Old Microsoft 365 Settings Can Leave Security Gaps Behind

Picture of Ikram Massabini

Ikram Massabini

July 27, 2026

Old Microsoft 365 Settings Can Leave Security Gaps Behind

Microsoft has tightened many Microsoft 365 defaults over the past few years.

That is good news for new tenants.

The problem is that older tenants do not always inherit those safer settings automatically. If your Microsoft 365 environment was set up years ago, inherited from another IT provider, or never fully audited, some older configurations may still be sitting in place.

That can leave gaps around file sharing, email forwarding, third-party apps, audit logs, and MFA.

Microsoft 365 may be secure by design, but it still needs to be reviewed in the real environment your business is using every day.

File Sharing Links May Be Too Open

SharePoint and OneDrive make it easy to share files, but the default link setting matters.

In some older Microsoft 365 tenants, sharing may still default to “Anyone with the link.” That means the person receiving the link may not need to sign in, and the file can be forwarded to someone else without much visibility.

That is fine for a public flyer. It is not fine for proposals, HR files, financial documents, client records, or internal project information.

A better default is “Specific people,” which requires authentication and keeps access more controlled. It is also smart to set expiration dates for any remaining anonymous links so old shares do not stay active forever.

External Email Forwarding Should Be Checked

Attackers love inbox forwarding rules.

If they compromise an email account, they may set up a rule that quietly copies messages to an outside address. That gives them time to monitor invoices, payment requests, client conversations, and internal communication without raising obvious alarms.

Microsoft now blocks automatic external forwarding by default in many cases, but older rules or custom policies may still exist.

The setting should be checked at the tenant level, and existing mailbox rules should be reviewed for forwarding to personal or unknown addresses.

Third-Party App Access Can Linger

Many users have clicked “allow” on a third-party app at some point.

Maybe it was a scheduling tool, PDF editor, CRM add-on, AI tool, browser app, or project platform. Some of those apps may have been granted access to mail, calendars, files, or contacts.

The issue is that those permissions can stay active long after the tool is forgotten.

A Microsoft 365 review should include Enterprise Applications in Entra ID. Look for apps with access to email, files, sites, or calendars. Anything unknown, unused, or unnecessary should be revoked.

This is especially important for businesses that have used Microsoft 365 for several years without reviewing app consent.

Audit Logs Need Enough History

Audit logs are what help a business understand what happened after something goes wrong.

Who accessed a file? Who created an inbox rule? Who changed a setting? When did the activity start?

If log retention is too short, that evidence may be gone by the time the business needs it.

Microsoft 365 audit retention has improved, but the right retention period depends on the business, the industry, and the licensing in place. Healthcare, legal, financial, and regulated organizations may need longer retention than the default provides.

The key is to know what is being logged, how long it is kept, and whether those logs are useful during an investigation.

MFA and Conditional Access Can Be Inconsistent

Older tenants often have uneven MFA coverage.

Some users may have MFA. Admins may have it. Remote access may or may not require it. Service accounts or break-glass accounts may be excluded. Security Defaults may be off because Conditional Access was enabled, but the Conditional Access policies may not cover everyone.

That is a common configuration gap.

MFA should be reviewed across all users, admins, remote access, and high-risk accounts. Conditional Access should be mapped carefully so the business knows exactly who is protected and where exceptions exist.

A Tenant Review Is Worth the Time

For companies using Microsoft 365 every day, small settings can create large exposure.

A file link that never expires, a forgotten forwarding rule, an old app permission, short audit history, or uneven MFA enforcement may not seem urgent on its own. Together, they can create avoidable risk.

A practical review does not have to happen all at once. Start with the quiet items first: app consent, audit logs, and forwarding rules. Then review sharing defaults and MFA policies with a communication plan so employees understand what is changing.

The goal is not to make Microsoft 365 harder to use.

The goal is to make sure the settings match how the business works now, not how the tenant was configured years ago.

Do Not Assume Defaults Fixed It

Microsoft continues to improve its security defaults, but those improvements do not replace an actual tenant review.

If your Microsoft 365 environment has been around for a few years, it is worth checking what is still active, what is still allowed, and what needs to be tightened.

The best security settings are the ones that are not only available, but actually turned on.