Home 9 Business 9 5 Microsoft 365 Settings You Should Check Today

5 Microsoft 365 Settings You Should Check Today

5 Microsoft 365 Settings You Should Check Today (Especially if Your Setup Is a Few Years Old)

If your Microsoft 365 system was set up a few years ago, there’s a good chance it’s not as secure as you think.

Microsoft has improved security defaults over time. But those improvements don’t always apply to older setups. That means your business could still be running with outdated settings quietly exposing your data.

The good news is this. You can fix most of these in under an hour.

In this guide, we’ll walk you through five important settings to review, why they matter, and how to approach them safely.

If you’re unsure where to start, our team at Bespoke IT Solutions can help you review and secure your setup properly.


Why this matters

Microsoft follows a “secure by default” approach. New systems get stronger protection automatically, but older ones often keep their original settings.

For example:

  • Sharing links created years ago may still give open access
  • Email forwarding rules may still send data outside your business
  • Apps connected years ago may still have access to files and emails

And in many cases, no one is actively checking these.

This is exactly where most security gaps appear.


1. SharePoint and OneDrive file sharing links

Your problem:
Files may still be shared with “Anyone with the link” access.

This means anyone with the link can open the file without signing in, and you won’t know who has accessed it.

Microsoft explains that “Anyone” links don’t require authentication and can be forwarded to others without tracking. /learn.microsoft.com/en-us/sharepoint/shareable-links-anyone-specific-people-organization)

Our solution:
Change the default sharing setting to “Specific people” or “Only people in your organisation.”

Also set expiry dates on older links so access doesn’t stay open forever.

The benefit to you:
You stay in control of who sees your data. No more unknown access or links being passed around.

👉 Need help locking this down? Speak to our team


2. External email forwarding rules

Your problem:
Emails may still be automatically forwarded to personal accounts without you realising.

Microsoft now blocks this by default because it increases the risk of sensitive data leaving your organisation. /learn.microsoft.com/en-us/defender-office-365/outbound-spam-policies-external-email-forwarding)

Our solution:
Check your outbound spam policy and review existing mailbox rules across your team.

The benefit to you:
You stop data leaks before they happen and regain visibility over where emails are going.

👉 We regularly find hidden forwarding rules during security reviews. Book a check


3. Old third-party app access

Your problem:
Apps connected years ago may still have access to emails, calendars, and files.

Microsoft updated its default consent controls in July 2025 to prevent users from approving risky apps going forward. /blog.interian.be/2025/07/17/microsoft-entra-consent-changes-coming-july-2025-a-guide-for-admins/)

However, existing permissions stay in place unless you review them.

Our solution:
Audit your connected apps in Microsoft Entra ID and remove anything you no longer recognise or need.

The benefit to you:
You reduce unnecessary access and close down hidden security risks.


4. Audit log retention

Your problem:
You may not have enough history to investigate issues or meet compliance requirements.

Microsoft increased the default audit log retention to 180 days in October 2023, up from 90 days. [4](https://learn.microsoft.com/en-us/purview/audit-log-retention-policies)

But many industries require much longer records.

Our solution:
Check your retention settings and extend them if your licensing allows.

The benefit to you:
You have the evidence you need when something goes wrong, and you stay aligned with compliance requirements.


5. Multi-Factor Authentication (MFA) and Security Defaults

Your problem:
MFA might not be fully enforced across your team, especially in older setups.

Microsoft introduced Security Defaults to enforce MFA automatically for new tenants. [5](https://learn.microsoft.com/en-us/microsoft-365/admin/security-and-compliance/set-up-multi-factor-authentication?view=o365-worldwide)

These defaults require a second sign-in method and significantly improve account security. [5](https://learn.microsoft.com/en-us/microsoft-365/admin/security-and-compliance/set-up-multi-factor-authentication?view=o365-worldwide)

The problem is older systems often have gaps, especially if changes were made over time.

Our solution:
Check whether Security Defaults or Conditional Access is in place and confirm every account is protected.

The benefit to you:
You protect your business from one of the most common attack methods with a simple but powerful step.


A simple order to review these safely

  • Start with audit logs and app access (no user impact)
  • Check email forwarding next (usually silent)
  • Plan communication before changing file sharing
  • Review MFA last, as it needs careful setup

You don’t need to change everything at once. Small, steady improvements work best.


