
Microsoft 365 is the most widely deployed business productivity platform in Australia. But deploying it and configuring it correctly are two entirely different things. Out-of-the-box Microsoft 365 settings are designed for ease of use, not security. Without deliberate configuration, your environment is almost certainly less secure than it should be — and you’re likely not getting full value from what you’re paying for.
Microsoft reports that MFA blocks over 99% of account compromise attacks. Yet many organisations have MFA enabled but not enforced — leaving it optional for staff who choose convenience over security. Every user account should have MFA enforced via Conditional Access policies, with no exceptions.
Older protocols like Basic Authentication bypass MFA entirely. Attackers know this. Legacy authentication should be blocked via Conditional Access unless there is a specific, documented business requirement for it.
Microsoft provides Security Defaults as a baseline, but they’re not sufficient for most businesses. Properly configured Conditional Access policies are necessary to enforce MFA contextually, block risky sign-ins, require compliant devices, and control access by location.
Default SharePoint settings allow broad external sharing. Most businesses should restrict external sharing to specific domains or require access requests to be approved, rather than allowing staff to share files with anyone who has the link.
Microsoft does not back up your data. The shared responsibility model means Microsoft guarantees platform availability — your data protection is your responsibility. Emails, SharePoint files, and Teams conversations need third-party backup (such as Veeam for Microsoft 365) to be protected against accidental deletion, malicious deletion, and ransomware.
Microsoft 365 audit logging is not enabled by default on all plans. Without audit logs, you have no visibility into who did what, when — which is critical for investigating security incidents and meeting compliance requirements.
Microsoft Secure Score provides a quantified measure of your security posture and specific improvement recommendations. Most organisations have a Secure Score well below where it should be, simply because no one is monitoring or acting on the recommendations.
Global administrator accounts should not be used for daily work. Microsoft Entra Privileged Identity Management (PIM) provides just-in-time elevated access — administrators request elevation when needed, and access expires automatically. Most businesses skip this configuration entirely.
SPF, DKIM, and DMARC records in DNS prevent email spoofing and protect your domain from being used in phishing attacks. Many businesses have SPF but not DKIM or DMARC — leaving a significant gap in email security.
Most businesses have at least 10–25% of their Microsoft 365 licences either over-provisioned (paying for premium features users don’t need) or misaligned (users lacking features their role requires). A licensing audit typically identifies meaningful monthly savings.
A professional Microsoft 365 review covers all of these areas and more. The process involves benchmarking your current configuration against Microsoft’s own best practice frameworks, implementing targeted improvements, and establishing ongoing monitoring to catch new issues as they emerge. For most businesses, a single review pays for itself through licensing savings alone — before the security improvements are even considered.