Abstract dark navy and purple graphic representing Microsoft 365 security audit
|

Is Your Microsoft 365 Tenant Actually Secure? What We Check

Microsoft 365 is the backbone of most South African businesses. Email, files, teams, identity. But the default configuration is built for convenience, not security. We have yet to audit an M365 tenant where everything was properly locked down.

Conditional access

This is the first thing we look at. Conditional access policies are the rules that say who can access what, from where, with what device. If you do not have any, anyone with a username and password can log in from any device on any network. That includes attackers who bought your credentials from a breach database for R50.

The basics: require MFA for all users, not just admins. Block legacy authentication protocols that bypass MFA. Restrict admin access to compliant devices only. If you are still allowing IMAP and SMTP basic auth, that is a gap.

Global admin sprawl

How many global admins do you have? The right number is between 2 and 5, depending on the size of the organisation. We regularly see 15, 20, sometimes 30 global admins. Every one of those accounts is a full keys-to-the-kingdom compromise if it gets phished. Most of them do not need global admin. They need a scoped role that lets them do their job without being able to reset every password in the tenant.

DLP and data exfiltration

Data loss prevention in M365 is not on by default. Without it, anyone can download their entire mailbox to a PST file, share a SharePoint folder with a personal email address, or sync the company OneDrive to a home computer. If you do not have DLP policies, you are trusting that nobody will ever leave and take data with them. That is not a strategy.

What an audit actually looks like

When we audit an M365 tenant, we look at about 40 things. Conditional access, admin roles, DLP, mail flow rules, external sharing settings, audit log retention, mobile device management, sensitivity labels, and a long list of configuration defaults that Microsoft leaves open because they do not know your business.

The output is a prioritised list. What is critical, what should be fixed in 30 days, what is nice to have. Not a 60-page report. Something you can act on.

We manage M365 environments for businesses that do not have the time or the specialist skills to do this themselves. That includes ongoing administration, security hardening, and the regular configuration reviews that keep falling through the cracks. Contact us if you want to know what your tenant looks like from the outside.

Audit log retention

Audit logs in M365 are retained for 90 days by default. If you only discover an incident three months after it happened, the logs are gone. TheUnified audit log should be retained for at least a year, and for organisations with compliance requirements, longer. This is a configuration that Microsoft leaves to you, and most businesses never change it.

External sharing and guest access

SharePoint and OneDrive default to allowing external sharing. Anyone in your organisation can share a document with a personal email address, and that person gets access without any approval process. For some businesses that is fine. For most, it is a data leak waiting to happen. We check the external sharing settings, the guest access policies, and whether there is any governance around who can invite external users and how long their access lasts.

Teams guest access is another common gap. If guests can join teams without approval, and those teams contain sensitive files, you have external users with access to internal data that nobody is tracking.

Mail flow rules and forwarding

One of the most common ways data leaves an organisation is through mail forwarding rules. An attacker who has compromised a mailbox sets up a rule to forward all incoming email to an external address. The user never sees it, the admin never sees it, and the data flows out quietly. We check every tenant for hidden forwarding rules, and we find them more often than not.

Auto-forwarding to external domains should be blocked by default. If there is a business need, it should go through an approved process, not a setting that any user can change. This is a simple control that prevents a significant data leak, and it is off by default in most tenants.

Mobile device management

If your staff access M365 from personal phones and there is no mobile device management policy, you have no control over what happens to company data on those devices. No remote wipe, no compliance check, no app protection policy. If someone loses a phone with company email on it, the only option is a password change and hope.

Microsoft Intune is included in many M365 plans, and basic MDM can be enabled in an afternoon. It does not need to be heavy-handed — app protection policies that prevent copy-paste to personal apps and allow remote wipe of company data are enough for most businesses. But it needs to be turned on.

Want to know what attackers can see about your business? We run a free attack-surface scan for South African companies. It’s passive, so nothing gets touched. You get a plain English report in your inbox. Start here: free security scan

Need Help With Your Security or IT?

We work with South African businesses to assess, deploy, and manage security and IT that actually fits. No jargon, no scare tactics. Practical advice and real support.

Contact Us →

See what hackers can see about your business

Get your free security scan

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *