Microsoft 365 sits at the centre of day-to-day work for many organisations. Email, documents, meetings, identities, devices and increasingly AI-assisted workflows all depend on the same connected platform.
That integration makes Microsoft 365 productive, but it also means a compromised account or poorly governed SharePoint site can expose much more than a single mailbox. Attackers may use valid credentials, malicious inbox rules, OAuth applications, overshared files or unmanaged devices to reach business data without deploying traditional malware.
Microsoft secures the underlying cloud platform and provides a broad set of security controls. The customer must still configure those controls, govern access, protect endpoints, monitor alerts and prepare for recovery. Microsoft 365 security is therefore an operating discipline, not a setting that can be switched on once and forgotten.
What has changed since the original Microsoft 365 security model?
The core risks remain familiar, but the platform and attack methods have moved on.
- Microsoft 365 Advanced Threat Protection is now Microsoft Defender for Office 365. It includes controls such as Safe Links, Safe Attachments, anti-phishing policies and investigation capabilities.
- Microsoft Entra ID is the identity control plane. Conditional Access, Identity Protection, Privileged Identity Management, access reviews and lifecycle workflows now play a central role in securing Microsoft 365.
- Microsoft Defender XDR correlates activity across identities, endpoints, email and cloud applications. Coverage alone is not enough; alerts and detections still need to be tuned and investigated.
- Microsoft Purview protects and governs information. Sensitivity labels, Data Loss Prevention, Records Management, eDiscovery and Insider Risk Management can be applied across Exchange, Teams, SharePoint, OneDrive and endpoints, subject to licensing.
- Microsoft 365 Copilot and agents increase the importance of existing permissions. AI can surface information a user already had access to but may never previously have found.
- Phishing-resistant authentication is increasingly practical. Passkeys, FIDO2 security keys and Windows Hello for Business can provide stronger protection than passwords combined with approval-based MFA.
The security programme should reflect this wider identity, data and AI landscape rather than focus only on antivirus and infected files.
The main Microsoft 365 security risks in 2026
1. Stolen identities and session tokens
Microsoft 365 is designed to be accessed from many locations and devices. This makes identity the main route into the platform. Attackers may steal passwords through phishing, persuade users to approve an MFA request, compromise a browser session or socially engineer the service desk into resetting an account.
Once signed in, an attacker can read email, search SharePoint, create inbox rules, register applications, impersonate the user and target colleagues or suppliers from a trusted account.
Multi-factor authentication remains a minimum control, but organisations should move higher-risk users and administrators towards phishing-resistant methods. Microsoft recommends options such as passkeys using FIDO2, FIDO2 security keys, Windows Hello for Business and certificate-based authentication. Conditional Access authentication strengths can enforce the required method for sensitive resources.
2. Excessive and permanent administrator access
Microsoft 365 tenants often accumulate more privileged accounts than the organisation realises. Global Administrator rights may be assigned permanently, old project accounts remain active and support staff use privileged identities for routine work.
Administrative accounts should be separate from normal user accounts. Microsoft Entra Privileged Identity Management can provide time-limited, just-in-time activation for privileged roles, supported by approval, MFA, justification and audit where appropriate.
Maintain at least two emergency access accounts for situations where normal identity controls fail. These accounts require strong protection, monitoring and a tested procedure; they should not become convenient alternatives to the normal administration process.
3. Phishing, impersonation and business email compromise
Email remains a common entry point. The risk is no longer limited to crude messages containing an obvious malicious attachment. Attackers can imitate senior leaders, suppliers or finance contacts, use compromised legitimate accounts and generate convincing language at scale.
Microsoft Defender for Office 365 can provide anti-phishing controls, impersonation protection, Safe Links and Safe Attachments. Microsoft publishes Standard and Strict preset security policies that provide a maintained starting point for recommended settings.
Technology should be combined with business verification. Changes to bank details, urgent payment requests and privileged password resets should be confirmed through an approved channel that does not rely solely on the message, call or meeting being presented.
