When I access a new client's Microsoft 365 tenant for the first time, I run through the same checklist every time. And almost every time, I find the same problems.
Not because these businesses haven't tried to secure their environment. Because Microsoft's out-of-the-box defaults are not secure defaults. They're designed for ease of onboarding — not for protecting a business.
Here are the five settings I find misconfigured most often, what the risk actually is, and what to do about it.
1. Legacy Authentication Is Still Enabled
What it is: Legacy authentication refers to older sign-in protocols — think basic SMTP auth, IMAP, POP3, and older Office clients. These protocols don't support modern Multi-Factor Authentication.
Why it's a problem: If legacy authentication is enabled, an attacker only needs a username and password to get in — MFA doesn't apply. Password spray attacks almost always target legacy authentication endpoints for exactly this reason.
What to do: Block legacy authentication using a Conditional Access policy. If you have users on very old versions of Outlook or mobile mail apps, they'll need to update — but the security gain is worth the short-term friction.
2. MFA Is Switched On But Not Enforced
What it is: Many tenants have MFA enabled in principle — but users can skip it, delay it, or it simply hasn't been applied to every account.
Why it's a problem: MFA that isn't enforced for every user, every time, on every device isn't really MFA. Shared mailboxes and service accounts are particularly common blind spots — they often have no MFA at all.
What to do: Move away from per-user MFA settings and implement Conditional Access policies instead. These give you proper control — you can require MFA for all users, enforce compliant devices, and block access from untrusted locations. Check your admin accounts first; they should have the strictest policies.
3. SharePoint and OneDrive External Sharing Is Wide Open
What it is: By default, SharePoint and OneDrive are often configured to allow "Anyone with a link" to access shared files — no sign-in required.
Why it's a problem: Every time a staff member shares a document link, that link could be forwarded to anyone. For businesses handling client data, financial information, or anything sensitive, this is a significant data exposure risk — and a potential GDPR issue.
What to do: Review your sharing settings in the SharePoint Admin Centre. For most professional services firms, the right setting is "Only people in your organisation" or "Existing guests" — not "Anyone." You can also set link expiry dates and restrict download permissions on sensitive libraries.
4. The Unified Audit Log Is Switched Off
What it is: The Unified Audit Log records user and admin activity across Microsoft 365 — who logged in, who accessed what, what was deleted, what was forwarded.
Why it's a problem: In many tenants, this is not switched on by default. Without it, if you experience a breach, a data leak, or a compromised account, you have no forensic trail. You can't answer the question "what did they access?" because the records simply don't exist.
What to do: Go to the Microsoft Purview compliance portal and confirm audit logging is enabled. It should be on for all users, and ideally retained for at least 90 days — longer if your sector has specific compliance requirements.
5. Microsoft Secure Score Is Being Ignored
What it is: Secure Score is Microsoft's built-in security scoring tool — it assesses your tenant configuration and gives you a score out of 100, with recommended actions to improve it.
Why it's a problem: Most businesses either don't know it exists or checked it once and forgot about it. It's a live indicator of your security posture, and it updates as your configuration changes — or as Microsoft adds new recommendations.
What to do: Find it in the Microsoft Defender portal under Secure Score. Don't treat the number as a target — treat the recommended actions as a prioritised list. Focus on the high-impact, low-effort items first. A score in the 40s is typical for an unconfigured tenant; most businesses should be targeting 70+.
The Common Thread
None of these are exotic vulnerabilities. They're configuration gaps — things that are switched off, set too permissively, or simply never reviewed after the tenant was set up.
The CIS Microsoft 365 Foundations Benchmark covers all of these and more. It's a free, peer-reviewed security standard that gives you a clear baseline for what a properly configured M365 tenant should look like.
If you're not sure where your tenant stands on any of the above, that's worth finding out sooner rather than later.
Datatechs Consulting runs M365 security audits aligned to the CIS Foundations Benchmark. You'll get a clear report showing exactly where your tenant stands, what's at risk, and what to fix — in plain English.
👉 Download our free M365 Security Quick-Check — 10 things to review in your tenant today.
Or get in touch at datatechs.co.uk to discuss a full security audit.
Marcus Harris
