Your Microsoft 365 tenant may look perfectly healthy. Users are sending emails, Teams meetings are running, and files are being shared every day.
But what is hiding in the dark corners?
Behind the familiar Microsoft 365 apps, businesses often leave security settings untouched, permissions unchecked and accounts active long after they are needed. These overlooked gaps can create a clear path for attackers, even when your staff believe they are working in a secure cloud environment.
This is the uncomfortable truth: Microsoft provides the platform, but your organisation is responsible for configuring, monitoring and managing it properly.
As Halloween approaches, it is time to shine a light into the shadows. Here are the most common Microsoft 365 security blind spots SMEs need to address, and how Microsoft 365 managed services can help you fortify your tenant.
Is MFA Really Protecting Everyone?
What is it?
Multi-Factor Authentication (MFA) requires users to prove their identity using more than just a password. This could involve an authenticator app, security key, biometric check or one-time code.
MFA is one of the most effective protections against stolen passwords. However, many businesses enforce it only for standard employees while leaving gaps around:
- Global Administrators
- Old administrator accounts
- Temporary users
- Service accounts
- Shared mailboxes
- External collaborators
- Emergency or “break-glass” accounts
How it works
Attackers actively search for accounts that can sign in using only a password. A dormant admin account with no MFA can be more dangerous than an active employee account because it may have extensive access and attract little attention.
Service accounts require particular care. Some cannot use interactive MFA in the traditional way, so they should be replaced or redesigned using tightly scoped application identities, certificates or workload identities wherever possible. Simply leaving them exempt is not a secure long-term solution.
Your checklist:
- Enforce MFA for every suitable user and administrator.
- Remove unnecessary per-user MFA exceptions.
- Reduce the number of standing Global Administrators.
- Review emergency access accounts and monitor their use.
- Replace legacy service account approaches with modern, restricted authentication.
Are Legacy Protocols Still Creeping Through the Door?
What is it?
Legacy authentication includes older methods such as POP3, IMAP, SMTP AUTH and outdated Office clients. These protocols were designed before modern identity security became standard.
In many cases, they cannot properly support MFA or modern risk-based access controls.
How it works
A business may believe MFA is enabled, while an old mail client or protocol quietly allows password-only access. If a criminal obtains a password, they may be able to use that older route to access mail without triggering the protections you expected.
The risks include:
- Unauthorised mailbox access
- Credential stuffing attacks
- Silent email theft
- Increased exposure to business email compromise
- Difficult-to-trace sign-ins from unfamiliar locations
Microsoft recommends disabling legacy authentication unless there is a documented and controlled reason to retain it. If an exception is unavoidable, it should be restricted, monitored and given a clear retirement date.
Leaving legacy access enabled “just in case” is not future-proofing. It is preserving a legacy entrance that attackers already know how to find.
Who Still Has Access to Your Tenant?
What is it?
User lifecycle management is the process of creating, changing and removing access as people join, move within or leave your organisation.
Without a consistent process, Microsoft 365 tenants accumulate:
- Dormant user accounts
- Former employees with active licences
- Unused guest accounts
- Orphaned SharePoint permissions
- Shared mailboxes with unknown owners
- Third-party applications no one remembers approving
How it works
Every unused identity increases your attack surface. A former employee’s account may still contain emails, OneDrive files, Teams conversations and access to shared business data.
Licence sprawl also creates a direct financial risk. You may be paying for Microsoft 365 licences that no longer serve a business purpose, while active users may not have the security capabilities they actually need.
A regular review should identify:
- Which accounts are inactive.
- Which licences are assigned but unused.
- Which guests still require access.
- Which users hold excessive permissions.
- Which applications have access to email or files.
This is where Reduced Financial Risk and Improved Compliance meet. Good licence management saves money, while good access management reduces exposure.
Are Guests and External Links Sharing More Than Intended?
What is it?
Microsoft Teams, SharePoint and OneDrive make collaboration easy. They also make it easy to share information beyond your organisation.
Settings such as “Anyone with the link” can be useful in limited circumstances, but they can also allow sensitive files to travel far beyond their intended audience.
How it works
A link created for a supplier or project may remain active indefinitely. A guest added to a Team may retain access after a contract ends. A document shared with one external person may be forwarded or copied elsewhere.
Potential consequences include:
- Confidential documents being downloaded externally
- Customer or financial information being exposed
- Former suppliers retaining access
- Sensitive Teams conversations being accessible to unnecessary guests
- Compliance investigations becoming harder to manage
Practical controls include:
- Prefer named recipients over anonymous links.
- Limit external sharing to approved domains where appropriate.
- Review guest users and shared links regularly.
- Use sensitivity labels and Data Loss Prevention (DLP) where licensing supports them.
- Establish owners for Teams, SharePoint sites and shared workspaces.