4. Risky OAuth applications and application consent
Users may grant third-party applications access to Microsoft 365 data without sharing their password. An OAuth application can retain access through permissions to read mail, files, contacts or calendars, potentially continuing after the original user interaction has ended.
Control which users can consent to applications, establish an approval process and review enterprise applications regularly. Microsoft Defender for Cloud Apps can show which user-installed OAuth applications have access to Microsoft 365 data, the permissions they hold and which users granted access.
Unused applications, broad permissions and old credentials should be removed. A tenant-wide application permission can create more risk than a dormant user account.
5. Weak joiner, mover and leaver processes
Access changes throughout employment. A person may join a project, move department, become a manager, work with an external partner and then leave. If each change only adds permissions, access expands without a reliable way to remove it.
Automate identity lifecycle tasks where possible and connect them to an authoritative HR record. Use access reviews for sensitive groups, applications, guest users and privileged roles. Reviewers should be named business owners who understand whether the access remains necessary, not only IT administrators.
6. SharePoint, Teams and OneDrive oversharing
Collaboration sites are easy to create and share. Over time, broad groups, external guests, anonymous links and inherited permissions can make sensitive information available to more people than intended.
For SharePoint Online, Microsoft manages and patches the underlying service. Customers do not apply SharePoint Online server patches. Their responsibility is to manage site creation, sharing, permissions, guest access, information protection, retention and monitoring. Organisations operating SharePoint Server on premises have a separate patching responsibility.
Use controlled site-provisioning standards, expiry for external access, regular owner reviews and sensitivity labels for sites and Microsoft 365 groups. Remove stale workspaces and guest access when the collaboration need has ended.
7. Copilot exposing existing data-governance problems
Microsoft 365 Copilot generally works within the access available to the signed-in user. That is an important security boundary, but it can reveal permissions that were already too broad. AI can search and combine information far faster than a person browsing through old sites and folders.
Before a tenant-wide rollout, identify overshared SharePoint and OneDrive content, apply appropriate sensitivity labels, review retention and remove obsolete data. Microsoft Purview Data Loss Prevention can also restrict selected sensitive information from being processed in Microsoft 365 Copilot prompts or grounding data, depending on the configuration and licences in use.
Copilot readiness should therefore start with identity and information governance, not only licence assignment and user training.
8. Unmanaged or unhealthy devices
A valid account used from an infected or unmanaged device can expose Microsoft 365 data. Browser downloads, synchronised OneDrive folders, locally cached email and copied Teams content may remain outside the organisation’s normal controls.
Use Microsoft Intune or an equivalent management platform to enforce device configuration, encryption, update and compliance requirements. Conditional Access can require a compliant or managed device for sensitive applications and block unsupported legacy authentication.
Microsoft Defender for Endpoint can provide endpoint protection, detection and response. Safe Attachments can also be extended to SharePoint, OneDrive and Teams where the appropriate Defender for Office 365 capability is configured.
9. Data leakage through email, chat, files and endpoints
Users can disclose sensitive information accidentally, through a compromised account or by deliberately bypassing policy. The same data may move between Exchange, Teams, SharePoint, OneDrive, endpoints and non-Microsoft services.
Microsoft Purview sensitivity labels can classify and protect documents, email and collaborative workspaces. Data Loss Prevention can detect and control sensitive information across Microsoft 365 locations and endpoints. Policies should reflect the organisation’s real data and working practices, not a generic label structure that users cannot understand.
Start in simulation or audit mode where the product supports it. Review the results and reduce false positives before introducing controls that block legitimate work.
10. Incomplete monitoring and uninvestigated alerts
Microsoft 365 produces sign-in, audit, endpoint, email, application and data-security signals. These have limited value when nobody reviews them or when default detections generate more noise than the team can handle.
Microsoft Defender XDR can correlate incidents across Defender products, while Microsoft Sentinel can combine Microsoft and third-party security data in a SIEM. The operating process should define who owns priority alerts, response times, out-of-hours escalation and how detections are tuned.