How we can help

If you’re unsure where your setup stands, you’re not alone.

Most businesses we speak to haven’t reviewed these settings since their system was first set up.

Your problem:
You don’t know what’s been left open or missed.

Our solution:
We carry out clear, practical Microsoft 365 reviews and fix what needs attention without disrupting your team.

The benefit to you:
You get peace of mind, better protection, and a system that works the way it should.

👉 Book a Microsoft 365 security review with Bespoke IT Solutions


FAQs

Are newer Microsoft 365 systems fully secure?

They are more secure by default, but still need regular review. Settings, app access, and sharing can all change over time.

Is external email forwarding still allowed?

No, it is blocked by default now, but older rules may still exist and need checking. [2](https://learn.microsoft.com/en-us/defender-office-365/outbound-spam-policies-external-email-forwarding)

How long are audit logs stored?

180 days by default, with longer retention available depending on licensing. [4](https://learn.microsoft.com/en-us/purview/audit-log-retention-policies)

What does MFA actually add?

It adds a second sign-in step, which significantly improves security against common attacks. [5](https://learn.microsoft.com/en-us/microsoft-365/admin/security-and-compliance/set-up-multi-factor-authentication?view=o365-worldwide)

Recent Posts

Cyber Security Is Not Your Job. Understanding Business Risk Is.

Cyber Security Is Not Your Job. Understanding Business Risk Is.

Many business owners switch off the moment cyber security enters the conversation. They picture firewalls, software updates, security alerts and technical jargon. It feels like something that belongs firmly in the hands of IT professionals. The reality is very...

Cyber Confidence Guide and checklist.

Cyber Confidence Guide and checklist.

Welcome to the Cyber Confidence Guide Cyber security is no longer just an IT concern. It is a business priority. Whether your organisation has five employees or five hundred, protecting your systems, data and people is essential to maintaining trust, productivity and...

The 30-Minute IT Health Check Every Small Business Should Do

The 30-Minute IT Health Check Every Small Business Should Do

The 30-Minute IT Health Check Every Small Business Should Do Monthly Most IT problems don't appear out of nowhere. Backups quietly stop running, updates sit unfinished for weeks and old staff accounts stay active long after someone has left the business. A simple...

What Are Passkeys, and Should Your Business Use Them?

What Are Passkeys, and Should Your Business Use Them?

Cybersecurity made simple Passkeys: The Safer, Simpler Way to Sign In Without Passwords Passwords have been causing businesses problems for years. They get reused, forgotten, guessed, leaked, written down, shared, and typed into fake login pages by mistake. Passkeys...

How are cyber attacks effecting your insurance?

How are cyber attacks effecting your insurance?

Cyber Insurance Renewal: What’s Changed and How to Avoid Claim Denial If your cyber insurance renewal feels harder this year, you’re not alone. Right now, many businesses are facing longer forms, tougher questions, and more pressure to prove their security. As a...

Could Someone Send Emails Pretending To Be Your Business

Could Someone Send Emails Pretending To Be Your Business

Cyber Security Guide Could Someone Send Emails Pretending To Be Your Business? Email spoofing is one of the simplest ways scammers can damage trust in your business. The good news is that three DNS records — SPF, DKIM and DMARC — can make it much harder for criminals...

Continuous Digital Transformation Partnerships

Continuous Digital Transformation Partnerships

Continuous Digital Transformation Partnerships Why outsourcing is no longer about handing work off, but moving forward together For many organisations, change never really stops. You upgrade one system, and another starts to fall behind. You move to the cloud, and...

Could a Cyber Criminal Send Emails Pretending to Be You?

Could a Cyber Criminal Send Emails Pretending to Be You?

Could a Cyber Criminal Send Emails Pretending to Be Your Company Today? Imagine one of your customers receives an email from what appears to be your accounts department. The branding looks correct. The signature looks genuine. The email address seems legitimate. The...

How Outsourcing Is Driving Innovation in UK Businesses

How Outsourcing Is Driving Innovation in UK Businesses

Beyond Cost Savings: Outsourcing for Innovation Why UK businesses are turning IT partners into growth drivers The problem For a long time, outsourcing was just about saving money. You handed over IT tasks, reduced costs, and kept things running. But today, that...