There's a comfortable assumption that comes with moving to Microsoft 365: it's Microsoft, it's the cloud, so security is handled. The platform genuinely is strong — Microsoft invests more in securing it than any single business ever could. But the security you get depends entirely on how it's configured, and the defaults are built for easy adoption, not for a locked-down tenant.

Put plainly: Microsoft secures the platform. You're responsible for securing your use of it. That line is where most of the risk lives, and it's where we find the same gaps over and over.

The gaps we see most often

Multi-factor authentication that isn't actually enforced. It's available on every plan, but we routinely find it switched on for some accounts and not others, or left optional. One executive mailbox without it is all an attacker needs.

Legacy sign-in methods left open. Older authentication protocols that bypass modern protections are still enabled in a surprising number of tenants, quietly undoing the MFA you thought you had.

Oversharing by default. Files and folders shared more broadly than anyone intended, guest access that was never reviewed, and link-sharing settings that let “anyone with the link” reach things that should never have left the building.

No alerting on the obvious red flags. A login from another country, a mailbox rule that auto-forwards to an outside address, a sudden burst of file downloads — all of these can be caught automatically. In an unconfigured tenant, nobody is watching.

Why this keeps happening

None of these are exotic. They're the result of a migration that got the email flowing and the documents moved — the visible part of the job — and then stopped. The hardening, the part nobody sees, never got done. The tenant works, so it looks finished.

Treat the tenant like infrastructure

A Microsoft 365 environment deserves the same discipline as any other critical system: enforced identity protection, least-privilege access, monitoring on the events that matter, and a periodic review as people and permissions change. The platform gives you every tool to do this well. It just won't do it for you. That part is a decision — and someone has to own it.