Microsoft 365 gets configured when a business starts using it and then it largely gets left alone, which is understandable, because it works, people can send email, and there is always something more pressing.
The defaults, though, are chosen to get you working quickly rather than to keep you safe once you are. These are the 5 we look at first.
1. Multi-factor authentication, on everyone
Not most people. Everyone, including the director who finds it irritating and the shared account nobody wants to touch, because a password on its own is one breach of one unrelated website away from being public and the accounts that get exempted are reliably the ones worth compromising. If you only do one thing off this list, do this one.
2. Legacy authentication, turned off
Older mail protocols cannot do multi-factor authentication at all, so leaving them enabled means an attacker can use one of those instead and walk straight past the MFA you have just rolled out. It is the gap that leaves businesses confident they are protected when they are not, and turning it off is a 5 minute change in the admin centre.
3. Mailbox forwarding rules
A quiet forwarding rule sending copies of everything to an outside address is one of the most common signs of a compromised mailbox, and it can sit there for months because nothing visibly changes for the person whose account it is.
Have a look at who has forwarding configured, and at whether external forwarding ought to be permitted at all, which for most businesses it should not.
4. Who has admin rights
Global admin gets handed out during setup, generally to whoever happened to be in the room, and then never taken back off anybody. Each of those accounts is a complete compromise of your tenant if it falls over, so the list is worth reading. It is normally longer than anyone expects and frequently includes somebody who left.
5. What happens when someone leaves
There should be a clear answer here: the account disabled, sessions revoked, the mailbox preserved or handed to a manager, devices wiped or unenrolled. Where leaving depends on somebody remembering to do all that, it will eventually not get done, usually in the month everyone is busy. Device management through Intune turns it from a memory test into a process that runs whether anybody is paying attention or not.
One to check separately: whose tenant is it
Some providers set Microsoft 365 up under their own tenant or their own partner agreement, which is convenient right up until the day you want to move. Your tenant, your licences and your data should be in your name with your provider holding delegated access rather than ownership, and it is a 5 minute question to ask now rather than during a handover.
Where this leaves you
None of the above is difficult and none of it needs a project. They are configuration changes that stay undone because nobody owns them, and the actual work is knowing which ones matter given how your business operates.
How we do it
We are a Microsoft Solutions Partner, so this is daily work for a dedicated team rather than an occasional favour.
That covers Microsoft 365 properly: accounts, domains and security, migration from whatever you are on now, licensing worked out so you are not paying for seats nobody uses, company policies, and training so your staff actually use Teams, SharePoint and OneDrive rather than emailing attachments around them.
Azure gets used where it earns its place, with virtual machines on Windows or Linux, migration and deployment, performance tuning, security and compliance. We will also tell you when something belongs on your own infrastructure instead, since we run that too and have no particular reason to push you either way.
Intune goes across every device for security policies, app deployment and compliance checks, which is what turns a leaver into a process. Monitoring runs around the clock afterwards, with multi-factor authentication, encryption and backup in place from the start rather than added after an incident.
Your tenant stays yours throughout. We hold delegated access rather than ownership, there is no long tie-in, and you keep control of your licences and your data.
If you want these checked properly, that is part of the free consultation, and we will tell you what we find whether or not you take it further.