10 Microsoft 365 Security Mistakes We See in London SMEs

200+ Articles published
5 IT topics covered
20+ Years of IT expertise
CE+ Cyber Essentials Plus
Share
In This Article
    Speedster IT
    Worried About Cyber Threats?

    Get a free cyber security review and find out where your business is exposed.

    Explore Cyber Security

    Why Microsoft 365 Security Gaps Leave London Businesses Exposed

    Microsoft Secures the Platform, but Businesses Must Manage Access

    Microsoft secures the platform itself. Your business is responsible for who has access, what they can see, and how that access is controlled, the exact area our IT security services for London businesses are built to cover. Most real-world gaps live in that second half, often called the shared responsibility model.

    Why Small Configuration Gaps Can Create Wider Business Risk

    One account without MFA. One oversharing link. One former employee’s login left active. Each looks minor on its own. Together, they give an attacker several easy ways into the business, exactly the kind of thing a free IT audit is designed to catch.

    What This Article Covers

    Microsoft 365 is secure by design, but most of the security incidents we see in London SMEs come down to configuration, not a flaw in the platform. As part of our Microsoft 365 support work, we come across the same mistakes again and again. Here are ten of the most common ones, what each exposes, and what to check in your own environment.

    1. Not Enforcing Multi-Factor Authentication for Every User

    Why Protecting Only Administrator Accounts Is Not Enough

    Many businesses enable MFA for administrators and assume that covers the risk. It does not. Standard user accounts often hold access to email, SharePoint, Teams and OneDrive, and attackers know these accounts are frequently the least protected.

    Service Accounts and Other MFA Exceptions Attackers Can Target

    Service accounts, shared mailboxes and legacy integrations are often excluded from MFA policies for convenience. These exceptions rarely get revisited once they are set up, which makes them an attractive, quiet target for attackers looking for the path of least resistance.

    What London SMEs Should Review

    Check the following across every account in your tenant:

    • Which accounts are currently excluded from MFA
    • Why each exception exists
    • Whether that exception is still genuinely needed

    Every user account should be protected, not just administrators, because compromised standard accounts can still provide access to email, files and internal communications.

    Is Multi-Factor Authentication Enough to Protect Microsoft 365 on Its Own?

    MFA is one of the most effective security controls available, but it is not enough by itself. Attackers increasingly use techniques such as consent phishing, session token theft, social engineering, and MFA fatigue, which can bypass or weaken MFA protections if no other controls are in place. We have covered this specific technique in more detail in what is MFA fatigue.

    2. Giving Too Many Users Administrator Access

    Why Global Administrator Accounts Carry Greater Risk

    A Global Administrator account can change settings across the entire Microsoft 365 tenant. If one of these accounts is compromised, the impact is far greater than a standard user account being compromised. The more Global Administrator accounts exist, the more opportunities an attacker has.

    The Difference Between Everyday and Administrative Accounts

    Staff who need administrative rights for a specific task should ideally use a separate administrative account for that task, rather than an all-purpose login used for email and daily work. Mixing the two increases the chance that an everyday phishing attempt lands on a highly privileged account.

    How Least-Privilege Access Reduces Exposure

    Least-privilege access means giving each user only the permissions needed for their role, nothing more. Reviewing who genuinely needs elevated access, and removing it from everyone else, is one of the simplest ways to limit the damage a single compromised account can cause.

    How Many Administrators Should a Business Have in Microsoft 365?

    Only users who genuinely require elevated privileges should hold administrator rights. Keeping the number of Global Administrator accounts as small as possible reduces the impact of any single credential being compromised, and supports least-privilege security principles.

    3. Leaving Former Employee Accounts Active

    How Dormant Accounts Become an Unmonitored Entry Point

    When someone leaves a business, their Microsoft 365 account should be disabled promptly. In practice, we regularly find accounts still active weeks or months after someone has gone. These accounts are rarely monitored closely, which makes them an easy, quiet way in.

    What a Secure Microsoft 365 Leaver Process Should Cover

    A proper leaver process should:

    • Disable the account immediately
    • Remove or reassign licences
    • Revoke active sessions
    • Check what devices and applications still hold a connection to that account

    Doing this consistently, every time, matters more than doing it well once.

    Why Access to Teams, SharePoint and Shared Mailboxes Must Be Reviewed

    Disabling the main login is only part of the process. Former employees are often still listed as members of Teams, SharePoint sites and shared mailboxes, sometimes with access that was never formally removed. These need to be reviewed separately, not assumed to disappear with the account.

    4. Relying on Passwords or Basic Security Defaults Alone

    Why Password Security Cannot Carry the Full Load

    Even a strong password policy does not stop credential theft, phishing or reused passwords from other breaches. Password strength alone was never designed to be the only line of defence, and treating it as one leaves an obvious gap.

    When London SMEs Should Consider Conditional Access

    Conditional Access becomes worth considering once a business wants more control over how and where accounts can be accessed, particularly with hybrid or remote teams using a mix of personal and company devices.

    What Is Conditional Access in Microsoft 365?

