Skip to content
TB Enterprise
All guides
Security

5 things worth checking in Microsoft 365

Most Microsoft 365 tenants are set up once and never revisited. These are the settings that matter.

Microsoft 365 gets configured when a business starts using it and then it largely gets left alone, which is understandable, because it works, people can send email, and there is always something more pressing.

The defaults, though, are chosen to get you working quickly rather than to keep you safe once you are. These are the 5 we look at first.

1. Multi-factor authentication, on everyone

Not most people. Everyone, including the director who finds it irritating and the shared account nobody wants to touch, because a password on its own is one breach of one unrelated website away from being public and the accounts that get exempted are reliably the ones worth compromising. If you only do one thing off this list, do this one.

2. Legacy authentication, turned off

Older mail protocols cannot do multi-factor authentication at all, so leaving them enabled means an attacker can use one of those instead and walk straight past the MFA you have just rolled out. It is the gap that leaves businesses confident they are protected when they are not, and turning it off is a 5 minute change in the admin centre.

3. Mailbox forwarding rules

A quiet forwarding rule sending copies of everything to an outside address is one of the most common signs of a compromised mailbox, and it can sit there for months because nothing visibly changes for the person whose account it is.

Have a look at who has forwarding configured, and at whether external forwarding ought to be permitted at all, which for most businesses it should not.

4. Who has admin rights

Global admin gets handed out during setup, generally to whoever happened to be in the room, and then never taken back off anybody. Each of those accounts is a complete compromise of your tenant if it falls over, so the list is worth reading. It is normally longer than anyone expects and frequently includes somebody who left.

5. What happens when someone leaves

There should be a clear answer here: the account disabled, sessions revoked, the mailbox preserved or handed to a manager, devices wiped or unenrolled. Where leaving depends on somebody remembering to do all that, it will eventually not get done, usually in the month everyone is busy. Device management through Intune turns it from a memory test into a process that runs whether anybody is paying attention or not.

One to check separately: whose tenant is it

Some providers set Microsoft 365 up under their own tenant or their own partner agreement, which is convenient right up until the day you want to move. Your tenant, your licences and your data should be in your name with your provider holding delegated access rather than ownership, and it is a 5 minute question to ask now rather than during a handover.

Where this leaves you

None of the above is difficult and none of it needs a project. They are configuration changes that stay undone because nobody owns them, and the actual work is knowing which ones matter given how your business operates.

How we do it

We are a Microsoft Solutions Partner, so this is daily work for a dedicated team rather than an occasional favour.

That covers Microsoft 365 properly: accounts, domains and security, migration from whatever you are on now, licensing worked out so you are not paying for seats nobody uses, company policies, and training so your staff actually use Teams, SharePoint and OneDrive rather than emailing attachments around them.

Azure gets used where it earns its place, with virtual machines on Windows or Linux, migration and deployment, performance tuning, security and compliance. We will also tell you when something belongs on your own infrastructure instead, since we run that too and have no particular reason to push you either way.

Intune goes across every device for security policies, app deployment and compliance checks, which is what turns a leaver into a process. Monitoring runs around the clock afterwards, with multi-factor authentication, encryption and backup in place from the start rather than added after an incident.

Your tenant stays yours throughout. We hold delegated access rather than ownership, there is no long tie-in, and you keep control of your licences and your data.

If you want these checked properly, that is part of the free consultation, and we will tell you what we find whether or not you take it further.

More guides
Custom software or off the shelf?
How to work out which one your business actually needs, before anyone quotes you for either.
Is your business actually backed up?
Having a backup and having a backup that works are two different things. Here is how to tell which one you have.