Skip to main content

Stevens IT Solutions Ltd

Cart
£0.00
0

Get to Know Us

About Us
Find out about Stevens IT Solutions
Our Core Values
See what matters most to us
Mission Statement
Discover our mission and purpose
Our Climate Pledge
Our commitment to a greener future
Contact Us
Get in touch with us

IT Support for All

Computer Repairs
Discover our full range of home computer repair services, diagnostics, virus removal, data recovery, upgrades, and more.
Laptop Repairs
Discover our full range of home laptop repair services, diagnostics, virus removal, data recovery, upgrades, and more.
Gaming PC Repairs
Expert repairs and upgrades for your gaming PC. From performance issues and overheating to hardware faults and system crashes, we’ll get your rig running smoothly and ready for action.
New Build Gaming PC
Custom-built gaming PCs designed for power, performance, and precision. Whether you want a high-end setup or a budget-friendly build, we’ll create a system tailored to your gaming needs.
Data Erasure
Secure, certified data erasure for home and business users. We permanently remove your data from computers, laptops, and storage devices, ensuring your personal or company information stays protected.
IT Recycling
Environmentally responsible recycling for your old tech. We safely dispose of or repurpose unwanted computers and IT equipment, helping you clear space while reducing electronic waste.

Managed IT Services

IT Support
Comprehensive IT support for your business, both on-site and remotely. We proactively manage and maintain your systems, resolving issues quickly to minimise downtime and keep your operations running smoothly.
Printers and Copiers
Streamline your office printing with our managed print solutions. We supply, install, and configure printers and copiers to suit your business needs, ensuring reliable performance, cost control, and ongoing support.
Mobile Device Management (MDM)
Securely manage and monitor all your business mobile devices from one central platform. We help deploy, update, and protect smartphones and tablets, ensuring your team stays connected and data remains safe.
Managed Networks and Secure Wifi
Reliable, secure networking solutions for your business. We design, install, and manage networks and Wi-Fi, ensuring fast, stable connections while protecting your data and devices from threats.
Business Continuity and Disaster Recovery
Protect your business from unexpected disruptions. We help plan, implement, and manage strategies to ensure your systems, data, and operations can recover quickly and keep your business running.

Cyber Security

Security Operations Centre (SOC)
24/7 monitoring and protection for your business IT systems. Our Security Operations Centre detects, investigates, and responds to cyber threats, helping safeguard your data and maintain operational security.
Endpoint Security
Protect all your business devices from malware, viruses, and cyber threats. We secure desktops, laptops, and mobile devices, ensuring your systems and data remain safe and your operations run smoothly.
Cloud Security
Protect your business data and applications in the cloud. We implement robust security measures, monitor for threats, and ensure your cloud systems remain safe, compliant, and reliable.
Microsoft 365 Security and Compliance
Keep your Microsoft 365 environment secure and compliant. We protect your emails, files, and collaboration tools while helping you meet regulatory requirements and safeguard sensitive business data.
Dark Web Monitoring
Stay one step ahead of cyber threats. We monitor the dark web for compromised credentials and sensitive business data, alerting you quickly so you can take action to protect your organisation.
Vulnerability Assessment
Identify and address security weaknesses in your systems before they can be exploited. We assess your networks, devices, and applications, helping you strengthen defences and reduce risk.
Email Security
Protect your business email from phishing, malware, and spam. We secure your inboxes, monitor for threats, and help ensure safe, reliable communication across your organisation.
Human Risk Management (HRM)
Reduce the risk of cyber threats caused by human error. We provide training, awareness programmes, and best-practice guidance to help your team make smarter, safer decisions when using technology.
Password Manager
Securely store, generate, and manage all your passwords in one place. We help businesses protect access to systems and data while making it easy for your team to use strong, unique credentials.

