Default settings exist to make things work, not to protect
This distinction is worth understanding, because it explains almost every problem we find. Microsoft 365 arrives configured to reduce friction: everything works immediately, nobody gets blocked, adoption is fast. It is a sensible choice for a product sold to millions of different organisations.
In a business context those same choices become exposures, and the three that weigh most are always the same.
1. Automatic forwarding to external addresses
This is the most underestimated mechanism and the one behind the most expensive frauds.
An attacker who obtains the credentials to a mailbox — bought in a list, or handed over on a fake login page — does not need to come back. They set a rule forwarding a copy of all the mail and then do nothing else detectable. They sit reading for weeks, learn how you talk to your suppliers, and step in only when a payment is under way.
It is why the request to change bank details always arrives at exactly the right moment, inside a genuine conversation. There is nothing anomalous to block: there is a mail rule nobody has looked at.
The fix: block automatic forwarding to external addresses at organisation level, and check the rules that already exist — because if somebody is already inside, that rule is there now.
2. The second factor, and the protocols that bypass it
Enabling the second factor is the single measure with the highest return, and that much is well known. Less well known is that in some configurations mail can be reached bypassing it, using older protocols that do not support a second factor at all.
While those protocols stay enabled, a stolen password keeps working. They should be disabled at the same time as the second factor is enabled, not afterwards.
There is also an order of priority almost everybody gets wrong: everyone’s mail is protected while the administrative accounts are left uncovered — the accounts with the worst consequences and often the least looked after, because one person uses them.
3. Sharing links
Sharing a file with a link is convenient and gets used constantly. The problem is that the link stays valid until somebody revokes it, and nobody revokes it.
In assessments we regularly find company documents reachable by anyone holding the address, created years earlier to send to a supplier who no longer works with the company. It is not a dramatic breach: it is a door left ajar and forgotten.
The fix comes in two parts: setting rules for the future about who can create which kind of link and with what expiry, and reviewing the ones that already exist — which is the longer part of the job.
Backup: the most widespread misunderstanding of all
Microsoft guarantees that the service will be available. It does not guarantee the recovery of your content after a deletion, an encryption or a mistake.
Recycle bins exist but have limited retention, and an attack carried out with valid credentials is logged as legitimate activity: nothing triggers. By the time the problem is noticed, the retention may already have expired.
You need an independent copy, under the same rules as any other backup: outside the perimeter, with previous versions retained and at least one copy that cannot be altered. We cover it on the off-site backup page.
What we look at in a review
- Accounts and privileges: how many administrators actually exist, and how many should;
- Second factor: who has it enabled, and whether any route bypasses it;
- Mail rules: external forwarding already configured, which is also how a compromise in progress gets discovered;
- Active shares: existing public links and their expiry;
- Audit logs: whether they are enabled and for how long they retain, because without them nothing can be reconstructed;
- Mail protection: filtering, sender verification, attachment handling;
- Dormant accounts: mailboxes belonging to people who have left, still active and still licensed.
The rest
See also Microsoft 365 support for day-to-day management, IT security for the complete picture and off-site backup for the independent copy.
The first step
A review of your Microsoft 365 environment with the corrections listed in order of risk, separating those that can be applied straight away from those that need a decision. Free and without obligation.