Skip to content

Resource

Microsoft 365 security gaps most businesses miss.

Microsoft 365 ships with sensible defaults, for a generic customer. The security gaps show up the moment a real business uses it the way real businesses do.

Why the defaults aren't enough.

Microsoft 365 is responsible for keeping the platform running. Your business is responsible for everything above that - who has access, what they can share, how email flows, and whether the settings that were configured at setup still reflect how the business actually operates.

Most Microsoft 365 tenants were set up once by whoever was available at the time. A provider, an internal IT person, a consultant on a one-time project. The settings made sense at the time. Then the business grew. People joined and left. New features got enabled by default. Sharing permissions expanded to make collaboration easier. Nobody went back to review what accumulated.

The result is a tenant that looks functional from the outside and has real exposure underneath. Not from exotic attacks, from normal settings that were never tightened and normal processes that were never finished.

Security settings and baselines inside Microsoft 365

Where the gaps actually live.

Each of these is common. None of them require a sophisticated attacker to exploit.

MFA enabled in name only

Multi-factor authentication gets turned on and marked complete. But MFA without conditional access behind it can be bypassed. A user on an unmanaged device in an unsupported location can still authenticate if the policy doesn't account for it. MFA is the starting point, not the finish line.

Global admin accounts that accumulated

Admin accounts get created when needed and rarely get cleaned up. A tenant with ten or fifteen global admin accounts - some belonging to people who left years ago, some created for one-time projects - has a significant attack surface that most businesses don't know exists. Global admin access is the highest privilege in the environment. The number of accounts holding it should be small and reviewed regularly.

Offboarding that never finished

When someone leaves, their account gets disabled. Usually. The mailbox stays accessible for a period. The license gets reassigned. But the connected apps, the delegated permissions, the shared mailbox access, the Teams memberships. Those often don't get cleaned up. A former employee who can no longer sign in directly may still have paths into the environment through connected applications that were never reviewed.

External sharing links that never expired

A file gets shared with a client. The link gets created without an expiration date. The project ends. The link keeps working. Years later, external parties have active access to files the business has forgotten about. Most tenants have dozens of these. Some have hundreds.

Mailbox rules forwarding email out

An attacker who gains access to a mailbox through a phishing attempt, a compromised password, a session token, often creates a forwarding rule before doing anything else. The rule forwards copies of incoming email to an external address. The attacker loses access. The rule keeps running. This is one of the most common and most overlooked persistence mechanisms in business email compromise. Most businesses have never audited their mailbox rules.

Connected apps with permissions nobody reviewed

Staff connect third-party applications to Microsoft 365 for legitimate reasons - productivity tools, integrations, automation. Each connection gets granted permissions. Those permissions don't expire when the app stops being used or when the person who connected it leaves. A tenant accumulates connected applications over time, each with permissions that were granted once and never revisited.

Audit logging not configured

Microsoft 365 has audit logging capabilities that record what happens in the tenant - who accessed what, when, from where, what changed. Audit logging has to be configured and retained. In a tenant where it was never set up, there is no record to investigate when something goes wrong. Insurance carriers and regulators increasingly ask about this. Most tenants that haven't been actively managed don't have it in place.

Why these gaps exist.

Microsoft 365 is not insecure by design. The default settings provide a baseline that works for a generic customer. The problem is that a generic customer and a real business operating over time are different things.

Default settings don't account for how a specific business shares files with clients. They don't account for the offboarding processes that get skipped when someone leaves unexpectedly. They don't account for the admin accounts created during an implementation that nobody remembered to clean up. They don't account for the connected applications that accumulated as the team tried new tools.

A tenant that was set up correctly at launch and never actively managed looks different two years later than it did on day one. The settings didn't change. The business did. The gap between the two is where the exposure lives.

What good looks like.

A well-managed Microsoft 365 tenant isn't complicated. It's documented, reviewed on a schedule, and held to a written standard.

MFA enforced everywhere with conditional access policies that account for device, location, and risk level. Admin role hygiene with separation between global admin and delegated admin accounts, reviewed regularly. Offboarding that actually finishes. Connected apps, shared mailbox access, delegated permissions, and Teams memberships closed when employment ends. External sharing intentional and audited, with expiration dates on links that don't need to live forever. Mailbox rule monitoring active, with alerts when new rules get created. Connected apps inventoried and scoped. Permissions reviewed and unnecessary connections removed. Audit logging configured and retained so there's a record if something needs to be investigated.

A written configuration standard that the tenant is held to. So when something changes, there's a baseline to compare against.

None of this requires a major project. It requires someone who knows what the standard should be and checks that the environment reflects it.

How to know if your Microsoft 365 is configured correctly.

These questions don't require technical knowledge to ask. The answers will tell you what you need to know.

How many global admin accounts exist in the tenant, and when were they last reviewed? If the answer is vague or the number is high, the admin surface hasn't been maintained.

Is audit logging configured and being retained? If the answer is no or uncertain, there's no record of what's happened in the environment.

When someone leaves, what specifically gets cleaned up. And is there documentation of what that process covers? If the answer is "we disable the account," the offboarding is incomplete.

Has anyone reviewed external sharing links in the last six months? If not, there are almost certainly active links pointing to files the business has forgotten about.

Is there a mailbox rule monitoring policy in place? If not, forwarding rules could be running without anyone knowing.

What changes when Microsoft 365 is managed to a standard.

The tenant reflects how the business actually operates, not how it operated when someone set it up two years ago. Admin access is documented and limited to the people who need it. Offboarding closes all the access, not just the primary account. External sharing is intentional. Mailbox rules get monitored. Audit logging exists when it's needed.

When a client sends a security questionnaire asking about Microsoft 365 configuration, the answers are in documentation, not memory. When a carrier asks about MFA and conditional access on the renewal, the controls exist and can be shown.

If none of this is in place, the gaps accumulate without announcing themselves. A former employee's connected application keeps running. A mailbox forwarding rule created during a compromise keeps sending copies of email to an address nobody is watching. An external sharing link from three years ago keeps working. The exposure grows until something forces the question. And by then the cost of finding out has already started.

If you're not sure how your Microsoft 365 tenant is configured or when it was last reviewed, that's exactly what an IT Environment Review is for.

Schedule an IT Environment Review

Common questions

Questions leadership usually asks first.

Next step

Get a clearer view of your IT environment.

Find out what is working, where the risks are, and what needs attention next.