<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>blog</title>
    <link>https://www.datatechs.co.uk/blog</link>
    <description>Practical insights on Microsoft 365 security, CIS Benchmark compliance, and endpoint management from Datatechs' specialist engineers.</description>
    <language>en-us</language>
    <pubDate>Tue, 21 Jul 2026 07:01:36 GMT</pubDate>
    <dc:date>2026-07-21T07:01:36Z</dc:date>
    <dc:language>en-us</dc:language>
    <item>
      <title>New 1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd (Clone)</title>
      <link>https://www.datatechs.co.uk/blog/new-1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd-clone-1</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.datatechs.co.uk/blog/new-1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd-clone-1" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.datatechs.co.uk/hubfs/hero-home.png" alt="New 1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd (Clone)" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=148777188&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.datatechs.co.uk%2Fblog%2Fnew-1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd-clone-1&amp;amp;bu=https%253A%252F%252Fwww.datatechs.co.uk%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Tag1</category>
      <pubDate>Mon, 20 Jul 2026 21:03:48 GMT</pubDate>
      <author>marcus.harris@datatechs.co.uk (Marcus Harris)</author>
      <guid>https://www.datatechs.co.uk/blog/new-1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd-clone-1</guid>
      <dc:date>2026-07-20T21:03:48Z</dc:date>
    </item>
    <item>
      <title>New 1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd (Clone) (Clone)</title>
      <link>https://www.datatechs.co.uk/blog/new-1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd-clone-clone</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.datatechs.co.uk/blog/new-1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd-clone-clone" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.datatechs.co.uk/hubfs/hero-home.png" alt="New 1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd (Clone) (Clone)" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=148777188&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.datatechs.co.uk%2Fblog%2Fnew-1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd-clone-clone&amp;amp;bu=https%253A%252F%252Fwww.datatechs.co.uk%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Mon, 20 Jul 2026 21:03:24 GMT</pubDate>
      <author>marcus.harris@datatechs.co.uk (Marcus Harris)</author>
      <guid>https://www.datatechs.co.uk/blog/new-1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd-clone-clone</guid>
      <dc:date>2026-07-20T21:03:24Z</dc:date>
    </item>
    <item>
      <title>New 1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd (Clone)</title>
      <link>https://www.datatechs.co.uk/blog/new-1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd-clone</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.datatechs.co.uk/blog/new-1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd-clone" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.datatechs.co.uk/hubfs/hero-home.png" alt="New 1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd (Clone)" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=148777188&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.datatechs.co.uk%2Fblog%2Fnew-1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd-clone&amp;amp;bu=https%253A%252F%252Fwww.datatechs.co.uk%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Mon, 20 Jul 2026 21:02:55 GMT</pubDate>
      <author>marcus.harris@datatechs.co.uk (Marcus Harris)</author>
      <guid>https://www.datatechs.co.uk/blog/new-1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd-clone</guid>
      <dc:date>2026-07-20T21:02:55Z</dc:date>
    </item>
    <item>
      <title>5 Microsoft 365 Settings Most Businesses Have Wrong by Default (Clone) (Clone)</title>
      <link>https://www.datatechs.co.uk/blog/5-microsoft-365-settings-most-businesses-have-wrong-by-default-clone-clone</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.datatechs.co.uk/blog/5-microsoft-365-settings-most-businesses-have-wrong-by-default-clone-clone" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.datatechs.co.uk/hubfs/AI-Generated%20Media/Images/Microsoft%20365%20Admin%20Portal%20Interface.png" alt="5 Microsoft 365 Settings Most Businesses Have Wrong by Default (Clone) (Clone)" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;When I access a new client's Microsoft 365 tenant for the first time, I run through the same checklist every time. And almost every time, I find the same problems.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When I access a new client's Microsoft 365 tenant for the first time, I run through the same checklist every time. And almost every time, I find the same problems.&lt;/p&gt; 
