Skip to content
Compu-Tech, Inc.
Your Trusted Technology Provider
Compu-Tech, Inc.Compu-Tech, Inc.
Search:
Search

proud to serve



  • Home
  • About
  • IT Services
    • IT Consulting
    • Hourly IT Services
    • On-Site Computer Repair
    • Remote IT Services
    • Data Backup and Recovery
    • Managed Services
    • Email/Spam Protection
    • Cloud Computing
  • Xerox Solutions
    • XEROX
    • Healthcare
    • Solution for education
    • Education
    • Xerox Showcase
    • Legal
  • Telecom Services
    • VOIP Services
    • Allworx Connect 324
    • Allworx Connect 536 and 530
    • Allworx Connect 731
  • Contact
  • Support
  • Referral
  • Videos
  • Testimonial
  • Blog
  • Landing Page
  • Home
  • About
  • IT Services
    • IT Consulting
    • Hourly IT Services
    • On-Site Computer Repair
    • Remote IT Services
    • Data Backup and Recovery
    • Managed Services
    • Email/Spam Protection
    • Cloud Computing
  • Xerox Solutions
    • XEROX
    • Healthcare
    • Solution for education
    • Education
    • Xerox Showcase
    • Legal
  • Telecom Services
    • VOIP Services
    • Allworx Connect 324
    • Allworx Connect 536 and 530
    • Allworx Connect 731
  • Contact
  • Support
  • Referral
  • Videos
  • Testimonial
  • Blog
  • Landing Page
You are here:
  1. Home
  2. Uncategorized
  3. Microsoft 365 Security Settings Every…
Jul272026
UncategorizedMicrosoft 365 Security Settings

Many businesses assume their Microsoft 365 environment is secure simply because Microsoft regularly improves its security features. However, Microsoft 365 security settings created before 2022 may still rely on legacy configurations that were never updated automatically. If your Microsoft 365 tenant was configured years ago or managed by a previous IT provider, reviewing these settings can help reduce security risks and improve compliance.

Microsoft has introduced stronger default protections over the last several years, but these updates generally apply only to newly created tenants. Older environments often continue using previous settings unless an administrator manually updates them. Here are five important Microsoft 365 security settings every organization should review.


1. Review SharePoint and OneDrive Sharing Settings

One of the most overlooked Microsoft 365 security settings is file sharing.

Older SharePoint and OneDrive environments often default to “Anyone with the link,” allowing files to be accessed without authentication. Even if a file was shared months ago, that public link may still work unless it has been removed manually.

Instead, configure your tenant to use “Specific people” or “Only people in your organization” as the default sharing option. You should also configure expiration dates for anonymous sharing links whenever they must be used.

Updating this setting improves document security without affecting existing links until users generate new ones.


2. Disable External Email Forwarding

External email forwarding is another Microsoft 365 security setting worth checking.

Microsoft now blocks automatic forwarding to external email addresses by default, but older tenants may still allow users to forward company emails to personal Gmail, Outlook, or Yahoo accounts.

Review your outbound spam policy and verify that automatic forwarding is either:

  • Off
  • Automatic (System-controlled)

Additionally, audit mailbox rules to identify users who already have forwarding rules configured. Removing unnecessary forwarding rules helps reduce the risk of sensitive company information leaving your organization.


3. Audit Third-Party Application Permissions

Many employees connect third-party apps to Microsoft 365 for convenience. These applications often request permission to access emails, calendars, contacts, files, or SharePoint sites.

Microsoft now requires administrator approval for most new app consent requests, but older applications previously approved by users may still have extensive access.

Review Enterprise Applications in Microsoft Entra ID and identify:

  • Applications employees no longer use
  • Unknown applications
  • Apps requesting unnecessary permissions
  • Legacy integrations from completed projects

Removing unused permissions reduces your organization’s attack surface and strengthens overall Microsoft 365 security.


4. Verify Audit Log Retention Policies

Another critical Microsoft 365 security setting involves audit log retention.

Microsoft increased standard audit log retention from 90 days to 180 days. While this is sufficient for many organizations, businesses in regulated industries often require significantly longer retention periods.

Organizations using Microsoft 365 E5 or Microsoft Purview Audit (Premium) can extend audit retention to one year or longer depending on licensing.

