Key insights
- You do not need to manage Microsoft 365 yourself to ask useful security questions.
- Email filtering tells you what was blocked. Only simulation tells you whether staff would click.
- Annual tick-box training does not change behaviour. Short, frequent and role-relevant does.
- Microsoft 365 retention is not a backup. Real recovery needs a copy that sits outside Microsoft.
- Admin access grows quietly over time and is rarely reviewed.
- The basics such as MFA and leaver processes matter, but they are usually the part schools have already covered.
- Security is people, process and technology working together, not just settings in an admin portal.
If you are a Bursar, School Business Manager or Operations Lead, you may not manage every Microsoft 365 setting yourself. But you may still be accountable for whether the school's systems are secure, backed up and properly controlled.
That can feel uncomfortable. Cyber security is full of technical language, and Microsoft 365 can be a maze of settings, licences and admin screens. But you do not need to be an IT expert to ask the right questions.
This guide gives you five practical checks to discuss with your IT lead or provider. It deliberately spends the least time on the things most schools have already done, such as multi-factor authentication, and the most time on the three areas where gaps are still common: phishing simulation, staff training and independent backup.
Because the work that protects pupils' wellbeing deserves infrastructure that simply works.
1. Find out whether your staff would actually click
Most schools have email filtering, and most assume it is doing the job. Filtering is necessary, but it only tells you what was blocked. It tells you nothing about what happens when a convincing email gets through, which some always will.
Phishing simulation answers the question filtering cannot. It sends safe, realistic test emails to staff and shows you who clicked, who entered their credentials and who reported it. No blame and no consequences, just an honest picture of where the school actually stands today.
Schools are attractive targets for email fraud because they handle payments, personal data and urgent parent communications. Attackers impersonate senior leaders, parents, suppliers, governors and official bodies. A convincing email landing at the wrong moment can cause real disruption, especially when staff are busy, under pressure or simply trying to be helpful.
Questions to ask your IT lead or provider:
- Have we ever tested staff with a simulated phishing email?
- If we have, what proportion clicked, and what happened next?
- Are senior leaders and finance staff included, given they are the most impersonated?
- Are suspicious emails reported in a consistent way, and does anyone act on those reports?
- Do we know whether reporting rates are improving over time?
If the honest answer is that the school has never tested, that is worth knowing in itself. Phishing is the main threat behind the great majority of school breaches, yet most schools have no idea how their own staff would respond to one. That number is usually the most revealing one available.
2. Look at how staff security training actually works
Security is people, not just technology. Almost every serious incident involves someone doing something entirely reasonable at the wrong moment.
Most schools do some form of training, so the gap is rarely whether it exists. The gap is whether it changes anything. An annual module completed in September is largely forgotten by October, and it seldom reflects the threats staff actually meet in their inbox.
Training that works tends to be short, frequent and relevant to the role. A finance officer needs to recognise invoice fraud. A Head's PA needs to recognise impersonation. Everyone needs to know how to report a concern without feeling foolish.
Questions to ask:
- What security training do staff currently receive, and how often?
- Is it a single annual module, or something little and often?
- Is it tailored to roles, particularly finance and senior leadership?
- Can we see completion rates, and does anyone follow up on the gaps?
- Do new starters get trained before they have access to sensitive systems?
The aim is to make safe behaviour easy: clear reporting, calm guidance and no blame when someone raises a concern.
3. Check whether your backup sits outside Microsoft
This is the gap that tends to matter most, and the most expensive one to discover late.
Microsoft 365 includes useful retention and recovery features. Retention is mainly about keeping or deleting information according to rules. It is not the same as a backup, and it is not designed to get a school back on its feet after a serious incident.
Backup is about recovering clean, usable data when something goes wrong: accidental deletion, a compromised account, ransomware, a sync error or a major outage. The detail that matters most is where that copy lives. If your only copy sits inside the same Microsoft environment, then whoever compromises an admin account can potentially reach the backup too.
An independent backup sits outside that environment. It gives the school a separate line of defence and a route back even when the Microsoft tenant itself is the problem.
Questions to ask:
- What Microsoft 365 data is actually backed up, including email, OneDrive, SharePoint and Teams?
- Where does that backup live, and is it genuinely separate from our Microsoft environment?
- Could someone with a compromised admin account delete or encrypt the backup?
- How quickly could we restore, and has a restore actually been tested rather than assumed?
- Who owns recovery if something goes wrong on a Saturday?
The practical question for a school is not "Do we have Microsoft 365?" It is "If important data was deleted, encrypted or compromised, how quickly could we get it back, and are we certain the copy itself is safe?"
This is where the Recover part of Prevent · Respond · Recover matters. No school should rely on prevention alone.
4. Know who has admin access
Admin accounts are the keys to the Microsoft 365 environment. They can change settings, create users, access sensitive areas and, in some cases, override controls.
In many organisations, admin access grows gradually. Someone needs temporary access for a project. A shared login is created for convenience. A former supplier still has rights. Over time, the school can end up with more people holding powerful permissions than anyone realises.
That creates risk. If an admin account is compromised, the impact is far greater than an ordinary user account, because it is also the route by which security settings and backups can be reached.
Questions to ask:
- Who currently has Microsoft 365 admin access?
- Does each person still need that level of access?
- Are there any shared or generic admin logins?
- Are admin accounts protected with MFA?
- Is there a regular review of admin permissions?
This is not about blame. It is about good housekeeping. The safest approach is usually least privilege: people should have the access they need to do their job, but no more than that.
5. Confirm the basics are genuinely complete
Most schools have already done the groundwork here, so this section is deliberately short. The value is in checking the basics are complete rather than mostly complete, because partial coverage is common and easy to miss.
Multi-factor authentication. MFA means a password is not enough on its own. Most schools have it switched on for staff, but coverage often has quiet gaps: a service account, a shared mailbox, an exception granted years ago and never revisited. The useful question is not whether MFA is on, but whether anything is still outside it, admin accounts above all.
Leaver access. Schools have constant staff movement: term changes, temporary staff, contractors, governors, supply teachers and seasonal admin support. Access should be removed on the final working day rather than when someone remembers, and the checklist should cover email forwarding, shared mailboxes, file ownership, devices and remote access.
Questions to ask:
- Are there any accounts, including service and shared accounts, that MFA does not cover?
- Are staff using an authenticator app rather than relying only on text messages?
- Who tells IT when someone leaves, and is there a record that the process was completed?
If these are already solid, that is good news. It means the school's attention is better spent on the three areas above.
A quick self-check
Use this as a quick conversation starter with your IT lead or provider:
- We have tested staff with a simulated phishing email at least once.
- We know what proportion clicked, and whether that is improving.
- Security training is little and often, not one annual module.
- Training is tailored for finance and senior leadership.
- We have a backup of Microsoft 365 data that sits outside Microsoft.
- A compromised admin account could not delete or encrypt that backup.
- We have tested a restore rather than assuming one would work.
- We know exactly who has Microsoft 365 admin access, and it is reviewed.
- MFA covers every account, including admin, service and shared accounts.
- Leaver access is removed on the final working day, with a record kept.
If you cannot confidently tick every box, that does not mean something is wrong. It simply shows where to ask the next question.
Book a Free Security Health Check
Microsoft 365 security does not need to feel overwhelming. The strongest schools are not always the ones with the most complicated tools. They are the ones with clear ownership, sensible controls and people who know what to do when something looks unusual.
ARC works with essential services organisations, including schools and colleges, to reduce cyber risk with proactive support and plain-English guidance. We work alongside your team or existing provider, not around them, so everyone is clear on what is happening, what matters and what comes next. ARC is a Microsoft Authorised Education Partner, a G-Cloud supplier and Cyber Essentials certified.
If you would like a professional second opinion, ARC's Free Security Health Check gives you a plain-English view of where your Microsoft 365 setup is strong, where there may be gaps, and what to prioritise next.