    Conditional Access allows a business to control sign-in based on factors such as location, device health and sign-in risk. It can require extra verification for unusual sign-ins, or block access outright from locations and devices the business does not recognise.

    How Device, Location and Sign-In Context Affect Access Decisions

    Without Conditional Access, Microsoft 365 generally treats a sign-in from a recognised password the same everywhere, whether it comes from a company laptop in the office or an unfamiliar device overseas. Adding context to that decision closes an obvious gap that relies purely on the password being correct. This matters more with hybrid and remote teams, which we cover further in our remote work cybersecurity checklist.

    5. Failing to Block Legacy Authentication

    Why Older Authentication Methods Create Security Gaps

    Legacy authentication protocols were built before modern MFA existed, and they do not support it. An account that can still sign in using a legacy protocol can effectively bypass MFA altogether, regardless of how well MFA is configured everywhere else.

    Which Business Systems May Still Depend on Older Connections

    Systems that can still rely on legacy authentication behind the scenes include:

    • Older printers and scan-to-email systems
    • Line-of-business software
    • Some third-party integrations

    This is usually why legacy authentication gets left enabled long after it should have been switched off.

    Why Changes Should Be Assessed Before Legacy Access Is Disabled

    Blocking legacy authentication without first identifying what depends on it can break working systems overnight. It is worth reviewing sign-in logs for legacy protocol usage before disabling it, so nothing business-critical stops working unexpectedly.

    6. Mismanaging SharePoint, OneDrive and Teams Permissions

    How Permission Sprawl Builds Up Over Time

    As people join projects, change roles or move teams, they tend to accumulate access rather than have it reassessed. Over months and years, this builds into permission sprawl, where individuals end up with far more access than their current role actually needs.

    What Is Permission Sprawl in Microsoft 365?

    Permission sprawl happens when users gradually build up access to files, folders, Teams and SharePoint sites over time, without that access ever being reviewed or removed. It increases the risk of sensitive information being seen by people who no longer need to see it.

    The Risks of Public Links and Unrestricted External Sharing

    Public “anyone with the link” sharing is convenient, but it removes control over who can view a document once the link exists. Combined with permission sprawl, this can mean sensitive files are more widely accessible than anyone in the business realises.

    Is SharePoint External Sharing Safe?

    External sharing can be managed securely, but only with proper governance. Risks come from unreviewed guest access, unrestricted “anyone” links, and permissions that were never revisited. Regular audits keep shared content appropriately restricted rather than quietly expanding over time.

    Why Guest Users and Old Group Memberships Need Regular Reviews

    Guest accounts added for a specific project often outlive that project. Old group memberships work the same way. Reviewing both regularly is one of the more overlooked steps in keeping Microsoft 365 permissions under control.

    Can Microsoft Copilot Expose Information That Was Already Overshared?

    Microsoft Copilot does not bypass Microsoft 365 permissions. It works within the access a user already has. The concern is that Copilot makes existing information much easier to find and summarise, so historical oversharing and permission sprawl become more visible than before. This is exactly why reviewing permissions matters more, not less, as businesses start adopting AI tools.

    Work With Speedster IT

    Want IT support that actually works?

    Talk to us about how your IT is supported today, and what a managed IT partner should be taking off your plate.

    Talk to Our Team

    7. Overlooking App Consent and Third-Party Application Access

    What Microsoft 365 App Consent Phishing Looks Like

    App consent phishing does not try to steal a password. Instead, a user is persuaded to approve a permissions request from a malicious or unfamiliar application, often through a convincing-looking prompt or email. Once approved, that application can access Microsoft 365 data on the user’s behalf.

    Why MFA Does Not Solve Every App-Permission Risk

    MFA protects the sign-in itself, but an approved application consent grant does not require a fresh sign-in each time it accesses data. This means MFA, however well configured, does not directly stop a malicious app that has already been granted permission.

    Why Is App Consent Phishing Becoming More Common?

    As MFA adoption has grown, traditional password-stealing phishing has become harder to pull off. Attackers have adapted by looking for alternative routes in, and persuading a user to approve a third-party application is one of the more effective ones currently in use.

    How to Review Applications Connected to Business Data

    Most businesses have never reviewed which third-party applications have been granted access to their Microsoft 365 data. A periodic review of connected apps, removing anything unfamiliar or no longer in use, closes a gap that MFA alone cannot cover.

    8. Assuming Microsoft 365 Email Is Fully Protected by Default

    Why Phishing and Impersonation Require Dedicated Controls

    Microsoft 365 includes baseline email protection, but sophisticated phishing and impersonation attempts often need additional, deliberately configured controls to catch reliably. Assuming the defaults are enough is one of the more common gaps we find.

    The Role of SPF, DKIM and DMARC

    SPF, DKIM and DMARC are email authentication standards that help prevent attackers from sending convincing emails that appear to come from your own domain. Without them correctly configured, it becomes much easier for a criminal to impersonate your business in an email to a customer or supplier.

    When Safe Links, Safe Attachments and Impersonation Protection Matter

    Features such as Safe Links, Safe Attachments and impersonation protection, available through Microsoft Defender for Office 365, add real-time scanning and checks that standard Microsoft 365 email security does not include on its own. These become increasingly important as phishing techniques evolve.

