Table of Contents

5 Microsoft 365 Mistakes I See Over and Over

A practical look at five common Microsoft 365 problems I repeatedly encounter in real-world business environments — and what you can do about them.

Reading time: 35–40 minutes

Introduction

Microsoft 365 has become a standard part of running a modern business. Email, Microsoft Teams, OneDrive, SharePoint, Office applications and user accounts can all be managed from one Microsoft 365 environment.

But having Microsoft 365 does not automatically mean that it has been configured or managed properly.

Over the years, I’ve worked with businesses where Microsoft 365 was technically working, but there were still some fairly serious problems hiding underneath the surface. Sometimes it was something as simple as users not having multi-factor authentication enabled. Other times, it was a tenant where far too many people had Global Administrator access, former employees still had active accounts, or a business was paying for licenses it didn’t actually need.

Then there are the problems that seem small until they suddenly aren’t — like printers and scanners that were configured years ago to send email and suddenly stop working.

None of these problems are particularly unusual. In fact, they are some of the things I find repeatedly when looking at business Microsoft 365 environments.

So in this article, I’m going to look at five Microsoft 365 mistakes I see over and over, why they matter, and what businesses should be doing instead.

1. No Multi-Factor Authentication

If there is one Microsoft 365 security setting I would want every business to look at first, it is multi-factor authentication (MFA).

And yet, it is still something I encounter surprisingly often: Microsoft 365 accounts where MFA has not been properly enabled, accounts where only some users are protected, or environments where MFA was configured but never properly enforced.

The problem is that a username and password are no longer a particularly strong security boundary on their own.

Passwords get reused. They get written down. They get entered into fake login pages. They can be exposed through data breaches elsewhere. Users can also be tricked into handing over their credentials through phishing attacks.

Once an attacker has a valid Microsoft 365 username and password, they may be able to access much more than just someone’s email.

Depending on the user’s permissions, they could potentially gain access to:

  • Email and attachments.
  • OneDrive files.
  • SharePoint documents.
  • Microsoft Teams conversations and files.
  • Contacts and calendars.
  • Other Microsoft 365 services.
  • Information that may help them compromise other systems.

This is why protecting the login itself matters so much.

What MFA Actually Does

MFA adds another layer of verification when a user signs in.

Instead of Microsoft 365 asking only:

“Do you know the password?”

it can also require something else that helps prove the person signing in is actually the legitimate user.

That second factor might involve an authenticator application, security key, or another supported authentication method.

The important point is that knowing the password is no longer enough by itself.

If an attacker manages to obtain a user’s password, they still have another barrier to overcome.

That doesn’t make an organisation impossible to compromise, but it significantly improves the security of the account compared with relying on passwords alone.

“But We’re a Small Business”

This is one of the arguments I hear from smaller businesses:

“We’re too small for someone to bother attacking us.”

Unfortunately, being a small business doesn’t make your Microsoft 365 environment uninteresting to attackers.

In many cases, attackers aren’t specifically targeting a company because of its size or reputation. They’re looking for accounts that are poorly protected.

A small business can also contain valuable information:

  • Customer information.
  • Financial documents.
  • Quotes and invoices.
  • Passwords and credentials.
  • Contracts.
  • Business plans.
  • Personal information.
  • Access to other services.

Your Microsoft 365 account is therefore part of your business security infrastructure, regardless of whether you have five employees or five hundred.

MFA Shouldn’t Be an Afterthought

Another problem is treating MFA as something that can be switched on later.

It should form part of the basic setup of a Microsoft 365 environment.

When a new user is created, security should already be considered. When an employee leaves, their access should be removed. When administrator accounts are created, those accounts should receive particular attention because compromising an administrative account can have much greater consequences.

Security should be built into the environment rather than added after something goes wrong.

Don’t Stop at “MFA Is Enabled”

There is also an important distinction between having MFA available and actually having a properly secured environment.

A business should know:

  • Which users are protected by MFA.
  • Which accounts are exceptions and why.
  • Which administrator accounts exist.
  • Whether old authentication methods are still being used.
  • Whether there are accounts that should no longer have access.
  • Whether security policies are being applied consistently.

In other words, ticking an “MFA enabled” box is not the end of the conversation.

It is the beginning of properly managing identity security.

A Practical Starting Point

If you’re responsible for a Microsoft 365 environment and you’re not sure where things stand, start with a simple review.

Look at your users and ask:

Does every person who needs access have appropriate MFA protection?

Then look specifically at administrator accounts.

