BlogM365 SecurityThe 5 Most Common M365 Security Mistakes

The 5 Most Common M365 Security Mistakes Organisations Make

While AI dominates the cybersecurity conversation, the latest data from Microsoft and Verizon shows that most successful attacks still exploit basic weaknesses: stolen credentials, password spray, missing or inconsistent MFA, and weak access controls. Microsoft's Digital Defense Report 2025 reports that 97% of identity attacks are password spray, and Verizon's Data Breach Investigations Report identifies credential abuse as the leading initial access vector in confirmed breaches. The lesson is clear: before chasing the next advanced technology, organisations must first get the fundamentals right - starting with identity, MFA, device protection, and secure configuration of the Microsoft 365 stack.

In our assessments of Microsoft 365 tenants across organisations, the same security gaps appear again and again. These aren't obscure technical edge cases - they're foundational controls that have been missed, often because no one flagged them at initial setup.

1. MFA is not enforced

The single most impactful identity control available is Multi-Factor Authentication - and it is absent or incomplete in the majority of Microsoft 365 tenants we assess. "We have MFA available" is not the same as "MFA is enforced for all users." Without a Conditional Access policy that requires MFA, users can simply choose not to register, and many don't. A compromised password without MFA is a direct path into your entire Microsoft 365 environment: email, files, Teams, everything.

The evidence for MFA is unambiguous. A Microsoft Research study found that MFA reduces account compromise risk by 99.22% overall, and by 98.56% even when credentials have already been leaked - more than 99.99% of MFA-enabled accounts remained secure throughout the study period. Microsoft's Digital Defense Report 2025 reaches the same conclusion: modern MFA can prevent over 99% of identity-based attacks.

2. A single account is used for both admin tasks and daily work

Global Administrator accounts can reconfigure your entire Microsoft 365 tenant - reset any password, read any mailbox, disable any security control. Using a Global Admin account as your daily email inbox means every phishing email you receive is arriving in an account that has complete control over your tenant. If that account is compromised, the damage can be done in minutes. Dedicated admin accounts, used only for administrative tasks, dramatically reduce this risk.

3. SharePoint external sharing allows unauthenticated links

When the SharePoint sharing setting is set to "Anyone with a link," any user in your organisation can generate a file link that requires no sign-in and can be forwarded to anyone, indefinitely. This setting is often configured during initial setup for convenience and never revisited. A single carelessly forwarded link can expose confidential documents to an entirely unintended audience - with no record of who accessed them.

4. No DLP policies cover sensitive data

Without Data Loss Prevention policies, there is no technical barrier to an employee emailing a spreadsheet containing customer data, AHV numbers, or financial information to an external party - either intentionally or by mistake. DLP policies provide an automated guardrail that intercepts these transmissions before they occur, and generates an audit trail when they're overridden. They take under an hour to configure using Microsoft's built-in templates.

5. Devices are not enrolled in management

Unmanaged devices - personal laptops, company machines that were never enrolled in Intune - can access Microsoft 365 with valid credentials but are completely invisible to your security controls. You cannot enforce encryption on them, cannot remotely wipe them if lost, and cannot require them to be compliant before granting access. Every unmanaged device is a gap in your security perimeter. Intune enrolment is the prerequisite for almost every device-level security control in Microsoft 365.

The Kleeo M365 Health Check identifies all five of these issues - and more - automatically, so you know exactly where you stand.

Start your free Health Check