Monitor for unusual sign-ins, risky users, impossible travel, malicious inbox rules, mass download or deletion, privilege changes, new OAuth consent, disabled controls and unexpected external sharing.
11. Confusing retention, versioning and backup
SharePoint and OneDrive include version history, recycle bins and service-level recovery features. These can be valuable following accidental deletion or ransomware, but they should be assessed against the organisation’s recovery requirements rather than assumed to be a complete backup strategy.
Microsoft states that deleted SharePoint content may remain available through service backups for a limited period after other recovery routes have been exhausted. That recovery window may not meet every legal, operational or ransomware scenario.
Define recovery point and recovery time objectives for Exchange, SharePoint, OneDrive, Teams and any business applications relying on Microsoft 365 data. Decide whether native recovery and retention are sufficient or whether a separate backup platform is needed. Test representative restores and protect recovery administration from the same identities used in production.
12. Licensing gaps and unused security entitlement
Microsoft 365 security capability varies by licence. Features such as Entra ID Governance, Privileged Identity Management, risk-based Conditional Access, Defender for Office 365, Defender for Endpoint, Purview and advanced auditing are not available in every subscription.
Organisations can therefore have two opposite problems: assuming a control is active because the product name appears in the tenant, or paying for E5 and other add-ons without deploying the included capability.
Map each required control to the licence, configuration, owner and operating process. Microsoft Secure Score can help identify recommended actions, but a higher score is not proof that business risk has been addressed. Prioritise recommendations against exposure, available licences and the services that matter most.
A practical Microsoft 365 security baseline
The exact design will depend on licences, users, data and regulatory requirements. The following baseline provides a sensible starting point.
- Inventory the tenant. Record verified domains, users, guests, administrators, applications, service accounts, devices, Microsoft 365 groups, Teams, SharePoint sites and licences.
- Protect every user with MFA. Use Security Defaults where that is the appropriate baseline or Conditional Access for a managed policy set. Move administrators and high-risk users to phishing-resistant authentication.
- Block legacy authentication. Remove protocols and clients that cannot support modern authentication unless a documented exception is genuinely required.
- Separate and control privileged access. Use dedicated administrator accounts, least privilege, Privileged Identity Management and monitored emergency access accounts.
- Implement Conditional Access carefully. Apply user, device, risk, location and application conditions in stages. Use report-only mode and exclude emergency accounts from policies where Microsoft guidance requires it, while monitoring those accounts separately.
- Apply Microsoft’s email protection baselines. Review Standard or Strict preset security policies, Safe Links, Safe Attachments, anti-phishing, impersonation protection and domain-authentication controls such as SPF, DKIM and DMARC.
- Manage endpoints. Require supported operating systems, encryption, security updates and endpoint protection. Restrict sensitive data from unmanaged devices where the business requirement supports it.
- Govern applications and consent. Limit user consent, introduce an approval process and review OAuth apps, enterprise applications, credentials and permissions regularly.
- Automate access lifecycle. Connect joiner, mover and leaver processes to HR data where possible. Run recurring access reviews for guests, sensitive groups, applications and privileged roles.
- Reduce SharePoint and Teams oversharing. Establish site ownership, creation standards, guest expiry, link controls and periodic access reviews. Remove inactive workspaces and obsolete data.
- Deploy information protection. Build sensitivity labels, retention and DLP around the organisation’s records and risk requirements. Test policies before enforcement.
- Complete Copilot groundwork before broad deployment. Review access, oversharing, labels, retention and high-risk data. Define which information Copilot and agents may process.
- Connect security monitoring to a response process. Use Defender XDR, Sentinel or the organisation’s selected platforms with named ownership, escalation and detection tuning.
- Define and test recovery. Confirm how mailboxes, files, sites, Teams content, identities and configurations would be recovered after deletion, compromise or ransomware.
- Review Secure Score and licences regularly. Use improvement actions as an input to prioritisation and identify unused security entitlement or missing capability.
A 90-day improvement plan
Days 1–30: identify immediate exposure
- Confirm MFA coverage and block legacy authentication.