Cloud Services

Productivity

Microsoft 365
Empower your business with Microsoft 365 productivity tools. We provide setup, management, and support for emails, collaboration apps, and cloud services to help your team work efficiently and securely.
Microsoft 365 Add-Ons
Enhance your Microsoft 365 environment with additional tools and features. We help businesses integrate add-ons for productivity, security, and collaboration, tailored to your specific needs.
Microsoft Copilot
Boost productivity with Microsoft Copilot’s AI-powered assistance. We help integrate Copilot into your Microsoft 365 environment to streamline tasks, enhance collaboration, and make work smarter and faster.
Microsoft Dynamics 365
Transform your business operations with Microsoft Dynamics 365. We provide setup, integration, and support for CRM and ERP solutions, helping you manage sales, finance, and customer relationships efficiently.
Power Platform Solutions
Unlock the full potential of your business with Microsoft Power Platform. We help design, build, and support custom apps, workflows, and analytics to automate processes and drive efficiency.
Email Signature Management
Ensure consistent, professional email signatures across your organisation. We help design, deploy, and manage signatures that reflect your brand while including compliance and legal requirements.

Backup and Storage

Cloud Backup
Keep your business data safe and accessible with secure cloud backups. We protect files, applications, and systems, ensuring you can quickly recover information in the event of loss or disruption.
Microsoft 365 Backup
Protect your business data in Microsoft 365 with secure, automated backups. We ensure emails, files, and Teams data are safely stored and can be quickly restored if lost or compromised.
Microsoft 365 Email Archiving
Securely store and manage your business emails for compliance and easy retrieval. We help retain, organise, and protect email data, ensuring it’s accessible when you need it and meets regulatory requirements.

Communications and IOT

Microsoft Teams Phones
Enhance business communication with Microsoft Teams Phones. We provide setup, configuration, and support for Teams-enabled devices, enabling seamless calls, collaboration, and productivity across your organisation.
Business Mobile Sims
Stay connected with business mobile SIMs from O2, Vodafone, and EE. We provide setup, management, and support to ensure your team has reliable, flexible mobile connectivity for work on the go.
Business Broadband
Coming Soon
VOIP
Coming Soon

Share this page:

The Dark Corners of Your Microsoft 365 Tenant (and Who’s Hiding There)

The Dark Corners of Your Microsoft 365 Tenant (and Who’s Hiding There)

Your Microsoft 365 tenant may look perfectly healthy. Users are sending emails, Teams meetings are running, and files are being shared every day.

But what is hiding in the dark corners?

Behind the familiar Microsoft 365 apps, businesses often leave security settings untouched, permissions unchecked and accounts active long after they are needed. These overlooked gaps can create a clear path for attackers, even when your staff believe they are working in a secure cloud environment.

This is the uncomfortable truth: Microsoft provides the platform, but your organisation is responsible for configuring, monitoring and managing it properly.

As Halloween approaches, it is time to shine a light into the shadows. Here are the most common Microsoft 365 security blind spots SMEs need to address, and how Microsoft 365 managed services can help you fortify your tenant.

Is MFA Really Protecting Everyone?

What is it?

Multi-Factor Authentication (MFA) requires users to prove their identity using more than just a password. This could involve an authenticator app, security key, biometric check or one-time code.

MFA is one of the most effective protections against stolen passwords. However, many businesses enforce it only for standard employees while leaving gaps around:

  • Global Administrators
  • Old administrator accounts
  • Temporary users
  • Service accounts
  • Shared mailboxes
  • External collaborators
  • Emergency or “break-glass” accounts

How it works

Attackers actively search for accounts that can sign in using only a password. A dormant admin account with no MFA can be more dangerous than an active employee account because it may have extensive access and attract little attention.

Service accounts require particular care. Some cannot use interactive MFA in the traditional way, so they should be replaced or redesigned using tightly scoped application identities, certificates or workload identities wherever possible. Simply leaving them exempt is not a secure long-term solution.

Your checklist:

  • Enforce MFA for every suitable user and administrator.
  • Remove unnecessary per-user MFA exceptions.
  • Reduce the number of standing Global Administrators.
  • Review emergency access accounts and monitor their use.
  • Replace legacy service account approaches with modern, restricted authentication.

Abstract cloud identity gateway with authentication key and connected user nodes

Are Legacy Protocols Still Creeping Through the Door?

