# Nine Things a Microsoft 365 Security Review Finds Almost Every Time

Source: https://elementdigital.com.au/blog/nine-things-a-microsoft-365-security-review-finds/
Published: 2026-06-16

> The same findings come up in nearly every tenant we assess. Nine of them, what each one actually costs you, and how to check your own as you read.

We run a lot of Microsoft 365 security reviews. The same findings turn up so consistently that we can usually predict most of the report before opening the tenant.

None of these means you have been compromised. All of them are worth an afternoon of somebody's time. Check yours as you read.

## 1. External forwarding is not blocked

Outbound spam policies often permit automatic forwarding to external addresses, or fail to clearly block it.

This is the control that turns a mailbox compromise into a long-running one. An attacker sets a forwarding rule, and keeps reading your mail for months after you reset the password and moved on.

Set automatic forwarding to off, then document your exceptions. There are usually one or two legitimate ones, and they should be named rather than assumed.

## 2. Somebody uses a Global Administrator account every day

The account reading email, opening attachments and browsing the web is also the account that can do anything in the tenant.

That account is exposed to phishing and session theft in a way a dedicated admin account never is. When it goes, everything goes with it.

Create separate admin accounts and use them only for admin work. Privileged Identity Management takes this further, making the role something you activate when you need it rather than something you hold permanently.

## 3. There is only one Global Administrator

The mirror image of the last one, and the two turn up in the same tenant surprisingly often.

A single admin account is a single point of failure. If that person leaves suddenly, loses their phone, or gets locked out, your way back in is a support case and a bad week.

Create a second emergency account. Exclude it from the Conditional Access policies that could lock it out, store a long random password somewhere physical, and test once a year that it still works.

## 4. No DMARC record

Nothing tells receiving systems what to do with mail claiming to come from your domain that fails authentication.

For most businesses this is the highest impact item on the list, because it is what invoice fraud relies on.

Publish DMARC in reporting mode first, read what comes back, then tighten. The full sequence is in [SPF, DKIM and DMARC](/blog/spf-dkim-and-dmarc/).

## 5. DKIM is not enabled

Related, and usually missing alongside DMARC.

Without it, receivers cannot verify your mail came from an authorised system and arrived unmodified. It also leaves DMARC with only SPF to work with, which gets fragile as soon as mail is forwarded.

Enable it for each accepted domain and confirm the DNS records resolve.

## 6. Sharing links default to edit

When somebody shares a file, the default link hands edit access to whoever receives it.

Most sharing is not meant to grant edit. People take the default because the default is the fast path, and almost nobody changes it.

Set the default to specific people, view only. Users can still choose something broader when they mean to, which is exactly the point.

## 7. Anonymous links never expire

A link created to get one file to a supplier is still live three years later.

Nobody revokes these because nobody remembers them. They accumulate quietly, and each one is a file available to anyone holding the URL.

Set an expiry. Start at 30 days and adjust if people complain. In our experience fewer do than you would expect.

## 8. External users can re-share

A guest invited to one document can pass that access to somebody you have never heard of.

This is on by default, and it extends access well past the original invitation without anybody noticing.

Restrict re-sharing for sensitive content. If your business genuinely runs on external collaboration, and plenty do, the answer is not to switch it off everywhere. It is to decide where it applies and write the decision down.

## 9. There is no backup

Retention is not backup, and most tenants hold no independent copy of their own data.

The detail is in [Microsoft 365 Backup](/blog/microsoft-365-backup/). The short version is that the recycle bin windows are measured in days, and the scenarios that actually hurt take longer than that to notice.

## Working through the list

Do items one, two and four first. They change the most for the least effort.

Then treat the three sharing items as a single piece of work, because they are all the same conversation with the business. Collaboration is not the enemy here. The goal is to make it deliberate instead of accidental.

None of this needs a project. It needs somebody with the right access, a free afternoon and a list, and you now have the list.

Element Digital does [cyber security work](/cyber-security/) in Hobart and across Tasmania. If you would rather have someone run the review properly, [get in touch](/contact/).
