{"id":19765,"date":"2026-02-12T06:50:59","date_gmt":"2026-02-12T05:50:59","guid":{"rendered":"https:\/\/coreit.se\/okategoriserad\/are-security-features-enabled-by-default-in-microsoft-365"},"modified":"2026-03-26T07:23:58","modified_gmt":"2026-03-26T06:23:58","slug":"are-security-features-enabled-by-default-in-microsoft-365","status":"publish","type":"post","link":"https:\/\/coreit.se\/en\/faq\/are-security-features-enabled-by-default-in-microsoft-365","title":{"rendered":"Are security features enabled by default in Microsoft 365?"},"content":{"rendered":"\n<div class=\"custom-ai-wrapper\">\n  <h2 class=\"ai-question\">Are security features enabled by default in Microsoft 365?<\/h2>\n\n  <div class=\"ai-summary\">\n    <p>Microsoft 365 comes with several security features pre-configured, but not all advanced protections are enabled by default. Basic features like email filtering, antivirus, and simple policies are active, while advanced features like multi-factor authentication, Advanced Threat Protection (ATP), Conditional Access, and Secure Score require administrative activation and customization to provide a full level of security. <\/p>\n  <\/div>\n\n  <div class=\"ai-columns\">\n    <div class=\"ai-background\">\n      <h2>Background and overview<\/h2>\n      <p>Security is a core part of Microsoft 365, but to maximize protection, administrators often need to configure and enable certain features. This is because organizations&#8217; needs and risk profiles vary. <\/p>\n\n      <h3>Basic security features<\/h3>\n      <p>Businesses get direct protection against malware and spam via Exchange Online Protection, as well as basic antivirus for files and emails.<\/p>\n\n      <h3>Advanced security features<\/h3>\n      <p>Features such as Advanced Threat Protection (ATP), Safe Links, Safe Attachments, Conditional Access and MFA are not always enabled by default, but require administrative configuration.<\/p>\n\n      <h3>Why some features are not active by default<\/h3>\n      <p>Microsoft leaves flexibility for companies to customize security according to risk level, user groups and internal policies, leaving advanced settings to be manually enabled.<\/p>\n\n      <h3>Enable and configure security<\/h3>\n      <p>Administrators use Microsoft 365 Security &#038; Compliance Center or Azure AD to enable MFA, configure ATP, Conditional Access and check Secure Score to improve security.<\/p>\n\n      <h3>Reporting and transparency<\/h3>\n      <p>Once activated, logs and reports provide visibility into user activity and security status, facilitating monitoring and compliance.<\/p>\n\n      <h3>Benefits of enabling security features<\/h3>\n      <p>Fully enabled security features reduce the risk of data breaches, phishing, ransomware and other cyber threats, while strengthening your organization&#8217;s compliance and security awareness.<\/p>\n\n      <h3>Common mistakes<\/h3>\n      <p>Relying on default settings without enabling advanced protections, or not informing users of new policies, can limit security.<\/p>\n    <\/div>\n\n    <div class=\"ai-right\">\n      <div class=\"ai-details\">\n        <h2>Main points about the default activation of security features<\/h2>\n        <ul>\n          <li><strong>Basic protection:<\/strong> Malware and spam filtering is automatically activated.<\/li>\n          <li><strong>Advanced protections:<\/strong> Advanced Threat Protection (ATP), Safe Links and Safe Attachments require activation.<\/li>\n          <li><strong>Multi-factor authentication:<\/strong> Not always enabled by default, should be enabled manually.<\/li>\n          <li><strong>Conditional Access:<\/strong> Requires configuration to manage risk levels.<\/li>\n          <li><strong>Secure Score:<\/strong> Helps administrators identify and implement additional protections.<\/li>\n          <li><strong>Reporting:<\/strong> Provides transparency and facilitates compliance once the features are activated.<\/li>\n        <\/ul>\n      <\/div>\n\n      <div class=\"ai-faq\">\n        <h2>Related questions<\/h2>\n\n        <div>\n          <h3>Are all security features enabled by default?<\/h3>\n          <p>No, basic functions are active, but advanced protections require administrative configuration.<\/p>\n        <\/div>\n\n        <div>\n          <h3>Which functions are active directly?<\/h3>\n          <p>Exchange Online Protection, basic antivirus and spam filters are examples of features that are active right away.<\/p>\n        <\/div>\n\n        <div>\n          <h3>How to activate MFA and ATP?<\/h3>\n          <p>Through the Microsoft 365 Security &#038; Compliance Center or Azure AD, where administrators can configure policies and enable protection.<\/p>\n        <\/div>\n\n        <div>\n          <h3>What is Secure Score?<\/h3>\n          <p>A score showing the company&#8217;s security status and recommended actions to improve protection.<\/p>\n        <\/div>\n\n        <div>\n          <h3>Why is it important to enable advanced features?<\/h3>\n          <p>To protect against advanced threats such as phishing, ransomware and social engineering, which are not always stopped by basic protection.<\/p>\n        <\/div>\n\n      <\/div>\n    <\/div>\n  <\/div>\n<\/div>\n\n<script type=\"application\/ld+json\">\n{\n  \"@context\": \"https:\/\/schema.org\",\n  \"@type\": \"FAQPage\",\n  \"mainEntity\": [\n    {\n      \"@type\": \"Question\",\n      \"name\": \"\u00c4r alla s\u00e4kerhetsfunktioner aktiverade som standard?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Nej, grundl\u00e4ggande funktioner \u00e4r aktiva, men avancerade skydd kr\u00e4ver administrativ konfiguration.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Vilka funktioner \u00e4r aktiva direkt?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Exchange Online Protection, grundl\u00e4ggande antivirus och spamfilter \u00e4r exempel p\u00e5 funktioner som \u00e4r aktiva direkt.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Hur aktiverar man MFA och ATP?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Genom Microsoft 365 Security & Compliance Center eller Azure AD, d\u00e4r administrat\u00f6rer kan konfigurera policyer och aktivera skyddet.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Vad \u00e4r Secure Score?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"En po\u00e4ngs\u00e4ttning som visar f\u00f6retagets s\u00e4kerhetsstatus och rekommenderade \u00e5tg\u00e4rder f\u00f6r att f\u00f6rb\u00e4ttra skyddet.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Varf\u00f6r \u00e4r det viktigt att aktivera avancerade funktioner?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"F\u00f6r att skydda mot avancerade hot som phishing, ransomware och social engineering, som inte alltid stoppas av grundskydd.\"\n      }\n    }\n  ]\n}\n<\/script>\n\n","protected":false},"excerpt":{"rendered":"<p>Are security features enabled by default in Microsoft 365? Microsoft 365 comes with several security features pre-configured, but not all advanced protections are enabled by default. Basic features like email filtering, antivirus, and simple policies are active, while advanced features like multi-factor authentication, Advanced Threat Protection (ATP), Conditional Access, and Secure Score require administrative activation [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":15862,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[178,181],"tags":[],"class_list":["post-19765","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-faq","category-microsoft-365"],"acf":[],"_links":{"self":[{"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/posts\/19765","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/comments?post=19765"}],"version-history":[{"count":0,"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/posts\/19765\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/media\/15862"}],"wp:attachment":[{"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/media?parent=19765"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/categories?post=19765"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coreit.se\/en\/wp-json\/wp\/v2\/tags?post=19765"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}