What is it?

Legacy authentication includes older methods such as POP3, IMAP, SMTP AUTH and outdated Office clients. These protocols were designed before modern identity security became standard.

In many cases, they cannot properly support MFA or modern risk-based access controls.

How it works

A business may believe MFA is enabled, while an old mail client or protocol quietly allows password-only access. If a criminal obtains a password, they may be able to use that older route to access mail without triggering the protections you expected.

The risks include:

  • Unauthorised mailbox access
  • Credential stuffing attacks
  • Silent email theft
  • Increased exposure to business email compromise
  • Difficult-to-trace sign-ins from unfamiliar locations

Microsoft recommends disabling legacy authentication unless there is a documented and controlled reason to retain it. If an exception is unavoidable, it should be restricted, monitored and given a clear retirement date.

Leaving legacy access enabled “just in case” is not future-proofing. It is preserving a legacy entrance that attackers already know how to find.

Who Still Has Access to Your Tenant?

What is it?

User lifecycle management is the process of creating, changing and removing access as people join, move within or leave your organisation.

Without a consistent process, Microsoft 365 tenants accumulate:

  • Dormant user accounts
  • Former employees with active licences
  • Unused guest accounts
  • Orphaned SharePoint permissions
  • Shared mailboxes with unknown owners
  • Third-party applications no one remembers approving

How it works

Every unused identity increases your attack surface. A former employee’s account may still contain emails, OneDrive files, Teams conversations and access to shared business data.

Licence sprawl also creates a direct financial risk. You may be paying for Microsoft 365 licences that no longer serve a business purpose, while active users may not have the security capabilities they actually need.

A regular review should identify:

  1. Which accounts are inactive.
  2. Which licences are assigned but unused.
  3. Which guests still require access.
  4. Which users hold excessive permissions.
  5. Which applications have access to email or files.

This is where Reduced Financial Risk and Improved Compliance meet. Good licence management saves money, while good access management reduces exposure.

Are Guests and External Links Sharing More Than Intended?

What is it?

Microsoft Teams, SharePoint and OneDrive make collaboration easy. They also make it easy to share information beyond your organisation.

Settings such as “Anyone with the link” can be useful in limited circumstances, but they can also allow sensitive files to travel far beyond their intended audience.

How it works

A link created for a supplier or project may remain active indefinitely. A guest added to a Team may retain access after a contract ends. A document shared with one external person may be forwarded or copied elsewhere.

Potential consequences include:

  • Confidential documents being downloaded externally
  • Customer or financial information being exposed
  • Former suppliers retaining access
  • Sensitive Teams conversations being accessible to unnecessary guests
  • Compliance investigations becoming harder to manage

Practical controls include:

  • Prefer named recipients over anonymous links.
  • Limit external sharing to approved domains where appropriate.
  • Review guest users and shared links regularly.
  • Use sensitivity labels and Data Loss Prevention (DLP) where licensing supports them.
  • Establish owners for Teams, SharePoint sites and shared workspaces.
  • Remove access when a project ends.

Collaboration should be productive, not invisible. If no one owns the permissions, no one can confidently explain who can access the data.

Interconnected cloud folders and collaboration nodes protected by a glowing shield barrier

Are Attackers Quietly Redirecting Your Email?

Mailbox forwarding rules and inbox rules are among the most unsettling threats because they can operate quietly in the background.

An attacker who compromises a mailbox may:

  • Create an inbox rule that hides replies
  • Forward invoices to an external address
  • Redirect executive correspondence
  • Monitor negotiations and payment instructions
  • Search for passwords, contracts or customer information
  • Alter or delete evidence of suspicious activity

These changes may not immediately disrupt the user. That makes them particularly valuable to criminals conducting business email compromise.

Your organisation should monitor for:

  • New external forwarding rules
  • Changes to mailbox permissions
  • Suspicious delegate access
  • Unusual transport rules
  • Sign-ins followed by rule creation
  • Unexpected changes to finance or executive mailboxes

External auto-forwarding should be restricted wherever practical. High-risk changes should also generate alerts and be linked to an approved administrative process.

