Five Microsoft 365 Settings Most SMBs Get Wrong (And How to Fix Them)

Microsoft 365 is secure-capable, not secure-by-default. Here are the five settings we most often find misconfigured — and why each one matters.

Microsoft 365 ships secure-capable, not secure-by-default. The platform includes strong security tools, but most of the protective settings sit off or loosely configured out of the box — because Microsoft optimizes the default experience for ease of setup, not for a regulated small business's risk profile. Here are the five gaps we see most often when we review a new client's tenant for the first time.

1. Security defaults are on, but conditional access isn't. Microsoft's "Security Defaults" toggle is a reasonable baseline — it enforces MFA for all users — but it's an all-or-nothing switch with no nuance. Businesses that need more control (for example, requiring MFA every time from unmanaged devices but trusting recognized company laptops) need Conditional Access policies instead, which require at least an Entra ID P1 license. Many SMBs are still running only Security Defaults years after they outgrew what it can do.

2. Legacy authentication protocols are still enabled. Older protocols like POP3, IMAP, and SMTP AUTH don't support modern MFA at all — meaning a compromised password alone is enough to access mail through them, completely bypassing whatever MFA policy is configured elsewhere. Attackers know this and specifically probe for it. Legacy authentication should be disabled tenant-wide unless a specific, documented business application still requires it.

3. Mailbox forwarding rules aren't being monitored. One of the most common signs of a compromised mailbox is a quiet auto-forwarding rule an attacker sets up to silently copy incoming email — often targeting finance or HR mailboxes to intercept invoices or wire instructions. Microsoft 365 can alert on new forwarding rules, but that alerting has to be explicitly configured; it isn't active by default.

4. Shared mailboxes and generic accounts don't have MFA enforced. It's common to find a shared "info@" or "billing@" mailbox that multiple staff log into directly with a shared password and no MFA, specifically because enforcing MFA on a shared mailbox used to be awkward. Modern Microsoft 365 supports better patterns for this — shared mailbox access through individual accounts rather than shared logins — but the old habit persists in a lot of tenants.

5. Audit logging is available but not actually reviewed. Microsoft 365 can log virtually every meaningful action — sign-ins, file access, permission changes, mailbox rule creation — but logging exists in a lot of tenants purely because it's technically on, not because anyone is watching it. Without active review or alerting tied to specific high-risk events, the logs are only useful after the fact, during an investigation, rather than catching something as it happens.

The pattern across all five: Microsoft 365 gives you the tools, but almost none of the protective configuration is automatic. A tenant that was set up quickly to get a business running — which describes most SMB tenants — usually has significant gaps between what's technically possible and what's actually configured.

If it's been a while since anyone did a full review of your tenant's security settings, that's usually a half-day project, not a major overhaul — and it closes some of the most commonly exploited gaps we see in real incidents.

Ready to Stop Worrying About IT and Security?

Book a free 30-minute discovery call. No pressure, no jargon — just a straight conversation about where your business stands today.

Schedule a Discovery Call

Right Icon