Microsoft 365 Security: Why the Default Settings Aren't Enough

Most businesses treat a Microsoft 365 migration as a project with a clear end point. The mailboxes move, the files sync to SharePoint and OneDrive, everyone can log in, and the project is marked done. What often gets missed is that moving to Microsoft 365 is not the same thing as securing it.
Microsoft ships sensible baseline protections, but the defaults are built for a broad range of customers, not for your specific risk profile. Left untouched, they leave gaps that attackers know how to find. Here is what tends to slip through the cracks, and what's worth checking.
Conditional access is doing less than you think
Conditional access policies control who can sign in, from where, on what device, and under what conditions. Many tenants either never configure them beyond the Microsoft-recommended baseline, or set them up once during migration and never revisit them.
Common gaps:
- No block on legacy authentication protocols, which don't support modern MFA and are a favourite entry point for credential-stuffing attacks.
- No restriction on sign-ins from unexpected countries or from unmanaged, unrecognised devices.
- Policies that apply to some user groups but were never extended to new starters, contractors or service accounts.
A short review of who conditional access actually applies to, versus who it should apply to, often turns up accounts nobody remembers adding.
Admin roles accumulate quietly
Global administrator access tends to spread over time. An IT person needed it for a one-off task two years ago and never had it removed. A departed staff member's account was disabled but still holds admin rights. Every one of these is a standing risk, because a compromised admin account gives an attacker far more reach than a compromised standard mailbox.
Worth doing on a regular basis:
- List everyone with any admin role, not just Global Administrator, and confirm each one still needs it.
- Move away from permanent admin access where possible, using time-limited elevation instead.
- Require a separate, more strongly protected account for anyone who genuinely needs admin rights, rather than granting admin privileges on their everyday login.
Third-party app consent is an open door
When staff sign in to a website or app with their Microsoft 365 credentials and grant it permission to read their mailbox or files, that consent often persists indefinitely. Attackers have used this exact mechanism, tricking a user into approving a malicious app that then quietly reads email or exfiltrates files, all without ever needing a password.
Reviewing which third-party apps have been granted access, and restricting user consent so only pre-approved apps can be authorised, closes a route into the tenant that MFA does not protect against.
Mailbox rules are a favourite hiding spot
Once an attacker gets into a mailbox, even briefly, a common move is to create a forwarding or hide-and-delete rule that quietly copies incoming mail, particularly anything mentioning invoices or banking details, to an external address. These rules are easy to miss because they don't disrupt the mailbox owner's day-to-day experience at all.
Periodic auditing of mailbox forwarding rules, and alerting when a new external forwarding rule is created, catches this kind of compromise early rather than after money has moved.
Retention is not the same as backup
Microsoft 365 includes retention policies and a recycle bin, and many businesses assume that's sufficient protection against data loss. It isn't designed for that purpose. Retention has limits, gaps around permanently deleted items, and no real protection against an account being compromised and its data deliberately wiped. A proper backup, held independently of the tenant, is still necessary if you can't afford to lose that data.
Secure Score is a starting point, not a report card
Microsoft's Secure Score gives a rough sense of configuration maturity, but a high score doesn't mean the tenant is well defended for your specific business. It doesn't account for how your staff actually work, what data you hold, or which of your accounts are most likely to be targeted. Treat it as one input among several, not the final word.
Where this fits into a wider security posture
None of this is about buying more software. It's about reviewing configuration that's often already included in your Microsoft 365 licence but never switched on properly, or checked after go-live. This is exactly the kind of gap that a security-first managed service provider looks for as part of ongoing monitoring, rather than a one-time migration checklist.
If your Microsoft 365 environment has been running quietly since it was set up, with no one revisiting the configuration since, it's worth a second look. The defaults got you moved in. They weren't necessarily meant to be the whole plan.
Want this handled for you?
Talk to the F1 team about cybersecurity, AI and managed IT for your business.

