Common Microsoft 365 Security Mistakes
Most Microsoft 365 breaches are not sophisticated. They exploit the same handful of misconfigurations we find in almost every tenant we audit. This article lists the ten most common Microsoft 365 security mistakes small and mid-sized businesses in Greater Sudbury make, why each one matters, and what to change today.
1. MFA is not enforced for every user
The single most common finding. Multi-factor authentication is either optional, enabled only for admins, or bypassed by legacy protocols. Enforce MFA for every licensed user through Conditional Access or Security Defaults, and disable legacy auth entirely.
2. Legacy authentication is still enabled
POP, IMAP, SMTP AUTH, and older Exchange protocols bypass MFA. Attackers spray these endpoints with leaked passwords. Disable them tenant-wide unless a specific device demonstrably needs one, and only for the account that needs it.
3. Too many Global Administrators
We routinely find tenants with six or more Global Admins, most of them long-departed staff or vendor accounts. Limit Global Admin to two or three named humans, use role-based admin (Exchange Admin, User Admin, etc.) for everyone else, and require phishing-resistant MFA on every admin account.
4. External sharing is wide open
SharePoint and OneDrive default to allowing anonymous sharing links. Restrict external sharing to authenticated guests only, disable anonymous links except where clearly justified, and expire links after a set period.
5. No Microsoft 365 backup
Microsoft replicates your data for availability, not for your protection against deletion, ransomware, or misconfigured retention. Deploy a dedicated Microsoft 365 backup that covers Exchange, OneDrive, SharePoint, and Teams.
6. Mailbox audit logging is off or unreviewed
Without audit logging you can't answer basic incident-response questions like which mailbox was accessed and when. Confirm unified audit log is enabled and that mailbox audit is on for every mailbox.
7. Anti-phishing and impersonation protection is at defaults
The default Microsoft anti-phishing policy does not protect against impersonation of your executives or your domain. Customize impersonation protection to cover your top leaders and your primary domain, and add Safe Links / Safe Attachments if licensed for Defender for Office 365.
8. SPF, DKIM, and DMARC are not fully deployed
Missing or misconfigured email authentication lets attackers spoof your domain. Publish SPF, enable DKIM on every sending domain, and move DMARC from p=none to p=quarantine or p=reject.
9. Departed staff are still licensed and active
Old accounts, still MFA-enabled or not, are prime targets. Build an offboarding checklist that disables sign-in, revokes sessions, converts mailboxes to shared where needed, and removes licences within 24 hours.
10. No one owns Microsoft 365 in the business
The biggest security mistake isn't a setting it's the absence of a named owner. Every tenant needs a person or MSP who reviews Secure Score, sign-in logs, and configuration drift monthly.
When to call an IT provider
If any of the above are unknown or unowned in your business, a Microsoft 365 security audit will find them and give you a prioritized remediation plan. Most audits pay for themselves in reduced insurance premiums and avoided incidents.
Frequently asked questions
How long does a Microsoft 365 security audit take?
A typical SMB tenant audit takes one to two days, followed by a written report and prioritized remediation plan.
Will fixing these break anything for users?
Most controls MFA, legacy auth, sharing tightening are transparent when rolled out with proper communication and a pilot group.
Do we need Business Premium for all of this?
Many controls work on Business Standard. Conditional Access, Intune, and Defender for Office 365 require Business Premium or higher.
Get a Microsoft 365 security audit
We'll audit your tenant against the most common misconfigurations and deliver a prioritized remediation plan.
Related services, locations, and resources
Related services
- Cybersecurity Services
Endpoint protection, MFA, email filtering, and M365 hardening.
- Microsoft 365 Support
Exchange, Teams, SharePoint, OneDrive, and licensing.
- Managed IT Services
Proactive monitoring, patching, and predictable monthly support.
- Backup & Disaster Recovery
Backup strategy, monitoring, and recovery testing.
Related service areas
Related resources
- Why Does Outlook Keep Crashing?
Outlook is the most common ticket a Sudbury MSP sees. Here are the real reasons it crashes on business PCs …
- Why Businesses Need Backups
Why proper backups are non-negotiable for modern businesses, what to back up, how often, and the myths that…
- Active Microsoft 365 Phishing Campaign Targeting Northern Ontario Businesses
A widespread Microsoft 365 login-harvest phishing campaign is currently hitting Ontario SMBs. Watch for the…
- Why Every Business Needs Multi-Factor Authentication
If you do only one security thing this year, do this. MFA blocks the vast majority of account-takeover atta…