- Remove access when a project ends.
Collaboration should be productive, not invisible. If no one owns the permissions, no one can confidently explain who can access the data.
Are Attackers Quietly Redirecting Your Email?
Mailbox forwarding rules and inbox rules are among the most unsettling threats because they can operate quietly in the background.
An attacker who compromises a mailbox may:
- Create an inbox rule that hides replies
- Forward invoices to an external address
- Redirect executive correspondence
- Monitor negotiations and payment instructions
- Search for passwords, contracts or customer information
- Alter or delete evidence of suspicious activity
These changes may not immediately disrupt the user. That makes them particularly valuable to criminals conducting business email compromise.
Your organisation should monitor for:
- New external forwarding rules
- Changes to mailbox permissions
- Suspicious delegate access
- Unusual transport rules
- Sign-ins followed by rule creation
- Unexpected changes to finance or executive mailboxes
External auto-forwarding should be restricted wherever practical. High-risk changes should also generate alerts and be linked to an approved administrative process.
Is Conditional Access Actually Making Decisions?
What is it?
Conditional Access applies rules based on factors such as user, location, device health, application, sign-in risk and sensitivity of the requested resource.
It moves your security model beyond “correct password equals access”.
How it works
A modern policy might require:
- MFA for all users
- Stronger controls for administrators
- A compliant device for access to sensitive data
- Blocked sign-ins from high-risk locations
- Restricted access from unsupported devices
- Legacy authentication to be blocked
- Additional verification for risky sign-ins
However, Conditional Access is only useful if it is correctly designed, tested and applied to the right users. Common gaps include policies that exclude administrators, exceptions created for convenience and device compliance requirements that are never enforced.
The modern approach is not to block everything. It is to apply proportionate controls that protect your information without making work unnecessarily difficult.
Microsoft’s security guidance for small and medium-sized businesses covers MFA, admin protection, device security, Teams, file sharing and ongoing maintenance.
Can You See What Is Happening Inside the Tenant?
What is it?
Audit logging records important activity across Microsoft 365, including sign-ins, file access, administrator changes, mailbox activity and application permissions.
How it works
Logs are only valuable when they are enabled, retained appropriately and reviewed. A tenant may technically have audit data available, but if nobody monitors it, suspicious activity can remain hidden.
You should be able to investigate questions such as:
- Who added a new Global Administrator?
- When was an external forwarding rule created?
- Which user consented to a high-risk application?
- Who accessed a sensitive SharePoint file?
- When did a Conditional Access policy change?
- Was an unusual sign-in followed by data downloads?
Without reliable logging, incident response becomes guesswork. That can increase downtime, remediation costs and regulatory pressure.
What Do Microsoft 365 Managed Services Include?
Microsoft 365 managed services provide ongoing expertise rather than a one-off setup. At Stevens I.T. Solutions, this can include:
- Secure Microsoft 365 setup and migration
- MFA, Conditional Access and tenant hardening
- User onboarding and offboarding
- Licence allocation and optimisation
- Teams, SharePoint and OneDrive governance
- Monitoring for risky sign-ins and suspicious changes
- Mailbox and forwarding rule oversight
- Security and compliance reporting
- Microsoft 365 backup and recovery planning
- Strategic advice as your business grows
A managed approach helps replace the old “set and forget” model with continuous improvement. It also gives your business a clear owner for the security work that is otherwise likely to remain unfinished.
Microsoft 365 managed services can also help you prepare for Microsoft Copilot. Copilot readiness is not simply about purchasing licences. It requires sensible permissions, clean data, controlled sharing and confidence that users can only surface information they are authorised to see.
How Can You Uncover the Shadows with Ease?
Start with a structured tenant review. Prioritise the controls that close the most dangerous gaps:
- Enforce MFA and review all administrative exceptions.
- Disable legacy authentication wherever possible.
- Remove dormant accounts, unnecessary guests and unused licences.
- Review external sharing across Teams, SharePoint and OneDrive.
- Monitor mailbox forwarding, inbox rules and permission changes.
- Apply Conditional Access to users, devices and risky sign-ins.
- Enable and review audit logging.
- Check third-party applications and OAuth permissions.
- Strengthen email security with SPF, DKIM and DMARC.
- Schedule regular reporting rather than treating security as a once-a-year project.
The threats hiding inside your tenant are real, but they are manageable. You do not need to navigate every Microsoft 365 setting alone.
Stevens I.T. Solutions helps businesses move from legacy, reactive IT to secure, modern and properly managed technology. Whether you are a sole trader or an organisation with up to 500 employees, our team can uncover the gaps, fortify your environment and simplify the process with ease.
Explore our Microsoft 365 security and compliance services or contact Stevens I.T. Solutions for a practical review of your tenant.
.png)



