All Posts

Microsoft 365 Baseline Security Mode: What Small Businesses Should Enable and Test First

22 September, 2026
#Managed IT
#Cybersecurity
#Microsoft 365
#Business Productivity
Microsoft 365 Baseline Security Mode planning for small business identity, email, and collaboration security

Microsoft 365 Baseline Security Mode: What Small Businesses Should Enable and Test First

Microsoft 365 gives small businesses a lot of security controls.

That is useful, but it also creates a practical problem: the settings are spread across Microsoft Entra, Exchange Online, SharePoint, OneDrive, Teams, and the Microsoft 365 apps. A business can have MFA turned on and still leave old authentication paths, risky application consent, legacy file behaviors, or broadly usable room accounts in place.

Microsoft 365 Baseline Security Mode is designed to make that work more manageable. It brings a set of recommended hardening controls into the Microsoft 365 admin center and lets administrators review impact before enabling individual settings.

For a small or midsize business, that can be valuable. It can also cause disruption if someone treats it like a single “make us secure” button.

The right question is not simply whether Baseline Security Mode should be enabled. The better question is: which settings reduce meaningful risk in this tenant, what could they break, and how will the business validate the change?

Why This Topic Matters Now

Microsoft says Baseline Security Mode is available across Microsoft 365 subscriptions and plans. It covers controls related to Microsoft Entra identity, Exchange Online, SharePoint, OneDrive, Teams, Microsoft 365 apps, and Teams room devices.

That wider scope matters because modern Microsoft 365 attacks do not stay in one product.

In September 2026, Microsoft reported that the EvilTokens phishing-as-a-service platform had helped compromise more than 12,000 inboxes across more than 10,000 organizations worldwide. The platform abused device-code authentication, stole tokens, searched mailboxes, created malicious inbox rules, and used Microsoft Graph to map organizations and permissions.

The business lesson is bigger than one phishing kit. A compromised identity can lead to email access. Email access can expose invoices, customers, vendors, and internal approvals. The same identity may also reach SharePoint, OneDrive, Teams, applications, and connected devices.

At the same time, Microsoft is removing or restricting older access paths. Exchange Web Services retirement is moving into its final phase in October 2026, legacy authentication continues to be blocked, and phishing-resistant authentication is becoming a more important baseline for privileged accounts.

The buyer-relevant keyword cluster behind this post is Microsoft 365 Baseline Security Mode, Microsoft 365 security baseline, Microsoft 365 security hardening, Microsoft 365 security settings for small business, Microsoft Entra identity protection, Exchange Online security, SharePoint and OneDrive security, Teams Rooms security, and Microsoft 365 security assessment.

This is not a vanity topic. It connects directly to account compromise risk, email fraud, data exposure, aging integrations, employee disruption, cyber insurance evidence, and confidence that Microsoft 365 is being actively managed.

What Microsoft 365 Baseline Security Mode Is

Baseline Security Mode is a collection of recommended settings presented in the Microsoft 365 admin center under Settings > Org Settings > Security & Privacy > Baseline Security Mode.

It brings together controls that previously required administrators to work across multiple portals or use PowerShell. The available settings cover several security areas, including:

  • administrator authentication
  • legacy and basic authentication
  • application credentials and user consent
  • SharePoint and OneDrive access
  • Exchange Web Services
  • old or risky Microsoft Office file behaviors
  • Teams room and resource accounts

The settings are independently managed. That is important.

Baseline Security Mode should be treated as a structured hardening workspace, not one universal policy that every business should turn on all at once. Microsoft recommends reviewing impact reports, enabling settings that show no meaningful dependency, and addressing legitimate dependencies before enforcing controls that could interrupt work.

What Baseline Security Mode Is Not

Baseline Security Mode is not a replacement for operating Microsoft 365 security.

It does not eliminate the need to:

  • configure anti-phishing, anti-spam, and anti-malware policies
  • review Microsoft Defender for Office 365 coverage where licensed
  • configure SPF, DKIM, and DMARC for the company's domains
  • monitor risky sign-ins, mailbox rules, forwarding, and application consent
  • manage guest users and external file sharing
  • patch and protect employee devices
  • train employees to report suspicious messages and sign-in requests
  • maintain an account-compromise response plan
  • review security alerts and logs
  • test backup and recovery assumptions

A tenant can pass a baseline settings review and still have weak email authentication, excessive permissions, stale accounts, poor offboarding, or nobody watching security alerts.

Think of Baseline Security Mode as a useful control plane for reducing common configuration risk. It is one part of a managed Microsoft 365 security program.

