Microsoft 365 Security Baseline 2026: the twelve minimum measures for SMEs.
This is the security foundation Qteco recommends and configures for every Microsoft 365 environment of an organisation with 10 to 250 employees. Twelve measures, each with the reason, the setting and the evidence you can show a regulator, insurer or customer. An organisation that has these twelve in place covers the NIS2 duty of care for the Microsoft 365 layer and closes the attack paths we see exploited most often in practice.
How this baseline is put together.
Every measure meets three criteria: it closes an attack path that is actually exploited in SMEs, it can be configured with a Business Premium licence without extra products, and the result is demonstrable inside Microsoft 365 itself. Measures that need E5 or separate tooling are deliberately left out of the baseline; they belong to the tailored layer above it.
Sources
Microsoft Secure Score and the Zero Trust deployment guidance, the basic measures of the Dutch NCSC, article 21 of the NIS2 directive and the practice of the tenants managed by Qteco.
Order
The measures are listed in the order we configure them: identity first, then devices and e-mail, then data and recovery, and finally insight and people. The first four remove the most risk.
Evidence
Each measure states where the evidence comes from: a report, a policy export or a score. That makes the baseline usable as an evidence file for NIS2, a cyber insurance policy or a customer audit.
Twelve measures, in the order of configuration.
Per measure: why, how (the setting in Microsoft 365) and the evidence. The settings apply to Microsoft 365 Business Premium; with E3, Defender for Business and Defender for Office 365 are add-ons.
MFA for all users, phishing-resistant for administrators
Why: a stolen password is the most common way in. How: Conditional Access policy "Require MFA for all users"; Authenticator with number matching as the minimum, SMS disabled; passkeys or FIDO2 keys mandatory for administrators and finance roles. Evidence: the Authentication methods activity report in Entra ID, 100 percent registered.
Legacy authentication blocked
Why: old protocols (POP, IMAP, SMTP basic auth) bypass MFA entirely. How: Conditional Access policy "Block legacy authentication"; Security defaults off once Conditional Access is active. Evidence: sign-in logs filtered on legacy clients show zero successful sign-ins.
Separate admin accounts and least privilege
Why: a global admin who e-mails and browses every day is one phishing mail away from a full takeover. How: separate admin accounts without a mailbox, at most two to four global admins, all other roles as small as possible; break-glass account documented. Evidence: the role overview in Entra ID and the Secure Score recommendation "fewer than five global admins".
Only managed and healthy devices
Why: a private laptop without updates or encryption weakens every other measure. How: Intune compliance policy (encryption, updates, Defender active) and Conditional Access "Require compliant device" for company data; mobile via app protection policies. Evidence: the Intune compliance report, all devices compliant or blocked.
EDR on every device
Why: antivirus recognises known files, not the behaviour of an attack. How: Defender for Business (or for Endpoint) rolled out via Intune to all Windows, macOS and mobile devices, with automatic isolation enabled. Evidence: the Defender portal: onboarding 100 percent, no devices without a sensor.
E-mail protection against phishing and malicious attachments
Why: e-mail is the largest attack gateway; Microsoft is the most impersonated brand. How: Defender for Office 365 with Safe Links, Safe Attachments and anti-phishing with impersonation protection for management and finance; a report button in Outlook. Evidence: the policy export and the monthly Threat protection report.
SPF, DKIM and DMARC enforced
Why: without DMARC anyone can send mail in your name, to customers and colleagues. How: SPF and DKIM for every sending system, DMARC policy on quarantine or reject with reporting. Evidence: the DNS records and the DMARC reports of the past month.
Independent, immutable backup of Microsoft 365
Why: Microsoft guarantees availability, not the retention of your data; the recycle bin is empty after the retention period. How: daily backup of Exchange, OneDrive, SharePoint and Teams to immutable storage outside the tenant, in the EU; restore test at least annually. Evidence: the backup report and the record of the last restore test.
