Home 9 Business 9 5 Microsoft 365 Settings You Should Check Today

5 Microsoft 365 Settings You Should Check Today

5 Microsoft 365 Settings You Should Check Today (Especially if Your Setup Is a Few Years Old)

If your Microsoft 365 system was set up a few years ago, there’s a good chance it’s not as secure as you think.

Microsoft has improved security defaults over time. But those improvements don’t always apply to older setups. That means your business could still be running with outdated settings quietly exposing your data.

The good news is this. You can fix most of these in under an hour.

In this guide, we’ll walk you through five important settings to review, why they matter, and how to approach them safely.

If you’re unsure where to start, our team at Bespoke IT Solutions can help you review and secure your setup properly.


Why this matters

Microsoft follows a “secure by default” approach. New systems get stronger protection automatically, but older ones often keep their original settings.

For example:

  • Sharing links created years ago may still give open access
  • Email forwarding rules may still send data outside your business
  • Apps connected years ago may still have access to files and emails

And in many cases, no one is actively checking these.

This is exactly where most security gaps appear.


1. SharePoint and OneDrive file sharing links

Your problem:
Files may still be shared with “Anyone with the link” access.

This means anyone with the link can open the file without signing in, and you won’t know who has accessed it.

Microsoft explains that “Anyone” links don’t require authentication and can be forwarded to others without tracking. /learn.microsoft.com/en-us/sharepoint/shareable-links-anyone-specific-people-organization)

Our solution:
Change the default sharing setting to “Specific people” or “Only people in your organisation.”

Also set expiry dates on older links so access doesn’t stay open forever.

The benefit to you:
You stay in control of who sees your data. No more unknown access or links being passed around.

👉 Need help locking this down? Speak to our team


2. External email forwarding rules

Your problem:
Emails may still be automatically forwarded to personal accounts without you realising.

Microsoft now blocks this by default because it increases the risk of sensitive data leaving your organisation. /learn.microsoft.com/en-us/defender-office-365/outbound-spam-policies-external-email-forwarding)

Our solution:
Check your outbound spam policy and review existing mailbox rules across your team.

The benefit to you:
You stop data leaks before they happen and regain visibility over where emails are going.

👉 We regularly find hidden forwarding rules during security reviews. Book a check


3. Old third-party app access

Your problem:
Apps connected years ago may still have access to emails, calendars, and files.

Microsoft updated its default consent controls in July 2025 to prevent users from approving risky apps going forward. /blog.interian.be/2025/07/17/microsoft-entra-consent-changes-coming-july-2025-a-guide-for-admins/)

However, existing permissions stay in place unless you review them.

Our solution:
Audit your connected apps in Microsoft Entra ID and remove anything you no longer recognise or need.

The benefit to you:
You reduce unnecessary access and close down hidden security risks.


4. Audit log retention

Your problem:
You may not have enough history to investigate issues or meet compliance requirements.

Microsoft increased the default audit log retention to 180 days in October 2023, up from 90 days. [4](https://learn.microsoft.com/en-us/purview/audit-log-retention-policies)

But many industries require much longer records.

Our solution:
Check your retention settings and extend them if your licensing allows.

The benefit to you:
You have the evidence you need when something goes wrong, and you stay aligned with compliance requirements.


5. Multi-Factor Authentication (MFA) and Security Defaults

Your problem:
MFA might not be fully enforced across your team, especially in older setups.

Microsoft introduced Security Defaults to enforce MFA automatically for new tenants. [5](https://learn.microsoft.com/en-us/microsoft-365/admin/security-and-compliance/set-up-multi-factor-authentication?view=o365-worldwide)

These defaults require a second sign-in method and significantly improve account security. [5](https://learn.microsoft.com/en-us/microsoft-365/admin/security-and-compliance/set-up-multi-factor-authentication?view=o365-worldwide)

The problem is older systems often have gaps, especially if changes were made over time.

Our solution:
Check whether Security Defaults or Conditional Access is in place and confirm every account is protected.

The benefit to you:
You protect your business from one of the most common attack methods with a simple but powerful step.


A simple order to review these safely

  • Start with audit logs and app access (no user impact)
  • Check email forwarding next (usually silent)
  • Plan communication before changing file sharing
  • Review MFA last, as it needs careful setup

You don’t need to change everything at once. Small, steady improvements work best.


