Microsoft 365 migrations have become routine. The mail moves, the files move, people log in on Monday and mostly everything works. The project gets marked complete and everyone moves on.
What frequently does not happen is the configuration work afterwards. A new tenant ships with defaults chosen to make setup frictionless for the widest possible range of customers, from a two-person startup to an enterprise with a dedicated security team. Frictionless defaults are not secure defaults, and nobody at Microsoft knows which of those two you are.
What we typically find in an inherited tenant
- Legacy authentication protocols still enabled, providing a route around MFA entirely.
- Any user able to consent to third-party applications reading their mailbox — a common phishing payload.
- External sharing on SharePoint and OneDrive set to “anyone with the link,” with no expiry.
- No conditional access policy, so a valid credential works from any country on any device.
- Global Administrator rights on the day-to-day account of whoever set it up, still in use for email.
- Audit logging enabled but never queried, and retention left at the default.
- Licenses assigned to staff who left, sometimes years ago.
None of these are exotic. All of them are the state a tenant sits in unless somebody deliberately changes it.
The changes worth making first
If you do nothing else, do these four, roughly in this order.
- Block legacy authentication. It is the single highest-yield change available, and it closes the most common MFA bypass.
- Enforce MFA for everyone, administrators first, with no standing exclusions. Exceptions should have an expiry date attached.
- Separate administrative identity from daily identity. Nobody should read email as a Global Administrator.
- Restrict user consent to third-party applications, and require admin approval instead.
Every one of these is included in licensing you already hold. The cost is attention, not money.
Then the operational ones
After the security baseline, the settings that matter are the ones governing information rather than access. Decide how long mail and files are retained and whether that matches any regulatory obligation you carry. Decide what external sharing should mean at your firm and configure it, rather than leaving it to whatever each person clicks. Review licenses against actual usage at least twice a year, because the drift is always upward.
None of this is difficult work, and it is not expensive. It just has no natural trigger — no outage forces it, no vendor calls to ask about it. Which is precisely why, several years after a migration that everyone remembers as a success, the tenant is still sitting on defaults.
Written by the team at Summex Technologies.
Ask us about this