Are there any accounts with elevated privileges that aren’t properly protected or no longer need those permissions?

Finally, look for exceptions.

If someone isn’t using MFA, is there a legitimate business reason — or was it simply never configured?

These are simple questions, but they can reveal problems that have been sitting unnoticed for months or even years.

MFA isn’t the complete Microsoft 365 security strategy. It is, however, one of the fundamental layers that should be in place before you start worrying about the more advanced stuff.

And that brings us to another problem I regularly encounter: too many people having more access than they actually need.

2. Too Many Global Administrators

The second Microsoft 365 mistake I see quite often is giving Global Administrator permissions to far too many people.

This one can be particularly dangerous because it often starts with a perfectly understandable reason.

Someone needs to configure something.

They can’t access it.

Someone gives them administrator permissions.

The problem is solved.

Six months later, nobody remembers why that person has those permissions, and there are suddenly several users with access to parts of Microsoft 365 that they don’t actually need.

It is convenient, but convenience and security don’t always make good partners.

What Is a Global Administrator?

Global Administrator is one of the highest levels of administrative access within Microsoft 365.

A Global Administrator can manage a huge range of settings across the Microsoft 365 environment.

That means a Global Administrator account isn’t just another user account with a few extra permissions.

If that account is compromised, the potential impact can be significantly greater than compromising an ordinary user’s account.

This is why administrator accounts need to be treated differently from standard user accounts.

“But They’re the IT Person”

This is where things can get slightly complicated for small businesses.

A small company may not have a dedicated internal IT department.

Instead, Microsoft 365 might be managed by:

  • The business owner.
  • An office manager.
  • An external IT provider.
  • A senior employee who “knows computers”.
  • Several different people who have needed access at different points.

It can therefore seem reasonable to simply make everyone an administrator.

After all, it means nobody has to keep asking for permission.

But that’s exactly the problem.

If everyone has the keys to the building, eventually you lose track of who actually needs them.

The Principle of Least Privilege

A better approach is least privilege.

The basic idea is simple:

Give someone the access they need to do their job — and no more than that.

If someone only needs to manage a particular function, they shouldn’t automatically receive unrestricted access to the entire Microsoft 365 tenant.

Modern Microsoft environments provide different administrative roles and permissions for a reason.

You may have people who need to manage users, people who need to work with devices, people who manage specific services, and people who only need access to their normal user account.

Those requirements aren’t necessarily the same.

Why This Matters During a Security Incident

Imagine that one of your employees accidentally enters their Microsoft 365 credentials into a convincing phishing website.

If that person is an ordinary user, the potential damage is already serious.

But if that same account also has Global Administrator permissions, the situation becomes much more concerning.

The attacker may now have access to administrative capabilities that can affect the wider environment.

This is one of the reasons I don’t like seeing administrator permissions handed out simply because they are convenient.

You’re not just giving someone another checkbox.

You’re increasing the potential impact if that account is compromised.

Administrator Accounts Should Be Deliberate

Another good practice is separating normal day-to-day activity from administrative activity where appropriate.

An account used for reading email, browsing the web and opening documents has a very different risk profile from an account capable of making major changes to the Microsoft 365 environment.

You don’t necessarily want your highest level of access attached to the account being used for everything else.

The exact design will depend on the size and requirements of the business, but the principle remains the same:

Administrative access should be intentional.

You should know:

  • Who has administrative access.
  • What role they have.
  • Why they have it.
  • Whether they still need it.
  • Whether their account is properly protected.
  • Whether there are old or unused administrator accounts that should be removed.

Don’t Forget Former IT Providers

This is another one worth checking.

A business may have changed IT providers several times over the years.

The previous provider may have had administrative access.

The person who originally configured the Microsoft 365 tenant may have left.

An employee who used to manage the system may have moved on.

But their access can remain.

I’ve seen enough environments where old accounts, old permissions and old configurations have accumulated over time to know that “we don’t use that account anymore” isn’t the same thing as “that account no longer has access.”

When responsibility for an environment changes, permissions should be reviewed as part of the handover.

A Simple Administrator Audit

If you’re responsible for a Microsoft 365 tenant, one of the simplest things you can do is review your administrator list.

Ask:

Who currently has elevated permissions?

Then:

Does every one of those people actually need them?

Then:

Do we know exactly why they have those permissions?

And finally:

If one of these accounts was compromised tonight, how much of our environment could an attacker potentially control?

Those questions can be uncomfortable, but they’re useful.

The goal isn’t to make administration difficult.

