Rate Us:
Category

Microsoft 365 Misconfigurations That Put Your Business at Risk

Share this post

Most Canadian businesses running Microsoft 365 assume their environment is secure because it came from Microsoft. This assumption is where many breaches start.

Security controls in Microsoft 365 are optional or depend on licensing, and default configurations are built to balance usability and compatibility rather than to meet every organization’s security requirements. Without an intentional review of your tenant, those settings stay as Microsoft left them.

A misconfigured Microsoft 365 environment can look like it’s working, until something goes wrong.

Common Microsoft 365 Misconfigurations That Create Risk

These misconfigurations show up regularly in M365 environments of every size, including in those that have been running Microsoft 365 for years.

MFA Not Enforced Across All Accounts

Many businesses set up MFA at the start but leave exceptions in place for shared accounts or applications that were never updated to support it. Every account without MFA enforced is a credential that a stolen password alone can compromise, and admin accounts without MFA hand an attacker control over your entire tenant.

Legacy Authentication Protocols Still Enabled

Although Microsoft has retired Basic Authentication for Exchange Online, older authentication methods can still exist through legacy applications, hybrid deployments, or protocols such as SMTP AUTH where they remain enabled. These protocols don’t automatically enforce modern authentication controls like MFA, and where they remain active, they may provide attackers with a path that bypasses MFA protections entirely.

Overly Permissive External Sharing

SharePoint and OneDrive defaults can allow users to share files with anyone who has a link, including people outside your organisation with no requirement to sign in. Stricter external sharing policies that require authenticated access close that exposure without meaningfully disrupting how your team collaborates.

Email Forwarding Rules With No Oversight

Attackers who gain access to a mailbox frequently create forwarding rules that silently copy or redirect incoming mail to an external address. Without monitoring for suspicious mail flow rules, those configurations can persist for weeks undetected.

Global Admin Accounts Used for Routine Tasks

Using a global administrator account for day-to-day IT tasks increases the exposure window for that credential. Applying the principle of least privilege, where you assign the permissions each role actually needs, significantly reduces what an attacker can access if that account is compromised.

Conditional Access Policies Missing or Incomplete

Smaller Microsoft 365 tenants often rely on Microsoft’s Security Defaults, while organizations with Microsoft Entra ID Premium licensing can build more granular Conditional Access policies. Understanding which model your business uses helps determine whether additional protections are available. Many tenants have no Conditional Access policies configured, leaving access decisions to a binary credential check, regardless of device, location, or behaviour.

Audit Logging Not Configured Properly

Unified audit logging is enabled by default for most Microsoft 365 organizations today, but retention periods and available audit data still vary depending on licensing and configuration. If your logs don’t go back far enough, they can’t support a meaningful investigation when something goes wrong. Reviewing your audit log retention is a foundational step in any M365 security audit.

Third-Party App Permissions Not Reviewed

Every Microsoft 365 tenant accumulates connected third-party applications over time. A poorly secured app with broad permissions can access sensitive business data without any credential compromise required, and most organizations have never formally reviewed which apps are connected or what they can access.

Why These Gaps Stay Hidden

Many of these misconfigurations originate at setup and are never revisited. A configuration that was reasonable two or three years ago may have gaps today as Microsoft releases new features and updates its security recommendations.

Microsoft Secure Score provides a baseline measurement of your tenant’s security posture and highlights configuration improvements. It gives companies a useful starting point for identifying where gaps are most likely to occur, but it shouldn’t be used as a compliance checklist.

Even a well-configured tenant can drift over time as users, applications, and Microsoft features change. Regular reviews and ongoing configuration management help ensure yesterday’s secure setup still meets today’s standards.

Frequently Asked Questions

The most reliable way is a structured configuration audit conducted against current Microsoft security benchmarks. Many businesses running Microsoft 365 for several years have never had their tenant settings formally reviewed, and the gaps that exist are often not visible through normal day-to-day use.
Some security controls are optional or depend on licensing, while default configurations are designed to balance usability and compatibility rather than meet every organization's security requirements. A review against your actual business context is the only reliable way to know where you stand.
Legacy authentication protocols often can't enforce modern authentication controls such as MFA. Although Microsoft has retired Basic Authentication for Exchange Online, these protocols can still exist through older applications, hybrid deployments, or SMTP AUTH where enabled and may provide attackers with a path that bypasses MFA protections.
At minimum, review Microsoft 365 security settings annually. Businesses operating in regulated industries or making frequent infrastructure changes may benefit from quarterly reviews. Microsoft also regularly updates its security recommendations, so a configuration that was well-hardened two years ago may have gaps today.
Conditional Access lets you define rules governing when and how users can access company resources, requiring MFA from outside the office, blocking access from unfamiliar locations, or restricting access from unmanaged devices. Most businesses benefit from at least a baseline set of conditional access policies, and many have none in place at all.
Yes. If a misconfiguration results in unauthorized access to personal information, it may constitute a breach of security safeguards under PIPEDA or applicable provincial privacy legislation, triggering reporting obligations to the Office of the Privacy Commissioner and notification requirements for affected individuals. Firms in Quebec face additional obligations under Law 25.

The Business Impact

Business email compromise, data exfiltration through incorrect sharing settings, and tenant-wide compromise through unprotected admin accounts are common attacks against Canadian businesses. A misconfiguration that allows unauthorized access to personal information can trigger reporting to the Office of the Privacy Commissioner and notification to affected individuals under PIPEDA and provincial privacy laws. Reputational damage outlasts regulatory fallout.

Solutions For You works with Canadian businesses to review, harden, and maintain Microsoft 365 environments through cloud solutions that keep your configuration current as the platform evolves.

Reach out to Solutions For You to discuss an M365 configuration review for your business.

Share this post

What can we do better?

We love to hear from our clients, please let us know if there are any areas that you think we could improve upon.