5 Microsoft 365 Security Settings Every Business Should Verify

Microsoft has strengthened many Microsoft 365 security defaults over the last few years, but those changes do not always apply to existing tenants. If your Microsoft 365 environment was set up before 2022, inherited from a previous IT provider, or left unaudited for years, you may still be relying on outdated settings that increase your cyber risk.

Legacy configurations can leave gaps in file sharing, email forwarding, app permissions, audit log retention, and MFA enforcement. These settings are worth reviewing now, especially for businesses that rely on managed IT services or cloud-based productivity tools.

A few of these changes may require Microsoft 365 Business Premium, E3, or E5 licensing. Some may also generate support questions from users because they change familiar workflows. Even so, they are all worth checking, and you do not need to address them all at once.

1. Review SharePoint and OneDrive sharing defaults

One of the most common Microsoft 365 risks is overexposed file sharing. In older tenants, SharePoint and OneDrive sharing links may still default to “Anyone with the link,” which means anyone who receives the URL can open the file without signing in.

That can create serious data security issues if a former employee, vendor, or customer still has access to a shared file. Newer Microsoft 365 environments often default to more secure sharing settings, but older sites may still allow anonymous access.

Check the SharePoint admin center under Policies > Sharing. Set the default link type to “Specific people” whenever possible, and apply expiration dates to any remaining anonymous sharing links. This helps reduce unauthorized access and improves cloud data protection.

2. Confirm external email forwarding is blocked

Automatic email forwarding to outside addresses is a common data leakage risk. Microsoft now blocks this by default in many tenants, but older outbound spam policies or legacy configurations may still allow it.

A user may have created a forwarding rule years ago that still sends company email to a personal inbox. That creates a major security and compliance concern, especially if sensitive client or financial data is involved.

In the Microsoft Defender portal, review Email & Collaboration > Policies & Rules > Anti-spam policies > Anti-spam outbound policy. Confirm that automatic forwarding is set to “Off” or “Automatic - System-controlled.” Then audit existing inbox rules across mailboxes to identify any forward-to-external configurations.

3. Review historical third-party app consents

Third-party app access can create hidden risk in Microsoft 365 and Microsoft Entra ID. Microsoft changed user consent behavior so that new consent requests are more tightly controlled, but older permissions may still be active.

This means an app approved years ago may still have access to files, mail, calendar data, or other resources. Many businesses forget these apps exist, especially if they were installed for a one-time project or by a former employee.

Go to Microsoft Entra ID > Enterprise Applications > All applications and review apps that were granted user consent. Look for anything with access to mail, files, or calendars, and revoke permissions for anything unnecessary or unrecognized. This is an important step in reducing third-party risk and strengthening SaaS security.

4. Verify audit log retention settings

Audit log retention is essential for security investigations, compliance, and incident response. Microsoft 365 audit retention changed in October 2023, but your actual retention period depends on licensing and configuration.

For many organizations, the default audit retention period may still be too short for legal, financial, or regulatory needs. If you work in healthcare, financial services, legal, or another regulated industry, you may need longer retention to support compliance requirements and investigations.

Review Audit > Audit retention policies in the Microsoft Purview compliance portal. Confirm whether your business needs extended retention and whether your licensing supports it. Longer audit retention can be especially valuable for cybersecurity monitoring, eDiscovery, and compliance audits.

5. Check MFA enforcement and Security Defaults

Multi-factor authentication remains one of the most important Microsoft 365 security controls, but older tenants often have inconsistent MFA enforcement. Security Defaults may be disabled in legacy environments, and Conditional Access policies may not cover every user account.

This is especially risky if administrator accounts or emergency access accounts are excluded from MFA policies. In some tenants, Security Defaults are off because Conditional Access was introduced without fully replacing the original baseline protections.

Check three areas in Microsoft Entra ID:

  • Properties > Manage Security Defaults.

  • Protection > Conditional Access.

  • Administrative and break-glass accounts.

Make sure MFA is enforced for all users, including admins, and confirm that every exception is intentional and documented. This is one of the most important steps in protecting your cloud environment from account takeover and phishing attacks.

Recommended order for implementation

Not every change should be made at the same time. Some settings are invisible to users, while others affect daily workflows.

Start with audit retention and third-party app consent reviews, since these usually have no user impact. Next, verify external email forwarding rules. After that, update file sharing defaults, since that may require user communication and education.

Save MFA and Conditional Access review for last. That is the highest-risk change and the one most likely to cause lockouts if it is not planned carefully.

Final thoughts

Microsoft 365 is more secure out of the box than it used to be, but older tenants may still carry legacy settings that create unnecessary risk. Reviewing these five areas can improve data protection, reduce exposure, and support better compliance across your business.

If you need help reviewing Microsoft 365 security settings, improving cloud security, or partnering with a managed IT provider, Hoop5 can help you identify gaps and strengthen your environment.

For more tips and tech info, follow us on LinkedIn and Instagram. 

Inspired by insights from The Technology Press.

Previous
Previous

What to Check Before Turning on Microsoft 365 Copilot

Next
Next

How Small Business Ransomware Attacks Work and How to Stop Them