|
Getting your Trinity Audio player ready...
|

Microsoft has strengthened Microsoft 365’s built-in security over the past several years, giving newly created tenants much stronger protection by default. However, organizations that have been using Microsoft 365 for several years may still be running with outdated settings that were never automatically updated.
That’s because Microsoft generally doesn’t change existing tenant configurations when new security defaults are introduced. If your Microsoft 365 environment was deployed before 2022, managed by a previous IT provider, or simply hasn’t been reviewed in a while, there may be security gaps hiding in plain sight.
Below are five Microsoft 365 settings that are worth reviewing to improve security and reduce unnecessary risk.
Note: Some of these settings require Microsoft 365 Business Premium, Microsoft 365 E3, or Microsoft 365 E5 licensing. If certain options aren’t available, your subscription level is likely the reason. Also, some changes may affect how users currently work, so it’s best to implement them gradually rather than all at once.
1. Review Microsoft 365 Security Settings for SharePoint and OneDrive
Whenever someone shares a file from SharePoint or OneDrive, Microsoft uses a default sharing permission. In many older Microsoft 365 tenants, that default is still set to “Anyone with the link.”
This means anyone who receives the URL can access the file without signing in. The link can also be forwarded indefinitely, making it difficult to know who has access to sensitive information.
Newer Microsoft 365 tenants typically default to “Only people in your organization,” but older SharePoint sites often continue using legacy sharing settings. For example, an employee who emailed themselves a document months ago could still have unrestricted access through that original link unless it has been manually revoked.
To improve security:
- Open the SharePoint Admin Center
- Navigate to Policies > Sharing
- Change the default sharing link to “Specific people”
- Set expiration dates for any remaining anonymous sharing links
Estimated time: About 15 minutes.
Changing the default only affects newly created sharing links. Existing links remain active until they are replaced or revoked.
2. Verify External Email Forwarding Rules
Microsoft now blocks automatic email forwarding to external addresses by default through its outbound spam protection. This helps prevent sensitive business emails from being silently copied to personal email accounts.
However, organizations that configured Microsoft 365 years ago may still have older forwarding rules that remain active.
For example, an employee could have previously created a rule that forwards every incoming email to a personal Gmail account. If that rule predates Microsoft’s newer security defaults, it may still be functioning today.
To verify your settings:
- Open the Microsoft Defender portal
- Go to Email & Collaboration > Policies & Rules > Anti-spam policies
- Review the Outbound Anti-Spam Policy
- Confirm Automatic Forwarding is set to Off or Automatic (System-controlled)
It’s also a good idea to review existing mailbox rules and use Microsoft Purview audit logs to identify users who previously created forwarding rules.
Estimated time: Around 10 minutes to verify settings, with additional time needed to audit user mailboxes.
3. Audit Older Third-Party Application Permissions
Beginning in July 2025, Microsoft started requiring administrator approval for most new third-party applications requesting access to Microsoft 365 data.
While new app requests are now more tightly controlled, applications that received permission before this policy change may still retain access to user mailboxes, calendars, OneDrive files, and SharePoint data.
Many organizations discover applications that employees installed years ago for temporary projects and have long since forgotten.
To review existing permissions:
- Open Microsoft Entra ID
- Select Enterprise Applications
- Review All Applications
- Sort by user consent and identify applications with access to email, files, or calendars
- Remove permissions for any applications that are no longer required
Estimated time: 30–60 minutes, depending on how many applications are installed.
4. Check Your Microsoft 365 Audit Log Retention Policies
Audit logs are essential for investigating suspicious activity, security incidents, and compliance requirements.
Microsoft increased the default retention period for standard Microsoft 365 audit logs from 90 days to 180 days in October 2023. Organizations with Microsoft 365 E5 licensing or Microsoft Purview Audit (Premium) can retain many audit records for up to one year.
While 180 days may be sufficient for some businesses, organizations in regulated industries often require much longer retention periods.
Industries such as healthcare, finance, and legal services frequently need audit records that span multiple years to satisfy compliance requirements and support investigations.
To review retention settings:
- Open the Microsoft Purview Compliance Portal
- Navigate to Audit > Audit Retention Policies
- Confirm your current retention period
- Extend retention if your licensing supports it
Estimated time: Approximately 15 minutes once licensing has been verified.
5. Confirm MFA and Conditional Access Are Properly Configured
Multi-factor authentication (MFA) remains one of the most effective ways to protect Microsoft 365 accounts, yet it’s also one of the most commonly misconfigured areas in older tenants.
Microsoft introduced Security Defaults several years ago to automatically require MFA in newer tenants. At the same time, organizations using Conditional Access policies often disable Security Defaults as part of the migration process.
If Conditional Access wasn’t fully implemented, it’s possible to end up with Security Defaults disabled while some users, including administrators, are no longer protected by MFA.
Review these areas carefully:
- In Microsoft Entra ID, verify whether Security Defaults are enabled or disabled.
- Review Conditional Access Policies to confirm MFA is enforced for all users.
- Pay close attention to emergency (“break-glass”) administrator accounts, which are sometimes excluded from Conditional Access and unintentionally left without MFA protection.
Estimated time: Around one hour, depending on the complexity of your Conditional Access policies.
For additional guidance on securing your Microsoft 365 environment, Microsoft provides best practices in its Microsoft 365 security documentation.
Prioritize These Changes for the Smoothest Rollout
Not every security improvement affects end users the same way. Some changes happen entirely behind the scenes, while others change familiar workflows.
A practical implementation order is:
- Review audit log retention and third-party app permissions since these have little to no user impact.
- Verify external email forwarding settings, which typically won’t affect users unless someone relies on automatic forwarding.
- Update SharePoint and OneDrive sharing defaults, but communicate the change beforehand so employees understand why file sharing may work differently.
- Review MFA and Conditional Access policies last. This is the most critical security improvement but also the easiest place to accidentally lock users out if changes aren’t carefully planned and tested.
Final Thoughts
Microsoft continues to strengthen Microsoft 365 security, but those improvements don’t automatically update older tenants. As a result, many organizations unknowingly continue operating with legacy configurations that increase their exposure to cyber threats.
Taking the time to review these five settings can significantly improve your organization’s security posture without requiring major infrastructure changes. A periodic Microsoft 365 security assessment helps ensure your tenant keeps pace with Microsoft’s evolving security standards while reducing unnecessary risk to your business.
Ready to strengthen your Microsoft 365 security? Contact Twintel today to schedule a Microsoft 365 security assessment and identify hidden risks before they become problems.
Twintel has grown into an expansive, full team of IT services professionals, acting as the outsourced IT department of non-profits, small to mid-size businesses, and enterprise-level corporations in Orange County, across California, and nationally.
Today, it’s the strength and deep expertise of the Twintel team that drives positive outcomes for clients. Each of the support staff, technicians, and engineers works diligently each day to make sure that the companies served have the seamless, secure, and stable IT environments needed to allow them to pursue their organizational objectives.