Somebody gets your email password. Not through a movie-style hack. Through a fake sign-in page, or a password they bought in a batch of a thousand from an old breach, or because it was the same password somebody used on a website that got hit three years ago.
What happens next is decided by one setting in your Microsoft 365 account. Not by how complicated the password was. Not by whether your IT person is any good.
The setting is called Conditional Access
Ignore the name. Here is what it does in your life.
You can tell Microsoft: when somebody signs in from a device we don't recognize, or from a city we don't do business in, make them prove it's really them before the mailbox opens. In plain terms, your password alone stops being enough when the sign-in looks wrong.
That's the whole idea. You write a few rules about when to ask for the second form of proof, and Microsoft enforces them every time someone signs in.
Without that setting, a stolen password is usually enough. The attacker signs in from wherever they are, reads your mail, sends invoices to your customers from your address, and sets up a rule that quietly files the replies out of your inbox. Most people find out days later when a customer calls.
Why we bring this up
Almost nobody running a 20-person shop has ever opened it. The setting lives behind an admin screen most owners have never seen, and whoever set up your email three years ago has moved on.
There is a second reason. If you are on Microsoft 365 Business Premium, you already paid for Conditional Access. Microsoft's own documentation is clear that Conditional Access requires the identity protection license bundled with Business Premium. You are not buying anything new. You are flipping a switch that has been sitting there the whole time.
The case for flipping it is not a sales pitch. Microsoft's 2025 Digital Defense Report says multifactor authentication still blocks over 99% of unauthorized access attempts, and that even when an attacker has a valid username and password, MFA blocks access in over 99% of cases. The same report says the low share of sign-ins it sees stopped by MFA reflects limited adoption, not weak protection. People are not skipping it because it doesn't work. They are skipping it because nobody asked them to turn it on.
That pattern shows up in the rest of your subscription too. A CoreView analysis of more than five million Microsoft 365 accounts found that 56% of licenses were inactive, underutilized, oversized, or unassigned, and that the average business could cut its Microsoft 365 costs by 14% just by noticing and reassigning the ones nobody uses. Paying for something and not using it is not unusual. It is the normal state of affairs.
If you're not on Business Premium
Then you may not have Conditional Access at all. Business Basic and Business Standard don't include it.
What you do have is called security defaults, and Microsoft's guidance says it is suitable for most organizations and switches itself on. It requires everyone to register a second form of sign-in, and it blocks the old, weak ways of connecting to email that attackers lean on. For a lot of small shops, that is genuinely enough.
So the first honest question is not "how do I get Conditional Access." It is "which plan am I on, and is the protection I already have actually switched on?" That question takes about ten minutes to answer in the Microsoft 365 admin center. And there is a real chance security defaults got turned off at some point by someone who meant well, which leaves you with less protection than a brand new account.
Three things worth checking this week
In the Microsoft 365 admin center, open Billing, then Licenses. Count the assigned licenses against your actual headcount. Every gap is a seat you are paying for that nobody is sitting in.
Next, open Reports and run the usage report for the last 30 days. Any account with no activity deserves a look, especially if that person left the company.
Finally, find out who can sign in as an administrator, and whether those accounts have the second form of sign-in turned on. Admin accounts are the ones attackers want first, because they open every other door.
None of that requires new software. It requires somebody to open the screens and read them honestly.
The part that matters
We are not going to tell you that turning on one setting makes you safe. Nothing makes you safe. What we can tell you is that this is one of the cheapest, highest-value hours most small businesses have available to them, and most of them never spend it.
If you would rather not be the one reading the admin center, that is a normal answer. Bring someone in for an hour and ask them to show you what you are paying for and what is actually turned on. If it turns out you are in decent shape, that is a good day's work too.
You do not need to buy anything to find out where you stand. That is the free assessment.