The goal is to make sure that the people who have significant control over your Microsoft 365 environment actually need that level of control.

MFA protects the account when someone tries to sign in.

Least privilege limits what that account can do once it has access.

Both are important.

And even when you get those two things right, there is another area where businesses regularly fall short: what happens when an employee leaves?

3. Poor Offboarding

The third mistake is one that is easy to overlook because businesses tend to focus heavily on bringing people into the organisation.

A new employee starts.

An account gets created.

A Microsoft 365 licence is assigned.

Their laptop is configured.

Email works.

Teams works.

OneDrive works.

Everyone is happy.

But when that employee leaves, the process is often much less organised.

Sometimes the account is simply disabled. Sometimes the Microsoft 365 licence is removed immediately. Sometimes nothing happens until someone remembers weeks later.

And sometimes the account remains active because nobody is quite sure what information is still attached to it.

Offboarding should be treated with the same importance as onboarding.

An Employee Leaving Is More Than Disabling an Account

When someone leaves a business, you’re not simply dealing with a Microsoft 365 username anymore.

You’re potentially dealing with:

  • Their email.
  • Their OneDrive files.
  • Shared documents.
  • Microsoft Teams access.
  • SharePoint access.
  • Calendars.
  • Contacts.
  • Company devices.
  • Saved credentials.
  • Access to other systems.
  • Information that other employees may still need.

Simply disabling the account may protect you from one problem while creating another.

For example, if an employee was responsible for important documents stored in their OneDrive, deleting or removing things without understanding what needs to be retained could create a completely different problem.

The business needs a process.

What Happens to Their Email?

Email is usually one of the first things that needs consideration.

A business may still receive messages intended for a former employee long after they’ve left.

Customers may not know that the person has left.

Suppliers may still use their old address.

Important correspondence may still arrive.

That doesn’t necessarily mean the former employee’s mailbox should simply remain active forever.

Instead, the business should decide what should happen to the mailbox and incoming mail based on its requirements.

That might involve forwarding, delegation, an automatic response, mailbox retention, or another appropriate approach.

The important part is that the decision should be intentional.

What About OneDrive?

OneDrive is another area that can easily be forgotten.

Employees often store business information in their OneDrive without thinking of it as a formal company file repository.

There may be:

  • Documents.
  • Spreadsheets.
  • Presentations.
  • Customer information.
  • Project files.
  • Templates.
  • Work in progress.
  • Important reference material.

If the employee leaves and the account is simply removed without considering the data, the business could lose access to information it still needs.

This is why offboarding should include a review of the user’s data and access before accounts and licences are removed.

Licences Are Part of the Process Too

There is also a financial side to offboarding.

If someone leaves the company, why continue paying for a Microsoft 365 licence that nobody is using?

It sounds obvious, but in environments where users have been added and removed over several years, unused licences can accumulate.

A proper offboarding process should therefore include a licence review.

That doesn’t necessarily mean immediately deleting everything associated with the account.

It means understanding what the business needs to retain, what access needs to be removed, and when the licence can safely be reassigned or removed.

Security and cost management can therefore overlap here.

Don’t Forget Their Devices

Microsoft 365 offboarding shouldn’t happen in isolation from the employee’s hardware.

If someone leaves with a company laptop, for example, you need to know what happens to that device.

The same applies to:

  • Phones.
  • Tablets.
  • Company-owned laptops.
  • USB devices.
  • Authentication devices.
  • Other equipment.

The device may contain locally stored information, saved credentials or access to company resources.

A good offboarding process therefore considers both the cloud account and the physical equipment.

The Problem With “We’ll Sort It Out Later”

One of the biggest problems with poor offboarding is that the consequences often aren’t immediately visible.

The employee leaves.

Everything appears fine.

Two months later, someone needs an old document.

Three months later, an important customer emails the former employee.

Six months later, someone notices the business is still paying for an unused licence.

A year later, someone discovers an old account that nobody realised was still configured.

By then, the original employee may be long gone and nobody remembers exactly what was configured.

That makes the situation much harder to untangle.

Build a Simple Offboarding Checklist

You don’t need an enormous enterprise process to improve this.

Even a small business can create a basic checklist covering:

  • Confirm the employee’s final working date.
  • Disable or otherwise secure their account at the appropriate time.
  • Review their email requirements.
  • Review OneDrive and other business data.
  • Check Microsoft Teams and SharePoint access.
  • Remove access to other business systems.
  • Review their Microsoft 365 licence.
  • Recover company-owned devices.
  • Remove unnecessary permissions.
  • Confirm that important business information has been transferred or retained appropriately.

