Skip to content
Microsoft 365

Microsoft 365 security for schools

Published 13 August 2026 · Last reviewed 13 August 2026

For most UK schools, Microsoft 365 is the IT estate: identity, email, files, devices. That makes its security settings the highest-leverage cyber decisions a school owns — and the place where the gap between “we have Microsoft” and “we are protected” quietly lives. This page is the map; the guides beneath it go deep on each part.

Identity first — because that’s where the attacks go

Almost nobody attacks a school’s firewall any more; they sign in with a stolen or phished password. So the questions that matter most are identity questions: is multi-factor authentication enforced for everyone (the MFA guide — including what registration-but-not-enforcement looks like and how not to lock teachers out), and what rules govern sign-ins (the identity guide — Entra ID and Conditional Access, together, because separately they make no sense).

The licence reality, briefly

What your school can switch on depends on which licence family you actually hold — and the naming trips everyone: Office 365 Education plans (including the free A1) carry basic Entra ID only, while Microsoft 365 Education A3/A5 carry the premium identity and device security features. Every school gets Microsoft’s free security defaults (baseline MFA for everyone); Conditional Access needs Entra ID P1 or above; the Defender family splits across tiers in ways worth checking rather than assuming — the Defender guide untangles it against Microsoft’s own service description.

The school/provider split

In most schools an external IT provider holds the admin keys, which makes the split worth writing down: the provider configures; the school decides and evidences. Decisions like “MFA is enforced for all staff”, “legacy sign-in protocols are blocked” and “admin accounts are separate from daily accounts” are school policies executed by the provider — and the DfE’s expectation that user accounts are controlled and secured lands on the school either way. The practical move: ask your provider the questions in the complete guide, and file the answers.

Governance and evidence

  • An MFA position, dated — enforced for whom, exceptions and why, admin accounts covered.
  • The sign-in rules in force — security defaults on, or the Conditional Access policy set, in writing.
  • What your licence includes and what you actually use — paying for A5 and running none of its security is the most expensive quiet gap in education IT.
  • Who holds Global Administrator — how many, named, and protected hardest of all.
Where Ceidwad fits — precisely
With a school’s consent, Atlas reads two things from Microsoft 365: the tenant’s Secure Score (Microsoft’s own posture measure) and MFA registration coverage — how many staff have set MFA up. That makes the picture continuous and board-readable. It does not configure anything, and registration is not enforcement — a distinction the MFA guide explains, because it is exactly where schools get falsely reassured.

Want to know where your school stands?

Assess your school’s cyber readiness in about two minutes — no account, and nothing connects to your systems. You’ll get an indicative score and a plain-English list of what to fix first.

Start the free assessment

Related