Microsoft 365 Security

Is Your Microsoft 365 Tenant Actually Secure?

Seven configuration areas businesses regularly overlook

14 min read — Altitude Microsoft 365 Team

The Microsoft 365 Security Assumption

A common position in many businesses goes something like this: "We have Microsoft 365 Business Premium, Defender, Intune and MFA — so we should be secure."

The problem is not the intent. The problem is the gap between owning a tool and actually using it correctly.

Microsoft provides the controls. Somebody still has to configure them, review them, maintain them and decide which exceptions are justified. Microsoft 365 security is less about what appears on the invoice and more about what is actually switched on, configured and reviewed.

Why Licensing Is Not Configuration

Buying a security product creates capability. It does not create security. Consider two businesses on identical Microsoft 365 Business Premium licences. One has spent time configuring Conditional Access, reviewing administrator accounts, cleaning up guest users and enabling audit logging. The other installed Microsoft 365 and moved on. Their invoices are the same. Their security posture is not.

This gap is very common. Businesses migrate to Microsoft 365, get up and running quickly, and then rarely revisit the security configuration. Over time, users join and leave, exceptions accumulate, and the configuration drifts away from best practice without anyone making a deliberate decision to reduce security.

What a Security Baseline Is

A security baseline is a defined set of configuration settings that represent a reasonable minimum for an organisation of a given type. For Microsoft 365, a baseline typically covers authentication, administrator access, external sharing, device management, logging, workload-specific settings (Exchange Online, SharePoint, Teams) and monitoring.

The purpose of a baseline review is not to achieve perfection. It is to understand the current position, compare it against recognised guidance and identify the most important gaps — then make deliberate decisions about what to fix and in what order.

CIS Microsoft 365 Foundations Explained

The Center for Internet Security (CIS) publishes an independent Microsoft 365 Foundations Benchmark. It is one of the most widely referenced independent sources of secure-configuration guidance for Microsoft 365 environments.

The current version is CIS Microsoft 365 Foundations Benchmark v7.0.0. This release includes 22 new recommendations, 12 recommendations relocated from the Microsoft Azure Foundations Benchmark, 2 removed recommendations, 68 updated recommendations and revised control mappings.

The CIS benchmark is used alongside — not instead of — Microsoft's own guidance and Secure Score. It provides an independent cross-check and covers areas that Microsoft's own tooling may not surface clearly.

Using the CIS benchmark as a reference point does not mean every control will be implemented. Some controls may be not applicable, deferred, covered by a compensating control, dependent on licensing or subject to a business decision. The benchmark informs the review — it does not replace judgement about what is right for a specific organisation.

Microsoft Secure Score Explained

Microsoft Secure Score is a measurement of your organisation's security posture based on the security controls implemented within your Microsoft 365 tenant. Microsoft surfaces it prominently in the Security portal and updates it as you implement recommended actions.

Secure Score is useful. It surfaces improvement actions, shows current posture at a glance, enables tracking over time and provides a comparison with organisations of similar size. Microsoft itself states, however, that Secure Score is not a guarantee against breach, that not every recommendation is appropriate for every organisation, and that security must be balanced with usability.

Chasing 100% Secure Score is not the right objective. The right objective is to understand every significant security decision in the tenant — what is in place, what is not in place and why.

CIS vs Secure Score

Secure Score and the CIS benchmark are not alternatives — they are complementary. Secure Score measures your current implementation of Microsoft's recommended actions. The CIS benchmark provides an independent view covering some areas Secure Score may not fully surface, including detailed configuration of Exchange Online, SharePoint and Teams settings, specific Conditional Access patterns and logging requirements.

A review that uses both provides a more complete picture than either alone. Neither replaces a human assessment of whether the configuration makes sense for the specific business.

Seven Areas Worth Reviewing

Across Microsoft 365 environments, the same areas tend to contain the most important security gaps. Here is what each area covers and why it matters.

1 — Authentication

MFA is the most important single control available in Microsoft 365. But MFA alone is not enough if the authentication method is weak. SMS-based MFA is technically weaker than app-based MFA, and app-based MFA is weaker than phishing-resistant methods such as passkeys, FIDO2 keys or Windows Hello for Business.

An authentication review looks at which methods are in use across the tenant, whether legacy authentication protocols remain enabled, whether Conditional Access is configured to enforce appropriate authentication strength, and whether administrator accounts use strong MFA.

MFA is the starting point. The quality of the authentication method matters too.

2 — Privileged Access

Global Administrators have unrestricted access to everything in a Microsoft 365 tenant. Every account that holds a Global Administrator role — or any other privileged role — represents a significant risk if it is compromised, misused or simply forgotten about.

Common problems include: too many Global Administrators; administrator accounts used for daily email and browsing; accounts belonging to former IT suppliers or former employees; shared administrator credentials; and standing privilege where Privileged Identity Management (PIM) would be more appropriate.

Every privileged account should have a current owner and a current reason for existing.

3 — External Sharing

SharePoint, OneDrive and Teams all support external collaboration. That is useful. What is less useful is when external sharing defaults are set too broadly, anonymous links never expire, guest accounts accumulate without review, or external users retain access to content long after a project ends.

External sharing is useful. Uncontrolled external sharing is a security problem.

4 — Devices

In most Microsoft 365 tenants, a valid username and password — even combined with MFA — is sufficient to access company data from any device. Conditional Access with device compliance requirements changes that: it ensures that trusted identities connect from trusted devices.

