Blog

10 Microsoft 365 Security Settings Singapore SMEs Must Enable Today

Many Singapore SMEs run Microsoft 365 thinking “basic login” is enough. It’s not. We’ve seen 15-person firms in Toa Payoh lose access to their entire finance folder after a single compromised password. Microsoft 365 security Singapore SME teams need isn’t optional—it’s enforceable under PDPC guidelines when personal data is involved. These 10 settings aren’t just checkboxes; they’re the baseline we configure for every client at Typent.

Enable Multi-Factor Authentication (MFA) for All Users

A password alone is a broken lock. MFA adds a second check—like a code from an app or SMS—before granting access. Microsoft reports that MFA blocks over 99.9% of account compromise attacks. In Singapore, we’ve seen multiple 20-person firms in Jurong fall to phishing emails that harvested credentials. Without MFA, attackers walked straight into email and SharePoint. With it, even if a password leaks, the account stays locked. This isn’t just security—it’s compliance. IRAS and CPF submissions require access controls, and MFA is a recognised control under PDPC’s Advisory Guidelines on Ransomware.

managed services we deploy include MFA rollout and user training to reduce helpdesk calls during adoption. We use Microsoft Authenticator app-based approvals by default, avoiding SMS where possible due to SIM-swapping risks.

Restrict Legacy Authentication Protocols

Legacy protocols like IMAP, POP3, and SMTP don’t support MFA. They rely only on passwords, making them a backdoor for attackers. Microsoft recommends disabling them—and so do we. In a recent audit for a 30-person logistics SME in Tuas, we found Outlook 2010 clients still using SMTP auth. That single gap allowed a brute-force tool to run for weeks undetected. Disabling legacy auth closed it instantly. This setting should be enforced via Conditional Access policies in Azure AD, not just suggested.

Configure Conditional Access Policies Based on Risk

Conditional Access lets you define rules like “block login from Nigeria” or “require MFA if user is logging in from a new device.” For SMEs with remote workers, this prevents access from high-risk locations or unmanaged devices. We had a client in Paya Lebar where an employee’s laptop was infected with infostealer malware. Conditional Access policies flagged the unusual sign-in pattern and blocked access before the attacker could move laterally into Teams or OneDrive.

Set up location-based restrictions and device compliance checks. If your team uses personal devices, require Intune registration or at least a compliant browser. This is part of what our managed services monitor 24/7.

Enforce Data Loss Prevention (DLP) Policies in SharePoint and OneDrive

DLP stops employees from accidentally or intentionally sharing sensitive data. A 12-person marketing agency in CBD once uploaded a spreadsheet with 500 customer NRIC numbers to a public SharePoint folder. DLP would have blocked the upload or required approval. Under PDPA Section 24, failing to prevent unauthorized disclosure can lead to penalties up to S$1 million.

Configure DLP to detect common Singapore-specific data: NRIC, passport numbers, CPF contribution files, IR8A forms. Microsoft 365’s built-in templates help, but we customise them for local compliance. DLP alerts go to admins—we include this in our monthly security reports for clients.

Turn On Audit Logging and Retention

You can’t investigate what you can’t see. Audit logging tracks file access, email forwarding rules, admin changes, and login attempts. By default, logs expire after 90 days. For compliance, extend retention to at least one year. During an IRAS audit, one client in Tampines couldn’t prove who modified a GST filing record. No logs meant no accountability. We now set audit retention to 365 days as standard.

Enable Unified Audit Logging in the Security & Compliance Centre. Use PowerShell or the portal to export logs when needed. This ties into Office 365 solutions we deploy with long-term retention policies.

Disable Auto-Forwarding Rules in Exchange Online

Attackers love mail forwarding rules. Once inside an account, they set up silent forwarding to external addresses. The victim doesn’t notice, but all emails—invoices, contracts, HR data—flow out. A 25-person firm in Woodlands lost six months of client correspondence this way. The attacker used it to launch targeted phishing against partners.

Block users from creating inbox rules that forward externally. Use Exchange Online mail flow rules to reject any auto-forwarding to non-whitelisted domains. This is one of the first policies we apply during onboarding.

Enable Safe Links and Safe Attachments in Microsoft Defender for Office 365

Phishing is the top entry vector for SMEs. Safe Links checks URLs in real time—even shortened links. Safe Attachments opens suspicious files in a sandbox first. We’ve seen this catch malware-laced PDFs sent to procurement teams in industrial firms. One client in Tuas received a fake invoice with a malicious macro. Safe Attachments detonated it in isolation and blocked delivery.

Enable both features across email, Teams, and SharePoint. Tune them to your risk level—some SMEs prefer to block first, ask later. This is part of our Trend Micro security integration for layered defence.

Set Up Multi-Stage Admin Approval for Sensitive Actions

Don’t let one admin make irreversible changes. Require two or more approvals for actions like resetting another admin’s password or exporting mailboxes. A 40-person firm in CBD had an insider threat: a departing IT contractor deleted critical data. Multi-stage approval would have flagged the action for review.

Use Privileged Access Management (PAM) in Azure AD. It creates time-limited, audited access. We configure this for all clients using Microsoft 365, especially those handling employee or customer PII.

Isolate and Monitor Inactive Accounts

An inactive account is a forgotten backdoor. We found a 60-person firm in Jurong with a former HR manager’s account still active—no MFA, no monitoring. It had full access to employee records. Microsoft 365 lets you identify stale accounts (no sign-in for 30+ days). Automate their disablement or require reactivation approval.

We integrate this into our managed services with monthly identity reviews. It’s part of maintaining a clean, auditable user base.

Implement Conditional Access for External Sharing

SMEs often share files with vendors, contractors, or clients. But default settings can allow public links with no expiry. Set external sharing to “collaboration only” and require sign-in. Apply Conditional Access so external users must meet security requirements—even if they’re not your employees.

One logistics SME in Pasir Ris shared a tender document via public link. It was indexed by Google. Now, IRAS-related documents are shared only with authenticated users and expire in seven days. We enforce this using sensitivity labels and access controls.

Most of the issues covered here show up clearly in a structured IT audit. Start with a free risk assessment and we’ll identify which ones apply to your setup.

Uncover your hidden systems risk in 5 minutes.

Stop reading about risk and start measuring yours. Our free interactive assessment generates a custom IT vulnerability score — specific to your setup, your sector, and your staff count.