"It's Microsoft — isn't it already secure?" It's a fair question, and the honest answer is: not the way it arrives. Microsoft 365 is a serious, capable platform. But out of the box it's optimized to get you up and running quickly and painlessly, not to keep a determined attacker out. The safety rails exist — they're just left down so setup is easy. Putting them up is somebody's job, and by default that job is left undone.
Microsoft will even show you the gap
You don't have to take our word for it. Buried in the admin center is a running tally Microsoft calls Secure Score, with a companion compliance score in Purview. They grade your tenant against Microsoft's own recommended settings and hand you a number. A fresh tenant that nobody has hardened almost always scores low — and that's not a defect. It's the defaults doing exactly what they were designed to do: get you working fast, with the security decisions left for you or your IT provider to make later. Most practices never make them.
The doors that get left open
When we take over a tenant that's never been hardened, it's the same short list of open doors nearly every time:
- Legacy authentication. Old protocols like IMAP, POP, and basic sign-in that were built before multi-factor existed. They're an attacker's favorite because they walk right past MFA. Leave them on and your multi-factor has a back door.
- Automatic external forwarding. A mailbox quietly set to copy every incoming email to an outside address. It's how email-account thefts run for months without anyone noticing. Allowed by default; almost never actually needed.
- Shared logins. One username the whole front desk signs into. When everyone is "the same person," your records can't tell you who did what — and one leaked password unlocks everything.
- MFA left optional. The basic setup treats multi-factor as a suggestion, not a rule. A password on its own is a single point of failure.
- Wide-open sharing. Files and links shareable with anyone, anonymously, with no expiration — a slow leak of whatever lives in your OneDrive and SharePoint.
What we turn off — and what we turn on
Hardening a tenant isn't one switch. It's a checklist we run on every one we manage:
- Enforce MFA for everyone through Conditional Access — with extra scrutiny for sign-ins from outside the country or from unmanaged devices.
- Disable legacy authentication completely, so there's no way around that MFA.
- Block automatic external forwarding and get alerted the moment a new forwarding rule is created.
- Kill shared credentials. Every person gets their own account, so the logs actually mean something.
- Push a device baseline — drive encryption, screen-lock timeouts, USB control, Defender turned up, and a real password policy on every machine.
- Rein in sharing — no anonymous links, expirations on the rest, outside guests only where there's a reason for them.
- Turn on audit logging and keep it — so if anything ever does go wrong, there's a record to follow.
- Layer on anti-phishing and safe links so bad mail gets caught before it reaches the front desk.
Why the score is the whole point
Secure Score and the compliance score turn "are we secure?" from a shrug into a number you can watch. We drive it up when we take a tenant over, and we keep it up as Microsoft adds new recommendations over time. This isn't vanity. A documented, improving score is exactly what a cyber-insurance underwriter asks to see, and it lines up directly with the technical safeguards a HIPAA risk assessment expects. When your security is a number moving in the right direction, you can actually prove you're taking it seriously.
A 60-second test for your own setup
You don't need to open the admin center to get a feel for where you stand. Ask whoever runs your IT three questions:
- Is legacy authentication turned off in our tenant?
- Is automatic external email forwarding blocked?
- What's our Secure Score today — and where was it when you started?
If those get blank stares, the doors are probably still open. And here's the kicker: on most business plans, none of this costs extra. It's included in what you already pay for. It just has to be turned on — and kept on.
