Unbeknown to most, Microsoft 365 includes many built-in security features. However, if your system still has the older settings, it may come with unnecessary risks. A managed IT service provider said that a quick look at some configurations below can help significantly improve your security without causing too much disruption.

Microsoft 365 Settings You Should Review Today According to A Managed IT Service Provider
Most of the time, employees share files through SharePoint and OneDrive. What most do not realize is that every shared link follows a default permission setting. As such, older Microsoft 365 environments often use broader sharing permissions such as an “Anyone” sharing links. Although this makes it easier to access the files as those links automatically open files to anyone who receives them, it also poses a threat. A managed IT service provider explains that this is because those links do not expire without any manual changes and may reach unintended recipients as well. Plus, since these files have unrestricted access, they can still be accessible and open even though they have been shared months ago.
Fortunately, newer Microsoft Teams sites have a more restrictive default sharing setting. Regardless of whether new or old, a managed IT service provider said that it is still wise to review your SharePoint sharing policies carefully. Ensuring the default is changed to “Specific people” provides more protection right away. Additionally, every new link should require user authentication. Furthermore, public links should also be set to automatically expire after a certain period of time. These updates that can be done in mere minutes will help ensure data is safer.
Automatic email forwarding creates another hidden security concern, according to a managed IT service provider. This is because although most external forwards are now disabled by default in Microsoft, older tenants can still have some old forwarding rules. In some cases, although employees are forwarding business e-mails privately, sensitive business communications may still be sent automatically outside your organization. This is because older custom policies may override Microsoft default policies.
Because of this, a managed IT service provider suggests checking outbound anti-spam policies within Microsoft Defender. This means confirming automatic forwarding remains disabled or system-controlled. Next, you can also review the rules in your mailbox throughout your organization. Aside from being extra careful about forwarding to external email addresses, check audit logs to include the dates on which forwarding rules are added. Checking tenant settings only takes a few minutes compared to reviewing every mailbox.
Many businesses connect outside applications to Microsoft 365. However, those applications typically ask for access to email, files, and permissions that can remain active even after projects finish. The only exceptions to this are for Microsoft’s own needs, which must be approved by an administrator. A managed IT service provider explains that older approvals remain unless removed manually. So, forgotten applications that have been authorized long ago can still provide access to valuable data.
To fix this, a managed IT service provider suggests visiting Microsoft Entra ID and reviewing Enterprise Applications. Here, you need to search for apps via mail, calendar, or file permissions. In doing so, take away anything different or no longer needed. This simple and easy cleanup strengthens security without affecting daily work and can be done in minutes.
Audit logs record important activity across Microsoft 365 and support compliance and investigation of incidents. As such, keeping those records longer provides greater business protection. Recently, Microsoft raised the default retention to 180 days while others are given one year depending on the licensing and availability of compliance functions. A managed IT service provider clarifies that retention periods may be significantly longer for regulated industries.
Healthcare, legal, and financial organizations, however, face stricter obligations. Thus, they need records covering several years. Because of this, a short retention period may fail compliance expectations. Therefore, rechecking your retention policies inside Microsoft Purview regularly is essential. Additionally, for businesses that need longer retention, more licenses are needed. Configuring this is quick after license confirmation. Having this extended retention enhances investigations and bolsters compliance preparedness.
Multi-factor authentication remains one of your strongest defenses, stressed a managed IT service provider. However, older Microsoft 365 tenants may have inconsistent settings which create gaps in key accounts that are not needed. Fortunately, Microsoft introduced Security Defaults several years ago. With this, new tenants usually receive automatic MFA protection compared to older environments that may never have enabled those safeguards.
However, problems can appear during incomplete migrations. This leads to security defaults being disarmed without warning. Plus, Conditional Access policies may only cover specific users, making several emergency administrator accounts not secured at all. To fix this, a managed IT service provider suggests reviewing Security Defaults inside Microsoft Entra ID. Inspecting every Conditional Access policy carefully and ensuring all staff members are protected with MFA are essential. This must also include administrators. Although testing these settings takes longer, it prevents future security problems.
Some updates can occur in the background. Whereas others have a more short-term impact on the daily activities of staff. However, when each step is planned and managed well, there will be no confusion and unneeded disruptions. A managed IT service provider suggests starting with audit retention and application permissions. Oftentimes, users will not notice those improvements. Next, verify external email forwarding policies since very few employees ever use external forwarding.
File sharing changes deserve advanced communication. This is because staff should understand new sharing requirements beforehand. Lastly, do MFA reviews until every other task is completed to prevent unintentionally locking out staff from the programs they are using. With some careful planning, there will be no need for unnecessary downtime and frustration. Regular Microsoft 365 reviews strengthen business security. Is your team still struggling or blissfully ignorant about these issues? We can help!