A Microsoft 365 tenant set up quickly will send and receive mail on the first day. That is usually where configuration stops. The settings below are the ones we find open most often during health checks, roughly in the order we close them.
1. Multi-factor authentication is not enforced
It is enabled for the administrator and left optional for everyone else. A single reused password then gives an attacker a mailbox, and from that mailbox, a convincing invoice. Enforcement through conditional access, with sensible exclusions for shared devices, closes the most common route in.
2. Legacy authentication is still allowed
Older mail protocols bypass modern authentication entirely, which means they bypass your multi-factor requirement too. Blocking them is a single policy, but it needs an inventory first — a scanner or an old accounting package is often still using one.
3. There are too many global administrators
We routinely find five or six. Every one of them is an equally valuable target. Most of those people need a specific administrative role, not the highest one.
4. Email authentication records are incomplete
SPF exists, DKIM was never signed, DMARC is absent or set to take no action. The result is that anybody can send mail appearing to come from your domain, and you will not hear about it.
5. Anti-phishing impersonation protection is off
Defender can be told which of your people are most likely to be impersonated — the chief executive, the finance officer — and treat lookalike sender addresses accordingly. It is off by default.
6. Auditing was never switched on
When an incident happens, the first question is what the account did. If unified audit logging was never enabled, that history does not exist.
7. Anonymous sharing links are permitted everywhere
SharePoint and OneDrive will happily produce a link that works for anyone who has it, forever. Restricting to internal or authenticated-external sharing, with expiry, prevents documents leaving quietly.
8. Retention and deletion have no policy
Everything is kept forever, including material you were entitled and sometimes obliged to destroy. Purview retention labels are included in most business licences and are almost never applied.
9. Devices are unmanaged
Staff access company mail on personal phones with no encryption requirement and no remote wipe. Intune is often already licensed; a basic compliance policy takes an afternoon.
10. Nobody is reading the alerts
The security centre generates them, and they go to a shared mailbox nobody opens. An alert nobody reads is not a control.
Where to start
Items one, two and three, in that order. Together they remove the value of a stolen credential, which is the beginning of nearly every incident we are called to.
If you would like these checked against your own tenant, a health check produces a written report with each finding, its risk and whether the fix is already covered by your licences.