Microsoft 365 security How to harden your tenant beyond the defaults
Oct 6, 2026
Microsoft 365 security depends on settings the defaults leave open, so identity, email, sharing, and data controls can end up weaker than policy requires even when the platform itself is secure. Mis-scoped access rules, open collaboration defaults, short log-retention windows, and later configuration drift can expose data and weaken audit evidence. Fixing them requires deliberate tenant hardening, documented reviews, and continuous visibility into configuration changes.
CoreView reported that 45% of large organizations experienced a security or compliance incident caused by a Microsoft 365 misconfiguration in the past 12 months. The same research, which draws on an analysis of 1.6 million Microsoft 365 users, found that 90% of organizations struggle to enforce even basic security controls, including password policies and failed-login monitoring.
Those are configuration failures, and configuration sits on the customer's side of Microsoft's shared responsibility model. Microsoft secures the platform itself, including the data centers, the hypervisors, and the service code. Tenant settings, from sharing defaults to MFA policy scoping, remain the customer's responsibility, and many of those defaults favor collaboration over restriction. Effective hardening requires deliberate configuration, documented evidence, and a review cadence that catches drift over time.
Why default Microsoft 365 settings aren't enough
Microsoft's shared responsibility model reduces to one sentence: Microsoft secures the infrastructure, while the customer retains responsibility for data, accounts, endpoints, and access management, even in SaaS.
Microsoft provides security defaults out of the box and enables them on all new tenants. Security Defaults enforce multi-factor authentication (MFA) registration for all users, require MFA for 16 administrator roles, block legacy authentication protocols, and, starting July 1, 2026, block device code flow on new tenants. That is a genuinely useful baseline and the maximum protection available without additional configuration.
Security Defaults offer no middle ground: they're on or off, with no exclusions for break-glass accounts, no device-compliance or location conditions, no risk-based policies, and no just-in-time admin elevation. They also can't coexist with Conditional Access; enabling one disables the other. Organizations needing granular control and exceptions should use Conditional Access instead.
The same pattern repeats across the suite. The Standard and Strict email protection presets "are assigned to no one" until an administrator assigns them, external sharing is on by default, and administrators must create data loss prevention (DLP) policies.
Identity and access configuration
Identity is where most tenant compromises start, and it's also where Microsoft leaves the most configuration to the customer. Hardening identity means strengthening authentication, enforcing access policy consistently, and cutting standing privilege down to what emergency access actually requires.
Enforce MFA and eliminate legacy authentication
Move privileged accounts to phishing-resistant MFA and confirm legacy authentication is blocked everywhere. Microsoft's authentication strengths rank the Fast Identity Online 2 (FIDO2) authentication standard, Windows Hello for Business, and certificate-based authentication as phishing-resistant; push notifications and time-based one-time password (TOTP) codes are not, because adversary-in-the-middle kits relay them.
The Tycoon2FA kit reached over 500,000 organizations per month, and Proofpoint's broader 2025 research found that 59% of accounts taken over industrywide had MFA enabled. On the legacy side, Microsoft's data shows more than 97% of credential-stuffing attacks use legacy authentication. Microsoft has disabled basic authentication in all Exchange Online tenants, with Simple Mail Transfer Protocol authentication (SMTP AUTH) the remaining exception until the end of December 2026.
Netwrix Auditor tracks changes in Entra ID, including who made them, when, and the values before and after, so a hardened setting that gets rolled back leaves a record. Request a demo.
Configure Conditional Access policies
Build Conditional Access around device compliance, location, and risk, and run every policy in enforcement mode. A solid Conditional Access foundation on Entra ID P1 includes MFA for admins, MFA for all users, blocking legacy authentication, and requiring compliant devices; risk-based sign-in and user policies require Entra ID P2.
Huntress found that 55 of 78 compromised accounts it analyzed had active Conditional Access policies requiring MFA, but the policies failed anyway due to incorrect scoping, report-only mode, or condition mismatches. That makes enforcement mode the detail that decides outcomes. Exclude your emergency access accounts from these policies so a misfire leaves emergency administrative access available.
Audit and govern admin roles
Cut standing Global Administrator assignments down to your emergency-access accounts and route everything else through Privileged Identity Management (PIM). Limit Global Administrator assignments to fewer than five; Microsoft's admin center alerts you once a tenant crosses that threshold.
