Back to Blog
Microsoft 365 5 February 2026 · 8 min read

Microsoft 365 Security: The Gaps Most Businesses Don't Know They Have

Microsoft 365 is the most widely used productivity platform for Australian businesses — and it is the most targeted. The combination of email, file storage, video conferencing, and identity management in a single cloud service makes it extraordinarily valuable to attackers. When a Microsoft 365 account is compromised, an attacker potentially has access to every email ever sent, all files in SharePoint and OneDrive, the entire Teams chat history, and a platform from which to launch attacks on other staff. The problem is that a newly provisioned M365 tenant is not configured securely by default.

The Default Settings That Leave You Exposed

MFA Is Not Enforced by Default

While Microsoft has made MFA "Security Defaults" available and enabled it for new tenants created after October 2019, many existing tenants have it disabled — or have it enabled through Security Defaults but with no Conditional Access policies to enforce it for specific scenarios. Security Defaults is a good start, but it is an all-or-nothing setting that doesn't allow the fine-grained control needed for a business environment. Properly configured Conditional Access policies are the right approach.

Legacy Authentication Is Often Still Enabled

Legacy authentication protocols — including Basic Auth used by older versions of Outlook, IMAP, POP3, and some line-of-business applications — do not support MFA. An attacker who has a user's password can connect directly via a legacy protocol and bypass MFA entirely. Microsoft has been progressively deprecating legacy auth in Exchange Online, but it may still be enabled in your tenant, particularly if you have older applications or devices that rely on it. Blocking legacy authentication is one of the highest-impact security changes you can make.

No Audit Logging

Microsoft 365 has comprehensive audit logging capabilities, but audit log retention varies by licence and must be configured. Without adequate audit logging, you have no visibility into who accessed what, when files were deleted or shared, or what an attacker did inside a compromised account. If you experience a security incident, audit logs are essential for understanding the scope of the compromise.

Exchange Online Misconfiguration

Several Exchange Online settings require attention. External email forwarding rules — where a compromised account has been configured to automatically forward all emails to an external address — are a common attacker technique that can persist undetected for weeks. Audit your tenant for any auto-forwarding rules that weren't explicitly configured by your IT team. Anti-phishing and anti-spoofing policies in Microsoft Defender for Office 365 also require configuration beyond the default to provide meaningful protection.

No Data Loss Prevention Policies

Microsoft 365's Data Loss Prevention (DLP) capabilities can detect and prevent sensitive information — such as credit card numbers, Tax File Numbers, and health information — from being emailed externally or saved to unmanaged devices. These policies are not configured by default and require deliberate setup.

Overly Permissive External Sharing

SharePoint Online and OneDrive default external sharing settings often allow users to share files with anyone outside the organisation via an anonymous link — no authentication required. This means a user can accidentally share sensitive documents with the entire internet. External sharing policies should be reviewed and restricted to specific domains or require recipient authentication as a minimum.

Microsoft Secure Score: Your Baseline Metric

Microsoft provides a free tool called Secure Score within the Microsoft 365 Defender portal. It analyses your tenant configuration and assigns a score out of a maximum, with recommendations ranked by impact. A Secure Score below 50% suggests significant basic configuration work is needed.

Recommended Baseline Hardening Steps

Why M365 Data Needs Third-Party Backup

Microsoft's service agreement makes it clear that their responsibility is service uptime, not your data. Microsoft does not back up your mailboxes or files in a way that allows point-in-time recovery after accidental deletion, ransomware encryption, or a departing employee's deliberate data destruction. A third-party backup solution — such as Veeam Backup for Microsoft 365 or Acronis — provides genuine recoverable backups of Exchange Online, SharePoint, OneDrive, and Teams data with configurable retention periods.

Key Takeaways

Category: Microsoft 365 Published: 5 February 2026 Read time: 8 minutes Author: Xen IT Team

Need help protecting your business?

Xen IT can audit your Microsoft 365 tenant, fix the security gaps, and implement ongoing monitoring to keep your environment hardened.

Get a Free Assessment