Your M365 Tenant Has More Attack Surface Than You Think
Microsoft 365 is the backbone of most small and mid-size businesses today. Email, Teams, SharePoint, OneDrive — it handles everything. But that centralization also makes it a prime target. When attackers compromise an M365 account, they don't just get email. They potentially get your entire organization.
Most businesses turn on M365, set up their email, and call it done. That leaves a lot of doors unlocked.
The Settings Most People Never Touch
Multi-Factor Authentication. Still the single highest-impact control you can enable, and still not universally deployed. Legacy authentication protocols — basic auth over SMTP, IMAP, and POP3 — bypass MFA entirely. If you haven't disabled legacy auth in your tenant, you have a gap. Attackers use password spray attacks against these endpoints constantly.
Conditional Access Policies. This is where you define who can access M365, from where, on what devices. Without Conditional Access, a valid credential from anywhere in the world grants full access. At minimum, you should be blocking legacy auth protocols and requiring MFA for all users via Conditional Access — not just per-user MFA settings, which are weaker.
Audit Logging. Microsoft 365 audit logging is not enabled by default in all tenants. If you can't tell what happened in your tenant for the past 90 days, you're flying blind during an incident. Turn it on and keep it on.
Mailbox Forwarding Rules. Business Email Compromise attackers will often set an auto-forward rule on a compromised mailbox — silently copying all email to an external address. Review your tenant for mailbox forwarding rules regularly, and consider a policy that blocks forwarding to external domains unless explicitly approved.
Licensing Matters
A lot of the best security controls in M365 require Microsoft 365 Business Premium or an E3/E5 license. If your team is on Business Basic or Business Standard, you don't have Conditional Access, Defender for Business, or Intune device management. It's worth doing a license audit to understand what you have — and what you're missing.
Bottom Line
M365 security isn't a one-time setup. It requires ongoing review as Microsoft releases new features, as your team changes, and as the threat landscape shifts. If you haven't had your tenant configuration reviewed in the past 12 months, it's overdue.
JRM360 offers M365 security assessments and ongoing tenant administration across Florida. Reach out if you'd like a review of your current configuration.