Microsoft 365 security controls protecting organisational data and systems

21 September 2026

Microsoft 365 Security: Are Your Existing Controls Really Protecting Your Organisation

A Microsoft 365 security feature can be switched on and still fail to protect your organisation. Your environment holds identities, email, files and collaboration data that attackers may target, so settings need to work as intended, not just appear in a portal.

Those settings can fall out of date as staff, devices, apps and business needs change. IBM’s 2024 Cost of a Data Breach Report put the global average cost of a breach at US$4.88 million. That figure covers breaches across sectors and technologies; it is not specific to Microsoft 365.

The key question is whether your controls can spot and contain common attacks, limit access to sensitive information and show that protection works. A focused review can reveal where to act first.

Understand the threats Microsoft 365 security must stop

An effective review starts with likely attack paths, not a checklist of enabled features. Map each risk to the identity, email or data controls that should reduce its impact. Then check whether those controls work across your actual users and services.

Trace a compromised account to business data

A stolen password or session token could give an attacker access to a user’s email, Teams chats, SharePoint sites and OneDrive files. The exposure depends on the account’s permissions, sign-in conditions and the sensitivity of the data it can reach.

Follow a sample account through its access. Check which sites it can open, whether it can share files externally and what an attacker could do with its mailbox.

Learn from a documented Microsoft 365 attack

In its January 2024 disclosure, Microsoft reported that Midnight Blizzard used password spraying to access a legacy, non-production test account. The actor then accessed some corporate email accounts.

The incident does not show that every Microsoft 365 environment has the same weakness. It does show why organisations should review old accounts, monitor unusual sign-ins and limit the paths from test systems to business data.

Map threats to your own environment

Consider phishing, password attacks, malicious inbox rules, unsafe OAuth app grants and accidental external sharing. Which risks matter most will depend on your users, data and work processes.

Check incident records and relevant threat reports to test your assumptions. A generic risk list cannot tell you whether your own staff face targeted invoice fraud or whether teams often share files with outside partners.

Test Microsoft 365 security identity controls

Identity controls should cover staff, administrators, guests and service accounts. For each one, confirm whether the control is licensed, set up and enforced. A policy that excludes key users may offer less protection than its name suggests.

Verify MFA coverage and strength

Review who has enrolled in multifactor authentication, which methods they can use and whether any accounts or sign-in cases are exempt. Pay close attention to older accounts and service accounts, which may not follow standard sign-in rules.

Where it fits your risk and support needs, consider phishing-resistant options such as passkeys or FIDO2 security keys. Check enrolment and sign-in records to confirm people use the methods your policy allows.

Check Conditional Access and legacy authentication

Conditional Access can weigh factors such as user risk, device status, location and app sensitivity. Review exclusions and overlapping rules, then check whether older authentication methods can bypass the protections you expect.

Test policy changes with a small group before wider use. This helps catch accidental lockouts while confirming that the rules block unsafe access.

Restrict and monitor privileged accounts

Reduce standing administrator roles and protect privileged sign-ins with strong authentication and tighter access rules. Where available, Privileged Identity Management can grant time-limited access when someone needs it.

Emergency access accounts need strict storage, monitoring and regular tests. Confirm that alerts reach a team that can act if one of these accounts is used.

Close gaps across email, devices and apps

Attackers may target weak points after sign-in, including deceptive messages, unmanaged devices and third-party app access. Review these areas together: email filters cannot stop every stolen session, and device controls cannot limit an app that has broad data permissions.

Strengthen email protection and response

Review anti-phishing, anti-spam and anti-malware policies in Microsoft Defender for Office 365 where your licence includes them. Check impersonation protection, Safe Links and Safe Attachments settings, along with any policy exceptions.

Make sure staff know how to report suspicious messages and that someone investigates them. Include checks for unexpected inbox rules, which can hide replies or send copies of mail to an attacker.

Apply consistent protection to devices and sessions

Check that devices with access to organisational data meet your security requirements. Review endpoint detection and response coverage, including devices used for email and file access.

Set clear rules for unmanaged devices and mobile access. Session controls can help limit what users do in a browser, but available options depend on licensing and setup.

Review OAuth apps and third-party access

Inventory enterprise apps, consent grants and the data each app can reach. Remove apps that are unused or have wider permissions than their purpose requires.

Limit who can approve new apps and set a regular review process for third-party access. A trusted app can still create risk if it keeps access after a project or supplier relationship ends.

Protect sensitive data in Microsoft 365

A valid sign-in does not prevent data exposure. Clear labels, sharing rules and user guidance can reduce the chance that staff disclose information by mistake or give it to the wrong people.

Find and classify important data

Identify sensitive information across Exchange, SharePoint, OneDrive and Teams. Apply sensitivity labels and handling rules that match clear business terms, such as public, internal or confidential.

Keep the label scheme manageable. If staff cannot tell which label fits a file, they are less likely to apply it correctly.

Reduce oversharing in Teams, SharePoint and OneDrive

Review anonymous links, guest access, external sharing settings, site permissions and site ownership. Look for sites that are broadly open and links that are no longer needed.

Set defaults that limit exposure, then allow business units to request exceptions with a clear reason. This keeps routine sharing useful without leaving sensitive sites open by default.

Use DLP and retention controls with clear ownership

Microsoft Purview data loss prevention policies can detect or limit risky sharing, depending on licensing and configuration. Test policies before enforcing them, explain alerts to staff and assign owners to manage exceptions.

Retention rules help meet records and compliance needs, but they do not prevent every form of data loss. Keep retention decisions separate from controls designed to stop unauthorised sharing.

Prove that Microsoft 365 security controls work

A settings review is only a start. You also need evidence that controls cover the right accounts and data, that alerts reach the right people and that response plans work under pressure.

Use Secure Score as a guide, not a guarantee

Microsoft Secure Score can point to improvement opportunities, but it does not certify an environment as secure. Weigh each recommendation against business impact, existing safeguards, licensing and the effort needed to maintain it.

A high score cannot replace tests of real attack paths. Prioritise gaps that could expose valuable accounts or sensitive data.

Check audit coverage, alerts and response plans

Confirm that relevant audit logs are enabled and retained for the period your organisation needs. Check that alerts go to a team with the access and time to investigate them.

Test response steps for a compromised account, a malicious email and suspected data exposure. Record who makes decisions, who contacts affected users and how access is contained.

Set a recurring review

Set a regular schedule to check identity exclusions, administrator roles, external sharing, app consent, device coverage and policy changes. Assign an owner to each control and document accepted exceptions.

Retest after major changes, such as a new app or policy update. This keeps a one-off review from becoming an outdated snapshot.

Conclusion

Microsoft 365 security depends on controls that are correctly set up, consistently enforced and checked over time. Secure identities, limit unnecessary access, protect sensitive data and make sure someone can act on alerts.

Start with the gaps that pose the greatest risk, assign an owner and track each fix to completion. Then test the change. That is how you turn a list of settings into measurable protection.