The exact process will vary from business to business, but having a process is far better than relying on someone’s memory.

Offboarding Is a Security Process

This is the part I think businesses sometimes underestimate.

Offboarding isn’t just administration.

It is security.

Every former employee whose account, permissions, device or credentials haven’t been properly dealt with represents a potential leftover access point.

The goal isn’t to make the process complicated.

The goal is to make sure that when someone leaves the business, their access leaves with them — while the business retains the information it actually needs.

And once you’ve dealt with users, permissions and offboarding, there is another question worth asking:

Are you actually paying for the Microsoft 365 licences your business needs — or are you simply paying for whatever licences were assigned over the years?

4. Using the Wrong Microsoft 365 Licence

The fourth mistake is one that is less obvious than a security problem, but it can have a very real impact on a business:

paying for the wrong Microsoft 365 licences.

When a business first moves onto Microsoft 365, licensing is often treated as a fairly simple decision.

Someone needs email, so they get a licence.

Someone needs Office, so they get a licence.

Someone needs Teams, so they get a licence.

And once everything is working, nobody thinks about it again.

The problem is that businesses change.

Employees come and go. Their responsibilities change. The business starts using new Microsoft services. Some users need more functionality than others, while others may only need a small portion of what their licence provides.

If nobody reviews the licensing, the business can eventually end up paying for a setup that no longer matches what its employees actually need.

Not Every User Needs the Same Thing

One of the easiest mistakes to make is assuming that every employee should have exactly the same Microsoft 365 licence.

It certainly makes administration simple.

But simple doesn’t always mean cost-effective.

Consider a business with ten employees.

You might have:

  • Someone who primarily needs email.
  • Someone who works heavily with Microsoft Office applications.
  • Someone who needs access to Teams and SharePoint.
  • Someone who requires additional security or management features.
  • Someone who rarely uses Microsoft 365 at all.

Their requirements may be completely different.

That doesn’t automatically mean you should give every person a different licence either.

The point is to understand what the business actually needs before deciding what everyone should receive.

The Most Expensive Licence Isn’t Automatically the Best One

Another common approach is:

“Let’s just give them the bigger licence so we know they’ll have everything.”

I understand why businesses do this.

It reduces the risk of discovering later that someone needs a feature they don’t have.

But there is a cost attached to that convenience.

If you have twenty users and you’re paying for features that most of those users never use, the monthly difference can become significant over time.

It may not seem like much when looking at one user.

Multiply that difference across an entire company for twelve months, and suddenly the number becomes much more interesting.

This is where a proper licensing review can uncover savings without removing anything the business actually relies on.

The Opposite Problem Also Happens

Of course, the problem can go the other way.

Sometimes a business tries to save money by assigning a cheaper licence without properly understanding what that user actually needs.

Everything works initially.

Then someone needs a particular feature.

Or they need functionality that isn’t included.

Or the business starts relying on a service that the existing licensing doesn’t properly support.

Now IT has to work backwards and figure out why something isn’t available.

Saving money is good.

Saving money by removing something the business actually needs isn’t.

Licensing Should Follow the Job

A better way to approach Microsoft 365 licensing is to start with the user’s role.

Ask:

What does this person actually need to do?

Do they need desktop Office applications?

Do they primarily use browser-based services?

Do they need Teams?

Do they work with SharePoint?

Do they need additional security capabilities?

Do they need device management?

Do they have access to sensitive business information?

The answers help determine what the appropriate licensing requirements might be.

This is much better than starting with:

“Which licence does everyone else have?”

Don’t Forget Former Employees

This connects directly to the previous section about offboarding.

If an employee leaves, their Microsoft 365 licence should eventually be dealt with as part of the offboarding process.

Otherwise, you can end up with licences being paid for even though nobody is using them.

This is particularly easy to miss in businesses that have experienced staff turnover over several years.

Someone leaves.

A replacement joins.

A new licence gets purchased.

The old one is never properly reviewed.

Repeat that process enough times and the business can end up carrying unnecessary monthly costs.

Licensing Reviews Don’t Have to Be Complicated

You don’t necessarily need to spend days analysing your entire Microsoft 365 environment.

Start with a basic list of users and ask:

  • Who is currently using Microsoft 365?
  • What licence does each person have?
  • What does that person actually need?
  • Are there users with licences they no longer require?
  • Are there unused or unassigned licences?
  • Are users missing functionality they genuinely need?
  • Have employees who left the business been properly removed from the licensing picture?

