Microsoft 365 is one of the most secure productivity platforms on the market. It comes packed with sophisticated security tools, compliance features, and threat protection capabilities. There’s just one problem: most of them are not turned on by default.
Out of the box, Microsoft 365 is configured for ease of use and broad compatibility — not maximum security. That makes it accessible for new users, but it also means thousands of businesses are running Microsoft 365 every day with critical security gaps they don’t know exist. Here are the most common and consequential settings we find missing when we audit a new client’s environment.
1. Multi-Factor Authentication (MFA) Is Not Enforced
This is the single most impactful security control available in Microsoft 365 — and it’s consistently the most underdeployed. MFA requires users to verify their identity with a second factor (an app notification, a code, a hardware key) in addition to their password.
Microsoft’s own data shows that MFA blocks 99.9% of account compromise attacks. Even if an attacker has a user’s password through phishing or a data breach, MFA stops them from accessing the account. Despite this, many organizations have MFA available but not required — leaving accounts vulnerable to exactly the attacks it was designed to prevent.
2. Legacy Authentication Protocols Are Still Enabled
Older email protocols — IMAP, POP3, SMTP Auth, and Basic Authentication — don’t support MFA. If these protocols are enabled in your tenant, attackers can bypass MFA entirely by targeting legacy authentication endpoints. Many breaches that occur in “MFA-protected” environments exploit exactly this gap.
Blocking legacy authentication is one of the most effective steps you can take to protect your Microsoft 365 environment — but it requires careful configuration to avoid disrupting legitimate users and systems.
3. Microsoft Defender for Office 365 Features Are Underutilized
Microsoft 365 Business Premium and higher plans include Defender for Office 365, which provides powerful protection against email threats. However, its most effective features require explicit configuration:
- Safe Links — rewrites URLs in emails and documents and checks them in real time when clicked, blocking malicious links even after they’ve been delivered
- Safe Attachments — detonates attachments in a sandbox environment before delivery to detect malware that evades traditional signature-based detection
- Anti-phishing policies — detects impersonation attempts of your executives, domains, and trusted senders
These features can be configured in minutes and dramatically reduce the risk of email-based attacks — but they require someone to actually configure them.
4. Audit Logging Is Disabled
Microsoft 365 can log virtually every action taken in your environment — who signed in from where, which emails were accessed, what files were downloaded, when admin settings were changed. This audit trail is invaluable for detecting suspicious activity and investigating incidents after they occur.
However, unified audit logging must be explicitly enabled. Without it, you’re flying blind — and you may not know an account was compromised until months after the fact.
5. Admin Accounts Are Used for Daily Tasks
Global Administrator accounts in Microsoft 365 have unrestricted access to everything in your tenant. Using these accounts for day-to-day tasks — reading email, attending meetings, browsing the web — unnecessarily exposes your most powerful credentials to everyday risks.
Best practice is to create separate, dedicated admin accounts used only for administrative tasks, while daily work happens in standard user accounts with minimal permissions. Ideally, admin accounts should also use hardware security keys rather than software MFA.
6. Conditional Access Policies Are Not Configured
Conditional Access is one of Microsoft 365’s most powerful security features. It allows you to define rules for when and how users can access company resources — requiring MFA when logging in from new locations, blocking access from certain countries, requiring compliant devices for sensitive applications.
Without Conditional Access policies, a user’s credentials are the only barrier between an attacker and your organization’s data — regardless of where the attacker is or what device they’re using.
Get a Microsoft 365 Security Assessment
These six settings represent the most common and consequential security gaps we find in Microsoft 365 environments — but they’re far from the only ones. A comprehensive security configuration review covers dozens of additional settings across identity, email, endpoint, and data protection.
Adaptive IT provides Microsoft 365 security assessments and ongoing configuration management as part of our Managed Security Services. We review your tenant against Microsoft’s security benchmarks, identify gaps, and implement the right controls — without disrupting your team’s productivity.
Contact us today to schedule your Microsoft 365 security review.