The Highest-Value Identity Settings

Identity is the best place to start because one compromised Microsoft 365 account can connect the attacker to email, files, collaboration, and business applications.

Require Phishing-Resistant Authentication for Administrators

Privileged accounts should not rely on the same sign-in controls as ordinary users.

Baseline Security Mode can help administrators create or manage protection that requires phishing-resistant authentication for supported Microsoft admin access. Depending on the organization's licensing and design, that may involve passkeys, FIDO2 security keys, or Windows Hello for Business through Conditional Access authentication strengths.

Small businesses should prioritize:

  • Global Administrators
  • Conditional Access Administrators
  • Security Administrators
  • Exchange Administrators
  • SharePoint Administrators
  • Teams Administrators
  • Intune Administrators
  • privileged MSP or outside IT accounts

Use separate administrator accounts where practical. Do not use a Global Administrator account for ordinary email and web browsing.

Block Legacy Authentication Flows

Legacy authentication methods do not support modern MFA controls in the same way as current authentication flows. If old clients, scripts, scanners, or applications still depend on them, they can create an avoidable path around stronger identity protection.

Before blocking, identify actual usage. A forgotten copier, line-of-business application, or old mobile client should not force the entire organization to keep an insecure protocol available indefinitely.

The business should either modernize the dependency, isolate it through a documented alternative, or accept the risk with an owner and review date.

Restrict Application Consent

Employees often see application permission prompts as part of normal work. That creates risk when a malicious or poorly governed app asks to read email, access files, maintain access, or view profile and directory information.

Baseline Security Mode includes a setting to restrict end-user consent to lower-risk applications that meet defined criteria. That does not mean every certified application is right for the business. It means consent can move from an unrestricted user decision toward a controlled review process.

Small businesses should also define:

  • who reviews application requests
  • which permissions require security review
  • whether publishers and domains are verified
  • who owns each approved application
  • when unused consent grants are removed
  • how emergency approval is handled without bypassing the process

Reduce Password Credentials on Applications

Applications and service principals can use password-style secrets for authentication. Those secrets can be copied, exposed in scripts, forgotten, or left active after the original owner departs.

Where supported, prefer managed identities, workload identity federation, or certificate-based methods. Inventory the business applications first so a security improvement does not unexpectedly stop an integration, automation, or scheduled process.

Email and Exchange Online: Security With a Productivity Blast Radius

One of the most consequential Baseline Security Mode settings is the ability to disable organization-wide Exchange Web Services access.

EWS can access email, calendars, contacts, and related Exchange Online data. Reducing EWS exposure can shrink the attack surface and help organizations move away from a legacy API. Microsoft is also entering the final phase of EWS retirement in Exchange Online beginning in October 2026.

However, EWS has been used by third-party applications and some Microsoft workflows. Turning it off without discovery can affect:

  • older Outlook or Office add-in scenarios
  • calendar sharing and free/busy across some tenant or cloud boundaries
  • Power Query Exchange connectors in Excel, Power BI, Fabric, and Power Platform
  • older Dynamics integrations
  • hybrid Exchange dependencies
  • archiving, migration, CRM, backup, scheduling, or workflow tools that still use EWS

This is why “disable EWS” is not a checkbox exercise. It is an integration project.

Inventory applications, review Microsoft 365 usage and sign-in evidence, contact vendors, test supported replacements such as Microsoft Graph where appropriate, and schedule the change with a rollback plan.

Also remember what this setting does not solve. EWS hardening does not replace email filtering, impersonation protection, Safe Links, Safe Attachments, mailbox auditing, outbound sending controls, or SPF, DKIM, and DMARC.

SharePoint, OneDrive, and Microsoft 365 App Hardening

Microsoft 365 file security is not only about sharing permissions. File types, old protocols, embedded components, and custom scripts can also create risk.

Baseline Security Mode includes settings related to:

  • blocking basic authentication prompts in Microsoft 365 apps
  • blocking file access over insecure protocols such as HTTP or FTP
  • blocking outdated FrontPage Remote Procedure Call behavior
  • restricting legacy SharePoint and OneDrive authentication paths
  • preventing new custom scripts in SharePoint sites
  • limiting end-user installation of SharePoint Store applications
  • opening older Office formats in Protected View
  • blocking ActiveX controls
  • blocking risky OLE objects
  • blocking Dynamic Data Exchange server launches in Excel
  • blocking Microsoft Publisher ahead of its October 2026 retirement from Microsoft 365

Many SMBs can reduce risk here without affecting everyday Word, Excel, PowerPoint, SharePoint, and OneDrive use. The challenge is finding the exceptions.