You can then compare the actual requirements against what the business is currently paying for.

This is also a good opportunity to look at the reason behind each licence, rather than simply changing things because one option appears cheaper.

Don’t Make Licensing Decisions Based on Price Alone

There is a temptation to treat Microsoft 365 licensing as a simple cost-cutting exercise.

I wouldn’t.

The cheapest option isn’t automatically the correct option.

A licence should be evaluated based on the combination of:

Functionality + security + management requirements + business needs + cost.

If a slightly more expensive licence provides something the business genuinely depends on, that additional cost may be completely justified.

On the other hand, if you’re paying extra every month for functionality nobody uses, that deserves a conversation too.

Review It When the Business Changes

Licensing should be reviewed whenever there is a significant change in the business.

For example:

  • A new employee starts.
  • Someone changes roles.
  • An employee leaves.
  • The company adopts a new Microsoft service.
  • Security requirements change.
  • The business grows.
  • The company changes its working model.
  • Microsoft changes its licensing options or features.

This doesn’t need to become another giant IT project.

It simply needs to become part of normal Microsoft 365 management.

The Bigger Lesson

Microsoft 365 licensing is one of those areas where “it works” isn’t necessarily the same as “it’s right.”

If everyone can access their email and open their documents, the environment might appear perfectly healthy.

But that doesn’t tell you whether the business is:

  • Properly licensed.
  • Paying a sensible amount.
  • Giving users the functionality they actually need.
  • Missing important capabilities.
  • Carrying unnecessary licences.

A periodic licensing review can therefore improve both cost control and the overall management of the Microsoft 365 environment.

And there is one final mistake that sits slightly outside the usual Microsoft 365 conversation — but I encounter it all the time in real business environments.

The printer or scanner that suddenly can’t send email anymore.

5. Printer and Scanner Email Problems

This is probably the mistake that feels the least exciting on this list.

Nobody wakes up thinking:

“I wonder if our multifunction printer is using the correct SMTP configuration today.”

But then someone needs to scan a document and email it.

They press Scan to Email.

Nothing happens.

The printer says there is an error.

Someone restarts it.

It still doesn’t work.

Then the IT person gets the call.

This is a surprisingly common problem in Microsoft 365 environments, particularly with older printers, scanners and multifunction devices that were configured several years ago.

“It Used to Work”

This is usually where the conversation starts.

“It was working yesterday.”

Or:

“It has worked for years and suddenly stopped.”

And that may be completely true.

The problem is that the fact something worked for years doesn’t necessarily mean the configuration is still appropriate today.

Microsoft 365 has changed significantly over the years, particularly around authentication and security.

A printer that was configured when the company’s Microsoft 365 environment looked very different may still be relying on an older method of sending email.

Eventually, something changes.

The device stops authenticating correctly.

And suddenly scanning to email doesn’t work.

Your Printer Is Not a Microsoft 365 User

One of the things that makes this problem confusing is that a printer isn’t a normal Microsoft 365 user.

It doesn’t behave like Anthony sitting at a computer and signing into Outlook.

The device needs a way to authenticate with the mail service and send messages.

Depending on the device, its age and the configuration being used, there may be different ways of achieving this.

That means the correct solution isn’t always:

“Change the password.”

Sometimes the underlying method needs to be reviewed.

Old Devices Create Old Problems

Printers and scanners can stay in businesses for a very long time.

I’ve encountered plenty of environments where the computers have been replaced several times while the multifunction printer has simply carried on doing its job.

That creates an interesting situation.

The Microsoft 365 environment might have changed.

Security requirements might have changed.

Authentication methods might have changed.

The printer, however, is still configured the way someone set it up years ago.

From the printer’s perspective, nothing is wrong.

It is simply trying to do what it was originally configured to do.

Don’t Just Disable Security to Make It Work

This is where troubleshooting can sometimes go wrong.

Someone needs the printer working immediately.

They find a setting that appears to be blocking the connection.

They change it.

The printer works again.

Problem solved.

Except that the change may have weakened the security of the Microsoft 365 environment.

That’s not really a solution.

It is a workaround.

When dealing with authentication problems, the objective should be to find a supported and appropriate configuration, rather than simply making the security controls less restrictive.

This is particularly important in business environments where email accounts may have access to sensitive information.

Think About What the Device Actually Needs

A printer doesn’t need a full Microsoft 365 user account simply because it needs to send an email.