External sharing restricted and sensitive data labelled
Why: "anyone with the link" and "everyone in the organisation" are the source of most data breaches and Copilot surprises. How: external sharing only with known guests and with an expiry date, guest access reviewed periodically, sensitive documents labelled with Microsoft Purview. Evidence: the SharePoint sharing report and the overview of labels in use.
Audit logging on and alerts configured
Why: without a log an incident cannot be reconstructed or reported within 24 hours. How: unified audit log enabled with a retention of at least 180 days, alerts on risky sign-ins, new administrators and forwarding rules to external addresses. Evidence: the alert rules and a sample from the audit log.
Secure Score as the monthly measure
Why: a baseline erodes without measurement; new recommendations arrive every month. How: Microsoft Secure Score at least 70 percent, reviewed monthly by the IT partner, deviations documented with a reason. Evidence: the Secure Score history of the tenant.
Awareness and phishing simulation every quarter
Why: technology does not catch everything; employees are the last layer. How: a short training at onboarding and annually for everyone including the board, a phishing simulation every quarter, the report button actively used. Evidence: the attendance list and the simulation report per quarter.
Which measure covers which part of the duty of care.
The Dutch Cyberbeveiligingswet lists ten topics from article 21 of the NIS2 directive. This table shows which of the twelve measures cover them for the Microsoft 365 layer; the full checklist is in the publication NIS2 SME checklist 2026.
Frequently asked questions about the baseline.
Is Microsoft Authenticator enough against phishing?
For regular users the Authenticator app with number matching is the minimum and stops by far the most attacks. It does not help against adversary-in-the-middle phishing, where a fake sign-in page relays the code live. That is why the baseline requires passkeys or FIDO2 keys for administrators and finance roles, and why Qteco recommends them for everyone afterwards.
Can an attacker bypass MFA?
Yes, in three ways: through legacy authentication that skips MFA (measure 2), through a hijacked sign-in session after a fake sign-in page (measure 1, passkeys) and through MFA fatigue from repeated push notifications (number matching). The baseline closes all three.
How do you give executive accounts extra protection?
Management and finance are the targets of CEO fraud. For them the baseline requires passkeys, impersonation protection in Defender for Office 365, no forwarding rules to external addresses, and a separate Conditional Access policy that blocks sign-ins from unknown locations.
How do you recognise a stolen Microsoft 365 session?
By unusual sign-in behaviour: a sign-in from another country within an hour of a sign-in in the Netherlands, a new device without Intune registration, or a forwarding rule that suddenly appears. Measure 10 makes sure those signals raise an alert; a SOC assesses them 24/7 and revokes the session.
What does it cost to implement this baseline?
All twelve measures can be configured with the licence most SMEs already have, Microsoft 365 Business Premium. At Qteco the configuration and maintenance of this baseline is part of every workplace package from around € 89 per workplace per month. Only the independent backup (measure 8) requires a separate service, which is included in the packages as well.
How often is this baseline reviewed?
Annually, or earlier when Microsoft changes a measure or a new attack path appears in practice. Every version gets a number (2026.1) and a date, and the changes compared with the previous version are listed at the bottom of the page. Always cite with the version number.
How to cite this publication.
This baseline is published under the Creative Commons Attribution 4.0 International licence (CC BY 4.0): you may share, adapt and quote it, including commercially, as long as you credit Qteco and state the version number. Changes per version are listed alongside.
Nguyêñ Dúc, T. (2026). Qteco Microsoft 365 Security Baseline 2026, version 2026.1. Qteco B.V., Eindhoven. https://qteco.nl/en/microsoft-365-security-baseline. Licence: CC BY 4.0.
September 2026, first public version
Twelve measures, mapping to the NIS2 duty of care, FAQ. Based on the state of Microsoft 365 Business Premium in September 2026. English edition and CC BY 4.0 licence added on 9 September 2026.
Find out in 2 minutes how many of the twelve you already have.
The free Microsoft 365 security check tests the key measures from this baseline. Or let Qteco configure and maintain the full baseline as part of the managed workplace.