An accounting workbook may use DDE. A manufacturing or engineering workflow may open an older file format. A legacy intranet may depend on custom script. A vendor may still send files through an insecure protocol. Publisher may still be used for a monthly customer document.

Do not preserve insecure behavior because “someone might use it.” Use the impact report and application inventory to find out who actually uses it, what business process depends on it, and how that process should be modernized.

Teams Rooms and Resource Accounts

Teams room accounts can become overlooked identities.

They may be widely known inside the company, used on shared devices, excluded from normal policies, or able to access more Microsoft 365 content than the room requires. Baseline Security Mode includes controls designed to limit room resource accounts and require supported managed-device conditions.

Review:

  • which room and shared-device accounts exist
  • whether each account has an owner
  • which licenses and roles are assigned
  • whether interactive sign-in is broader than necessary
  • whether the account can access SharePoint or OneDrive files
  • whether the Teams device is enrolled, supported, and compliant
  • whether Conditional Access exclusions are narrow and documented
  • how passwords, passkeys, or other authentication methods are managed

A room account should not become a quiet exception that attackers can use from an unmanaged device.

A Practical Rollout Plan for Small Businesses

Baseline Security Mode should improve security without surprising the business. A staged rollout is the safest approach.

1. Assign an Owner

Decide who owns the review. That may be an internal IT lead, the MSP, a security provider, or a joint team.

Ownership should include more than permission to click Enable. The owner should be responsible for dependency discovery, testing, change communication, monitoring, rollback, documentation, and follow-up.

2. Capture the Current State

Before changing anything, record:

  • current Baseline Security Mode setting status
  • Security Defaults and Conditional Access status
  • privileged roles and administrator accounts
  • authentication methods in use
  • enterprise applications and consent settings
  • Exchange and EWS integrations
  • SharePoint custom scripts and legacy workflows
  • Office add-ins and older file dependencies
  • Teams room and resource accounts
  • exclusions, service accounts, and emergency-access accounts

This creates evidence for the review and a reference point if something changes unexpectedly.

3. Run Impact Reports

Use the available impact reporting for each setting. Investigate the users, devices, applications, files, and workflows that appear.

“No impact found” is a useful signal, not an absolute guarantee. Pair the report with application ownership, help-desk history, vendor documentation, and a pilot.

4. Prioritize High-Value, Low-Disruption Controls

The exact order depends on the tenant, but many small businesses should examine these early:

  1. phishing-resistant authentication for privileged administrators
  2. legacy authentication blocks
  3. tighter application consent
  4. basic authentication prompt blocking
  5. old and insecure file protocol controls
  6. ActiveX, DDE, and outdated file behavior controls
  7. Teams room resource-account restrictions
  8. EWS restrictions after integration discovery

The goal is not to delay every change until the environment is perfect. It is to take the easiest meaningful risk reductions first while planning the settings with a larger business impact.

5. Pilot With Real Workflows

Test with representative people and systems, not only IT accounts.

Include:

  • an administrator
  • an executive or owner
  • finance or accounting
  • a remote employee
  • a heavy SharePoint or OneDrive user
  • a user with important Office add-ins
  • a Teams room or shared device
  • any user tied to a legacy application

Ask the pilot group to perform real tasks: sign in, open shared files, use add-ins, run reports, access calendars, join meetings, work remotely, and use approved business applications.

6. Communicate and Schedule the Change

Tell affected employees what is changing, what they may see, when the change will happen, and how to get help.

For higher-impact settings, define:

  • the maintenance window
  • the test plan
  • the rollback decision and owner
  • the support contact
  • the vendors who may need to participate
  • the evidence that confirms success

7. Validate After Enforcement

After a setting is enabled, review sign-in failures, application errors, help-desk tickets, Defender incidents, audit logs, and user feedback.

Validation should answer two questions:

  1. Did the control reduce the intended exposure?
  2. Did the business keep working as expected?

Document both answers. A security control that was enabled but never verified is still an assumption.

Common Mistakes to Avoid

Avoid these rollout mistakes:

  • treating Baseline Security Mode as one universal on/off switch
  • enabling every setting without impact review
  • leaving settings disabled forever because one dependency exists
  • creating broad exclusions for whole departments
  • using a normal daily account for Microsoft 365 administration
  • forgetting room accounts, shared devices, scanners, and service accounts
  • disabling EWS before checking business integrations
  • assuming Baseline Security Mode configures all email protection
  • failing to review user consent and application ownership
  • skipping rollback and support planning
  • enabling controls but not monitoring the result
  • treating Microsoft's baseline as the company's complete security standard

The best outcome is not the most settings turned on in one afternoon. It is a defensible configuration that removes unnecessary risk, preserves legitimate work, and keeps exceptions visible.

