a loss. Charged per user per month.

Tell us what you need

Jessica, our Operations Director, reads every enquiry and replies personally the same day. The first step is a conversation about your business, what's working and where you need help.

Prefer to talk? Call 0333 335 5020. A real person answers, always.

LM04.202, The Leather Market
Weston Street, London SE1 3ER
A short walk from London Bridge and Borough stations

Not sure what's switched on in your Microsoft 365?

Tell us which licence you're on and roughly how many people you have. Jessica, our Operations Director, replies to every enquiry personally, the same day.

Tell us what you need

Does Microsoft back up our Microsoft 365 data?

Not in the way most people assume. Microsoft keeps the service running and keeps deleted items for a limited time, but it is not a backup of your data against deletion, ransomware or a leaver clearing their mailbox. We add a separate, tested backup, charged per user per month.

Which Microsoft 365 licence do we need for this?

Microsoft 365 Business Premium includes Intune, Defender for Business and conditional access, which covers most of what a firm of 20 to 250 people needs. Everything on this page apart from DMARC management is available on Business Premium and above. If you're on Business Standard or Basic, we'll tell you what you're missing and whether it's worth the upgrade.

We already have multi-factor authentication. Isn't that enough?

It's the most important single setting, and it's often less complete than it looks: exempt accounts, legacy sign-in methods still allowed, and admins without a stricter standard. Conditional access, email protection, sharing limits and logging close the gaps that MFA alone leaves.

What is conditional access?

Rules about who can sign in, from where and from what. For example: company data only from managed, encrypted devices; no sign-ins from countries you don't operate in; admin access only from certain machines. It's included in Business Premium and is the setting that stops a stolen password being useful.

How long does a Microsoft 365 security review take?

The review itself takes a few days. Making the changes is done in stages over two to four weeks so nobody is locked out and your team is told what is changing. You get a written record at the end.

Can you do this if another company looks after our IT?

Yes. We can review and secure the tenant as a project and hand the documentation to your provider. Most firms who come to us this way move their IT to us afterwards, because keeping the settings right is a continuous job.

The Cyber Security Vault: 22+ tools and apps

Most of them are free. We'll send you our list of resources you and your team can use to improve your cyber security straight away. No technical knowledge needed.

Get the Cyber Security Vault