Start with MFA: security defaults or Conditional Access
Microsoft says that multifactor authentication and blocking legacy authentication stop more than 99.9% of common identity attacks. Microsoft Entra ID (the sign-in service behind Microsoft 365) gives you two ways to turn them on.
- Security defaults: free, on or off, no customization. They require all users to register for MFA, require admins to use MFA, block legacy authentication protocols and device code flow, and protect Azure portal access. Microsoft rolls them out by default to new tenants.
- Conditional Access: rules of the form “if this user, app, device, or place, then require MFA, require a compliant device, or block”. It needs Microsoft Entra ID P1, which Microsoft 365 Business Premium includes.
My starting point for a small office: security defaults. Move to Conditional Access when you need exceptions (a scanner, a shared account) or device rules.
A safe order for turning on MFA
- Create two emergency (“break glass”) cloud-only admin accounts and keep their credentials offline. Microsoft recommends two such accounts, permanently assigned the Global Administrator role, for the day normal admin sign-in does not work.
- List what still uses legacy authentication: old scanners or printers that send email with a username and password, IMAP or POP mail clients, Office 2010. Security defaults block them, so fix or replace them first.
- Warn your staff and have everyone register the Microsoft Authenticator app at myprofile.microsoft.com (Security info). The app asks the user to type a number, which helps against MFA fatigue.
- Turn on security defaults (Microsoft Entra admin center > Entra ID > Overview > Properties > Manage security defaults), then watch the sign-in logs for blocked legacy sign-ins.
To move to Conditional Access, you must first turn security defaults off and then enable your policies right away: Microsoft says so, and offers equivalent managed policies.
What Intune does
Intune is Microsoft’s cloud service for managing devices and apps. It enrolls, configures, secures, and updates devices and deploys apps, from a web console, with no server in your office. It manages Windows, macOS, iOS and iPadOS, Android, and Linux. It works in two modes:
- Device management (MDM): the device is enrolled (by the user through the Company Portal, or automatically with Windows Autopilot) and Intune manages its settings, security, and apps. A lost or stolen device can be wiped.
- App management (MAM): Intune manages only the work apps and their data, often on a personal phone. When someone leaves, you remove company data without touching personal content.
Intune also tells Conditional Access whether a device is compliant, which allows a rule like “company email only from compliant devices”. Each managed user or device needs an Intune licence; Microsoft 365 Business Premium includes Intune Plan 1, Entra ID P1, and Defender for Business.
The first Intune settings I set up in a small office
- Enroll the computers and phones that touch company email.
- Disk encryption (BitLocker on Windows) and a screen lock.
- Windows and app updates on a schedule.
- A compliance rule that flags devices that are unencrypted or out of date.
- A clear offboarding step: remove or wipe the device when someone leaves.
I can set it up for you
I set up MFA, Conditional Access, and Intune for Montreal small businesses, remotely or on site, in French or English. You get a written quote first, and I change nothing without your agreement. The one-day IT health check shows where you stand on all of this before you start.