Many organizations never review their Microsoft 365 tenant settings after the initial setup. As Microsoft continues to strengthen security across its platform, older Microsoft 365 tenant settings can remain unchanged for years, creating unnecessary security and compliance risks.
 
If your Microsoft 365 tenant was set up several years ago—or inherited from a previous IT provider—many of those newer security improvements may not have been applied automatically. Legacy configurations often remain in place, creating hidden vulnerabilities that attackers can exploit.That’s why it’s important to periodically review your Microsoft 365 environment and ensure critical settings align with current security best practices.

Here are five Microsoft 365 tenant settings every business should review.

 

1. Review Microsoft 365 Tenant Settings for SharePoint and OneDrive Sharing

File sharing makes collaboration easy. Unfortunately, outdated sharing settings can also make sensitive information easier to access than you intended.

In many older Microsoft 365 tenants, files shared from SharePoint or OneDrive may still default to “Anyone with the link.” This means anyone who receives the URL can open the file without signing in or verifying their identity.
 

Why This Matters

When sharing links don’t require authentication:

  • Files can be forwarded outside your organization.
  • Former employees may retain access.
  • You lose visibility into who is viewing documents.
  • Sensitive business information can be exposed.

What to Check

Review the sharing settings in the SharePoint Admin Center and verify the default sharing link type.

For most organizations, “Specific People” or “Only People in Your Organization” provides stronger security while still supporting collaboration. You should also consider applying expiration dates to external sharing links

 

2. Check Microsoft Tenant Settings for Email Forwarding

 
Cybercriminals love email forwarding rules because they can quietly move company data outside your environment without drawing attention.

Microsoft now blocks automatic forwarding to external email addresses by default in many Microsoft 365 environments. However, older forwarding rules and legacy configurations may still be active.
 

Why This Matters

An employee may have configured a forwarding rule years ago that automatically sends emails to a personal account.

If that account is compromised, confidential information could be exposed without anyone realizing it.

What to Check

Review:

  • Tenant-wide anti-spam policies
  • Existing inbox forwarding rules
  • Historical forwarding configurations

Removing unnecessary forwarding rules is a simple step that can significantly improve security.
 

3. Strengthen Microsoft 365 Tenant

Every time a user connects a third-party application to Microsoft 365, they may grant access to organizational data.

Over time, those permissions add up.

Many businesses discover applications that were approved years ago and forgotten entirely. Some may still have access to:

  • Email
  • Calendars
  • OneDrive files
  • SharePoint documents
  • Microsoft Teams data

Microsoft introduced stricter user consent policies in recent years, but previously approved applications may still retain their access.
 

Why This Matters

Unused applications create unnecessary security risks.

If a connected app is compromised, attackers may gain access to company data without directly breaching Microsoft 365.

What to Check

Review Enterprise Applications within Microsoft Entra ID and identify:

  • Unused applications
  • Duplicate applications
  • Unknown applications
  • Apps with excessive permissions

Removing unnecessary access helps reduce your overall attack surface.
 

4. Audit Log Retention Settings

If your organization experiences a security incident, audit logs can help answer critical questions:

  • What happened?
  • When did it happen?
  • Who accessed the data?
  • Which systems were affected?

Microsoft extended standard audit log retention from 90 days to 180 days, but that timeline may not satisfy your compliance requirements.
 

Why This Matters

Organizations in healthcare, finance, legal services, and other regulated industries often need access to audit records for much longer periods.

Without adequate retention policies, important evidence may no longer be available when it’s needed most.

What to Check

Review your audit retention policies in Microsoft Purview and verify they align with:

  • Compliance requirements
  • Cyber insurance requirements
  • Internal security policies
  • Regulatory obligations

Longer retention periods can be invaluable during investigations and audit
 

5. MFA Enforcement and Security Defaults

If there’s one setting you should prioritize, it’s multi-factor authentication (MFA).

MFA remains one of the most effective ways to prevent unauthorized access, even when passwords have been stolen.

The challenge is that older Microsoft 365 tenants often contain inconsistent MFA configurations due to previous migrations, licensing changes, or incomplete deployments.
 

Why This Matters

Many organizations assume MFA is fully enforced when it isn’t.

Common issues include:

  • Administrator accounts without MFA
  • Legacy accounts excluded from policies
  • Incomplete Conditional Access rules
  • Disabled Security Defaults

Each of these gaps creates opportunities for attackers.
 

What to Check

Review:

  • Security Defaults
  • Conditional Access policies
  • Administrative accounts
  • Emergency access accounts
  • MFA coverage across all users

A consistent MFA strategy helps strengthen security across your entire Microsoft 365 tenant.
 

A Smart Approach to Prioritizing Changes

Not every update needs to happen immediately.

Start with changes that have little impact on users:

  1. Audit log retention
  2. Third-party application review
  3. External email forwarding checks

Next, address sharing settings and communicate any changes to employees before implementation.

Finally, review MFA and Conditional Access policies carefully. While these settings offer some of the greatest security benefits, they also require proper planning to avoid disrupting users.
 

When Was the Last Time Your Microsoft 365 Tenant Was Reviewed?

Many businesses assume Microsoft automatically updates every security setting as new protections become available. In reality, older configurations often remain untouched for years.

A periodic Microsoft 365 tenant review can help identify outdated settings, reduce cybersecurity risk, improve compliance, and ensure your environment aligns with current best practices.

At Universal Data Inc., we help organizations evaluate their Microsoft 365 security posture, identify vulnerabilities, and implement practical improvements that protect users, data, and business operations.
 

Ready to Review Your Microsoft 365 Tenant?

If your Microsoft 365 environment hasn’t been reviewed recently—or you’re unsure how it’s currently configured—now is the time to take a closer look.

Contact us to schedule a Microsoft 365 security assessment and ensure your tenant is configured to protect your business.

error: Content is protected !!