&lt;p&gt;Not because these businesses haven't tried to secure their environment. Because Microsoft's out-of-the-box defaults are not secure defaults. They're designed for ease of onboarding — not for protecting a business.&lt;/p&gt; 
&lt;p&gt;Here are the five settings I find misconfigured most often, what the risk actually is, and what to do about it.&lt;/p&gt;  
&lt;h2&gt;1. Legacy Authentication Is Still Enabled&lt;/h2&gt; 
&lt;p&gt;&lt;strong&gt;What it is:&lt;/strong&gt; Legacy authentication refers to older sign-in protocols — think basic SMTP auth, IMAP, POP3, and older Office clients. These protocols don't support modern Multi-Factor Authentication.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Why it's a problem:&lt;/strong&gt; If legacy authentication is enabled, an attacker only needs a username and password to get in — MFA doesn't apply. Password spray attacks almost always target legacy authentication endpoints for exactly this reason.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;What to do:&lt;/strong&gt; Block legacy authentication using a Conditional Access policy. If you have users on very old versions of Outlook or mobile mail apps, they'll need to update — but the security gain is worth the short-term friction.&lt;/p&gt;  
&lt;h2&gt;2. MFA Is Switched On But Not Enforced&lt;/h2&gt; 
&lt;p&gt;&lt;strong&gt;What it is:&lt;/strong&gt; Many tenants have MFA enabled in principle — but users can skip it, delay it, or it simply hasn't been applied to every account.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Why it's a problem:&lt;/strong&gt; MFA that isn't enforced for every user, every time, on every device isn't really MFA. Shared mailboxes and service accounts are particularly common blind spots — they often have no MFA at all.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;What to do:&lt;/strong&gt; Move away from per-user MFA settings and implement Conditional Access policies instead. These give you proper control — you can require MFA for all users, enforce compliant devices, and block access from untrusted locations. Check your admin accounts first; they should have the strictest policies.&lt;/p&gt;  
&lt;h2&gt;3. SharePoint and OneDrive External Sharing Is Wide Open&lt;/h2&gt; 
&lt;p&gt;&lt;strong&gt;What it is:&lt;/strong&gt; By default, SharePoint and OneDrive are often configured to allow "Anyone with a link" to access shared files — no sign-in required.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Why it's a problem:&lt;/strong&gt; Every time a staff member shares a document link, that link could be forwarded to anyone. For businesses handling client data, financial information, or anything sensitive, this is a significant data exposure risk — and a potential GDPR issue.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;What to do:&lt;/strong&gt; Review your sharing settings in the SharePoint Admin Centre. For most professional services firms, the right setting is "Only people in your organisation" or "Existing guests" — not "Anyone." You can also set link expiry dates and restrict download permissions on sensitive libraries.&lt;/p&gt;  
&lt;h2&gt;4. The Unified Audit Log Is Switched Off&lt;/h2&gt; 
&lt;p&gt;&lt;strong&gt;What it is:&lt;/strong&gt; The Unified Audit Log records user and admin activity across Microsoft 365 — who logged in, who accessed what, what was deleted, what was forwarded.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Why it's a problem:&lt;/strong&gt; In many tenants, this is not switched on by default. Without it, if you experience a breach, a data leak, or a compromised account, you have no forensic trail. You can't answer the question "what did they access?" because the records simply don't exist.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;What to do:&lt;/strong&gt; Go to the Microsoft Purview compliance portal and confirm audit logging is enabled. It should be on for all users, and ideally retained for at least 90 days — longer if your sector has specific compliance requirements.&lt;/p&gt;  
&lt;h2&gt;5. Microsoft Secure Score Is Being Ignored&lt;/h2&gt; 
