M365Clarity · SMB Security
The assumption that security configuration gaps are primarily an enterprise problem is wrong. Small and medium-sized businesses on Microsoft 365 Business Basic and Business Premium face the same default configuration issues as larger tenants — external forwarding enabled, mailbox auditing off, MFA gaps, no device compliance policies — with less IT resource to find and fix them.
M365Clarity scans across tenants of all sizes. Business Basic tenants consistently show 10 or more findings on a first scan. Business Premium tenants, with more features available, typically show 30 or more. Most of these findings are not difficult to fix — they just require knowing they exist.
Microsoft 365 Business Basic provides Exchange Online, Teams, SharePoint, OneDrive, and web versions of Office apps. It does not include desktop Office applications, Intune device management, or Defender for Business. Security in Business Basic is therefore limited to:
Within these limits, there are still significant configuration choices that affect security. The most common gaps in Business Basic tenants:
By default, Microsoft 365 allows users to set up automatic forwarding rules that send copies of all inbound email to an external address. This is a primary technique used in business email compromise — an attacker who gains access to a mailbox immediately sets up forwarding to quietly exfiltrate all future emails. An anti-spam policy with external forwarding set to Off or On with a block action prevents this.
Mailbox auditing logs actions taken on mailboxes — emails read, deleted, or forwarded by delegates. It should be enabled by default in modern Microsoft 365 tenants, but verification is worth doing. Without audit logging, detecting a compromised mailbox after the fact is significantly harder.
Microsoft Entra ID P1 (included in Business Basic) supports Conditional Access policies. Many Business Basic tenants have never configured a single policy. At minimum, requiring MFA for all users and blocking legacy authentication protocols should be configured as two separate Conditional Access policies.
New Microsoft 365 tenants have Security Defaults enabled by default — a simplified set of protections including MFA registration required for all users. Security Defaults and Conditional Access are mutually exclusive. Tenants that have moved to Conditional Access should have Security Defaults disabled; tenants still on Security Defaults should consider whether Conditional Access would give them more granular control.
Business Premium significantly expands the security feature set, adding Intune device management, Defender for Business (endpoint and email protection), Microsoft Entra ID P1 (same as Business Basic), and Azure Information Protection P1 (sensitivity labels).
The most common gaps in Business Premium tenants are in the features that require active configuration after licencing:
Intune device management is licensed in Business Premium but device compliance policies — which define what constitutes a compliant device and what happens to non-compliant ones — must be created explicitly. Without compliance policies, all enrolled devices are marked compliant by default regardless of their actual security state.
Business Premium tenants often have a BitLocker encryption requirement in their compliance policy but have never verified that BitLocker is actually enabled on enrolled devices. A device can be enrolled in Intune and marked compliant while running without BitLocker enabled if the compliance policy grace period is set too long or the BitLocker enforcement policy is not properly targeted.
Defender for Business ships with default baseline policies but they must be deployed to device groups. Tenants that enrolled Intune without deploying the Defender for Business baseline may have endpoints with no active threat protection configuration despite being licensed for it.
Defender for Business includes Defender for Office 365 Plan 1 features including Safe Attachments and Safe Links. These require explicit policies targeting your user population. The default state is no coverage — policies must be created and targeted to apply protection.
Business Premium is excellent value when fully configured. The combination of Intune, Defender for Business, Conditional Access, and sensitivity labels gives small businesses enterprise-grade protection. The challenge is not the technology — it is knowing what needs to be switched on.
M365Clarity scans 20 checks across Business Basic tenants and over 80 across Business Premium tenants, covering all the areas above. Each finding is rated Red, Amber, or Green with a plain-English explanation and a step-by-step guide to fix it. Free to scan — no agents, no scripts, read-only access.
Find out exactly what is configured and what is missing in your Microsoft 365 tenant in 30 seconds. Free, no agents, read-only access.
Free scan →Related articles