The right solution depends on the environment and the capabilities of the device.

You need to consider things such as:

  • What model of printer or scanner is being used?
  • How old is the device?
  • What firmware is it running?
  • What SMTP configuration is currently being used?
  • How is the device authenticating?
  • Is the current authentication method still supported?
  • Does the device need to send internally or externally?
  • How many devices need to send email?
  • What security controls are required?
  • Is the configuration documented?

These questions help you solve the actual problem instead of simply changing random settings until the printer starts working again.

This Applies to More Than Printers

The same type of problem can occur with other business systems that need to send email.

For example:

  • Scanners.
  • CCTV systems.
  • Backup software.
  • Monitoring systems.
  • Line-of-business applications.
  • Website forms.
  • ERP or accounting systems.
  • Other network appliances.

They may all have been configured at some point to send email through the organisation’s mail environment.

When authentication or security requirements change, those systems can suddenly start producing errors.

This is why an IT environment should be viewed as a collection of interconnected systems rather than simply a collection of computers and user accounts.

Document Your Email-Sending Devices

One of the easiest ways to make these problems more difficult than they need to be is to have no record of how anything was configured.

If a business has five printers, a CCTV system, a backup application and several other systems sending email, it is useful to know:

  • What each device is.
  • Where it is located.
  • What account or method it uses.
  • What mail configuration it relies on.
  • Who configured it.
  • When it was last reviewed.

That information can save a huge amount of time when something eventually stops working.

It also makes changing IT providers or replacing equipment much easier.

Don’t Wait Until Something Breaks

This is the common theme running through all five mistakes in this article.

A lot of IT problems aren’t caused by something suddenly going wrong.

They are caused by something that was never properly reviewed in the first place.

The printer that stops sending email is often only noticed because someone needs to scan a document.

The unused license is only noticed when someone finally looks at the monthly bill.

The former employee’s account is only discovered during an audit.

The Global Administrator nobody remembers is only questioned when someone reviews permissions.

And the user without MFA is only noticed when security becomes a priority.

A little preventative maintenance can be considerably easier than troubleshooting the same problem during an emergency.

The Bigger Lesson

Microsoft 365 doesn’t exist in isolation.

It sits at the centre of a wider IT environment containing users, devices, applications, printers, security systems and business processes.

When something changes in Microsoft 365, those connected systems can sometimes be affected too.

That is why Microsoft 365 management shouldn’t simply be:

“Everyone can send and receive email, so everything must be fine.”

A healthy environment needs to be reviewed as a whole.

And that brings us back to the five mistakes we’ve covered.

MFA protects identities.

Least privilege limits administrative access.

Proper offboarding removes access when people leave.

Correct licensing keeps the environment aligned with business requirements.

And properly managed email-sending devices prevent yesterday’s configuration from becoming tomorrow’s IT emergency.

How to Check Your Own Microsoft 365 Environment

After going through these five mistakes, you might be wondering where to start if you’re responsible for a Microsoft 365 environment yourself.

The good news is that you don’t necessarily need to perform a massive technical audit immediately.

Start with the basics.

The objective is to understand whether your Microsoft 365 environment is still configured around the needs of the business today, rather than simply continuing with decisions that were made several years ago.

1. Review Your User Accounts

Start by looking at the users who currently have access to Microsoft 365.

Ask:

  • Does every account belong to a current employee?
  • Are there former employees who still have accounts?
  • Are there shared or generic accounts that nobody properly owns?
  • Are there accounts that haven’t been used for a long time?
  • Does every user actually need their current access?

This is one of those exercises that can uncover problems surprisingly quickly.

Businesses change constantly.

People join.

People leave.

Roles change.

Departments change.

But Microsoft 365 environments don’t necessarily change automatically with them.

A regular review helps make sure your digital environment reflects the actual business.

2. Review MFA

Next, look at authentication.

You want to know whether users are properly protected by MFA and whether there are exceptions.

If someone doesn’t have MFA enabled, ask why.

If there are exceptions, document them.

And pay particular attention to accounts with administrative permissions.

The important thing isn’t simply to say:

“We have MFA.”

The important question is:

“Are the accounts that matter properly protected?”

3. Review Your Administrators

Look at the people who can make changes to the Microsoft 365 environment.

Make a list.

Then ask:

Does every person on this list actually need this level of access?

If someone was given administrator access two years ago because they needed to fix one particular problem, do they still need it today?

If a previous employee or IT provider still appears on the list, why?

This is a simple review, but it can make a significant difference to your security posture.

