5 Microsoft 365 Mistakes I See Over and Over

A practical look at five common Microsoft 365 problems I repeatedly encounter in real-world business environments — and what you can do about them. Reading time: 35–40 minutes Introduction Microsoft 365 has become a standard part of running a modern business. Email, Microsoft Teams, OneDrive, SharePoint, Office applications and user accounts can all be managed from one Microsoft 365 environment. But having Microsoft 365 does not automatically mean that it has been configured or managed properly. Over the years, I’ve worked with businesses where Microsoft 365 was technically working, but there were still some fairly serious problems hiding underneath the surface. Sometimes it was something as simple as users not having multi-factor authentication enabled. Other times, it was a tenant where far too many people had Global Administrator access, former employees still had active accounts, or a business was paying for licenses it didn’t actually need. Then there are the problems that seem small until they suddenly aren’t — like printers and scanners that were configured years ago to send email and suddenly stop working. None of these problems are particularly unusual. In fact, they are some of the things I find repeatedly when looking at business Microsoft 365 environments. So in this article, I’m going to look at five Microsoft 365 mistakes I see over and over, why they matter, and what businesses should be doing instead. 1. No Multi-Factor Authentication If there is one Microsoft 365 security setting I would want every business to look at first, it is multi-factor authentication (MFA). And yet, it is still something I encounter surprisingly often: Microsoft 365 accounts where MFA has not been properly enabled, accounts where only some users are protected, or environments where MFA was configured but never properly enforced. The problem is that a username and password are no longer a particularly strong security boundary on their own. Passwords get reused. They get written down. They get entered into fake login pages. They can be exposed through data breaches elsewhere. Users can also be tricked into handing over their credentials through phishing attacks. Once an attacker has a valid Microsoft 365 username and password, they may be able to access much more than just someone’s email. Depending on the user’s permissions, they could potentially gain access to: This is why protecting the login itself matters so much. What MFA Actually Does MFA adds another layer of verification when a user signs in. Instead of Microsoft 365 asking only: “Do you know the password?” it can also require something else that helps prove the person signing in is actually the legitimate user. That second factor might involve an authenticator application, security key, or another supported authentication method. The important point is that knowing the password is no longer enough by itself. If an attacker manages to obtain a user’s password, they still have another barrier to overcome. That doesn’t make an organisation impossible to compromise, but it significantly improves the security of the account compared with relying on passwords alone. “But We’re a Small Business” This is one of the arguments I hear from smaller businesses: “We’re too small for someone to bother attacking us.” Unfortunately, being a small business doesn’t make your Microsoft 365 environment uninteresting to attackers. In many cases, attackers aren’t specifically targeting a company because of its size or reputation. They’re looking for accounts that are poorly protected. A small business can also contain valuable information: Your Microsoft 365 account is therefore part of your business security infrastructure, regardless of whether you have five employees or five hundred. MFA Shouldn’t Be an Afterthought Another problem is treating MFA as something that can be switched on later. It should form part of the basic setup of a Microsoft 365 environment. When a new user is created, security should already be considered. When an employee leaves, their access should be removed. When administrator accounts are created, those accounts should receive particular attention because compromising an administrative account can have much greater consequences. Security should be built into the environment rather than added after something goes wrong. Don’t Stop at “MFA Is Enabled” There is also an important distinction between having MFA available and actually having a properly secured environment. A business should know: In other words, ticking an “MFA enabled” box is not the end of the conversation. It is the beginning of properly managing identity security. A Practical Starting Point If you’re responsible for a Microsoft 365 environment and you’re not sure where things stand, start with a simple review. Look at your users and ask: Does every person who needs access have appropriate MFA protection? Then look specifically at administrator accounts. Are there any accounts with elevated privileges that aren’t properly protected or no longer need those permissions? Finally, look for exceptions. If someone isn’t using MFA, is there a legitimate business reason — or was it simply never configured? These are simple questions, but they can reveal problems that have been sitting unnoticed for months or even years. MFA isn’t the complete Microsoft 365 security strategy. It is, however, one of the fundamental layers that should be in place before you start worrying about the more advanced stuff. And that brings us to another problem I regularly encounter: too many people having more access than they actually need. 2. Too Many Global Administrators The second Microsoft 365 mistake I see quite often is giving Global Administrator permissions to far too many people. This one can be particularly dangerous because it often starts with a perfectly understandable reason. Someone needs to configure something. They can’t access it. Someone gives them administrator permissions. The problem is solved. Six months later, nobody remembers why that person has those permissions, and there are suddenly several users with access to parts of Microsoft 365 that they don’t actually need. It is convenient, but convenience and security don’t always make good partners. What Is a Global Administrator? Global Administrator is one of the highest levels of administrative access within