Cyber Risk

Microsoft 365 hardening: the controls that matter first

Most Microsoft 365 compromises we review did not defeat a control. They walked through a tenant setting nobody had ever been asked to own.

5 August 2026 · 6 min read

Start from a published baseline, not a vendor deck

There are two credible reference points. Microsoft publishes security defaults and recommended configurations for Entra ID and Microsoft 365, and CISA publishes the Secure Cloud Business Applications (SCuBA) minimum viable secure configuration baselines for Microsoft 365. Using a published baseline changes the conversation from opinion to gap: you are either at the baseline, deliberately deviating with a documented reason, or drifting.

Identity is the control plane

Almost every material improvement is an identity decision. In priority order:

  • Phishing-resistant MFA for administrators, then all users — passkeys or certificate-based authentication rather than SMS.
  • Conditional Access that blocks legacy authentication protocols outright; they bypass modern MFA.
  • Privileged access separation: cloud-only admin accounts, no mailboxes, just-in-time role activation rather than standing Global Administrator.
  • Break-glass accounts that are documented, excluded from policy correctly, and monitored for use.

The quiet settings that cause the incidents

Beyond identity, a small set of tenant-level defaults accounts for a disproportionate share of the incidents we see investigated:

  • Mail forwarding to external recipients, still permitted tenant-wide in many estates.
  • OAuth application consent, allowing users to grant third-party apps access to corporate data without review.
  • Anonymous and organisation-wide sharing links in SharePoint and OneDrive, with no expiry.
  • Audit logging left at default retention, so an investigation finds no evidence in the window that matters.
  • Guest access in Teams and Entra ID with no periodic review of who is still there.

Make posture measurable, then reportable

Hardening is not a project with an end date; tenants drift as features ship and administrators change settings under delivery pressure. Establish a baseline configuration, record every approved deviation with an owner and a review date, and track change over time rather than reporting a single score.

For the board, the useful framing is not how many settings were altered. It is which attack paths are now closed, which remain open, what closing them costs, and who owns the decision to fund it.

Book Assessment

Navigate Risk. Build Confidence.

A focused executive session to establish where you stand across AI, cyber and business risk.