4. Review Former Employees

Look specifically for users who have left the business.

For each former employee, consider:

  • Account status.
  • Email.
  • OneDrive.
  • Teams and SharePoint access.
  • Other application access.
  • Microsoft 365 licensing.
  • Company-owned equipment.
  • Any administrative permissions.

You want to reach a point where you can confidently say:

“This person no longer works here, and their access has been properly dealt with.”

5. Review Your Microsoft 365 Licences

Then look at what you’re paying for.

Don’t just look at the total monthly amount.

Look at the individual users and what they have been assigned.

Ask:

  • Does this user still need the licence?
  • Does their current role require it?
  • Are there unused licences?
  • Are former employees still consuming licences?
  • Are there users paying for functionality they don’t use?
  • Are there users who actually need a different licence?

This is an area where a little housekeeping can potentially save money over time.

6. Find Your Email-Sending Devices

Finally, make a list of the devices and applications in your business that send email.

Don’t limit this to Outlook.

Think about:

  • Printers.
  • Scanners.
  • CCTV.
  • Backup systems.
  • Monitoring systems.
  • Accounting or ERP software.
  • Website forms.
  • Other network equipment.

Then ask:

Do we know how each one sends email?

If the answer is no, that is useful information in itself.

It means you’ve identified something that should eventually be documented.


The Microsoft 365 Health Check

If I had to reduce this entire article down to a simple starting point, I’d use five questions:

Security

Is MFA properly protecting our users?

Permissions

Does everyone have only the access they actually need?

Offboarding

Can we confidently remove a user’s access when they leave without losing important business information?

Licensing

Are we paying for the licences our business actually needs?

Infrastructure

Do we know which devices and applications depend on Microsoft 365 for sending email?

If you can’t answer one or more of these questions, that doesn’t necessarily mean your Microsoft 365 environment is broken.

It means you’ve found an area worth investigating.

And that’s really the point.

You don’t need to know everything about Microsoft 365 to start improving your environment.

You just need to start asking the right questions.


Why These Problems Keep Happening

One thing that stands out to me when looking at Microsoft 365 environments is that many of these problems aren’t caused by someone deliberately doing something wrong.

They usually happen because the business grew and the IT environment grew with it.

A new employee needed an account.

Someone needed administrator access.

A printer was configured.

A previous IT provider made some changes.

A licence was purchased.

An employee left.

Someone else took over their responsibilities.

And then everyone moved on to the next problem.

One change isn’t necessarily a problem.

The problem comes when those changes accumulate over several years without anyone stepping back and asking:

“Does this environment still make sense?”

That’s why regular reviews are so valuable.

IT management isn’t only about fixing things when they break.

A large part of good IT management is looking at what is already there and asking whether it is still secure, appropriate, documented and cost-effective.


Microsoft 365 Should Be Managed, Not Just Used

It’s easy to think of Microsoft 365 as simply a collection of applications.

You use Outlook for email.

Teams for communication.

OneDrive for files.

Word and Excel for documents.

But underneath all of that is an environment containing identities, permissions, data, devices, security controls, licences and integrations.

That environment needs management.

The fact that everyone can send an email doesn’t necessarily mean the environment is healthy.

The fact that nobody has complained about their Microsoft 365 account doesn’t mean the configuration is secure.

And the fact that the monthly bill is being paid doesn’t mean the business is getting the right value from its licences.

Sometimes the most valuable IT work is the work that nobody notices.

The account that gets secured before it is compromised.

The administrator permission that gets removed before it becomes a problem.

The former employee whose access is properly closed.

The unused licence that gets cancelled.

The printer configuration that gets documented before it stops working.

None of those things make particularly exciting headlines.

But they’re exactly the sort of things that keep an IT environment healthy.


Frequently Asked Questions

Is Microsoft 365 secure by default?

Microsoft provides a large number of security features and controls, but a secure Microsoft 365 environment still requires appropriate configuration and ongoing management.

Security isn’t simply something you purchase with the subscription.

How those features are configured and used matters.

Does every Microsoft 365 user need MFA?

Businesses should strongly consider MFA as a fundamental part of protecting Microsoft 365 identities.

The exact implementation can depend on the organisation’s environment, security requirements and supported authentication methods, but relying solely on passwords is a poor security strategy.

Should everyone in the company be a Global Administrator?

No.

Administrative permissions should be assigned deliberately according to what someone actually needs to manage.

Giving every user elevated privileges simply because it is convenient increases the potential impact if an account is compromised.