Questions to Ask Your IT Provider

Business leaders do not need to know every Microsoft portal. They should expect clear answers to practical questions.

Ask:

  • Have we reviewed Microsoft 365 Baseline Security Mode?
  • Which recommended settings are enabled, disabled, or still being tested?
  • What evidence supports each exception?
  • Are all privileged Microsoft 365 accounts using phishing-resistant authentication?
  • Do any users or applications still rely on legacy authentication?
  • Can employees approve applications that read email or files?
  • Which systems still use EWS, and what is the migration plan?
  • Are Teams room accounts usable from unmanaged devices?
  • Are anti-phishing, SPF, DKIM, DMARC, Safe Links, and Safe Attachments managed separately?
  • Who reviews risky sign-ins, malicious inbox rules, forwarding, and suspicious application consent?
  • When will the baseline be reviewed again?

“Microsoft handles it” is not a sufficient answer. Microsoft provides the platform and the controls. The business and its IT provider are still responsible for configuring, operating, and validating them.

Microsoft 365 Baseline Security Mode Checklist

Use this as a practical starting point:

  • Confirm who owns Microsoft 365 security configuration.
  • Open Baseline Security Mode in the Microsoft 365 admin center.
  • Record the current status of every available setting.
  • Run and review impact reports.
  • Inventory administrators and require stronger authentication.
  • Find remaining legacy authentication usage.
  • Review application credentials and user consent.
  • Inventory EWS applications and plan migrations.
  • Check SharePoint custom script and older file dependencies.
  • Review ActiveX, DDE, OLE, HTTP, FTP, and legacy file-format use.
  • Inventory Teams room and shared-device resource accounts.
  • Pilot changes with representative users and devices.
  • Document narrow exceptions with owners and review dates.
  • Schedule higher-impact changes with rollback plans.
  • Validate sign-ins, applications, email, files, meetings, and reports after rollout.
  • Keep Defender, domain authentication, monitoring, and incident response in scope.
  • Review the baseline after major licensing, application, or Microsoft service changes.

How CybarWorks Can Help

CybarWorks helps small and midsize businesses turn Microsoft 365 security settings into a practical, managed program.

We can review Baseline Security Mode, Microsoft Entra authentication, Conditional Access, administrator protection, application consent, Exchange Online, Defender for Office 365, EWS dependencies, SharePoint and OneDrive, Teams room accounts, domain email authentication, and account-compromise response.

The goal is not to turn on controls blindly. It is to identify the highest-value gaps, understand business dependencies, implement changes safely, document exceptions, and verify that the environment is more secure without creating avoidable disruption.

If your business is not sure which Microsoft 365 security settings are enabled—or what might break if they change—contact CybarWorks. We can help you build and validate a Microsoft 365 security baseline that fits how your employees, applications, and customers actually work.

Frequently Asked Questions

What is Microsoft 365 Baseline Security Mode?

Microsoft 365 Baseline Security Mode is an admin-center experience that brings together recommended security settings for identity, Microsoft 365 apps, Exchange Online, SharePoint, OneDrive, and Teams room devices. Administrators can review and manage settings individually.

Is Baseline Security Mode available to small businesses?

Microsoft says the settings can be configured across Microsoft 365 subscriptions and plans. Specific underlying features, reporting, and Conditional Access capabilities may still depend on tenant licensing and configuration, so businesses should verify what their subscription supports.

Should a business enable every Baseline Security Mode setting?

Not without testing. Many settings are strong recommendations, but some can affect older authentication, EWS integrations, Office add-ins, SharePoint customizations, legacy files, or Teams room workflows. Review impact, pilot the change, and address dependencies rather than creating permanent broad exceptions.

Does Baseline Security Mode replace Microsoft Defender for Office 365?

No. Baseline Security Mode helps harden configuration. Defender for Office 365 provides email and collaboration protections such as anti-phishing capabilities, Safe Links, Safe Attachments, investigation, and remediation features depending on licensing. Businesses also need SPF, DKIM, DMARC, monitoring, reporting, and response processes.

Can CybarWorks perform a Microsoft 365 security baseline review?

Yes. CybarWorks can review Microsoft 365 identity, email, files, collaboration, applications, device access, and operational processes, then prioritize configuration changes based on risk, business impact, and available licensing.

Works Cited

Ready to transform your business with our IT expertise?