Is Conditional Access Actually Making Decisions?

What is it?

Conditional Access applies rules based on factors such as user, location, device health, application, sign-in risk and sensitivity of the requested resource.

It moves your security model beyond “correct password equals access”.

How it works

A modern policy might require:

  • MFA for all users
  • Stronger controls for administrators
  • A compliant device for access to sensitive data
  • Blocked sign-ins from high-risk locations
  • Restricted access from unsupported devices
  • Legacy authentication to be blocked
  • Additional verification for risky sign-ins

However, Conditional Access is only useful if it is correctly designed, tested and applied to the right users. Common gaps include policies that exclude administrators, exceptions created for convenience and device compliance requirements that are never enforced.

The modern approach is not to block everything. It is to apply proportionate controls that protect your information without making work unnecessarily difficult.

Microsoft’s security guidance for small and medium-sized businesses covers MFA, admin protection, device security, Teams, file sharing and ongoing maintenance.

Can You See What Is Happening Inside the Tenant?

What is it?

Audit logging records important activity across Microsoft 365, including sign-ins, file access, administrator changes, mailbox activity and application permissions.

How it works

Logs are only valuable when they are enabled, retained appropriately and reviewed. A tenant may technically have audit data available, but if nobody monitors it, suspicious activity can remain hidden.

You should be able to investigate questions such as:

  • Who added a new Global Administrator?
  • When was an external forwarding rule created?
  • Which user consented to a high-risk application?
  • Who accessed a sensitive SharePoint file?
  • When did a Conditional Access policy change?
  • Was an unusual sign-in followed by data downloads?

Without reliable logging, incident response becomes guesswork. That can increase downtime, remediation costs and regulatory pressure.

Abstract security monitoring graphic with audit trails, alert pulses and a magnifying glass over a secure cloud

What Do Microsoft 365 Managed Services Include?

Microsoft 365 managed services provide ongoing expertise rather than a one-off setup. At Stevens I.T. Solutions, this can include:

  • Secure Microsoft 365 setup and migration
  • MFA, Conditional Access and tenant hardening
  • User onboarding and offboarding
  • Licence allocation and optimisation
  • Teams, SharePoint and OneDrive governance
  • Monitoring for risky sign-ins and suspicious changes
  • Mailbox and forwarding rule oversight
  • Security and compliance reporting
  • Microsoft 365 backup and recovery planning
  • Strategic advice as your business grows

A managed approach helps replace the old “set and forget” model with continuous improvement. It also gives your business a clear owner for the security work that is otherwise likely to remain unfinished.

Microsoft 365 managed services can also help you prepare for Microsoft Copilot. Copilot readiness is not simply about purchasing licences. It requires sensible permissions, clean data, controlled sharing and confidence that users can only surface information they are authorised to see.

How Can You Uncover the Shadows with Ease?

Start with a structured tenant review. Prioritise the controls that close the most dangerous gaps:

  1. Enforce MFA and review all administrative exceptions.
  2. Disable legacy authentication wherever possible.
  3. Remove dormant accounts, unnecessary guests and unused licences.
  4. Review external sharing across Teams, SharePoint and OneDrive.
  5. Monitor mailbox forwarding, inbox rules and permission changes.
  6. Apply Conditional Access to users, devices and risky sign-ins.
  7. Enable and review audit logging.
  8. Check third-party applications and OAuth permissions.
  9. Strengthen email security with SPF, DKIM and DMARC.
  10. Schedule regular reporting rather than treating security as a once-a-year project.

The threats hiding inside your tenant are real, but they are manageable. You do not need to navigate every Microsoft 365 setting alone.

Stevens I.T. Solutions helps businesses move from legacy, reactive IT to secure, modern and properly managed technology. Whether you are a sole trader or an organisation with up to 500 employees, our team can uncover the gaps, fortify your environment and simplify the process with ease.

Explore our Microsoft 365 security and compliance services or contact Stevens I.T. Solutions for a practical review of your tenant.

Stevens I.T. Solutions logo