Many businesses assume their Microsoft 365 environment is secure simply because Microsoft regularly improves its security features. However, Microsoft 365 security settings created before 2022 may still rely on legacy configurations that were never updated automatically. If your Microsoft 365 tenant was configured years ago or managed by a previous IT provider, reviewing these settings can help reduce security risks and improve compliance.
Microsoft has introduced stronger default protections over the last several years, but these updates generally apply only to newly created tenants. Older environments often continue using previous settings unless an administrator manually updates them. Here are five important Microsoft 365 security settings every organization should review.
1. Review SharePoint and OneDrive Sharing Settings
One of the most overlooked Microsoft 365 security settings is file sharing.
Older SharePoint and OneDrive environments often default to “Anyone with the link,” allowing files to be accessed without authentication. Even if a file was shared months ago, that public link may still work unless it has been removed manually.
Instead, configure your tenant to use “Specific people” or “Only people in your organization” as the default sharing option. You should also configure expiration dates for anonymous sharing links whenever they must be used.
Updating this setting improves document security without affecting existing links until users generate new ones.
2. Disable External Email Forwarding
External email forwarding is another Microsoft 365 security setting worth checking.
Microsoft now blocks automatic forwarding to external email addresses by default, but older tenants may still allow users to forward company emails to personal Gmail, Outlook, or Yahoo accounts.
Review your outbound spam policy and verify that automatic forwarding is either:
- Off
- Automatic (System-controlled)
Additionally, audit mailbox rules to identify users who already have forwarding rules configured. Removing unnecessary forwarding rules helps reduce the risk of sensitive company information leaving your organization.
3. Audit Third-Party Application Permissions
Many employees connect third-party apps to Microsoft 365 for convenience. These applications often request permission to access emails, calendars, contacts, files, or SharePoint sites.
Microsoft now requires administrator approval for most new app consent requests, but older applications previously approved by users may still have extensive access.
Review Enterprise Applications in Microsoft Entra ID and identify:
- Applications employees no longer use
- Unknown applications
- Apps requesting unnecessary permissions
- Legacy integrations from completed projects
Removing unused permissions reduces your organization’s attack surface and strengthens overall Microsoft 365 security.
4. Verify Audit Log Retention Policies
Another critical Microsoft 365 security setting involves audit log retention.
Microsoft increased standard audit log retention from 90 days to 180 days. While this is sufficient for many organizations, businesses in regulated industries often require significantly longer retention periods.
Organizations using Microsoft 365 E5 or Microsoft Purview Audit (Premium) can extend audit retention to one year or longer depending on licensing.
Longer audit retention provides valuable historical information during:
- Security investigations
- Compliance audits
- Legal requests
- Internal incident reviews
Before changing retention periods, verify your Microsoft 365 licensing supports the desired policy.
5. Confirm MFA and Security Defaults
Among all Microsoft 365 security settings, Multi-Factor Authentication (MFA) remains one of the most important.
New Microsoft 365 tenants typically have Security Defaults enabled automatically. Older tenants, however, may have Security Defaults disabled because Conditional Access policies were implemented years ago.
Verify that:
- Security Defaults are enabled if Conditional Access is not being used.
- Conditional Access policies require MFA for every user.
- Administrator accounts are protected.
- Emergency (“break-glass”) accounts follow your organization’s documented security procedures.
Incorrect Conditional Access configurations can unintentionally leave users—or even administrators—without MFA protection, making this review especially important.
Best Order for Updating Microsoft 365 Security Settings
Not every security change affects users immediately. A phased approach helps minimize disruption.
A recommended order is:
- Review audit log retention.
- Audit third-party application permissions.
- Verify external email forwarding.
- Update SharePoint and OneDrive sharing defaults.
- Review MFA and Conditional Access policies.
This approach lets you address low-impact security improvements first before implementing changes that may require user communication or testing.
Final Thoughts
Reviewing your Microsoft 365 security settings is one of the simplest ways to strengthen your organization’s cybersecurity posture. Older tenants often contain legacy configurations that remain active long after Microsoft’s secure-by-default improvements were introduced.
By verifying sharing permissions, blocking unnecessary email forwarding, reviewing third-party app access, extending audit log retention where appropriate, and ensuring consistent MFA enforcement, businesses can significantly reduce security risks while improving compliance and visibility across their Microsoft 365 environment.
Frequently Asked Questions
Are older Microsoft 365 tenants less secure?
Not necessarily, but older tenants often retain legacy configurations that newer Microsoft 365 deployments no longer use. Reviewing your Microsoft 365 security settings ensures those older configurations don’t become security gaps.
Does Microsoft automatically update security settings?
Microsoft improves default settings for newly created tenants, but existing tenants usually keep their current configurations until administrators change them manually.
How often should Microsoft 365 security settings be reviewed?
Most organizations should review Microsoft 365 security settings at least once a year or whenever major Microsoft security changes are announced.
Is MFA enough to secure Microsoft 365?
MFA is one of the strongest security controls, but it should be combined with secure sharing settings, application permission reviews, audit logging, and email protection for comprehensive security.
Which Microsoft 365 license is best for advanced security?
Microsoft 365 Business Premium and Microsoft 365 E5 provide advanced security capabilities, including Conditional Access, Microsoft Defender, and enhanced Microsoft Purview features








