Microsoft 365 Security Mistakes to Fix Today
MFA isn't enough. These are the most common Microsoft 365 misconfigurations I find on day one of an audit — and how to fix them this week.
Microsoft 365 Security Mistakes to Fix Today
MFA isn't enough on its own — that's the single biggest misconception I run into. Multi-factor authentication is necessary, but it's one control among many, and Microsoft 365's flexibility means it's entirely possible to have MFA turned on while several other doors are left wide open. These are the misconfigurations that show up in almost every audit I run, in roughly the order I find them.
Legacy authentication still enabled
Legacy auth protocols (POP, IMAP, older Exchange ActiveSync clients) don't support modern authentication — which means they don't support MFA either. If legacy auth is still allowed on your tenant, it's a direct bypass around every other security control you've put in place. This is usually the first thing I disable, because it closes the biggest gap for the least disruption.
No conditional access policies
Conditional access is what lets Microsoft 365 make smart decisions about when to challenge a sign-in — blocking access from unexpected countries, requiring a compliant device, or forcing re-authentication for sensitive actions. Without it, every sign-in is treated the same whether it's coming from your office or from an unfamiliar server on the other side of the world at 3 a.m.
Global admins without hardware security keys
Global admin accounts are the highest-value target in your tenant — compromise one, and an attacker has the keys to everything. Password-plus-app MFA is good; a hardware security key, or at minimum phishing-resistant MFA, on every global admin account is what actually stops the kind of targeted phishing designed specifically to intercept a one-time code.
Shared mailboxes with sign-in enabled
Shared mailboxes (info@, support@, billing@) are supposed to be accessed through individual user accounts with delegated permissions — not signed into directly. When direct sign-in is left enabled, that mailbox becomes an account with no individual owner, often no MFA, and a password that's been emailed around the office at some point in its history. It's one of the most common ways into a tenant that has nothing to do with sophisticated hacking, just an old, forgotten door.
Anonymous link sharing left wide open in SharePoint
SharePoint and OneDrive default sharing settings are more permissive than most business owners realize. "Anyone with the link" sharing means a file can end up fully public the moment someone forwards an email — no account, no login, no audit trail required. Scoping default sharing down to "people in your organization," with specific external sharing granted case-by-case, closes this without meaningfully slowing anyone down.
Why small businesses are a common target
Attackers don't need a business to be large to be worth targeting — they need it to be reachable and under-defended. Small businesses often run the same Microsoft 365 platform as an enterprise, without an internal security team dedicated to keeping the configuration tight. That gap between "the software is capable of enterprise-grade security" and "the tenant is actually configured that way" is exactly what these five issues represent.
Why these keep happening
None of these are exotic. They're default settings, or settings that were reasonable years ago and never revisited as the tenant grew. Microsoft 365 ships secure-capable, not secure-by-default — the tools to lock things down are there, but they have to be turned on and configured deliberately.
Fixing this doesn't require a security team
Every one of these can be assessed and mostly fixed in an afternoon by someone who knows where to look — this isn't about hiring a full-time security team or ripping out your existing setup. It's about turning on controls that are already included in your Microsoft 365 license and rarely configured out of the box.
The bigger risk isn't the difficulty of the fix — it's not knowing these gaps exist until something goes wrong. A short, focused audit is usually enough to find and close all five before they show up in an incident report instead of a checklist.
Want help putting this into practice?
Book a free strategy call and we'll map a clear next step.
Book a Strategy Call