Employee signing in to a laptop with a phone nearby for multi-factor authentication

Cloud SolutionsCybersecurityMicrosoft 365

Cloud Security Best Practices: How to Protect Your Organization

Most cloud breaches at small organizations start on the customer’s side: a phished password, a folder shared with anyone who has the link, an app someone clicked “Accept” on. The big providers spend more on security than any office could, but they secure their platform and leave your accounts, settings, devices and data to you. Cloud security best practices are about that half.

If your email lives in Microsoft 365 or Google Workspace, your files sit in OneDrive or SharePoint, and your accounting, practice management or donor system is a web app, you already run in the cloud. This brief covers what attacks look like, the warning signs, and the steps that stop most of them.

Key takeaways

  • You are always responsible for your data, accounts, devices and access controls, whichever cloud service you use.
  • Stolen credentials and unpatched vulnerabilities are the leading ways in, so MFA, blocking legacy sign-ins and patching come first.
  • Oversharing and over-permissioned apps expose data with no hacker involved.
  • Cloud sync is not backup.
  • Any cloud provider storing protected health information needs a signed business associate agreement.

Who secures what

Microsoft calls this the shared responsibility model. The provider handles the data centers, the network and the core service. Whatever type of cloud service you use, Microsoft says you always keep responsibility for:

  • Your data, including how it is classified, protected and retained.
  • Your endpoints, meaning the laptops, desktops and phones that sign in.
  • Your accounts, including creating and removing users.
  • Access management, such as MFA and conditional access rules.

Old blog posts, including some of ours, used to say the provider takes on most of the security burden. That was never accurate. If an employee’s password is phished or a folder is shared publicly, the provider did nothing wrong, and the data is still exposed.

How cloud accounts get broken into

At client offices we have seen business email compromise, password spraying, MFA push bombing, QR code phishing, malicious search ads and bad browser extensions. They fall into four groups.

Close-up of a person typing on a laptop at a desk

Stolen credentials

A phished or guessed password gives an attacker the same access as the employee, from anywhere. In Verizon’s 2025 Data Breach Investigations Report, credential abuse was the top way attackers got in, at 22% of breaches. Our post on password spraying shows one common method.

Unpatched vulnerabilities

In the 2026 report, exploited vulnerabilities moved into first place. Patching the apps and devices that connect to your cloud matters as much as the cloud settings.

31%

Share of breaches in Verizon’s 2026 Data Breach Investigations Report that began with an exploited vulnerability, now the top way in

Oversharing and risky apps

Files shared with “anyone with the link,” guest accounts nobody removed, and admin rights handed out freely become breaches with no hacker involved. Many apps ask users to grant access to their mailbox or files, and malicious browser extensions often arrive through fake update prompts. Once granted, that access keeps working after a password reset. See our post on the dangers of browser extensions.

Vendors

In the same 2026 report, 48% of breaches involved a third party, up from 30% a year earlier. Every cloud vendor holding your data is part of your attack surface.

Warning signs worth an alert

  • Sign-ins from a country or city where nobody on staff is.
  • A new inbox rule that forwards, moves or deletes mail.
  • Large numbers of files downloaded or shared in a short time.
  • MFA prompts nobody requested.
  • A new app granted access to mailboxes or files.

Our email sign-in monitoring watches a mix of signals like these, and it has caught real takeover attempts at client offices. When it flags one, we contain the account within the hour.

Cloud security best practices, in order of impact

  1. Require MFA for everyone and block legacy sign-in methods. Microsoft says MFA together with blocking legacy authentication stops more than 99.9% of common identity attacks. Security defaults in Microsoft Entra ID turn on both at no extra cost, and Microsoft 365 Business Premium includes Microsoft Entra ID P1, which adds Conditional Access for finer control.
  2. Limit admin accounts. Give admin rights to as few people as possible, use separate admin accounts, and never use one for daily email.
  3. Control app consent. Microsoft recommends letting users approve only apps from verified publishers with low-risk permissions. Everything else goes through IT.
  4. Review sharing. Restrict “anyone” links, set expiration dates on external shares, and remove stale guest accounts.
  5. Secure the devices that sign in: patched, encrypted and protected with endpoint detection and response.
  6. Turn on audit logging, and make sure someone watches for the warning signs above.
  7. Back up your cloud data separately. Sync and the recycle bin won’t save you from deletion or ransomware. More in our backup best practices.

Two of these are the ones we most often find missing in the Microsoft 365 tenants we review: there is no conditional access, and auditing is turned off, so when something does go wrong there is no record of it. For a detailed benchmark, CISA’s Secure Cloud Business Applications (SCuBA) project publishes secure configuration baselines for Microsoft 365 and Google Workspace. They were written for federal agencies, but they work as a checklist for anyone. Our post on preventing cloud misconfiguration walks through them.

Vetting providers and meeting your obligations

Before sensitive data goes into any cloud app, confirm it supports MFA and single sign-on, where data is stored and whether it is encrypted, how you export it if you leave, whether the provider publishes an independent audit such as a SOC 2 report, and whether it will sign the agreements your industry requires. Our guide to choosing a cloud services provider covers the rest.

HHS is direct: a covered entity or business associate that uses a cloud service to store or process electronic protected health information without a business associate agreement is violating HIPAA, and a provider holding only encrypted data, without the key, is still a business associate. Firms under the FTC Safeguards Rule must oversee the service providers that handle customer information, and law firms have confidentiality duties that follow client files. Keep a list of your cloud vendors, the data each holds and the agreements in place. Our compliance services help build and maintain it.

Every client of ours has a 24/7 security operations center watching their environment, and as a Microsoft CSP partner we license and manage their Microsoft 365 tenants. If you want to know which of the steps above your own tenant is missing, book a 20-minute call. More on our cloud services and cybersecurity services.

FAQ

Frequently asked questions

Do I need a VPN if everything is in the cloud?

Not for most cloud apps, which are already encrypted in transit. Strong identity controls, device security and secure remote access for anything still on-site matter more.

Does Microsoft back up my Microsoft 365 data?

Microsoft keeps the service available and has recycle bins for short-term recovery, but protecting your data is your responsibility. A separate backup covers deletion, ransomware and long-term recovery.

Sources: Microsoft Learn, Shared responsibility in the cloud; Microsoft Learn, Security defaults in Microsoft Entra ID; Microsoft Learn, Configure how users consent to applications; Verizon, 2025 Data Breach Investigations Report news release; Verizon, 2026 Data Breach Investigations Report news release; CISA, Secure Cloud Business Applications (SCuBA) project; HHS, Guidance on HIPAA and cloud computing; Microsoft Learn, Microsoft Entra licensing.

Talk to an advisor

Questions about your own environment?

Our team can walk through how this applies to your organization, with honest recommendations and no pressure.