The short answer is that a brand-new Microsoft 365 tenant created today is reasonably secure, and considerably more so than one created five years ago. The longer and more useful answer is that almost nobody is running a brand-new tenant, and the difference between the two is where most SME risk lives.

What Microsoft actually gives you

Microsoft operates on a shared responsibility model. They secure the platform — the datacentres, the hypervisors, the service code, the availability of the thing itself. That part they do well, at a scale no individual business could match.

What sits on your side of the line is everything about how the service is configured for your organisation: who has access, what they can reach, which devices are permitted, what happens when someone leaves, and what is recorded.

Recent tenants get some helpful defaults. Security defaults enforce multi-factor authentication for all users and block legacy authentication protocols. That single measure removes a large proportion of the commodity attacks that succeed against smaller organisations. Newer tenants also get sensible starting positions on external sharing and app consent.

If you set up Microsoft 365 last month, left security defaults on, and have not changed anything since, your baseline is genuinely reasonable.

Why established businesses are not in that position

Almost every organisation we assess has a tenant that has been through some combination of:

  • A migration from on-premises Exchange, under time pressure, with settings relaxed to get it done
  • The 2020 shift to remote working, which required rapid decisions about device access and sharing
  • A merger or acquisition, bringing a second directory and a set of guest accounts
  • Two or three changes of IT provider, each inheriting the previous one’s decisions and reasonably assuming they were deliberate
  • Individual exceptions granted to individual people for individual reasons, none of them recorded

None of these are failures. They are what running a business looks like. But the cumulative effect is a configuration nobody designed and nobody has reviewed as a whole.

The findings that recur

Across Microsoft 365 reviews, the same items come up repeatedly. Not one dramatic hole — a collection of small ones.

MFA exclusions that outlived their purpose. Security defaults get disabled to accommodate a system that could not handle modern authentication, or an exclusion group is created for a migration. The system is later replaced or the migration completes, and the exclusion stays. We routinely find groups created three or four years ago still containing active users.

Too many Global Administrators. The role gets handed out because someone needed to do one thing, and it is never taken back. Ten or more is common in an organisation of a hundred people. Each one is an account whose compromise gives an attacker complete control of your email, files and identity system.

Anonymous sharing links with no expiry. “Anyone with the link” is convenient, and by default those links do not expire. Tenants that have been running for several years commonly hold thousands, some pointing at folders that have since accumulated far more sensitive material than they held when the link was created.

Application consents nobody remembers granting. A user trials a productivity tool, clicks through a consent prompt, and that application now holds standing permission to read their mail or files. The trial ends; the consent does not.

Departed staff who are still present. Not just an active mailbox, but group memberships, application access, shared mailbox permissions and — occasionally — a mobile device still syncing.

Audit logging that will not answer the question. Logging is enabled, but retention under your licence tier is shorter than the time it typically takes to notice an intrusion. When you finally need to establish what happened, the record has already rolled off.

Security defaults or Conditional Access?

This is where a lot of organisations end up in an unintended middle position.

Security defaults are a single switch: MFA for everyone, legacy authentication blocked, no exceptions and no configuration. For a small organisation with straightforward needs, they are an excellent answer.

Conditional Access is the flexible alternative available with Entra ID Plan 1 — included in Business Premium and most enterprise plans. It lets you require MFA in specific circumstances, demand a compliant device, block sign-in from countries you never operate in, and treat administrators differently from everyone else.

The problem arises when an organisation turns security defaults off in order to build Conditional Access policies, and then builds them partially. We have seen tenants where security defaults were disabled in preparation for a Conditional Access design that was never finished — leaving no baseline MFA enforcement at all. The intention was an improvement; the outcome was a regression.

If you have disabled security defaults, it is worth confirming that what replaced them actually covers every account.

What “good” looks like for an SME

You do not need an enterprise security programme. For most organisations between twenty and five hundred staff, a defensible position looks like this:

  • MFA enforced on every account, with exclusions limited to documented break-glass accounts that are monitored
  • Global Administrator held by two named accounts, elevated when needed rather than permanently
  • Conditional Access requiring a managed or compliant device for access to company data
  • External sharing restricted to a deliberate set of cases, with link expiry enforced
  • Application consent restricted so users cannot grant broad access to their own data
  • Audit logging retained long enough to investigate, with alerting on privileged role changes
  • A leaver process that is documented, followed, and includes access review rather than just licence removal

Every one of these is achievable on Business Premium. None requires E5.

The honest summary

Microsoft 365 is not insecure by default. It is unconfigured by default, and after a few years of ordinary business activity it is misconfigured in ways nobody chose.

The remedy is not a product. It is someone looking at the whole tenant carefully, establishing what is actually set, and correcting it in an order that does not disrupt your staff. That is a matter of a couple of weeks’ work, and it is usually the highest-value security spend available to an SME.