Back to all articles
Best Practices

Top 10 Microsoft 365 Security Misconfigurations We See in Every Audit

After scanning hundreds of M365 tenants, these are the most common security gaps — and how to fix them in under 30 minutes.

TenantVigil TeamApril 8, 20263 min read
M365SecurityMFAConditional AccessExchange Online

After scanning hundreds of Microsoft 365 tenants across industries, we've identified a consistent pattern of security misconfigurations that leave organizations exposed. Here are the top 10 — ranked by how often we see them — along with actionable fixes.

1. MFA Not Enforced for All Users

Prevalence: 73% of tenants

Multi-Factor Authentication remains the single most impactful security control. Yet nearly three-quarters of organizations still have users who can authenticate with just a password.

Fix: Enable Security Defaults in Entra ID, or deploy Conditional Access policies requiring MFA for all users.

2. Legacy Authentication Protocols Enabled

Prevalence: 68% of tenants

Protocols like POP3, IMAP, and SMTP Basic Auth bypass MFA entirely. Attackers actively exploit these in password spray campaigns.

Fix: Create a Conditional Access policy that blocks legacy authentication. Monitor sign-in logs for 30 days first to identify dependencies.

3. No Conditional Access Policies

Prevalence: 54% of tenants

Without Conditional Access, there's no way to enforce location-based restrictions, device compliance, or risk-based authentication.

Fix: Start with three baseline policies: Require MFA for admins, block legacy auth, and require MFA for risky sign-ins.

4. External Sharing Over-Permissioned in SharePoint

Prevalence: 61% of tenants

Default SharePoint settings allow anyone with a link to access shared content — including external users without authentication.

Fix: Restrict external sharing to "Existing guests" or "Only people in your organization" at the tenant level. Use sensitivity labels for exceptions.

5. Mailbox Forwarding Rules to External Domains

Prevalence: 41% of tenants

Auto-forwarding rules are a favorite persistence mechanism for attackers who've compromised an account.

Fix: Block auto-forwarding to external domains via a transport rule in Exchange Online. Audit existing forwarding rules immediately.

6. No Admin Account Separation

Prevalence: 58% of tenants

Global Admins using the same accounts for daily email and web browsing creates unnecessary attack surface.

Fix: Create dedicated admin accounts (admin-user@domain.com) with no mailbox. Use Privileged Identity Management (PIM) for just-in-time access.

7. Audit Logging Not Enabled

Prevalence: 37% of tenants

Without unified audit logging, you can't investigate incidents or detect suspicious activity.

Fix: Enable Unified Audit Log in the Microsoft Purview compliance portal. Set retention to at least 90 days.

8. Default Password Policies Too Weak

Prevalence: 45% of tenants

Short password requirements and no banned password list leave accounts vulnerable to brute force attacks.

Fix: Require 14+ character passwords, enable Azure AD Password Protection with custom banned words, and disable password expiration (per NIST guidance).

9. No Data Loss Prevention Policies

Prevalence: 62% of tenants

Sensitive data like credit card numbers and SSNs can be shared freely via email, Teams, and SharePoint without any DLP controls.

Fix: Start with Microsoft's built-in DLP templates for financial data and PII. Apply to Exchange, SharePoint, and Teams.

10. Intune Device Compliance Not Configured

Prevalence: 49% of tenants

Even organizations with Intune often haven't configured compliance policies, meaning unmanaged and unpatched devices access corporate data freely.

Fix: Create baseline compliance policies requiring OS updates, encryption, and PIN/password. Pair with Conditional Access to block non-compliant devices.


How TenantVigil Helps

TenantVigil automatically checks for all 10 of these misconfigurations — plus 40 more security controls — every time you run a scan. Try a free assessment to see where your tenant stands.

Check your tenant's security posture

Run a free, read-only assessment of your Microsoft 365 configuration in under 2 minutes.

Free Assessment