What should I do with a Microsoft 365 account when an employee leaves?

Don’t simply delete it without considering the information and access associated with the account.

The business should have an offboarding process that considers email, OneDrive, Teams, SharePoint, other applications, licensing, permissions and company-owned devices.

The exact process depends on the business and its retention requirements.

Can I save money by changing Microsoft 365 licences?

Potentially, but licensing shouldn’t be treated purely as a cost-cutting exercise.

The correct licence depends on what the user and business actually require.

A cheaper licence isn’t necessarily better if it removes functionality or security capabilities that the business needs.

Why did my printer suddenly stop sending emails?

One possibility is that the printer or scanner is relying on an older email authentication or SMTP configuration that is no longer appropriate or supported.

However, the actual cause needs to be investigated.

The correct solution is to identify how the device is configured and determine what supported configuration is appropriate for that device and environment.

How often should a business review Microsoft 365?

There isn’t one universal schedule that works for every organisation.

However, Microsoft 365 should not be treated as something that is configured once and then forgotten.

A review is particularly valuable when employees join or leave, responsibilities change, new services are introduced, IT providers change, or Microsoft changes relevant features and security requirements.


Final Thoughts

Microsoft 365 is incredibly useful for businesses, but simply having a Microsoft 365 subscription doesn’t mean the environment is automatically well managed.

The five mistakes we’ve looked at are relatively common:

  1. No MFA or inconsistent MFA protection.
  2. Too many Global Administrators.
  3. Poor employee offboarding.
  4. Incorrect or poorly reviewed licensing.
  5. Old or poorly managed printer and application email configurations.

None of these problems are particularly difficult to understand.

The bigger issue is that they can remain unnoticed for a long time.

That’s why I always recommend periodically stepping back from the day-to-day IT problems and looking at the environment as a whole.

Ask who has access.

Ask whether that access is still required.

Ask whether former employees have been properly removed.

Ask what you’re paying for.

Ask what devices depend on Microsoft 365.

And most importantly, ask whether the environment you have today still makes sense for the business you are running today.

Because good IT isn’t just about getting things working.

It’s about making sure they continue to work securely, efficiently and for the right reasons.


Want to Check Your Microsoft 365 Environment?

If you’re not sure whether your Microsoft 365 environment has accumulated some of these problems, a proper review can help identify where the risks, unnecessary costs and configuration issues are hiding.

If you’d like help reviewing your Microsoft 365 environment, get in touch with Anthony Roux | IT to discuss what your business needs.

About Anthony Roux

Hi, I’m Anthony Roux.

I’m a Technical Lead with experience across infrastructure, Microsoft 365, networking, cybersecurity, backup and disaster recovery, CCTV, and managed IT services.

Throughout my career, I’ve worked with businesses of different sizes, helping them solve technical problems, improve reliability, and build technology environments that support the way they work.

AnthonyRoux.me is my professional portfolio and knowledge hub.

It’s where I document my experience, publish technical articles, share practical lessons from the field, showcase projects I’ve worked on, and create resources for IT professionals and businesses alike.

Whether you’re here to learn something new, explore my experience, discuss an opportunity, or simply follow my journey, welcome — and I hope you find something here that’s genuinely useful.


Continue Learning

Everyone learns differently, so I’ve created this topic in multiple formats to help you explore it in the way that works best for you.

Watch the Full Video

Sometimes it’s easier to hear these ideas explained rather than read through them.

If you’d rather watch than read, check out the companion video for this article, where I break down the five Microsoft 365 mistakes and explain why they’re worth paying attention to.


Continue Exploring

Continue exploring this topic and put what you’ve learned into practice.

Microsoft 365 Business Health Check

Reading about Microsoft 365 problems is useful, but actually checking your own environment is even better.

Use the accompanying worksheet to work through the five areas covered in this article:

  • Multi-factor authentication.
  • Administrator permissions.
  • Employee offboarding.
  • Microsoft 365 licensing.
  • Printers and other systems that send email.

The goal isn’t to perform a complicated enterprise audit.

It’s to identify the obvious things that may have been overlooked.

Download the Free Worksheet

Put what you’ve learned into practice with the accompanying Microsoft 365 Business Health Check worksheet.

Download the Free Worksheet


Connect With Anthony

Technology never stops evolving — and neither should we.

If you found this article useful, I’d love to stay connected. I regularly share practical IT insights, real-world projects, behind-the-scenes content, and lessons learned from working in the industry.

Follow along on your preferred platform: