Network Bridge Solutions

What are the most common mistakes small businesses make with Microsoft 365 security?

Short answer

Seven, and none of them exotic: sign-in checks with exceptions, administrator accounts used for everyday work, leavers whose accounts never left, sharing set to everything, signals nobody reads, backup by assumption, and no record of any of it. All seven are the residue of decisions nobody was ever asked to make.

None of them is exotic. All of them are invisible from the inside.

Part of Microsoft 365 x NIS2
A factory fire door propped open with a fire extinguisher, the production floor visible beyond.

A pattern, not a survey

What follows is not a statistic. It is a pattern: the same handful of findings, tenant after tenant, in businesses run by careful people. We see them because we look at Microsoft 365 environments for a living. The owners do not see them for the same reason you cannot smell your own house.

The mistakes share one root. Nobody in the business ever sat down and made security decisions about the tenant, so the tenant runs on the decisions nobody made. Under NIS2, which asks for measures that are documented, managed and monitored, that root cause is itself the finding. But the pattern is easier to fix when you can name its parts.

The seven

One: the second sign-in check with exceptions. Most businesses now have multi-factor authentication, which is progress. Almost as many have exceptions: the managing director who found it annoying, the shared mailbox in dispatch, the old account the accounts package logs in with. Attackers do not attack your policy. They attack your exceptions, and one is enough.

Two: administrator accounts used for everyday work. The same account that reads email and opens attachments can also change every rule in the tenant. One convincing phishing message and the attacker is not a user, he is the administrator. Admin rights belong in separate accounts, used only for admin work, watched more closely than anything else you own.

Three: the leavers who never left. Accounts of people who resigned years ago, still enabled, still licensed, sometimes still forwarding mail. Every one is an unwatched door with a valid key, and the forwarding rule is how a quiet compromise stays quiet.

Four: sharing set to everything, forever. Links that anyone can open, passed along outside the business; guest accounts from a project in 2022 with standing access to the whole site. The file server had walls. The default cloud has none until someone builds them, and "someone" was never named.

Five: nobody reads the signals. The platform already produces sign-in alerts, a security score, audit logs. In most small businesses they arrive nowhere. The tenant is shouting into a room with no one in it, which is why day one of an incident is routinely weeks after the intrusion.

Six: backup by assumption. The belief that the platform's resilience is a backup of your data. It is not, and the difference appears precisely when you need it most.

Seven: no record of any of it. Even where settings are decent, nothing is written down: no as-built record, no reasons, no change log. Which means the business cannot answer a customer questionnaire, cannot brief a new IT provider, and cannot prove to anyone, including itself, that its security is deliberate.

Why sensible people make them

Not carelessness. Sequence. Every one of these is the residue of a rational day-one choice: get everyone working, keep friction low, move on. The tenant was configured for a business getting started, and no event ever forced the transition to a business being run. Software does not rust visibly. The settings that were fine at five people are still there at eighty, and nothing beeps.

This is why we keep saying the gap is a systems gap, not a people gap. Nobody was given the job of deciding, so the defaults decided. NIS2's contribution, for all its bureaucratic prose, is to create the forcing event: the customer questionnaire arrives, and "nobody ever decided" stops being invisible.

The order that works

Fix them in the order an attacker would exploit them, not the order they annoy you.

First, close the identity doors: the second check everywhere, no exceptions surviving without a written reason and a compensating control; separate admin accounts. Second, clean the population: leavers disabled, guests reviewed, forwarding rules audited. Third, turn the signals toward a human: alerts routed to a named person, the score read monthly. Fourth, make one backup copy real and tested. Fifth, write down what you now have, because the record is what turns all the above from housekeeping into evidence.

Then keep it that way, which is the part that separates a clean-up from a security posture. Settings drift, people join and leave, exceptions creep back. A quarterly hour reviewing the five areas above, logged in one page, is the minimum heartbeat; a managed baseline makes the heartbeat automatic and the log write itself.

None of the seven requires new software. All of them require a decision, a name and a date. That is the whole difference between the tenant you have and the tenant the questionnaire assumes you have.

Related questions

Will this help us meet the 24-hour incident reporting requirement under NIS2?4 min read
Can our company be held liable if a supplier or third party we use isn't compliant?4 min read
Why do default Microsoft 365 settings fail a NIS2 audit?5 min read

Prefer the conversation to the reading?

Thirty minutes on the alignment between your strategy and your technology. Not a sales pitch.

Book a discovery call