Network Bridge Solutions
← All insightsThinking · 3 min read

Seven Microsoft 365 Security Mistakes: Why Do Careful Businesses Keep Making Them?

None of them is exotic. All of them are invisible from the inside.

Part of Microsoft 365 x NIS2
A factory fire door propped open with a fire extinguisher, the production floor visible beyond.

A pattern, not a survey

What follows is not a statistic. It is a pattern: the same handful of findings, tenant after tenant, in businesses run by careful people. We see them because we look at Microsoft 365 environments for a living. The owners do not see them for the same reason you cannot smell your own house.

The mistakes share one root. Nobody in the business ever sat down and made security decisions about the tenant, so the tenant runs on the decisions nobody made. Under NIS2, which asks for measures that are documented, managed and monitored, that root cause is itself the finding. But the pattern is easier to fix when you can name its parts.

The seven

One: the second sign-in check with exceptions. Most businesses now have multi-factor authentication, which is progress. Almost as many have exceptions: the managing director who found it annoying, the shared mailbox in dispatch, the old account the accounts package logs in with. Attackers do not attack your policy. They attack your exceptions, and one is enough.

Two: administrator accounts used for everyday work. The same account that reads email and opens attachments can also change every rule in the tenant. One convincing phishing message and the attacker is not a user, he is the administrator. Admin rights belong in separate accounts, used only for admin work, watched more closely than anything else you own.

Three: the leavers who never left. Accounts of people who resigned years ago, still enabled, still licensed, sometimes still forwarding mail. Every one is an unwatched door with a valid key, and the forwarding rule is how a quiet compromise stays quiet.

Four: sharing set to everything, forever. Links that anyone can open, passed along outside the business; guest accounts from a project in 2022 with standing access to the whole site. The file server had walls. The default cloud has none until someone builds them, and "someone" was never named.

Five: nobody reads the signals. The platform already produces sign-in alerts, a security score, audit logs. In most small businesses they arrive nowhere. The tenant is shouting into a room with no one in it, which is why day one of an incident is routinely weeks after the intrusion.

Six: backup by assumption. The belief that the platform's resilience is a backup of your data. It is not, and the difference appears precisely when you need it most.

Seven: no record of any of it. Even where settings are decent, nothing is written down: no as-built record, no reasons, no change log. Which means the business cannot answer a customer questionnaire, cannot brief a new IT provider, and cannot prove to anyone, including itself, that its security is deliberate.

Why sensible people make them

Not carelessness. Sequence. Every one of these is the residue of a rational day-one choice: get everyone working, keep friction low, move on. The tenant was configured for a business getting started, and no event ever forced the transition to a business being run. Software does not rust visibly. The settings that were fine at five people are still there at eighty, and nothing beeps.

This is why we keep saying the gap is a systems gap, not a people gap. Nobody was given the job of deciding, so the defaults decided. NIS2's contribution, for all its bureaucratic prose, is to create the forcing event: the customer questionnaire arrives, and "nobody ever decided" stops being invisible.

The order that works

Fix them in the order an attacker would exploit them, not the order they annoy you.

First, close the identity doors: the second check everywhere, no exceptions surviving without a written reason and a compensating control; separate admin accounts. Second, clean the population: leavers disabled, guests reviewed, forwarding rules audited. Third, turn the signals toward a human: alerts routed to a named person, the score read monthly. Fourth, make one backup copy real and tested. Fifth, write down what you now have, because the record is what turns all the above from housekeeping into evidence.

Then keep it that way, which is the part that separates a clean-up from a security posture. Settings drift, people join and leave, exceptions creep back. A quarterly hour reviewing the five areas above, logged in one page, is the minimum heartbeat; a managed baseline makes the heartbeat automatic and the log write itself.

None of the seven requires new software. All of them require a decision, a name and a date. That is the whole difference between the tenant you have and the tenant the questionnaire assumes you have.