

3 Things to Fix Today in Every Microsoft 365 Tenant
In many Belgian SMB environments, security incidents are not caused by advanced threats, but by basic controls that are missing or only partially implemented. For CSP resellers and MSPs, this creates a very practical opportunity: fix a few fundamentals, deliver immediate value, and build the foundation for recurring security services.
Below are three actions that should be standard in every tenant—and that you can realistically assess and improve in a single engagement.

1. Enforce MFA Everywhere (the right way)
Most SMB breaches still start with compromised credentials. If MFA is not consistently enforced, attackers don’t need sophisticated techniques.
In practice, many tenants still have gaps:
- MFA is enabled only for admins, not all users
- Legacy authentication (IMAP, POP, SMTP AUTH) is still allowed
- Per-user MFA is used instead of Conditional Access
The objective isn’t just enabling MFA, it’s enforcing it intelligently using Conditional Access policies.
A solid baseline approach includes:
- Requiring MFA for all users
- Applying stricter controls for admin roles
- Blocking legacy authentication protocols
- Adding policies for risky sign-ins or external access
For MSPs, this is a quick and repeatable implementation. It also naturally leads to discussions around Entra ID P1/P2, identity protection, and ongoing policy management.
2. Make Sure All Devices Are Visible and Protected
A common blind spot in SMB tenants is the lack of full endpoint visibility. Devices may exist, but they are not properly onboarded into Defender, or no one is actively monitoring them.
Typical issues you’ll encounter:
- Devices missing from the Defender portal
- Only basic antivirus in place, no EDR capabilities
- Alerts not reviewed or acted upon
The first step is simple: ensure every device is onboarded into the right solution:
- Defender for Business for SMB environments
- Defender for Endpoint for customers on E3/E5
Then validate that the setup is effective:
- Are all devices reporting correctly?
- Are threat alerts being generated?
- Is there a process to respond to incidents?


3. Use Secure Score as an Action Plan, not a Dashboard
Many tenants have a low Secure Score, but the issue is rarely complexity, it’s simply that recommended actions haven’t been executed.
Secure Score should not be seen as a theoretical metric. It is a ready-made improvement plan with clear, prioritized actions.
Some of the most common quick wins include:
- Reducing the number of global administrators
- Enabling advanced email protections (Safe Links, Safe Attachments)
- Blocking automatic email forwarding to external domains
- Enabling audit logging
- Improving sharing and collaboration settings
The key is to focus on achieving high-impact actions with low implementation effort that will result in immediate risk reduction.
For MSPs, Secure Score is also a powerful commercial tool. It can be reused as a baseline assessment report or a customer conversation starter.
Turning These Fixes into a Partner Play
What makes these three actions valuable is not just their security impact, but how easily they translate into services.
Each fix naturally maps to a partner opportunity:
- MFA and Conditional Access → Identity security services
- Device onboarding → Endpoint protection / MDR
- Secure Score improvements → Security assessments and roadmaps
This allows you to move from one-time remediation into structured, recurring engagement

Conclusion
If you standardise your approach across customers, these three steps become a powerful baseline:
- Strong identity protection
- Full device visibility
- Continuous security improvement
They are simple, repeatable, and relevant for almost every SMB tenant in the Belgian market.
More importantly, they shift the conversation from reactive support to proactive security, exactly where MSPs and CSP partners can differentiate and grow.