&lt;p&gt;&lt;strong&gt;What it is:&lt;/strong&gt; Secure Score is Microsoft's built-in security scoring tool — it assesses your tenant configuration and gives you a score out of 100, with recommended actions to improve it.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Why it's a problem:&lt;/strong&gt; Most businesses either don't know it exists or checked it once and forgot about it. It's a live indicator of your security posture, and it updates as your configuration changes — or as Microsoft adds new recommendations.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;What to do:&lt;/strong&gt; Find it in the Microsoft Defender portal under Secure Score. Don't treat the number as a target — treat the recommended actions as a prioritised list. Focus on the high-impact, low-effort items first. A score in the 40s is typical for an unconfigured tenant; most businesses should be targeting 70+.&lt;/p&gt;  
&lt;h2&gt;The Common Thread&lt;/h2&gt; 
&lt;p&gt;None of these are exotic vulnerabilities. They're configuration gaps — things that are switched off, set too permissively, or simply never reviewed after the tenant was set up.&lt;/p&gt; 
&lt;p&gt;The CIS Microsoft 365 Foundations Benchmark covers all of these and more. It's a free, peer-reviewed security standard that gives you a clear baseline for what a properly configured M365 tenant should look like.&lt;/p&gt; 
&lt;p&gt;If you're not sure where your tenant stands on any of the above, that's worth finding out sooner rather than later.&lt;/p&gt;  
&lt;p&gt;&lt;strong&gt;Datatechs Consulting runs M365 security audits aligned to the CIS Foundations Benchmark.&lt;/strong&gt; You'll get a clear report showing exactly where your tenant stands, what's at risk, and what to fix — in plain English.&lt;/p&gt; 
&lt;p&gt;&#x1f449; &lt;a href="https://datatechs.co.uk"&gt;Download our free M365 Security Quick-Check&lt;/a&gt; — 10 things to review in your tenant today.&lt;/p&gt; 
&lt;p&gt;Or get in touch at &lt;strong&gt;datatechs.co.uk&lt;/strong&gt; to discuss a full security audit.&lt;/p&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=148777188&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.datatechs.co.uk%2Fblog%2F5-microsoft-365-settings-most-businesses-have-wrong-by-default-clone-clone&amp;amp;bu=https%253A%252F%252Fwww.datatechs.co.uk%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Mon, 20 Jul 2026 21:02:35 GMT</pubDate>
      <author>marcus.harris@datatechs.co.uk (Marcus Harris)</author>
      <guid>https://www.datatechs.co.uk/blog/5-microsoft-365-settings-most-businesses-have-wrong-by-default-clone-clone</guid>
      <dc:date>2026-07-20T21:02:35Z</dc:date>
    </item>
    <item>
      <title>New 1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd</title>
      <link>https://www.datatechs.co.uk/blog/new-1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.datatechs.co.uk/blog/new-1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.datatechs.co.uk/hubfs/hero-home.png" alt="New 1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=148777188&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.datatechs.co.uk%2Fblog%2Fnew-1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd&amp;amp;bu=https%253A%252F%252Fwww.datatechs.co.uk%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Mon, 20 Jul 2026 21:00:40 GMT</pubDate>
      <author>marcus.harris@datatechs.co.uk (Marcus Harris)</author>
      <guid>https://www.datatechs.co.uk/blog/new-1cccccdegnckketluehtkjjdueircjcnrdkghbivuhvvd</guid>
      <dc:date>2026-07-20T21:00:40Z</dc:date>
    </item>
    <item>
      <title>5 Microsoft 365 Settings Most Businesses Have Wrong by Default (Clone)</title>
      <link>https://www.datatechs.co.uk/blog/5-microsoft-365-settings-most-businesses-have-wrong-by-default-clone</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.datatechs.co.uk/blog/5-microsoft-365-settings-most-businesses-have-wrong-by-default-clone" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.datatechs.co.uk/hubfs/hero-msp-partners.png" alt="5 Microsoft 365 Settings Most Businesses Have Wrong by Default (Clone)" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;When I access a new client's Microsoft 365 tenant for the first time, I run through the same checklist every time. And almost every time, I find the same problems.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When I access a new client's Microsoft 365 tenant for the first time, I run through the same checklist every time. And almost every time, I find the same problems.&lt;/p&gt; 
&lt;p&gt;Not because these businesses haven't tried to secure their environment. Because Microsoft's out-of-the-box defaults are not secure defaults. They're designed for ease of onboarding — not for protecting a business.&lt;/p&gt; 
&lt;p&gt;Here are the five settings I find misconfigured most often, what the risk actually is, and what to do about it.&lt;/p&gt;  
&lt;h2&gt;1. Legacy Authentication Is Still Enabled&lt;/h2&gt; 
