Common Microsoft 365 Security Mistakes
Most Microsoft 365 breaches are not sophisticated. They exploit the same handful of misconfigurations we find in almost every tenant we audit. This article lists the ten most common Microsoft 365 security mistakes small and mid-sized businesses in Greater Sudbury make, why each one matters, and what to change today.
1. MFA is not enforced for every user
The single most common finding. Multi-factor authentication is either optional, enabled only for admins, or bypassed by legacy protocols. Enforce MFA for every licensed user through Conditional Access or Security Defaults, and disable legacy auth entirely.
2. Legacy authentication is still enabled
POP, IMAP, SMTP AUTH, and older Exchange protocols bypass MFA. Attackers spray these endpoints with leaked passwords. Disable them tenant-wide unless a specific device demonstrably needs one, and only for the account that needs it.
3. Too many Global Administrators
We routinely find tenants with six or more Global Admins, most of them long-departed staff or vendor accounts. Limit Global Admin to two or three named humans, use role-based admin (Exchange Admin, User Admin, etc.) for everyone else, and require phishing-resistant MFA on every admin account.
Want a second opinion on your Microsoft 365 tenant?
We review licensing, sharing, mailbox rules, and security defaults, then show you what to change and why it matters.
Request a Microsoft 365 Review4. External sharing is wide open
SharePoint and OneDrive default to allowing anonymous sharing links. Restrict external sharing to authenticated guests only, disable anonymous links except where clearly justified, and expire links after a set period.
5. No Microsoft 365 backup
Microsoft replicates your data for availability, not for your protection against deletion, ransomware, or misconfigured retention. Deploy a dedicated Microsoft 365 backup that covers Exchange, OneDrive, SharePoint, and Teams.
6. Mailbox audit logging is off or unreviewed
Without audit logging you can't answer basic incident-response questions like which mailbox was accessed and when. Confirm unified audit log is enabled and that mailbox audit is on for every mailbox.
7. Anti-phishing and impersonation protection is at defaults
The default Microsoft anti-phishing policy does not protect against impersonation of your executives or your domain. Customize impersonation protection to cover your top leaders and your primary domain, and add Safe Links / Safe Attachments if licensed for Defender for Office 365.
8. SPF, DKIM, and DMARC are not fully deployed
Missing or misconfigured email authentication lets attackers spoof your domain. Publish SPF, enable DKIM on every sending domain, and move DMARC from p=none to p=quarantine or p=reject.
9. Departed staff are still licensed and active
Old accounts, still MFA-enabled or not, are prime targets. Build an offboarding checklist that disables sign-in, revokes sessions, converts mailboxes to shared where needed, and removes licences within 24 hours.
10. No one owns Microsoft 365 in the business
The biggest security mistake isn't a setting it's the absence of a named owner. Every tenant needs a person or MSP who reviews Secure Score, sign-in logs, and configuration drift monthly.
When to call an IT provider
If any of the above are unknown or unowned in your business, a Microsoft 365 security audit will find them and give you a prioritized remediation plan. Most audits pay for themselves in reduced insurance premiums and avoided incidents.
Frequently asked questions
How long does a Microsoft 365 security audit take?
A typical SMB tenant audit takes one to two days, followed by a written report and prioritized remediation plan.
Will fixing these break anything for users?
Most controls MFA, legacy auth, sharing tightening are transparent when rolled out with proper communication and a pilot group.
Do we need Business Premium for all of this?
Many controls work on Business Standard. Conditional Access, Intune, and Defender for Office 365 require Business Premium or higher.
Joshua Arimoro
Joshua Arimoro is the Principal Consultant at Nickel City Tech Solutions, a managed IT and cybersecurity provider based in Lively, Ontario, serving businesses across Greater Sudbury and Northern Ontario. He works hands-on with Microsoft 365, server and network infrastructure, endpoint management, and backup and recovery for small and mid-sized organisations.
More about our teamGet a Microsoft 365 security audit
We'll audit your tenant against the most common misconfigurations and deliver a prioritized remediation plan.
Technologies mentioned in this article
See what we support around each platform on our supported technologies hub.
Related services, locations, and resources
Related services
- Cybersecurity Services
Endpoint protection, MFA, email filtering, and M365 hardening.
- Microsoft 365 Support
Exchange, Teams, SharePoint, OneDrive, and licensing.
- Managed IT Services
Proactive monitoring, patching, and predictable monthly support.
- Backup & Disaster Recovery
Backup strategy, monitoring, and recovery testing.
Related service areas
Related resources
- Backing Up Microsoft 365 With a Third-Party Tool
Microsoft keeps your email and files running, but it does not back them up the way most businesses assume. …
- Secure Client Document Exchange for Accountants
Emailing tax returns and identification documents as attachments is the single most common security gap in …
- Acronis Backup for Small Businesses: What It Covers and How It Is Set Up
A practical look at what Acronis Cyber Protect Cloud actually backs up for a small business and how a typic…
- What to Do After a Business Email Account Is Compromised
The first hour after discovering a compromised email account determines whether the incident stays containe…
