Our Microsoft 365 Environment Has Never Had a Microsoft 365 security review. Where Do We Start?
- Hanna Korotka
- Jul 15
- 3 min read

Many small and medium-sized businesses rely on Microsoft 365 every day for email, file sharing, Teams, and identity management. But once the tenant is configured, it's often left untouched for months—or even years.
The problem is that Microsoft 365 isn't a "set it and forget it" platform. Employees join and leave, new applications are connected, devices change, and Microsoft regularly introduces new security features. Over time, these changes can create security gaps that increase your risk.
The good news is that you don't need to redesign your entire environment overnight. A structured review can help you identify the most important issues first and prioritize improvements.
Why perform a Microsoft 365 security review?
A security review helps answer questions such as:
Are administrator accounts properly protected?
Is multifactor authentication enabled where it should be?
Are suspicious sign-ins being monitored?
Are users sharing sensitive information unintentionally?
Do former employees still have access to company resources?
Are security features included with your licenses actually being used?
Finding these issues before an attacker does can significantly reduce your organization's risk.
Step 1: Review your Secure Score
Microsoft Secure Score provides recommendations based on your tenant configuration and compares your security posture against Microsoft's recommended practices.
The score isn't intended to be a competition or something that must reach 100%. Instead, it
helps prioritize improvements that can have the greatest impact on reducing risk.
Examples of recommendations may include enabling multifactor authentication, configuring security policies, or improving device protection.
Step 2: Verify administrator accounts
Administrative accounts deserve special attention because they have the ability to change settings across your environment.
During your review, check:
How many Global Administrators exist
Whether administrators use multifactor authentication
Whether inactive administrator accounts still exist
Whether each administrator role follows the principle of least privilege
Microsoft recommends assigning only the permissions users need to perform their jobs and limiting the number of Global Administrators.
Step 3: Review identity protection
Most Microsoft 365 attacks begin with compromised credentials.
Review:
Recent sign-in activity
Risky sign-in alerts (if available with your licensing)
Unfamiliar locations or impossible travel events
Failed sign-in patterns
Legacy authentication usage, if applicable
Unexpected sign-in activity often provides one of the earliest indicators of account compromise.
Step 4: Check email security
Email remains the primary entry point for phishing and business email compromise attacks.
Review your Exchange Online protection by checking:
Anti-phishing policies
Safe Links policies
Safe Attachments policies
Spam filtering configuration
External forwarding settings
Mailbox forwarding rules
These controls help reduce the likelihood that malicious emails reach users or that attackers silently forward messages outside the organization.
Step 5: Review device protection
If employees use Windows devices, review how those devices are protected.
Questions to ask include:
Are devices managed through Microsoft Intune?
Is Microsoft Defender Antivirus enabled?
Is BitLocker protecting company data?
Are devices required to meet compliance requirements before accessing company resources?
A compromised device can become an entry point into Microsoft 365, making endpoint security an important part of the overall review.
Step 6: Review file sharing and collaboration
Microsoft 365 makes collaboration simple, but it's important to verify that information is being shared appropriately.
Review:
External sharing settings in SharePoint and OneDrive
Guest users who no longer require access
Anonymous sharing links
Permissions on sensitive sites and libraries
Many organizations discover they have external sharing configured more broadly than intended.
Step 7: Confirm security monitoring
Even strong security controls cannot prevent every attack.
Make sure you know:
Where security alerts are generated
Who reviews them
How suspicious activity is investigated
How quickly compromised accounts can be contained
Having a documented response process is just as important as preventive controls.
Step 8: Review licensing
Many organizations own Microsoft 365 security capabilities that have never been configured.
Depending on your subscription, you may already have access to features such as:
Microsoft Defender for Office 365
Microsoft Defender for Endpoint
Microsoft Intune
Microsoft Purview Data Loss Prevention
Microsoft Entra Conditional Access
Reviewing your licenses alongside your configuration helps ensure you're getting the value you're already paying for.
Make security reviews a regular process
A security review shouldn't be a one-time project.
Microsoft continuously improves Microsoft 365 with new capabilities and recommendations. At the same time, your business changes as users, devices, applications, and data evolve.
Reviewing your environment at least once or twice a year can help identify configuration drift, remove unnecessary access, and ensure your security settings continue to align with Microsoft's current best practices.
How PlexHosted can help
PlexHosted helps businesses strengthen their Microsoft 365 security and compliance posture by implementing Microsoft security best practices, managing security policies, monitoring for threats, and helping remediate security issues. Our goal is to reduce cyber risk while helping you get the most value from your Microsoft 365 security features.





Comments