&lt;p&gt;&lt;strong&gt;What it is:&lt;/strong&gt; Legacy authentication refers to older sign-in protocols — think basic SMTP auth, IMAP, POP3, and older Office clients. These protocols don't support modern Multi-Factor Authentication.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Why it's a problem:&lt;/strong&gt; If legacy authentication is enabled, an attacker only needs a username and password to get in — MFA doesn't apply. Password spray attacks almost always target legacy authentication endpoints for exactly this reason.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;What to do:&lt;/strong&gt; Block legacy authentication using a Conditional Access policy. If you have users on very old versions of Outlook or mobile mail apps, they'll need to update — but the security gain is worth the short-term friction.&lt;/p&gt;  
&lt;h2&gt;2. MFA Is Switched On But Not Enforced&lt;/h2&gt; 
&lt;p&gt;&lt;strong&gt;What it is:&lt;/strong&gt; Many tenants have MFA enabled in principle — but users can skip it, delay it, or it simply hasn't been applied to every account.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Why it's a problem:&lt;/strong&gt; MFA that isn't enforced for every user, every time, on every device isn't really MFA. Shared mailboxes and service accounts are particularly common blind spots — they often have no MFA at all.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;What to do:&lt;/strong&gt; Move away from per-user MFA settings and implement Conditional Access policies instead. These give you proper control — you can require MFA for all users, enforce compliant devices, and block access from untrusted locations. Check your admin accounts first; they should have the strictest policies.&lt;/p&gt;  
&lt;h2&gt;3. SharePoint and OneDrive External Sharing Is Wide Open&lt;/h2&gt; 
&lt;p&gt;&lt;strong&gt;What it is:&lt;/strong&gt; By default, SharePoint and OneDrive are often configured to allow "Anyone with a link" to access shared files — no sign-in required.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Why it's a problem:&lt;/strong&gt; Every time a staff member shares a document link, that link could be forwarded to anyone. For businesses handling client data, financial information, or anything sensitive, this is a significant data exposure risk — and a potential GDPR issue.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;What to do:&lt;/strong&gt; Review your sharing settings in the SharePoint Admin Centre. For most professional services firms, the right setting is "Only people in your organisation" or "Existing guests" — not "Anyone." You can also set link expiry dates and restrict download permissions on sensitive libraries.&lt;/p&gt;  
&lt;h2&gt;4. The Unified Audit Log Is Switched Off&lt;/h2&gt; 
&lt;p&gt;&lt;strong&gt;What it is:&lt;/strong&gt; The Unified Audit Log records user and admin activity across Microsoft 365 — who logged in, who accessed what, what was deleted, what was forwarded.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Why it's a problem:&lt;/strong&gt; In many tenants, this is not switched on by default. Without it, if you experience a breach, a data leak, or a compromised account, you have no forensic trail. You can't answer the question "what did they access?" because the records simply don't exist.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;What to do:&lt;/strong&gt; Go to the Microsoft Purview compliance portal and confirm audit logging is enabled. It should be on for all users, and ideally retained for at least 90 days — longer if your sector has specific compliance requirements.&lt;/p&gt;  
&lt;h2&gt;5. Microsoft Secure Score Is Being Ignored&lt;/h2&gt; 
&lt;p&gt;&lt;strong&gt;What it is:&lt;/strong&gt; Secure Score is Microsoft's built-in security scoring tool — it assesses your tenant configuration and gives you a score out of 100, with recommended actions to improve it.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Why it's a problem:&lt;/strong&gt; Most businesses either don't know it exists or checked it once and forgot about it. It's a live indicator of your security posture, and it updates as your configuration changes — or as Microsoft adds new recommendations.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;What to do:&lt;/strong&gt; Find it in the Microsoft Defender portal under Secure Score. Don't treat the number as a target — treat the recommended actions as a prioritised list. Focus on the high-impact, low-effort items first. A score in the 40s is typical for an unconfigured tenant; most businesses should be targeting 70+.&lt;/p&gt;  
&lt;h2&gt;The Common Thread&lt;/h2&gt; 
&lt;p&gt;None of these are exotic vulnerabilities. They're configuration gaps — things that are switched off, set too permissively, or simply never reviewed after the tenant was set up.&lt;/p&gt; 
