Most Microsoft 365 tenants we get called in to look at aren’t broken, they’re just never finished. Someone switched on the licenses, added users, and moved on. That’s enough to send email and open a spreadsheet. It’s not the same as being set up properly, and the gap between the two is where most of the risk sits.
MFA that’s enabled but not enforced
Multi-factor authentication being available and MFA being required are two different states, and we still find tenants where it’s the former. Conditional access policies that actually enforce MFA for every sign-in, not just admin accounts, close one of the most common and most preventable routes into a business’s mailboxes.
No real conditional access policy
Beyond MFA, conditional access is where you control what “normal” looks like for your business: which locations, which devices, which risk levels get treated differently. Without it, every sign-in is treated the same whether it’s a laptop in the office or an unfamiliar device somewhere else entirely. This is usually a half-day of configuration, not a project.
Mailbox and file permissions that outlived the person who set them
Shared mailboxes with a dozen forgotten delegates. SharePoint sites still open to “everyone” from a migration two years ago. Former employees whose accounts are disabled but whose OneDrive is still silently shared with three other people. None of this shows up until someone goes looking, which is exactly the problem.
No data loss prevention policy at all
DLP doesn’t need to be aggressive to be useful. Even a baseline policy that flags obvious things, card numbers, national insurance numbers, leaving the tenant by email, catches the accidental cases that make up the majority of real incidents. Most businesses running Microsoft 365 for years still have this switched off entirely.
License spend nobody has looked at since day one
This one isn’t a security gap, it’s a cost one. Licensing tiers get chosen once, at setup, based on whatever seemed reasonable at the time, and then nobody revisits it as the team changes. We regularly find businesses paying for premium tiers that half their users don’t need, and a handful of users on a lower tier who’d genuinely benefit from an upgrade.
None of this is really about Microsoft 365
Every one of these gaps is the same shape: something was configured once, at the start, and never looked at again. That’s true of Azure environments too, it’s the whole reason Support Packs exist as an ongoing thing rather than a one-off project. Microsoft 365 just tends to be the one that gets set up fastest and reviewed least, because it feels finished the moment email works.
If you want us to take a look at where your tenant actually stands, get in touch.