For many UK SMEs, Microsoft 365 is the digital backbone of the business. It manages your emails, stores your sensitive documents in SharePoint, and facilitates collaboration through Teams. Because it is so central to your operations, Microsoft Defender—the security suite built into the platform—should be your primary line of defence. However, simply having a Microsoft 365 licence does not mean you are secure. In our experience at Black Sheep Support, we frequently encounter businesses that believe they are fully protected, only to discover that their Defender environment is riddled with "silent" misconfigurations. These gaps are not necessarily bugs; they are often the result of default settings that prioritise ease of use over robust security, or a misunderstanding of how complex the configuration process truly is. These overlooked settings can leave your organisation wide open to the very threats Defender is designed to prevent. This guide will explore the most common pitfalls that leave UK SMEs vulnerable and provide actionable steps to tighten your security posture.
What Microsoft Defender misconfigurations actually mean
A "misconfiguration" in Microsoft Defender refers to any setting within the security suite that is not optimally configured to protect your organisation against current cyber threats. It is not an error in the software itself, but rather a suboptimal choice or oversight in its setup. Essentially, you own a powerful security system, but it is either not fully switched on, or its various components are not communicating effectively to provide comprehensive protection. This can manifest as overly permissive email policies, disabled endpoint protection features, or identity controls that are easily bypassed. The default settings provided by Microsoft are often a compromise, designed to ensure basic functionality without disrupting user experience. For a UK SME, these defaults are rarely sufficient for genuine security. True protection requires deliberate, informed adjustment of these settings to match your specific risk profile and the evolving threat landscape.
Why it matters for UK SMEs
For UK SMEs, the consequences of Defender misconfigurations extend far beyond mere inconvenience; they represent tangible business risks. Firstly, there is the immediate commercial impact. A successful cyber attack, facilitated by a misconfigured Defender environment, can lead to significant financial losses from ransomware demands, fraud, or data theft. Operational downtime can crialyse your business, impacting revenue and client trust.
Beyond direct financial losses, there is a substantial regulatory dimension. The Information Commissioner's Office (ICO) in the UK takes a dim view of organisations that fail to adequately protect personal data. Under the UK GDPR, a data breach resulting from negligent security configurations can lead to hefty fines and mandatory reporting, damaging your reputation and potentially triggering investigations. Demonstrating that you have taken "appropriate technical and organisational measures" to secure data is a legal requirement.
Furthermore, industry standards and compliance frameworks increasingly demand robust security. Achieving certifications like Cyber Essentials, a UK government-backed scheme, often necessitates specific configurations within Microsoft Defender for Endpoint and Office 365. A low Microsoft Secure Score, often a symptom of misconfigurations, directly indicates non-compliance with these best practices, making it harder to secure crucial contracts, particularly within public sector supply chains. Cyber insurance providers are also becoming more stringent, often requiring proof of foundational controls such as Multi-Factor Authentication (MFA) and advanced threat protection, which are frequently misconfigured. Failing to meet these requirements can invalidate policies or lead to significantly higher premiums. In essence, neglecting your Defender configuration is not just an IT oversight; it is a business risk that can affect your finances, legal standing, and market viability.
How to optimise Microsoft Defender, a practical walkthrough
Optimising Microsoft Defender requires a methodical approach, moving beyond the comfort of default settings to implement policies that genuinely protect your business.
1. Move beyond the "Default Settings" Trap
The most common misconception we encounter is the belief that Microsoft Defender is "plug-and-play." While it is true that Defender offers a baseline level of protection out of the box, this baseline is designed to be as unobtrusive as possible to prevent productivity issues. For a modern SME facing sophisticated cyber threats like ransomware and business email compromise (BEC), "out-of-the-box" is insufficient.
When you first set up your Microsoft 365 tenant, many security features are either disabled or set to a "passive" mode. For example, automated investigation and response capabilities may not be fully enabled, or email filtering might be set to a level that allows too many potentially malicious attachments through to your staff’s inboxes.
- Actionable Advice: Treat your Microsoft 365 tenant as a blank canvas. Conduct an audit of your "Security Defaults." Often, moving from the basic "Security Defaults" to "Conditional Access" policies is the single most important step an SME can take to improve its maturity. Conditional Access provides granular control, allowing you to define specific conditions under which users can access resources, such as requiring MFA only when accessing sensitive data from an untrusted location. On a recent client tenant audit for a 50-user London-based design agency, we found the default security settings were still active, leaving critical attack surface exposed, particularly around guest access and administrative roles.
2. Fortify Email Filtering and Anti-Phishing Policies
Email remains the primary attack vector for cybercriminals targeting UK SMEs. Phishing campaigns have become increasingly convincing, often bypassing standard spam filters. A common misconfiguration in Defender for Office 365 is the failure to tune anti-phishing and anti-spam policies to reflect the current threat landscape.
- Impersonation Protection: Are you protecting your CEO and Finance Director? Attackers frequently register domains that look almost identical to yours to trick employees into transferring funds. Defender has built-in impersonation protection, but it must be manually configured to monitor specific high-profile accounts, including internal users and critical external domains that your staff frequently interact with. It is also wise to protect your own domain from being spoofed by external senders.
- Safe Attachments and Links: Are you using "Dynamic Delivery"? This allows users to read the body of an email while Defender scans the attachments in the background. If the attachment is found to be malicious, it is replaced with a warning, preventing the user from ever opening the threat. This is a critical layer of defence against zero-day malware. Similarly, Safe Links re-writes URLs in emails, scanning them for malicious content at the point of click, not just on arrival.
- Practical Configuration Steps:
- Navigate to the Microsoft 365 Defender portal (security.microsoft.com).
- Under Email & collaboration > Policies & rules > Threat policies, review your Anti-phishing policies. Ensure that "Safety tips" are enabled so users get a visual warning if an email looks suspicious. Configure user and domain impersonation protection for your key personnel and frequently used external domains.
- For Anti-spam policies, set the "Action" for high-confidence phishing emails to "Quarantine" rather than "Move to Junk." Junk folders are often checked by users, whereas quarantined items require administrator intervention and review. Also, consider enabling "Zero-hour auto purge" (ZAP) to remove malicious emails that might have initially bypassed filters but were later identified as threats.
- Within Safe Attachments and Safe Links policies, ensure these are applied broadly to all users. For Safe Attachments, set the action to "Block" for detected malware, with "Dynamic Delivery" as the preferred scanning method.
3. Actively Engage with Microsoft Secure Score Recommendations
Microsoft provides a tool called "Microsoft Secure Score," which acts as a scorecard for your security posture. It measures how well you have implemented recommended security controls. Many SMEs ignore this, viewing it as a marketing tool rather than a technical roadmap.
A low Secure Score indicates that you have left "doors unlocked." Microsoft provides specific, step-by-step instructions on how to improve your score. By completing these tasks, you are not just ticking a box; you are actively closing security gaps that threat actors use to gain initial access.
- Compliance Alignment: For UK SMEs, improving your Secure Score is a foundational step toward achieving Cyber Essentials certification. It provides documented proof that you are managing your IT assets in accordance with industry best practices. Many of the actions recommended by Secure Score directly correlate to controls required for Cyber Essentials, such as enabling MFA, managing administrative access, and securing endpoints. This is increasingly required for insurance premiums and government contracts. Regularly reviewing and acting on these recommendations also aligns with the NCSC's Small Business Guide to cyber security.
4. Eliminate the "Partial" MFA Gap and Legacy Authentication
Multi-Factor Authentication (MFA) is no longer optional; it is a business necessity. However, a common misconfiguration involves "partial" MFA implementation. This happens when MFA is enforced for some users but not others, or when legacy authentication protocols are left enabled.
The legacy authentication risk is substantial. Legacy authentication (like older versions of Outlook or POP3/IMAP protocols) does not support modern MFA. If these protocols are enabled, an attacker can bypass your MFA entirely by using a legacy application to authenticate. From our service desk data, the most common cause of account compromise in UK SMEs is a combination of weak passwords and the presence of enabled legacy authentication protocols.
- Audit Your Tenant: Disable legacy authentication immediately. Microsoft provides reporting tools in Azure AD (now Microsoft Entra ID) to identify users and applications still relying on these protocols before you disable them.
- Conditional Access for MFA: Instead of just "turning on MFA" for all users through Security Defaults, use Conditional Access policies in Microsoft Entra ID. This allows you to set sophisticated rules such as: "If a user is logging in from a non-UK IP address, require an MFA challenge," or "If a user is logging in from an unmanaged device, block access to sensitive applications." This adds a layer of geographic and device intelligence to your security, making MFA much more effective and user-friendly. Ensure MFA is enforced for every single user, particularly administrative accounts, which are prime targets for attackers.
5. Embrace Automated Investigation and Response (AIR)
Many SMEs operate with a "wait and see" approach to security alerts. In a modern threat environment, manual response is too slow. If a device is compromised, it can spread ransomware across your network in seconds. The average "dwell time" (the period an attacker remains undetected in a network) can be substantial if manual processes are relied upon.
Microsoft Defender for Endpoint features Automated Investigation and Response (AIR). When an alert is triggered, the system can automatically investigate the threat, determine if it is malicious, and remediate it—all without human intervention. This includes actions like isolating devices, stopping processes, or quarantining files.
- Why this is vital: By enabling "Full" automation in your Defender for Endpoint settings, you ensure that your security is working 24/7, even when your IT team is offline. This significantly reduces the "dwell time" of an attacker—the time they spend inside your network before being detected and evicted—minimising potential damage. Review the automation level for your security incidents and ensure it is set to "Full" where appropriate, considering your organisation's risk appetite and incident response processes.
6. Configure Endpoint Security Baselines and Attack Surface Reduction
Beyond simply installing Defender for Endpoint, its true power lies in its advanced configuration. Many SMEs overlook the granular controls available to harden endpoints.
- Attack Surface Reduction (ASR) Rules: These rules prevent common attack techniques, such as blocking executables from running unless they meet specific criteria, or preventing Office applications from injecting code into other processes. They are highly effective against ransomware and fileless malware but are often not fully enabled or tuned.
- Controlled Folder Access (CFA): This feature protects your critical data folders from unauthorised changes by malicious applications, specifically targeting ransomware. It needs to be configured to protect the folders where your sensitive documents are stored, and legitimate applications need to be whitelisted.
- Device Control: Managing USB devices and other peripherals can prevent data exfiltration and malware introduction. Policies can be set to block, audit, or allow specific devices based on your security requirements.
7. Implement Proper Audit Logging and Alerting
Even the most robust security system is ineffective if you are unaware of incidents. A common misconfiguration is failing to properly configure audit logging and alert notifications.
- Audit Log Retention: Ensure that audit logs for all critical services (Exchange Online, SharePoint Online, Azure AD) are enabled and retained for a sufficient period, ideally 90 days or longer, to aid in forensic investigations. This is crucial for demonstrating compliance and understanding past security events.
- Alert Policies: Configure custom alert policies in the Microsoft 365 Defender portal for high-severity events that are specific to your business, such as unusual administrative activity, mass file deletions, or suspicious external forwarding rules. Ensure these alerts are routed to the appropriate personnel or security monitoring system. Without proper alerting, even the most advanced detection capabilities are effectively silent.
Common mistakes we see
- "Set and Forget" Mentality: Policies are configured once during initial setup and never reviewed or updated, despite the evolving threat landscape.
- Ignoring Secure Score: Treating Microsoft Secure Score as a vanity metric rather than an actionable roadmap for improving security posture.
- Partial MFA Implementation: Believing MFA is fully deployed when legacy authentication protocols are still enabled, creating a bypass, or not enforcing it for all users.
- Over-Reliance on Defaults: Assuming out-of-the-box settings provide adequate protection without any customisation or tuning.
- Lack of Centralised Alert Management: Alerts are generated but not monitored, actioned, or escalated, leading to missed threats.
Key Takeaways
To ensure your Microsoft Defender environment is working for you, rather than against you, keep these principles in mind:
- Move beyond defaults: Use Conditional Access policies instead of generic "Security Defaults" for granular control.
- Prioritise identity: Disable legacy authentication and ensure MFA is enforced for every single user, including administrative accounts.
- Tune your email security: Implement strict impersonation protection, Safe Attachments/Links, and use the quarantine feature for suspected threats.
- Use the Secure Score: Treat the Microsoft Secure Score as your primary checklist for compliance and security maturity, actively addressing its recommendations.
- Enable Automation: Let the AI do the heavy lifting by configuring Automated Investigation and Response to handle threats at machine speed.
- Configure Endpoints Deeply: Implement Attack Surface Reduction rules and Controlled Folder Access to harden your devices.
- UK Context: Always ensure your policies align with ICO guidance regarding data protection and GDPR, particularly concerning how you log and store security events.
Securing your environment is an ongoing process, not a one-time project. As cyber threats evolve, so too must your configurations. If you are unsure whether your current setup is robust enough to withstand a modern attack, or if the thought of configuring all of this yourself makes you want to lie down in a darkened room, it is time to have a professional audit.
To take the next step



