A Microsoft 365 tenant that was stood up quickly and never revisited is one of the most common things we are asked to look at. Mail flows, people can log in, so nobody goes back to it. Meanwhile the defaults — which Microsoft tunes for compatibility rather than security — are still in place years later.
These are the five we check first. None of them cost anything beyond the licensing you already hold.
1. Multi-factor authentication, actually enforced
Not “available”. Not “enabled for admins”. Enforced for every account, including shared mailboxes with sign-in enabled and the service account somebody created for the copier. Credential theft is overwhelmingly the way small organisations get breached, and MFA is the single control that most reliably stops it.
Expect a week of friction during rollout and then nothing. Plan the rollout, communicate it, and do not exempt the leadership team — they are the most targeted accounts you have.
2. Legacy authentication, switched off
Legacy protocols such as IMAP, POP and older Exchange clients cannot do MFA. While they remain enabled, an attacker with a valid password can simply authenticate over a protocol that never asks for a second factor, and your MFA rollout has bought you much less than you think.
Check your sign-in logs for legacy auth before you block it. Usually it is one scanner and one old phone.
3. SPF, DKIM and DMARC — at enforcement
Most tenants we review have an SPF record, no DKIM signing, and a DMARC policy of p=none. That combination tells the world “please do not act on failures”, which is to say it does nothing except collect reports nobody reads.
Publish DKIM, then move DMARC through p=quarantine to p=reject once reporting is clean. This is also the single most effective thing you can do about your own mail landing in customers’ junk folders.
4. Audit logging
Unified audit logging is what lets you answer “what did that compromised account do while it was compromised”. If it was never switched on, the answer after an incident is simply: we cannot tell. There is no retroactive fix — the data was never recorded.
5. Mailbox forwarding rules
A standard move after a mailbox compromise is to add a quiet forwarding rule and leave it running. Nothing looks wrong to the user. Block automatic external forwarding at the tenant level, and periodically review any rules that do exist.
While you are in there
Pull a licence report at the same time. We routinely find tenants paying for licences assigned to people who left, or paying for a premium tier to get one feature that is included a step down. The review that improves your security posture often reduces the monthly bill as well.
If you want a second pair of eyes on a tenant, that is something we do as a fixed-scope piece of work — more on that here.