Microsoft 365 is the most widely used productivity platform for Australian businesses — and it is the most targeted. The combination of email, file storage, video conferencing, and identity management in a single cloud service makes it extraordinarily valuable to attackers. When a Microsoft 365 account is compromised, an attacker potentially has access to every email ever sent, all files in SharePoint and OneDrive, the entire Teams chat history, and a platform from which to launch attacks on other staff. The problem is that a newly provisioned M365 tenant is not configured securely by default.
The Default Settings That Leave You Exposed
MFA Is Not Enforced by Default
While Microsoft has made MFA "Security Defaults" available and enabled it for new tenants created after October 2019, many existing tenants have it disabled — or have it enabled through Security Defaults but with no Conditional Access policies to enforce it for specific scenarios. Security Defaults is a good start, but it is an all-or-nothing setting that doesn't allow the fine-grained control needed for a business environment. Properly configured Conditional Access policies are the right approach.
Legacy Authentication Is Often Still Enabled
Legacy authentication protocols — including Basic Auth used by older versions of Outlook, IMAP, POP3, and some line-of-business applications — do not support MFA. An attacker who has a user's password can connect directly via a legacy protocol and bypass MFA entirely. Microsoft has been progressively deprecating legacy auth in Exchange Online, but it may still be enabled in your tenant, particularly if you have older applications or devices that rely on it. Blocking legacy authentication is one of the highest-impact security changes you can make.
No Audit Logging
Microsoft 365 has comprehensive audit logging capabilities, but audit log retention varies by licence and must be configured. Without adequate audit logging, you have no visibility into who accessed what, when files were deleted or shared, or what an attacker did inside a compromised account. If you experience a security incident, audit logs are essential for understanding the scope of the compromise.
Exchange Online Misconfiguration
Several Exchange Online settings require attention. External email forwarding rules — where a compromised account has been configured to automatically forward all emails to an external address — are a common attacker technique that can persist undetected for weeks. Audit your tenant for any auto-forwarding rules that weren't explicitly configured by your IT team. Anti-phishing and anti-spoofing policies in Microsoft Defender for Office 365 also require configuration beyond the default to provide meaningful protection.
No Data Loss Prevention Policies
Microsoft 365's Data Loss Prevention (DLP) capabilities can detect and prevent sensitive information — such as credit card numbers, Tax File Numbers, and health information — from being emailed externally or saved to unmanaged devices. These policies are not configured by default and require deliberate setup.
Overly Permissive External Sharing
SharePoint Online and OneDrive default external sharing settings often allow users to share files with anyone outside the organisation via an anonymous link — no authentication required. This means a user can accidentally share sensitive documents with the entire internet. External sharing policies should be reviewed and restricted to specific domains or require recipient authentication as a minimum.
Microsoft Secure Score: Your Baseline Metric
Microsoft provides a free tool called Secure Score within the Microsoft 365 Defender portal. It analyses your tenant configuration and assigns a score out of a maximum, with recommendations ranked by impact. A Secure Score below 50% suggests significant basic configuration work is needed.
Recommended Baseline Hardening Steps
- Enable and configure Conditional Access policies, including MFA enforcement and device compliance requirements.
- Block legacy authentication across the entire tenant.
- Enable and review unified audit logging; configure alerts for suspicious activities.
- Audit and disable all unauthorised auto-forwarding rules in Exchange Online.
- Configure anti-phishing, anti-spoofing, and Safe Links policies in Microsoft Defender for Office 365.
- Restrict external sharing in SharePoint and OneDrive to authenticated recipients.
- Review and implement DLP policies appropriate to your data classification.
- Implement third-party backup for Microsoft 365 data — Microsoft's built-in retention is not a substitute for backup.
Why M365 Data Needs Third-Party Backup
Microsoft's service agreement makes it clear that their responsibility is service uptime, not your data. Microsoft does not back up your mailboxes or files in a way that allows point-in-time recovery after accidental deletion, ransomware encryption, or a departing employee's deliberate data destruction. A third-party backup solution — such as Veeam Backup for Microsoft 365 or Acronis — provides genuine recoverable backups of Exchange Online, SharePoint, OneDrive, and Teams data with configurable retention periods.
Key Takeaways
- Microsoft 365 is not secure by default — significant configuration work is required to meet a reasonable security baseline.
- Blocking legacy authentication is one of the highest-impact changes you can make — it prevents MFA bypass via older protocols.
- Check your Microsoft Secure Score as a free baseline assessment — it highlights the most impactful improvements with clear instructions.
- Microsoft does not back up your data — a third-party backup solution for M365 is essential for genuine data protection.