    9. Having No Data Loss Prevention or Retention Strategy

    Why Sensitive Data Needs More Than Access Permissions

    Permissions control who can open a file. They do not stop that file being emailed, copied or shared once someone has legitimate access to it. Data Loss Prevention policies add a further layer, flagging or blocking sensitive information such as card details or personal data from leaving the business inappropriately.

    How Uncontrolled Data Sharing Creates Compliance Problems

    Without any retention or data governance policy, businesses can end up holding, or losing, information in ways that create compliance problems later, particularly around data protection obligations and how long certain records should genuinely be kept.

    The Importance of Matching Retention Rules to Business Requirements

    Default retention settings rarely match a specific business’s actual regulatory or operational needs. Retention policies should be set deliberately, based on what the business is required to keep, for how long, and what should be safely removed.

    10. Treating Microsoft 365 Security as a One-Off Setup

    Why Permissions and Risks Change as the Business Grows

    A Microsoft 365 environment that was configured securely at launch will not stay that way on its own. New starters, leavers, new projects and new integrations all change the picture over time, whether anyone is actively tracking it or not.

    What Continuous Monitoring Can Reveal

    Ongoing monitoring can surface unusual sign-ins, risky permission changes and suspicious application activity long before they turn into an actual incident. Without it, these signs typically go unnoticed until something has already gone wrong.

    How Regular Security Reviews Reduce Configuration Drift

    Configuration drift is what happens when small, individually reasonable changes gradually move an environment away from its original, secure setup. Regular reviews catch this drift early, rather than leaving it to accumulate for years between checks.

    How Often Should Microsoft 365 Permissions Be Reviewed?

    Permissions should be reviewed on a regular schedule, and whenever there is a significant change in staffing, departments or supplier relationships. It is also worth periodically auditing external sharing, guest accounts and group memberships as a routine check, not just after an incident.

    How Can a Microsoft 365 Security Audit Identify These Gaps?

    Rather than checking each of the ten mistakes above in isolation, an audit looks at your whole environment in one pass and tells you where the real risk sits.

    Identity, MFA and Administrator Access

    An audit starts by reviewing who has access, how they authenticate, and who holds elevated privileges. This alone typically surfaces several of the ten issues covered above.

    Email, Applications and External Sharing

    It then looks at email authentication settings, connected third-party applications, and how information is being shared both internally and externally.

    Data Governance, Devices and Monitoring

    Finally, it reviews data retention, device access and whether any ongoing monitoring is in place at all, since many businesses have none.

    What Does a Microsoft 365 Security Audit Actually Deliver?

    A useful audit does not stop at a list of findings. It should give you a prioritised, plain-English report you can act on, showing which issues carry the most risk and which can wait, rather than a generic checklist applied the same way to every business.

    Prioritising Remediation Without Disrupting the Business

    Not every finding needs fixing on day one. Sequencing changes correctly means the highest-risk issues get closed first, without disrupting day-to-day work while the rest are addressed.

    How Speedster IT Helps London SMEs Secure Microsoft 365

    Fixing What the Audit Finds

    Once we know where your environment stands, we implement the changes ourselves, from enforcing MFA and tightening administrator access to cleaning up sharing permissions and blocking legacy authentication. We carry out this work as part of our Microsoft 365 consultancy and support for London businesses.

    Managed Security, Monitoring and User Support

    Beyond the initial fix, our cyber security services cover ongoing monitoring, MFA implementation and day-to-day user support, so improvements do not quietly slip once the initial project is finished. We have also written about how Microsoft 365 optimisation drives productivity for SMEs, alongside the security side covered here.

    Can Microsoft 365 Support Cyber Essentials Compliance?

    Yes, a well-configured Microsoft 365 environment, including MFA, access controls and patching, can help a business meet several of the technical requirements assessed under Cyber Essentials certification. We have covered the current certification requirements in our article on why Cyber Essentials is getting harder to pass in 2026.

    How Can a London IT Support Company Help Secure Microsoft 365?

    Being based locally means we can carry out an on-site review where it genuinely helps, not just a remote scan and a PDF. If you want a clearer picture of where your own environment stands, our free IT audit is a straightforward place to start.

    Related Reading

    Microsoft 365 and Copilot risk is closely linked to broader AI security concerns. Our article on AI-powered cyber attacks and how Microsoft 365 and Copilot are exposing businesses looks at this in more depth. If you want a wider view of how AI tools are changing business risk generally, see our article on 10 AI security risks every London business should know.

    Fixing configuration gaps reduces the chance of an incident happening in the first place, but no business can prevent every attack. Our article on building a cyber incident response plan covers what to do when prevention is not enough.

    Talk to Speedster IT About Microsoft 365 Security

    Not sure where your own Microsoft 365 environment stands? Speedster IT helps London businesses close these gaps with practical, prioritised reviews. Call us on 0204 511 9111, email hello@speedster-it.com, or get in touch to request a Microsoft 365 security audit.

    Ready to Talk?

    Let’s fix this properly.

    Book a free consultation with one of our engineers and find out what better IT support actually looks like.

    Get In Touch