All Resources
Microsoft 365

Common Microsoft 365 Security Mistakes

Most Microsoft 365 breaches are not sophisticated. They exploit the same handful of misconfigurations we find in almost every tenant we audit. This article lists the ten most common Microsoft 365 security mistakes small and mid-sized businesses in Greater Sudbury make, why each one matters, and what to change today.

June 4, 2026 9 min read Greater Sudbury & Ontario

1. MFA is not enforced for every user

The single most common finding. Multi-factor authentication is either optional, enabled only for admins, or bypassed by legacy protocols. Enforce MFA for every licensed user through Conditional Access or Security Defaults, and disable legacy auth entirely.

2. Legacy authentication is still enabled

POP, IMAP, SMTP AUTH, and older Exchange protocols bypass MFA. Attackers spray these endpoints with leaked passwords. Disable them tenant-wide unless a specific device demonstrably needs one, and only for the account that needs it.

3. Too many Global Administrators

We routinely find tenants with six or more Global Admins, most of them long-departed staff or vendor accounts. Limit Global Admin to two or three named humans, use role-based admin (Exchange Admin, User Admin, etc.) for everyone else, and require phishing-resistant MFA on every admin account.

4. External sharing is wide open

SharePoint and OneDrive default to allowing anonymous sharing links. Restrict external sharing to authenticated guests only, disable anonymous links except where clearly justified, and expire links after a set period.

5. No Microsoft 365 backup

Microsoft replicates your data for availability, not for your protection against deletion, ransomware, or misconfigured retention. Deploy a dedicated Microsoft 365 backup that covers Exchange, OneDrive, SharePoint, and Teams.

6. Mailbox audit logging is off or unreviewed

Without audit logging you can't answer basic incident-response questions like which mailbox was accessed and when. Confirm unified audit log is enabled and that mailbox audit is on for every mailbox.

7. Anti-phishing and impersonation protection is at defaults

The default Microsoft anti-phishing policy does not protect against impersonation of your executives or your domain. Customize impersonation protection to cover your top leaders and your primary domain, and add Safe Links / Safe Attachments if licensed for Defender for Office 365.

8. SPF, DKIM, and DMARC are not fully deployed

Missing or misconfigured email authentication lets attackers spoof your domain. Publish SPF, enable DKIM on every sending domain, and move DMARC from p=none to p=quarantine or p=reject.

9. Departed staff are still licensed and active

Old accounts, still MFA-enabled or not, are prime targets. Build an offboarding checklist that disables sign-in, revokes sessions, converts mailboxes to shared where needed, and removes licences within 24 hours.

10. No one owns Microsoft 365 in the business

The biggest security mistake isn't a setting it's the absence of a named owner. Every tenant needs a person or MSP who reviews Secure Score, sign-in logs, and configuration drift monthly.

When to call an IT provider

If any of the above are unknown or unowned in your business, a Microsoft 365 security audit will find them and give you a prioritized remediation plan. Most audits pay for themselves in reduced insurance premiums and avoided incidents.

Frequently asked questions

How long does a Microsoft 365 security audit take?

A typical SMB tenant audit takes one to two days, followed by a written report and prioritized remediation plan.

Will fixing these break anything for users?

Most controls MFA, legacy auth, sharing tightening are transparent when rolled out with proper communication and a pilot group.

Do we need Business Premium for all of this?

Many controls work on Business Standard. Conditional Access, Intune, and Defender for Office 365 require Business Premium or higher.

Get a Microsoft 365 security audit

We'll audit your tenant against the most common misconfigurations and deliver a prioritized remediation plan.

Keep exploring

Related services, locations, and resources

Related services

Related resources