Common gaps include: Intune licences that exist but devices are not enrolled; compliance policies that are technically enabled but not enforced; unmanaged personal devices accessing SharePoint and Teams data; and mobile devices with no protection policies in place.

A valid password and MFA challenge do not automatically make the device trustworthy.

5 — Logging and Visibility

Microsoft Purview Audit, Microsoft Entra sign-in logs and Defender alerts collectively provide visibility into what is happening in your tenant. When something goes wrong — a compromised account, a suspicious download, an unusual administrator change — the ability to investigate depends on whether the relevant logs exist and whether anyone is looking at them.

Audit logging must be enabled. Retention must be sufficient (which depends on licensing). Someone must own the process of reviewing risky sign-ins and Defender alerts. Without that, logging is present but not useful.

Logging matters only if the business can use it when something goes wrong.

6 — Security Baseline Configuration

The settings within individual Microsoft 365 workloads matter as much as the overarching identity controls. Exchange Online configurations — anti-phishing, anti-spam, malware protection, external email forwarding — have direct security implications. SharePoint and Teams settings control how data can be accessed and shared. Device policies affect whether corporate data stays protected on endpoints.

A baseline review compares these settings against recommended guidance across all major workloads, not just the identity controls visible in Secure Score.

7 — Configuration Drift and Monitoring

A configuration that was secure twelve months ago may not be secure today. Users join and leave. Administrators make changes. Exceptions are added for one specific project and never removed. Microsoft updates its services and recommendations. Guest accounts accumulate. Applications gain consent.

Configuration drift is the gradual movement of a tenant away from a known-good security baseline without any deliberate decision to reduce security. A secure configuration today can become an insecure configuration gradually without anybody deliberately changing the security strategy.

Common Warning Signs

In practice, certain patterns suggest a tenant security review is overdue:

  • Nobody knows the current Microsoft Secure Score
  • Nobody knows every current Global Administrator
  • Former IT suppliers still have access
  • MFA has not been reviewed recently
  • Administrator accounts are used for normal email and browsing
  • Guest accounts have never been formally reviewed
  • Anonymous sharing links remain available without expiry
  • Intune licences exist but devices are not enrolled
  • Unmanaged devices can access company data in SharePoint or Teams
  • Conditional Access contains unexplained exclusions
  • Risky sign-in alerts have no defined owner
  • Defender alerts have no response process
  • Security configuration changes are undocumented
  • The tenant has never had a formal security review

The biggest Microsoft 365 security problem is often not knowing what you do not know.

The Cyber Essentials Connection

A Microsoft 365 security review may support preparation for Cyber Essentials or Cyber Essentials Plus — particularly in areas where the frameworks overlap, such as MFA, privileged account management, supported operating systems and devices, malware protection and security updates.

However, the frameworks answer different questions. CIS benchmark alignment does not equal Cyber Essentials readiness. A high Microsoft Secure Score does not mean Cyber Essentials criteria are met. And a Microsoft 365 security review does not itself provide Cyber Essentials certification.

The frameworks overlap in places, but they answer different questions. Where Cyber Essentials is a specific objective, Altitude can scope the review and any subsequent remediation with that certification boundary in mind.

How Often Should Microsoft 365 Security Be Reviewed?

An annual review is a reasonable minimum. Many organisations benefit from more frequent touchpoints — particularly those with significant user turnover, active external collaboration, complex device environments or recent security incidents.

The most effective approach is to make Microsoft 365 security monitoring part of a recurring IT management process rather than a one-off project. A structured review every six to twelve months, combined with ongoing monitoring of Secure Score, risky sign-ins and administrator changes, provides far better coverage than periodic reviews alone.

What a Baseline Review Should Produce

A useful Microsoft 365 security review does not end with a long list of unweighted observations. The output should be practical:

  • A plain-English executive summary of current posture
  • A scored assessment across the seven control areas — what is controlled, what needs improvement and where there are material gaps
  • A prioritised action plan classifying findings as critical, high, medium, low or informational
  • A Secure Score review identifying high-value improvement opportunities
  • CIS alignment observations highlighting material deviations
  • A privileged access review documenting significant administrator accounts
  • A remediation plan identifying quick wins, configuration work, licence dependencies and longer-term actions

The deliverable should be readable by a business owner and useful to a technical administrator — not written for a security consultant's filing cabinet.

The Altitude View

Altitude IT reviews Microsoft 365 environments for businesses across Manchester and the North West. The practical experience of managing tenants day-to-day — configuring Conditional Access, managing Intune enrolment, cleaning up administrator access, investigating risky sign-ins — informs how we approach a baseline review.

We use the CIS Microsoft 365 Foundations Benchmark and Microsoft Secure Score as reference frameworks, alongside Microsoft's own security guidance and the specific requirements of the business. We do not claim CIS certification, Microsoft designation or guaranteed security outcomes. We produce honest findings and a realistic plan.

Microsoft 365 security is a configuration discipline — not a licensing decision. The review exists to establish what is actually configured, compare it against what should be configured and identify what to fix first.

Want to know where your Microsoft 365 security gaps actually are?

Altitude's Microsoft 365 Security Baseline Review compares your current tenant configuration with Microsoft security guidance, Secure Score, relevant CIS recommendations and your own business requirements — then gives you a prioritised plan for improvement.

Talk to an Expert Back to All Blog Posts