- Review Global Administrators and other high-impact roles.
- Establish or validate emergency access accounts.
- Check external sharing, anonymous links and guest users.
- Review email-protection policies and high-risk impersonation targets.
- Identify unapproved OAuth applications and broad consent grants.
- Confirm priority security alerts have a named response owner.
Days 31–60: strengthen governance
- Deploy or tune Conditional Access policies.
- Introduce Privileged Identity Management where licensed.
- Start recurring access reviews for privileged and guest access.
- Define SharePoint and Teams creation and ownership standards.
- Build the initial Purview label and DLP design.
- Map required controls to current licences and identify unused entitlement.
Days 61–90: prove the controls work
- Run a phishing and account-compromise exercise.
- Test a SharePoint, OneDrive or mailbox recovery scenario.
- Review Defender XDR or SIEM incidents and tune noisy detections.
- Complete a Copilot readiness assessment before wider AI rollout.
- Produce an executive view of risk, completed actions and the next funded priorities.
How CloudCoCo helps secure Microsoft 365
Microsoft 365 security crosses identity, endpoints, email, data governance, AI, licensing and security operations. CloudCoCo can assess the tenant, deliver the required controls and operate them as a managed or co-managed service.
- Microsoft technology services – Microsoft Purview sensitivity labels and DLP, SharePoint oversharing remediation, Entra ID Governance, Conditional Access, Privileged Identity Management, Microsoft 365 Copilot readiness, Defender XDR and Sentinel optimisation.
- Cyber Security – identity-led defence, email and human-layer security, managed detection and response through a UK SOC, Data Security Posture Management, penetration testing and incident-response support.
- Managed IT Services – Microsoft Intune, Autopilot, Defender for Endpoint, joiner-mover-leaver operations, access reviews, service desk and observability with named accountability.
- IT Consulting – fixed-scope Microsoft 365 Optimisation covering licence right-sizing, Purview gaps, Copilot readiness, Entra hardening and a costed implementation plan.
The first step is usually a tenant and licensing assessment. This establishes which controls are already licensed, which are configured effectively, where access has accumulated and what should be addressed first.
Microsoft 365 security FAQs
Is Microsoft 365 secure by default?
Microsoft provides secure infrastructure and several baseline protections, but the customer must still manage users, permissions, devices, applications, sharing, data governance, monitoring and recovery. The level of available protection also depends on the licences in use.
What happened to Microsoft 365 ATP?
Office 365 Advanced Threat Protection was renamed Microsoft Defender for Office 365. Current controls include Safe Links, Safe Attachments, anti-phishing and investigation capabilities.
Is MFA enough to secure Microsoft 365?
No. MFA significantly improves security, but attackers may target weaker authentication methods, session tokens, application consent or service-desk processes. Use Conditional Access, phishing-resistant authentication for higher-risk users, identity monitoring and verified account-recovery procedures.
Do we need to patch SharePoint Online?
No. Microsoft manages and patches SharePoint Online. Customers remain responsible for permissions, sharing, guest access, data protection, configuration and monitoring. SharePoint Server operated on premises must still be patched by the organisation responsible for it.
Does Microsoft 365 Copilot create new access to our data?
Copilot generally uses the signed-in user’s existing Microsoft 365 access. The risk is that existing access may already be broader than intended. Review SharePoint and OneDrive oversharing, sensitivity labels, DLP, retention and guest access before a broad rollout.
Does Microsoft back up Microsoft 365 data?
Microsoft provides platform resilience and native recovery features, including version history and recycle bins. Organisations should assess whether these meet their recovery, retention and ransomware requirements and introduce separate backup where needed.
How often should Microsoft 365 security be reviewed?
Priority alerts and risky sign-ins require continuous attention. Access, applications, sharing, licences and Secure Score should be reviewed on a regular operating schedule, with privileged and sensitive access reviewed at least quarterly where the risk warrants it.
Talk to CloudCoCo about assessing, securing and operating your Microsoft 365 environment.

Leave a comment!