...

Common Microsoft 365 Mistakes UK Firms Make

Table of Contents

Introduction: Why Microsoft 365 Is Often Misconfigured
The 15 Most Common Microsoft 365 Mistakes
1. Not Enabling Multi-Factor Authentication (MFA)

What it looks like

Why it’s a problem

How to fix it

2. Weak or Reused Passwords

What it looks like

Why it’s a problem

How to fix it

3. Allowing Legacy Authentication

What it looks like

Why it’s a problem

How to fix it

4. Over-Permissive SharePoint & OneDrive Sharing

What it looks like

Why it’s a problem

How to fix it

5. No Backup for Microsoft 365 Data

What it looks like

Why it’s a problem

How to fix it

6. Poor User Access Control

What it looks like

Why it’s a problem

How to fix it

7. Not Monitoring Suspicious Logins

What it looks like

Why it’s a problem

How to fix it

8. Lack of Email Security Policies

What it looks like

Why it’s a problem

How to fix it

9. Misconfigured Spam & Phishing Protection

What it looks like

Why it’s a problem

How to fix it

10. No Staff Phishing Training

What it looks like

Why it’s a problem

How to fix it

11. Ignoring Updates and Changes

What it looks like

Why it’s a problem

How to fix it

12. No Device Management or Endpoint Security

What it looks like

Why it’s a problem

How to fix it

13. Using Personal Accounts for Business Data

What it looks like

Why it’s a problem

How to fix it

14. No Joiners and Leavers Process

What it looks like

Why it’s a problem

How to fix it

15. Poor Use of Teams and File Storage

What it looks like

Why it’s a problem

How to fix it

Microsoft 365 Security Checklist
Microsoft 365 Optimisation Checklist

FAQs

It has solid security features you just need to enable them correctly.

Yes, SMEs represent a major segment of overall target for attacks.

Yes; Microsoft backs up your data, but does not provide a comprehensive backup.

At least once every three months.

Some of them may be fixed by working with external experts.

About This Guide

The Computer Support Centre has produced a guide to help UK SMEs learn about typical configuration errors made during setup of Microsoft 365. Many businesses use Microsoft 365 as their main tool for email, file storage, collaboration and communication tools. In most cases, organisations deploy Microsoft 365 much quicker than they move through the security and management setup processes.

This document provides a simple and practical explanation of common MS-365 configuration errors and demonstrates how to resolve those errors. Correcting errors related to user access control, multi-factor authentication, email security/protection and device management will help reduce organisations’ cyber-security risk, improve organisation productivity, and assist with compliance with UK data protection laws and regulations.

Conclusion

The Microsoft 365 platform is considered one of the biggest and best-performing business solutions available today in the UK; however Microsoft 365 does not have built-in security features and optimisations once it has been rolled out.

When Microsoft 365 is initially rolled out, many organisations do not realise they have left significant security gaps within their use of the platform. In many cases, the following types of security are available- authentication, access control, data loss protection, and email security. Because of these security misconfiguration, there are numerous opportunities for cyberattacks, data loss and disruption of operations to occur.

To help reduce the ever-growing amount of risk and increase the security posture of Microsoft 365; by addressing the common mistakes mentioned within this guide and implementing some simple changes to your Microsoft 365 environment (i.e. MFA, permission restrictions, monitoring activity, providing education and training); your organisation can make significant improvements to your overall security.

Implementation of a multiple review process, having a clear, concise policy for using Microsoft 365, and ongoing employee education will help to ensure that Microsoft 365 will provide a secure, efficient and compliant environment for your organisation as your organisation continues to grow.