5 Microsoft 365 Security Settings Most Small Businesses Get Wrong
- Aug 5
- 3 min read

Microsoft 365 works well enough out of the box that most small businesses never go back and check the defaults. That's usually fine — until one of those defaults turns into a data leak, a compliance gap, or a line item you didn't need to be paying for. Here are the five we find most often when we review a new client's tenant.
1. External Sharing Links Are Set to "Anyone"
By default, SharePoint and OneDrive often let anyone with a shared link view a file — no login required, no expiration date, no way to know who's actually opened it. That's convenient for sharing a file quickly, and it's exactly how sensitive documents end up circulating far beyond the people who were supposed to see them.
What to check: In the SharePoint admin center, under Policies > Sharing, confirm the default link type is set to "Specific people" rather than "Anyone." At minimum, set links to expire after a defined period and require sign-in. For anything involving client financial data, patient records, or contract terms, "Anyone with the link" should never be the default.
2. Legacy Authentication Is Still Enabled
Multi-factor authentication only works if every path into an account actually requires it. Older protocols — IMAP, POP, and SMTP AUTH — were built before MFA existed, and if they're still enabled on your tenant, they give attackers a way to log into mailboxes using just a stolen password, completely bypassing MFA. This is one of the most common ways compromised accounts happen, and most business owners have no idea these protocols are even active.
What to check: In Entra ID (formerly Azure AD), create a Conditional Access policy that blocks legacy authentication for all users. If you're not sure whether anything in your business still depends on IMAP or POP (an old scanner, an accounting integration), test in report-only mode first before enforcing the block.
3. Mailbox Auto-Forwarding Rules Are Never Reviewed
Auto-forwarding rules are a normal feature — someone sets up their vacation coverage, or forwards receipts to a bookkeeper. But they're also one of the first things an attacker sets up after compromising an account, quietly forwarding every incoming email to an external address so they can monitor invoices, wire instructions, and password reset emails without you noticing anything's wrong in the inbox itself.
What to check: Run a report on all mailbox forwarding rules pointing to external domains and review them for anything unexpected. Many businesses set a policy blocking auto-forward to external addresses by default, with exceptions granted individually when there's a legitimate business reason.
4. No Retention or Deletion Hold Policies Are Configured
Deleted items in Exchange and OneDrive don't stay recoverable forever — the default retention window is short, and once it passes, that data is gone. That becomes a real problem when an employee leaves and something in their mailbox turns out to matter three months later, or when a compliance requirement calls for records to be kept for a specific number of years.
What to check: In the Microsoft Purview compliance portal, set retention policies appropriate to your industry — HIPAA-covered practices and government contractors handling CUI typically need longer, documented retention windows than the Microsoft default provides.
5. Licenses Don't Match What People Actually Need
It's common to find every employee on the same license tier regardless of role, shared or resource mailboxes accidentally assigned a paid user license instead of being set up as free shared mailboxes, and departed employees still holding a license months after they've left. None of this is a security problem — it's a straightforward cost problem, and it's one of the easiest things to fix once someone actually looks.
What to check: Pull a report of all assigned licenses against current employees and job functions. Downgrade anyone on Business Premium who only needs Business Standard, convert any shared inboxes to free shared mailboxes, and remove licenses from disabled accounts.
Five Minutes a Setting, Real Risk Removed
None of these require new software or a big project. They're configuration changes inside a platform you're already paying for — the kind of thing that's easy to overlook because Microsoft 365 mostly just works, until one of these defaults is the reason something goes wrong.
If it's been a while since anyone reviewed your tenant settings against what your business actually needs, contact us today — a quick M365 configuration review is part of every IT assessment we run for businesses across Virginia, Maryland, and DC.



