Your team is in M365 all day. So are the criminals.


Microsoft 365 is the backbone of the modern small business. Email, file storage, Teams calls, shared calendars — it’s all there, always on, always connected. And that’s exactly what makes it such an attractive target for cybercriminals.

M365 account compromises have surged in recent years, and small businesses bear a disproportionate share of the damage. It’s not because small businesses are careless — it’s because they face a specific set of circumstances that make their M365 environments harder to protect without dedicated IT support.

Here’s an honest look at why these attacks happen so frequently, and what you can do to close the gaps.


The Stakes Are Higher Than You Think

When a criminal gets into a Microsoft 365 account, they don’t just get email. They get:

  • OneDrive and SharePoint files — including contracts, client records, financial documents, and payroll data
  • Teams conversations — internal discussions, shared files, and meeting recordings
  • Connected apps — anything your business has linked to M365, from accounting software to CRMs
  • The ability to impersonate you — sending emails that come from your real address, to your real contacts

A compromised M365 account isn’t a nuisance. It’s a full window into your business — and a launchpad for fraud, data theft, and attacks on your clients and vendors.


Why Small Businesses Are Especially Vulnerable

1. Multi-factor authentication still isn’t turned on everywhere

This is the single biggest factor. Microsoft’s own data shows that MFA blocks over 99% of automated account compromise attacks. Yet many small businesses either haven’t enabled it, or have only turned it on for some accounts and not others — leaving gaps that attackers find quickly.

The reasons are understandable: employees push back, setup feels complicated, or nobody flagged it as urgent. But without MFA, a stolen password is all a criminal needs to walk right in.

2. Passwords get reused across sites

Your employees use the same password for M365 that they use for a retail website, a gym app, or a forum they signed up for years ago. That other site gets breached (and breaches happen constantly — billions of credentials are available on criminal marketplaces right now). The attacker tries that email-and-password combination against Microsoft 365. It works. This is called credential stuffing, and it’s one of the most common entry points for M365 compromises.

Small businesses rarely have password manager policies in place or enforcement mechanisms to stop this from happening.

3. Phishing emails slip through

Microsoft 365’s built-in spam filtering is decent — but it’s not impenetrable, especially for sophisticated phishing emails that don’t carry traditional malware signatures. Attackers send messages that look like Microsoft security alerts, shared document notifications, or voicemail notifications, all designed to get an employee to enter their M365 credentials on a fake login page.

Without additional email security layers — and without employees who’ve been trained to recognize these attempts — one convincing email is all it takes.

4. Admin accounts aren’t protected carefully enough

In many small businesses, one or two people have global administrator access to the M365 tenant — and those accounts are treated just like any other user account. No separate admin credentials, no additional MFA policies, no monitoring. If an attacker compromises an admin account, they can lock out legitimate users, create new accounts, disable security settings, and extract data at will.

5. Legacy authentication protocols are still active

Older email clients and applications use authentication protocols — like Basic Auth — that don’t support MFA at all. If your M365 environment still allows these legacy protocols (and many small business tenants do, because nobody has turned them off), attackers can bypass MFA entirely by connecting through those older pathways. Microsoft has been phasing these out, but environments that haven’t been actively managed may still have them enabled.

6. Security alerts go unnoticed

Microsoft 365 generates security signals constantly — logins from unusual locations, impossible travel (a login from Philadelphia and then from Eastern Europe 20 minutes later), new inbox rules being created, mass email forwarding being turned on. These are all red flags that an account may be compromised.

But if nobody is watching the Microsoft Secure Score dashboard or reviewing sign-in logs, those alerts surface and disappear without anyone acting on them. Small businesses rarely have the time or internal expertise to monitor this consistently.

7. Conditional access policies aren’t configured

Microsoft 365 includes powerful tools — particularly Conditional Access in Entra ID — that let you define rules for when and how users can log in. You can require MFA only when logging in from outside the office, block logins from high-risk countries, or require compliant devices. These controls significantly reduce attack surface.

Most small businesses either aren’t on a license tier that includes them, or haven’t configured them even when they’re available.


What Happens After an Account Is Compromised

Understanding the attacker’s playbook helps illustrate why a quick response matters so much.

Within minutes of gaining access, a criminal will typically:

  1. Search the inbox for keywords like “wire,” “invoice,” “bank,” “password,” and “tax” to identify financial opportunities
  2. Set up forwarding rules to silently copy all incoming emails to an external address — so they keep receiving mail even after the password is changed
  3. Look for other accounts to pivot to — using the compromised inbox to reset passwords on connected services
  4. Identify vendors and clients to impersonate in follow-up fraud

By the time anyone notices something is wrong, the attacker may have been in the account for days or weeks.


How to Significantly Reduce Your Risk

None of these steps require enterprise-level resources. They do require someone to actually implement and maintain them.

Turn on MFA for every account, no exceptions. Use Microsoft Authenticator rather than SMS codes where possible, as SMS can be intercepted. This is the single highest-impact action you can take.

Disable legacy authentication protocols. If your team is using modern apps and email clients, there’s no reason to leave older protocols active. Blocking them eliminates a significant bypass route for attackers.

Review and set Conditional Access policies. Even basic policies — like requiring MFA for any login outside your office network — add meaningful friction for attackers.

Deploy advanced anti-phishing protection. Microsoft Defender for Office 365 (Plan 1 or Plan 2, depending on your license) adds layers of protection against phishing and business email compromise that go well beyond the default filtering.

Protect admin accounts separately. Admin accounts should have separate credentials, dedicated MFA, and ideally be used only for administrative tasks — not daily email.

Enable alerts for suspicious sign-in activity. At minimum, make sure someone is notified when logins occur from unusual locations or when inbox rules are created. Responding fast is the difference between a contained incident and a costly one.

Run security awareness training. A short phishing simulation and training session can dramatically change how your employees respond to suspicious emails. It doesn’t have to be elaborate to be effective.


The Underlying Problem

Most small businesses set up Microsoft 365, hand out licenses, and move on. The default configuration is designed for convenience, not security. Closing the gaps requires deliberate setup — and ongoing attention as Microsoft releases new features, retires old ones, and as the threat landscape shifts.

That’s a lot to manage when you’re focused on running your business.

We can help. Data Troop can take Microsoft 365 security off your plate: configuring MFA and Conditional Access, monitoring for suspicious activity, keeping licenses and policies current, and making sure your environment is actually as secure as you assume it is.


Let’s Get Started