How we can help

If you’re unsure where your setup stands, you’re not alone.

Most businesses we speak to haven’t reviewed these settings since their system was first set up.

Your problem:
You don’t know what’s been left open or missed.

Our solution:
We carry out clear, practical Microsoft 365 reviews and fix what needs attention without disrupting your team.

The benefit to you:
You get peace of mind, better protection, and a system that works the way it should.

👉 Book a Microsoft 365 security review with Bespoke IT Solutions


FAQs

Are newer Microsoft 365 systems fully secure?

They are more secure by default, but still need regular review. Settings, app access, and sharing can all change over time.

Is external email forwarding still allowed?

No, it is blocked by default now, but older rules may still exist and need checking. [2](https://learn.microsoft.com/en-us/defender-office-365/outbound-spam-policies-external-email-forwarding)

How long are audit logs stored?

180 days by default, with longer retention available depending on licensing. [4](https://learn.microsoft.com/en-us/purview/audit-log-retention-policies)

What does MFA actually add?

It adds a second sign-in step, which significantly improves security against common attacks. [5](https://learn.microsoft.com/en-us/microsoft-365/admin/security-and-compliance/set-up-multi-factor-authentication?view=o365-worldwide)

Recent Posts

What Are Passkeys, and Should Your Business Use Them?

What Are Passkeys, and Should Your Business Use Them?

Cybersecurity made simple Passkeys: The Safer, Simpler Way to Sign In Without Passwords Passwords have been causing businesses problems for years. They get reused, forgotten, guessed, leaked, written down, shared, and typed into fake login pages by mistake. Passkeys...

How are cyber attacks effecting your insurance?

How are cyber attacks effecting your insurance?

Cyber Insurance Renewal: What’s Changed and How to Avoid Claim Denial If your cyber insurance renewal feels harder this year, you’re not alone. Right now, many businesses are facing longer forms, tougher questions, and more pressure to prove their security. As a...

Could Someone Send Emails Pretending To Be Your Business

Could Someone Send Emails Pretending To Be Your Business

Cyber Security Guide Could Someone Send Emails Pretending To Be Your Business? Email spoofing is one of the simplest ways scammers can damage trust in your business. The good news is that three DNS records — SPF, DKIM and DMARC — can make it much harder for criminals...

Continuous Digital Transformation Partnerships

Continuous Digital Transformation Partnerships

Continuous Digital Transformation Partnerships Why outsourcing is no longer about handing work off, but moving forward together For many organisations, change never really stops. You upgrade one system, and another starts to fall behind. You move to the cloud, and...

Could a Cyber Criminal Send Emails Pretending to Be You?

Could a Cyber Criminal Send Emails Pretending to Be You?

Could a Cyber Criminal Send Emails Pretending to Be Your Company Today? Imagine one of your customers receives an email from what appears to be your accounts department. The branding looks correct. The signature looks genuine. The email address seems legitimate. The...

How Outsourcing Is Driving Innovation in UK Businesses

How Outsourcing Is Driving Innovation in UK Businesses

Beyond Cost Savings: Outsourcing for Innovation Why UK businesses are turning IT partners into growth drivers The problem For a long time, outsourcing was just about saving money. You handed over IT tasks, reduced costs, and kept things running. But today, that...

How secure is your backup solution?

How secure is your backup solution?

Immutable Backups: The Cyber Insurance Question That Catches Businesses Out Immutable backups are now one of the most important parts of cyber insurance and ransomware protection. However, many businesses are not sure what they are or whether they already have them in...

What to do in case of a cyber attack

What to do in case of a cyber attack

Cyberattack? Here's Exactly What Your Business Should Do in the First Hour It's 2pm on a normal Monday. Your team are busy working, emails are flowing, and everything seems normal. Then suddenly something isn't right. Files won't open. Systems are running strangely. A...

Small businesses are still targets of cyber attacks.

Small businesses are still targets of cyber attacks.

A ransomware attack on a small business does not happen overnight. Instead, it builds step by step, often starting with simple mistakes that go unnoticed. In fact, many attacks succeed because of small gaps rather than complex hacking. So in this guide, we will walk...