Sango-Ota, Ogun State
Sui Generis Technologies
Microsoft 365

The ten Microsoft 365 settings most Nigerian tenants leave open

A tenant handed over by a reseller is configured to work, not to be secure. These are the settings we most often find untouched, and what each one costs when it is exploited.

14 July 2026Sui Generis TechnologiesINS/001
INS/001 14 July 2026

A Microsoft 365 tenant set up quickly will send and receive mail on the first day. That is usually where configuration stops. The settings below are the ones we find open most often during health checks, roughly in the order we close them.

1. Multi-factor authentication is not enforced

It is enabled for the administrator and left optional for everyone else. A single reused password then gives an attacker a mailbox, and from that mailbox, a convincing invoice. Enforcement through conditional access, with sensible exclusions for shared devices, closes the most common route in.

2. Legacy authentication is still allowed

Older mail protocols bypass modern authentication entirely, which means they bypass your multi-factor requirement too. Blocking them is a single policy, but it needs an inventory first — a scanner or an old accounting package is often still using one.

3. There are too many global administrators

We routinely find five or six. Every one of them is an equally valuable target. Most of those people need a specific administrative role, not the highest one.

4. Email authentication records are incomplete

SPF exists, DKIM was never signed, DMARC is absent or set to take no action. The result is that anybody can send mail appearing to come from your domain, and you will not hear about it.

5. Anti-phishing impersonation protection is off

Defender can be told which of your people are most likely to be impersonated — the chief executive, the finance officer — and treat lookalike sender addresses accordingly. It is off by default.

6. Auditing was never switched on

When an incident happens, the first question is what the account did. If unified audit logging was never enabled, that history does not exist.

7. Anonymous sharing links are permitted everywhere

SharePoint and OneDrive will happily produce a link that works for anyone who has it, forever. Restricting to internal or authenticated-external sharing, with expiry, prevents documents leaving quietly.

8. Retention and deletion have no policy

Everything is kept forever, including material you were entitled and sometimes obliged to destroy. Purview retention labels are included in most business licences and are almost never applied.

9. Devices are unmanaged

Staff access company mail on personal phones with no encryption requirement and no remote wipe. Intune is often already licensed; a basic compliance policy takes an afternoon.

10. Nobody is reading the alerts

The security centre generates them, and they go to a shared mailbox nobody opens. An alert nobody reads is not a control.

Where to start

Items one, two and three, in that order. Together they remove the value of a stolen credential, which is the beginning of nearly every incident we are called to.

If you would like these checked against your own tenant, a health check produces a written report with each finding, its risk and whether the fix is already covered by your licences.

Next step

Want this checked against your own organisation?

A discovery session costs nothing and produces a written view of what to fix first — yours to keep either way.

Request a consultation

INS/* More
Information governance 18 April 2026

Before you digitise your filing room

Scanning a disorganised registry produces a disorganised registry you cannot flip through. Four decisions to make before the…

Read
Start a conversation

Tell us what is slowing your organisation down.

A discovery session costs nothing. We will look at how your information, systems and approvals work today, and show you what can be improved first.

Send an enquiry