Microsoft 365 includes powerful security, but a secure Microsoft 365 environment does not happen automatically. The right licences, professional configuration, continuous monitoring, and safe user behaviour are all necessary. In this article, you will read about Microsoft 365’s strengths, the responsibilities that remain with your organisation, and why even the best security can never provide an absolute guarantee.
Microsoft invests heavily in the security of Microsoft 365. The platforms behind Exchange Online, SharePoint, OneDrive, Teams, and Microsoft Entra have extensive security mechanisms.
However, there is an important distinction between:
- the security of the Microsoft platform itself;
- the security features included in your Microsoft 365 licence;
- the way those features are professionally configured;
- the continuous monitoring and follow-up;
- and the behaviour of the users.
Is Microsoft 365 secure by default?
The short answer is: Microsoft 365 is built on a highly secure cloud platform, but a standard tenant is not automatically optimally secured for your organisation.
The protection you ultimately have depends, among other things, on:
- your Microsoft 365 licences;
- Microsoft Entra and your identity configuration;
- MFA (Multi-Factor Authentication);
- Conditional Access;
- the security of laptops and smartphones;
- Exchange Online and email security;
- SharePoint and OneDrive sharing policies;
- administrator roles;
- logging and monitoring;
- backup and recovery;
- and the security awareness of users.
Microsoft and your organisation share responsibility
Microsoft 365 is a cloud service. That does not mean Microsoft is automatically responsible for every possible security issue.
Microsoft secures, among other things, the underlying cloud infrastructure, physical data centres, servers, networks, and platform services.
Your organisation remains responsible for important components such as:
- users and identities;
- access rights;
- Microsoft 365 configuration;
- client devices;
- business data;
- MFA and Conditional Access;
- user management;
- and the way users handle data and security alerts.
1. User accounts are an important attack vector
One of the biggest risks within Microsoft 365 is not necessarily the platform itself, but a stolen or misused user account.
That is why multi-factor authentication is an absolute basic measure today.
Microsoft offers, among other things, Security Defaults as basic protection, but professional business environments often require a more targeted policy.
Which methods are allowed, when MFA is requested, what exceptions exist, and how administrator accounts are protected make a big difference.
2. Not every form of MFA is equally strong
Modern Microsoft 365 security goes beyond just asking for an extra code.
Think, for example, of:
- Microsoft Authenticator;
- number matching;
- Windows Hello;
- passkeys;
- FIDO2 security keys;
- phishing-resistant authentication;
- limiting weaker authentication methods.
3. Conditional Access makes a big difference
Conditional Access determines under which circumstances someone gains access to Microsoft 365.
Policies can, for example, take into account:
- the user;
- the application used;
- the device;
- the security status of that device;
- the sign-in risk;
- the authentication method used;
- the location or other context of the sign-in.
With this, you can for example:
- require stronger authentication for administrators;
- block risky sign-ins;
- limit access to sensitive data to managed devices;
- add extra protection to certain applications;
- close off unwanted access paths.
Incorrectly configured policies can unnecessarily block users, create necessary exceptions, or leave security gaps.
4. Good Microsoft 365 security requires specialists
Microsoft 365 includes so many security features that professional configuration goes far beyond ticking a few boxes.
Specialists must determine, among other things:
- which security measures fit the organisation’s risk profile;
- which Conditional Access rules are necessary;
- which authentication methods are allowed;
- how administrator accounts are protected;
- which devices may gain access;
- how email and collaboration are secured;
- which logging and monitoring are needed;
- how incidents are detected and handled;
- and how security measures are tested without disrupting business operations.
Our expertise has also been recognised externally: FLEXAMIT was awarded Cybersecurity Partner of the Year by its Microsoft distributor for three consecutive years.
We use that expertise to configure Microsoft 365 not only to work but also thoughtfully and securely.
5. The device must also be secured
A perfectly secured Microsoft 365 account is only part of the story.
When business data is accessible from a poorly secured, infected, or unmanaged computer, there is still a risk.
That is why, among other things, these elements belong to a modern security approach:
- central device management;
- Microsoft Intune;
- endpoint protection;
- EDR (Endpoint Detection and Response);
- BitLocker;
- patch management;
- compliance policies;
- Conditional Access based on device status.
6. Email remains an important gateway for attackers
Phishing, malware, malicious links, fraudulent invoices, and stolen accounts still very often come via email.
Good email security therefore includes more than spam filtering.
Think of:
- anti-phishing;
- malware protection;
- protection against dangerous links and attachments;
- SPF (Sender Policy Framework);
- DKIM (DomainKeys Identified Mail);
- DMARC (Domain-based Message Authentication, Reporting & Conformance);
- impersonation protection;
- monitoring;
- security awareness.