Longer audit retention provides valuable historical information during:

  • Security investigations
  • Compliance audits
  • Legal requests
  • Internal incident reviews

Before changing retention periods, verify your Microsoft 365 licensing supports the desired policy.


5. Confirm MFA and Security Defaults

Among all Microsoft 365 security settings, Multi-Factor Authentication (MFA) remains one of the most important.

New Microsoft 365 tenants typically have Security Defaults enabled automatically. Older tenants, however, may have Security Defaults disabled because Conditional Access policies were implemented years ago.

Verify that:

  • Security Defaults are enabled if Conditional Access is not being used.
  • Conditional Access policies require MFA for every user.
  • Administrator accounts are protected.
  • Emergency (“break-glass”) accounts follow your organization’s documented security procedures.

Incorrect Conditional Access configurations can unintentionally leave users—or even administrators—without MFA protection, making this review especially important.


Best Order for Updating Microsoft 365 Security Settings

Not every security change affects users immediately. A phased approach helps minimize disruption.

A recommended order is:

  1. Review audit log retention.
  2. Audit third-party application permissions.
  3. Verify external email forwarding.
  4. Update SharePoint and OneDrive sharing defaults.
  5. Review MFA and Conditional Access policies.

This approach lets you address low-impact security improvements first before implementing changes that may require user communication or testing.


Final Thoughts

Reviewing your Microsoft 365 security settings is one of the simplest ways to strengthen your organization’s cybersecurity posture. Older tenants often contain legacy configurations that remain active long after Microsoft’s secure-by-default improvements were introduced.

By verifying sharing permissions, blocking unnecessary email forwarding, reviewing third-party app access, extending audit log retention where appropriate, and ensuring consistent MFA enforcement, businesses can significantly reduce security risks while improving compliance and visibility across their Microsoft 365 environment.


Frequently Asked Questions

Are older Microsoft 365 tenants less secure?

Not necessarily, but older tenants often retain legacy configurations that newer Microsoft 365 deployments no longer use. Reviewing your Microsoft 365 security settings ensures those older configurations don’t become security gaps.

Does Microsoft automatically update security settings?

Microsoft improves default settings for newly created tenants, but existing tenants usually keep their current configurations until administrators change them manually.

How often should Microsoft 365 security settings be reviewed?

Most organizations should review Microsoft 365 security settings at least once a year or whenever major Microsoft security changes are announced.

Is MFA enough to secure Microsoft 365?

MFA is one of the strongest security controls, but it should be combined with secure sharing settings, application permission reviews, audit logging, and email protection for comprehensive security.

Which Microsoft 365 license is best for advanced security?

Microsoft 365 Business Premium and Microsoft 365 E5 provide advanced security capabilities, including Conditional Access, Microsoft Defender, and enhanced Microsoft Purview features

Category: UncategorizedBy Kyle DostalerJuly 27, 2026Leave a comment

Author: Kyle Dostaler

Post navigation

PreviousPrevious post:Windows 10 End of Support: What Businesses Must Do Now

Related Posts

Windows 10 End of Support
Windows 10 End of Support: What Businesses Must Do Now
July 21, 2026
Cyberattack Response for Small Business
Cyberattack Response for Small Business: What to Do in the First Hour
July 21, 2026
Small Business Digital Advertising
Small Business Digital Advertising: A Guide for SMEs
July 1, 2026
Ransomware Protection
How to Prevent Ransomware Attacks: 5 Essential Cybersecurity Steps for Businesses
March 23, 2026

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Post comment

Recent Posts
  • Microsoft 365 Security Settings Every Business Should Verify
  • Windows 10 End of Support: What Businesses Must Do Now
  • Cyberattack Response for Small Business: What to Do in the First Hour
  • AI Skills for Gen Z: How Young Professionals Can Thrive in the AI Era
  • Small Business Digital Advertising: A Guide for SMEs
Recent Comments
    Categories
    • Blog
    • Uncategorized

    ABOUT

    Compu-Tech specializes in a wide range of services, including tailored IT services and solutions for small and medium sized businesses in Connecticut. We are committed to providing each and every one of our clients with high quality service and support.

    Secured by Positive SSL

     

     

    Facebook-f Instagram Linkedin
    Copyright © 2026 | Compu Tech
     

    Get Free Consultation