IT helpdesk support headset icon
Talk to our experts for fast, reliable IT support.

connectivity

10 Microsoft 365 Settings Most Australian Businesses Have Wrong

Most businesses have Microsoft 365 but very few have it configured correctly. Here are the most common security and configuration gaps — and how to fix them.
August 21, 2026
Matt Scott, Technical Director — Tyto IT
6 min read
Microsoft 365

Why Microsoft 365 Configuration Matters

Microsoft 365 is the most widely deployed business productivity platform in Australia. But deploying it and configuring it correctly are two entirely different things. Out-of-the-box Microsoft 365 settings are designed for ease of use, not security. Without deliberate configuration, your environment is almost certainly less secure than it should be — and you’re likely not getting full value from what you’re paying for.

The 10 Most Common Microsoft 365 Gaps

1. Multi-Factor Authentication Not Enforced for All Users

Microsoft reports that MFA blocks over 99% of account compromise attacks. Yet many organisations have MFA enabled but not enforced — leaving it optional for staff who choose convenience over security. Every user account should have MFA enforced via Conditional Access policies, with no exceptions.

2. Legacy Authentication Protocols Still Enabled

Older protocols like Basic Authentication bypass MFA entirely. Attackers know this. Legacy authentication should be blocked via Conditional Access unless there is a specific, documented business requirement for it.

3. Security Defaults or Conditional Access Not Configured

Microsoft provides Security Defaults as a baseline, but they’re not sufficient for most businesses. Properly configured Conditional Access policies are necessary to enforce MFA contextually, block risky sign-ins, require compliant devices, and control access by location.

4. SharePoint and OneDrive External Sharing Too Permissive

Default SharePoint settings allow broad external sharing. Most businesses should restrict external sharing to specific domains or require access requests to be approved, rather than allowing staff to share files with anyone who has the link.

5. Microsoft 365 Backup Not in Place

Microsoft does not back up your data. The shared responsibility model means Microsoft guarantees platform availability — your data protection is your responsibility. Emails, SharePoint files, and Teams conversations need third-party backup (such as Veeam for Microsoft 365) to be protected against accidental deletion, malicious deletion, and ransomware.

6. Audit Logging Not Enabled

Microsoft 365 audit logging is not enabled by default on all plans. Without audit logs, you have no visibility into who did what, when — which is critical for investigating security incidents and meeting compliance requirements.

7. Microsoft Secure Score Not Monitored

Microsoft Secure Score provides a quantified measure of your security posture and specific improvement recommendations. Most organisations have a Secure Score well below where it should be, simply because no one is monitoring or acting on the recommendations.

8. Privileged Accounts Without Just-in-Time Access

Global administrator accounts should not be used for daily work. Microsoft Entra Privileged Identity Management (PIM) provides just-in-time elevated access — administrators request elevation when needed, and access expires automatically. Most businesses skip this configuration entirely.

9. Email Authentication Records Incomplete

SPF, DKIM, and DMARC records in DNS prevent email spoofing and protect your domain from being used in phishing attacks. Many businesses have SPF but not DKIM or DMARC — leaving a significant gap in email security.

10. Licences Misaligned to User Needs

Most businesses have at least 10–25% of their Microsoft 365 licences either over-provisioned (paying for premium features users don’t need) or misaligned (users lacking features their role requires). A licensing audit typically identifies meaningful monthly savings.

How to Fix These Gaps

A professional Microsoft 365 review covers all of these areas and more. The process involves benchmarking your current configuration against Microsoft’s own best practice frameworks, implementing targeted improvements, and establishing ongoing monitoring to catch new issues as they emerge. For most businesses, a single review pays for itself through licensing savings alone — before the security improvements are even considered.

Need support now?

Having an IT issue right now? Call our helpdesk on 1300 070 565 — you’ll speak to a real engineer who already knows IT, not a call centre script.
Support Portal
Circular dark gray button with a white arrow pointing diagonally up and right.Black arrow pointing diagonally upward and to the right on white background.

empowering businesses with tailored IT solutions

Contact Us Now
©2026 Tyto. All rights reserved.