&lt;p&gt;The CIS Microsoft 365 Foundations Benchmark covers all of these and more. It's a free, peer-reviewed security standard that gives you a clear baseline for what a properly configured M365 tenant should look like.&lt;/p&gt; 
&lt;p&gt;If you're not sure where your tenant stands on any of the above, that's worth finding out sooner rather than later.&lt;/p&gt;  
&lt;p&gt;&lt;strong&gt;Datatechs Consulting runs M365 security audits aligned to the CIS Foundations Benchmark.&lt;/strong&gt; You'll get a clear report showing exactly where your tenant stands, what's at risk, and what to fix — in plain English.&lt;/p&gt; 
&lt;p&gt;&#x1f449; &lt;a href="https://datatechs.co.uk"&gt;Download our free M365 Security Quick-Check&lt;/a&gt; — 10 things to review in your tenant today.&lt;/p&gt; 
&lt;p&gt;Or get in touch at &lt;strong&gt;datatechs.co.uk&lt;/strong&gt; to discuss a full security audit.&lt;/p&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=148777188&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.datatechs.co.uk%2Fblog%2F5-microsoft-365-settings-most-businesses-have-wrong-by-default-clone&amp;amp;bu=https%253A%252F%252Fwww.datatechs.co.uk%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Tag1</category>
      <category>Tag2</category>
      <pubDate>Mon, 20 Jul 2026 20:58:35 GMT</pubDate>
      <author>marcus.harris@datatechs.co.uk (Marcus Harris)</author>
      <guid>https://www.datatechs.co.uk/blog/5-microsoft-365-settings-most-businesses-have-wrong-by-default-clone</guid>
      <dc:date>2026-07-20T20:58:35Z</dc:date>
    </item>
    <item>
      <title>5 Microsoft 365 Settings Most Businesses Have Wrong by Default</title>
      <link>https://www.datatechs.co.uk/blog/5-microsoft-365-settings-most-businesses-have-wrong-by-default</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.datatechs.co.uk/blog/5-microsoft-365-settings-most-businesses-have-wrong-by-default" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.datatechs.co.uk/hubfs/hero-contact.png" alt="5 Microsoft 365 Settings Most Businesses Have Wrong by Default" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;When I access a new client's Microsoft 365 tenant for the first time, I run through the same checklist every time. And almost every time, I find the same problems.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When I access a new client's Microsoft 365 tenant for the first time, I run through the same checklist every time. And almost every time, I find the same problems.&lt;/p&gt; 
&lt;p&gt;Not because these businesses haven't tried to secure their environment. Because Microsoft's out-of-the-box defaults are not secure defaults. They're designed for ease of onboarding — not for protecting a business.&lt;/p&gt; 
&lt;p&gt;Here are the five settings I find misconfigured most often, what the risk actually is, and what to do about it.&lt;/p&gt;  
&lt;h2&gt;1. Legacy Authentication Is Still Enabled&lt;/h2&gt; 
&lt;p&gt;&lt;strong&gt;What it is:&lt;/strong&gt; Legacy authentication refers to older sign-in protocols — think basic SMTP auth, IMAP, POP3, and older Office clients. These protocols don't support modern Multi-Factor Authentication.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Why it's a problem:&lt;/strong&gt; If legacy authentication is enabled, an attacker only needs a username and password to get in — MFA doesn't apply. Password spray attacks almost always target legacy authentication endpoints for exactly this reason.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;What to do:&lt;/strong&gt; Block legacy authentication using a Conditional Access policy. If you have users on very old versions of Outlook or mobile mail apps, they'll need to update — but the security gain is worth the short-term friction.&lt;/p&gt;  
&lt;h2&gt;2. MFA Is Switched On But Not Enforced&lt;/h2&gt; 
&lt;p&gt;&lt;strong&gt;What it is:&lt;/strong&gt; Many tenants have MFA enabled in principle — but users can skip it, delay it, or it simply hasn't been applied to every account.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Why it's a problem:&lt;/strong&gt; MFA that isn't enforced for every user, every time, on every device isn't really MFA. Shared mailboxes and service accounts are particularly common blind spots — they often have no MFA at all.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;What to do:&lt;/strong&gt; Move away from per-user MFA settings and implement Conditional Access policies instead. These give you proper control — you can require MFA for all users, enforce compliant devices, and block access from untrusted locations. Check your admin accounts first; they should have the strictest policies.&lt;/p&gt;  