7. SharePoint and OneDrive must be correctly configured
Microsoft 365 makes sharing easy. That is very convenient, but it can also pose a security risk when sharing is set too broadly.
Think, for example, of:
- anonymous links;
- old external users;
- unnecessarily long active sharing links;
- overly broad Teams and SharePoint permissions;
- sharing entire folders when just one document would suffice.
8. Administrator accounts deserve extra protection
An administrator can do much more than a regular user. That is why administrator accounts are particularly valuable to attackers.
Professional configuration takes into account, among other things:
- least privilege;
- a minimum of permanent administrator rights;
- strong or phishing-resistant authentication;
- specific Conditional Access rules;
- monitoring of administrative activity;
- periodic review of rights and roles.
9. Microsoft 365 is not automatically a complete backup strategy
Microsoft provides various recovery options such as version history, recycle bins, retention, and redundancy.
However, organisations must determine for themselves what recovery guarantees they need.
Consider in advance:
- how long data must be retained;
- how quickly data must be recoverable;
- how far back you need to be able to go in time;
- recovery after ransomware;
- recovery after mass or accidental deletion;
- legal or contractual retention periods.
10. No configuration provides 100% security
This is an important but sometimes forgotten aspect of cybersecurity: absolute security does not exist.
You can secure a Microsoft 365 environment very strongly and provide multiple technical layers to catch errors and attacks.
But no product and no configuration can make every human action completely impossible.
A user can, for example:
- trust a convincing phishing email;
- open a malicious file;
- deliberately ignore a security warning;
- approve an MFA request they did not initiate;
- send confidential information to the wrong person;
- share data via an undesired channel;
- perform an action for which they legitimately have rights.
That is why good cybersecurity always consists of multiple layers:
- technology to block and detect attacks;
- professional configuration to use that technology correctly;
- monitoring to quickly detect suspicious situations;
- procedures to correctly handle incidents;
- security awareness so users recognise risks;
- the user themselves, who ultimately still makes decisions.
Who is ultimately responsible?
Cybersecurity is a shared responsibility.
Microsoft secures its cloud platform. Your IT partner configures and manages the security features. The organisation determines the policy and access rights. And users must interact safely with that environment.
That is why it is too simplistic to say that one technology or one provider can guarantee complete security.
If an authorised user consciously clicks through warnings, executes malicious software, or voluntarily discloses sensitive information, technology can greatly limit the consequences but cannot fully prevent them in every situation.
11. Security is not a one-time project
Securing a Microsoft 365 environment once and then leaving it untouched for years is not a good approach.
Microsoft is constantly changing, but attackers and attack techniques also evolve.
That is why organisations must regularly review:
- new Microsoft security features;
- new attack techniques;
- Conditional Access rules;
- administrator rights;
- devices;
- security alerts;
- Secure Score;
- new users and departed employees;
- external access and sharing;
- security awareness.
What does a well-secured Microsoft 365 environment look like?
For a professional business environment, we expect at least attention to:
- MFA for all users;
- phishing-resistant authentication where possible;
- Conditional Access;
- extra protection of administrator accounts;
- managed and compliant devices;
- endpoint protection and EDR;
- correct email security;
- SPF, DKIM, and DMARC;
- secure SharePoint and OneDrive sharing policies;
- logging and monitoring;
- incident response;
- backup and recovery policies;
- security awareness;
- periodic review and improvement of the configuration.
How do you know if your Microsoft 365 environment is well secured?
For an end user or business owner, that is difficult to assess themselves.
The fact that MFA is active or Microsoft Defender is installed does not yet tell you, for example:
- whether the configuration is correct and complete;
- whether Conditional Access is properly set up;
- whether administrator accounts are sufficiently protected;
- whether all devices are truly managed;
- whether external sharing is set too broadly;
- whether alerts are actually followed up;
- whether recovery after an incident is sufficiently prepared;
- whether security has been recently evaluated.
FLEXAMIT helps organisations professionally secure, manage, and monitor their Microsoft 365 environment.
Our expertise in cybersecurity has been recognised three years in a row by our Microsoft distributor with the Cybersecurity Partner of the Year award.
Would you like to know where your Microsoft 365 environment is strong today and where risks or improvement points remain?
Contact:
sales@flexamit.com
In brief
- Microsoft 365 runs on a highly secure cloud platform.
- A standard Microsoft 365 tenant is not automatically optimally secured.
- Security features must be professionally configured and maintained.
- Identity, MFA, Conditional Access, endpoints, email, and data must be viewed as one whole.
- Cybersecurity is a shared responsibility between Microsoft, the organisation, IT partner, and users.
- No configuration can guarantee 100% security.
- Technology can protect and warn users but cannot prevent every conscious user action.
- Security awareness remains just as important as technical security.
- Security must be continuously monitored and improved.
Comments
0 comments
Please sign in to leave a comment.