Microsoft 365 and admin access
Microsoft 365 Security: What Should Small Businesses Review?
A plain-English review of the Microsoft 365 security habits small businesses should keep visible and repeatable.
The short answer
Start with MFA, named admin roles, leaver processes, mailbox and sharing review, third-party app access, and device visibility. Microsoft 365 security is a rhythm, not a one-off settings tidy-up.
The takeaways
- MFA is important, but it does not replace access review or leaver processes.
- Admin roles should be named, limited, and reviewed.
- Mailboxes, groups, sharing, and third-party app access need periodic checks.
What should you secure first?
- Require MFA for users, with extra attention to admins and sensitive roles.
- Keep a small named list of admin accounts and review it regularly.
- Review shared mailboxes, groups, forwarding rules, and external sharing.
- Check phishing, spam, and malware protections are understood and monitored.
- Review third-party apps connected to Microsoft 365 accounts.
- Keep devices and core applications updated.
- Use a documented joiner and leaver process.
- Keep recovery and emergency access arrangements documented.
How should admin access be handled?
Admin access should be tied to named people and specific roles. Global admin access should be limited, protected, and reviewed because it can affect the whole tenant.
| Area | What to check | Why it matters |
|---|---|---|
| Global admins | Who has the role and why. | Keeps the most powerful access limited. |
| Helpdesk roles | Whether lower-privilege roles can handle routine tasks. | Reduces unnecessary admin access. |
| Emergency access | How the business regains access if an admin is unavailable. | Avoids single-person lockout. |
| Supplier access | Which external admins exist and when they are reviewed. | Keeps delegated support visible. |
What does MFA not solve?
Old access
MFA does not decide whether an ex-employee, contractor, guest, or old shared mailbox should still have access.
Excessive privileges
An account can have MFA and still hold more admin access than it needs.
Data sharing
MFA helps protect sign-in, but it does not automatically clean up external file sharing, mailbox delegation, or group membership.
What should you review each month?
- New users, leavers, guests, and contractors.
- Admin roles and supplier access.
- Shared mailboxes, distribution groups, Teams, SharePoint sites, and external sharing.
- Forwarding rules and suspicious mailbox changes.
- Third-party app consent and connected services.
- Devices that are stale, unmanaged, or missing updates.
- Open exceptions that need a named owner and review date.
Where are Kindura's remote-only limits?
Kindura can help review and administer Microsoft 365 remotely, including users, groups, licences, admin roles, mailbox settings, joiner/leaver workflows, and practical security baselines.
Hands-on device repair, office networking, physical recovery of devices, in-person incident response, and specialist forensic work are outside the core remote service unless a separate route is agreed.
Questions to ask any provider
Use these on any Microsoft 365 security review - including ours. They should be answerable without drama.
- Which admin roles exist, and why does each person or supplier need them?
- How are MFA, emergency access, and account recovery handled?
- How are leavers, guests, shared mailboxes, and external sharing reviewed?
- Which third-party apps can access our tenant?
- What will be checked monthly rather than only during a clean-up?
Where Kindura fits
Kindura can support the remote admin rhythm
Kindura can help review Microsoft 365 users, groups, licences, admin roles, mailbox settings, MFA routes, and joiner/leaver workflows remotely. Physical device repair, forensic incident response, and onsite recovery are separate from the core service. Whether or not that suits you, the review points above should stay visible.
Related resources
Checklist
Employee Offboarding Checklist: How Should Access Be Removed?
A calm checklist for removing account access, revoking sessions, recovering devices, transferring ownership, and recording completion when someone leaves.
Checklist
New Starter IT Setup Checklist: What Should Happen?
A practical checklist for setting up devices, Microsoft 365 accounts, MFA, software access, approvals, and first-week support for new starters.
Guide
Cyber Essentials For SMEs: What Should You Prepare?
A practical SME guide to Cyber Essentials, the five technical control areas, preparation evidence, and Kindura's remote-only readiness boundary.