Microsoft 365 is, by default, insecure. Not because it's a bad product, but because it's designed to be easy to use from day one. When a company activates its tenant, it gets a configuration oriented toward getting everything working quickly — not protecting data. 80% of the SMEs I audit have this problem active. And 80% of those companies don't know it.
The specific mistake: trusting default configuration
Microsoft 365's default configuration allows a user to access email, SharePoint, and Teams from any device, from any location, with just a username and password. If someone steals those credentials — through phishing or password reuse — they have complete access with no additional barriers.
The 5 changes you should make today
1. Activate MFA for all users
How to do it: Microsoft 365 Admin Center → Users → Active Users → Multi-factor authentication. Estimated time: 30 minutes to activate.
2. Activate Entra ID Security Defaults
How to do it: Azure Portal → Microsoft Entra ID → Properties → Manage Security Defaults → Enable. Estimated time: 5 minutes.
3. Review and remove former employee accounts
One of the most common and most avoidable attack vectors. How to do it: Admin Center → Users → review users with very old last login dates.
4. Review who has Global Administrator permissions
The Global Administrator role has access to absolutely everything. It should have the fewest possible people assigned. How to do it: Admin Center → Roles → Global Administrator.
5. Activate the unified audit log
By default, Microsoft 365 doesn't log all user activities. The unified audit log is essential for detecting incidents and for GDPR compliance. How to do it: Microsoft Compliance Portal → Audit → Start Recording.
These five changes are the starting point. If you want to know exactly what state your M365 environment is in, request a free security audit.