
Microsoft 365 is the backbone of how most Houston businesses communicate, collaborate, and store data. It's also one of the most targeted platforms in the world. Business email compromise (BEC) attacks β where attackers gain access to a legitimate M365 account and use it to redirect wire transfers, impersonate executives, or compromise clients β cost U.S. businesses more than $2.9 billion in 2023 alone, according to the FBI's Internet Crime Complaint Center.
The problem isn't Microsoft 365 itself β it's the gap between the security settings most organizations deploy and the settings that actually protect them. Microsoft ships M365 with a set of defaults that balance security with ease of onboarding. Those defaults are not sufficient for a business handling sensitive data, client information, financial records, or regulated information.
This checklist covers the specific settings, policies, and configurations that Houston businesses β across The Woodlands, Katy, Sugar Land, Pasadena, Conroe, and downtown Houston β should have in place in 2026. Work through it with your IT team or managed service provider and treat every unchecked item as an open vulnerability.
This is the single highest-impact security control in M365. Accounts protected by MFA are more than 99% less likely to be compromised, according to Microsoft's own telemetry. Yet many organizations still have MFA gaps β legacy service accounts, executives who requested exemptions, or shared accounts that were never enrolled.
Legacy authentication protocols β SMTP AUTH, POP3, IMAP, and older Exchange ActiveSync β do not support modern MFA. Attackers specifically target these protocols to bypass MFA entirely. If your tenant still allows legacy authentication, an attacker with a stolen password can authenticate to your environment without triggering any MFA challenge.
Conditional Access is the policy engine that controls when and how users can authenticate β evaluating signals like user identity, device compliance, location, and application being accessed before granting access. Basic Conditional Access policies every M365 tenant should have:
These three DNS-based email authentication standards work together to prevent attackers from sending email that appears to come from your domain. Many Houston businesses have SPF configured (because it's been around the longest) but are missing DKIM and DMARC.
p=none (monitoring mode), review the reports, then advance to p=quarantine and eventually p=reject to actively block spoofed email. A DMARC policy at p=reject makes it extremely difficult for attackers to send phishing emails impersonating your domainExchange Online Protection (the baseline email filter included with M365) is a starting point, not a complete solution. Microsoft Defender for Office 365 (Plan 1 is included with M365 Business Premium) adds significantly more protection:
When attackers compromise an M365 inbox, one of their first actions is creating inbox rules that forward all email to an external address, delete security alerts, or hide replies to their own messages. These rules persist even after a password reset if you don't explicitly look for and remove them.
Get-Mailbox -ResultSize Unlimited | Get-InboxRuleAdmin accounts used to read email and browse the web are admin accounts waiting to be compromised. Global administrators, Exchange administrators, SharePoint administrators, and other privileged roles should exist as dedicated, separate accounts β used only for administrative tasks, never for email or general computing.
PIM (available with Entra ID P2 or Microsoft 365 E5) implements just-in-time privileged access β admin roles are not permanently assigned but must be explicitly activated for a time-limited period when needed. This eliminates the large standing attack surface of permanently assigned admin privileges.
Before enabling strict Conditional Access policies, ensure you have two emergency access accounts that are excluded from all Conditional Access policies and can be used if your primary admin accounts are locked out. These accounts should use long, complex passwords stored securely offline, be monitored for any sign-in activity (any use is an alert), and use FIDO2 hardware keys as their authentication method.
Default sharing settings in M365 allow users to share files with anyone who has the link β including people outside your organization who aren't authenticated. For most Houston businesses handling client data, this is too permissive.
DLP policies prevent users from sharing sensitive information β Social Security numbers, credit card numbers, HIPAA-regulated health data, ITAR-controlled technical information β through email, Teams, or SharePoint. For Houston businesses in regulated industries, DLP is not optional.
Microsoft 365's audit log records user and admin activities across Exchange, SharePoint, OneDrive, Teams, and Entra ID. This is your primary forensic resource after an incident β but only if it was enabled before the incident. Audit logging is not enabled by default in all tenants.
Microsoft Secure Score (available in the M365 Defender portal) gives your tenant a score out of 100 based on which security controls are enabled. It provides a prioritized list of recommended actions with estimated score impact. Most organizations start between 30-50%; a well-hardened tenant targeting 70%+ has meaningfully reduced its attack surface.
For organizations with more mature security requirements β multi-location businesses, those in regulated industries, or companies with a high-risk profile β forwarding M365 audit and sign-in logs to a SIEM (Security Information and Event Management) platform or a managed SOC enables correlated alerting across your entire environment, not just M365 in isolation.
| Category | Control | Priority |
|---|---|---|
| Identity | MFA enforced for all users | Critical |
| Identity | Legacy authentication blocked | Critical |
| Identity | Conditional Access policies deployed | Critical |
| Identity | Phishing-resistant MFA for admins | Critical |
| SPF + DKIM + DMARC configured | High | |
| Defender anti-phishing with impersonation protection | High | |
| Safe Links + Safe Attachments enabled | High | |
| Regular inbox rule audit | High | |
| Admin | Dedicated admin accounts (no mailbox) | High |
| Admin | PIM for just-in-time privileged access | Medium |
| Admin | Break-glass emergency access accounts | High |
| Data | SharePoint external sharing restricted | High |
| Data | DLP policies for regulated data types | Medium |
| Monitoring | Unified audit logging enabled + retained | Critical |
| Monitoring | Microsoft Secure Score reviewed quarterly | Medium |
After working with businesses across Harris County, Montgomery County, Fort Bend County, and Brazoria County, the gaps we see most consistently are:
p=none forever) β monitoring mode with no enforcement means attackers can still spoof your domain. The goal is p=reject.LayerLogix offers Microsoft 365 security assessments and hardening for businesses across Greater Houston β from small professional services firms in Sugar Land and Katy to mid-market manufacturers in Conroe and multi-location healthcare groups serving patients across The Woodlands and Pearland.
Our M365 security service includes a full configuration audit against the CIS Microsoft 365 Benchmarks, a prioritized remediation plan with business-impact context for each finding, implementation assistance for all controls, and ongoing monitoring to catch configuration drift before it creates exposure.
Request a Microsoft 365 security assessment. We'll tell you exactly where your tenant stands and what needs to change β no jargon, no upsell pressure, just a clear picture of your current posture. Call 713-571-2390 or use our contact form.
Related: The Three Cyberthreats Dominating 2026 | Dark Web Monitoring for Houston Businesses | Zero Trust Architecture for Texas Businesses
LayerLogix provides expert cybersecurity solutions for businesses across Houston and nationwide.
Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.