Person using a laptop displaying files and folders, representing the review and management of Microsoft 365 tenant security settings.

Microsoft has strengthened many of its default Microsoft 365 security settings over the past few years. However, those improvements don’t always apply to existing tenants. If your Microsoft 365 environment was set up several years ago—or by a previous IT provider—it may still be using outdated settings that leave your business unnecessarily exposed. Here are five important areas worth reviewing.

Microsoft regularly improves the security of Microsoft 365, introducing stronger default settings to help protect businesses against modern cyber threats.

The catch?

If your Microsoft 365 tenant was created several years ago, those newer defaults may not have been applied automatically.

That means settings configured years ago could still be active today, even if Microsoft now recommends a more secure approach.


A quick review can help identify outdated configurations before they become a security risk.

1. SharePoint & OneDrive File Sharing

One of the most common areas of unnecessary risk is file sharing.

Older Microsoft 365 tenants often allow files to be shared using “Anyone with the link”, meaning recipients can access documents without signing in.

While convenient, this makes it difficult to control who ultimately receives the file or how long access remains available.

Instead, businesses should consider requiring users to authenticate before accessing shared files and setting expiry dates for sharing links wherever possible.

Doing so provides greater visibility and significantly improves control over sensitive business information.

2. External Email Forwarding

Automatic email forwarding to personal accounts can create a significant security and compliance risk.

Microsoft now blocks external forwarding by default for many organisations, but older tenants may still have historical forwarding rules in place.

These rules can allow company emails to be copied automatically to personal inboxes without anyone realising.

Reviewing forwarding policies and existing inbox rules helps ensure business information stays within your organisation.

3. Third-Party Application Permissions

Over the years, employees often connect third-party applications to Microsoft 365 to improve productivity.

The problem is that many of these apps continue to retain access long after they’ve stopped being used.

Some may still have permission to access:

  • Email
  • Calendars
  • OneDrive files
  • SharePoint documents

Regularly reviewing connected applications helps remove unnecessary access and reduces potential security risks.

4. Audit Log Retention

Audit logs are invaluable when investigating security incidents or demonstrating compliance.

Microsoft has increased default audit log retention in recent years, but your current settings may still not meet your business or regulatory requirements.

If you ever need to investigate suspicious activity, longer retention periods provide far greater visibility into what happened and when.

It’s worth confirming your current retention policy aligns with your organisation’s needs.

5. Multi-Factor Authentication (MFA)

MFA remains one of the most effective ways to protect Microsoft 365 accounts.

However, older tenants sometimes have inconsistent configurations after years of policy changes, licence upgrades, or IT provider transitions.

It’s worth checking that:

  • MFA is enabled for all users
  • Administrator accounts are protected
  • Conditional Access policies are working as intended
  • Emergency (“break glass”) accounts remain secure

An incomplete MFA rollout can leave unexpected gaps in your security.


Where Should You Start?

Not every change needs to happen immediately.

A sensible approach is to begin with settings that have little or no impact on your users before moving on to those that may require communication or planning.

For example:

  • Review connected applications
  • Check audit log retention
  • Audit external email forwarding
  • Update file sharing policies
  • Finally, review MFA and Conditional Access settings

Taking a phased approach helps improve security while minimising disruption.

Small Changes Can Make a Big Difference

Cybersecurity isn’t always about deploying new technology.

Sometimes the biggest improvements come from reviewing the systems you already have.

If your Microsoft 365 tenant hasn’t had a security review in several years, now is a great time to check whether your settings still reflect current best practice.

A short audit today could prevent a costly security incident tomorrow.

👉 Not sure whether your Microsoft 365 tenant is configured securely? Our team can review your environment, identify outdated settings, and help ensure your business is making the most of Microsoft’s latest security features. Contact us today!

Article used with permission from The Technology Press.


Tags

Comments are closed