Microsoft 365 Security: Are You Actually Protected or Just Subscribed?

Having a Microsoft 365 subscription is not the same as being protected by Microsoft 365. This is one of the most common and most costly misunderstandings in business IT today.

Microsoft 365 is an extraordinarily capable platform, and it includes a significant suite of security tools. But those tools don't configure themselves. Most businesses are running Microsoft 365 with default settings, and the default settings leave substantial security gaps that attackers know how to exploit.

This guide explains what's missing, what it matters, and what you need to do about it.

Why Default Settings Are Insufficient

Microsoft designs its default configurations to balance usability and security. For a consumer product, that balance makes sense. For a business protecting sensitive data and critical operations, the defaults are not adequate.

The reason isn't that Microsoft has made poor decisions — it's that security controls often create friction, and Microsoft's defaults prioritise accessibility over protection. Enabling security controls requires configuration decisions that depend on understanding your business and your risk profile. Microsoft can't make those decisions for you.

The result is that the vast majority of Microsoft 365 tenants are running with a security posture significantly below what the platform is capable of providing.

Multi-Factor Authentication

Microsoft's own data indicates that MFA blocks over 99% of account compromise attacks. Despite this, a significant proportion of Microsoft 365 tenants do not have MFA enforced for all users.

The reasons are usually practical: nobody set it up, some users pushed back on the inconvenience, or there are legacy systems or processes that don't support MFA and it was disabled rather than fixed.

None of these are sufficient reasons to leave your accounts without MFA. The inconvenience of MFA is trivial compared to the cost of an account compromise.

MFA should be enforced through Conditional Access policies, not just enabled as an option. The difference is significant: enabling MFA gives users the option to set it up; Conditional Access enforces it for every login from every location. Conditional Access also allows you to create nuanced policies — requiring stricter authentication from unfamiliar locations or unmanaged devices.

Defender for Office 365

This is where the default gap is most significant and most consequential. Microsoft Defender for Office 365 (included in Business Premium and above) provides Safe Links and Safe Attachments capabilities that fundamentally change the security posture of your email environment.

Safe Links rewrites URLs in emails and documents and checks them at click time against Microsoft's threat intelligence. If someone clicks a link that leads to a malicious site, Safe Links blocks the connection. This is enormously valuable protection against phishing attacks, where links may be benign at the time of delivery but later redirect to malicious destinations.

Safe Attachments detonates email attachments in a sandboxed environment before delivering them to the user. If an attachment contains malware, it's blocked before it reaches the inbox. This isn't just signature-based detection; it's behavioural analysis of what the attachment actually does when opened.

Neither of these controls is enabled by default. They require explicit configuration.

Email Authentication (DMARC, DKIM, SPF)

Email authentication is the set of controls that prevent attackers from sending emails that appear to come from your domain. Without them, an attacker can send a convincing phishing email to your clients or suppliers that appears to come from a legitimate address in your domain.

SPF (Sender Policy Framework) defines which servers are authorised to send email on behalf of your domain. DKIM (DomainKeys Identified Mail) provides a cryptographic signature that verifies an email was sent from an authorised source. DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receiving mail servers what to do with messages that fail SPF and DKIM checks.

These records need to be configured in your DNS settings. Microsoft provides guidance, and any competent IT provider should be able to implement them. The consequence of not having them is that your domain can be used by attackers in phishing campaigns — against your clients, your suppliers, or your staff.

Privileged Identity Management

Admin accounts are the most valuable accounts in your Microsoft 365 environment. If an attacker gains access to a global admin account, they have complete control over your tenant.

Most businesses run with too many permanent admin accounts, and those accounts are used for routine day-to-day activities — reading email, accessing documents — as well as administrative functions. This is unnecessary risk.

Microsoft Entra Privileged Identity Management (available in some licence tiers) provides just-in-time admin access — admin permissions that are activated on request for a specific period, rather than permanently assigned. This dramatically reduces the window of exposure if an admin account is compromised.

Audit Logging and Threat Detection

Microsoft 365 generates detailed audit logs of user and admin activity. These logs are invaluable for investigating security incidents — but only if they're being collected and reviewed.

Microsoft Defender for Cloud Apps (formerly MCAS) provides visibility into cloud application usage, detects suspicious activity patterns, and can enforce policy controls. Microsoft Sentinel, Microsoft's SIEM platform, can aggregate and analyse security signals from across your Microsoft 365 environment.

For smaller businesses, Microsoft Secure Score is a useful starting point — it scores your security configuration against Microsoft's recommendations and provides actionable guidance on improvements.

Practical Steps to Close the Gaps

An audit of your Microsoft 365 security configuration is the starting point. This should cover authentication policies, Defender for Office 365 configuration, email authentication records, admin account management, and data loss prevention policies.

Many of these gaps can be closed relatively quickly with the right knowledge and access. The challenge is knowing what to look for and having the time and expertise to address it systematically.

We regularly audit Microsoft 365 tenants for businesses across West Sussex and find significant gaps in the vast majority of cases. If you want to understand exactly what your configuration looks like and what needs to change, get in touch. The assessment is free, and the improvements are often straightforward.

Previous
Previous

Incident Response Planning: What Happens When Your Business Gets Hacked?

Next
Next

Managed IT vs Break-Fix: Which Model Costs Less in the Long Run?