Security

5 Microsoft 365 Settings to Check in Your Tenant

Microsoft 365 settings

Your Microsoft 365 Tenant May Not Be As Secure As You Think

Microsoft has tightened its default settings in Microsoft 365 considerably over the past few years. New tenants get meaningful protection straight out of the box. The catch? Legacy configurations don’t update themselves. A setting Microsoft changed for new tenants in 2024 won’t retroactively apply to yours — and historical user consents, inbox rules, and sharing links stay exactly where they were.

If your tenant is more than two or three years old, was set up by a previous IT provider, or hasn’t been formally reviewed, it’s worth working through the following five areas. A few things to note before you start: some of these settings require Microsoft 365 Business Premium, E3, or E5 licensing, so grayed-out toggles usually mean a licence issue. And not all of these changes are invisible to your team — a couple will change how things already work, so plan accordingly.

If your tenant predates Microsoft’s tightened sharing defaults, the default link scope is likely still set to “Anyone with the link” — meaning no sign-in required, no expiry, and no visibility over where the link gets forwarded.

In the SharePoint admin centre under Policies > Sharing, switch the tenant default to “Specific people” so every new link requires authentication. You can also set a maximum expiry on any remaining “Anyone” links. This doesn’t affect existing links until they’re regenerated, so it’s low-risk to action.

Estimated time: 15 minutes.

2. External Email Forwarding Rules

Microsoft’s outbound spam policy now blocks automatic email forwarding to external addresses by default. But tenants with custom outbound spam policies configured before this change may not reflect the current default — and inbox rules created before the policy was enforced can still be active.

In the Microsoft Defender portal, navigate to Email & Collaboration > Policies & Rules > Anti-spam policies > Anti-spam outbound policy and confirm automatic forwarding is set to “Off” or “Automatic - System-controlled.” Then use the Microsoft Purview audit log to search for inbox rule creation events across your mailboxes and identify any rules forwarding to external addresses.

This is a common data exfiltration vector worth closing off — it aligns directly with ACSC Essential Eight controls around restricting administrative privileges and auditing.

Estimated time: 10 minutes to verify the tenant setting; longer for a full mailbox audit.

3. Historical Third-Party App Consents

As of mid-2025, Microsoft routes new third-party app consent requests through an admin for review. The problem is everything consented to before that policy existed — apps granted access to mail, calendars, and files that nobody may remember approving.

In Microsoft Entra ID > Enterprise Applications > All applications, sort by user consent and review what currently has access to sensitive data. Revoke anything unfamiliar or no longer needed from the same screen.

Estimated time: 30”“60 minutes depending on how many historical apps are in the list.

4. Audit Log Retention in Microsoft Purview

Since October 2023, Audit (Standard) logs are retained for 180 days. Organisations with E5 licensing or the Microsoft Purview Audit (Premium) add-on get 12 months for Exchange, SharePoint, OneDrive, and Entra ID records.

If you operate in a regulated industry — financial services, healthcare, legal — 180 days likely won’t meet your obligations under the Privacy Act or Notifiable Data Breaches scheme. Audit retention policies sit in the Microsoft Purview compliance portal under Audit > Audit retention policies.

Estimated time: 15 minutes to configure once licensing is confirmed.

5. MFA Enforcement and Conditional Access

This is the area most likely to be inconsistent in older tenants. Microsoft’s Security Defaults, introduced in 2019, enforce MFA automatically on new tenants. Older tenants may have no baseline enforcement at all.

There’s also a common configuration trap: when an admin enables a Conditional Access policy, Security Defaults may be turned off — and if the Conditional Access policy doesn’t cover every user, you’re left with gaps.

Check three places in Entra ID: confirm whether Security Defaults is on or off under Properties > Manage Security Defaults; confirm a Conditional Access policy is actively enforcing MFA for all users under Protection > Conditional Access; and pay close attention to break-glass admin accounts, which are sometimes excluded and left without MFA entirely.

Estimated time: Around an hour, longer if Conditional Access has several existing policies to map through.

A Sensible Order to Work Through the Changes

Not all of these changes are visible to your team. Start with audit log retention and the historical app consent review — no user-facing impact. Verifying external forwarding is also silent in most cases. Save the sharing default and MFA review for last; both can affect day-to-day workflows and deserve proper planning and communication before you make changes.


Not sure when your tenant was last reviewed? We can work through these settings with you and flag anything that needs attention. Get in touch with the team at IT TechNinjas — or if you’re looking for a more structured approach to securing your Microsoft 365 environment, take a look at our Safe to Scale programme.

Ready to scale safely?

Book a discovery call and we'll map out where you stand and what comes next.