Microsoft 365 Security: Why the Defaults Aren't Enough
Most Australian SMBs run on Microsoft 365. Email, Teams, SharePoint, OneDrive - it's the backbone of your business. Chances are your invoices go out through it, your team collaborates in it, and your client data lives inside it.
Here's the problem: the default settings leave you exposed. Microsoft's out-of-the-box configuration is designed to be easy to set up, and easy means open. We review Microsoft 365 tenants as part of every client onboarding, and three issues show up in almost every single one.
The Three Gaps We Find in Almost Every Tenant
1 No MFA on Admin Accounts
The single most common finding: administrator accounts protected by nothing more than a password. If your global admin (the account with the keys to the whole tenant) only has a password, then the entire business is one credential leak away from being owned.
Why it matters: An attacker with admin access doesn't need to "hack" anything else. They reset passwords, read everyone's mail, create their own forwarding rules, and quietly exfiltrate your data over weeks. The account is one password guess away from someone owning your domain, your email, your files.
The fix: Turn on MFA for every account - starting with all administrator roles - and enforce it with Conditional Access so it can't be turned off by a user.
2 Shared Logins
"It's easier." That's the justification for a team sharing one mailbox login, one admin account, or one generic user. It's easier, yes - until the person who left six weeks ago still has access to the accounts mailbox.
Why it matters: Shared logins destroy accountability. When an email goes missing or a payment is redirected, you can't tell who did it because the audit trail just shows "the shared account." They're also a favourite target for attackers: one credential compromise hands them access to everyone who relies on that login.
The fix: A named account for every human, every time. Shared mailboxes exist for a reason - use them - and terminate access the day someone leaves.
3 Inbox Rules Nobody Knows About
This is the silent one. Attackers who compromise a mailbox don't announce themselves. They create a quiet inbox rule - forward everything containing "invoice" to an external address, or move admin emails to a folder the victim never opens - and then they wait.
Why it matters: We've found attackers sitting silently in inboxes for weeks, reading invoices, redirecting payments, learning the rhythm of the business before striking. Because the rule is invisible to the person whose mailbox it's in, the compromise can go undetected for months.
The fix: Review inbox rules regularly, and turn on alerts for suspicious patterns: new forwarding rules, rules sending mail outside the organisation, or mailbox logins from new locations.
The Good News: The Fix Takes About Two Hours
None of this is expensive or complicated to fix. For a tenant under 50 users, locking down these three gaps takes roughly two hours of focused work:
- Enforce MFA everywhere. Enable security defaults or set up Conditional Access policies, then require MFA for all users and all admin roles.
- Audit admin roles. Most tenants have far more administrators than they need. Reduce global admins to the two or three people who genuinely need them, and give everyone else least-privilege roles.
- Block legacy authentication. Old protocols (IMAP, SMTP auth, basic auth) bypass MFA entirely. Block them and the phishing-resistant setup you just built actually holds.
- Clean up shared accounts and stale access. Replace shared logins with named accounts, and remove anyone who has left.
- Set up alerting. Forwarding rules, unusual logins, and admin changes should trigger a notification to someone who knows what to do with it.
Most businesses don't know they need this. The default settings look fine, everything works, nobody's had an incident yet. The security posture of your tenant is a risk you're carrying without realising it.
Why It Stays Broken
Here's the uncomfortable part: the tenants we see are rarely broken because someone made a bad decision. They're broken because nobody was looking. Microsoft 365 security changes constantly - new attack techniques, new defaults, new features that need configuring. Keeping up is a job in itself.
That's why a one-off cleanup isn't the answer. The two-hour fix gets you to a safe baseline, and then the configuration needs to be reviewed on a schedule. The businesses that stay secure are the ones where someone checks the tenant regularly: MFA coverage, admin roles, forwarding rules, login anomalies.
You don't need to become a Microsoft 365 security expert. You need someone who checks it for you.
Want to know what state your Microsoft 365 tenant is in?
We review Microsoft 365 configuration as part of every free health check - MFA coverage, admin roles, forwarding rules, and legacy authentication. Takes about 15 minutes and you get a one-page report. No obligation, no pitch.
Book Your Free Health Check