PIM requires Entra ID P2. PIM deployments should carry zero permanently active assignments outside emergency access, with activation windows of 1–24 hours and at least two approvers. The two permanent exceptions should be cloud-only break-glass accounts on the *.onmicrosoft.com domain that remain independent of federation and synchronization.
Email and collaboration hardening
Microsoft 365's collaboration surface, spanning email, SharePoint, OneDrive, and Teams, ships with defaults that favor ease of use over restriction. Hardening it means tightening authentication, sharing permissions, and mailbox-rule visibility before a misconfiguration becomes an incident.
Email authentication and anti-phishing
Publish Sender Policy Framework (SPF) with a hard fail, enable DomainKeys Identified Mail (DKIM) on every custom domain, and move Domain-based Message Authentication, Reporting, and Conformance (DMARC) to p=reject. The standard SPF record is v=spf1 include:spf.protection.outlook.com -all, with -all recommended once DKIM and DMARC are also in place. DMARC should progress from p=none through p=quarantine to p=reject.
Inbound filtering needs the same attention, because the default anti-phishing policy leaves impersonation protection and phishing thresholds unconfigured. The Standard preset raises the phishing threshold to level 3 ("More aggressive") and configures impersonation protection, while Strict sends suspected messages to quarantine.
Safe Links and Safe Attachments require Defender for Office 365. Business Premium includes it, and E3 has included it since July 1, 2026. The built-in Configuration Analyzer compares your tenant against the Standard and Strict baselines and includes a configuration drift analysis tab.
External sharing controls
Tighten SharePoint and OneDrive sharing before users generate links you can't recall. Microsoft enables external sharing by default across the environment, sets OneDrive's default link type to "Anyone with the link," and allows Anyone links to bypass Conditional Access unmanaged-device policies entirely.
Set the organization level to guests only, change the default link type to specific people, and apply domain allow or block lists, which support up to 5,000 domains. Teams needs a parallel pass. Microsoft enables guest access, federation with all external domains, and anonymous meeting join by default. Restrict federation to trusted domains and set lobby bypass to people in your organization.
Mailbox rule and auto-forwarding hygiene
Set outbound auto-forwarding to Off explicitly because the displayed default can vary by tenant age. The default reads "Automatic - System-controlled," which behaves as Off for tenants created since 2021 but can remain equivalent to On for older tenants, so set the value explicitly rather than trusting the display.
Close the parallel path with the remote-domain command Set-RemoteDomain -Identity Default -AutoForwardEnabled $false. Then audit inbox rules on high-risk accounts. Mailbox auditing logs rule operations by default.
Proofpoint research found that roughly 10% of compromised accounts in Q4 2025 had malicious mailbox rules created after access, with the fastest observed rule creation just 5 seconds after takeover.
Data protection configuration
Microsoft 365 data protection doesn't happen automatically. Sensitivity labels, DLP policies, and audit log retention all depend on administrators actively configuring them, and the defaults leave sensitive content unlabeled and under-logged until someone does.
Sensitivity labels and DLP policies
Enable label processing for SharePoint and OneDrive first, because downstream controls depend on it. The label-processing prerequisite is Set-SPOTenant -EnableAIPIntegration $true; after administrators apply it, a label and its encryption remain with the file wherever users store it, including after download.
Container labels on Teams and SharePoint sites don't flow down to the items inside them, and auto-labeling requires E5-tier licensing. Plan around both before rollout.
To block downloads to unmanaged devices, Set-SPOTenant -ConditionalAccessPolicy AllowLimitedAccess enforces browser-only access with no download, print, or sync. Those session controls don't support the Teams desktop application. For DLP itself, deploy in simulation mode first, review matches, then move to enforcement.
Retention and audit log configuration
Extend audit log retention past the default before an investigation forces the issue. Audit (Standard) retains records for 180 days. Audit (Premium) on E5 extends Entra ID, Exchange, SharePoint, and OneDrive events to one year, with a separate add-on reaching ten years.
IBM reported the average breach lifecycle at 241 days, and the Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 requires twelve months of audit log retention. Sophos found logs missing in 47% of incident cases it analyzed.
Entra ID sign-in logs run on a separate clock, with retention of just seven days on the free tier and 30 days on P1/P2.