&lt;h2&gt;3. SharePoint and OneDrive External Sharing Is Wide Open&lt;/h2&gt; 
&lt;p&gt;&lt;strong&gt;What it is:&lt;/strong&gt; By default, SharePoint and OneDrive are often configured to allow "Anyone with a link" to access shared files — no sign-in required.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Why it's a problem:&lt;/strong&gt; Every time a staff member shares a document link, that link could be forwarded to anyone. For businesses handling client data, financial information, or anything sensitive, this is a significant data exposure risk — and a potential GDPR issue.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;What to do:&lt;/strong&gt; Review your sharing settings in the SharePoint Admin Centre. For most professional services firms, the right setting is "Only people in your organisation" or "Existing guests" — not "Anyone." You can also set link expiry dates and restrict download permissions on sensitive libraries.&lt;/p&gt;  
&lt;h2&gt;4. The Unified Audit Log Is Switched Off&lt;/h2&gt; 
&lt;p&gt;&lt;strong&gt;What it is:&lt;/strong&gt; The Unified Audit Log records user and admin activity across Microsoft 365 — who logged in, who accessed what, what was deleted, what was forwarded.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Why it's a problem:&lt;/strong&gt; In many tenants, this is not switched on by default. Without it, if you experience a breach, a data leak, or a compromised account, you have no forensic trail. You can't answer the question "what did they access?" because the records simply don't exist.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;What to do:&lt;/strong&gt; Go to the Microsoft Purview compliance portal and confirm audit logging is enabled. It should be on for all users, and ideally retained for at least 90 days — longer if your sector has specific compliance requirements.&lt;/p&gt;  
&lt;h2&gt;5. Microsoft Secure Score Is Being Ignored&lt;/h2&gt; 
&lt;p&gt;&lt;strong&gt;What it is:&lt;/strong&gt; Secure Score is Microsoft's built-in security scoring tool — it assesses your tenant configuration and gives you a score out of 100, with recommended actions to improve it.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Why it's a problem:&lt;/strong&gt; Most businesses either don't know it exists or checked it once and forgot about it. It's a live indicator of your security posture, and it updates as your configuration changes — or as Microsoft adds new recommendations.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;What to do:&lt;/strong&gt; Find it in the Microsoft Defender portal under Secure Score. Don't treat the number as a target — treat the recommended actions as a prioritised list. Focus on the high-impact, low-effort items first. A score in the 40s is typical for an unconfigured tenant; most businesses should be targeting 70+.&lt;/p&gt;  
&lt;h2&gt;The Common Thread&lt;/h2&gt; 
&lt;p&gt;None of these are exotic vulnerabilities. They're configuration gaps — things that are switched off, set too permissively, or simply never reviewed after the tenant was set up.&lt;/p&gt; 
&lt;p&gt;The CIS Microsoft 365 Foundations Benchmark covers all of these and more. It's a free, peer-reviewed security standard that gives you a clear baseline for what a properly configured M365 tenant should look like.&lt;/p&gt; 
&lt;p&gt;If you're not sure where your tenant stands on any of the above, that's worth finding out sooner rather than later.&lt;/p&gt;  
&lt;p&gt;&lt;strong&gt;Datatechs Consulting runs M365 security audits aligned to the CIS Foundations Benchmark.&lt;/strong&gt; You'll get a clear report showing exactly where your tenant stands, what's at risk, and what to fix — in plain English.&lt;/p&gt; 
&lt;p&gt;&#x1f449; &lt;a href="https://datatechs.co.uk"&gt;Download our free M365 Security Quick-Check&lt;/a&gt; — 10 things to review in your tenant today.&lt;/p&gt; 
&lt;p&gt;Or get in touch at &lt;strong&gt;datatechs.co.uk&lt;/strong&gt; to discuss a full security audit.&lt;/p&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=148777188&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.datatechs.co.uk%2Fblog%2F5-microsoft-365-settings-most-businesses-have-wrong-by-default&amp;amp;bu=https%253A%252F%252Fwww.datatechs.co.uk%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Tag1</category>
      <category>Tag2</category>
      <pubDate>Thu, 25 Jun 2026 20:41:37 GMT</pubDate>
      <author>marcus.harris@datatechs.co.uk (Marcus Harris)</author>
      <guid>https://www.datatechs.co.uk/blog/5-microsoft-365-settings-most-businesses-have-wrong-by-default</guid>
      <dc:date>2026-06-25T20:41:37Z</dc:date>
    </item>
  </channel>
</rss>
