Vai al contenuto

Microsoft 365 security for companies

The default settings are not enough, and the three that genuinely matter can be changed in an afternoon.

In breve

Microsoft 365 arrives with settings designed to make everything work immediately, not to protect: mail accepts automatic forwarding to external addresses, audit logs do not always cover the period you would need, and anyone can share files with public links. The three corrections that move the most risk — second factor, blocking forwarding, sharing permissions — take a few hours.

The second factor, before anything else

A stolen password alone must not be enough to get in. It is the single measure with the highest return and it costs little.

Automatic forwarding is the way out

An attacker who gets into a mailbox sets a forwarding rule and reads the mail for months without touching anything else.

Sharing permissions

A public link created for convenience stays valid until somebody revokes it. Nobody revokes it.

Default settings exist to make things work, not to protect

This distinction is worth understanding, because it explains almost every problem we find. Microsoft 365 arrives configured to reduce friction: everything works immediately, nobody gets blocked, adoption is fast. It is a sensible choice for a product sold to millions of different organisations.

In a business context those same choices become exposures, and the three that weigh most are always the same.

1. Automatic forwarding to external addresses

This is the most underestimated mechanism and the one behind the most expensive frauds.

An attacker who obtains the credentials to a mailbox — bought in a list, or handed over on a fake login page — does not need to come back. They set a rule forwarding a copy of all the mail and then do nothing else detectable. They sit reading for weeks, learn how you talk to your suppliers, and step in only when a payment is under way.

It is why the request to change bank details always arrives at exactly the right moment, inside a genuine conversation. There is nothing anomalous to block: there is a mail rule nobody has looked at.

The fix: block automatic forwarding to external addresses at organisation level, and check the rules that already exist — because if somebody is already inside, that rule is there now.

2. The second factor, and the protocols that bypass it

Enabling the second factor is the single measure with the highest return, and that much is well known. Less well known is that in some configurations mail can be reached bypassing it, using older protocols that do not support a second factor at all.

While those protocols stay enabled, a stolen password keeps working. They should be disabled at the same time as the second factor is enabled, not afterwards.

There is also an order of priority almost everybody gets wrong: everyone’s mail is protected while the administrative accounts are left uncovered — the accounts with the worst consequences and often the least looked after, because one person uses them.

Sharing a file with a link is convenient and gets used constantly. The problem is that the link stays valid until somebody revokes it, and nobody revokes it.

In assessments we regularly find company documents reachable by anyone holding the address, created years earlier to send to a supplier who no longer works with the company. It is not a dramatic breach: it is a door left ajar and forgotten.

The fix comes in two parts: setting rules for the future about who can create which kind of link and with what expiry, and reviewing the ones that already exist — which is the longer part of the job.

Backup: the most widespread misunderstanding of all

Microsoft guarantees that the service will be available. It does not guarantee the recovery of your content after a deletion, an encryption or a mistake.

Recycle bins exist but have limited retention, and an attack carried out with valid credentials is logged as legitimate activity: nothing triggers. By the time the problem is noticed, the retention may already have expired.

You need an independent copy, under the same rules as any other backup: outside the perimeter, with previous versions retained and at least one copy that cannot be altered. We cover it on the off-site backup page.

What we look at in a review

The rest

See also Microsoft 365 support for day-to-day management, IT security for the complete picture and off-site backup for the independent copy.

The first step

A review of your Microsoft 365 environment with the corrections listed in order of risk, separating those that can be applied straight away from those that need a decision. Free and without obligation.

Frequently asked questions

Are Microsoft 365's default settings secure?

They are designed to make everything work immediately, not to protect. In the initial configuration mail accepts automatic forwarding rules to external addresses, file sharing can create links accessible to anyone holding the address, and audit logs do not always cover a period long enough to reconstruct an incident. None of these is a defect in the product - they are convenience choices that need revisiting in a business context.

Why is automatic forwarding so dangerous?

Because it is silent. Whoever gets into a mailbox with stolen credentials does not need to come back: they set a rule forwarding a copy of all the mail and then sit reading for months without doing anything else detectable. It is the mechanism behind most bank-details fraud, because it lets the attacker wait for the right moment while knowing the conversation.

Is enabling the second factor for all users enough?

It is the first step and on its own covers much of the risk, but it needs two things alongside it. The first is disabling the older mail protocols, which in some configurations allow access bypassing the second factor entirely. The second is protecting the administrative accounts first, which are often the least looked after because one person uses them.

Does data in Microsoft 365 need a backup?

Yes, and this is the most widespread misunderstanding. Microsoft guarantees the availability of the service, not the recovery of your content after a deletion or an encryption. Recycle bins have limited retention, and an attack carried out with valid credentials is logged as legitimate activity. You need an independent copy, under the same rules as any other backup - outside the perimeter and unalterable.

How long does it take to secure a tenant?

The three main corrections are applied in a few hours and do not require interrupting anyone's work. A complete review - permissions, existing shares, logs, protocols, privileged accounts - takes a few days, and the longest part is almost always cleaning up the sharing links created over the years.

Is your Microsoft 365 configured properly?

Almost every tenant starts with default settings that leave open what nobody uses. Let us look at how yours is set up.