The configuration drift problem
Huntress analyzed more than 12,000 tenants and found more than 50% of recommended controls missing in 60% of them, including environments that already used posture tooling. Microsoft's Secure Score history tracks regressions caused by configuration, user, or device changes.
Administrators roll back settings to unblock a project, exceptions accumulate as staff turns over, and each change looks reasonable in isolation. The Netwrix 2026 Data and Identity Security Report found that 76% of organizations don't immediately and automatically revoke access after users no longer need it. In the survey behind it, 66% said some or most privileged roles keep standing, always-on access.
CoreView reported that 38% of organizations detect configuration tampering through manual review alone and 17% have no detection method at all.
Mapping configuration to compliance evidence
Effective audit evidence must show both control design and operating effectiveness. Auditors across frameworks define design evidence as the configuration at a point in time. Operating-effectiveness evidence proves the control ran continuously, covered the full population, and handled exceptions.
The same Netwrix research found that 74% of organizations cannot get a single unified view of where sensitive data resides and which identities can access it. A Service Organization Control 2 (SOC 2) Type II report evaluates controls over six months or more.
Cybersecurity Maturity Model Certification (CMMC) assessors verify controls using three defined methods, described in assessment guidance as "examine, interview, and test." One NOT MET assessment objective fails the entire security requirement. Health Insurance Portability and Accountability Act (HIPAA) enforcement follows the same logic. The Office for Civil Rights' (OCR's) 2025 action against Warby Parker cited "a failure to implement procedures to regularly review records of information system activity" as a distinct violation, meaning logging that nobody reviews still fails.
The most common evidence failures are an MFA policy left in report-only mode when enforcement is required and drafts or other unofficial records standing in for written policy. Both are avoidable.
Building a repeatable configuration review cadence
Quarterly is the right baseline for a full configuration review, and it matches how assessors and agencies already operate. The Cybersecurity and Infrastructure Security Agency's (CISA's) Binding Operational Directive 25-01 requires federal agencies to report Microsoft 365 secure-configuration assessment results quarterly.
A practical quarterly pass covers Conditional Access effectiveness and privileged role review, including conversion of permanent assignments to PIM-eligible. It should also cover consented apps with high-risk permission grants and a configuration diff against the prior quarter. Record every change in a documented change log.
Microsoft Secure Score belongs in that review as a directional signal only. Microsoft states plainly that "it isn't an absolute measurement of how likely your system or data could be breached" and that the recommendations don't cover every attack surface. Changes take 24–48 hours to reflect, and Microsoft separately tracks risk-acceptance trends. Treat a dropping score as a prompt to investigate and a rising score as a directional indicator.
Documentation makes the cadence repeatable across staff changes. For secure configurations, establish and maintain a secure configuration process, per Center for Internet Security (CIS) Controls Safeguard 4.1. Also record approved deviations from the baseline and a change log showing what moved since the last review. The National Institute of Standards and Technology (NIST) SP 800-171r3 additionally separates temporary deficiencies, tracked in a plan of action and milestones (POA&M), from enduring exceptions documented in the system security plan.
How Netwrix helps harden and monitor Microsoft 365
A current, centralized record of configuration state is what turns quarterly reviews and audit prep from manual reconstruction into a lookup. Netwrix Auditor records configuration and permission changes across Entra ID, SharePoint Online, and Active Directory with before-and-after values in a single, searchable audit trail, deployable in about 30 minutes
Flagler Bank, a Florida community bank with a one-person IT department, shortened its investigations by deploying Netwrix Auditor. What used to take hours now takes about 10 minutes, and the platform delivered usable value within 30 minutes of setup.
First National Bank and Trust of Beloit turned OCC audit preparation into a repeatable, evidence-backed process across its 17 locations. Group Policy changes, Structured Query Language (SQL) activity, and privileged access logs now come from a single platform in about an hour, work that used to take an entire week.
Keeping pace with a tenant that never stops changing
Microsoft security gaps reappear as administrators adjust policies, licenses reshape available controls, and exceptions outlive the systems they supported. A current configuration record helps teams investigate those changes and preserve the evidence needed for audits, rather than reconstructing it under a deadline.
Request a demo to see how Netwrix Auditor shows who changed a setting in your own Entra ID and SharePoint Online environment, and what it said before.
Frequently asked questions about Microsoft 365 security configuration
Share on
Learn More
About the author