Office 365 Security Yorkshire Dales? 4 Quick Checks for Your Business
If you run a business in the Dales — a hotel in Grassington, a veterinary practice in Leyburn, a farm-diversification operation in Wensleydale, a professional services firm in Skipton — your Office 365 security profile isn’t the same as the Leeds textbook. Two things about the Dales specifically shape what you should actually check:
First, mobile coverage. Anyone whose staff work from a farm above Hawes, a converted barn near Kirkby Malham, or a walking-tour base in Ingleton knows SMS-based MFA can silently fail when the signal drops. That’s not a theoretical risk — it’s the reason a lot of Dales firms disable MFA “temporarily” and never turn it back on. Second, seasonal staffing. Tourism operators in Grassington, Aysgarth, Hawes and Malham double or triple headcount for the summer, then shrink back. Licence sprawl and forgotten sign-ins are the natural result if there’s no cleanup rhythm.
Both factors mean the standard “just enable MFA and call it done” advice needs adjusting for Dales-specific reality. Here are the four checks that actually matter locally.
Check 1 — MFA that survives poor mobile signal
The classic MFA setup pushes a code by SMS. If your staff are working from Wensleydale farms, Wharfedale visitor centres, or driving between sites in the Dales, SMS delivery is unreliable and often people just stop bothering. The fix isn’t dropping MFA — it’s picking an MFA method that works offline.
Move everyone to the Microsoft Authenticator app with TOTP (time-based codes) rather than SMS. TOTP works with no signal at all — it just needs the phone to have the app open. For staff who genuinely can’t use a phone (older team members, kitchen staff, farm workers with limited handset access), FIDO2 security keys plug into the USB port and work with no signal or app at all.
What to verify: no user in your tenant is set to “SMS only” as an MFA option. Legacy authentication (ActiveSync, POP, IMAP) should be blocked outright — those bypass MFA entirely and are the biggest single Office 365 attack vector against small rural businesses.
Check 2 — Admin accounts that don’t grow in shoulder-season
Small businesses in the Dales typically have one or two people who “sort of know IT” and they end up with admin permissions for everyone else’s convenience. That’s normal, but it needs discipline. When a tourism business scales up for July and August, the temptation is to give the seasonal manager global admin so they can add users quickly. That admin permission then never gets removed in October when they leave.
Practically: named admin accounts only (not shared), separated from day-to-day sign-ins, with a clean list of who holds admin rights that you review each Autumn as the season ends. If your last review was “when the current provider set us up,” you’re probably overdue.
Ask any external supplier for the current list of global admins, tenant admin, and Exchange admin on your tenant. If they hesitate or need a week, that answers a different question about the supplier.
Check 3 — Backups that survive both ransomware AND the seasonal cleanup
Office 365 keeps deleted items for a period, but it’s not a backup. Two Dales-specific failure modes make third-party backup genuinely worth the ~£3-4/user/month:
Ransomware attackers know rural businesses often have thinner IT support and slower response times. If your practice manager isn’t in until Tuesday, an attack Friday evening has a full weekend to run before anyone notices. A backup that lives outside your tenant is what lets you restore rather than pay.
Seasonal cleanup: when a manager delete a seasonal staff member’s OneDrive in October to reclaim the licence, they’ve also just deleted whatever files that person was owning. Sometimes those files matter (bookings, guest lists, supplier contacts). Third-party backup means those come back.
Ask any provider: how fast can you restore a mailbox to a point three months ago? If the answer isn’t “in hours, and we’ve done it before,” don’t count on it.
Check 4 — Email authentication so you don’t get spoofed to your suppliers
Dales businesses trade with a lot of small suppliers — feed merchants, laundry services, boiler engineers, food wholesalers, local trades. That web of small-B2B email is exactly what an attacker impersonates when they want to redirect a payment. If your domain doesn’t have SPF, DKIM and DMARC records published correctly, a spoofed email from “you” to a supplier can be indistinguishable from the real thing.
These records live in DNS — usually with your domain registrar or Cloudflare. They’re set once (with occasional maintenance) and they cost nothing beyond the setup time. If you don’t know whether yours are in place, run a free check at MXToolbox and see what shows up. If DMARC is “not found,” fixing that is the single highest-leverage thing you can do this month.
What to do next
Don’t try to do all four at once. Start with MFA — move everyone off SMS to Authenticator or FIDO2 within two weeks. Then run the DMARC check. Then decide about backup based on how much data you’d actually miss. Admin cleanup can wait until after the summer if you’re mid-season.
If you’d rather have someone else check your tenant against these four points and give you a plain-English one-pager, that’s an hour of an experienced Yorkshire-based IT provider’s time. Better than another year of assuming the defaults are enough.







